Amazon built the wall. AI found the door.

Amazon built the wall. AI found the door.

On August 4 2026 a federal appeals court dealt a setback to Amazon’s bid to block AI shopping bots from its site. The Ninth U.S. Circuit Court of Appeals in San Francisco vacated a preliminary injunction that had barred Perplexity’s Comet browser – an AI “shopping assistant” – from logging into Amazon customer accounts. The court held that Perplexity itself did not “access” Amazon’s computers in violation of law; rather, when Comet’s built-in agent made purchases, it was effectively the user who was accessing Amazon. In other words Perplexity’s customers, not the company, “accessed” Amazon's site. This reasoning is unprecedented: as Reuters noted, it appears to be “the first [federal] appeals court ruling to address whether AI agents acting on behalf of users can legally access online platforms,” a question with far-reaching implications. If accepted as precedent it could mean that retailers have far less power to exclude unauthorized bots – raising the prospect that e-commerce sites may not be able to block shopping assistants at all.

Background and timeline

Amazon’s complaint began in late 2025. The company sued Perplexity in November 2025 accusing the startup’s new Comet browser of covertly logging into customers’ Amazon accounts and placing orders without Amazon’s permission. In the months prior Amazon had warned Perplexity that Comet was violating its terms of service by not identifying itself as an automated agent. Comet sent the same “Chrome” user-agent string as a normal browser hiding its true nature. Perplexity publicly pushed back. Its blog post “Bullying is not innovation” argued that Comet only operates with the customer’s consent and therefore should have the same permissions as the user. In Perplexity’s view a Comet user “has granted [the AI] access to their account – just as if they had given those same credentials to a human” so Amazon could not lawfully bar the activity.

  • October 2025: Amazon issues cease-and-desist notices to Perplexity demanding that Comet immediately stop using Amazon logins. Perplexity responds with a public blog (“Bullying is not innovation”) vowing to defend “the right of internet users to choose their own AI”.
  • November 4, 2025: Amazon files its federal lawsuit (N.D. Cal.) under the Computer Fraud and Abuse Act (CFAA) and California’s analogous anti-hacking law asserting that Comet “covertly” accessed password-protected Amazon accounts and ignored Amazon’s orders to cease.
  • March 9, 2026: U.S. District Judge Maxine Chesney grants Amazon a preliminary injunction. Chesney agrees Amazon has “strong evidence” that Comet accessed accounts “with the Amazon user’s permission but without authorization by Amazon”. In her view once Amazon revoked Comet’s access any continued use of the login credentials violated the CFAA. The injunction forbids Perplexity from using its AI agent on Amazon and orders it to delete any collected Amazon account data.
  • March 11, 2026: Perplexity immediately appeals and obtains an administrative stay from the Ninth Circuit allowing Comet to continue running while the appeal proceeds.
  • April 2026: Amicus briefs pour in. Digital-rights advocates (EFF, Mozilla, ACLU, Columbia’s Knight Institute) warn the court that Chesney’s broad reading of the CFAA would give Amazon a veto power over how the public accesses the internet. In its brief the EFF noted that Perplexity “does not ‘access’ Amazon’s servers – users of Comet do” echoing Perplexity’s argument. At the same time a coalition of major news publishers via Digital Content Next filed a brief backing Amazon warning that “spoofing” bots could corrupt ad metrics and subscription models.
  • August 4, 2026: The Ninth Circuit hears arguments and issues its decision (details below). The panel formally lifts Chesney’s injunction siding with Perplexity’s position.

District court’s preliminary injunction

Judge Chesney’s March 2026 order hinged on the CFAA’s “authorization” requirement. Citing Power Ventures v. Facebook (9th Cir. 2016) Chesney concluded that while individual users had consented to give Comet their Amazon passwords that did not automatically authorize Perplexity itself. Once Amazon explicitly withdrew permission (via its cease-and-desist) any further access by Comet constituted a violation. Chesney wrote that Amazon had shown “strong evidence” of unauthorized access: Comet (at Amazon’s account areas) acted “with the Amazon user’s permission but without authorization by Amazon”. The judge found that Amazon likely would suffer irreparable harm – from lost sales data, user confusion and the need to deploy new defenses – if the botting continued. The preliminary injunction therefore barred Comet from logging into any Amazon account and even required Perplexity to delete any Amazon account information it had gathered.

In explaining its ruling the district court treated the situation analogously to a user posting private information on Facebook and then, after revocation, allowing a third party to use that login. Although Comet’s actions were initiated by the user Chesney held Perplexity could still be liable for exceeding its authority. This interpretation followed prior CFAA cases in which a site owner revoked access (as with Facebook in Power Ventures): continued use of the account was deemed unauthorized. Amazon also argued that the automation made matters worse – by disguising as a human browser Comet skirted safeguards. Under this analysis at the preliminary stage Chesney found Amazon had met all the factors for an injunction.

Ninth Circuit’s ruling

The Ninth Circuit panel reversed all of that. In a 21-page published opinion authored by Judge Milan D. Smith the court found that no one had proven Perplexity’s code itself “accessed” Amazon’s systems without permission. Citing the Supreme Court’s CFAA jurisprudence the panel explained that “to violate the CFAA a person must obtain information from a protected computer – i.e., Amazon’s servers – without authorization”. Here Perplexity never directly entered Amazon’s network. The AI agent merely automated actions that a user voluntarily performed. In the court’s view this was the legal equivalent of a person using a regular browser: an iPhone or desktop browser user accessing Amazon isn’t Amazon and similarly Comet’s user – not Perplexity – is the actor. “It is the user who ‘accesses’ Amazon’s computers”, the opinion stated, “with the help of the [AI] Assistant”, not Perplexity itself. Perplexity’s servers simply got copies of data that the user’s device already fetched; that passive data gathering did not count as “access” under the CFAA.

The appeals court emphasized ordinary users should not be caught in a widening net of liability. Citing the rule of lenity (which advises narrow construction of criminal statutes) the panel warned that if this use of computers were considered unauthorized then “millions of users” who delegate tasks to software could be guilty of felonies. In short, the court refused to stretch the anti-hacking law into uncharted terrain. It therefore held Amazon was “unlikely to succeed” on its CFAA claim and vacated the injunction.

The Ninth Circuit also applied the same logic to California’s Comprehensive Computer Data Access and Fraud Act (CDAFA), which mirrors the CFAA and drew the same conclusion: Perplexity had not “hacked” Amazon.

Key legal takeaways

The core legal question was who “accesses” a computer when an AI agent operates. Under the CFAA (18 U.S.C. §1030) liability attaches only if someone accesses a protected computer “without authorization”. In United States v. Van Buren (2021) and earlier Ninth Circuit cases like Nosal courts have narrowed CFAA liability to true hacking or credential abuse. In Power Ventures the Ninth Circuit held that continuing to use a revoked Facebook login was unauthorized. Amazon argued that once it revoked Comet’s credentials any further use was per se a CFAA violation.

The Ninth Circuit panel rejected that approach here. It focused on the identity of the actor. Because Comet’s actions were directed by a consenting user, not by Perplexity on its own initiative, the court found no “unauthorized access” by Perplexity. As EFF’s brief argued - “Perplexity itself does not access Amazon’s servers – users of the Comet browser do”. The appeals court agreed noting Perplexity’s involvement was essentially passive.

Other factors tended to support Perplexity. Judge Smith noted that the CFAA is a criminal statute originally aimed at malicious hackers. Giving Amazon the benefit of ambiguity would “expos[e] users themselves to criminal liability” for common activities. The court also pointed out that Congress wrote the CFAA in 1986, long before AI agents existed; it was not obvious that its language should sweep in advanced browser automation. In effect, the panel signaled that any new restrictions on AI agents would have to come from Congress or clearer industry regulation, not an elastic reading of old anti-hacking law.


Reactions and commentary

Amazon’s immediate response was terse. An Amazon spokesperson told Reuters: “We respectfully disagree with today’s decision on the preliminary injunction. We remain confident in our case and are evaluating our next steps.” Perplexity celebrated the outcome. Company spokesperson Jesse Dwyer said they would “continue to fight for the right of internet users to choose whatever AI they want”.

Privacy and innovation advocates hailed the ruling. The Electronic Frontier Foundation praised it as a “gratifying” decision – noting that large companies often use the CFAA to “bully upstarts and innovators”. The Knight Institute (part of Columbia Law School) cheered too. Jake Karr commented that “computer crime laws… shouldn’t be stretched to penalize tools that automate a user’s access to their own information”. In their view the court’s common-sense distinction preserves “user control and independent journalism” and prevents ordinary users from being ensnared in hacking statutes.

Not everyone agreed. Media and advertising interests had largely sided with Amazon during the appeal. A trade group of publishers warned that AI agents masquerading as human visitors could wreak havoc on online ad systems. They pointed out that if bots inflate page views or video plays advertisers and publishers lose trust in their metrics (and revenue). Industry analysts note the ruling could deprive sites of a key defense. As one technology columnist put it the decision “gives agent-makers a template to argue that acting for a user is not hacking” meaning “platforms lose one of their sharpest tools for keeping third-party agents out”. In plain terms: if the law says an AI agent is legally just another browser session by a real user then websites can no longer easily tell those bots “you’re not authorized here.”


Implications for retailers, AI developers and policy

The Ninth Circuit’s logic could reshape e-commerce and internet policy in several ways:

  • Retailers’ control is weakened. If Comet-like bots are legally considered the user, online stores may no longer forbid them under the CFAA. Merchants might have to rely on technical means (like CAPTCHA challenges) or new contractual frameworks to regulate AI agents. Some platforms may create official APIs or opt-in programs for approved shopping assistants. Without legal backing, however, any outright ban could be very difficult to enforce.
  • Advertising and data concerns. Amazon and many retailers earn substantial revenue from sponsored listings, ads and analytics. An AI agent that ignores ads or filters search results threatens these revenue streams. Digital publishers already worry about “invalid traffic” from scrapers and bots; AI agents could greatly increase that problem. If bot-driven access is indistinguishable from a real user publishers and advertisers may demand new rules – for example, requiring bots to identify themselves or share revenue.
  • Consumer choice and market pressure. The decision effectively affirms a broad consumer right to use AI tools of their choice. Many software companies (and big tech firms) are racing to build shopping agents: ChatGPT’s plugins can already check out items, Google and Microsoft have agentic shopping features and Alibaba in China has integrated AI assistants into its shopping platforms. If agents flourish retailers may feel compelled to adapt. Some will try to integrate their own AI assistants (Amazon has quietly developed its “Rufus” shopping AI) or design commerce sites that are “bot-friendly” to stay competitive.
  • Policy responses. Lawmakers have begun to take notice. For example, a bipartisan Senate bill sponsored by Senator Mark Warner would direct the FTC to create a registry of “trusted” AI agents and certify their security standards. Consumer protection regulators may also demand transparency when bots use user accounts (similar to “assistant” rules in California’s privacy law). More broadly this case could spur targeted legislation defining what counts as “authorization” when AI is involved. Congress might consider amendments to the CFAA or new digital-access laws that explicitly address automated software.
  • Liability and user risk. The ruling leaves unanswered questions about responsibility. If an AI shopping assistant goes awry – say it orders the wrong item or is tricked by a phishing link – is the user solely liable? Under the appeals court’s reasoning presumably yes, since the AI is treated as acting at the user’s direction. But courts and regulators may still have to wrestle with situations like identity fraud or agent malfunctions. For now the decision underscores that users have broad leeway to automate their online accounts for better or worse.

Conclusion

The Ninth Circuit’s decision is a landmark in the age of agentic AI. It opens the door to a new style of commerce where automated helpers roam the web on behalf of consumers. Retailers may need to rethink how they manage their sites and revenue models while developers of AI tools will be emboldened to push the boundaries of what their software can do. Amazon has already signaled it is weighing its options possibly seeking rehearing or even Supreme Court review. In the meantime the underlying lawsuit will continue on other grounds (Amazon may pursue contract or state-law claims for example).

More broadly, the case highlights a growing tension: the internet was built for people but AI agents turn every user into a network participant at machine speed. As one commentator observed the real question for the future may not just be “how to optimize websites for AI” but “whether sites can prevent those AI agents from coming in at all.” The answer will likely unfold only as courts apply the appeals ruling to other contexts and as lawmakers and tech companies negotiate the rules of this emerging agentic economy.