On August 4 2026 a federal appeals court dealt a setback to Amazon’s bid to block AI shopping bots from its site. The Ninth U.S. Circuit Court of Appeals in San Francisco vacated a preliminary injunction that had barred Perplexity’s Comet browser – an AI “shopping assistant” – from logging into Amazon customer accounts. The court held that Perplexity itself did not “access” Amazon’s computers in violation of law; rather, when Comet’s built-in agent made purchases, it was effectively the user who was accessing Amazon. In other words Perplexity’s customers, not the company, “accessed” Amazon's site. This reasoning is unprecedented: as Reuters noted, it appears to be “the first [federal] appeals court ruling to address whether AI agents acting on behalf of users can legally access online platforms,” a question with far-reaching implications. If accepted as precedent it could mean that retailers have far less power to exclude unauthorized bots – raising the prospect that e-commerce sites may not be able to block shopping assistants at all.
Amazon’s complaint began in late 2025. The company sued Perplexity in November 2025 accusing the startup’s new Comet browser of covertly logging into customers’ Amazon accounts and placing orders without Amazon’s permission. In the months prior Amazon had warned Perplexity that Comet was violating its terms of service by not identifying itself as an automated agent. Comet sent the same “Chrome” user-agent string as a normal browser hiding its true nature. Perplexity publicly pushed back. Its blog post “Bullying is not innovation” argued that Comet only operates with the customer’s consent and therefore should have the same permissions as the user. In Perplexity’s view a Comet user “has granted [the AI] access to their account – just as if they had given those same credentials to a human” so Amazon could not lawfully bar the activity.
Judge Chesney’s March 2026 order hinged on the CFAA’s “authorization” requirement. Citing Power Ventures v. Facebook (9th Cir. 2016) Chesney concluded that while individual users had consented to give Comet their Amazon passwords that did not automatically authorize Perplexity itself. Once Amazon explicitly withdrew permission (via its cease-and-desist) any further access by Comet constituted a violation. Chesney wrote that Amazon had shown “strong evidence” of unauthorized access: Comet (at Amazon’s account areas) acted “with the Amazon user’s permission but without authorization by Amazon”. The judge found that Amazon likely would suffer irreparable harm – from lost sales data, user confusion and the need to deploy new defenses – if the botting continued. The preliminary injunction therefore barred Comet from logging into any Amazon account and even required Perplexity to delete any Amazon account information it had gathered.
In explaining its ruling the district court treated the situation analogously to a user posting private information on Facebook and then, after revocation, allowing a third party to use that login. Although Comet’s actions were initiated by the user Chesney held Perplexity could still be liable for exceeding its authority. This interpretation followed prior CFAA cases in which a site owner revoked access (as with Facebook in Power Ventures): continued use of the account was deemed unauthorized. Amazon also argued that the automation made matters worse – by disguising as a human browser Comet skirted safeguards. Under this analysis at the preliminary stage Chesney found Amazon had met all the factors for an injunction.
The Ninth Circuit panel reversed all of that. In a 21-page published opinion authored by Judge Milan D. Smith the court found that no one had proven Perplexity’s code itself “accessed” Amazon’s systems without permission. Citing the Supreme Court’s CFAA jurisprudence the panel explained that “to violate the CFAA a person must obtain information from a protected computer – i.e., Amazon’s servers – without authorization”. Here Perplexity never directly entered Amazon’s network. The AI agent merely automated actions that a user voluntarily performed. In the court’s view this was the legal equivalent of a person using a regular browser: an iPhone or desktop browser user accessing Amazon isn’t Amazon and similarly Comet’s user – not Perplexity – is the actor. “It is the user who ‘accesses’ Amazon’s computers”, the opinion stated, “with the help of the [AI] Assistant”, not Perplexity itself. Perplexity’s servers simply got copies of data that the user’s device already fetched; that passive data gathering did not count as “access” under the CFAA.
The appeals court emphasized ordinary users should not be caught in a widening net of liability. Citing the rule of lenity (which advises narrow construction of criminal statutes) the panel warned that if this use of computers were considered unauthorized then “millions of users” who delegate tasks to software could be guilty of felonies. In short, the court refused to stretch the anti-hacking law into uncharted terrain. It therefore held Amazon was “unlikely to succeed” on its CFAA claim and vacated the injunction.
The Ninth Circuit also applied the same logic to California’s Comprehensive Computer Data Access and Fraud Act (CDAFA), which mirrors the CFAA and drew the same conclusion: Perplexity had not “hacked” Amazon.
The core legal question was who “accesses” a computer when an AI agent operates. Under the CFAA (18 U.S.C. §1030) liability attaches only if someone accesses a protected computer “without authorization”. In United States v. Van Buren (2021) and earlier Ninth Circuit cases like Nosal courts have narrowed CFAA liability to true hacking or credential abuse. In Power Ventures the Ninth Circuit held that continuing to use a revoked Facebook login was unauthorized. Amazon argued that once it revoked Comet’s credentials any further use was per se a CFAA violation.
The Ninth Circuit panel rejected that approach here. It focused on the identity of the actor. Because Comet’s actions were directed by a consenting user, not by Perplexity on its own initiative, the court found no “unauthorized access” by Perplexity. As EFF’s brief argued - “Perplexity itself does not access Amazon’s servers – users of the Comet browser do”. The appeals court agreed noting Perplexity’s involvement was essentially passive.
Other factors tended to support Perplexity. Judge Smith noted that the CFAA is a criminal statute originally aimed at malicious hackers. Giving Amazon the benefit of ambiguity would “expos[e] users themselves to criminal liability” for common activities. The court also pointed out that Congress wrote the CFAA in 1986, long before AI agents existed; it was not obvious that its language should sweep in advanced browser automation. In effect, the panel signaled that any new restrictions on AI agents would have to come from Congress or clearer industry regulation, not an elastic reading of old anti-hacking law.
Amazon’s immediate response was terse. An Amazon spokesperson told Reuters: “We respectfully disagree with today’s decision on the preliminary injunction. We remain confident in our case and are evaluating our next steps.” Perplexity celebrated the outcome. Company spokesperson Jesse Dwyer said they would “continue to fight for the right of internet users to choose whatever AI they want”.
Privacy and innovation advocates hailed the ruling. The Electronic Frontier Foundation praised it as a “gratifying” decision – noting that large companies often use the CFAA to “bully upstarts and innovators”. The Knight Institute (part of Columbia Law School) cheered too. Jake Karr commented that “computer crime laws… shouldn’t be stretched to penalize tools that automate a user’s access to their own information”. In their view the court’s common-sense distinction preserves “user control and independent journalism” and prevents ordinary users from being ensnared in hacking statutes.
Not everyone agreed. Media and advertising interests had largely sided with Amazon during the appeal. A trade group of publishers warned that AI agents masquerading as human visitors could wreak havoc on online ad systems. They pointed out that if bots inflate page views or video plays advertisers and publishers lose trust in their metrics (and revenue). Industry analysts note the ruling could deprive sites of a key defense. As one technology columnist put it the decision “gives agent-makers a template to argue that acting for a user is not hacking” meaning “platforms lose one of their sharpest tools for keeping third-party agents out”. In plain terms: if the law says an AI agent is legally just another browser session by a real user then websites can no longer easily tell those bots “you’re not authorized here.”
The Ninth Circuit’s logic could reshape e-commerce and internet policy in several ways:
The Ninth Circuit’s decision is a landmark in the age of agentic AI. It opens the door to a new style of commerce where automated helpers roam the web on behalf of consumers. Retailers may need to rethink how they manage their sites and revenue models while developers of AI tools will be emboldened to push the boundaries of what their software can do. Amazon has already signaled it is weighing its options possibly seeking rehearing or even Supreme Court review. In the meantime the underlying lawsuit will continue on other grounds (Amazon may pursue contract or state-law claims for example).
More broadly, the case highlights a growing tension: the internet was built for people but AI agents turn every user into a network participant at machine speed. As one commentator observed the real question for the future may not just be “how to optimize websites for AI” but “whether sites can prevent those AI agents from coming in at all.” The answer will likely unfold only as courts apply the appeals ruling to other contexts and as lawmakers and tech companies negotiate the rules of this emerging agentic economy.