The Agentic Review

Incidents — AUGUST 21, 2026

Ninth Circuit sides with Perplexity, ruling AI agents are 'tools, not persons' under federal hacking law

In the first federal appellate decision on agentic commerce, the Ninth Circuit vacated an injunction barring Perplexity's Comet browser from Amazon.com, holding that under the CFAA it is the user — not the AI agent — who 'accesses' a third-party website.

On August 4, 2026, the U.S. Court of Appeals for the Ninth Circuit vacated the preliminary injunction that had barred Perplexity AI’s Comet browser from interacting with Amazon.com, delivering the first federal appellate reading of how the Computer Fraud and Abuse Act applies to agentic commerce. The panel’s answer was narrow but structurally significant: under a statute enacted in 1986, an AI agent is “a tool, not a person, for statutory purposes,” and it’s the user who accesses the third-party site.

The case, Amazon.com Services, LLC v. Perplexity AI, began in November 2025 when Amazon sued in the Northern District of California, alleging that Comet’s Assistant logged into customer accounts, compared products, and submitted orders without authorization, after Amazon had already told Perplexity its AI products weren’t welcome on the store. Perplexity had also declined to adopt a user-agent string that would’ve let Amazon identify and block the Assistant. In March 2026, Judge Maxine Chesney granted Amazon’s injunction. Administrative stays kept it from biting while the appeal ran.

The Ninth Circuit’s reasoning turned on plumbing. Comet takes screenshots on the user’s own machine, sends them to Perplexity’s servers, and routes the returned navigation instructions back through the user’s computer. From that architecture the panel drew its statutory conclusion: “Perplexity itself does not directly communicate with Amazon’s servers.” It was “the user who accessed Amazon’s computers, with the help of Perplexity’s AI agent.” Because “the CFAA contemplates access by a person,” Amazon’s federal hacking theory, and its California CDAFA analogue, were unlikely to succeed.

Judge John Hinderaker was careful to note that the 1986 statute wasn’t drafted with AI agents in mind, and warned of unintended consequences in stretching it into a new domain. The opinion says explicitly that its holdings “do not establish a new legal regime governing agentic AI.”

Which is where the ruling’s real center of gravity sits. The panel expressly left open contract, tort, and terms-of-service theories, the exact tools platforms already use to police scraping. Outside counsel at Cooley, Wilson Sonsini, Ropes & Gray, and Ballard Spahr all flagged the same architectural tell: agents that connect directly to a website’s servers, rather than relaying through the user’s device, may still trigger CFAA liability.

The case now returns to the Northern District of California. Amazon’s federal hacking claim is weaker; its private ordering leverage is untouched. The fight over agentic commerce isn’t ending, it’s migrating into the fine print.

Sources

— END —