AI Agents Can Shop Amazon Again: What the Ninth Circuit's Perplexity Ruling Actually Decided
On August 4, 2026, a federal appeals court vacated the injunction that had barred Perplexity's Comet shopping assistant from Amazon — holding that when a user directs an AI agent, it is the user, not the AI company, who 'accesses' the website under the federal anti-hacking statute. The ruling is narrow, explicitly provisional, and enormously consequential for agentic commerce.
Bottom line
The Ninth Circuit vacated Amazon's preliminary injunction against Perplexity's Comet browser, ruling Amazon is unlikely to prove Perplexity 'accessed' its servers under the Computer Fraud and Abuse Act because users — not Perplexity — operate the agent. This research-based explainer covers what the court held, what it deliberately left open, why the rule of lenity mattered, which of Amazon's claims survive, and what the decision means for anyone building or using AI shopping agents.
Editorial accountability
Who checked this guide
- Evaluation type
- Research-based verification
- Last materially checked
- Evidence
- 5 listed sources
Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.
Editorial basis
What this guidance is based on
- Editorial basis
- Source-led analysis
- Primary references
- 5
- Products covered
- 3
- Last checked
- 2026-08-06
Important limits
- • Features, availability, and pricing can change after publication; confirm consequential details with the provider.
In this guide
*This is a research-based legal news analysis built from the Ninth Circuit's published opinion and analysis by law firms and reporters covering the case. It is general information, not legal advice — consult counsel before making decisions that depend on this ruling.*
The short answer
On August 4, 2026, the US Court of Appeals for the Ninth Circuit vacated the preliminary injunction that had barred Perplexity's Comet browser assistant from shopping on Amazon since March 2026. The panel, in an opinion authored by Judge Milan D. Smith, Jr., held that Amazon is unlikely to succeed on its Computer Fraud and Abuse Act (CFAA) claim because Comet's agentic "Assistant" is a tool operated by users — meaning it is the users, who hold legitimate Amazon accounts, who "access" Amazon's servers, not Perplexity.
Three qualifiers keep the ruling in proportion:
- It is a preliminary-injunction ruling, not a final judgment. The court decided Amazon is *unlikely to succeed* on the CFAA theory — the underlying lawsuit continues.
- The holding is expressly narrow. The panel noted there is "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents" under the CFAA, and said agentic AI law "will doubtless change."
- Amazon's other claims survive. The trademark and state-law claims were not resolved by this decision, and website operators retain contractual and technical means of managing automated traffic.
How the case got here
Amazon sued Perplexity in November 2025, alleging that Comet's AI Assistant accessed password-protected Amazon pages without Amazon's authorization — violating the CFAA and California's parallel statute (CDAFA). In March 2026, the district court agreed and enjoined Comet from Amazon: it reasoned that Amazon had not authorized Perplexity's access, regardless of whether Amazon customers had authorized the Assistant to act on their own accounts.
That framing — the platform's permission versus the user's permission — is the entire case. If a website's non-authorization of the *tool vendor* controls, then every AI agent needs permission from every site it visits. If the *user's* authorization controls, then an agent acting on a logged-in user's instructions stands in the user's shoes.
What the Ninth Circuit held
The panel sided with the user-authorization framing at this stage, on three grounds reported consistently across legal analyses:
- Operation, not creation, is what counts. Perplexity built the tool, but users invoke it, direct it, and authenticate with their own credentials. On that record, the "access" is the user's.
- The rule of lenity. The CFAA is a criminal statute applied civilly. Where its text is ambiguous — and attributing agent conduct is genuinely ambiguous — courts construe the ambiguity against liability. The Electronic Frontier Foundation, which filed in support of neither party, argued that building a browser cannot itself be a CFAA violation; the panel's reasoning tracks that concern.
- Judicial modesty about a moving target. The panel repeatedly flagged that agentic AI is new, the record is thin, and Congress — not a preliminary-injunction appeal — is the right forum for a comprehensive rule.
What the ruling does *not* decide
- It does not hold that AI companies can never be liable under the CFAA. A tool that acts autonomously, without user direction, or that circumvents technical barriers could be analyzed differently.
- It does not give agents a right to ignore a website's terms of service. Contract claims, trademark claims, and unfair-competition claims proceed on their own tracks.
- It does not prevent Amazon from technically blocking or rate-limiting agent traffic. The decision addresses criminal-statute liability, not network engineering.
- It does not bind courts outside the Ninth Circuit, though it is the first appellate word on the question and will be widely cited.
Why this matters for agentic commerce
The practical stakes are larger than one shopping assistant:
For AI companies, the decision removes — for now, in one circuit — the most severe legal theory against user-directed agents: felony-statute liability for merely visiting sites the vendor lacks permission to visit. Expect agent vendors to lean into the "user-operated tool" architecture the court credited: user credentials, user initiation, user-visible actions.
For website operators, the decision signals that the CFAA is the wrong tool for managing unwanted agent traffic. The durable levers are contractual terms, technical controls (bot management, agent-identification protocols), and business deals — several large retailers have chosen partnership over litigation, striking agentic-checkout agreements with AI providers rather than suing them.
For users, agents that shop, book, and compare on your behalf just became meaningfully harder to ban outright. The open question is whether platforms respond with cooperation (sanctioned agent APIs) or friction (aggressive bot detection that degrades the experience).
For everyone, the panel's candor is the headline: there is essentially no settled law on responsibility for AI agents' actions, and this ruling is a first draft. Businesses building on agentic access should assume the rules will keep moving.
Questions worth asking before you build on this ruling
- Does your agent act only on explicit user direction, with the user's own credentials? That is the architecture the court credited.
- Do you have a fallback if target platforms deploy technical blocks? A legal right to exist is not an engineering guarantee of access.
- Are your terms and disclosures honest about the agent's identity? Trademark and misrepresentation theories survived this ruling.
- Are you monitoring the remand and parallel cases? A preliminary ruling can be narrowed, distinguished, or superseded.
Sources and verification
Product details and claims were checked against the following primary sources.
- Amazon.com, Inc. v. Perplexity AI, Inc. — Ninth Circuit published opinion (August 4, 2026)
- Ninth Circuit Rules on AI Agent 'Access' to Third-Party Websites Under CFAA — Cooley LLP
- Appeals Court Agrees with EFF that Building a Web Browser Doesn't Violate the CFAA — Electronic Frontier Foundation
- Ninth Circuit Narrows CFAA Reach in Perplexity Agentic Commerce Ruling — PYMNTS
- Court lets Perplexity's AI agent shop on Amazon, overturning a ban — The Next Web
Frequently asked questions
Did Perplexity win the lawsuit against Amazon?
Not the whole lawsuit — it won the appeal of the preliminary injunction. The Ninth Circuit vacated the order that had barred Comet from Amazon, finding Amazon unlikely to succeed on its Computer Fraud and Abuse Act claim. The underlying case continues, and Amazon's trademark and state-law claims were not resolved by this decision.
Does this ruling mean any AI agent can access any website legally?
No. The holding is narrow: on this record, a user-directed agent authenticating with the user's own credentials meant the user — not Perplexity — 'accessed' Amazon under the CFAA. Agents that act autonomously, circumvent technical barriers, or misrepresent themselves could be analyzed differently, and websites retain contractual and technical means of restricting automated traffic. The court itself said agentic AI law 'will doubtless change.'
What is the rule of lenity and why did it matter here?
The rule of lenity is the principle that ambiguous criminal statutes are construed against liability. Because the CFAA is a criminal statute (also enforceable civilly) and there is almost no caselaw on attributing an AI agent's actions, the panel resolved the ambiguity about who 'accesses' a server in favor of the narrower reading. It was a key reason the court declined to treat Perplexity as the accessing party.
Can Amazon still block AI shopping agents technically?
Yes. The ruling addresses liability under an anti-hacking statute, not network engineering. Amazon and other retailers can still deploy bot detection, rate limiting, and agent-identification requirements, and can pursue contract and trademark theories. The strategic question for platforms is whether to fight agent traffic with friction or channel it through sanctioned partnerships and agent-checkout APIs.
Found this useful?
Get the next one in your inbox.
One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.
Free · one email a week · unsubscribe any time
Tools mentioned in this article
Perplexity AI
AI-powered search engine with real-time citations and research capabilities
Perplexity combines AI chat with real-time web search, delivering cited, verifiable answers. Think Google Search meets ChatGPT.
ChatGPT
The general-purpose AI assistant that started it all
OpenAI's flagship conversational AI model, powering everything from casual chat to complex reasoning, coding, and creative work.
Claude
Anthropic's thoughtful, safety-focused AI with exceptional long-form reasoning
Claude excels at deep analysis, long-form writing, and nuanced reasoning. Built by Anthropic with a focus on safety and helpfulness.
Read next
Recommended for you

JobCopilot Review 2026: Is AI Auto-Apply Worth It?
JobCopilot can remove hours of repetitive application work, but match quality, truthful answers, and human review matter more than raw submission volume.
A research-based JobCopilot review covering automated applications, current pricing, privacy, risks, alternatives, and a practical buyer test.
Read guide
AI Tools for Nonprofits in 2026: Build a Practical Mission-First Stack
Best AI Tools Under $50 a Month for Small Business in 2026
Best AI Writing Tools in 2026: 9 Picks by Use Case, Budget, and Workflow