GuideUpdated 2026-08-06

AI Agents Can Shop Amazon Again: What the Ninth Circuit's Perplexity Ruling Actually Decided

On August 4, 2026, a federal appeals court vacated the injunction that had barred Perplexity's Comet shopping assistant from Amazon — holding that when a user directs an AI agent, it is the user, not the AI company, who 'accesses' the website under the federal anti-hacking statute. The ruling is narrow, explicitly provisional, and enormously consequential for agentic commerce.

By DiscoverAI Editorial Team5 min readBuild, Design & GovernHow we evaluate

Bottom line

The Ninth Circuit vacated Amazon's preliminary injunction against Perplexity's Comet browser, ruling Amazon is unlikely to prove Perplexity 'accessed' its servers under the Computer Fraud and Abuse Act because users — not Perplexity — operate the agent. This research-based explainer covers what the court held, what it deliberately left open, why the rule of lenity mattered, which of Amazon's claims survive, and what the decision means for anyone building or using AI shopping agents.

Editorial basis

What this guidance is based on

Editorial basis
Source-led analysis
Primary references
5
Products covered
3
Last checked
2026-08-06

Important limits

  • Features, availability, and pricing can change after publication; confirm consequential details with the provider.
In this guide
  1. The short answer
  2. How the case got here
  3. What the Ninth Circuit held
  4. What the ruling does *not* decide
  5. Why this matters for agentic commerce
  6. Questions worth asking before you build on this ruling

*This is a research-based legal news analysis built from the Ninth Circuit's published opinion and analysis by law firms and reporters covering the case. It is general information, not legal advice — consult counsel before making decisions that depend on this ruling.*

The short answer

On August 4, 2026, the US Court of Appeals for the Ninth Circuit vacated the preliminary injunction that had barred Perplexity's Comet browser assistant from shopping on Amazon since March 2026. The panel, in an opinion authored by Judge Milan D. Smith, Jr., held that Amazon is unlikely to succeed on its Computer Fraud and Abuse Act (CFAA) claim because Comet's agentic "Assistant" is a tool operated by users — meaning it is the users, who hold legitimate Amazon accounts, who "access" Amazon's servers, not Perplexity.

Three qualifiers keep the ruling in proportion:

  1. It is a preliminary-injunction ruling, not a final judgment. The court decided Amazon is *unlikely to succeed* on the CFAA theory — the underlying lawsuit continues.
  2. The holding is expressly narrow. The panel noted there is "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents" under the CFAA, and said agentic AI law "will doubtless change."
  3. Amazon's other claims survive. The trademark and state-law claims were not resolved by this decision, and website operators retain contractual and technical means of managing automated traffic.

How the case got here

Amazon sued Perplexity in November 2025, alleging that Comet's AI Assistant accessed password-protected Amazon pages without Amazon's authorization — violating the CFAA and California's parallel statute (CDAFA). In March 2026, the district court agreed and enjoined Comet from Amazon: it reasoned that Amazon had not authorized Perplexity's access, regardless of whether Amazon customers had authorized the Assistant to act on their own accounts.

That framing — the platform's permission versus the user's permission — is the entire case. If a website's non-authorization of the *tool vendor* controls, then every AI agent needs permission from every site it visits. If the *user's* authorization controls, then an agent acting on a logged-in user's instructions stands in the user's shoes.

What the Ninth Circuit held

The panel sided with the user-authorization framing at this stage, on three grounds reported consistently across legal analyses:

  • Operation, not creation, is what counts. Perplexity built the tool, but users invoke it, direct it, and authenticate with their own credentials. On that record, the "access" is the user's.
  • The rule of lenity. The CFAA is a criminal statute applied civilly. Where its text is ambiguous — and attributing agent conduct is genuinely ambiguous — courts construe the ambiguity against liability. The Electronic Frontier Foundation, which filed in support of neither party, argued that building a browser cannot itself be a CFAA violation; the panel's reasoning tracks that concern.
  • Judicial modesty about a moving target. The panel repeatedly flagged that agentic AI is new, the record is thin, and Congress — not a preliminary-injunction appeal — is the right forum for a comprehensive rule.

What the ruling does *not* decide

  • It does not hold that AI companies can never be liable under the CFAA. A tool that acts autonomously, without user direction, or that circumvents technical barriers could be analyzed differently.
  • It does not give agents a right to ignore a website's terms of service. Contract claims, trademark claims, and unfair-competition claims proceed on their own tracks.
  • It does not prevent Amazon from technically blocking or rate-limiting agent traffic. The decision addresses criminal-statute liability, not network engineering.
  • It does not bind courts outside the Ninth Circuit, though it is the first appellate word on the question and will be widely cited.

Why this matters for agentic commerce

The practical stakes are larger than one shopping assistant:

For AI companies, the decision removes — for now, in one circuit — the most severe legal theory against user-directed agents: felony-statute liability for merely visiting sites the vendor lacks permission to visit. Expect agent vendors to lean into the "user-operated tool" architecture the court credited: user credentials, user initiation, user-visible actions.

For website operators, the decision signals that the CFAA is the wrong tool for managing unwanted agent traffic. The durable levers are contractual terms, technical controls (bot management, agent-identification protocols), and business deals — several large retailers have chosen partnership over litigation, striking agentic-checkout agreements with AI providers rather than suing them.

For users, agents that shop, book, and compare on your behalf just became meaningfully harder to ban outright. The open question is whether platforms respond with cooperation (sanctioned agent APIs) or friction (aggressive bot detection that degrades the experience).

For everyone, the panel's candor is the headline: there is essentially no settled law on responsibility for AI agents' actions, and this ruling is a first draft. Businesses building on agentic access should assume the rules will keep moving.

Questions worth asking before you build on this ruling

  1. Does your agent act only on explicit user direction, with the user's own credentials? That is the architecture the court credited.
  2. Do you have a fallback if target platforms deploy technical blocks? A legal right to exist is not an engineering guarantee of access.
  3. Are your terms and disclosures honest about the agent's identity? Trademark and misrepresentation theories survived this ruling.
  4. Are you monitoring the remand and parallel cases? A preliminary ruling can be narrowed, distinguished, or superseded.

Sources and verification

Product details and claims were checked against the following primary sources.

Frequently asked questions

Did Perplexity win the lawsuit against Amazon?

Not the whole lawsuit — it won the appeal of the preliminary injunction. The Ninth Circuit vacated the order that had barred Comet from Amazon, finding Amazon unlikely to succeed on its Computer Fraud and Abuse Act claim. The underlying case continues, and Amazon's trademark and state-law claims were not resolved by this decision.

Does this ruling mean any AI agent can access any website legally?

No. The holding is narrow: on this record, a user-directed agent authenticating with the user's own credentials meant the user — not Perplexity — 'accessed' Amazon under the CFAA. Agents that act autonomously, circumvent technical barriers, or misrepresent themselves could be analyzed differently, and websites retain contractual and technical means of restricting automated traffic. The court itself said agentic AI law 'will doubtless change.'

What is the rule of lenity and why did it matter here?

The rule of lenity is the principle that ambiguous criminal statutes are construed against liability. Because the CFAA is a criminal statute (also enforceable civilly) and there is almost no caselaw on attributing an AI agent's actions, the panel resolved the ambiguity about who 'accesses' a server in favor of the narrower reading. It was a key reason the court declined to treat Perplexity as the accessing party.

Can Amazon still block AI shopping agents technically?

Yes. The ruling addresses liability under an anti-hacking statute, not network engineering. Amazon and other retailers can still deploy bot detection, rate limiting, and agent-identification requirements, and can pursue contract and trademark theories. The strategic question for platforms is whether to fight agent traffic with friction or channel it through sanctioned partnerships and agent-checkout APIs.

Continue exploring

A useful next step

View topic →
WorkflowWork & Operations

How Nonprofits Can Use AI for Grant Reporting and Compliance in 2026

Reduce the burden of grant reporting with AI tools that help compile metrics, generate narrative, reconcile budgets, and meet funder requirements without cutting corners on accuracy.

Grant reporting is one of the heaviest administrative burdens nonprofits face. AI tools can dramatically reduce reporting time while maintaining the accuracy and transparency funders expect. This guide walks through the full workflow — from data compilation to narrative generation to compliance checklist verification.

Read guide

ReviewWork & Operations

Perplexity AI Review 2026: The Research-First AI Assistant, Honestly Assessed

We tested Perplexity Pro across research, fact-checking, competitive analysis, and deep-dive investigative tasks to determine whether its citation-first approach makes it the best AI tool for knowledge workers who need answers they can trust.

Perplexity takes a fundamentally different approach from ChatGPT and Claude — every answer comes with citations to real sources. We tested whether this approach delivers more trustworthy results for research, analysis, and fact-checking, and where general-purpose chatbots still have the edge.

Read guide

ReviewContent & Search

Claude Review 2026: The Deep Work AI Assistant, Honestly Assessed

We tested Claude Pro across writing, analysis, research, coding, and creative work to determine whether its nuanced reasoning and long-form capabilities make it the best AI assistant for knowledge workers — and where ChatGPT still has the edge.

Claude has earned a reputation as the 'thinking person's AI' — better at nuanced reasoning, long-form writing, and deep analysis than competitors. We put that reputation to the test across 40 real-world knowledge work tasks to determine where Claude genuinely leads, where it's caught up, and which users should make it their primary AI assistant.

Read guide

WorkflowWork & Operations

How Nonprofits Can Use AI for Program Evaluation and Outcomes Measurement in 2026

A practical framework for using AI to design evaluation methodologies, analyze program data, identify what's working, and communicate outcomes to funders — without needing a dedicated evaluation team.

Most small and mid-size nonprofits know they should evaluate their programs but lack the staff, budget, or expertise to do rigorous evaluation. AI tools can help design surveys, analyze qualitative feedback, identify patterns in program data, and draft evaluation reports — making meaningful evaluation accessible to organizations that couldn't previously afford it.

Read guide

Keep the useful part coming

Practical AI guidance for lean teams.

Get one weekly email with important tool changes, carefully selected resources, and workflows you can actually use. No hype; unsubscribe any time.

Tools mentioned in this article

Perplexity AI

AI-powered search engine with real-time citations and research capabilities

4.4

Perplexity combines AI chat with real-time web search, delivering cited, verifiable answers. Think Google Search meets ChatGPT.

FreemiumChatbotsData Analysis

ChatGPT

The general-purpose AI assistant that started it all

4.6

OpenAI's flagship conversational AI model, powering everything from casual chat to complex reasoning, coding, and creative work.

FreemiumChatbotsWriting

Claude

Anthropic's thoughtful, safety-focused AI with exceptional long-form reasoning

4.5

Claude excels at deep analysis, long-form writing, and nuanced reasoning. Built by Anthropic with a focus on safety and helpfulness.

FreemiumChatbotsWriting