GuideUpdated 2026-08-06

AI Agents Can Shop Amazon Again: What the Ninth Circuit's Perplexity Ruling Actually Decided

On August 4, 2026, a federal appeals court vacated the injunction that had barred Perplexity's Comet shopping assistant from Amazon — holding that when a user directs an AI agent, it is the user, not the AI company, who 'accesses' the website under the federal anti-hacking statute. The ruling is narrow, explicitly provisional, and enormously consequential for agentic commerce.

Bottom line

The Ninth Circuit vacated Amazon's preliminary injunction against Perplexity's Comet browser, ruling Amazon is unlikely to prove Perplexity 'accessed' its servers under the Computer Fraud and Abuse Act because users — not Perplexity — operate the agent. This research-based explainer covers what the court held, what it deliberately left open, why the rule of lenity mattered, which of Amazon's claims survive, and what the decision means for anyone building or using AI shopping agents.

Editorial accountability

Who checked this guide

Meet the editorial team →
Evaluation type
Research-based verification
Last materially checked
Evidence
5 listed sources

Hands-on testing is identified explicitly. Research-based coverage uses cited product documentation and other named sources; it does not imply every paid plan was used. Read the full methodology.

Editorial basis

What this guidance is based on

Editorial basis
Source-led analysis
Primary references
5
Products covered
3
Last checked
2026-08-06

Important limits

  • Features, availability, and pricing can change after publication; confirm consequential details with the provider.
In this guide
  1. The short answer
  2. How the case got here
  3. What the Ninth Circuit held
  4. What the ruling does *not* decide
  5. Why this matters for agentic commerce
  6. Questions worth asking before you build on this ruling

*This is a research-based legal news analysis built from the Ninth Circuit's published opinion and analysis by law firms and reporters covering the case. It is general information, not legal advice — consult counsel before making decisions that depend on this ruling.*

The short answer

On August 4, 2026, the US Court of Appeals for the Ninth Circuit vacated the preliminary injunction that had barred Perplexity's Comet browser assistant from shopping on Amazon since March 2026. The panel, in an opinion authored by Judge Milan D. Smith, Jr., held that Amazon is unlikely to succeed on its Computer Fraud and Abuse Act (CFAA) claim because Comet's agentic "Assistant" is a tool operated by users — meaning it is the users, who hold legitimate Amazon accounts, who "access" Amazon's servers, not Perplexity.

Three qualifiers keep the ruling in proportion:

  1. It is a preliminary-injunction ruling, not a final judgment. The court decided Amazon is *unlikely to succeed* on the CFAA theory — the underlying lawsuit continues.
  2. The holding is expressly narrow. The panel noted there is "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents" under the CFAA, and said agentic AI law "will doubtless change."
  3. Amazon's other claims survive. The trademark and state-law claims were not resolved by this decision, and website operators retain contractual and technical means of managing automated traffic.

How the case got here

Amazon sued Perplexity in November 2025, alleging that Comet's AI Assistant accessed password-protected Amazon pages without Amazon's authorization — violating the CFAA and California's parallel statute (CDAFA). In March 2026, the district court agreed and enjoined Comet from Amazon: it reasoned that Amazon had not authorized Perplexity's access, regardless of whether Amazon customers had authorized the Assistant to act on their own accounts.

That framing — the platform's permission versus the user's permission — is the entire case. If a website's non-authorization of the *tool vendor* controls, then every AI agent needs permission from every site it visits. If the *user's* authorization controls, then an agent acting on a logged-in user's instructions stands in the user's shoes.

What the Ninth Circuit held

The panel sided with the user-authorization framing at this stage, on three grounds reported consistently across legal analyses:

  • Operation, not creation, is what counts. Perplexity built the tool, but users invoke it, direct it, and authenticate with their own credentials. On that record, the "access" is the user's.
  • The rule of lenity. The CFAA is a criminal statute applied civilly. Where its text is ambiguous — and attributing agent conduct is genuinely ambiguous — courts construe the ambiguity against liability. The Electronic Frontier Foundation, which filed in support of neither party, argued that building a browser cannot itself be a CFAA violation; the panel's reasoning tracks that concern.
  • Judicial modesty about a moving target. The panel repeatedly flagged that agentic AI is new, the record is thin, and Congress — not a preliminary-injunction appeal — is the right forum for a comprehensive rule.

What the ruling does *not* decide

  • It does not hold that AI companies can never be liable under the CFAA. A tool that acts autonomously, without user direction, or that circumvents technical barriers could be analyzed differently.
  • It does not give agents a right to ignore a website's terms of service. Contract claims, trademark claims, and unfair-competition claims proceed on their own tracks.
  • It does not prevent Amazon from technically blocking or rate-limiting agent traffic. The decision addresses criminal-statute liability, not network engineering.
  • It does not bind courts outside the Ninth Circuit, though it is the first appellate word on the question and will be widely cited.

Why this matters for agentic commerce

The practical stakes are larger than one shopping assistant:

For AI companies, the decision removes — for now, in one circuit — the most severe legal theory against user-directed agents: felony-statute liability for merely visiting sites the vendor lacks permission to visit. Expect agent vendors to lean into the "user-operated tool" architecture the court credited: user credentials, user initiation, user-visible actions.

For website operators, the decision signals that the CFAA is the wrong tool for managing unwanted agent traffic. The durable levers are contractual terms, technical controls (bot management, agent-identification protocols), and business deals — several large retailers have chosen partnership over litigation, striking agentic-checkout agreements with AI providers rather than suing them.

For users, agents that shop, book, and compare on your behalf just became meaningfully harder to ban outright. The open question is whether platforms respond with cooperation (sanctioned agent APIs) or friction (aggressive bot detection that degrades the experience).

For everyone, the panel's candor is the headline: there is essentially no settled law on responsibility for AI agents' actions, and this ruling is a first draft. Businesses building on agentic access should assume the rules will keep moving.

Questions worth asking before you build on this ruling

  1. Does your agent act only on explicit user direction, with the user's own credentials? That is the architecture the court credited.
  2. Do you have a fallback if target platforms deploy technical blocks? A legal right to exist is not an engineering guarantee of access.
  3. Are your terms and disclosures honest about the agent's identity? Trademark and misrepresentation theories survived this ruling.
  4. Are you monitoring the remand and parallel cases? A preliminary ruling can be narrowed, distinguished, or superseded.

Sources and verification

Product details and claims were checked against the following primary sources.

Frequently asked questions

Did Perplexity win the lawsuit against Amazon?

Not the whole lawsuit — it won the appeal of the preliminary injunction. The Ninth Circuit vacated the order that had barred Comet from Amazon, finding Amazon unlikely to succeed on its Computer Fraud and Abuse Act claim. The underlying case continues, and Amazon's trademark and state-law claims were not resolved by this decision.

Does this ruling mean any AI agent can access any website legally?

No. The holding is narrow: on this record, a user-directed agent authenticating with the user's own credentials meant the user — not Perplexity — 'accessed' Amazon under the CFAA. Agents that act autonomously, circumvent technical barriers, or misrepresent themselves could be analyzed differently, and websites retain contractual and technical means of restricting automated traffic. The court itself said agentic AI law 'will doubtless change.'

What is the rule of lenity and why did it matter here?

The rule of lenity is the principle that ambiguous criminal statutes are construed against liability. Because the CFAA is a criminal statute (also enforceable civilly) and there is almost no caselaw on attributing an AI agent's actions, the panel resolved the ambiguity about who 'accesses' a server in favor of the narrower reading. It was a key reason the court declined to treat Perplexity as the accessing party.

Can Amazon still block AI shopping agents technically?

Yes. The ruling addresses liability under an anti-hacking statute, not network engineering. Amazon and other retailers can still deploy bot detection, rate limiting, and agent-identification requirements, and can pursue contract and trademark theories. The strategic question for platforms is whether to fight agent traffic with friction or channel it through sanctioned partnerships and agent-checkout APIs.

Found this useful?

Get the next one in your inbox.

One five-minute briefing a week: a meaningful change, a practical workflow, and a clearer tool decision—already filtered for lean teams.

Free · one email a week · unsubscribe any time

Tools mentioned in this article

Perplexity AI

AI-powered search engine with real-time citations and research capabilities

4.4

Perplexity combines AI chat with real-time web search, delivering cited, verifiable answers. Think Google Search meets ChatGPT.

FreemiumChatbotsData Analysis

ChatGPT

The general-purpose AI assistant that started it all

4.6

OpenAI's flagship conversational AI model, powering everything from casual chat to complex reasoning, coding, and creative work.

FreemiumChatbotsWriting

Claude

Anthropic's thoughtful, safety-focused AI with exceptional long-form reasoning

4.5

Claude excels at deep analysis, long-form writing, and nuanced reasoning. Built by Anthropic with a focus on safety and helpfulness.

FreemiumChatbotsWriting

Read next

More on Build, Design & Govern