On August 4, 2026, the U.S. Court of Appeals for the Ninth Circuit issued a groundbreaking decision in Amazon.com Services, LLC v. Perplexity AI, addressing the legal status of so-called “agentic AI” tools, which help users expedite various online tasks, including buying goods and services. The Ninth Circuit vacated a preliminary injunction that had barred the AI company Perplexity from enabling users of its Comet Browser’s AI assistant feature to access the Amazon Store. In so doing, it became the first circuit to weigh in on the intersection between agentic AI and federal laws—specifically the Computer Fraud and Abuse Act (CFAA), which prohibits unauthorized access to protected computer systems.
The Ninth Circuit held that Perplexity (through its AI agent) does not “access” Amazon’s computer system or website, as that term is understood under the CFAA or its California analogue, the California Comprehensive Computer Data Access and Fraud Act (CDAFA). Therefore, Amazon was not likely to succeed on its claims against Perplexity under either statute, even if end users access Amazon.com through Perplexity’s Comet Browser. The court also emphasized that the CFAA is principally an anti-hacking criminal statute and courts should exercise caution before expanding liability under it to new technologies and contexts.
While the result is significant for both AI companies and websites that may be accessed by users of AI agents, it should not be overread to protect agentic AI writ large or immunize AI providers from other theories of liability, including contract, tort claims, and IP claims. Indeed, the court’s decision turned on the mechanism by which the specific AI tool operated, particularly the details of the interaction between the end user, the AI agent, and the third-party website. An important lesson from the opinion is that operators of agentic AI technologies should avoid direct connections between their own computer systems and the third-party websites or systems that their tools are used to “access.” Beyond that, the details of how any given AI tool actually operates and is used will be essential in determining the risk of liability.
Background
Perplexity’s Comet Browser, like most popular web browsers, “run[s] locally on a user’s machine and enabl[es] the user to navigate the internet.”1 In addition to standard browser features, Comet has an optional AI “agent” (called an Assistant) that can perform tasks at the user’s direction, such as browsing websites like Amazon.com to shop for goods. “When a Comet user directs the Assistant to locate an item on Amazon.com, the Assistant takes screenshots of the browser view, sends those screenshots from the user’s computer to Perplexity’s servers, and receives instructions from Perplexity’s servers on how to navigate Amazon.com.”
Amazon attempted to prevent the Comet Assistant from accessing the Amazon Store, including through technological blocks and by sending a cease-and-desist letter to Perplexity. After these attempts failed to prevent Comet from accessing the Amazon Store, Amazon sued and sought a preliminary injunction under Section 1030(a)(2) of the CFAA and Section 502(c)(7) of the CDAFA. Judge Maxine Chesney of the U.S. District Court for the Northern District of California granted the preliminary injunction, finding that while it was a close question, Amazon was likely to succeed on both grounds and the other considerations (irreparable harm and public interest). Perplexity appealed.
The Ninth Circuit’s Decision: Amazon.com Services, LLC v. Perplexity AI
To succeed on its CFAA claim, Amazon had to show that Perplexity intentionally accessed Amazon’s servers without authorization or exceeded authorized access, and that it then obtained information from a protected computer causing at least $5,000 in damages. Perplexity argued that it had not “gained entry” to Amazon’s computer systems because no Perplexity computer ever accessed Amazon’s servers. Perplexity also argued that any “intent” to access Amazon’s password-protected areas (such as the checkout page) should be ascribed to the user, because any action taken by the Assistant was performed at the user’s direction. Amazon disagreed, arguing that Perplexity’s servers are not passive actors when they direct the Assistant to perform the tasks in Amazon’s protected spaces.
The Ninth Circuit first considered “whether Perplexity itself . . . directly communicate[s] with Amazon’s servers.” Finding that it did not, the court broke down the system as follows:
“What is clear from this description” is that “Perplexity itself does not directly communicate with Amazon’s servers.”
Next, the court asked whether Perplexity “uses a tool (the Assistant) to ‘access’ Amazon’s computers.” The panel rejected this idea too, finding instead that “[i]t is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com.” While Perplexity “may receive screenshots of the user’s browser” and instruct the Assistant, those activities “by themselves, do not mean that Perplexity has ‘accessed’ (gained entry) to Amazon’s servers.” Nor could the Assistant itself “access” the servers as a substitute for Perplexity, because “the CFAA contemplates access by a person,” not a tool, regardless of “[h]owever advanced it is.”
To reinforce its holdings, the court leveraged the rule of lenity and policy considerations. Because the CFAA is “equally applicable in the civil and criminal contexts,” any ambiguities in the statute cut “against liability.” Particularly where, as here, finding in favor of Amazon “could expose users themselves to criminal liability . . . for facilitating Perplexity’s purported unauthorized access to Amazon’s servers.” Moreover, imposing statutory liability on Perplexity “would require a novel interpretation far afield from the statute’s purpose ‘to prevent intentional intrusion onto someone else’s computer—specifically, computer hacking.’”
As to the CDAFA claim, the court found that “Amazon’s CFAA and CDAFA claims rise and fall together.” Even though “access” under the CDAFA “is broader” than under the CFAA, “the focus of the inquiry is still on the person accessing or causing the access.” Thus, the fact that the user and not Perplexity accesses Amazon through the Assistant is equally dispositive of the CDAFA claim.
The court concluded by stressing the limits of its ruling. “We do not establish a new legal regime governing agentic AI” or address whether Perplexity can avoid liability in other contexts, “including tort claims.” The holding here is strictly “limited to ‘access’ as contemplated by the CFAA and as applied to the Assistant’s interactions with Amazon.com.”
Key Takeaways
Wilson Sonsini routinely helps companies navigate complex issues pertaining to the CFAA, AI, and emerging technologies. For more information or advice concerning AI litigation, development, or practices, please contact Brian Willen from Wilson Sonsini’s Internet Strategy and Litigation Group or Demian Ahn from the Data, Privacy, and Cybersecurity practice.
Brian Willen, Demian Ahn, and Edward Percarpio contributed to the preparation of this alert.
[1] Descriptions of the Comet Browser and AI Assistant are drawn from the court’s opinion.