Perplexity Beats Amazon: Ninth Circuit Comet Ruling
The Ninth Circuit vacated Amazon's injunction against Perplexity's Comet shopping agent, ruling users — not the developer — access servers under the CFAA.
A federal appeals court has handed the AI industry its clearest legal win yet on the question of whether autonomous agents can act on a user’s behalf across the open web. On Tuesday, August 4, 2026, a three-judge panel of the U.S. Court of Appeals for the Ninth Circuit vacated a preliminary injunction that had barred Perplexity’s Comet shopping agent from operating on Amazon.com, ruling that it is the human user — not Perplexity — who “accesses” Amazon’s servers under the federal Computer Fraud and Abuse Act (CFAA).
The opinion, written by Circuit Judge Milan D. Smith, Jr., sends the case back to the district court but removes the block that had shut Comet out of Amazon since the spring. For a class of products that is defined by software acting on a person’s instructions, it is a foundational ruling: courts are beginning to decide how decades-old computer-crime law maps onto agents that click, browse, and buy on their own.
What the court decided
The panel’s central holding is narrow in form and broad in consequence. The CFAA imposes liability on whoever “accesses a computer without authorization or exceeds authorized access.” Amazon argued that Perplexity’s agentic Assistant, which powers the Comet browser, was doing the accessing when it logged into shopper accounts and placed orders against Amazon’s wishes. The court disagreed.
“Perplexity does not ‘access’ Amazon’s servers. Users do,” the panel reasoned. Even where Perplexity received account information from users and used it to instruct the Assistant, the court found that fell short of the level of control required to pin the access on the developer rather than the person operating the tool. In the court’s framing, an AI agent that a user directs is closer to a web browser or a script the user runs than to an independent intruder.
Crucially, the panel acknowledged it was writing on a near-blank slate. There is “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context,” the opinion noted. Faced with that ambiguity in a statute that carries criminal penalties, the court invoked the rule of lenity — the principle that ambiguous penal laws are construed against liability — and declined to read the CFAA as reaching Perplexity’s conduct.
The result: the preliminary injunction is vacated, and the case is remanded for further proceedings. This is not a final judgment on the merits, and Amazon’s separate trademark and state-law claims survive to be litigated on remand. But the practical effect is immediate. The tool that a district court shut down in March is, for now, allowed to run.
How the dispute got here
The fight began in November 2025, when Amazon sued Perplexity over Comet’s ability to shop on its marketplace on behalf of users. Amazon’s position was that its terms of service prohibit automated agents from placing orders, that Comet operated in defiance of technical and contractual barriers, and that letting third-party agents transact on the platform degrades the experience Amazon controls end to end — from search ranking to checkout.
In March 2026, a district court agreed enough to grant a preliminary injunction, effectively pulling Comet’s Amazon integration offline while the case proceeded. Perplexity appealed, and the dispute became a proxy for a much larger question the whole sector has been circling: when an AI agent takes actions on a website, who is legally responsible — the person who asked for the outcome, or the company that built the software?
That question is not academic. The current generation of consumer agents is built to do exactly what Comet does: take a natural-language goal, plan a sequence of steps, and execute them against live websites. The reason-and-act loop that underpins these systems means the software is constantly deciding which page to load and which button to click next. If every one of those loads counts as the developer accessing a server without authorization, the legal exposure for building agents that touch the open web becomes enormous.
The web-scraping lineage
The ruling did not appear from nowhere. It sits in a line of Ninth Circuit decisions that have steadily narrowed how far the CFAA reaches onto the public internet, most notably hiQ Labs v. LinkedIn, the 2022 case that found publicly accessible data could be scraped without violating the statute. The through-line is a reluctance to turn a violation of a website’s terms of service into a federal computer crime.
The Electronic Frontier Foundation, which filed an amicus brief supporting Perplexity, framed the stakes in exactly those terms. “Developers like Perplexity facilitate that access by creating tools that enable users to meaningfully engage with the web,” the EFF told the court, arguing that the CFAA’s “access” requirement points at the user, not the toolmaker. The panel’s opinion tracks that logic closely — building a browser, or an agent that acts like one, is not the same as breaking into a computer.
That distinction matters well beyond shopping. The same reasoning that protects a browser protects the crawlers behind search, the assistants that read pages for you, and the agents that increasingly sit between users and the sites they visit. It also intersects with the economics of a web where machines, not humans, are the visitors — a shift platforms have been fighting on multiple fronts, from AI summaries that keep users off the source page to agents that transact without ever rendering the seller’s storefront.
What Amazon still has
Reading this as a total defeat for Amazon would overstate it. The panel decided a specific question — whether Amazon was likely to succeed on its CFAA claim strongly enough to justify a preliminary injunction — and answered no. It did not rule that Perplexity is free of all liability, and it explicitly preserved Amazon’s other theories.
Amazon’s trademark and state-law claims remain live on remand, and those may prove a more durable line of attack. A platform that cannot use the CFAA to keep agents out can still argue that an agent misrepresents its identity, misuses branding, or breaches contract. Expect the next phase of this litigation, and others like it, to migrate away from computer-crime statutes and toward trademark, breach of contract, and unfair-competition claims where the “who accessed the server” question is less decisive.
There is also the technical arms race that runs parallel to the legal one. Nothing in the ruling requires Amazon to welcome agents; it only bars one particular legal weapon against them. Platforms that want to keep automated shoppers out can still invest in detection, rate limiting, and access controls — though agents built to behave like ordinary users, driving a real browser session, are precisely the hardest kind to fingerprint. And the same channels that let a helpful agent act for a user can let a malicious instruction ride in from a web page, the prompt-injection risk that makes agent security genuinely hard regardless of who wins in court.
What it means
For AI agent developers, this is the most encouraging signal the U.S. courts have sent so far. The Ninth Circuit — whose CFAA rulings carry outsized weight because so many large platforms are headquartered in its territory — has said, in a published and precedential opinion, that building a tool a user directs is not the same as accessing a server yourself. That is close to the load-bearing assumption of the entire consumer-agent business, and it just survived its first serious test on appeal.
Who wins: Perplexity most directly, but the benefit extends to every company shipping agents that act on the live web — OpenAI, Google, Anthropic, and the long tail of startups building browsers and assistants that shop, book, and file on a user’s behalf. The rule-of-lenity framing is especially valuable because it treats the criminal ambiguity of the CFAA as a reason to hold back, giving developers a principled shield rather than a fact-specific one.
Who loses, or at least doesn’t win: platforms that hoped to use federal computer-crime law as a clean off-switch for unwanted agents. Amazon’s marketplace is the archetype — a tightly controlled funnel from search to checkout that agents route around — and it now has to fight that battle on messier ground. Retail, travel, ticketing, and any business whose moat is control of its own front door faces the same reckoning.
What to watch next. First, the remand: Amazon’s trademark and contract claims are where the real fight moves, and an early ruling there will show whether those theories can do what the CFAA could not. Second, whether other circuits follow the Ninth’s lead or split from it — a circuit split is the fastest route to the Supreme Court, and this is exactly the kind of unsettled, high-stakes question that draws review. Third, the platform response: watch for updated terms of service that target agents by contract, new technical barriers, and possibly a push for legislation that speaks to agents directly rather than leaving it to a 1980s hacking statute. The law is starting to catch up to agents that act on their own — and for now, it is bending toward letting them.
Tagged
Keep reading
Chisato · · 4 min read What Is Context Engineering? Beyond Prompt Design
Context engineering is the discipline of deciding what an LLM sees at inference time — retrieved documents, tool outputs, memory, and history.
Chisato · · 6 min read Open Secure AI Alliance: Nvidia Rallies 37 Firms
Nvidia and 36 partners launched the Open Secure AI Alliance and open-sourced the NOOA agent framework, days after an autonomous AI attack on Hugging Face.
Chisato · · 6 min read OpenAI Presence: Enterprise AI Agent Platform Explained
OpenAI launched Presence, a managed platform for deploying voice and chat AI agents with guardrails, simulations, and a Codex-powered improvement loop.