AIR-2026-010 · AI Agent Incident Register
Amazon v Perplexity: the Ninth Circuit says the user, not the AI agent, 'accesses' a website under the CFAA
Incident: 2026-08-04 · Parties: Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026); D.C. No. 3:25-cv-09514-MMC (N.D. Cal.)
Liability locus: Deployer-carried. the organisation that deployed the agent answers for its output.
Legal analysis by Michael K. Onyekwere, CIPP/E · Janus Compliance · Published 2026-08-26 · Last reviewed 2026-08-26. Analysis of public facts. Not legal advice.
What happened
On 4 August 2026 the United States Court of Appeals for the Ninth Circuit vacated a preliminary injunction that Amazon had won against Perplexity, and sent the case back to the district court. Judge Milan D. Smith, Jr. wrote for the panel, sitting with Judge Eric C. Tung and District Judge John C. Hinderaker. The injunction had barred Perplexity's agentic browser tool, the Comet "Assistant", from carrying out tasks on Amazon.com at a user's request.
Perplexity built Comet, an AI-enabled web browser, and released it in 2025. A user can tell the Comet Assistant to do something on a website, shopping on Amazon among the examples. Amazon filed suit in November 2025, alleging that the Assistant accessed customers' password-protected accounts in violation of the federal Computer Fraud and Abuse Act (CFAA) and its California analogue, the Comprehensive Computer Data Access and Fraud Act (CDAFA). In March 2026 the district court (Judge Maxine M. Chesney, Northern District of California) granted Amazon a preliminary injunction, on the ground that Amazon had shown a likelihood of success on its CFAA claims under 18 U.S.C. § 1030(a)(2) and its CDAFA claims, together with irreparable harm and the equities in its favour.
The Ninth Circuit read the statute the other way. It held Amazon unlikely to succeed on the merits, because Perplexity did not "access" Amazon's computers for CFAA purposes. In the court's words, "It is the user who 'accesses' Amazon's computers, with the help of the Assistant to carry out specific acts on Amazon.com." One door stays open: in a footnote the court noted that its ruling "does not impair Amazon's ability to regulate access to Amazon.com via private terms of service for its users."
The panel decided the injunction, not the case, and its decision is not yet the last word. On 18 August 2026 Amazon petitioned the Ninth Circuit for rehearing en banc. If that petition fails, the merits return to the district court. If it succeeds, the full court could revisit the panel's reading of the CFAA. This entry states the position as at its review date and will be updated by dated addendum if the posture changes.
The duty engaged
This is computer-crime and unfair-competition law, not data protection. That is what makes it worth reading here: it fixes, at the appellate level, who the law treats as the actor when an AI agent does the clicking.
Who counts as the "accessor". A CFAA claim requires that the defendant intentionally accessed a computer, without authorisation or exceeding authorised access, and thereby obtained information from a protected computer, with loss of at least $5,000 in a year. The Ninth Circuit read "access" as something a person does. "However advanced the Assistant currently is," the court held, "it is a tool, not a person for statutory purposes", citing the statutory definition of "whoever" at 18 U.S.C. § 921(a)(1). The agent therefore cannot be the accessor. The user who directs it is.
Why the court was cautious. The CFAA is an anti-hacking statute. The panel repeated the circuit's settled reading that Congress aimed "to prevent intentional intrusion onto someone else's computer, specifically, computer hacking" (hiQ Labs v LinkedIn). A court asked to treat an AI shopping agent as a hacker under a criminal statute will look for the human intruder before it looks at the software.
What it does not decide. This is a preliminary-injunction ruling. The merits return to the district court, and the authorisation question, whether a user's agent-driven access exceeds what Amazon's terms permit, is unresolved. The court was explicit that Amazon can still police that access through its terms of service. The CFAA route narrowed. The contract route did not.
The liability chain
The ruling is a clean allocation of where CFAA exposure falls when an agent acts on a third-party system.
Not the AI vendor, on these facts. Amazon's theory was that because the Assistant "proceeds autonomously" and "behaves like an efficient human shopper", its autonomous action should be ascribed to Perplexity. The court declined to take that step. Autonomy does not turn the tool into the statutory accessor, so the developer of the agent does not "access" the sites its users point it at.
The user carries it. If anyone accessed Amazon's computers without authorisation, it was the user who set the Assistant its task. That is the person the CFAA is asking about. For an organisation that deploys an agent against a system it does not own, the access, and the exposure that travels with it, is the deployer's, not the tool-maker's.
The mirror image of the vendor-liability entries. In the security-breach cases the gravity of liability runs upstream to the provider. Here it runs the other way. When the question is who "accessed" a site, the answer the Ninth Circuit gives is the human who deployed the agent, and the vendor is a bystander to that particular claim. This is the CFAA counterpart to Moffatt (AIR-2026-003) and Ayinde (AIR-2026-005): the principal answers for what the agent produces, and now, the user answers for what the agent accesses.
What would have prevented it
The lesson here is for the businesses now pointing agents at systems they do not own, because the ruling maps their exposure rather than removing it.
- Read the target site's terms before you send an agent to it. The CFAA claim narrowed, but the court preserved Amazon's right to regulate access through its terms of service. A site's terms can still make agent-driven access "unauthorised" as a contract matter, and can carry their own remedies.
- Treat the agent's access as your access. The exposure for what an agent does on a third-party system falls on the organisation that deployed it, not on the vendor that built it. Procurement, policy and contracts should be written from that fact.
- Do not lean on "the agent acted autonomously". Amazon ran the autonomy argument in reverse, to pin the conduct on the vendor, and lost. The mirror holds for deployers: a business cannot disclaim its own agent's actions as the tool's doing.
- Where an agent touches logged-in accounts, get and record clean authorisation. The dispute began over an agent operating inside customers' password-protected accounts. Whose authority the agent acts under, and how that is evidenced, is the fact everything else turns on.
Mapped controls
- OWASP Top 10 for Agentic Applications 2026: no ASI category is a squarely fitting map. The ASI taxonomy classifies agent security failure modes. This is a legal ruling on statutory interpretation, not an exploit, so no
owasp_asiis asserted for this entry. - NIST AI RMF: a GOVERN and MAP matter for the deploying organisation. GOVERN: a policy on where the organisation's agents may act, against which systems, and under whose authorisation. MAP: recognising that an agent's actions against third-party systems carry the deployer's own legal exposure, contractual and statutory, and mapping that risk before deployment rather than after a cease-and-desist.
- Jurisdiction note. This is a US federal ruling on the CFAA. It does not translate directly to the UK or EU. The UK Computer Misuse Act 1990 frames "unauthorised access" differently, and a UK court would ask a related but distinct question about who secured access and with whose authority. Treat the principle, the human who directs the agent is the actor the access statute asks about, as persuasive rather than binding outside the United States.
- The general rule the case stands for: an AI agent is a tool, not a legal person, so the law looks through it to the human who deployed it. That is the same spine the register has drawn from Moffatt and Ayinde, now applied to access rather than output.
Sources
- Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026), Opinion by Judge Milan D. Smith, Jr. Full published opinion read in full, every quotation verified against the opinion text. [primary]. Opinion PDF via Courthouse News (a mirror of the court filing). The case also appears on Justia and the CourtListener docket (D.C. No. 3:25-cv-09514).
- Wilson Sonsini, "Ninth Circuit Addresses CFAA and Agentic AI Tools in Groundbreaking Decision" - corroborating analysis, checked 26 Aug 2026
- Cooley, "Ninth Circuit Rules on AI Agent 'Access' to Third-Party Websites Under CFAA" - corroborating analysis, checked 26 Aug 2026
- Troutman Pepper Locke, "Ninth Circuit Holds Human User, Not Developer of AI Agent, Responsible for Websites Accessed" - corroborating analysis, checked 26 Aug 2026
- Eric Goldman, Technology & Marketing Law Blog, "Ninth Circuit Lifts Restrictions on Agentic AI Accessing Amazon" - corroborating analysis, checked 26 Aug 2026
- Amazon's petition for rehearing en banc (filed 18 Aug 2026) reported by FindLaw, "Legal Fight Between Amazon and Perplexity Could Shape AI Agent Shoppers" and tracked on the CourtListener docket - checked 26 Aug 2026
Cite this entry as AIR-2026-010 (https://companyscope.io/register/air-2026-010). Entry IDs are stable; corrections publish as dated addenda on this page.
Talk to Michael about your agent deployment — or your AI vendor governance more broadly
CompanyScope's public profiles cover the general picture. Michael runs Janus DPO-as-a-Service for businesses that need ongoing AI vendor governance, and writes one-off CIPP/E-reviewed Vendor Risk Notes for specific procurement decisions. Tell him what you're actually trying to clear.
Your context goes only to Michael. We don't share with the vendor or anyone else. Privacy notice.
Subscribe to the AI Agent Incident Register
Every new Register entry delivered with the legal analysis: the incident, the duty engaged, who is liable across the chain, and what governance would have prevented it. Written by Michael K. Onyekwere, CIPP/E. Free.
Subscribe — freeDelivered via Compliance Engineering on Substack, which handles your subscription and consent. Unsubscribe any time. Privacy notice.
This analysis is the work Janus Compliance does for clients before the incident. For a fixed-scope read of your own EU AI Act Article 50 exposure, see the Article 50 teardown; for ongoing agent governance, Janus DPO-as-a-Service. New entries are delivered free through Compliance Engineering on Substack. Browse the full register or the vendor compliance index.