Key Point: In a significant ruling for the AI industry, the Ninth Circuit vacated a preliminary injunction against Perplexity AI, holding that Amazon was unlikely to succeed on its Computer Fraud and Abuse Act (CFAA) and California Comprehensive Data Access and Fraud Act (CDAFA) claims. The court concluded that Perplexity’s AI Assistant is a “tool, not a person” for statutory purposes, and that it is the user who “accesses” websites visited using the AI-powered Comet browser. The decision provides the first major appellate guidance on how the CFAA applies to agentic AI systems, though the court was careful to cabin its holding to the specific facts presented.
On August 4, 2026, the U.S. Court of Appeals for the Ninth Circuit issued its opinion in Amazon.com Services, LLC v. Perplexity AI, Inc., vacating the district court’s preliminary injunction that had barred Perplexity from having the AI Assistant in its Comet web browser access Amazon’s website.[1] The court held that Amazon failed to demonstrate a likelihood of success on the merits of its CFAA and CDAFA claims because Perplexity does not “access” Amazon’s computers within the meaning of either statute.
Link to I. Background I. Background
Link to a) The Statutory Framework a) The Statutory Framework
The CFAA, enacted in 1986, is the federal government’s primary anti-hacking statute. Among its provisions, the CFAA imposes criminal and civil liability on “[w]hoever . . . intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains . . . information from any protected computer.”[2] The statute defines a “protected computer” broadly to encompass any computer “used in or affecting interstate or foreign commerce or communication,” which in practice covers virtually any internet-connected device.[3]
In Van Buren v. United States, the Supreme Court clarified that the CFAA’s “exceeds authorized access” provision applies only when a person accesses a computer with authorization but then obtains information from areas of the computer to which their authorized access does not extend.[4] The Van Buren decision emphasized the importance of interpreting the CFAA in light of its original purpose — combating computer hacking — and cautioned against constructions that would “criminalize a breathtaking amount of commonplace computer activity.”[5]
The CDAFA, California’s state-law analogue, similarly prohibits unauthorized access to computer systems but defines “access” more broadly.[6] CDAFA claims are commonly asserted not only in cases involving traditional hacking allegations, but also in adtech litigations where plaintiffs allege that the placing of cookies or other marketing tracking technologies on their browsers amounts to improper access to their phone or computer.
Link to b) The Parties and Key Facts b) The Parties and Key Facts
Perplexity AI, Inc. developed the Comet browser, which includes an AI “Assistant” feature capable of navigating websites at the user’s direction. When a user instructs the Assistant to perform a task, the Assistant takes screenshots of the browser view displayed on the user’s device, sends those screenshots to Perplexity’s servers for analysis, and then receives instructions on how to navigate the website. The Assistant executes those instructions within the user’s browser session, interacting with the page much as the human user would.
A distinguishing feature of Comet is its decision not to use a unique “user-agent string.” At a high level, a “user-agent string” is a string of text included in HTTP headers that identifies who is accessing the website. It is common practice for AI-powered assistants to use a “user-agent string” which informs the website that an AI agent is being used. Comet’s decision to not use a unique “user-agent string,” therefore, precluded Amazon from knowing whether the browser accessing its website was using the AI assistant.
Link to II. Procedural History II. Procedural History
Amazon filed suit against Perplexity in November 2025 in the U.S. District Court for the Northern District of California, asserting claims under the CFAA and CDAFA and seeking a preliminary injunction. Amazon sought a preliminary injunction precluding Perplexity’s AI Assistant from accessing Amazon’s servers without authorization, which Amazon alleged was occurring in violation of its Conditions of Use.[7] In support of its motion, Amazon presented the District Court with evidence that Comet’s AI agents had navigated through Amazon’s password-protected pages, accessed users’ private account information, and transmitted that data to Perplexity’s servers to carry out user-requested tasks. Amazon similarly presented evidence that it had sent Perplexity a cease-and-desist letter revoking any authorization for AI Assistant access to its website and that Amazon employees had spent significant time developing tools to detect and block the AI Assistant’s access to its website.
Link to a) District Court’s Granting of Preliminary Injunction a) District Court’s Granting of Preliminary Injunction
In March 2026, the district court granted the preliminary injunction, concluding that Amazon was likely to succeed on the merits and that the balance of hardships tipped in Amazon’s favor.[8] As is relevant to the Ninth Circuit’s ultimate holding, the district court ruled that Amazon demonstrated a likelihood of success on both its CFAA and CDAFA claims.[9] In a short order, the district court found that “Amazon has provided strong evidence that Perplexity, through its Comet browser, accesses with the Amazon user’s permission but without authorization by Amazon, the user’s password-protected account, thereby obtaining information as to the user’s private Amazon account information, and that such information is transmitted to Perplexity’s servers for the purpose of conducting said user’s requested tasks.”[10]
Link to III. The Ninth Circuit’s Analysis III. The Ninth Circuit’s Analysis
On August 4, 2026, the Ninth Circuit reversed the district court’s granting of a preliminary injunction, holding that Amazon was unlikely to succeed on the merits of its CFAA and CDAFA claims.[11] The focus of the Ninth Circuit’s opinion was to analyze who was “accessing” Amazon, the human user directing the AI Assistant or Perplexity through the AI Assistant.
The court began its analysis by acknowledging that “Agentic AI is an emerging technology” and that there is a dearth of existing caselaw analyzing its agency.[12] The court then relied on various amicus briefs to describe the workings of Comet and the AI Assistant, and concluded that “Perplexity itself does not directly communicate with Amazon’s servers.”[13] The court found, however, that Perplexity’s lack of direct communication was not dispositive and that the court “must nevertheless determine whether Perplexity accesses Amazon.com through the Assistant” because “[t]he CFAA’s plain language suggests the Assistant itself cannot ‘access’ Amazon’s servers.”[14]
The Ninth Circuit concluded that “it is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com,” not the AI Assistant itself.[15] Focusing on the functionality of the AI Assistant, the court held that Perplexity’s receipt of screenshots from the user’s browser and provision of instructions to the AI Assistant based on those screenshots and instructions from the user were insufficient to show Perplexity was accessing Amazon’s servers.
Notably, the court was clear that Perplexity’s control over the AI Assistant was an essential consideration, and that “on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon’s servers.”[16] The court also went to great lengths to establish the narrow nature of its holding, reiterating its appreciation for the evolving nature of agentic AI and expressly stating it was not “establishing a new legal regime governing agentic AI” and was not addressing whether Perplexity could be liable “in other contexts, including tort claims” for the AI Assistant’s actions.[17]
Link to IV. Practical Takeaways IV. Practical Takeaways
The Ninth Circuit’s decision is the first federal appellate opinion to squarely address liability for actions taken by agentic AI systems, and it carries important implications for AI developers and website operators alike.
For AI companies: The decision provides meaningful support for the position that it is the human user directing an AI agent, and not the developer of the AI agent, who is liable for actions taken by the AI agent. That said, the Ninth Circuit was clear that the control over the agent is an essential element to be considered in this context and strongly suggested that there is some level at which the developer of the agent can become liable.
For website operators: The opinion does not leave website operators without recourse. The court made clear that its holding is limited to CFAA and CDAFA claims and does not preclude other theories of liability, including breach of contract, unfair competition, tortious interference, or state consumer protection claims. Operators should review and strengthen their terms of service to clearly address AI-assisted browsing, and should consider technical measures — such as requiring user-agent identification, implementing CAPTCHAs, or deploying behavioral analysis tools — to detect and manage automated interactions.
The Ninth Circuit was undisputedly correct that the use of agentic AI is constantly evolving and that there is a lack of caselaw addressing it. Only time will tell how other courts will address the questions of agency and liability that will necessarily follow from the proliferation of agentic AI.
[1] Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026).
[2] 18 U.S.C. § 1030(a)(2).
[3] 18 U.S.C. § 1030(e)(2) (defining “protected computer” as a computer “used in or affecting interstate or foreign commerce or communication”).
[4] Van Buren v. United States, 593 U.S. 374, 389 (2021).
[5] Id. at 393.
[6] Cal. Penal Code § 502.
[7] Amazon.com Services LLC v. Perplexity AI, Inc., No. 3:25-cv-9514 (N.D. Cal.).
[8] Amazon.com Services, LLC v. Perplexity AI, Inc., No. 25-cv-8431 (N.D. Cal. Mar. 12, 2026) (granting preliminary injunction).
[9] Amazon.com Services, LLC v. Perplexity AI, Inc., No. 25-cv-09514, 2026 U.S. Dist. LEXIS 48445, at *4 (N.D. Cal. Mar. 9, 2026).
[10] Id. at *4 (internal citations omitted).
[11] Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026).
[12] Id. at 12.
[13] Id. at 14.
[14] Id. at 14-15.
[15] Id. at 15.
[16] Id.
[17] Id. at 17.
