What The Ninth Circuit Actually Decided On 4 August
The case began on 9 March 2026, when a district court granted Amazon a preliminary injunction stopping Perplexity's Comet, an agentic web browser, from using its automation to navigate password-protected parts of Amazon's site on a user's behalf. Amazon argued the tool was violating the federal Computer Fraud and Abuse Act (CFAA) and its California state-law equivalent by accessing Amazon's systems without authorization. Perplexity appealed, the Ninth Circuit stayed the injunction pending the outcome, and on 4 August a three-judge panel ruled: Amazon is unlikely to succeed on the CFAA claim, because the statute punishes unauthorized access by a person, and here it is the user, logged into their own Amazon account, who is doing the accessing. The court described Perplexity's software as a tool the user directs, not an independent legal actor.
The Electronic Frontier Foundation, which filed an amicus brief backing Perplexity, framed the stakes plainly: accepting Amazon's theory would mean the browser you use, the extension you install, or the assistant you delegate a task to could itself commit a federal crime every time it fetches a page on your behalf, exposing you, the user, to liability by extension. The panel did not have to accept that framing to rule for Perplexity, but its holding, that software is a tool and not a person for CFAA purposes, forecloses the version of that argument that treats an agent's actions as a discrete unauthorized access separate from the user who launched it.
Why The Ruling Is Narrower Than The Headline Suggests
Vacating a preliminary injunction is not a final judgment. The Ninth Circuit only decided Amazon was unlikely to win on the merits of its CFAA claim, which is the standard needed to justify blocking Perplexity before trial; it did not dismiss the case, and it left the door open for Amazon to develop other theories at the district court, most obviously a breach-of-contract claim under Amazon's own Conditions of Use, which every account holder has already agreed to and which does not require proving unauthorized computer access at all, only that the terms were broken.
That distinction is the actual lesson. A computer-misuse statute is written to punish intrusion, and courts are visibly reluctant to stretch that language to cover software a legitimate, logged-in user chose to run. A contract, by contrast, can say whatever the platform wants it to say, including an explicit ban on automated agents, and a court does not need to reinterpret a criminal-hacking law to enforce it. Any platform that wants to keep AI agents out is now watching two different legal tools produce two very different outcomes.
The Question Every European Site Operator Should Ask Now
The CFAA is a US statute, but the underlying question is not American: does a computer-misuse law, written before agentic software existed, treat an AI tool acting on a user's instruction as a form of unauthorized access? The UK's Computer Misuse Act 1990 and various EU member states' own cybercrime statutes use similarly broad, human-intrusion-era language, and none of them have yet been tested against an agentic browser the way the Ninth Circuit just tested the CFAA. A European operator cannot assume a local court would read its own statute the way a US judge just declined to.
The practical move is not to wait for that test case. Review the terms of service on any site that handles logins, purchases, or account data, and add explicit language on automated and AI-agent access now, because that clause, not the hope that a computer-crime law will do the work, is what determined the outcome of this case once the criminal-statute argument failed. A platform's real defense against an unwanted agent is the contract it wrote, not the hacking law it hoped would apply.
Read next: The Model Changed but the API Name Did Not | The Agent Paying Your Invoices Is Not Software



