On the Computer Fraud and Abuse Act, who 'accesses' a website when an AI is driving, and what the Ninth Circuit left conspicuously unanswered
The court ruled your AI shopping agent isn't the burglar. You are. (You're also off the hook.)
Anti-AI
00
Skeptic
01
Neutral
00
Pro (practical)
02
Pro (hyped)
00
← Anti-AI · Pro-AI →
If you've ever handed an AI assistant your login credentials and told it to handle something — order that thing, book that flight, check that account — a federal appeals court just answered a question you probably didn't know was live.
The Ninth Circuit ruled on August 4 that when an AI browser acts on your behalf, you are the one legally doing the browsing. Not the company that made the AI. Under federal law, specifically the 1986 Computer Fraud and Abuse Act, which was written to stop hackers and not AI shopping tools, that distinction matters a lot.
Perplexity's Comet is an AI browser. It can open tabs, log into sites using credentials you provide, compare prices, and add things to carts, all without you clicking anything. Amazon sued Perplexity in November 2025 claiming this violated the CFAA and California's equivalent computer fraud law, even when users explicitly authorized Comet to act for them. A San Francisco district court sided with Amazon in March 2026 and blocked Comet from Amazon while the case moved forward. The Ninth Circuit vacated that block on August 4.
Here's the everyday version of the legal logic the appeals court used. When you hire a housecleaner and give them a key, the cleaning company didn't break into your house — you let them in, and the cleaner is doing your authorized work. The Ninth Circuit applied the same frame to AI browsing: you gave Comet your credentials, you authorized the access, so Perplexity's product isn't the one that "accessed" Amazon. You did. And you had every right to.
The CFAA criminalizes unauthorized access. If you're the user and you authorized it, there's no unauthorized access for Perplexity to be liable for.
- Nov 2025
Amazon files suit
Claims Comet violates federal CFAA and California computer fraud law by accessing Amazon servers without Amazon's authorization, even when users consent.
- March 10, 2026
District court blocks Comet
Judge Maxine Chesney grants preliminary injunction, finding Amazon likely to prevail. Comet prohibited from operating on Amazon while case proceeds.
- August 4, 2026
Ninth Circuit reverses
Vacates the injunction. Users, not Perplexity, 'access' Amazon's servers under CFAA. Case returns to district court on Amazon's remaining claims.
Source spread
- Ninth Circuit opinion, No. 26-1444 — [builder] Primary source. The full ruling; the rule-of-lenity analysis and the court's explicit acknowledgment that AI agent law is unsettled are both in here.
- EFF amicus brief response, August 5 — [skeptic of Amazon's position] The Electronic Frontier Foundation filed as amicus and the court agreed: building a browser doesn't make you a CFAA violator.
- Cooley insight on district court ruling — [builder] How the original district court read CFAA; useful for understanding what the Ninth Circuit reversed.
- Search Engine Journal analysis — [builder] Broadens the lens: implications for any AI agent that browses on behalf of users.
- Courthouse News factual summary — [builder] Clean blow-by-blow of the reversal.
What's real and what deserves a side-eye
What's real:
- The CFAA ruling gives user-authorized AI agents meaningful legal protection, at least in the Ninth Circuit. Not just Comet. Any AI that acts on behalf of an authenticated user — shopping, booking, filing — just got a cleaner legal framework to operate under.
- The "rule of lenity" the court used is a real constitutional principle: when a federal criminal statute is ambiguous, courts interpret the ambiguity against liability. The court applied it here because CFAA language didn't clearly define what it means for an AI to "access" a computer. That's a defensible call.
- The court was unusually candid. Explicitly admitting "little to no existing caselaw" on AI agent responsibility is a rare moment of judicial honesty about where the law actually is.
What deserves a side-eye:
- The ruling is narrow by the court's own design. The Ninth Circuit said its holding "will doubtless change" as AI agents proliferate. This is not a permanent answer.
- Amazon's trademark and California state-law claims survived. The case goes back to district court. Perplexity still faces a full trial on separate grounds.
- The CFAA is a 1986 hacking law. Courts applying it to AI agents in 2026 are working with tools built for a completely different problem. The ruling resolves one question while leaving a dozen adjacent ones untouched.
Little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents.
What this means for you
If you use an AI assistant that shops or browses on your behalf:
- Your AI agent can operate on Amazon again, at least until the district court case resolves — and unless another court in another circuit reaches a different conclusion. The Ninth Circuit covers California, Oregon, and Washington; this ruling isn't national.
- You're the one "accessing" the site, not the developer. That's actually how it should work: you're in control, which means you bear the responsibility. Trust your AI agent only as much as you trust the company behind it with your login credentials.
- Amazon can still block agents through technical means. Courts ruling that CFAA doesn't apply doesn't prevent platforms from deploying bot detection, terms-of-service enforcement, or just blocking traffic from known AI agent signatures. The legal battle and the technical one run in parallel.
- This ruling doesn't mean "AI agents can go anywhere." It means CFAA doesn't make the developer liable when a user authorized the access. Users can still violate terms of service. Platforms can still sue on other grounds.
- The Ninth Circuit holding covers California, Oregon, Washington, and other western states. Other circuits have not ruled. If you're building agentic products with national or global reach, treat this as a regional signal, not settled law.
- "User authorized it" is now a viable CFAA defense in the Ninth Circuit. Document user authorization explicitly — in your terms, in the UX flow, and in the credential-sharing model. If a user's authorization is ambiguous, so is your defense.
- Amazon's trademark and California CDAFA claims are still live. Monitor the district court for the next wave. The IP angle (is Comet confusing customers about Amazon's endorsement of Comet?) is where the next fight happens.
- The court said agentic AI law "will doubtless change." Build compliance flexibility into your agentic products now — logging, audit trails, per-site opt-in from users. Whatever authorization framework you adopt today should be updatable without a full product rebuild.
- The EFF filed amicus on the winning side. Their analysis of the case is worth reading for the first-principles argument about browser-building and CFAA.
Further reading
- Ninth Circuit opinion, No. 26-1444, August 4, 2026 — full ruling text; rule-of-lenity analysis in section III-B
- EFF — Appeals court agrees building a web browser doesn't violate CFAA — the EFF's analysis of what the ruling actually establishes
- Search Engine Journal — Amazon v. Perplexity: the CFAA case that decides whether AI agents can visit your website — pre-ruling explainer on the stakes
- Mogin Law — Courts weigh authorization, consent, and agentic AI — legal analysis on the CFAA authorization question
- Cooley — District court ruling, March 2026 — the reversed ruling; useful to understand what the Ninth Circuit actually disagreed with
Liked this? Get the weekly digest.
Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.
Your take
How'd I do on this one?
What did I miss?
Tell Samwise (and Sam).
Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.