Industry·3 min read·Bloomberg Law

Perplexity Wins: Its Agent Doesn't Access Amazon, You Do

The Ninth Circuit vacated the injunction that kept Perplexity's Comet agent off Amazon.com, holding that under the Computer Fraud and Abuse Act it is the user — not the company that ships the agent — who accesses a website. Judge Milan D. Smith Jr. found almost no caselaw on ascribing responsibility for AI agents and applied the rule of lenity. Amazon's trademark and California CDAFA claims survive on remand.

NINTH CIRCUIT · AUGUST 4, 2026 “Perplexity does not access. Users do.” USER types the request COMET AGENT clicks, scrolls, buys AMAZON.COM serves the page INJUNCTION VACATED access prong only · remanded to San Francisco BITSMINDS.COM
Share:

The Ninth Circuit vacated the preliminary injunction that had kept Perplexity's Comet shopping agent off Amazon.com, ruling on 4 August that the company which ships an AI agent is not the party that "accesses" a website when the agent goes to work. The user is. It is the most consequential ruling yet on whether the Computer Fraud and Abuse Act — a 1986 anti-hacking statute — reaches software that browses the web on a person's behalf.

Circuit Judge Milan D. Smith Jr., writing for the panel, put the holding in seven words: Perplexity does not access Amazon's servers, users do. The court found that Comet acts only when a person instructs it, and that shipping screenshots of Amazon pages back to Perplexity's servers to complete a task is not itself unauthorised access to those servers. Smith noted there is little to no existing caselaw on how to ascribe responsibility for AI agents under the CFAA, and leaned on the rule of lenity: because the CFAA carries criminal penalties, statutory ambiguity is construed against liability rather than for it.

Amazon sued in late 2025, arguing that Comet unlawfully reached into password-protected customer accounts through Perplexity's browser. A federal judge in San Francisco agreed enough to grant a preliminary injunction in March 2026, barring Perplexity's agents from making purchases on the platform while the case proceeded. That order is now gone, and Comet can shop on Amazon again — but the lawsuit is not over. The panel deliberately limited itself to the access prong at the preliminary-injunction stage, and Amazon's trademark claims and its California Comprehensive Computer Data Access and Fraud Act claims survive on remand. Amazon can also seek a rehearing or petition the Supreme Court.

Read alongside the other Perplexity ruling from last week, a pattern is forming in how courts are sorting agent cases. In Reddit's case against Perplexity and SerpApi, the claim that survived was not about copying or access at all — it was DMCA Section 1201 anti-circumvention, which asks only whether a technological barrier was bypassed. The access theories keep losing; the lock-picking theories keep advancing. For platforms that want to keep agents out, the message is that the durable arguments are about circumvention, contract, and trademark, not about who touched the server.

That distinction matters commercially because the "agentic commerce" plans at Amazon, Google, and OpenAI all assume the platform gets to decide which agents transact on it. If the party that authored the agent is not the one accessing the site, blocking becomes a technical and contractual problem rather than a federal-crime problem — and technical blocks are exactly what Section 1201 was written to protect.

Want AI news before everyone else?

The morning's most important AI stories, straight to your inbox. No fluff.

Related Articles

RUST-LANG/RUST · LLM POLICY Review it. Don’t write it. BANNED LLM-authored code Unmarked LLM comments Pasted review replies Soundness-critical work WITH DISCLOSURE Machine translation Trivial code or prose LLM-assisted bug finds Pre-arranged patches NO DISCLOSURE Asking questions Analysing and refining Reviewing other PRs Output only you see Five teams · the rust-lang/rust monorepo · adopted 5 August 2026 BITSMINDS.COM
Industry

Rust Bans LLM-Written Code in Its Compiler Monorepo

WHITE HOUSE — VOLUNTARY CYBER EVALUATION OpenAI agent breached Hugging Face Anthropic models breached 3 companies Google attending Meta attending Submit up to 30 days before public release TESTS FINALIZED Announced Monday, Aug 3 METRICS USED HOW RESULTS REPORTED WHETHER ANY IS PUBLIC Details withheld BITSMINDS.COM
Industry

White House Finalizes AI Cyber Tests After Agent Breaches

GOOGLE'S CHIP FINANCING CHAIN About $200bn of interlocking contracts, resting on one tenant $35bn tranche buys the chips 4.5GW committed PRIVATE CREDIT Apollo · Blackstone COMPUTE SPV Morgan Stanley GOOGLE TPUs built with Broadcom ANTHROPIC 20-year leases GUARANTEE LAYER Broadcom backstops ≈$30bn of the $35bn · Google guarantees up to $44bn of other tenants' rent Borrowing cost: 7.1% median on Google-backed projects vs 9.3% elsewhere BITSMINDS.COM
Industry

Google's $200bn Chip Finance Machine Rests on Anthropic