Can companies stop AI shopping agents from accessing their websites? That question is at the center of a closely-watched dispute between Amazon and Perplexity AI. In a newly-issued decision, the Ninth Circuit vacated a preliminary injunction entered to prevent the use of Perplexity’s agentic browser tool on Amazon.com, holding that Amazon is unlikely to succeed on its claim under the Computer Fraud and Abuse Act (“CFAA”) because, on the current record, it is the user – not Perplexity – that “accesses” Amazon’s computers.
The case centers on Comet, Perplexity’s AI-enabled browser. Comet users can instruct its optional AI assistant to perform tasks on their behalf. When directed to locate an item on Amazon.com, the AI assistant takes screenshots of the browser view, sends them from the user’s computer to Perplexity’s servers, and receives instructions from those servers on how to navigate Amazon.
In its November 2025 complaint, Amazon brought claims under the Computer Fraud and Abuse Act (“CFAA”) and California’s Comprehensive Computer Data Access and Fraud Act (“CDAFA”), alleging that Comet accessed Amazon.com without authorization. Granting a preliminary injunction earlier this year, the Northern District of California found that Amazon had presented strong evidence that Perplexity accessed users’ password-protected accounts – via Comet – without Amazon’s authorization and had demonstrated a likelihood of success on its CFAA and CDAFA claims.
Inside the Ninth Circuit’s Opinion
The Ninth Circuit disagreed. In an August 4 opinion, the appellate panel concluded that Perplexity itself does not directly communicate with Amazon’s servers. Instead, it held that the user’s browser accesses Amazon.com, while Perplexity’s AI assistant functions as a tool that helps the user carry out requested tasks.
As a result, the court concluded that it is the user – not Perplexity – that “accesses” Amazon’s computers within the meaning of the CFAA, and that Perplexity’s receipt of screenshots and transmission of instructions did not, by itself, establish that it had gained entry to Amazon’s servers.
Applying Existing Law to Agentic AI
In reaching that conclusion, the judges acknowledged that “agentic AI is an emerging technology” and observed that there is “little to no existing caselaw” directly addressing how to ascribe responsibility for AI agents. The court concluded that imposing CFAA liability under these circumstances would require a novel interpretation of the statute, one that departed from Congress’s purpose of preventing intentional intrusion into another party’s computer – specifically, computer hacking.
At the same time, the panel emphasized the narrow scope of its ruling. It stressed that it was not establishing a new legal regime for agentic AI or deciding whether Perplexity could face liability for the Assistant’s conduct in other contexts, including under tort law. Its holding was limited to the meaning of “access” under the CFAA as applied to the Assistant’s interactions with Amazon.com on the record before it.
The court similarly held that Amazon was unlikely to succeed on its CDAFA claim for the same central reason: on the current record, it is the user – not Perplexity – that accesses Amazon using the Assistant as an AI tool.
The Ninth Circuit also concluded that the remaining preliminary injunction factors favored Perplexity and vacated the injunction, citing Amazon’s limited showing of harm, the burden on Perplexity, and the public interest in preserving consumer choice and the development of a nascent technology.
THE BIGGER PICTURE: The significance of the ruling extends beyond Amazon and Perplexity. As AI agents increasingly browse websites, compare products, make purchases, and complete other online tasks on consumers’ behalf, they may become a new intermediary between companies and their customers. Against that backdrop, the opinion suggests that, at least under the Ninth Circuit’s interpretation and on the facts and technical record before it, the CFAA may not provide a broad mechanism for restricting AI agents when the user’s browser – rather than the AI developer’s servers – communicates directly with the website.
Instead, contractual restrictions governing users may become a more important tool for companies seeking to regulate AI agents. The court noted that its decision does not impair Amazon’s ability to regulate access to Amazon.com through its private terms of service. It held only that, on the current record, Amazon was unlikely to succeed in doing so under the CFAA and CDAFA.
The case is Amazon.com Services LLC v. Perplexity AI, Inc., 3:25-cv-09514 (N.D. Cal.).
