What happened
Amazon sued Perplexity in November 2025, alleging that the AI shopping agent built into Perplexity's Comet browser accessed password-protected Amazon accounts without authorization and made purchases on users' behalf. Amazon said Perplexity had agreed in 2024 to pause this kind of agentic shopping, then restored it, and that Comet identified itself with the same user-agent string as a normal Chrome browser, making agent traffic hard to distinguish from ordinary human browsing. In March 2026, U.S. District Judge Maxine Chesney granted Amazon a preliminary injunction, citing the Computer Fraud and Abuse Act (CFAA), a federal law that prohibits intentionally accessing a computer without authorization and causing at least $5,000 in loss. On August 4, 2026, a three-judge Ninth Circuit panel, in a unanimous ruling written by Judge Milan Smith, vacated that injunction. The court's reasoning was technical: Comet requests Amazon's pages onto the user's own device, the user's device receives the data first, and only afterward does the Comet agent relay screenshots and instructions back to Perplexity's servers. On that record, the court held it is the user, not Perplexity, who "accesses" Amazon's computers under the CFAA. The court called Comet's Assistant "a tool, not a person for statutory purposes," and noted that Amazon's theory, if accepted, could have exposed ordinary users themselves to criminal liability for using a browser. The court did not say AI agents are broadly permitted to do whatever they want on a platform. It noted explicitly that Amazon may still have other viable claims against Perplexity outside the CFAA, and the underlying lawsuit continues in federal court in San Francisco. Amazon said it disagrees with the decision and is evaluating a request for rehearing or an appeal to the Supreme Court.
Why it matters for business owners
This is the first time a federal appeals court has ruled on how a hacking law applies to an AI agent acting for a user, and it is being covered as a sweeping win for agentic AI. For a business owner, the relevant fact is narrower and more useful: a specific 1986 criminal statute, written decades before autonomous browser agents existed, was found not to fit this particular fact pattern. That is a real legal development. It is not a general legal clearance for deploying AI agents against a platform's wishes. Most businesses will never be a defendant in a CFAA case. But a growing number of businesses now use, or are being sold, AI agents that log into vendor portals, pull data from partner systems, fill out forms on outside websites, or otherwise interact with platforms your business does not control. This ruling is a useful signal for how one narrow slice of that risk, a specific hacking-law theory, is currently being read by one appeals court. It says nothing about your contract with that platform, your vendor's terms of service, or what happens if the agent gets something wrong.
What owners should not misunderstand
The ruling does not make it lawful to violate a platform's terms of service. The court's holding was limited to the CFAA and California's parallel computer-access statute, at the preliminary-injunction stage, based on the specific technical record of how Comet's data flows. A footnote in the opinion, reported by multiple outlets covering the case, notes that platforms like Amazon can still write and enforce terms of service against agentic access through ordinary contract law. That is a live path Amazon can still pursue, separate from the hacking-law theory the court rejected. The ruling also does not resolve who is liable when an AI agent causes real harm. The court itself said there is little to no existing caselaw on how to ascribe responsibility for AI agents, and it avoided the question of AI "intent" entirely by treating the agent as a tool operated by the user. That framing worked here because a user directed a specific shopping action. It does not tell you what a court would say if an agent with standing, ongoing access misread an instruction, acted outside what a user actually intended, or caused a financial or data loss no one directed it to cause. That question remains open, and it is the one that matters most for any business granting an agent real access to its own systems or a vendor's. Finally, this was a preliminary ruling on whether an injunction should have been granted, not a final judgment. The underlying lawsuit continues, Amazon has said it disagrees and is weighing further appeal, and the legal picture here is not finished settling.
The operational lesson
Treat this ruling as one data point about one type of legal exposure (a specific hacking statute), not as clearance for how your business uses AI agents. The practical exposure most businesses actually carry is contractual, not criminal: if an AI agent your business uses touches a vendor's platform, a customer's account, or a partner's system in a way that violates that party's terms of service, this ruling does not protect you from that vendor terminating the relationship, suing for breach of contract, or citing the violation as cause in a dispute. The deeper, still-unresolved question, who is responsible when an agent's action causes harm, is exactly the kind of question that should get answered before an agent is given standing access inside your business, not after something goes wrong. A court ruling that a tool "is not a person for statutory purposes" is a legal technicality that resolves a criminal-law question. It does not resolve who absorbs the cost when that same tool makes a mistake with your money, your customer's data, or a vendor relationship you depend on.
What a serious business should do next
List every AI agent or automated tool currently connected to a third-party platform, vendor account, or partner system on your business's behalf, whether that is a shopping agent, a CRM integration, a scraping tool, or an automation platform. For each one, check what the platform's terms of service actually say about automated or agentic access, not what a general news story about a court ruling implies. For any agent with standing access (it can act without a human approving each step), define in writing who is accountable if it acts incorrectly: your business, the vendor who built the agent, or some shared arrangement, and get that answer before relying on the agent for anything consequential, not after. Do not read this ruling, or any single court decision on a narrow legal theory, as a reason to expand what an AI agent is allowed to do unsupervised. Expand agent permissions based on your own risk tolerance and a clear accountability answer, not based on a favorable headline about someone else's lawsuit.
The Atlacis view
Atlacis is not a law firm and this is not legal advice. What Atlacis helps owners do is slow down before an AI agent gets standing access to a system that matters, map out exactly what that agent can touch, and identify where the accountability gap actually sits, before a headline court ruling or a vendor's marketing page makes that decision for you. A court finding that a tool is not a person under one specific statute does not answer who your business calls when that tool gets something wrong. That answer should exist before the access is granted, not after.
The short version
- On August 4, 2026, the Ninth Circuit ruled that Perplexity's Comet AI shopping agent did not violate the Computer Fraud and Abuse Act when it bought items on Amazon for users, because the user, not Perplexity, is the one who legally accesses Amazon's systems.
- It is the first federal appellate ruling addressing how a 1986 anti-hacking law applies to an AI agent, and the court itself noted there is little to no existing caselaw on how to assign legal responsibility for AI agents generally.
- The ruling does not make it lawful to violate a platform's terms of service. The court's holding covered one criminal statute at the preliminary-injunction stage; Amazon can still pursue contract-based claims, and the underlying lawsuit continues.
- The ruling does not resolve who is liable when an AI agent causes real harm rather than completing a directed task. That question remains open and is more relevant to most businesses than the hacking-law theory the court rejected.
- Amazon has said it disagrees with the ruling and is evaluating a rehearing request or a Supreme Court appeal, so the legal picture around this specific case is not finished settling.
Where ATLACIS can help
- Read about OpenAI's agent breaking containment inside a third-party testing environment
- Read about the research showing AI models cannot reliably tell a real instruction from an impostor
- Read the AI workflow audit guide
- Learn more about AI systems advisory
- Book a call to review which AI agents already have standing access in your business
Sources
- Electronic Frontier Foundation: Appeals Court Agrees with EFF that Building a Web Browser Doesn't Violate the CFAA (Andrew Crocker, August 4, 2026)
- San Francisco Chronicle: AI users can shop directly on Amazon without Amazon's permission, judges rule (Bob Egelko, August 4, 2026)
- Dataconomy: Perplexity defeats Amazon in AI browser ruling (August 5, 2026)