A federal appeals court vacated the preliminary injunction that had kept Perplexity AI's Comet browser assistant out of Amazon shopping accounts, ruling on August 4, 2026 that the person at the keyboard, and not the company that built the agent, is the party accessing the retailer's computers under United States hacking law.

In Short

Amazon won a court order in March 2026 that stopped Perplexity's AI shopping assistant from operating inside Amazon accounts. On August 4, 2026 the Ninth Circuit threw that order out, holding that an AI agent is a tool rather than a legal person, so the human user is the one doing the accessing. Amazon can still set rules for its own site through its terms of service, but it cannot rely on federal or California computer crime statutes to keep agents out when those agents run on a shopper's own machine.

What the panel decided

The United States Court of Appeals for the Ninth Circuit vacated the preliminary injunction in Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444, and sent the case back to the district court for further proceedings. The opinion, written by Circuit Judge Milan D. Smith, Jr., was filed on August 4, 2026 after argument in Seattle on June 11, 2026. Circuit Judge Eric C. Tung and District Judge John Charles Hinderaker of the District of Arizona, sitting by designation, completed the panel.

The ruling turns on a single statutory word. To win a civil claim under the Computer Fraud and Abuse Act, a plaintiff must show that the defendant intentionally accessed a computer, without authorization or exceeding authorized access, thereby obtained information from a protected computer, and suffered loss of at least $5,000 in any one-year period. Amazon cleared the loss threshold in the district court. It did not, on the record before the appeals panel, clear the first element.

According to the opinion, the Assistant built into Perplexity's Comet browser is a tool rather than a person for statutory purposes, and the statute punishes whoever intentionally accesses a protected computer. The panel read that language as contemplating access by a person, citing the definition of "whoever" at 18 U.S.C. § 921(a)(1) and a dictionary entry recorded as last visited on July 16, 2026. Applying the Supreme Court's reading in Van Buren v. United States, under which access in the computing context means entering a system or a particular part of one, the panel concluded that it is the user who accesses Amazon's computers, with the help of the Assistant to carry out specific acts on Amazon.com.

Amazon's parallel claim under California's Comprehensive Computer Data Access and Fraud Act failed for the same reason. The panel accepted that the state statute may define access more broadly than its federal counterpart, noting that Cal. Penal Code § 502(b)(1) reaches causing input to or data processing with the logical, arithmetical or memory functions of a computer. The prohibition Amazon invoked, § 502(c)(7), still applies only to a person who causes unauthorized access. The claims, in the panel's phrasing, rise and fall together.

How the court described the plumbing

The technical account in the opinion is narrower than the rhetoric surrounding agentic AI generally. Comet runs locally on a user's machine and behaves like any other browser. Its distinguishing feature is an optional agent, marketed as the Assistant, which can carry out tasks at the user's direction, including shopping on Amazon.com.

When a Comet user directs the Assistant to find an item, the Assistant takes screenshots of the browser view, sends those screenshots from the user's computer to Perplexity's servers, and receives navigation instructions back. The panel found that the Assistant cannot operate wholly independently, since it depends on both the user's direction and instructions returned from Perplexity's servers.

That architecture was set out most clearly, according to the opinion, in the amicus brief filed by the Electronic Frontier Foundation, the Alliance for Responsible Data Collection, Mozilla Corporation, Digital Medusa and EleutherAI. The browser requests the page from Amazon's server and displays it. The Assistant analyses what the browser has already rendered on the user's computer, and where the task requires it, passes the user's instructions plus information about the page to Perplexity's AI servers. The brief states that Perplexity's servers never directly access Amazon's servers, a description the panel found consistent with how both parties characterised the systems.

Perplexity's own analogy was to Safari filling in an address and payment details at checkout. Amazon's counter was that agentic capability goes beyond the passive display of a traditional browser, and that Perplexity itself has described the Assistant as behaving like an efficient human shopper. The panel did not resolve the analogy contest. It held only that receiving screenshots and sending instructions does not, by itself, amount to gaining entry to Amazon's servers.

Why the leading cases did not settle it

Both sides anchored their arguments in earlier Ninth Circuit and district court decisions, and the panel found neither a clean fit.

Amazon relied on Facebook, Inc. v. Power Ventures, Inc., where a social media aggregator was held liable for continuing to cause promotional messages to be sent inside Facebook after a cease-and-desist letter. The panel noted that the Power Ventures court assumed without discussion that Power had accessed Facebook, devoting the bulk of its analysis to authorization instead. That assumption is precisely what Amazon needed the court to extend, and the panel declined to treat an unexamined premise as controlling.

Perplexity relied on Meta Platforms, Inc. v. BrandTotal Ltd., in which a browser extension that passively logged data Meta had already sent to users was held not to be accessing Meta's servers. The panel found that analogy imperfect in the opposite direction, observing that the Assistant appears to do more than passive data collection.

Between those poles, the opinion reached for the rule of lenity. Because the Computer Fraud and Abuse Act is primarily a criminal statute whose interpretations apply equally in civil and criminal contexts, ambiguity is construed against liability. The panel added a consequence that platform operators may find uncomfortable: on Amazon's reading, the users themselves could face exposure under conspiracy or aiding-and-abetting theories for running an agent the platform had not authorised. Citing United States v. Nosal, the opinion warned against turning categories of otherwise innocuous behaviour into federal crimes because a computer is involved.

The equities, and the weakness of the harm case

Having found Amazon unlikely to succeed on the merits, the panel still worked through the remaining injunction factors, and found each of them unpersuasive on Amazon's side.

On irreparable harm, Amazon's declarations argued that the Assistant may not select the best price, delivery method or product recommendations for a customer shopping in its store. The panel treated that as a claim of degraded experience rather than demonstrable loss of goodwill, contrasting it with Stuhlbarg International Sales Co. v. John D. Brush & Co., where customs detention of goods already promised to named customers made the harm concrete. Degradation of an overall shopping experience, the opinion reasoned, is more abstract, as is the question of whether users would blame the Assistant they chose to switch on.

The cyber-risk argument fared no better. Amazon asserted that multiple security researchers had corroborated the risks posed by Perplexity. Perplexity responded that Amazon's own expert had been unable to fully replicate those risks and that the company had addressed them. The panel recorded that only one of the cyber risks cited in the expert declaration involved a shopping website, and that the example did not involve Amazon.com specifically.

Balance of equities and public interest followed. An injunction against conduct that likely violates neither statute would impose a burden on a product Perplexity spent large sums developing, the panel held, and would impair consumer choice while limiting development of a nascent technology.

What the opinion expressly does not do

The panel was unusually explicit about its own limits, and those limits matter for anyone reading the decision as a settled rule for automated traffic.

It does not establish a legal regime governing autonomous software. It does not address whether Perplexity could avoid liability in other contexts, including tort claims. It does not reach the remaining elements of the federal claim, including the scope of the loss provision, and a footnote records that the district court's written order never addressed Amazon's separate claim under § 1030(a)(4), which Amazon did not press on appeal. A further footnote leaves open whether, on a different record, Perplexity might exercise control over the Assistant in a way that does amount to gaining entry.

There is also an unresolved factual dispute sitting underneath the whole appeal. The parties disagree, according to a footnote, over whether Perplexity knowingly altered the Assistant's user-agent string after Amazon first succeeded in identifying and blocking it. The panel did not need to resolve that question to decide the access issue, so it did not.

The most consequential line for platform operators is the one addressed to remedy rather than statute. The opinion states that the outcome does not impair Amazon's ability to regulate access to Amazon.com through private terms of service for its users. What Amazon lost is the ability to convert that contractual preference into a federal computer crime claim against the agent's developer.

That reticence reflects the ground the panel was standing on. The United States has no comprehensive federal statute governing artificial intelligence, and none has advanced through Congress; the federal layer consists of executive orders, agency guidance under existing authorities at bodies such as the Federal Trade Commission, and procurement rules, none of which defines what an autonomous agent is or who answers for what it does. The one standalone federal statute that substantively regulates AI systems, the TAKE IT DOWN Act, took effect on May 19, 2026 and covers a single harm category, non-consensual intimate imagery. Binding private-sector duties sit instead in a state patchwork: Texas put its Responsible Artificial Intelligence Governance Act into force on January 1, 2026, California's AI Transparency Act became operative on August 2, 2026, and Colorado repealed its 2024 high-risk framework in May 2026 and replaced it with a narrower automated decision-making statute that starts on January 1, 2027. None of those instruments speaks to whether an agent shopping on a retail site is trespassing. The result is that agent conduct in the United States is assessed through statutes drafted for other purposes, which is precisely what happened here when a 1984 anti-hacking law was asked to classify a browser assistant, and the panel recorded the underlying problem plainly: there is little to no existing caselaw on how to ascribe responsibility for AI agents, let alone caselaw doing so in this statutory context.

An early reading from outside the United States

Marco Scialdone, head of litigation and academic outreach at Euroconsumers and adjunct professor of AI law at Università Europea di Roma, circulated an analysis of the opinion on LinkedIn, marked two weeks old at the time the post was captured and published under a notice that his views are strictly personal.

According to Scialdone, the appellate court clarified a point of legal classification under United States computer access frameworks, holding that "an AI agent, regardless of its operational sophistication, remains a software tool rather than a legal person." Because the browser assistant acts only at the direction of the consumer, and because Perplexity's servers never connect directly to the host platform, he wrote, the law treats the end user as the primary legal actor initiating and effecting access.

Scialdone framed the wider significance in terms of allocation rather than permission, describing the precedent as "a critical blueprint for delineating user accountability, platform governance and the legal limits of technological agency" as autonomous workflows expand.

Why this matters for advertisers, publishers and retailers

Amazon's advertising business is the commercial backdrop. The company reported advertising services revenue of $19.8 billion for the second quarter of 2026, up 26% year over year, five days before the opinion issued. Sponsored placements, recommendation carousels and the retail media surfaces that generate that revenue are exactly the page furniture an agent can skip, and the harm Amazon described to the court, an assistant that may not surface the best price or the recommended product, is also a description of an intermediary standing between advertisers and shoppers.

Publishers had already argued the point in this case. A coalition organised through the publisher trade body backed Amazon in the appeal, warning that agents presenting themselves as human traffic corrupt advertising metrics and undermine the revenue that funds journalism. The counsel listing in the opinion records that amicus as Digital Context Next, while earlier PPC Land coverage of the same brief identified the organisation as Digital Content Next, a discrepancy worth noting for anyone citing the docket. News/Media Alliance, the National Retail Federation, the Software and Information Industry Association and Airlines for America also appeared as amici, alongside the American Civil Liberties Union and the Knight First Amendment Institute on the civil liberties side.

The practical consequence is that identification, not litigation, becomes the operative control. Detecting agent traffic has been a live problem across the sector for more than a year: Google added Google-Agent to its official crawler list in March 2026, a reference compilation of user agent strings for major AI clients circulated among search practitioners in June 2026, and Cloudflare documented undeclared crawling using a generic Chrome user agent in 2025. Cryptographic approaches such as Web Bot Auth exist because a self-declared header proves nothing. None of that machinery was at issue in the appeal, but all of it becomes more load-bearing once the statutory route narrows.

Commerce platforms have been building the contractual and protocol layer in parallel. Amazon added a formal agent policy to its Business Solutions Agreement effective March 4, 2026, staffed an agentic commerce team aimed at controlled, API-mediated connections with external AI platforms, and joined the governance council for UCP in April 2026. The pattern across the sector has been to admit agents through negotiated interfaces while resisting uninvited ones, and research into commerce media has already flagged AI shortlists as the next contested paid placement. The opinion does not change any of that. It changes which lever a retailer pulls when an agent arrives without an invitation.

For media buyers, the measurement question is the one that outlasts the litigation. A session driven by an assistant still renders pages, still fires impressions and still resolves to a browser on a consumer device. Amazon's forensic expenditure, which the district court accepted as clearing the $5,000 statutory threshold, went into distinguishing that traffic from ordinary customer traffic. The appeal leaves the distinction technically as hard as it was and legally less useful.

Timeline

Summary

Who: The United States Court of Appeals for the Ninth Circuit, in a panel of Circuit Judges Milan D. Smith, Jr. and Eric C. Tung with District Judge John Charles Hinderaker sitting by designation, ruling between Amazon.com Services, LLC, represented by Hueston Hennigan LLP with Hagan Scotten arguing, and Perplexity AI, Inc., represented by Quinn Emanuel Urquhart & Sullivan LLP with Christopher G. Michel arguing.

What: The panel vacated the preliminary injunction that barred Perplexity's Comet Assistant from Amazon's password-protected accounts, holding that Amazon is unlikely to succeed on the access element of its Computer Fraud and Abuse Act and California Comprehensive Computer Data Access and Fraud Act claims, because the user rather than Perplexity accesses Amazon's computers when the Assistant is used. The panel also found that irreparable harm, the balance of equities and the public interest all failed to favour an injunction.

When: The opinion was filed on August 4, 2026, following argument on June 11, 2026, in an appeal from a preliminary injunction issued in March 2026 in a case filed in November 2025.

Where: The Ninth Circuit, sitting in Seattle, Washington, on appeal from the United States District Court for the Northern District of California, Case No. 3:25-cv-09514-MMC before Judge Maxine M. Chesney. The conduct at issue took place on Amazon.com through a browser installed on consumers' own machines.

Why: The decision removes federal and California computer crime statutes as a tool for blocking third-party AI agents that run locally at a user's direction, leaving terms of service, technical identification and negotiated commercial interfaces as the remaining controls available to retailers, publishers and advertising platforms.