The Ninth Circuit's August 4 decision in Amazon.com Services, LLC v. Perplexity AI, Inc. draws one of the first appellate lines around agentic AI and computer access law.
The immediate holding is narrower than the headlines make it sound. The court vacated a preliminary injunction that had blocked Perplexity's AI-enabled browser assistant from interacting with Amazon on users' behalf. The panel said Amazon was unlikely to succeed, on the record before it, in showing that Perplexity itself "accessed" Amazon's computers within the meaning of the federal Computer Fraud and Abuse Act and California's parallel statute.
That is not a general license for AI agents to operate on third-party platforms. The opinion instead suggests that, for purposes of the CFAA's access element, some user-directed AI activity may be treated as the customer's use of a tool rather than the tool provider's own entry into a platform's computers.
What the Fight Was About
Amazon's theory was straightforward. Perplexity's Assistant, an optional feature in its Comet browser, could use a customer's Amazon session to browse and carry out tasks on the user's behalf. Amazon said Perplexity lacked permission for that activity under the CFAA and California's Comprehensive Computer Data Access and Fraud Act. Central to the dispute was Perplexity's decision not to use a user-agent string that would identify the Assistant and allow Amazon to block it.
The district court had granted Amazon a preliminary injunction in March. The Ninth Circuit vacated that order and sent the case back.
The key question was easy to state and harder to answer: when a user tells an AI agent to act on a website, who is doing the "accessing" for computer fraud purposes?
Why the Ninth Circuit Matters
The Ninth Circuit answered that question narrowly, based on the technology and record before it.
The panel concluded that the user accessed Amazon's computers with the Assistant's help. Perplexity's servers received browser screenshots and sent instructions back to the Assistant, but did not directly communicate with Amazon's servers. Those facts did not show that Perplexity itself had gained entry to Amazon's systems, the court reasoned.
That reasoning matters because Amazon's CFAA claim required proof that Perplexity accessed a protected computer. The panel did not reach authorization or the statute's remaining elements, including its loss requirement.
The same user-versus-provider question is likely to arise again as AI agents move from answering questions to logging in, navigating sites, filling forms, pulling account data, and initiating transactions.
This Is Bigger Than One Shopping Dispute
Amazon v. Perplexity does not resolve agentic AI access disputes. It shows courts beginning to decide how older computer access laws apply when software takes multiple steps at a user's direction rather than waiting for each click.
That problem is not limited to e-commerce. The same legal tension can show up in:
- enterprise automation tools that log into third-party services on behalf of employees;
- consumer AI assistants that navigate password-protected sites;
- browser-based agents that compare products, prices, or terms across platforms;
- internal legal and compliance tools that automate retrieval from external systems; and
- research workflows that rely on user-authorized scraping or session-based access.
The Knight First Amendment Institute, joined by the ACLU and ACLU of Northern California, raised another concern in an amicus brief: reading the CFAA too broadly could chill journalism and public-interest research that depends on automated tools operating with user-provided access.
The argument does not immunize researchers or AI vendors, but it shows why the stakes extend beyond this dispute.
What Companies Should Take from It
The safest reading is not "AI agents are fine now." It is that the technical path matters: who directs the tool, which computers communicate, where data goes, and how much control the provider exercises. Although user direction was important to the panel's access analysis, the opinion did not decide whether a user's permission would defeat a platform's authorization argument.
For companies building agentic products, a few practical questions now look more important:
- Is the agent acting with clear, documented user authorization?
- Does the product rely on the user's own credentials and permissions, or does it bypass technical controls?
- What signals does the system send to the platform about the nature of the interaction?
- Does the workflow create separate data-use, contract, privacy, or state-law risk even if the CFAA theory weakens?
- How much of the task is user-directed versus autonomously optimized by the vendor?
For platforms, the decision shows the difficulty of a CFAA claim when the record depicts the user, rather than the tool provider, as entering the platform's systems. Contract claims, technical controls, API design, bot-detection systems, privacy arguments, and data-use restrictions may still matter.
Why Clearon Readers Should Care
This case sits at the intersection of AI product design, litigation risk, and platform governance.
Agentic AI marketing often assumes that if a user can do something, an AI agent can do it without changing the legal analysis. The Ninth Circuit did not endorse that broad claim. It instead held that Amazon was unlikely, on the current record, to prove that Perplexity was the party that accessed its computers.
That is an important early signal for legal teams reviewing AI assistants that operate inside customer accounts or interact with third-party services.
Future disputes are therefore likely to turn on details: credentials, disclosure, technical barriers, autonomy, data handling, system architecture, and the relationship among the user, vendor, and platform.
Bottom Line
Amazon v. Perplexity is one of the first appellate opinions to test how the CFAA applies to agentic AI.
The Ninth Circuit did not give AI agents blanket immunity. At the preliminary-injunction stage and on the record before it, the court held that Amazon was unlikely to show that Perplexity "accessed" Amazon's systems when the user accessed them with the Assistant's help.
That is a meaningful development for AI companies, platforms, and in-house legal teams.
The next question is whether other courts follow the same user-versus-tool framing, or whether different facts push them toward a narrower view of what agentic systems can do inside someone else's digital environment.









