
Short Answer: What did the court decide?
The Ninth Circuit ruled that when an AI agent acts on a person’s behalf, the user is the one accessing the website, not the AI company. The court vacated Amazon’s injunction against Perplexity’s Comet browser, finding the Computer Fraud and Abuse Act does not make an agent’s developer liable for visits the user directed.
Quick Summary
- The Ninth Circuit vacated Amazon’s injunction against Perplexity’s Comet shopping agent on August 4, 2026.
- The court called the agent “a tool, not a person” for statutory purposes, so the user is the one who accesses the site.
- The CFAA is now a weak tool for blocking AI agents. The court warned that using it this way could expose users themselves to criminal liability.
- This was a preliminary injunction, not a final judgment. The case continues, and the court noted Amazon may still have other viable claims.
- Blocking agents is now a technical decision, not a legal one. Robots.txt, WAF rules, and edge controls matter more than cease-and-desist letters.
On August 4, 2026, a three-judge panel of the Ninth Circuit lifted the block on Perplexity’s AI-powered shopping assistant, overturning a preliminary injunction Amazon had won in March.
The legal question sounds technical. The practical question is not: when an AI agent shows up on your website acting for a real person, who is the visitor?
The court’s answer is the person.
What Actually Happened?
Amazon sued Perplexity in late 2025, arguing that its Comet browser unlawfully accessed password-protected customer accounts when the AI agent shopped on a user’s behalf. A federal judge agreed enough to grant a preliminary injunction in March 2026, pausing Perplexity’s agentic shopping on Amazon while the case proceeded.
The Ninth Circuit vacated that injunction. The panel rejected Amazon’s framing that Perplexity was the party accessing Amazon’s servers. Comet, the court found, received screenshots that the users’ own browsers captured and forwarded.
Even where Perplexity received account information from users and used it to instruct the Assistant, the court found that fell short of the control required to attribute the access to the developer.
What Did the Court Actually Say?
Two findings carry the ruling.
- The Assistant is “a tool, not a person for statutory purposes.” Tools do not access computers under the CFAA. The people operating them do.
- The court acknowledged how new this is, noting there is “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context.”
The Electronic Frontier Foundation, which filed an amicus brief in the case, framed the policy stakes bluntly: stretching the computer-hacking statute to cover tool developers could expose users themselves to criminal liability.
That is the part site owners should sit with. If operating an AI agent were unauthorized access, the person clicking the button would be the one committing the offense.
Why This Matters for Brands and Site Owners
For most marketing teams, the takeaway is not about Perplexity or Amazon. It is about what leverage you have when agents arrive at your site.
Until this ruling, the CFAA was the biggest legal stick available for keeping unwanted automated visitors out. That stick just got considerably shorter, at least in the Ninth Circuit.
The practical consequence is that blocking AI agents is now primarily a technical and business decision, not a legal one. If you want to control agent access, the tools are edge-level crawler controls, robots.txt directives, WAF rules, and rate limiting — not a demand letter.
It also raises the value of knowing which agents actually visit you. That is the entire premise of agent analytics: you cannot make a decision about traffic you cannot see.
Should You Block AI Shopping Agents?
For most brands, no — and the ruling sharpens why.
An agent shopping on a customer’s behalf is a customer with extra steps. Blocking it does not remove the demand; it removes you from the transaction. The relevant question shifted from “can we keep them out” to “are we the brand the agent picks.”
That is a visibility problem, not a security problem. Our guides to AI shopping optimization and how product pages get recommended cover the mechanics.
There are legitimate reasons to restrict agents: infrastructure cost, scraping for training rather than transacting, fraud patterns, or contractual obligations. Those are real. But they are business judgments now, made case by case, rather than a blanket legal position.
What This Does Not Mean
Three qualifications matter, and skipping them produces a badly wrong read of this decision.
- This was a preliminary injunction, not a final ruling. The underlying litigation continues. Perplexity won an early round, not the case.
- The court did not say Amazon has no claims. It said Amazon is unlikely to succeed on the CFAA theory, while noting Amazon might have other viable claims — contract, trespass, or terms-of-service arguments among them.
- This binds the Ninth Circuit. It is persuasive elsewhere, not controlling. Other circuits could land differently, which is how questions reach the Supreme Court.
Law firms were already flagging this tension before the decision. Jones Day’s analysis of agents authorized by the user but blocked by the platform laid out the competing theories, and other coverage framed it as a question of whether agents get visitor rights at all.
How This Fits the Larger Picture
Two forces are now pushing in the same direction.
Agent traffic is growing fast, and the crawlers consuming the most content are not always the ones sending visitors back. At the same time, the legal route for excluding those agents just narrowed. Site owners are being told, in effect: manage this yourself.
Regulation is moving on a separate track. The EU began enforcing AI transparency rules on August 2, requiring AI systems to identify themselves. Disclosure obligations are tightening even as access restrictions loosen.
For marketers, the strategic response is the same one that has been forming all year. Measure agent behavior, understand where conversational demand is going, and make sure your brand is the answer an agent returns. That is the core of Answer Engine Optimization.
If Perplexity specifically is a meaningful channel for you, our guide on showing up on Perplexity is a practical starting point.
What Should You Do This Week?
- Check whether you are currently blocking AI agents at the edge or in robots.txt, and confirm that is a deliberate choice rather than an inherited default.
- Review which agents actually reach your site and what they do — published crawler identifiers make verification straightforward.
- Separate agents that transact from agents that scrape. They deserve different policies.
- If you sell online, test how AI shopping agents currently describe and compare your products.
- Keep terms of service and contractual protections current, since those claims survive this ruling even where CFAA arguments do not.
Frequently Asked Questions
What Did the Ninth Circuit Actually Rule?
That Perplexity was unlikely to be liable under the Computer Fraud and Abuse Act because the company itself does not access websites — its users do. The AI assistant was treated as a tool operated by end users, so the access is attributed to the person, not the developer.
Does This Mean AI Agents Can Access Any Website?
No. It means the CFAA is unlikely to be the mechanism that stops them, within the Ninth Circuit. Site owners can still use technical controls, and other legal theories such as contract or terms-of-service claims were not resolved by this decision.
Is the Amazon v. Perplexity Case Over?
No. The appeals court vacated a preliminary injunction, which is an early-stage order. The litigation continues, and the court noted Amazon may have other viable claims.
Should Ecommerce Brands Block AI Shopping Agents?
For most brands, blocking removes you from transactions rather than removing demand. Restrictions make sense for infrastructure cost, fraud, or contractual reasons, but the more valuable question is whether AI agents recommend your products when customers ask.
How Is This Different From the hiQ v. LinkedIn Case?
Both narrow the reach of the CFAA. hiQ concerned scraping publicly accessible data, while this decision addresses who is responsible when an AI agent acts on a specific user’s behalf, including in logged-in contexts. The through-line is judicial reluctance to turn a computer-hacking statute into a general tool for controlling automated access.
About the author
Kai Williams
Kai Williams has been in marketing for years, with a long background in SEO before AEO had a name. He stepped into Answer Engine Optimization the moment AI started reshaping how people search, and has been tracking the shift ever since. At Prompt Insider, he covers AEO, AI marketing, and the future of search, breaking down what is changing and what brands need to do about it.


