Short answer: no β not when a user directs the agent and the agent is just fetching pages the user’s own login already reached. On August 4, 2026, the Ninth Circuit vacated a preliminary injunction that had blocked Perplexity’s Comet browser from operating on Amazon accounts, holding that Perplexity itself does not “access” Amazon’s computers under the Computer Fraud and Abuse Act (CFAA) β the user does (EFF: “Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA,” Aug. 4, 2026). It’s the first federal appellate answer to a question every merchant with a login wall now has to think about: can a cease-and-desist letter and a 1986 anti-hacking statute keep an AI shopping agent out?
What the court decided
The case is Amazon.com Services LLC v. Perplexity AI, Inc., No. 26-1444, on appeal from the Northern District of California (CourtListener docket 71874820). Amazon sued in November 2025 over Comet’s optional “Assistant,” which logs into a user’s Amazon account to browse, compare and check out on their behalf. Senior District Judge Maxine Chesney granted Amazon a preliminary injunction on March 9, 2026, finding Amazon likely to succeed on CFAA and California Comprehensive Computer Data Access and Fraud Act claims; Perplexity filed its notice of appeal the next day, and the Ninth Circuit administratively stayed the injunction on March 30, 2026 while the appeal proceeded (case docket, entries for 3/9, 3/10 and 3/30/2026).
A three-judge panel β Circuit Judges Milan Smith Jr. and Eric Tung, with District Judge John Hinderaker sitting by designation β heard oral argument in Seattle on June 11, 2026 (Courthouse News Service: “Perplexity AI asks Ninth Circuit to allow shopping tool on Amazon”). At argument, Judge Hinderaker flagged the core difficulty directly: “This case is difficult in part because we are dealing with a statute from 1986… it’s not really built for these circumstances.” The panel’s memorandum disposition followed on the docket on August 5, 2026 (docket entry, “USCA Memorandum”).
The holding: the user accesses, not the tool
Per EFF, which filed an amicus brief backing Perplexity, the panel agreed that Comet’s Assistant “is a tool, not a person for statutory purposes,” operated by the user rather than by Perplexity β even though Perplexity’s software receives account information from the user and uses it to run the Assistant. The court found that arrangement doesn’t amount to Perplexity itself accessing Amazon’s servers, so Amazon was unlikely to succeed on its CFAA theory. The opinion also noted there is “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents,” but concluded that didn’t matter here because the tool/user distinction resolved the case without reaching questions of AI “intent.”
What’s still open
The ruling is narrow on purpose. It vacates a preliminary injunction on the CFAA “access” theory only β it isn’t a final judgment, and the case returns to the district court. Amazon’s trademark and other state-law claims are untouched. The panel itself said agentic AI law “will doubtless change,” leaving room for a different outcome on the merits, or from another circuit.
What this means for a merchant
Two practical takeaways for anyone auditing whether β and how β to gate agentic access:
- A cease-and-desist plus a CFAA threat is a weaker lever than it looked a year ago, at least in the Ninth Circuit and at the preliminary-injunction stage, once the agent is genuinely user-directed rather than operating on its own account or credentials.
- Contractual and technical gates are where the real leverage still sits. Amazon’s non-CFAA claims (trademark, state-law analogs) survived this ruling untouched, and nothing in the opinion disturbs a site’s ability to require agent self-identification in its terms of service, or to enforce access technically through mechanisms like Web Bot Auth or declared crawler categories. “Block by policy” and “block by statute” are not the same tool, and this ruling only narrowed the second one.
For merchants deciding how to treat agentic traffic, the access pillar of an AgentReady audit checks exactly this layer β whether a store’s ToS, robots directives and bot-identification setup are doing the gating work a CFAA claim increasingly can’t.
Sources
- Electronic Frontier Foundation, Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA, Deeplinks, August 4, 2026 β fetched via the source-fetch bridge August 11, 2026.
- CourtListener, Amazon.com Services LLC v. Perplexity AI, Inc., Docket No. 71874820, N.D. Cal. case docket (preliminary injunction, notice of appeal, USCA Case No. 26-1444 entries) β fetched via the source-fetch bridge August 11, 2026.
- Courthouse News Service, Perplexity AI asks Ninth Circuit to allow shopping tool on Amazon, June 11, 2026 β fetched via the source-fetch bridge August 11, 2026.
The court settled who’s “accessing” your site when an agent shops on a user’s behalf β it didn’t settle whether that agent can actually find, understand and buy what you sell, which is the part a legal win doesn’t fix for you.