---
title: "The Ninth Circuit&#8217;s CFAA Ruling in Amazon v. Perplexity"
description: "While I was at Black Hat and BSides, the appeals court vacated Amazon's injunction against Perplexity's Comet browser. However, the reasoning turns on a narrow technical question: who actually \"access..."
url: https://kaynemcgladrey.com/blog/the-ninth-circuits-cfaa-ruling-in-amazon-v-perplexity/
date: 2026-08-07
modified: 2026-08-07
author: "Kayne"
image: https://kaynemcgladrey.com/wp-content/uploads/2026/08/N.D.Cal_._3_25-cv-09514-MMC_114_0_1.webp
categories: ["Blog"]
type: post
lang: en
---

# The Ninth Circuit&#8217;s CFAA Ruling in Amazon v. Perplexity

While I was at Black Hat and BSides, the appeals court vacated Amazon’s injunction against Perplexity’s Comet browser. However, the reasoning turns on a narrow technical question: who actually “accesses” a website when an AI agent does the clicking.

Back in March 2026, a district court granted Amazon a preliminary injunction barring Perplexity’s Comet browser and its AI “Assistant” from accessing Amazon.com. [I noted at the time](https://www.linkedin.com/posts/kaynemcgladrey_april-6-report-activity-7446987846919557120-a4kD/) that the ruling stretched the CFAA further than the statute comfortably goes. In August, the Ninth Circuit vacated that injunction in a [published opinion](https://storage.courtlistener.com/recap/gov.uscourts.cand.459191/gov.uscourts.cand.459191.114.0.pdf) issued August 4, 2026. The panel didn’t say Perplexity’s conduct is lawful; instead, it said Amazon is unlikely to win under the Computer Fraud and Abuse Act (CFAA), the federal anti-hacking law, its California counterpart, the Comprehensive Computer Data Access and Fraud Act (CDAFA).

## The “Access” Question

The entire case turns on what “access” means under the CFAA. The statute punishes “whoever… intentionally accesses” a protected computer without authorization. Judge Milan D. Smith Jr., writing for the panel, read “whoever” as contemplating a person or entity, not a software tool. The Assistant, however sophisticated, is a tool. The user is the actor.

> “On the facts before us, it concluded that Perplexity did not use a tool to ‘access’ Amazon’s computers. Rather, it was the user who ‘accessed’ Amazon’s computers, with the help of Perplexity’s AI agent, the ‘Assistant,’ to carry out specific acts on Amazon.com.”– Ninth Circuit Opinion, August 4, 2026

The technical architecture drove this conclusion. When a Comet user directs the Assistant to shop on Amazon, the Assistant takes screenshots of the browser view on the user’s own machine, sends those screenshots to Perplexity’s servers, and receives instructions back on how to move through Amazon.com. Perplexity’s servers never directly communicate with Amazon’s servers.

Compare this to *Facebook, Inc. v. Power Ventures, Inc.*, where the defendant’s own systems caused messages to be transmitted directly on Facebook’s platform. In [Power Ventures](https://www.courtlistener.com/docket/4175967/facebook-inc-v-power-ventures-inc/), the defendant’s own systems caused messages to be transmitted directly on Facebook’s platform – the servers reached into Facebook’s infrastructure. Perplexity’s architecture doesn’t do that. The screenshots originate on the user’s machine, not Amazon’s servers.

| Element | Power Ventures | Perplexity (Current Record) |
| --- | --- | --- |
| Direct server-to-server communication? | Yes | No |
| Defendant’s systems contacted target? | Yes | No |
| User relay involved? | No | Yes |
| Outcome | CFAA liability found | Likely no CFAA liability |

The Supreme Court defined “access” in *Van Buren v. United States* (2021) as “entering a computer system itself,” and the Ninth Circuit found that Perplexity never gained entry to Amazon’s systems. The user did, with the Assistant helping carry out specific tasks.

## Why the Rule of Lenity Mattered

The panel then invoked the rule of lenity, a principle that resolves statutory ambiguity against liability. The CFAA is primarily a criminal statute, and civil interpretations track criminal ones. The court expressed a specific concern: if Amazon’s broad reading prevailed, individual users could face criminal aiding-and-abetting liability for using an AI shopping assistant.

Imagine a world where typing “buy me toothpaste on Amazon” through Comet exposes you to federal aiding-and-abetting charges simply because the tool you chose doesn’t identify itself to the retailer. The panel didn’t think that scenario likely, but the mere possibility was enough to tip it toward a narrow reading of the statute.

## The Injunction Factors Collapsed Too

Amazon’s evidence of irreparable harm consisted of claims that the Assistant “may not select the best price, delivery method, or product recommendations,” resulting in a degraded shopping experience. The court called that abstract. Amazon’s cybersecurity argument was similarly weak.

**Amazon’s Evidence, Broken Down:**

- Only one security risk cited involved a shopping website
- None of the risks specifically involved Amazon.com
- Amazon’s own expert couldn’t fully replicate the harms
- Perplexity had implemented improvements addressing the cited issues

The balance of equities favored Perplexity, which had invested substantial sums developing Comet, and the public interest favored consumer choice and continued development of the technology. The panel noted, almost as an aside, that Amazon retains the ability to regulate access through its terms of service. The CFAA just isn’t the right instrument.

## Where This Goes Next

The case returns to [the district court](https://www.courtlistener.com/docket/71874820/amazoncom-services-llc-v-perplexity-ai-inc/?order_by=desc#entry-114). The injunction is gone, but the lawsuit isn’t. Amazon’s remaining options look like this:

1. Pursue the untouched § 1030(a)(4) claim, which the district court’s order didn’t address
2. Develop a richer factual record on “access” if Perplexity modifies the Assistant’s architecture
3. Pivot to contract and tort theories grounded in terms of service violations

[Amazon told Reuters](https://www.reuters.com/business/retail-consumer/amazon-loses-us-court-ban-perplexitys-ai-shopping-tools-2026-08-04/) it “respectfully disagrees” and is “evaluating next steps,” which is corporate-speak for “we’re not done.”

## What This Decision Doesn’t Resolve

The panel was explicit about the limits of its holding. It addressed only the CFAA’s “access” prong on the specific facts presented. The judges acknowledged that agentic AI is new territory with almost no precedent, and they refused to pretend otherwise.

Several questions remain unanswered:

- Whether more autonomous agents would trigger different outcomes
- Whether agents whose servers communicate directly with target platforms would face CFAA liability
- How tort claims or contract enforcement would play out
- What state-law theories Amazon might pursue outside the CFAA and CDAFA

For platform operators, the lesson is straightforward. If the AI company’s servers communicate directly with your infrastructure, the CFAA likely applies to the company, and you’re in Power Ventures territory. But if everything routes through the user’s machine, as Perplexity’s Assistant does, the CFAA probably won’t help you block the agent. Terms of service *might*. The Ninth Circuit just told Amazon that anti-hacking laws don’t stretch far enough to cover a user picking the wrong shopping assistant.
