On August 4, the Ninth Circuit Court of Appeals answered a question that every company building or buying AI agents needs an answer to: when an agent acts on a user's behalf on someone else's platform, who is legally "accessing" that platform? In Amazon.com Services v. Perplexity AI, the court's answer was: the user. Not the AI company. That distinction just vacated an injunction that had shut down one of the more visible agentic AI products on the market.
What the court actually decided
Perplexity's Comet browser lets a user direct an AI agent to browse and buy on Amazon on their behalf. Amazon sued under the Computer Fraud and Abuse Act, the federal government's core anti-hacking statute, and California's parallel CDAFA, arguing that Perplexity's agent was accessing Amazon's systems without authorization. A district court agreed in March and issued a preliminary injunction blocking the agent. The Ninth Circuit vacated that injunction on August 4, holding that Amazon was unlikely to succeed on its CFAA and CDAFA claims. Comet routes its actions through the user's own browser rather than Perplexity's servers talking to Amazon's directly, and the panel held it was "the user who accessed Amazon's computers," not Perplexity.
Why the reasoning matters more than the headline
The CFAA punishes unauthorized computer intrusion. The court's logic was that if a user is the one directing the action, through a tool they chose to use, there's no intrusion to punish, regardless of how autonomous the tool looks while it's working. That's a meaningful, useful precedent. It is also easy to over-read. The panel was explicit that "different facts regarding how the agent operated may have changed the outcome." This ruling turned on Comet's specific architecture: actions routed through the user's own session. An agent built to talk directly to a company's servers, without that user-session routing, was not covered by this reasoning and could face a very different result under the same statute.
What this ruling doesn't do
Legal analyses from firms including Cooley and Ropes & Gray have been careful to flag the limits here, and they're worth taking seriously. The ruling only reaches the CFAA and CDAFA specifically. It arrived at the preliminary-injunction stage, which means the court assessed likelihood of success, not a final decision on the merits. Terms-of-service violations, breach of contract, and tort claims were untouched by this decision and remain live legal theories against agents that scrape or act on third-party platforms. Amazon can still seek a rehearing, petition the Supreme Court, or continue the underlying case in federal court in San Francisco. Nothing here is settled law yet. It's a strong early signal, not a permanent shield.
What this means if you're deploying agents
If your product includes an AI agent that acts on a user's behalf on a platform you don't control, three things are worth doing now:
- Map exactly how your agent talks to third-party platforms. Whether it routes through the user's own authenticated session or communicates server-to-server just became a legally load-bearing distinction, not just a technical one.
- Don't treat this ruling as blanket cover for agentic products. Terms-of-service and contract exposure are still on the table regardless of how the CFAA question shakes out.
- Get a real legal and architecture review before scaling an agent that acts on another company's platform. The right answer depends on how the thing is actually built, not on a general vibe that "courts are fine with agents now."
Where TrueHorizon fits
This is exactly the kind of detail that separates a demo from a deployment that survives contact with a courtroom. We design agent architectures with this class of exposure in mind from day one: how an agent authenticates, whose session it acts through, what it's allowed to touch, and where the legal exposure actually sits. That's not a checklist we're learning on your project. It's the expertise we bring to it. A ruling like this one is a useful data point. It isn't a substitute for knowing exactly how your own agent is built.
If you're building or scaling an agent that acts on platforms you don't control, take our AI readiness assessment before a lawsuit tells you where your risk was.

Written by
Deepankar Bhadrasen
Founding Engineer
Deepankar is an AI automation specialist and Founding Engineer at TrueHorizon AI, where he builds practical AI systems that help businesses streamline operations, reduce costs, and scale efficiently. He focuses on integrating custom AI agents and workflows with existing tools so teams can grow without expanding headcount.









