---
title: "A Federal Court Ruled Your AI Agent Isn't \"Accessing\" a Website When a User Directs It. The Catch Is in the Architecture."
date: 2026-08-12T09:00:00Z
author: Deepankar Bhadrasen
url: https://truehorizon.ai/news/amazon-perplexity-cfaa-agent-ruling
description: "The 9th Circuit cleared Perplexity's AI, ruling that users not agents legally access websites. Here are the implications for third-party developers."
---

# A Federal Court Ruled Your AI Agent Isn't "Accessing" a Website When a User Directs It. The Catch Is in the Architecture.

> The 9th Circuit cleared Perplexity's AI, ruling that users not agents legally access websites. Here are the implications for third-party developers.

On August 4, the Ninth Circuit Court of Appeals answered a question that every company building or buying AI agents needs an answer to: when an agent acts on a user's behalf on someone else's platform, who is legally "accessing" that platform? In [Amazon.com Services v. Perplexity AI](https://www.pymnts.com/news/artificial-intelligence/2026/ninth-circuit-narrows-cfaa-reach-in-perplexity-agentic-commerce-ruling/), the court's answer was: the user. Not the AI company. That distinction just vacated an injunction that had shut down one of the more visible agentic AI products on the market.

## What the court actually decided

Perplexity's Comet browser lets a user direct an AI agent to browse and buy on Amazon on their behalf. Amazon sued under the Computer Fraud and Abuse Act, the federal government's core anti-hacking statute, and California's parallel CDAFA, arguing that Perplexity's agent was accessing Amazon's systems without authorization. A district court agreed in March and issued a preliminary injunction blocking the agent. The Ninth Circuit vacated that injunction on August 4, holding that Amazon was unlikely to succeed on its CFAA and CDAFA claims. Comet routes its actions through the user's own browser rather than Perplexity's servers talking to Amazon's directly, and the panel held it was "the user who accessed Amazon's computers," not Perplexity.

## Why the reasoning matters more than the headline

The CFAA punishes unauthorized computer intrusion. The court's logic was that if a user is the one directing the action, through a tool they chose to use, there's no intrusion to punish, regardless of how autonomous the tool looks while it's working. That's a meaningful, useful precedent. It is also easy to over-read. The panel was explicit that "different facts regarding how the agent operated may have changed the outcome." This ruling turned on Comet's specific architecture: actions routed through the user's own session. An agent built to talk directly to a company's servers, without that user-session routing, was not covered by this reasoning and could face a very different result under the same statute.

## What this ruling doesn't do

Legal analyses from firms including Cooley and Ropes & Gray have been careful to flag the limits here, and they're worth taking seriously. The ruling only reaches the CFAA and CDAFA specifically. It arrived at the preliminary-injunction stage, which means the court assessed likelihood of success, not a final decision on the merits. Terms-of-service violations, breach of contract, and tort claims were untouched by this decision and remain live legal theories against agents that scrape or act on third-party platforms. Amazon can still seek a rehearing, petition the Supreme Court, or continue the underlying case in federal court in San Francisco. Nothing here is settled law yet. It's a strong early signal, not a permanent shield.

## What this means if you're deploying agents

If your product includes an AI agent that acts on a user's behalf on a platform you don't control, three things are worth doing now:

- Map exactly how your agent talks to third-party platforms. Whether it routes through the user's own authenticated session or communicates server-to-server just became a legally load-bearing distinction, not just a technical one.
- Don't treat this ruling as blanket cover for agentic products. Terms-of-service and contract exposure are still on the table regardless of how the CFAA question shakes out.
- Get a real legal and architecture review before scaling an agent that acts on another company's platform. The right answer depends on how the thing is actually built, not on a general vibe that "courts are fine with agents now."

## Where TrueHorizon fits

This is exactly the kind of detail that separates a demo from a deployment that survives contact with a courtroom. We design agent architectures with this class of exposure in mind from day one: how an agent authenticates, whose session it acts through, what it's allowed to touch, and where the legal exposure actually sits. **That's not a checklist we're learning on your project.** It's the expertise we bring to it. A ruling like this one is a useful data point. It isn't a substitute for knowing exactly how your own agent is built.

If you're building or scaling an agent that acts on platforms you don't control, [take our AI readiness assessment](https://truehorizon.ai/assessment) before a lawsuit tells you where your risk was.

Source: https://truehorizon.ai/news/amazon-perplexity-cfaa-agent-ruling
