Amazon won an injunction blocking Perplexity's Comet browser from its logged-in pages. Five months later the Ninth Circuit vacated it, holding that when a user directs an AI agent, the user is the one accessing the site under the CFAA.
Amazon sued Perplexity AI over Comet, a browser whose assistant can log into a site as the user and complete tasks there. On March 10, 2026 a district judge in San Francisco enjoined Comet from reaching Amazon's password-protected pages. On August 4, 2026 the Ninth Circuit vacated that injunction.
The appellate holding is one sentence long in substance and enormous in consequence: when a user directs an AI agent to visit a website, the user is the one who accessed it.
| Item | Detail |
|---|---|
| Caption | Amazon.com Services LLC v. Perplexity AI, Inc. |
| District court | U.S. District Court, Northern District of California |
| District docket | 3:25-cv-09514 |
| District judge | Maxine M. Chesney |
| Preliminary injunction | March 10, 2026 |
| Court of appeals | Ninth Circuit, No. 26-1444 |
| Appellate decision | August 4, 2026, injunction vacated and remanded |
| Claims | Computer Fraud and Abuse Act; California Penal Code section 502 |
| Status | Back in the district court |
Comet is an agentic browser. A user asks it to buy something, and the assistant navigates the site, fills forms, and completes checkout while logged into the user's own account. To do that on Amazon it operates inside a session the user authorized.
Amazon's complaint is not that Comet reads its public pages. It is that Comet operates inside logged-in areas, order history, account settings, checkout, while presenting itself as an ordinary browser. A central allegation is that Perplexity chose not to send a distinguishing user-agent string, which would have told Amazon's servers that an automated agent, not a person, was driving the session.
Perplexity's position is that the account belongs to the user, the user asked for the action, and Amazon does not get to dictate which software a customer uses to shop.
Judge Chesney found Amazon likely to succeed on its CFAA and section 502 claims and enjoined Comet from the password-protected portions of the site. CNBC covered the order when it issued.
The CFAA makes it unlawful to access a protected computer without authorization or in excess of authorized access. The statute was written in 1986 for a world of dial-up intrusions, and courts have spent two decades narrowing it. Van Buren v. United States in 2021 rejected the broad reading under which violating a website's terms of service becomes a federal crime, and hiQ Labs v. LinkedIn confined "without authorization" largely to circumventing a technical barrier.
Neither case answered this one. The user has credentials. The site does not want the agent. Who is the actor?
The Ninth Circuit answered that the actor is the user. As Cooley's analysis puts it, the panel reasoned that "it was the user who 'accessed' Amazon's computers," so the agent's provider could not itself be liable for accessing without authorization. The panel vacated the injunction and remanded for further proceedings. The opinion is on the Ninth Circuit's site.
That is a holding about the CFAA. It is not a holding that Perplexity wins.
The case returns to Judge Chesney. Amazon's other theories, including its state law claims and any contract or trespass-based arguments, were not resolved by the appeal. A plaintiff who loses a CFAA theory in this posture usually reframes around contract and around unfair competition, where authorization is a matter of agreement rather than of statute.
The practical fight moves to detection and blocking. Nothing in the ruling requires Amazon to serve Perplexity's agent. If the CFAA does not supply the remedy, technical measures and terms enforcement will.
For everyone building agents, the operative question shifted from "may we do this" to "what happens when the site blocks us." That is a commercial problem with a legal backstop, rather than the other way around.
Both dockets are worth watching, since the remand and any further appellate practice run in parallel.
Search the current record here: Amazon v. Perplexity AI. Remand dockets after a vacatur tend to produce a scheduling order and an amended pleading quickly, so case alerts will catch the next move faster than checking by hand.
Three practical takeaways, and none of them is that the coast is clear.
The CFAA is not the tool. After this ruling, a site that objects to an agent acting for a logged-in user cannot easily reach the agent's provider through the federal computer fraud statute in the Ninth Circuit. That closes one door.
Contract is the tool that remains. Terms of service, developer agreements, and API terms allocate authorization by agreement rather than by statute, and a breach of contract claim does not depend on who "accessed" anything.
Identification is now a business decision with legal consequences. A large part of Amazon's complaint was that Comet did not identify itself as an agent through its user-agent string. A provider that identifies its agent gives the site the ability to block it. One that does not invites exactly this litigation. Neither choice is free.
The Supreme Court's decision in Van Buren rejected the reading of the CFAA under which violating a website's terms of use is a federal crime, holding that "exceeds authorized access" refers to obtaining information from areas of a computer that are off limits.
The Ninth Circuit's hiQ decisions confined "without authorization" largely to circumventing a technical barrier such as authentication.
Read together, they left the statute pointed at intrusion rather than at misuse. This case applies that framing to a session the user was entitled to open, and the answer follows from it.
The other frontier AI dispute over unauthorized extraction, this one framed as trade secret theft rather than computer intrusion, is OpenEvidence v. Doximity. For the copyright version of the same argument about training and using other people's material, see Andersen v. Stability AI. And for the Supreme Court's 2026 statement on when an intermediary is liable for what its users do, read Cox Communications v. Sony Music.