Ninth Circuit Lifts Restrictions on Agentic AI Accessing Amazon
by guest blogger Kieran McCarthy
I recently described the district court’s decision in the case of Amazon v. Perplexity as “a shockingly poor effort to grapple with CFAA applicability to agentic AI technology.”
The Ninth Circuit appears to have agreed.
This week, the Ninth Circuit panel published its opinion vacating the district court’s preliminary injunction and remanding for further proceedings. Amazon.com Services, LLC v. Perplexity AI, Inc., 2026 WL 2237587 (9th Cir. Aug. 4, 2026).
The panel determined that Amazon was not entitled to a preliminary injunction because it was not likely to succeed on the merits of its CFAA claim. The court concluded that Perplexity did not “access” Amazon’s computers within the meaning of the CFAA, but rather it was the user who accessed Amazon’s computers. The panel also concluded that Amazon was equally unlikely to succeed on the merits of its CDAFA claim for the same reasons.
The panel also concluded that the remaining equitable factors favored Perplexity.
The Court kept its opinion narrow and specifically disclaimed the applicability of this opinion to other facts or other laws related to data access and agentic AI. But this was a nonetheless important step in distinguishing the infamous Power Ventures opinion, at least in the context of agentic AI.
—
I described the facts in detail in my prior write up of the district court’s decision, so I won’t rehash them here.
But unlike at the district court, the Ninth Circuit panel did not ignore the key factual pattern that makes this case so interesting. What’s unique and interesting about this case is that it involves a fundamentally new technology, in the form of Agentic AI, acting on the instructions of end users.
The panel wrote:
Agentic AI is an emerging technology. There is thus little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context. And CFAA cases dealing with more established technologies do not provide a perfect analogue to the case at hand.
Id. at 12.
The panel then went on to distinguish the facts of both Power Ventures and BrandTotal (both cases involving Facebook, ironically enough).
And the key distinguishing fact, according to the panel, was that on the facts presented to the Court, it was not Perplexity that was accessing Amazon’s computers, but rather the end users through their computers.
Under the CFAA’s plain language, Perplexity’s Comet Assistant itself cannot “access” Amazon’s servers.
According to the Court:
However advanced the Assistant currently is, it is a tool, not a person for statutory purposes. See 18 U.S.C. § 921(a)(1) (“The term . . . ‘whoever’ include[s] any individual, corporation, company, association, firm, partnership, society, or joint stock company.”); see also Whoever, Cambridge English Dictionary, [https://perma.cc/YY3TVTJF] (last visited July 16, 2026) (“[T]he person who” (emphasis added)).
Id. at 15.
Since it is the user using the Assistant tool, Perplexity’s not accessing Amazon’s servers in the first place. And the entire CFAA case unwinds after it reaches that conclusion.
The Court further reinforced its conclusion with the rule of lenity (which courts that enforce the CFAA always seem to forget). The Court was concerned that under Amazon’s theory of liability, end users could be exposed to criminal liability for using agents. Given the rapid adoption of this new technology, the Court was concerned about that approach.
But with just as much caution, the Court was equally quick to reiterate what the opinion was not.
We do not establish a new legal regime governing agentic AI. We do not address whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant’s actions. Our holding here is limited to “access” as contemplated by the CFAA and as applied to the Assistant’s interactions with Amazon.com on the record before us, not the broader landscape surrounding agentic AI.
Id. at 17.
—
The Court’s reasoning was largely identical in the context of the CDAFA, even though, as I noted in the prior district court opinion write up, the CDAFA is broader than the CFAA. Even though the CDAFA is broader, the “focus of the inquiry is still on the person accessing or causing the access.” Id. at 18. And since the panel concluded that it was not Perplexity that accessed Amazon’s servers, but rather end users through their own computers, that was that.
—
Once the panel determined that Amazon was unlikely to succeed on the merits, the district court’s thin and largely circular conclusions on the other equitable factors unraveled quickly.
In the end, the Ninth Circuit panel kept its opinion tight and focused on the primary issue in the case: whether Perplexity’s agentic AI tool was a “person” who accessed a site within the meaning of the CFAA. It is not, and the case has been remanded for further proceedings in light of that conclusion.
The case avoiding sweeping pronouncements and it was not the straight-up revocation of Power Ventures that some might have hoped for. Given the other legal issues presented, Perplexity might not be out of the woods just yet, but it’s fair to say that the Ninth Circuit vacated bad legal precedent and replaced it with a better one. And for that we can be thankful.
* * *
Eric’s Comments
In the copyright module of my Internet Law course, I ask students a simple question: is web browsing infringement and, if so, by whom? I use the Cablevision case to review the question. (In that case, the court held that for a DVR-as-a-service business, the users pressed the button to make the storage copies). The whodunit question blows students’ minds because it’s 2026 and they assume these issues have long been resolved. As this case shows, courts are still unsure who takes the legally significant actions online.
The ruling also brought to mind the Ticketmaster v. RMG case (the 2007 Hannah Montana case), which I still teach today. The facts in that case remain murky to this day, but I always interpreted RMG as handing off its software to its ticket broker customers, who then operated the software to snipe scarce event tickets, but with some ongoing facilitation from RMG (like relaying ticket purchase requests through a phalanx of RMG-associated IP addresses to reduce blockage). Ticketmaster successfully prevailed over RMG in that case on several legal theories, but does this court’s reasoning suggest that Ticketmaster’s redress should come solely from RMG’s customers, not RMG? Or does the RMG case suggest Amazon ought to win against Perplexity, just under other legal theories?
In support of that latter prospect, the opinion invites courts to more closely scrutinize exactly what the providers of agentic AI software do to facilitate their users’ activities. If they cross some undefined and currently invisible line, the software provider will transform into the legally relevant actor. That might harmonize this ruling with the RMG and Cablevision cases, but at the cost of inconsistent judicial outcomes and high defense costs.
As with other whodunit cases, if Perplexity is off the hook, where does that leave Perplexity’s users legally? Could Amazon assert CFAA/502 claims against users, or a range of other legal theories? In a footnote, the court says tersely: “This outcome does not impair Amazon’s ability to regulate access to Amazon.com via private terms of service for its users.”
The users’ legal exposure highlights some challenging policy fault lines of this case–and all online trespass to chattels cases. On the one hand, it would be a bad thing if websites more aggressively erect contract-based putative barriers to access. That creates a potential thicket for ordinary daily activities, and it raises greater risks that individuals will unintentionally trigger significant legal exposure if they don’t research and confirm their permission to visit every service they visit.
On the other hand, Amazon clearly expressed its preferences that it didn’t want Perplexity’s users to access its services through agentic AI, and why shouldn’t the law back up these strong and clear desires? We know that server operators need that prerogative to fend off hostile attacks, but we also know server operators will overclaim any legally backed prerogative they have.
As a result, as with most trespass-to-chattels cases, there are not likely to be any easy answers in this case. There are only significant and potentially problematic policy tradeoffs.

