Sunday, September 6, 2026

News

US Appeals Court: AI Agents Can't Violate Anti-Hacking Law

PolicyPatryk Raba
US Appeals Court: AI Agents Can't Violate Anti-Hacking Law
Fot. Sanfranman59, Wikimedia Commons (CC BY-SA 4.0)

The Ninth Circuit Court of Appeals overturned an injunction blocking Perplexity's Comet shopping assistant on Amazon, ruling that it is the user, not the software, who "accesses" the service under the federal anti-hacking law CFAA.

Contents
  1. The Fight Over Comet
  2. The Browser Argument
  3. What It Means for Agentic Commerce
  4. A New Battleground: Terms and Contracts

The US Court of Appeals for the Ninth Circuit ruled on August 4, 2026, that an autonomous AI agent is merely a tool, not an independent legal entity, and therefore cannot on its own violate the federal Computer Fraud and Abuse Act. The decision overturns an earlier injunction that had blocked Perplexity AI's Comet browser from making purchases on Amazon on behalf of users.

The Fight Over Comet

Perplexity AI launched its Comet browser in 2025, featuring a built-in agent capable of independently completing online purchases at a user's request. Amazon argued that the tool logged into customer accounts and navigated restricted areas of its site without the company's authorization, which it claimed violated both the federal CFAA and California's equivalent CDAFA.

After sending a cease-and-desist letter in November 2025, Amazon took the matter to court. Judge Maxine Chesney sided with the company at the preliminary stage, writing that Amazon had presented strong evidence that Comet accessed the site without the operator's consent, even if it did so at the explicit instruction of a user. The March 10, 2026 injunction blocked the agent from accessing logged-in Amazon pages.

The Browser Argument

Perplexity appealed to the Ninth Circuit, and the Electronic Frontier Foundation weighed in on the dispute in support of the company's position. The key argument centered on a comparison to an ordinary web browser: in this context, an AI agent is no different from Safari or Chrome, since it is always a human who clicks, types commands, and initiates actions, while the software merely carries them out.

The court accepted this argument almost in full. In its opinion, the panel wrote that the CFAA provision referring to 'whoever' presupposes access obtained by a person, not by a computer program. Since it is the user who instructs the agent to visit Amazon, it is the user, not Perplexity, who is the party 'obtaining access' under the statute.

An injunction against conduct that most likely does not violate the CFAA or the CDAFA would not serve the public interest. - from the opinion of the US Court of Appeals for the Ninth Circuit
We disagree with today's decision on the preliminary injunction. We remain confident in the merits of our case and are reviewing next steps. - Amazon spokeswoman

What It Means for Agentic Commerce

The ruling does not end Amazon's dispute with Perplexity, since it concerns only the validity of the preliminary injunction, while the underlying case is still proceeding in the district court in San Francisco. Amazon can seek en banc review by the full panel of judges or take the case to the Supreme Court. For now, though, Perplexity's shopping agent can resume operating on Amazon.com.

Technology lawyers see the decision as a precedent for the entire AI agent industry, calling it the first such clear appellate ruling on applying anti-hacking law to software that acts autonomously on a person's behalf. The ruling suggests that website operators cannot rely on the CFAA as an easy tool for blocking unwanted shopping agents or price-comparison bots.

A New Battleground: Terms and Contracts

With anti-hacking statutes proving an ineffective tool against AI agents, companies like Amazon will likely shift disputes toward contract law, terms of service, and new, dedicated AI regulations. Law firms commenting on the ruling note that AI agent developers gain more room to maneuver, provided their tools genuinely act on explicit user instructions rather than making fully autonomous decisions.

For Polish companies developing shopping agents or AI-based price comparison tools, the ruling has indirect significance, since it concerns US federal law, but it sets an interpretive direction that courts in other jurisdictions may draw on when assessing similar disputes. The growing number of agentic services on the Polish market, including retailers' announced openness to purchases made by AI agents, means the question of liability between tool creator and user will increasingly arise in Europe as well.

The court also cautioned that not every action by an AI agent is automatically protected. The panel suggested that at some level of interference with or control over a tool's behavior, the developer itself could be deemed the party obtaining access, leaving room for future cases in which an agent acts with less human involvement than Comet did.

Share: