Metropolitan News-Enterprise

 

Wednesday, August 5, 2026

 

Page 1

 

Ninth Circuit:

Amazon Loses Preliminary Bid to Halt Shopping by AI Agents

Opinion Says California, Federal Laws Prohibiting Unauthorized ‘Access’ of Computer System Contemplate Human Interaction, Not Use of Virtual ‘Assistant’ to Shop on User’s Behalf

 

By Kimber Cooley, associate editor

 

The Ninth U.S. Circuit Court of Appeals yesterday denied a request by Amazon.com Services LLC for a preliminary injunction against San Francisco-based Perplexity AI Inc. over the defendant’s deployment of an artificial intelligence “agent” that can shop for goods on the retailer’s website on a user’s behalf over the express objection of the online giant.

Amazon’s complaint asserts that Perplexity has violated federal and California laws designed to protect against “accessing” a computer without authorization, asserting that the defendant hides the use of the so-called “agentic” tool by “disguis[ing]” it as a human to evade the company’s filtering process, which otherwise would have been able to block the use of the AI assistant, and gains entry to the user’s private account without the plaintiff’s permission.

Yesterday’s opinion, authored by Circuit Judge Milan D. Smith Jr., declares that Amazon is unlikely to succeed on the merits of its claims because Perplexity cannot be said to have “access[ed]” the company’s systems as the statutes regulate only human action, saying “[h]owever advanced the Assistant currently is, it is a tool, not a person.”

He opined:

“Our focus is…to ask whether Perplexity uses a tool (the Assistant) to ‘access’ Amazon’s computers. On the facts before us, we answer no. It is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com.”

Unauthorized Access

Amazon asserted in its complaint, filed on Nov. 4, 2025, that Perplexity’s use of the AI tool on its website violates the Computer Fraud and Abuse Act (“CFAA”), found at 18 U.S.C. §1030, and California’s Comprehensive Computer Data Access and Fraud Act (“CDAFA”), codified at Penal Code §502, both of which criminalize and create a private cause of action for the “unauthorized access” of computer systems.

Alleging that the plaintiff has “told Perplexity’s executives…that its AI agents may not covertly access the Amazon Store” but that the company has failed to comply, the pleading adds:

“Perplexity operates…an application called Comet that includes ‘agentic AI’ functionality….In practice, these AI tools can independently interact with third-party websites, use stored credentials, and perform actions on the users’ behalf—executing sequences that resemble a human-controlled browser session even when no human is actively clicking.”

When a Comet user directs the “assistant” to locate an item online, the assistant takes screenshots from the browser, sends them to the Perplexity servers, and navigates a website like Amazon.com based on instructions received back from the system.

Citing cyber-security risks and the potential interference with company’s “integrated, dynamic environment that provides Amazon customers with a[n]…individualized shopping experience,” Amazon sought a preliminary injunction to stop Perplexity’s use of Comet in its store.

In March, Senior District Court Judge Maxine M. Chesney of the Northern District of California granted the plaintiff’s request to preliminarily enjoin Perplexity from “[a]ccessing, attempting to access,…or providing a means for others to access or attempt to access Amazon’s protected computer systems using AI agents.”

Likelihood of Success

Smith noted that the party seeking a preliminary injunction must show that it is likely to succeed on the merits of its claims, and to suffer irreparable harm without immediate relief, as well as establish that the balance of the equities and the public interest tips in its favor. Addressing the first point, he pointed out that the parties dispute what qualifies as “access” under the two statutory schemes and said:

“In Amazon’s view, it suffices for CFAA purposes that the Assistant communicates with Perplexity’s servers to, as Perplexity states, ‘determine appropriate actions’ regarding the Amazon Store. Amazon argues that Perplexity itself admits that the Assistant proceeds autonomously and ‘behaves like an efficient human shopper,’ and that autonomous action should be ascribed to Perplexity because it is the Perplexity servers that direct the Assistant.”

Perplexity argued that it cannot be said to have “accessed” the online retailer’s store because “no Perplexity computer ever accessed Amazon’s servers” as “any Amazon data was first transmitted to the user’s computer and then to Perplexity’s servers via browser screenshots.” The jurist remarked that “there is…little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context.” Looking to the statutory language, he reasoned at the section’s use of the phrase “[w]homever…intentionally accesses” a “protected computer” means the law “contemplates access by a person.”

Rule of Lenity

Adding that “[t]his conclusion is further reinforced by the rule of lenity,” which requires courts to construe any ambiguity against a finding of liability where criminal sanctions are at stake, he commented:

“[I]mposing liability here would require a novel interpretation far afield from the statute’s purpose ‘to prevent…computer hacking.’…Amazon’s approach, if accepted, could expose users themselves to criminal liability (under a conspiracy or aiding-and-abetting theory) for facilitating Perplexity’s purported unauthorized access to Amazon’s servers….[I]t is unlikely that Congress would have exposed individual users to criminal liability under the CFAA by using the Assistant and Comet browser to access Amazon.com under these facts.”

However, he cautioned:

“We do not address whether, on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon’s servers. On the current record, Amazon is not likely to succeed in proving the ‘access’ prong of its CFAA claim.”

Turning to the California law, he said “Amazon’s CFAA and CDFA claims rise and fall together,” pointing out that the relevant prohibition in the state version applies to “any person” who causes unauthorized access. Smith continued:

“While Amazon might be correct that “access” under the CDAFA is broader than the CFAA’s definition, the focus of the inquiry is still on the person accessing or causing the access. Accordingly, we arrive at the same conclusion: the user (not Perplexity) accesses Amazon using the Assistant as an AI tool, and thus Amazon is unlikely to succeed on the merits of its CDAFA claim.”

Remaining Factors

As to the remaining factors for determining whether preliminary relief is appropriate, he said that Chesney erred in finding that they tipped in Amazon’s favor. Smith added:

“Because we recognize that agentic AI is an emerging technology, we reiterate what this opinion is not. We do not establish a new legal regime governing agentic AI. We do not address whether in other contexts, including tort claims, Perplexity can avoid liability for the Assistant’s actions. Our holding here is limited to ‘access’…as applied to the Assistant’s interactions with Amazon.com on the record before us, not the broader legal landscape surrounding agentic AI. The legal understanding of agentic AI will doubtless change as AI technology grows increasingly sophisticated. For now, this opinion reflects and applies to the state of technology only as presented in the filings in this case.”

The case is Amazon.com Services LLC v. Perplexity AI Inc., 26-1444.

Amazon offers its own AI-shopping assistant, called “Rufus,” but critics of the company’s attempt to shut down the use of third-party alternatives are quick to point out that the internal tool, unlike the Comet and competitors, is unlikely to suggest to users that they purchase goods from other platforms even if a cheaper price or better product is available elsewhere.

Third-party AI “shoppers” also cut off Amazon’s ability to use ad-targeting or sponsored search results aimed at the human user.

 

Copyright 2026, Metropolitan News Company