Ninth Circuit Rejects Amazon's CFAA Theory Against Comet

On August 4, the Ninth Circuit vacated an injunction restricting Perplexity's Comet Assistant and found Amazon unlikely to succeed on its Computer Fraud and Abuse Act claim. The court treated the user, rather than Perplexity or the AI tool, as the party accessing Amazon on the current record and limited its holding to the CFAA access question in this dispute.
The Ninth Circuit vacated a preliminary injunction that restricted Perplexity's Comet Assistant from operating on Amazon and remanded the case for further proceedings. In its August 4 opinion, the court found Amazon unlikely to succeed on its Computer Fraud and Abuse Act claim because the current record did not show that Perplexity itself accessed Amazon's computers.
The dispute concerns Comet's optional Assistant, which can navigate Amazon at a user's direction. Amazon argued that Perplexity lacked authorization to access customer accounts. The appellate panel instead concluded that the user accessed Amazon with help from the AI tool.
The user was the accessor on this record
The opinion says the Assistant takes screenshots of the user's browser view, sends them to Perplexity's servers, and receives navigation instructions. Even with that server-side involvement, the panel found that Perplexity had not gained entry to Amazon's servers on the facts before it.
The court also rejected treating the software itself as the statutory actor. It wrote that the CFAA contemplates access by a person and described the Assistant as a tool, not a person for statutory purposes. That made the agent's own intent irrelevant to the access question in this case.
EFF, which filed an amicus brief supporting Perplexity, said the decision adopted its explanation that Comet users operate the tool. Techdirt's analysis likewise emphasizes the distinction between a user-operated browser agent and a provider independently directing automated access.
A narrow ruling, not blanket permission
The panel did not establish a general legal regime for agentic AI. It expressly limited the holding to CFAA access and the Assistant's interactions with Amazon on the existing record. It left open other claims, different facts, and situations in which a provider exercises greater control over an agent.
The ruling therefore does not mean every automated action is authorized or that agent builders cannot face liability. It narrows one asserted federal anti-hacking theory at the preliminary-injunction stage.
For teams building browser agents, the operational boundary is important: document who initiates a task, where execution occurs, what credentials are used, what server-side instructions are issued, and how a site communicates access restrictions. Those facts can affect whether a tool is characterized as helping a user act or as a provider's own automated access. The opinion offers a concrete framework for this dispute while warning that the legal treatment of more autonomous systems may change as the technology develops.
Key Points
- 1The Ninth Circuit vacated Amazon's preliminary injunction and found the company unlikely to prove Perplexity accessed its computers under the CFAA.
- 2The court treated the user as the accessor and described the Assistant as a tool rather than a statutory person.
- 3The holding is limited to the CFAA access question and the existing record, leaving other claims and different agent-control facts open.
Scoring Rationale
The opinion is a notable appellate interpretation of how the CFAA's access element applies to a user-operated browser agent. Its practical importance is high for agent builders, but the ruling is preliminary and expressly limited to the current record.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
