- The Ninth Circuit vacated an injunction against Perplexity's Comet Assistant, holding the user, not Perplexity, 'accessed' Amazon's servers under the CFAA.
- The ruling is narrow and leaves terms-of-service claims open, but it shows that where an agent runs can shape legal exposure.
- Platforms should ask whether they offer an official agent interface. AI builders should ask where their agent's session actually runs.
When you tell software to buy something for you, who is doing the shopping? A U.S. appeals court has given a partial answer. The answer depended less on what the software meant to do than on how it was wired.
What the court decided
Amazon sued Perplexity AI in November over Comet, Perplexity's browser, and its 'Assistant' feature. A conventional scraper only collects text. The Assistant behaves more like a human errand-runner. It can sign in as the user, weigh items against each other, load a basket, key in payment details and finish the checkout on its own.
Amazon's complaint was that users gave permission, but Amazon did not. It sued under the U.S. Computer Fraud and Abuse Act (CFAA) and California's Comprehensive Computer Data Access and Fraud Act.
This analysis draws on a commentary in The Hindu by Krishna Ravi Srinivas, Feba Sara and Gaurangi Kapoor. They report that on March 9 the trial judge granted a preliminary injunction. The judge's reasoning was that Amazon's users agreeing to the Assistant made no difference. Amazon had not authorised it.
On August 4, three Ninth Circuit judges set that order aside. They found that the person who 'accessed' Amazon's servers was the user. Perplexity's own systems never made direct contact with Amazon's.
How the design decided the case
The commentary describes a two-hop design. The user's browser talked directly to Amazon. Perplexity's servers, working from screenshots, talked only to the user's own device.
That is the opposite of a service that keeps its own logins with retailers and sends requests from its own servers. The authors note the panel distinguished an earlier case, Facebook v. Power Ventures, where a third party's servers contacted Facebook directly. In their view, a centralised service holding its own sessions with retailers 'would likely have fared differently'. That is the authors' reading, not a holding.
What the ruling does not settle
The authors call the ruling narrow. The panel ruled only on the meaning of 'access' under the CFAA. It did not decide whether the Assistant broke Amazon's terms of service. The panel noted that other legal theories, such as breach of those terms, 'may remain available'.
The commentary reports the panel's ruling on 'access' under the CFAA. It does not say how Amazon's California state-law claim fared. Nor does it say the panel settled whether agents may shop on Amazon's site.
The lesson: architecture is now a legal position
Here is the idea worth keeping. For an AI agent, the place where it runs is a legal choice as well as an engineering one. Run in the user's own session, and the court treated the user as the one acting. Run from a vendor's servers, and the vendor may be the one answering.
The same logic reaches the platforms. The authors argue that terms of service are 'a weak and largely untested line of defence' against agents. Amazon did not build its claim on them. They urge platforms to offer official agent interfaces with limits, such as caps on requests per minute and ways to turn away suspicious bots.
They also note that agents read a page's underlying structure, not its visual layout. They may skip banner ads and sponsored placements built for human attention. An official interface could protect that revenue.
Why this matters beyond the U.S.
The authors apply the case to India, citing a May 2026 ICICI Securities report. It put Flipkart at 50-60% of Indian e-commerce gross merchandise value and Amazon at 25-30%. They argue that a dominant platform blocking third-party agents while promoting its own assistant could draw scrutiny from the Competition Commission of India.
They also warn that Indian courts could read 'unauthorised access' broadly. That would give dominant platforms a ready tool against agent-based competitors. These are the authors' arguments about Indian law. No Indian court has ruled on this.
Questions to put to your team
If you run a retail or booking platform: do we know how much of our traffic comes from agents? Do we offer an official, rate-limited way for them to act? Or do we rely on terms that no court has tested against them?
If you build or buy agent tools: does the agent act inside the user's own session, or from our servers? Ask counsel what that difference means for liability before it appears in a complaint.
One narrow ruling does not settle who controls an agent. It does show that the answer may be built into the wiring.
Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: The Hindu.





