US Appeals Court Rules AI Agent's Website Actions Are Legally Attributed to the User
In a landmark dispute between Amazon and Perplexity, the Ninth Circuit ruled that a customer using an AI assistant to navigate Amazon is the party accessing the website under federal computer-access law, overturning an injunction against Perplexity.
A federal appeals court has delivered one of the first major US rulings defining who legally acts when an artificial-intelligence agent operates on a person's behalf, holding that an Amazon customer using Perplexity's AI assistant was the party accessing Amazon's computers — not Perplexity itself.
The US Court of Appeals for the Ninth Circuit issued the decision on August 4 in Amazon.com Services v. Perplexity AI, a closely watched case over Perplexity's Comet browser and its AI Assistant.
The software can navigate websites and carry out tasks at a user's direction, including searching for products and assisting with purchases on Amazon.
The ruling does not establish the much broader proposition that a person is automatically liable for everything an autonomous AI agent does.
Nor did the court decide that an AI agent can never violate computer-access laws.
Its narrower and potentially important holding concerns attribution: on the facts before the court, the human customer was the person who accessed Amazon, while Perplexity's Assistant functioned as a tool used by that customer.
Amazon had sued Perplexity after objecting to Comet's access to its platform, including password-protected customer accounts.
Amazon argued that Perplexity continued accessing its systems despite restrictions, technical countermeasures and demands that it stop.
A federal district judge in California initially sided with Amazon at the preliminary stage, finding Amazon likely to succeed on claims under the federal Computer Fraud and Abuse Act and California's corresponding computer-access law.
The district court granted a preliminary injunction restricting Perplexity's use of Comet on Amazon.
Perplexity appealed, arguing that this interpretation confused a user's chosen software tool with the person actually accessing the website.
The Ninth Circuit stayed the injunction while considering the appeal and has now vacated it.
The appellate court's reasoning centered on the meaning of the word 'access.' To establish the relevant Computer Fraud and Abuse Act claim, Amazon needed to show, among other elements, that Perplexity intentionally accessed a protected computer without authorization or by exceeding authorized access and obtained information from it.
The Ninth Circuit concluded that Amazon was unlikely to prove the crucial first proposition: that Perplexity itself performed the access.
The court distinguished between software carrying out a user's commands and a separate actor independently entering another company's computer system.
In the transactions examined by the court, users directed the Assistant to perform specific actions on Amazon.
The AI tool interacted with Amazon's website to accomplish those instructions, but the court treated those interactions as the users' access.
In practical terms, using an AI agent did not automatically insert the software provider as a separate legal visitor between the customer and the website.
That distinction has potentially broad consequences for the emerging agentic-AI industry.
AI systems are rapidly moving beyond answering questions and generating text toward software capable of navigating websites, filling forms, comparing products, booking services and conducting transactions.
If every automated interaction were automatically treated as access by the AI developer rather than by the person directing the software, existing computer-hacking statutes could place significant restrictions on agentic browsers and other digital assistants.
The decision therefore offers an important legal analogy between AI agents and other tools people use to interact with computers.
A conventional browser sends requests to websites on a user's behalf, as do password managers, accessibility software and other automated tools.
The Ninth Circuit's approach indicates that the presence of increasingly sophisticated automation does not by itself determine who legally performed the access.
But the judgment should not be interpreted as giving AI agents unrestricted authority to operate anywhere their users choose.
The decision arose from an appeal concerning a preliminary injunction, not a final judgment after a full trial.
The court vacated the injunction and sent the case back to the district court for further proceedings.
The ruling also does not create a general doctrine under which users are necessarily responsible for every unforeseen action taken by autonomous software.
Questions involving an agent exceeding a user's instructions, committing a tort, entering a binding contract, causing financial loss or performing an unlawful act can involve different statutes and legal doctrines.
Those questions were not resolved by this case.
The immediate decision is instead significant because of what the court did determine under the Computer Fraud and Abuse Act.
For the interactions in the record, the user was accessing Amazon with the assistance of an AI tool.
Perplexity was not independently accessing Amazon merely because its software helped execute the user's commands.
That conclusion also undermined Amazon's parallel claim under California's Comprehensive Computer Data Access and Fraud Act.
The Ninth Circuit concluded that Amazon was unlikely to succeed on that claim for essentially the same reason: the user, rather than Perplexity, was accessing Amazon through the Assistant.
The court additionally rejected the lower court's assessment of the remaining factors required for a preliminary injunction.
It concluded that the balance of potential harms did not justify blocking Perplexity's tool while the litigation proceeded and therefore vacated the injunction in full.
The ruling creates an important early precedent as courts confront the transition from software that merely provides information to software that takes actions.
It establishes that courts cannot simply assume that an AI company itself 'accesses' every computer touched by an agent operating at a customer's direction.
They must examine who directed the interaction, what the software actually did and how the relevant law defines access.
For companies developing AI agents, platforms attempting to control automated traffic and consumers delegating online tasks to software, those distinctions are becoming increasingly consequential.
Amazon's underlying lawsuit continues after the appellate court's remand, but the Ninth Circuit has now supplied an influential starting point for future disputes: when a person directs an AI assistant to interact with a website as a tool on that person's behalf, the user's actions do not automatically become the AI provider's access simply because artificial intelligence performed the clicks.