On August 4, 2026, the Ninth Circuit handed down the first federal appellate decision on who is legally responsible when an AI agent goes to work on someone else’s website — and the answer should send every business owner straight to their AI agent terms of service. In Amazon.com Services, LLC v. Perplexity AI, Inc., the court vacated an injunction that had blocked Perplexity’s Comet browser from shopping on Amazon, holding that when a user points an AI agent at a website, it is the user who accesses that site — not the AI company.
We picked this one up from Dr. Alex Wissner-Gross’s August 5 edition of The Innermost Loop, which flagged it as the first appellate holding that an AI acting on your behalf is you.

What the Ninth Circuit Actually Held
Amazon sued Perplexity in November 2025 in the Northern District of California, claiming that Comet’s “Assistant” feature logged into customers’ password-protected Amazon accounts and shopped on their behalf without identifying itself as a bot. Amazon’s theory ran under the federal Computer Fraud and Abuse Act (CFAA) and its California analogue, the Comprehensive Computer Data Access and Fraud Act. Judge Maxine M. Chesney granted a preliminary injunction in March 2026.
The Ninth Circuit vacated it. The panel — Judges Milan D. Smith, Jr. and Eric C. Tung, plus District Judge John Charles Hinderaker sitting by designation — found Amazon unlikely to succeed on the threshold question of who “accessed” the servers.
The reasoning turns on plumbing. Comet runs on the user’s own machine. It screenshots the browser view, sends those screenshots to Perplexity’s servers, and gets navigation instructions back. As the court put it, “Perplexity itself does not directly communicate with Amazon’s servers.” Everything routes through the user’s computer.
From there the statute did the work. The CFAA punishes “whoever” intentionally accesses a protected computer, and, in the panel’s words, “However advanced the Assistant currently is, it is a tool, not a person for statutory purposes.” So: “It is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com.”
One more piece deserves attention, because it explains the outcome. The court invoked the rule of lenity and noted that Amazon’s reading “could expose users themselves to criminal liability (under a conspiracy or aiding-and-abetting theory).” The theory that would have caught Perplexity would have caught Perplexity’s customers too. That is a large part of why it failed.
What the Court Was Careful Not to Say
Read past the headlines. The panel wrote plainly: “We do not establish a new legal regime governing agentic AI.” The holding is limited to the word “access” in two anti-hacking statutes, on this record, at the preliminary-injunction stage. The court expressly reserved tort and contract theories, and flagged that an agent with more autonomy — or one whose servers talk directly to the target site — could come out the other way.
So “an AI acting for you is legally you” is a fair shorthand for the CFAA question and an overstatement of everything else. The distinction matters, because the part the court left standing is the part that lands on your desk.
What It Means for Your Business
Two groups of business owners should care about their AI agent terms of service, and most of our clients are in both.
If you run a website, client portal, or customer account system, the CFAA just got much weaker as a tool for keeping unwanted bots out of logged-in areas. That statute was the big stick — criminal exposure, a private right of action, a $5,000 loss threshold that is easy to clear. In the Ninth Circuit, on these facts, it no longer reaches the AI company. Your AI agent terms of service have to do that work instead.
If your team uses AI agents on other companies’ platforms, the same logic runs at you. Your employee directing an agent into a vendor portal, a competitor’s site, or a data source is, on this reasoning, the one doing the accessing. You do not get to point at the AI vendor. Whatever that account’s terms of service say, your business agreed to them.
The commercial stakes were not lost on anyone. The National Retail Federation, News/Media Alliance, and Airlines for America filed amicus briefs on one side; the Electronic Frontier Foundation, Mozilla, the ACLU, and Columbia’s Knight First Amendment Institute weighed in on the other. Entire industries understood this was about who controls automated access to their platforms.
The Legal Impact: Your AI Agent Terms of Service Just Became the Main Event
Footnote 5 of the opinion is the sentence to circle: “This outcome does not impair Amazon’s ability to regulate access to Amazon.com via private terms of service for its users.”
Translated: the court took away the federal hammer and handed you a contract. Your AI agent terms of service are now the primary enforcement mechanism you have — and for most businesses we see, that document was written before agentic AI existed and says nothing useful about it.
Contracts and Commercial Terms
Most terms of service prohibit “scrapers,” “robots,” and “automated means.” Courts read those words against the drafter, and an AI assistant a customer runs on their own laptop is a genuinely different animal from a crawler. If your prohibition does not describe agentic tools, assume it does not cover them. The same drafting gap runs through master service agreements and statements of work that assume a human on the other end of every login — which is why we are rewriting AI agent terms of service alongside the commercial contracts they sit next to, not in isolation.
Employment and Internal Policy
This is the exposure business owners underrate. Your AI agent terms of service govern the agents coming in; your handbook governs the ones your own people send out. If the user is the accessor, then your employees’ agent use is your access, your breach, and your liability. Very few employee handbooks say anything about pointing an autonomous tool at a third party’s system. That is now a policy gap with contract and tort consequences attached.
Vendor Diligence and AI Contracts
The case turned on an architectural fact: client-side relay versus direct server-to-server contact. That is now a legal question, and it belongs in your diligence alongside your AI agent terms of service review. AI vendor contracts should carry representations about how the tool connects, notice if that architecture changes, and indemnity for third-party terms-of-service claims arising from the vendor’s design. We covered the broader allocation problem in our piece on AI agent liability.
Healthcare, Financial Services, and Other Regulated Portals
If your portal holds protected health information or financial account data, an agent reading a logged-in page is reading regulated data — and your access controls, business associate agreements, and audit obligations do not care that the CFAA came up short. Regulated operators should treat this as an access-control and vendor-management issue first, and a litigation issue second.
5 Critical Fixes to Make This Quarter
- Draft real AI agent terms of service — not a bot clause from 2019. Define automated agents to include AI assistants operating at a user’s direction. State whether they are permitted, and condition permission on identification (a declared user-agent string), rate limits, and no circumvention of blocking. Amazon’s entire complaint started with Perplexity declining to identify itself.
- Decide your actual policy before you draft it. A blanket ban is easy to write and bad for business — agentic commerce is coming to your customers whether you like it or not. Permissioned, identified, rate-limited access is usually the better commercial answer, and your AI agent terms of service should say so plainly. That is far more defensible than a prohibition you do not enforce.
- Add agent conduct to your employee acceptable-use policy. Tell your people which platforms they may point agents at and require them to read the counterparty’s terms first. Under this ruling, their conduct is your access. Handbook language is cheap; a tortious interference claim is not.
- Put architecture representations in your AI vendor agreements. Ask how the agent reaches third-party sites, get it in writing, get notice of material changes, and get indemnity for terms-of-service claims traceable to the vendor’s design.
- Preserve the theories you have left — and the evidence. Breach of contract, tortious interference, and trespass to chattels all survived this opinion. They all require proof: server logs, blocking attempts, notice letters, and records of loss.
If you plan to enforce, start keeping the file now, and talk to the commercial litigation team at Howard Law Group before you send the first cease-and-desist.
What Howard East Clients Should Do Now
Start with a one-hour inventory. Pull your current terms of service and search it for “robot,” “bot,” “automated,” and “agent.” If the answer is boilerplate from a template, your AI agent terms of service are the first project on the list.
Next, ask your operations lead a simple question: which AI tools are our people already running against outside platforms? The honest answer is usually longer than management expects, and it tells you which counterparty agreements to read this month.
Then check whether the authority to accept those platforms’ terms is even properly delegated in your governing documents, and whether your website’s legal posture has been reviewed at all in the last year.
Call a lawyer when any of these are true: you want to block or permit agents and need enforceable AI agent terms of service; you have already sent or received a demand letter about automated access; you are buying or selling a company whose product touches third-party platforms; or you operate a regulated portal where agent access implicates HIPAA, GLBA, or state privacy law.
Howard East advises business owners on commercial contracts, employment policy, technology agreements, and M&A across the East Coast and the Midwest. If your AI agent terms of service have not been looked at since agents became real, that is a short engagement with an outsized return. Book a consultation and we will start with the inventory.
Sources
- Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026) — full opinion
- 18 U.S.C. § 1030 — Computer Fraud and Abuse Act
- Cal. Penal Code § 502 — Comprehensive Computer Data Access and Fraud Act
- Van Buren v. United States, 593 U.S. 374 (2021)
- The Innermost Loop, “Welcome to August 5, 2026” by Dr. Alex Wissner-Gross
This article is for informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship. Outcomes depend on your specific facts and jurisdiction; the Ninth Circuit’s holding is binding only in that circuit and was issued at the preliminary-injunction stage.


