The short version: On August 4, 2026, the Ninth Circuit Court of Appeals lifted a block on Perplexity’s Comet browser, holding that AI shopping agents do not “access” a website under the federal anti-hacking law. The person who told the agent what to do is the one doing the accessing. The agent is a tool. That distinction protects the companies building these things, and it quietly moves responsibility onto whoever points the tool. For a small business owner, that is both halves of the story.
The case started the way these cases usually start. Amazon sued Perplexity over Comet, an AI browser whose assistant can log into your accounts and buy things on your behalf. Amazon argued this was unauthorized access under the Computer Fraud and Abuse Act, the 1986 statute that still does most of the work in American computer law. A district court agreed enough to issue a preliminary injunction. Comet was barred from Amazon.
A three-judge panel vacated that order. Judge Milan D. Smith, Jr. wrote the opinion in case number 26-1444, and the reasoning is worth more attention than the outcome.
What did the court actually decide?
The panel found Amazon unlikely to win its CFAA claim, because Perplexity never accessed anything. The user’s own browser visits Amazon. It captures what is on the screen and forwards it. Perplexity’s servers receive what the user sends them. Under that description, the company operating the model is several steps removed from the act the statute punishes.
The court was candid that it was working without a map. It noted there is little to no existing caselaw on how to assign responsibility for AI agents under the statute, and applied the rule of lenity, the principle that genuinely ambiguous criminal law gets read against liability rather than for it. The Electronic Frontier Foundation filed a brief in the case, and the panel said EFF’s description of how the system works articulated it most clearly. The conclusion the court reached: the assistant is a tool, not a person for statutory purposes.
Why does “tool, not a person” matter so much?
Most of the coverage framed this as a win for AI agents. That reading is not wrong, but it is shallow, and it misses what the court declined to do.
The panel had an option available to it. It could have treated the agent as an independent actor, something that goes out into the world and does things on its own account. Courts reach for that framing often, because it is intuitive and because the marketing around agentic AI invites it. The panel refused. It looked at software that can log into accounts, read pages, and complete purchases without a human touching the keyboard, and it still called that a tool operated by a person.
This is the same principle that ought to govern how you deploy AI inside your own business, and it is unusual to see it stated this plainly by a federal appeals court. The agent is not a replacement for a person. It is a person’s reach, extended. Someone is still holding it.
What changes if AI shopping agents visit your website?
If you sell anything online, the practical takeaway is narrow but real: the CFAA is not going to keep agents off your site for you.
That does not mean you have no options. It means the question moved from federal criminal law down to layers you actually control. Your terms of service still govern, and most terms inherited their automated-access language from an era before any of this existed, which means yours probably says something you did not mean and does not say the thing you now need. Your robots.txt and your bot management rules still work, and they can be audited against the agent user-agents that actually exist today rather than the crawlers you configured for years ago.
There is a strategic choice underneath the technical one, and it deserves a real decision rather than a default. You can welcome user-directed agents, on the theory that a customer who sends an agent to buy from you is still a customer buying from you. You can block them and accept that some of those customers go somewhere that does not. Or you can build a sanctioned path, an API or a clean surface an agent can use without pretending to be a logged-in human. Most small businesses will land on welcome, not because it is bold but because the alternative is refusing revenue that has already decided to arrive.
What changes if you are the one using AI shopping agents?
Here is the part that got almost no coverage, and it is the part with your name on it.
The court’s reasoning locates the act with the user. When your agent logs into a supplier portal, pulls pricing, and places an order, the reasoning that just protected Perplexity says that you visited that portal. You placed that order. The vendor built the tool. You operated it.
Be careful about how far that travels. This was a ruling about one word in one hacking statute, at the preliminary stage of one case. It is not a holding that users are on the hook for every term of service their agent brushes past. But the direction is not subtle, and if you were assuming that the AI company absorbs the consequences of what its agent does on your instruction, that assumption just got weaker rather than stronger.
Which is the same lesson that keeps arriving from different directions. We covered it when Google put computer use directly into Gemini and agents started clicking real buttons on real screens, and again when Claude Cowork and ChatGPT Work put that capability in front of ordinary business users. The capability question was settled a while ago. The question now is scope, and scope is your job.
What the ruling did not decide
Worth being precise, because a vacated injunction is not a verdict.
The panel addressed the CFAA claim and found Amazon unlikely to succeed on it. Amazon may still have other theories available, and EFF said as much in its own write-up of the win. Contract and terms-of-service claims live in a different body of law than federal anti-hacking statutes, and nothing here forecloses them. The case is not over. And the Ninth Circuit covers nine states, so other circuits are free to look at the same question and answer it differently, which is how a matter like this eventually reaches the Supreme Court.
What to do this week
Two things, and neither takes long.
If you run a site that takes orders, open your terms of service and read the automated-access clause out loud. If it was written before 2024, it is describing scrapers and screen-scrapers, not a customer’s assistant checking out with the customer’s own credentials. Decide which of those you actually want to prohibit, and write that.
If you use agents against other companies’ systems, write down which systems they are allowed to touch and what they are allowed to do there. Not because a court has told you to, but because the reasoning in this opinion says the answer to “who did that” is going to be you, and you would rather that answer be one you chose in advance. That is the same permissions discipline worth applying before you give any AI tool more access than it needs.
The interesting thing about this ruling is how ordinary its logic is. A federal appeals court looked at the most autonomous consumer software anyone has shipped, and described it as a tool that a person picks up. Not a worker. Not an actor. A tool, with someone’s hand on it. Nearly every hard question about deploying this technology gets simpler once you accept that framing, and most of the confusion in the market right now comes from people who have not.
Frequently Asked Questions
Can I legally block AI shopping agents from my website?
Yes. The ruling did not create a right for agents to access your site. It held that the federal anti-hacking statute is not the tool for keeping them out, because the user rather than the AI company is the one accessing. You can still restrict agents through your terms of service, your robots.txt file, and your bot management or firewall rules, which is where that decision now sits.
Does this mean my business is liable for what our AI agent does?
Not automatically, and the court did not rule on user liability. What it did was locate the act of accessing with the person operating the agent rather than the company that built it. That reasoning points toward the operator carrying more responsibility than the vendor, so the prudent assumption is that what your agent does on someone else’s system is treated as something you did.
Is the Amazon versus Perplexity case over?
No. The Ninth Circuit vacated a preliminary injunction, which is an early-stage order, and it addressed only the claim under the Computer Fraud and Abuse Act. Amazon may pursue other legal theories such as breach of contract or terms of service, and those sit in a different body of law that this ruling did not touch.
Should small businesses welcome or block AI shopping agents?
For most small businesses, welcoming them makes more sense than blocking them, because an agent sent by a customer is still a customer trying to buy from you. The better move is to make the decision deliberately rather than inheriting it from a firewall rule you configured years ago, and to update your terms of service so they describe user-directed agents rather than the scrapers they were originally written for.
We keep watching courts and regulators try to fit AI into words written for a different era, and this one landed on “tool” rather than “actor.” If a customer sent an agent to buy from you tomorrow, would you want it let through the door, and does your site currently agree with your answer?
