On August 4, 2026, the U.S. Court of Appeals for the Ninth Circuit issued a published decision addressing who “accesses” a website when a person directs an artificial-intelligence agent to act online. In Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026), the court held, on the preliminary record before it, that the user — not Perplexity — accessed Amazon’s computers with the help of Perplexity’s AI Assistant.
The decision does not create a comprehensive liability regime for AI agents. It interprets the “access” requirement under the federal Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer Data Access and Fraud Act (CDAFA). Even so, the decision matters to businesses that deploy AI agents, build agent features, or receive agent-mediated traffic. Read together with California Civil Code section 1714.46 and Executive Order 14409, it reinforces the need to identify who directs an agent, what the agent is authorized to do, and how contracts allocate the resulting risks.
What Happened in Amazon v. Perplexity?
Perplexity’s Comet browser includes an optional AI Assistant that can perform tasks at a user’s direction, including navigating websites to shop for requested products. According to the Ninth Circuit’s account, the browser communicates with Amazon’s servers from the user’s computer; the Assistant analyzes information displayed in the browser and may communicate with Perplexity’s servers for instructions. Perplexity’s servers did not directly access Amazon’s servers on the record before the court. Amazon v. Perplexity.
Amazon sued under the CFAA and CDAFA and obtained a preliminary injunction in the Northern District of California. The Ninth Circuit vacated that injunction and remanded the case. It concluded that Amazon was unlikely to establish the required “access” by Perplexity under either statute at that stage of the litigation. Amazon v. Perplexity.
The panel’s central distinction was between the person using the system and the software assisting that person:
“However advanced the Assistant currently is, it is a tool, not a person for statutory purposes.”
The court then explained:
“It is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com.”
Those conclusions were tied to the technology and record presented in this preliminary-injunction appeal. The court expressly left open whether different facts — such as evidence that the developer exercised greater control over an agent — could produce a different result. Amazon v. Perplexity.
Did the Ninth Circuit Make AI Agents Legal Everywhere?
No. The court emphasized the narrow scope of its ruling:
“We do not establish a new legal regime governing agentic AI.”
It also stated that it was not deciding whether Perplexity could avoid liability for the Assistant’s actions in other contexts, including tort claims. The holding addressed “access” under the CFAA and CDAFA, as applied to the Assistant’s interactions with Amazon on the record then before the court. The case continues after remand. Amazon v. Perplexity.
Three limits are especially important.
1. The ruling concerns two anti-hacking statutes
The decision does not resolve questions involving negligence, product liability, privacy, intellectual property, deceptive practices, or contract law. Nor does it establish that every agent-mediated interaction is authorized. It decides a particular statutory element — who accessed the computer — on a preliminary record.
2. A different technical design or factual record could matter
The panel did not decide whether Perplexity could be found to access Amazon’s systems if evidence later showed that Perplexity exercised enough control over the Assistant to gain entry to Amazon’s servers. Businesses should therefore avoid treating the opinion as a categorical immunity for AI developers or vendors. Amazon v. Perplexity.
3. Private terms of service remain relevant
In a footnote, the court stated:
“This outcome does not impair Amazon’s ability to regulate access to Amazon.com via private terms of service for its users.”
That observation does not establish that every terms-of-service restriction is enforceable in every circumstance. It does, however, underscore that contract terms may remain important even when an anti-hacking claim does not succeed. Amazon v. Perplexity.
Deploying AI agents in your business?
We’ll help you map what your agents can do, review the platform terms that apply, and put the risk allocation in writing — with an attorney licensed in AZ, CA & TX.
California Limits the “The AI Did It” Defense
California has separately addressed one potential defense in civil litigation involving AI. Assembly Bill 316, approved on October 13, 2025, added Civil Code section 1714.46.
The statute applies in an action against a defendant who developed, modified, or used AI that allegedly caused harm to the plaintiff. It provides:
“[I]t shall not be a defense, and the defendant may not assert, that the artificial intelligence autonomously caused the harm to the plaintiff.”
The statute does not eliminate all defenses. It expressly preserves other affirmative defenses, including evidence relevant to causation or foreseeability, as well as evidence concerning another person’s or entity’s comparative fault. Cal. Civ. Code § 1714.46.
The careful takeaway is not that every act of an AI agent automatically becomes the user’s legal act for every purpose. Rather, California defendants covered by section 1714.46 cannot rely on the AI system’s autonomy, standing alone, as a defense. Liability still depends on the applicable cause of action, facts, causation rules, defenses, and allocation of fault.
The Federal Enforcement Layer
On June 2, 2026, the President signed Executive Order 14409, “Promoting Advanced Artificial Intelligence Innovation and Security”. The order was published in the Federal Register on June 5, 2026.
Section 4 directs the Attorney General to prioritize enforcement of federal criminal laws against persons who use AI to access or damage computers illegally or without authorization, or who use AI during illegal access to further another crime. The order specifically refers to “employing AI agents to unlawfully access data or information that is subsequently used for a criminal or unlawful purpose.” Exec. Order No. 14409 § 4.
An executive order does not amend the elements of the CFAA or displace the Ninth Circuit’s interpretation. It sets enforcement priorities within the executive branch. Businesses should therefore distinguish between the Ninth Circuit’s interpretation of statutory “access” in a civil preliminary-injunction dispute and the federal government’s stated enforcement focus on criminal misuse of AI.
What Should a Business Deploying AI Agents Do?
The Ninth Circuit’s decision makes governance and documentation more — not less — important. A business deploying AI agents should consider the following measures.
Inventory what the agent can do
Identify whether an agent can browse, scrape, purchase, submit forms, send messages, access accounts, retrieve data, or take other external actions. Document which systems it may access, whose credentials it uses, and which actions require human approval.
Define authority and escalation rules
Specify who may instruct the agent and the limits of that authority. Use approval gates for purchases, account changes, external communications, data transfers, and other consequential actions. Maintain escalation procedures for unexpected conduct.
Review the terms governing third-party platforms
Before deploying an agent on a third-party website or service, review the applicable terms of service, acceptable-use rules, API conditions, and restrictions on automated access. The Ninth Circuit’s decision narrowed Amazon’s preliminary CFAA and CDAFA theories; it did not erase private contractual restrictions.
Address agent risk in vendor contracts
Contracts for AI-agent technology should clearly address:
- the agent’s intended functions and technical limitations;
- compliance with customer instructions and third-party platform rules;
- agent identification and disclosure practices;
- logging, audit rights, and incident notification;
- security controls and credential handling;
- responsibility for unauthorized or out-of-scope actions;
- indemnification, liability limitations, insurance, and remedies, as appropriate to the transaction; and
- suspension or termination if a platform blocks or objects to the agent.
These provisions should be tailored to the product, use case, bargaining position, and applicable law — not copied from a generic AI template. Our guide to AI vendor contract questions covers the diligence conversation in more detail.
Preserve meaningful records
Logs may help establish who instructed the agent, what information the agent received, what action it took, and whether a human approved or stopped the action. Retention practices should account for privacy, security, litigation-hold, and regulatory requirements.
What Should a Business Receiving AI-Agent Traffic Do?
Businesses operating websites, marketplaces, and software platforms should evaluate both contractual and technical controls.
State the rules clearly
If automated or agent-mediated activity is restricted, address it expressly in the terms users accept. Define prohibited conduct with enough precision to distinguish disallowed automation from permitted accessibility tools, browsers, APIs, integrations, and customer-directed agents.
Align terms with technical controls
Consider whether agents must identify themselves, use approved APIs, comply with rate limits, or obtain advance authorization. Technical measures and written terms should support the same policy.
Decide how violations will be handled
Establish proportionate responses, such as warnings, rate limits, credential revocation, account suspension, blocking, investigation, or contractual remedies. Coordinate those measures with privacy, consumer-protection, accessibility, competition, and other applicable requirements. Our guide to customer contract terms for AI products addresses the drafting side.
Building Contractual Guardrails for AI Agents
Businesses adopting agentic AI should not wait for a comprehensive statutory framework before defining authority, oversight, technical controls, and contractual risk allocation. The immediate questions are practical: What may the agent do? Who directs it? Which third-party rules apply? What records will show what happened? And who bears the risk if the agent operates outside its instructions?
Accord & Shield Legal, PLLC advises businesses on AI vendor agreements, customer-facing AI terms, technology transactions, and governance frameworks. To discuss contractual safeguards for an AI deployment, contact the firm to schedule an initial consultation.
Frequently Asked Questions
Did the Ninth Circuit authorize AI agents to access any website?
No. The court decided that Amazon was unlikely, on the preliminary record, to prove that Perplexity itself “accessed” Amazon’s computers under the CFAA or CDAFA. It did not confer a general right to use AI agents on any website or override applicable contracts and other laws. Amazon v. Perplexity.
Can a business still restrict AI-agent activity through its terms?
Potentially. The Ninth Circuit expressly stated that its outcome did not impair Amazon’s ability to regulate access through private terms of service for users. Whether a particular restriction is enforceable will depend on the terms, assent, facts, remedy sought, and applicable law. Amazon v. Perplexity.
Can a California defendant argue that an AI system acted autonomously?
A defendant covered by California Civil Code section 1714.46 may not assert that the AI autonomously caused the plaintiff’s harm as a defense. The statute preserves other defenses and evidence concerning causation, foreseeability, and comparative fault. Cal. Civ. Code § 1714.46.
Is Amazon v. Perplexity the final word?
No. The Ninth Circuit reviewed a preliminary injunction, vacated it, and remanded for further proceedings. Its holding is tied to the record and technology presented at that stage. Amazon v. Perplexity.
Sources
This information is current as of August 2026.
This article is provided for general informational purposes only and does not constitute legal advice. Reading this article or contacting Accord & Shield Legal, PLLC does not create an attorney-client relationship. Laws, judicial decisions, technologies, and enforcement priorities can change, and their application depends on specific facts and jurisdictions. Do not act or refrain from acting based on this article without obtaining advice from qualified counsel regarding your circumstances. This material may be considered attorney advertising in some jurisdictions. Past results do not guarantee future outcomes.