There is a sentence in the Ninth Circuit’s August 4, 2026 opinion in Amazon.com Services, LLC v. Perplexity AI, Inc. that will be quoted in every agentic commerce legal memo for the next decade: “[T]he CFAA contemplates access by a person.” Six words, and with them a panel led by Circuit Judge Milan D. Smith, Jr. dismantled the most aggressive legal theory any platform has yet deployed against the AI agent economy.
The court vacated the preliminary injunction that had barred Perplexity’s agentic Assistant, part of its Comet browser, from touching Amazon’s logged-in pages. In doing so it held that Amazon was unlikely to succeed on claims under the federal Computer Fraud and Abuse Act and California’s CDAFA, because Perplexity never “accessed” Amazon’s computers at all. The person who did was the shopper.
The industry read that as a green light, and in a narrow sense it is. But the ruling settles exactly one question: who may lawfully enter the store. It says nothing about whether the store has to show the agent honest shelves. And Amazon has spent the past year making sure it does not have to.
Nine Months from Lawsuit to Reversal
The timeline matters, because for most of this year the law pointed the other way.
- November 2025: Amazon sued Perplexity in the Northern District of California, case No. 3:25-cv-09514. The theory: Comet’s Assistant accessed password-protected Amazon accounts to browse and buy on users’ behalf, without identifying itself as an AI agent, in violation of Amazon’s terms of service, and that conduct violated the CFAA and California’s Comprehensive Computer Data Access and Fraud Act.
- March 9, 2026: US District Judge Maxine M. Chesney granted Amazon’s preliminary injunction, finding Amazon likely to succeed because Perplexity’s access was not authorized by Amazon, regardless of whether the users themselves had permitted the Assistant into their own accounts. For five months, the injunction stood. The Ninth Circuit stayed it pending appeal.
- April 9, 2026: The Electronic Frontier Foundation filed an amicus brief, with other public-interest groups, arguing the architectural point that would eventually win: “Developers like Perplexity facilitate that access by creating tools that enable users to meaningfully engage with the web.”
- June 11, 2026: Oral arguments in Seattle.
- August 4, 2026: The panel vacated the injunction and remanded. Amazon’s likelihood of success on the CFAA and CDAFA collapsed.
The same week this was happening, The Verge was reporting that Amazon shoppers had been locked out of their own review data since late 2025, mistakenly flagged as bots. Two stories, one theme: the fight over who gets to look at Amazon, and at what.
What the Court Actually Held
Strip away the procedural framing and the holding rests on a technical distinction that every agent developer should now treat as gospel.
To win a CFAA claim, a plaintiff must show the defendant intentionally accessed a computer without authorization, obtained information from a protected computer, and caused at least $5,000 in aggregate loss within a year. The panel focused on the threshold element: what counts as “access”? The court read the statute to mean “entering a computer system itself,” and its use of “whoever” to contemplate access by a person, not a software tool. On the record before it, “it was the user who ‘accessed’ Amazon’s computers, with the help of Perplexity’s AI agent, the ‘Assistant,’ to carry out specific acts on Amazon.com.”
The architecture decided the case. When a user directs the Assistant to shop, it takes screenshots of the browser view on the user’s own machine, sends them to Perplexity’s servers, and receives navigation instructions back. As Cooley’s analysis of the decision puts it, “Perplexity itself does not directly communicate with Amazon’s servers.” Everything passes through the user’s computer. The panel distinguished Facebook, Inc. v. Power Ventures, where the defendant’s own systems transmitted messages directly onto Facebook’s platform. The relay is the moat.
Two further points sealed it. The court applied the rule of lenity, following its precedent in Brekka: because the CFAA is primarily a criminal statute, ambiguity cuts against liability. And the panel was candid about the novelty, noting “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents,” while warning that the legal understanding of agentic AI “will doubtless change.”
Even Amazon’s harm evidence took damage. The claims that the Assistant might not select the best price or product for a user were, in the court’s view, comparatively weak and abstract, and the cybersecurity concerns unconvincing.
The Two Limits That Matter More Than the Win
Read the celebration in the trade press carefully. The ruling is narrower than the headlines, and the panel said so itself.
First, it is an architecture ruling, not an immunity ruling. The holding turned on the relay design: screenshots taken on the user’s machine, instructions returned to it, no direct server-to-server contact. Cooley flags the corollary plainly: agents with greater autonomy, or whose servers communicate directly with a target site, could still give rise to CFAA and CDAFA liability. Server-side scraping, headless data harvesters, and agents that identify themselves to merchant servers as the acting party all remain in the danger zone. The Ninth Circuit did not legalize the agent industry. It legalized one blueprint.
Second, only the anti-hacking theories died. Amazon’s trademark claims and its state-law theories survive at the district court, and the panel expressly left open breach of contract, terms-of-service enforcement, and tort. A website operator that cannot win a CFAA fight can still sue on the contract every user clicked, or simply engineer the friction: CAPTCHAs, bot flags, rate limits, account suspensions for users of agentic browsers. The law of trespass gave way to the law of curation.
The War Moves from the Courtroom to the Data
Here is why this ruling, decisive as it is, solves the wrong problem for consumers.
Assume the holding holds. Your AI agent lawfully enters Amazon as your tool, your authorization, your session. What does it see? A product page where review access has been systematically restricted since late 2025: sellers on Amazon’s own forums reporting eight visible reviews, no negative feedback, a request form and a five-business-day wait for more. Shoppers flagged as bots for the offense of browsing. And Amazon’s preferred fix for shoppers who want product insight is not more review access. It is Rufus, Amazon’s proprietary assistant, summarizing a corpus the public can no longer inspect.
The Ninth Circuit guaranteed your agent the right to stand in the store. Amazon controls what’s on the shelves, which reviews are visible, and which assistant gets to narrate. An agent that reads a curated page with machine-speed comprehension is not an impartial researcher. It is a very fast victim of curation. And a screenshot-relay agent, the exact architecture the court blessed, inherits every limitation of the page it photographs: sponsored placements mixed into results, featured five-star reviews displacing critical ones, and a trust environment optimized for conversion rather than accuracy.
This is the strategic meaning of August 2026 for anyone building in agentic commerce. The legal chokepoint failed. The data chokepoint is all Amazon has left, and it is already built.
The Trust Layer Nobody Can Injunction
If the marketplace controls the page and the courts have closed the anti-hacking road, the only durable counterweight is verification that does not depend on the marketplace’s rendering of itself. Three properties follow from the ruling’s own logic.
Independence. A trust signal computed from Amazon’s displayed page, whether by a human or an agent, is downstream of Amazon’s curation choices. The alternative is scoring computed from review corpora gathered and weighted outside the marketplace’s presentation layer: fake-review filtering, quality-weighted assessment, and a score that reflects what the reviews actually say rather than which reviews are shown. That is GoBuy’s Smart Score: a 0-100 measure of review quality, not review quantity, with manipulated feedback filtered out before it counts.
Machine-readability. The Ninth Circuit blessed agents that act as the user’s tool. Those agents need inputs they can consult in seconds, not pages they must photograph and hope. Exposing trust data through an MCP endpoint turns every compliant agent into a client: the agent enters the store lawfully, but checks the shelf against an independent score first. GoBuy’s MCP server at gobuy.ai/api/mcp exists precisely for this: agents consult GoBuy before purchasing, receive the top seven verified products per category rather than thousands of curation-dependent listings, and surface only products whose trust has earned it, including the GoBuy Verified badge reserved for products scoring 80 or above across 90 days.
Persistence. Litigation timelines run in years. Amazon’s own warnings that agentic AI law “will doubtless change” cut both ways: today’s permission could be tomorrow’s contract claim or congressional amendment. Trust infrastructure that does not depend on scraping permission is immune to the next docket. The GoBuy Chrome extension already puts the trust panel directly on the Amazon page, for the human riding along with the agent, which means the check on curation survives regardless of who wins the next round in court.
What to Watch Next
The case returns to Judge Chesney’s courtroom with trademark and state-law claims live, and the smart money expects Amazon to pivot hard to terms-of-service enforcement and technical gating rather than appeal the access holding. Watch three signals: whether Amazon starts suspending accounts that route through agentic browsers, whether Congress entertains a CFAA “clarification” that reassigns access liability to developers, and whether other circuits follow the Ninth’s user-operates-the-tool framework or split from it.
But the deeper verdict is already in. The law has decided your agent may enter the store. The only question left is who tells it the truth once it’s inside. The marketplace answered that question for itself. Someone independent has to answer it for you.
Before your agent buys, make it check. Point it at GoBuy’s trust layer at gobuy.ai, or wire the GoBuy MCP server into your stack with the agent docs at gobuy.ai/agent-docs.