The Ninth Circuit Just Ruled AI Agents Can Shop for You on Amazon. Perplexity's Comet Browser Won.
A federal appeals court ruled it's the user, not the AI tool, who accesses a website under the CFAA, clearing legal fog for founders building agentic shopping and browsing products.

News Breakdown · FiscEdge Academy
On August 4, the Ninth Circuit Court of Appeals vacated a federal injunction that had barred Perplexity's Comet browser from shopping on Amazon.com. The three-judge panel's holding was blunt: when an AI agent buys something on a user's behalf, the user is the one "accessing" the site under the Computer Fraud and Abuse Act (CFAA), not the software that carried out the click.
The ruling ends, at least for now, a nine-month legal fight. Amazon sued Perplexity in November 2025, arguing that Comet's agentic shopping tool logged into customer accounts and placed orders without authorization. U.S. District Judge Maxine Chesney agreed, granting a preliminary injunction on March 9 that blocked Comet from touching any logged-in Amazon page. Perplexity appealed immediately, and the Ninth Circuit heard oral arguments in Seattle on June 11.
Here's why the date on the calendar matters less than what the opinion actually says. The signal under the headline isn't "Perplexity won a lawsuit." It's that a federal appeals court just wrote the first real legal test for every startup building an agent that logs in, clicks, and buys on a user's behalf, and it came down on the side of the agents.
What the court actually ruled
The panel's 21-page opinion turns on a single question: who "accesses" a computer system when an AI agent does the clicking? Amazon argued it was Perplexity. The court disagreed, ruling that Comet only relays screenshots the user's own browser already captured, so the person directing the agent, not the company that built it, is the one accessing Amazon's servers. Applying the rule of lenity, the judges construed the CFAA's ambiguity against imposing liability, writing that "an injunction would impair consumer choice and needlessly limit development of a nascent technology."
The court was careful to flag how thin the ground still is. It noted there is "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents" and called its own holding narrow. Amazon's trademark and state-law claims survive and head back to district court in San Francisco; the company can still seek a rehearing or petition the Supreme Court.
Why this reaches past one browser
This case was never really about Comet. It's a proxy fight over agentic commerce broadly: any product that logs in, browses, or transacts on a user's behalf, from shopping copilots to travel-booking agents to invoice-paying bots, inherits some version of Amazon's CFAA theory the moment it touches a platform that doesn't want it there. A federal circuit siding with the "the user did it" framing hands every founder building on that model a citable precedent, not just a hopeful legal memo.
It also raises the stakes for Perplexity specifically. The company has been racing to turn Comet into a wedge into commerce, backed by a roughly $20B valuation from its most recent round and reported annualized revenue north of $450M. An injunction that permanently blocked Comet from Amazon would have gutted the product's core pitch. This ruling buys the category time, not certainty.
The fine print founders should actually read
Three things matter more than the headline.
First, this is a preliminary win, not a final one. The underlying case, and Amazon's trademark and state-law claims, are still alive and headed back to district court. Build assuming the rules can tighten again, not that this is settled law.
Second, the court explicitly said agentic AI law "will doubtless change." If you're shipping a product that automates access to a platform you don't control, terms of service still matter even where the CFAA doesn't reach, and platforms can still throttle, rate-limit, or ban agents technically rather than legally.
Third, notice what actually won the case: the architecture. Comet succeeded partly because it operates through the user's own authenticated session rather than independently impersonating credentials. Founders building on top of AI agents should treat that distinction as a design constraint, not a legal afterthought.
If you remember one thing
A federal appeals court just ruled that an AI agent acting on a user's authorization is, legally, the user acting, not the software. That's the first real precedent for the entire category of agentic tools, and it's narrow, contested, and reversible. Build your product as if today's ruling is temporary cover, not a permanent green light.
We teach the legal and product tradeoffs behind AI agent startups in FiscEdge's AI for entrepreneurs course, and how to prototype one without writing a line of code in the AI agents masterclass. For the strategy behind picking a defensible product category, see startup strategy. Browse the full blog for more news breakdowns. Follow @fiscedge for daily Business & AI analysis.
How interesting did you find this article?
The week's breakdowns, every Sunday.
Business & AI news decoded for founders. One email a week, no fluff.
Stay connected with FiscEdge Academy
Want more breakdowns like this one? Follow us and keep learning.