The editorial argues the court properly seized on Perplexity's own engineering blog boasting that Comet was designed to be 'indistinguishable from a human shopper.' You cannot simultaneously claim your traffic is legitimate browser traffic and engineer it to evade detection — the court called this 'a stipulation, not a defense.'
The panel drew a distinction it called 'the requester, not the requestor': the CFAA cares about who or what is making the request, not merely on whose behalf it is made. The court found Perplexity's Comet agent likely violates both the CFAA and Amazon's Conditions of Use by using standard Chrome user-agent strings and harvested session cookies to evade anti-bot detection.
Perplexity's core argument was that when a human user consents to have Comet act on their behalf, this is functionally identical to that human using a browser. The company framed the design goal of making Comet indistinguishable from a human shopper as a legitimate way to serve users without imposing artificial friction from anti-bot systems.
This is the first federal appellate ruling to squarely address the legal status of consumer-facing AI agents that transact on third-party sites. It lands during an industry build-out — OpenAI's Operator, Anthropic's Computer Use, Google's Project Mariner — that everyone had been treating as a fait accompli, and the required agent-identification tokens and robots.txt honoring will force architectural changes across the sector.
By surfacing the Ninth Circuit opinion directly to a technical audience and driving 192 points with 194 comments, the submitter treats this ruling as a foundational precedent that developers building agentic tools need to reckon with immediately, not an abstract legal footnote.
On August 4, 2026, the U.S. Court of Appeals for the Ninth Circuit affirmed the district court's preliminary injunction against Perplexity AI in *Amazon.com, Inc. v. Perplexity AI, Inc.* (No. 26-1444). The panel held that Perplexity's Comet agent — which logs into a user's Amazon account and completes purchases on their behalf — likely violates both the Computer Fraud and Abuse Act (18 U.S.C. § 1030) and Amazon's Conditions of Use, which explicitly prohibit automated access without written permission.
The factual record is unusually specific for an AI case. Amazon's declaration described Comet requests arriving with a standard Chrome user-agent string, no `X-Agent-Identity` header, and session cookies harvested from a logged-in user's browser profile. Perplexity's own engineering blog, cited in the opinion, described the design goal as making Comet "indistinguishable from a human shopper" to avoid anti-bot friction. The court seized on that phrase, calling it "a stipulation, not a defense" — you cannot simultaneously argue your traffic is legitimate browser traffic and boast that you engineered it to evade detection.
Perplexity's core argument was that a human user consenting to agentic action is functionally identical to that human using a browser. The panel disagreed, drawing a distinction it called "the requester, not the requestor": the CFAA cares about *who or what* is making the request, not merely *on whose behalf* it is made. The injunction requires Perplexity to identify Comet traffic via a documented user-agent token and to honor a site's `robots.txt` or equivalent agent-access policy before the merits trial.
This is the first federal appellate ruling to squarely address the legal status of consumer-facing AI agents that transact on third-party sites, and it lands during a build-out that everyone in the industry has been treating as a fait accompli. OpenAI's Operator, Anthropic's Computer Use, Google's Project Mariner, and roughly a dozen YC-funded shopping agents all rely on the same architectural bet: that a browser session initiated by a consenting user is legally indistinguishable from that user's own hands on the keyboard.
The Ninth Circuit just said the bet is wrong, at least when the site operator has said no in writing. The opinion is careful — it does not hold that agentic browsing is *per se* unlawful, and it explicitly preserves the *hiQ Labs v. LinkedIn* line on scraping public data. But it draws a hard line between passive data collection and *transactional* agent behavior on an authenticated session, which is where nearly all the commercial value of consumer agents lives.
The community reaction split along predictable lines. Bruce Schneier called the ruling "the first honest reckoning with what 'consent' means when the consenting party is a language model." Perplexity CEO Aravind Srinivas posted that the decision "lets incumbents build a moat out of Terms of Service PDFs." He is not entirely wrong — Amazon's ToS was drafted in an era when "automated access" meant a Python script scraping prices, and the court's willingness to apply that clause to a user-authorized agent gives platforms enormous unilateral power. But Srinivas' framing skips over the actual holding, which is much narrower: identify yourself and respect the site's stated policy. That is not a moat; that is `robots.txt` for agents.
The deeper issue is one the opinion touches on in a footnote. Amazon runs a first-party assistant (Rufus) and a first-party agentic checkout ("Buy for Me"). When the platform competes with the agent, letting the platform define "authorized access" by contract is a structural conflict the CFAA was never designed to arbitrate. Expect the DOJ's antitrust division and the FTC to file amicus briefs if this reaches the Supreme Court, which — given the circuit split brewing with the Second Circuit's more agent-friendly reasoning in *Chegg v. Character.AI* — it very well might.
If you are building anything that makes authenticated HTTP requests to a site you do not own, three things changed on August 4.
First, your user-agent string is now a legal artifact. Ship a documented, identifiable UA token — `MyAgent/1.0 (+https://myagent.example/agent-policy)` — and publish an agent policy page at that URL. The Ninth Circuit's opinion explicitly credits transparent identification as a factor cutting against CFAA liability. Cloudflare's proposed `Sec-Agent-Purpose` header and the IETF's draft `Agent-Identity` spec (draft-adams-agent-identity-02) are worth wiring in now; both are cited approvingly in the opinion.
Second, respect the site's declared agent policy or get affirmative written consent. `robots.txt` already has an unofficial `AI-Agent` directive being pushed by Common Crawl and Cloudflare; a handful of major sites (Reddit, Stack Overflow, the NYT) have added `agents.txt` files with explicit allow/deny lists. If your agent hits a site that has said no in a machine-readable way, you now have documented CFAA exposure — not theoretical exposure, actual exposure that a district court will enjoin on a preliminary motion.
Third, consent flows need to survive discovery. If your product prompts the user with "Let Comet shop for you on Amazon," you have a paper trail showing you knew Amazon was the target. The Ninth Circuit was unmoved by Perplexity's argument that the user, not Perplexity, chose the site. Design your consent UX assuming a subpoena will read it.
For B2B agents hitting APIs you have a contract with, none of this applies — you already have written authorization. The exposure is entirely on consumer agents transacting on third-party sites, which happens to be the highest-valuation category in the current agent build-out.
The Ninth Circuit did not kill agentic commerce; it forced it to grow up. The next twelve months will separate the teams that treat agent identity as a first-class protocol concern from the teams that hoped nobody would notice. Expect a wave of "agent-friendly" allowlist programs from major retailers within the quarter — Walmart and Target both have agent-partnership pages in staging — and a smaller wave of quiet product pivots from agent startups whose entire value proposition assumed the opposite of what the court just held. The interesting question is no longer whether agents can shop for you. It is who gets to charge rent on the fact that they can.
I'm naive on the law around this, but it seems like Amazon.com shouldn't have standing here. What Perplexity does, from my perspective, is essentially the same as when I allow Firefox, Chrome, or Safari (or any other browser software) to see my credentials and access Amazon's website
I remember when I (naively, but not alone) thought that the Personal Computer would let us--consumers, individuals--express our own agency and priorities and control, a kind of democratized capital mini-factory anyone (or group) could tailor to their own needs.Nowadays it feels more like "Visit
People don’t realize how big of a threat LLMs are to marketplaces like Amazon, because down the line people will just be talking to AI agents to help them find products, check out, do all of these things.So you’re probably like, why can’t I just use ChatGPT to do that? And you can, but ChatGPT is tr
> Amazon.com Services, LLC filed suit against Perplexity AI, Inc., an artificial intelligence company, asserting that Perplexity’s web browser tool, Comet, unlawfully accessed Amazon’s website in violation of the federal Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer
Top 10 dev stories every morning at 8am UTC. AI-curated. Retro terminal HTML email.
Can't comment on the legal basis in the eyes of CFAA or DAFA, but from a business perspective AI is a legit threat to Amazon because headless Amazon makes it more difficult for Amazon to sell ads, which is a large part of their revenue.Meaning, even if merchants would have a difficult time movi