A federal appeals court has vacated a preliminary injunction that restricted Perplexity AI’s Comet browser agent from interacting with Amazon’s systems, ruling that the record did not support treating Perplexity itself as the party that accessed Amazon’s computers under federal anti-hacking law.

In an Aug. 4 opinion, a three-judge panel of the U.S. Court of Appeals for the Ninth Circuit concluded that the Comet user, rather than Perplexity, performs the relevant access for purposes of the Computer Fraud and Abuse Act. The decision reverses, at least for the preliminary stage of the case, a lower-court finding that Perplexity was likely to have violated the CFAA after Amazon sent the company a cease-and-desist letter.

The panel’s analysis focused on the technical path between Comet, its user and Amazon’s infrastructure. A user directs the AI agent through a browser running on the user’s device. That browser communicates with Amazon’s servers, while Comet captures images of what appears in the browser and sends those images to Perplexity for processing. Perplexity’s systems then return instructions that guide the agent’s next actions.

On the evidence before the court, Perplexity’s servers did not communicate directly with Amazon’s servers. Judge Milan D. Smith Jr., writing for the panel, therefore determined that the person operating the browser was the actor accessing Amazon’s computers, even though Perplexity’s technology helped decide how the browser should navigate the site.

That distinction was central because the CFAA imposes liability on a person who intentionally accesses a protected computer without authorization or exceeds authorized access. The court declined to extend that language to make the AI provider the accessing party when its servers did not directly connect to the platform at issue. It reached the same result when considering claims under California’s Comprehensive Computer Data Access and Fraud Act.

The panel also relied on the rule of lenity, a principle directing courts to resolve genuine ambiguity in criminal statutes in favor of the defendant. The CFAA creates both criminal offenses and civil causes of action. The court reasoned that adopting a novel and expansive understanding of access in the Comet dispute could have consequences beyond the immediate civil case, including potential criminal exposure for users of similar tools.

The ruling does not establish that every use of an AI agent on a website is authorized, nor does it resolve all potential claims arising from automated interaction with online services. It vacates a preliminary injunction, an early form of relief issued before a case receives a final decision on the merits. The panel also limited its conclusion to the existing factual record, leaving room for different outcomes when an agent’s architecture or connections to a third-party service differ.

The opinion is the first federal appellate decision to address the application of computer-access statutes to agentic AI, according to a Jones Day analysis of the ruling. Its reasoning makes system design particularly important: an agent operating a local browser on a user’s behalf may present a different legal question from a cloud service that sends requests directly to a platform’s servers.

The decision also narrows one potential route for platforms seeking to stop outside AI agents. Companies may still use contractual restrictions, account controls, technical countermeasures and other legal claims to regulate automated activity. Whether those alternatives are available will depend on the relevant terms, the agent’s conduct and the technical measures used to reach or interact with the service.

As browser agents gain the ability to carry out multistep tasks, courts will increasingly have to distinguish among the user who requests an action, the software that executes it and the company operating the models behind that software. The Ninth Circuit’s ruling answers that question for Comet’s documented architecture at the preliminary-injunction stage, but expressly avoids setting a universal rule for future AI agents.

Sources: AI liability ruling, OpenAI