A three-judge panel of the U.S. Court of Appeals for the Ninth Circuit ruled on August 4, 2026, that when a person uses an AI agent to browse a website, it is the person — not the AI company — who “accesses” the site’s computers. The decision in Amazon.com Services v. Perplexity AI vacated a preliminary injunction that had barred Perplexity’s Comet browser from interacting with Amazon’s platform.
The panel’s central line: “However advanced the Assistant currently is, it is a tool, not a person for statutory purposes.” The user accesses the site. The AI is the means.
That sounds clean. It is not.
What the case actually decided
Amazon sued Perplexity under the Computer Fraud and Abuse Act (CFAA) and California’s equivalent, the CDAFA — federal and state anti-hacking statutes. Amazon argued that Perplexity’s AI Assistant, which can navigate websites to shop on a user’s behalf, amounted to unauthorised access to Amazon’s computers.
The Ninth Circuit disagreed, but only on the preliminary record before it. Perplexity’s browser runs on the user’s own machine. The Assistant analyses what the browser displays and may contact Perplexity’s servers for instructions. But Perplexity’s servers did not directly access Amazon’s servers — at least, not on the evidence available at the injunction stage.
The court was explicit about the limits. “We do not establish a new legal regime governing agentic AI,” the panel wrote. The holding applies to two specific anti-hacking statutes, on a specific factual record, at the injunction stage. The case goes back to the district court for further proceedings.
Three things the ruling does not do
First, it does not create blanket immunity for AI developers. The court noted that if evidence later showed Perplexity exercised enough control over the Assistant to itself gain entry to Amazon’s servers, the analysis could change. A different technical architecture — one where the AI company’s servers directly contact the target site — could produce a different result.
Second, it does not resolve tort claims, negligence, product liability, privacy, intellectual property, or deceptive practices. The decision is about one statutory element — who “accesses” a computer — under two hacking statutes.
Third, it does not override private terms of service. In a footnote, the court said its outcome “does not impair Amazon’s ability to regulate access to Amazon.com via private terms of service for its users.” Contract law still applies. If a site’s terms prohibit automated access, a user who deploys an agent to circumvent that restriction may still breach the contract — the CFAA simply is not the enforcement mechanism.
California says you cannot blame the AI
The Ninth Circuit ruling exists alongside a separate California statute that cuts the other way. Assembly Bill 316, approved in October 2025, added Civil Code section 1714.46, which says a defendant cannot raise the defence that “the artificial intelligence autonomously caused the harm to the plaintiff.”
In other words: in California civil litigation, “the AI did it on its own” is not a get-out-of-liability card. The statute preserves other defences — causation arguments, foreseeability, comparative fault — but the autonomy defence is off the table.
Put the two together and you get a landscape where the user is the one accessing the site (Ninth Circuit), and the user (or developer) cannot escape liability by saying the AI acted independently (California legislature). The framework is assembling itself in pieces, across different branches and different statutes, with no comprehensive scheme in sight.
The federal enforcement layer
Executive Order 14409, signed June 2, 2026, directs the Attorney General to prioritise enforcement of federal criminal laws against people who use AI to access computers illegally or who use AI during illegal access to further another crime. The order specifically references “employing AI agents to unlawfully access data or information that is subsequently used for a criminal or unlawful purpose.”
An executive order does not amend the CFAA. It sets enforcement priorities within the executive branch. But it signals that prosecutors should look at AI agent-mediated access through existing criminal statutes — not wait for new ones.
What this means for businesses deploying AI agents
The practical takeaway is not that AI agents are now legally safe. It is that governance and documentation matter more, not less.
A company deploying an AI agent should know what the agent can do — browse, purchase, submit forms, send messages, access data — and document which systems it may access, whose credentials it uses, and which actions require human approval. Contracts with AI vendors should specify intended functions, compliance with third-party platform rules, logging requirements, and responsibility for out-of-scope actions.
The Ninth Circuit gave a narrow answer to a narrow question. The broader questions — who is liable when an agent causes harm, what counts as authorisation, where the line between tool and actor sits — remain open.
NZ angle
New Zealand has no equivalent to the CFAA. The Crimes Act 1961 section 252 covers unauthorised access to a computer system, but the provision was written for human perpetrators and has not been tested against AI agent-mediated access. The Privacy Act 2020 governs data handling but does not directly address agentic browsing.
If a New Zealand company deploys an AI agent that accesses a foreign website — say, a U.S. e-commerce platform — the Ninth Circuit’s reasoning could still matter. U.S. courts may assert jurisdiction over the interaction. The question of whether the NZ company or its AI vendor is the one “accessing” the site is now marginally clearer, but only for the specific fact pattern the Ninth Circuit considered.
For NZ’s growing AI agent ecosystem, the lesson is the same as everywhere else: document what the agent does, who authorises it, and which platform terms apply. The law is not going to catch up soon.
❓ FAQ
Does this ruling mean AI agents can access any website? No. The court decided a narrow question about who “accesses” a computer under two anti-hacking statutes. It did not grant a general right to use AI agents on any website, and it explicitly noted that private terms of service still apply.
Can a company still block AI agents from its site? Yes, through terms of service and technical controls. The Ninth Circuit said its ruling does not impair a site’s ability to regulate access via private terms. Whether a specific restriction is enforceable depends on the terms and applicable law.
What is California Civil Code 1714.46? A statute that prevents defendants in civil cases from arguing the AI acted autonomously and therefore the defendant is not responsible. It preserves other defences but removes the “the AI did it” defence.
Is this the final word on AI agent liability? No. The Ninth Circuit reviewed a preliminary injunction and remanded the case. The holding is tied to the specific record and technology presented at that stage. Further proceedings could produce different results.