Amazon has failed to persuade the U.S. Court of Appeals for the Ninth Circuit to reconsider a closely watched ruling over Perplexity’s AI shopping agent, leaving intact an opinion that treats the locally operating assistant as a tool used by the shopper rather than as the company itself entering Amazon’s computer systems.
On September 10, the Ninth Circuit declined Amazon’s request for rehearing en banc. Courthouse News reports that not one judge requested a vote on whether the full court should rehear the dispute. The result leaves the court’s published August 4 opinion in Amazon.com Services v. Perplexity AI in place while the underlying lawsuit continues.
That August ruling vacated a preliminary injunction that had barred Perplexity from using its Comet browser’s AI Assistant to access Amazon’s protected systems. The appellate panel concluded that Amazon was unlikely to succeed on its claims under the federal Computer Fraud and Abuse Act, or CFAA, and California’s parallel Comprehensive Computer Data Access and Fraud Act because, on the technical architecture presented to the court, Perplexity itself did not “access” Amazon’s computers. The user did.
The decision is significant for the emerging market for AI agents that shop, book, compare and navigate websites on a person’s behalf. But its boundaries are equally important. The Ninth Circuit did not grant AI companies a general right to ignore website restrictions, and it did not decide the ultimate merits of every possible claim Amazon could bring against an agent provider.
The full Ninth Circuit will not revisit the panel’s ruling
Amazon’s rehearing request asked the Ninth Circuit to reconsider the August decision en banc, a procedure in which a larger group of judges can revisit a panel opinion. The September 10 order ends that effort at the circuit level for now: no judge requested a vote on whether rehearing should occur.
As a practical matter, the three-judge panel’s published interpretation therefore remains the governing appellate decision in the case. The district court’s preliminary injunction remains vacated, and the dispute returns to the lower court for further proceedings under the framework the Ninth Circuit established.
This procedural posture matters. Amazon did not lose a final trial determining every issue in the lawsuit. It lost the preliminary injunction and then failed to obtain rehearing of that appellate ruling. The question before the Ninth Circuit was whether Amazon had made the showing required to block the conduct while litigation continued, not whether every legal theory available to a retailer against an AI agent has been permanently resolved.
Even so, a published appellate opinion that survives an en banc rehearing request carries more practical weight than an unsettled district-court theory. Developers, platforms and lawyers now have a concrete Ninth Circuit interpretation to account for when analyzing user-directed agents under anti-hacking law.
The dispute turns on who actually “accesses” Amazon’s servers
Perplexity’s Comet browser runs locally on a user’s computer. Its optional Assistant can perform tasks at the user’s direction, including navigating Amazon to find products.
According to the technical record described by the Ninth Circuit, when a shopper directs the Assistant to locate an item, the browser on the user’s machine communicates with Amazon. The Assistant can analyze the page displayed locally, send screenshots and relevant information from the user’s computer to Perplexity’s servers, and receive instructions about what action to take next.
The crucial architectural point is that Perplexity’s servers do not directly connect to Amazon’s servers. Information first reaches the user’s computer through the browser. Perplexity then receives information from that local environment and sends instructions back to the Assistant.
Amazon argued that this distinction should not insulate Perplexity because the company’s servers help direct the agent’s actions and the Assistant can behave autonomously while carrying out the shopper’s task. Perplexity countered that the agent is software operating for the user, comparable in relevant respects to browser functionality that automates actions such as filling in an address or payment information.
The Ninth Circuit said the user—not Perplexity—was doing the accessing
The appellate panel focused closely on the CFAA’s concept of “access.” Under the Supreme Court’s interpretation, computer access concerns entering a computer system or a particular part of one.
On the record before it, the Ninth Circuit concluded that Perplexity did not itself gain entry to Amazon’s computers. Instead, the shopper accessed Amazon through a browser running on the shopper’s machine and used the Assistant to perform particular actions.
The court also emphasized that the CFAA applies to a person or legal entity that intentionally accesses a protected computer. However sophisticated an AI assistant may be, the panel said, the software itself is a tool rather than a statutory person.
Perplexity can receive screenshots and send navigation instructions, but the panel found those activities insufficient by themselves to establish that Perplexity had entered Amazon’s servers. Because Amazon was unlikely to prove the access element, its CFAA theory was unlikely to succeed at the preliminary-injunction stage.
California’s anti-hacking claim failed for the same reason
Amazon also relied on California’s Comprehensive Computer Data Access and Fraud Act, or CDAFA. The state law differs from the CFAA and contains a broader definition of access in some respects.
But the Ninth Circuit reached the same result. The relevant state provision still focuses on the person who accesses or causes access to a computer system. On the current record, the court concluded that the user was the person accessing Amazon while employing Perplexity’s Assistant as a tool.
That made Amazon unlikely to succeed on its CDAFA claim as well.
The court consequently vacated the preliminary injunction and found that the remaining equitable factors did not rescue Amazon’s request. Preventing Perplexity from operating a product based on conduct unlikely to violate the two anti-hacking statutes would burden the company, reduce consumer choice and restrict development of a nascent technology, the panel reasoned.
The ruling does not say AI agents can access any website they want
This is where the legal significance can easily be overstated. The Ninth Circuit went out of its way to describe its holding as narrow.
The panel said it was not creating a new legal regime for agentic AI. It did not decide whether Perplexity could face liability under tort law or other legal theories. It also left open the possibility that different technical facts could produce a different result—for example, if an AI provider exercised enough control over an agent to itself gain entry to a website’s servers.
The opinion is therefore not a general declaration that an AI company can deploy autonomous software against a website owner’s wishes without legal consequence.
It is an interpretation of “access” under the CFAA and CDAFA as applied to a particular architecture: a user-directed assistant operating through a browser on the user’s computer, with the user’s machine communicating with the retailer.
Amazon can still regulate access through private terms
The panel also explicitly preserved another route for platform control. In a footnote to the August opinion, the Ninth Circuit said its outcome does not impair Amazon’s ability to regulate access to Amazon.com through private terms of service for users.
The court’s point was narrower: under the facts before it, Amazon was unlikely to succeed in using the CFAA and CDAFA as the legal mechanism for imposing that restriction on Perplexity.
That distinction leaves a large amount of the agent-platform conflict unresolved. Retailers can write contractual terms governing automated access. They can design technical systems to identify and restrict agents. They may have tort, contract, authentication, privacy, intellectual-property or other claims depending on the conduct involved.
The legal question is therefore shifting from “Can a platform stop agents?” to the more complicated question of which tools a platform can lawfully use to stop which kinds of agents under which technical architecture.
The user-agent dispute shows how technical design can become legal strategy
Amazon’s conflict with Perplexity was not merely philosophical. Before Comet’s release, Amazon told Perplexity that its AI products would not be permitted to access the Amazon Store. After launch, Amazon again objected to the Assistant’s activity.
A central factual issue was Perplexity’s decision not to use a user-agent string that would tell Amazon that the shopper had activated an AI agent. The Ninth Circuit noted that such an identifier would have allowed Amazon to recognize and block the Assistant.
That detail demonstrates how the next generation of web-access disputes can turn on architecture and identity. An agent running on a consumer’s device may look technically different from a centralized crawler making server-to-server requests. An assistant using the shopper’s authenticated session may also raise different legal questions from a bot operating its own accounts.
The distinction is no longer merely technical. In this case, where the request originated and which computer actually communicated with Amazon became central to the statutory analysis.
The opinion pushes against turning ordinary computer use into hacking
The Ninth Circuit’s reasoning also reflects longstanding caution around the CFAA. Courts have repeatedly resisted interpretations that could transform the federal anti-hacking statute into a broad rule against any unwanted computer-mediated behavior.
The panel noted that accepting Amazon’s interpretation could potentially expose individual shoppers to criminal theories for facilitating the supposed unauthorized access by Perplexity. Because the CFAA is primarily a criminal statute even when invoked in civil litigation, ambiguity carries significant consequences.
The court invoked the principle that ordinary behavior should not become a federal crime simply because a computer is involved. On the current facts, using software to help navigate a website was too far removed from the traditional hacking conduct the statute was designed to address for the court to adopt Amazon’s theory at the preliminary stage.
For agent developers, that reasoning may be as important as the result itself. It frames user-directed automation as potentially analogous to other software tools a person uses to interact with a computer system, rather than automatically treating the software provider as the accessing party.
That could matter far beyond Amazon shopping
AI agents are being designed to do far more than compare products. They can book travel, fill forms, schedule appointments, manage subscriptions, interact with customer portals and execute multi-step tasks across third-party websites.
Many of those services have commercial incentives to keep users inside their own interfaces, control automation, preserve advertising or affiliate economics, enforce rate limits and protect customer data. Agent providers, by contrast, want software to act across those interfaces as a user’s delegated tool.
The Ninth Circuit’s opinion gives the agent side an important argument where the architecture resembles Comet: if the human is authenticated, the browser runs locally and the user’s computer is the system directly communicating with the website, the agent provider may not itself be the party “accessing” the website for CFAA purposes.
That does not resolve contract or technical access disputes, but it narrows one of the most powerful statutory arguments platforms might otherwise deploy.
The architecture of future agents could change the answer
The court was careful not to freeze its reasoning across every future form of agentic AI. Comet’s Assistant cannot operate wholly independently under the factual record. It depends on user direction and instructions from Perplexity’s servers, while the local browser remains the component communicating with Amazon.
A cloud-hosted agent could look very different. If an AI company’s own infrastructure logs into a service, directly sends requests to the platform and performs tasks without the user’s machine acting as the intermediary, the question of who gained entry to the target computer could be much harder for the provider.
The panel expressly left open whether a different record showing greater Perplexity control over the Assistant could amount to access by the company.
This makes system design a potential legal variable. Whether an agent runs locally, where authentication occurs, which machine sends network requests and how much autonomy the provider exercises can affect more than latency and product experience. Those facts may determine which party the law treats as interacting with the target service.
The case also exposes a strategic problem for retailers
Retail platforms have reasons to care about agents even when consumers authorize them. An assistant can alter product discovery, bypass sponsored placements, choose a different seller than the retailer would recommend, obscure merchandising, automate purchases and mediate the relationship between the marketplace and its customer.
Amazon argued that Comet could degrade the shopping experience by failing to select the best price, delivery option or product recommendation. It also raised cybersecurity concerns.
The Ninth Circuit found the evidence of irreparable harm too weak to support the preliminary injunction. The alleged degradation of the shopping experience was relatively abstract, while the cyber-risk evidence was limited and partially countered by Perplexity’s claimed security improvements.
But those concerns will not disappear simply because the CFAA theory stumbled. If agentic commerce grows, retailers will have to decide which automated intermediaries to welcome, which to negotiate with and which to resist through technical or contractual controls.
Rehearing denial strengthens the precedent without making it universal
The September 10 development matters because Amazon no longer has an en banc rehearing route inside the Ninth Circuit to undo the panel’s published opinion at this stage. The ruling therefore remains intact as the litigation moves forward.
That strengthens its practical value as precedent, particularly for disputes involving locally operating, user-directed agents. But “strengthens” should not be confused with “settles.” The opinion is tied to preliminary-injunction standards and the specific CFAA and CDAFA theories before the court.
The Ninth Circuit itself warns against extrapolating a complete legal framework for agentic AI from the case. Technology will evolve, more autonomous architectures will emerge and future records may place the agent provider much closer to direct server access.
Nor does the ruling prevent retailers from relying on private agreements or building technical defenses against automated activity.
The bigger precedent is that an AI agent can be treated as the user’s tool
For now, however, the Amazon-Perplexity case establishes an important starting point. Software does not necessarily become the legal accessor of a website merely because it can reason about the page and automate the user’s actions.
On the architecture before the Ninth Circuit, Comet’s Assistant remained a tool. The shopper’s browser entered Amazon’s system, the shopper directed the task, and the shopper was the party the court treated as accessing the site.
Amazon’s unsuccessful rehearing bid leaves that interpretation standing while the case returns to the district court. Platforms can still regulate agents, and other legal theories remain available, but the CFAA cannot simply be stretched into a universal anti-agent switch on these facts.
As AI moves from answering questions to taking actions, that distinction between a software company entering a service and a human using software to enter it may become one of the defining legal questions of the agentic web.