California Case Summaries

Amazon v. Perplexity AI — User-directed shopping agent likely does not “access” Amazon under hacking laws

Reported / Citable

Case
Amazon.com Services, LLC v. Perplexity AI, Inc.
Court
Ninth Circuit Court of Appeals
Judge
MILLER (Donald J. Trump, 2019)
Date Decided
2026-08-04
Docket No.
26-1444
Status
Reported / Citable
Topics
artificial intelligence agents, CFAA, California computer crime law, unauthorized access, preliminary injunction

Background

Perplexity developed an agentic browser assistant that carries out user-directed tasks, including shopping on Amazon.com. Amazon sought a preliminary injunction under the federal Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer Data Access and Fraud Act, arguing that Perplexity improperly accessed its systems despite Amazon’s restrictions.

The district court barred use of the assistant on Amazon while the lawsuit proceeded. Perplexity appealed, requiring the Ninth Circuit to decide whether Amazon had shown likely success and whether the equitable factors justified immediate relief.

The Court’s Holding

The Ninth Circuit vacated the injunction. On the preliminary record, the shopper—not Perplexity—accessed Amazon’s computers, using the assistant as a tool to execute specific instructions. That distinction undermined the required “access” element under both the CFAA and its California analogue. The ruling does not prevent Amazon from enforcing private terms of service, but a contractual restriction does not automatically establish a computer-hacking claim.

The remaining injunction factors also favored Perplexity. Amazon’s evidence of cybersecurity and customer harms was limited and partly countered by changes Perplexity said it had made. Enjoining a product absent likely statutory liability would burden innovation and consumer choice. The court remanded for continued litigation without the preliminary ban.

Key Takeaways

  • For user-directed AI agents, identifying who legally “accesses” a computer is distinct from identifying who built the tool.
  • Website terms of service and statutory unauthorized-access claims are not interchangeable.
  • A preliminary injunction requires concrete evidence of likely merits and irreparable harm, especially for emerging technology.
  • The decision is preliminary and fact-specific; it does not grant AI agents blanket permission to ignore site controls.

Why It Matters

Online businesses should use layered protections—clear contracts, technical controls, account rules, and evidence of actual harm—rather than assume the CFAA will police every unwanted automated interaction. The identity and agency of the end user can be decisive.

AI developers should preserve evidence showing that users initiate and control each task, while addressing security risks promptly. California practitioners should also separate federal and state statutory theories from contract, trespass, intellectual-property, and platform-policy claims that may remain available.

Read the full opinion (PDF) · Court docket

Scroll to Top