AI assistants just got their biggest legal win so far. The Ninth Circuit has vacated the injunction that kept Perplexity's Comet browser off Amazon, ruling that Amazon is unlikely to prove the AI agent broke the Computer Fraud and Abuse Act — the anti-hacking law the whole case leaned on.
The question under all of it
Strip out the company names and you're left with one question: when your AI assistant logs into a website for you, who's visiting — you, or the company that built the assistant?
Amazon said the latter. Its version: Comet dressed up automated traffic as a normal browser, broke Amazon's terms of service and got into customer accounts without authorization. A lower court bought it enough to issue a preliminary injunction banning Comet from the site.
Perplexity's answer: Comet only acts when a user tells it to, with credentials stored on the user's own device — so Amazon wasn't really protecting security, it was blocking people from choosing their own AI assistant. The company took that argument to the Ninth Circuit.
The court's answer: your agent is you
The appeals court went with the user. Amazon's website, the judges reasoned, is being accessed by Amazon's own customers — Comet is just the tool carrying out their instructions. And an anti-hacking law written for intruders sits awkwardly on software a shopper deliberately points at their own account.
That framing echoes well past this one lawsuit. Comet browses, logs in and buys on a user's behalf — exactly what every major AI company is building right now. Whether that kind of agent is an authorized user or an unauthorized bot decides whether the category works legally on the open web at all.
Almost no precedent existed before this
Appellate courts have barely touched agentic AI, so this ranks among the first rulings anywhere on whether AI agents can access platforms on a user's behalf. The decision treats the agent as an extension of the person driving it, not an intruder — and every platform weighing whether to admit or block agents, plus everyone building them, now has to work around that precedent.
Worth being exact about scope, though. The court vacated a preliminary injunction and judged Amazon's odds of winning; the lawsuit itself isn't over. Amazon still has other claims, including terms-of-service arguments, and litigation grinds on. But losing the CFAA theory on appeal takes away the heaviest weapon platforms had for locking agents out.
What actually changes
Right away: Comet can shop Amazon again. The bigger effects come later. Platforms that assumed anti-hacking law would keep AI agents out need a new plan — technical defenses, commercial deals, or terms they can genuinely enforce.
Agent-builders get firmer ground to stand on, but not a free pass. Acting strictly on user instructions with user-held credentials was central to why Perplexity's setup survived review. Agents that drift from that pattern might not.
The likeliest next chapter isn't another courtroom showdown — it's negotiation. Platforms want a say in how agents transact on their turf; agent companies want access to where people already shop. What this ruling told both sides is that the law, for now, sees the agent as the customer's hands. The leverage just moved.
Image: SHOX ART, via Pexels





