Address

30 N Gould St Ste N, Sheridan, WY 82801

Phone number

+212 681 53 04 05

Email

contact@skyweb3agency.com

A federal appeals court is about to decide whether your website’s terms of service can turn a user’s own AI shopping agent into a federal criminal. That is the real question sitting inside Amazon v. Perplexity, a case that started as a dispute over one browser’s checkout behavior and is now the closest thing the United States has to a precedent on agent-as-visitor rights.

Oral arguments happen June 11, 2026, in Seattle. Whatever the Ninth Circuit decides on agent access will shape how every retailer, marketplace, booking platform, and SaaS site treats AI agents acting on a logged-in user’s behalf — and most of them will be forced to take a position within the next year regardless of how the ruling lands.

How we got from a lawsuit to an appeal in eight weeks

Perplexity’s Comet browser can log into a user’s own Amazon account with the user’s stored credentials, browse products, and complete checkout on the user’s behalf. Amazon sued in the Northern District of California, arguing that this constitutes unauthorized access to its systems under the Computer Fraud and Abuse Act (CFAA) — regardless of whether the human user authorized the agent to act — and added trademark and unfair-competition claims tied to how Comet renders Amazon’s pages inside its own interface.

On March 10, Judge Maxine Chesney granted Amazon a preliminary injunction, a ruling we covered when Amazon first won its injunction against Comet. The order blocked Comet from Amazon’s password-protected pages — account details, order history, checkout — while leaving public product pages accessible. Chesney’s reasoning: Amazon’s terms of service define who is authorized to access logged-in areas, and a user’s instruction to an agent doesn’t extend that authorization to the agent itself.

About a week later, the Ninth Circuit paused the injunction while Perplexity’s appeal proceeds. That pause matters more than it sounds — appellate stays of preliminary injunctions are uncommon, and courts only grant them when the moving party has shown a real likelihood of winning on the merits. On May 8, Perplexity filed its appellate brief, calling Amazon’s CFAA theory “a fundamental misfit” for an agent operating under explicit user authorization. Mozilla, the Electronic Frontier Foundation, and other digital-rights groups filed amicus briefs backing Perplexity’s position.

The legal question underneath the headline

The CFAA dates to 1986 and was written to target hacking-style intrusion — the WarGames-era conception of unauthorized computer access. Over the following decades, plaintiffs stretched it in civil litigation to cover scraping, automated access, and account-sharing behavior that looks nothing like a break-in. The Supreme Court reined some of that in with Van Buren v. United States (2021), holding that someone with legitimate access to a system doesn’t violate the CFAA merely by using that access for the wrong reason. Whether that narrowing extends to an agent acting on a user’s explicit behalf is exactly what this case tests.

Amazon’s theory has three parts: its terms of service reserve access to natural-person browsing, not software agents; when Comet logs in, Comet itself — not the user — is the entity making the request from Amazon’s perspective; and because Amazon never separately authorized Comet, its access is “without authorization” under the statute, regardless of what the user instructed.

Perplexity’s counterargument runs on centuries-old agency law rather than statutory interpretation. The user is the principal, Comet is the user’s agent, and when a user directs Comet to complete a transaction the user is already authorized to complete, that access is the user’s access, simply channeled through software. There is no third, unauthorized party in the transaction — only a user and the tool they chose to delegate a task to.

Why the appellate pause is itself a signal

Appellate panels don’t usually explain a stay decision in writing, and this one didn’t either — the signal is procedural, not textual. But two doctrinal pressures likely explain the panel’s skepticism. First, Van Buren cut the CFAA back from a tool that could criminalize any terms-of-service violation to one that targets genuine unauthorized access; a reading that treats a user’s own delegated agent as an unauthorized intruder looks more like the pre-Van Buren expansion the Supreme Court rejected than the narrower doctrine it established. Second, legal agency principles have governed delegated transactions for centuries — when someone authorizes another party to act for them, that party’s actions are imputed to the principal, and software acting on explicit instruction is the modern extension of the same idea. Reading the CFAA to ignore that would effectively criminalize the ordinary act of delegating an online task to software, which describes most internet users at this point.

What’s actually riding on this ruling

If the District Court’s theory survives, every major website gains a federal legal weapon for blocking AI agents from logged-in accounts, even accounts the user fully owns. The Amazon playbook becomes standard practice: retailers could block AI shopping agents from price comparison, booking sites could block AI travel agents from completing reservations, and SaaS platforms could block agents from managing subscriptions — with the site’s own terms of service as the controlling document and the user’s explicit consent rendered legally irrelevant.

If the Ninth Circuit reverses, the CFAA gets pushed back inside its narrower, 1986-era lane. Sites would lose the federal criminal-law lever for blocking user-delegated agents, and the question of agent access would shift entirely to the contract-and-technology layer — enforceable through civil terms claims, technical blocks, or dedicated partnership APIs, rather than a federal statute originally aimed at hackers. A middle-ground outcome is also plausible: the panel could affirm on narrower grounds, distinguish between transaction-completing agents and data-retrieving ones, or remand for further fact-finding, leaving the core question to play out in another circuit later.

Whichever direction it goes, this case sets the operative precedent for agent-as-visitor rights in the U.S., and it will shape how sites approach the kind of agentic commerce protocols merchants are already weighing.

What to watch on June 11

Three things at oral argument will tell you which way this is heading. Watch how hard the panel presses Amazon’s counsel on why a user’s explicit instruction to their own agent doesn’t extend that user’s authorization — heavy pushback there suggests discomfort with the District Court’s reading. Watch whether the judges draw distinctions between types of agent access — a transaction-completing agent using stored credentials is a different question than a read-only agent retrieving public data, and a ruling that separates these categories would matter more for site owners than a blanket affirm-or-reverse. And watch whether the panel writes a broad doctrinal frame for AI agents generally, or confines the ruling narrowly to Amazon-and-Perplexity-specific facts, leaving the larger question for a later case.

Oral argument audio is typically posted within hours, and the panel composition, once published, is a decent early tell.

What site owners should do now, regardless of the outcome

Waiting for June 11 to decide your own agent-access posture is the wrong move, because the question of how AI agents actually see and interact with your website is already live for your users, whatever a court eventually says about liability.

Start by reading your own terms of service for automated-access clauses. Most of that language predates the agent era and was written with scraping bots in mind, not a user’s own delegated shopping assistant — decide whether it still says what you actually want, then make sure your robots.txt and access controls match that decision rather than contradicting it.

Then audit your access-control posture against the agent user agents your users actually run into: crawlers like GPTBot, PerplexityBot, and ClaudeBot on one side, and user-delegated browsers like Comet, ChatGPT Atlas, and various Gemini surfaces on the other. If your firewall or robots.txt blocks these by default, some of your own users are already hitting a wall they don’t understand.

Finally, pick a coherent posture rather than defaulting into one. You can welcome user-delegated agents outright, possibly pricing agent-driven transactions differently. You can block them and back that position with clear terms and enforced technical controls, accepting that some users will migrate to sites with a friendlier posture. Or you can partner, building an API surface that lets agents transact without touching your logged-in pages at all — the door instead of the wall. Whatever the Ninth Circuit rules, the default posture most sites are running today was written before agent-as-visitor was a real access category, and it’s very likely the wrong one now.

Frequently asked questions

What is Amazon v. Perplexity actually about?

Amazon sued Perplexity because its Comet browser can log into a user’s Amazon account and complete purchases on the user’s behalf. Amazon argues this is unauthorized computer access under the CFAA even though the user authorized it; Perplexity argues the user’s authorization covers the agent acting on their behalf.

What did the courts decide so far?

A district court granted Amazon a preliminary injunction blocking Comet from logged-in Amazon pages. The Ninth Circuit then paused that injunction pending Perplexity’s appeal, a procedural signal that the appellate panel may see the case differently. Oral arguments are set for June 11, 2026.

Why does this case matter beyond Amazon and Perplexity?

Because the ruling will set the precedent for whether any website can use the CFAA to block AI agents acting on a user’s own logged-in account. That affects retailers, booking platforms, financial services, and SaaS products alike.

What should website owners do before the ruling comes out?

Review terms-of-service language on automated access, audit access controls against the actual agent user agents in use, and choose a deliberate posture — welcome, block, or partner — rather than relying on default settings written before AI agents existed.

Leave a Reply

Your email address will not be published. Required fields are marked *