Amazon.com Services v. Perplexity AI – 9th Circuit Vacates Preliminary Injunction (2026)
Bottom Line
The U.S. Court of Appeals for the Ninth Circuit vacated the Northern District of California’s preliminary injunction against Perplexity AI’s Comet browser, finding that Amazon’s Computer Fraud and Abuse Act (CFAA) and California Comprehensive Computer Data Access and Fraud Act (CDAFA) claims are unlikely to succeed because the alleged “access” was performed by the user, not by Perplexity.
Case Overview
Parties: Amazon.com Services, LLC (plaintiff) vs. Perplexity AI, Inc. (defendant) Citation: Amazon.com Services, LLC v. Perplexity AI, Inc., 9th Cir. No. 26‑1444 (Aug. 4, 2026).
Core Dispute
- Perplexity’s Comet browser includes an AI “Assistant” that, when a user activates it, navigates Amazon.com, takes screenshots, and sends them to Perplexity’s servers for further instruction.
- Amazon warned Perplexity that the Assistant was unauthorized on its site and later sought a preliminary injunction alleging violations of the CFAA and CDAFA.
- The district court granted the injunction, finding Amazon likely to succeed on the merits and to suffer irreparable harm.
- On appeal, the Ninth Circuit vacated the injunction and remanded for further proceedings.
Legal Reasoning
1. Access Requirement under the CFAA
- Statutory text: The CFAA penalizes anyone who intentionally accesses a protected computer without authorization (18 U.S.C. § 1030(a)(2)).
- Court’s analysis: The panel held that access means the defendant must enter the target computer’s system. Perplexity never directly contacted Amazon’s servers; it only received screenshots from the user’s browser.
- Conclusion: Because the user performed the actual login and navigation, Perplexity did not “access” Amazon’s computers for CFAA purposes.
2. Parallel CDAFA Analysis
- California’s CDAFA defines “access” similarly—causing input or data processing on a computer without permission (Cal. Penal Code § 502(b)(1)).
- The court applied the same user‑centric reasoning and found Amazon unlikely to succeed on the CDAFA claim.
3. Equitable Factors for Injunction
- Irreparable harm – Amazon’s evidence of abstract harms (e.g., possible degradation of shopping experience) was deemed insufficient.
- Balance of equities – The injunction would heavily burden Perplexity’s development of a novel AI‑enabled browser while offering little concrete benefit to Amazon.
- Public interest – Blocking a nascent AI technology would impede consumer choice and innovation.
- Result: The remaining factors favored Perplexity, so the injunction was not warranted.
4. Scope of the Holding
- The opinion is limited to the “access” prong of the CFAA and CDAFA as applied to the facts before the court.
- It does not create a broader legal regime for agentic AI, nor does it address potential tort liability or other statutory theories.
Key Takeaways for AI‑Enabled Browsers
- User‑driven actions shield developers – When an AI tool merely relays user‑initiated actions, courts may view the user as the actual “accessor” of a third‑party site.
- Direct server contact matters – Liability under the CFAA is more plausible if the AI service directly communicates with the target site’s servers without user mediation.
- Preliminary injunctions are hard to secure – Plaintiffs must demonstrate concrete, not speculative, irreparable harm and a clear statutory violation.
- Policy considerations – Courts are wary of stifling emerging AI technologies that could benefit consumers.
Hacker News Community Insight
gz5: “AI is a legit threat to Amazon because headless browsing undermines ad revenue.”
eigencoder: “Perplexity’s behavior is akin to any browser that a user permits to use their credentials.”
theturtletalks: “LLMs will become the primary shopping interface, potentially displacing marketplaces like Amazon.”
cmiles8: “The ruling flips liability onto the user; Amazon may have to target customers rather than the AI provider.”
dzonga: “This is a welcome decision for search‑engine‑type services that scrape data; agents acting on behalf of users should be legal.”
These comments underscore two broader themes:
- Business impact – Companies fear AI agents will erode revenue streams tied to platform control (ads, data collection, friction).
- Legal strategy – Plaintiffs may need to focus on direct unauthorized server interactions rather than indirect, user‑mediated AI assistance.
What This Means for the Future
- Developers of agentic AI browsers should design architectures that avoid direct server‑to‑server communication with third‑party sites unless expressly authorized.
- Websites may need to update Terms of Service and technical defenses (e.g., mandatory user‑agent strings) to signal disallowance of AI agents.
- Policymakers may consider clarifying the scope of the CFAA and state analogues to address the gray area of AI‑mediated access.
- Litigation will likely focus on whether the AI tool exceeds user direction and acts autonomously in a way that constitutes “access” under existing statutes.
Final Verdict
The Ninth Circuit’s decision signals that, at least for now, AI tools that act as extensions of user intent are not automatically liable under the CFAA or CDAFA. Companies like Amazon must prove that the AI developer itself directly accesses their servers without permission, and they must present concrete evidence of irreparable harm to obtain injunctive relief.
Sources
Related
- Project
- Dispatch
- Dispatch
- Dispatch
- Dispatch