From the journal

Ninth Circuit Declines Broad CFAA Reading for Agentic AI Access, August 2026

On 4 August 2026, the U.S. Court of Appeals for the Ninth Circuit issued its opinion in Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444. The court declined to hold that Perplexity's Comet AI agent violated 18 U.S.C. § 1030(a)(2) of the Computer Fraud and Abuse Act by accessing Amazon.com. Applying the rule of lenity, the court construed the statute's access provisions narrowly on the facts presented and declined to establish a broader legal regime governing agentic AI.

2 min read

On 4 August 2026, the U.S. Court of Appeals for the Ninth Circuit decided Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444. The issue was whether Perplexity's Comet AI agent violated 18 U.S.C. § 1030(a)(2) of the Computer Fraud and Abuse Act when it accessed Amazon.com to execute user-initiated tasks. The court rejected Amazon's interpretation of § 1030(a)(2) and affirmed the district court's outcome on the narrow question of access as the statute defines it. The opinion is a binding Ninth Circuit precedent.

18 U.S.C. § 1030(a)(2) prohibits intentionally accessing a computer without authorisation or in excess of authorised access and obtaining information from any protected computer. Amazon argued the Comet assistant's retrieval of data from Amazon.com constituted such unauthorised access. The court applied the rule of lenity, which requires ambiguous criminal statutes to be construed against liability. Because the CFAA operates primarily as a criminal statute, the court resolved interpretive ambiguity in Perplexity's favour on the access question. The opinion expressly limits its holding to the access question on the specific record before the court.

AI developers operating agentic tools that access third-party websites and services face ongoing legal uncertainty about the CFAA's scope. The ruling does not immunise agentic AI from CFAA liability in all factual contexts; it resolves only the access question as applied to the Comet assistant on the record presented. AI companies building agents that scrape data, automate web navigation, or retrieve third-party content must assess their exposure under tort law, contractual terms-of-service provisions, and other federal and state statutes the court left expressly open.

The court stated that agentic AI is an emerging technology and that the opinion does not establish a new legal regime governing it. Tort claims and contract claims arising from terms-of-service violations were not before the court and remain unresolved. Further litigation in different factual contexts, involving different AI agent architectures and website access methods, is probable. No other federal circuit court has addressed agentic AI and CFAA access liability on comparable facts.

Licentium advises AI companies and platform operators on legal exposure from agentic AI deployment and automated third-party data access. Work we undertake includes CFAA exposure analysis, agentic AI governance documentation, terms-of-service compliance review, and cross-jurisdictional regulatory risk assessments for AI product and legal teams.

Source: Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026)

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

Matched-Category Analysis of the Hong Kong Stablecoin Issuer Route and the Singapore Digital Payment Token Service Route

This matter concerns whether current licensing data supports a commercial comparison between Hong Kong’s stablecoin issuer route and Singapore’s digital payment token service route. The question is whether the proposition remains legally accurate as of 12 August 2026. “Commercially useful” is assumed to mean useful for selecting a market-entry and operating model, not proof that either regulator is more permissive.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).