On 4 August 2026, the U.S. Court of Appeals for the Ninth Circuit decided Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444. The issue was whether Perplexity's Comet AI agent violated 18 U.S.C. § 1030(a)(2) of the Computer Fraud and Abuse Act when it accessed Amazon.com to execute user-initiated tasks. The court rejected Amazon's interpretation of § 1030(a)(2) and affirmed the district court's outcome on the narrow question of access as the statute defines it. The opinion is a binding Ninth Circuit precedent.
18 U.S.C. § 1030(a)(2) prohibits intentionally accessing a computer without authorisation or in excess of authorised access and obtaining information from any protected computer. Amazon argued the Comet assistant's retrieval of data from Amazon.com constituted such unauthorised access. The court applied the rule of lenity, which requires ambiguous criminal statutes to be construed against liability. Because the CFAA operates primarily as a criminal statute, the court resolved interpretive ambiguity in Perplexity's favour on the access question. The opinion expressly limits its holding to the access question on the specific record before the court.
AI developers operating agentic tools that access third-party websites and services face ongoing legal uncertainty about the CFAA's scope. The ruling does not immunise agentic AI from CFAA liability in all factual contexts; it resolves only the access question as applied to the Comet assistant on the record presented. AI companies building agents that scrape data, automate web navigation, or retrieve third-party content must assess their exposure under tort law, contractual terms-of-service provisions, and other federal and state statutes the court left expressly open.
The court stated that agentic AI is an emerging technology and that the opinion does not establish a new legal regime governing it. Tort claims and contract claims arising from terms-of-service violations were not before the court and remain unresolved. Further litigation in different factual contexts, involving different AI agent architectures and website access methods, is probable. No other federal circuit court has addressed agentic AI and CFAA access liability on comparable facts.
Licentium advises AI companies and platform operators on legal exposure from agentic AI deployment and automated third-party data access. Work we undertake includes CFAA exposure analysis, agentic AI governance documentation, terms-of-service compliance review, and cross-jurisdictional regulatory risk assessments for AI product and legal teams.
Source: Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026)