From the journal

Ninth Circuit Finds AI Agent Data Retrieval Is Not CFAA Server Access, August 2026

On August 4, 2026, the Ninth Circuit vacated a preliminary injunction against Perplexity AI in Amazon.com Services, LLC v. Perplexity AI, No. 26-1444. The court held that Amazon is unlikely to show Perplexity accessed its servers under 18 U.S.C. § 1030 because the data passed through a user's device before reaching Perplexity, not from Amazon's computers directly.

2 min read

The Ninth Circuit Court of Appeals vacated a district court preliminary injunction against Perplexity AI on August 4, 2026, in Amazon.com Services, LLC v. Perplexity AI, No. 26-1444. Amazon had sought to restrict Perplexity's AI agent from accessing data on its platform, arguing the access violated the Computer Fraud and Abuse Act, 18 U.S.C. § 1030. The panel found Amazon unlikely to prevail on the merits and lifted the injunction.

Section 1030(a)(2) of the CFAA prohibits intentional unauthorized access to a protected computer and the obtaining of information from it. The Ninth Circuit applied the Supreme Court's limiting construction from Van Buren v. United States, 593 U.S. 374 (2021), under which CFAA liability requires a defendant to access the victim's own computer system. Perplexity demonstrated that Amazon data reached its servers only after first passing through the requesting user's device. The panel found that sequence dispositive: Perplexity did not directly query Amazon's infrastructure.

AI search and retrieval products that aggregate publicly accessible web content may cite this ruling to resist CFAA claims. Operators can argue that receiving data relayed via a user's browser does not constitute unauthorized server access absent evidence of direct computer intrusion. Website operators who want to restrict AI indexing cannot rely on the CFAA alone; they must depend on enforceable contractual terms of service and technical access controls, including authentication gates or CAPTCHA systems.

The ruling is a preliminary injunction decision, not a final merits judgment. Amazon may still litigate its CFAA claims to trial. The panel did not address AI agents that bypass login barriers or circumvent rate-limiting controls, which present materially different facts under the statute's exceeds-authorized-access prong. Whether other circuits will follow this reasoning remains open; the Second and Fifth Circuits have addressed CFAA access questions on narrower records.

Licentium advises on AI-related regulatory and commercial legal matters and maintains a partner network for matters requiring local counsel. To discuss how this ruling affects your AI product or data acquisition strategy, contact us at contact@licentium.io. Work we undertake includes: AI agent compliance, CFAA exposure analysis, data licensing and acquisition agreements, web scraping terms of service disputes, and platform regulatory strategy.

Source: Amazon.com Services, LLC v. Perplexity AI, No. 26-1444 (9th Cir. Aug. 4, 2026)

More from the journal

See all
Illia Prokopiev

MLR Registration and the FCA Cryptoasset Gateway to 25 October 2027

This matter concerns the transition of a United Kingdom cryptoasset business from FCA registration under the Money Laundering Regulations 2017 to Part 4A permission under the Financial Services and Markets Act 2000. The question is whether MLR registration gives conversion, grandfathering, priority, or a right to continue after 25 October 2027, and what an affected firm should do before the gateway closes. This analysis assumes an existing UK-facing cryptoasset business, no relevant Part 4A permission, and an intention to continue after commencement.

Illia Prokopiev

ESMA's 2026 Custody Resilience CSA and the Rules That Actually Bind

ESMA’s 2026 Common Supervisory Action is a coordinated national review of digital operational resilience in crypto-asset custody. It will test whether selected crypto-asset service providers can demonstrate effective controls across six announced workstreams. The legal questions are which requirements are binding, how national competent authorities may assess control effectiveness, and what consequences may follow from a deficiency. This analysis assumes that the firm is permitted under MiCA Article 59 to provide custody and administration within Article 3(1)(17).

Illia Prokopiev

Stablecoin regulation in the US, Hong Kong and Singapore

Stablecoin and digital-token regulation now combines market-entry authorization with continuous financial-crime controls in daily operations. The question is whether the United States’ proposed payment-stablecoin customer identification program, Hong Kong’s narrow first licensing round, and Singapore’s digital payment token (DPT) directory support a bank-like compliance characterization. They do, with material limits. The more accurate proposition is that compliance is moving beyond approval into continuous financial-institution-grade operations.