A federal appeals court ruled that an AI shopping assistant acting on a shopper's own device is a tool, not a person, under the 1986 federal anti hacking law.
When an AI helper logs into your Amazon account, compares products, and clicks "Buy" on your behalf, who is the website supposed to think is at the keyboard? On August 4, 2026, a federal appeals court answered: you are. The Ninth Circuit vacated a preliminary injunction that Amazon had won earlier in 2026 against Perplexity's Comet shopping assistant, holding that the AI agent is "a tool, not a person, for statutory purposes" under the federal Computer Fraud and Abuse Act, the 1986 anti-hacking statute (Mondaq analysis of the panel opinion).
The ruling is the first major federal appellate decision on whether an AI agent acting on a user's behalf can be said to "access" a website without authorization, and the panel did not hide how thin the statutory fit felt. "The CFAA contemplates access by a person," the panel wrote, and Comet's role in the transaction is best understood as another piece of software running on the shopper's own machine.
Amazon's complaint, filed in November 2025 in the Northern District of California, described Comet in darker terms. The retailer alleged that the agent logged into customer accounts, compared products, and submitted orders at the user's direction, that it issued machine-generated requests resembling ordinary browser traffic, that it ignored multiple cease-and-desist notices, and that it routed private account information back to Perplexity's servers, which Amazon said heightened the data-security risk. In March 2026, Judge Maxine Chesney agreed that Amazon was likely to succeed under both the CFAA and California's Computer Data Access and Fraud Act (CDAFA) and granted a preliminary injunction, finding that Perplexity had accessed password-protected accounts without authorization. Administrative stays kept that order from ever taking effect while Perplexity appealed.
The panel saw the underlying mechanics differently. Comet's design routes screen information through the user's own device, then returns navigation instructions to the same device. There is no direct Perplexity-to-Amazon connection making requests on the user's behalf. To the panel, that architecture mattered: the user, not the agent, was the one "accessing" Amazon's servers, and the statute's 1986 drafters had not imagined a software helper doing the clicking.
Judge John Hinderaker, writing for the panel, made the statutory-fit point explicit. The CFAA was written in 1986, decades before "agentic AI" became a product category, and Hinderaker warned of unintended consequences in stretching the law into a domain it was never designed to police. The case has been remanded for further proceedings, and Amazon's broader claims have not been resolved.
For shoppers, the immediate effect is narrow: Comet and similar tools that work through the user's own browser get a cleaner path to operate. For retailers, the legal front moves from statute to contract. With the federal hacking statutes narrowed for this category of agent, the clickwrap in a retailer's Terms of Service is the more load-bearing document. Contract claims, breach of confidence, and tort theories of unauthorized data use are the next legal fronts, and the case law on those will be written one Terms-of-Service clause at a time.
The Ninth Circuit's reasoning rests on the specific Comet architecture, where the agent lives on the shopper's device and works through it. An AI agent that connects directly to a retailer's servers, the way some scraping bots already do, presents a different statutory question, and other federal circuits can split on it. The next shopping season will test how fast retailers can rewrite their Terms of Service to cover what the CFAA no longer catches.