Ninth Circuit Vacates Amazon's CFAA Injunction Against Perplexity's Comet Browser
The Ninth Circuit vacated Amazon's preliminary injunction against Perplexity's Comet on August 4, 2026, drawing a durable line between tool-maker and user under the CFAA. The ruling matters for every developer building software that touches third-party systems.

The Ninth Circuit drew a line incumbents have been trying to erase: building a tool users operate is not unauthorized computer access.
Key takeaways
- The Ninth Circuit vacated Amazon's preliminary injunction against Perplexity's Comet browser on August 4, 2026, ruling Amazon is unlikely to prove Perplexity "accessed" its servers under the CFAA because users, not Perplexity, operate the tool.
- The court applied the rule of lenity to construe CFAA ambiguity against liability, and explicitly noted, per the opinion, that there is "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents" under the statute.
- The case goes back to district court. Amazon's trademark and state-law claims survive. The Ninth Circuit said its holding is narrow and that agentic AI law "will doubtless change."
The Ninth Circuit Court of Appeals vacated the preliminary injunction Amazon had secured against Perplexity AI's Comet browser, per the court's opinion in No. 26-1444 issued August 4, 2026. The panel, authored by Circuit Judge Milan D. Smith, Jr., held that Amazon is unlikely to succeed on its Computer Fraud and Abuse Act claim because Perplexity's agentic "Assistant" is a tool operated by users, not by Perplexity itself.
Amazon had sued Perplexity in November 2025, claiming Comet's AI Assistant violated the CFAA and California's CDAFA by accessing Amazon's password-protected pages without authorization. U.S. District Judge Maxine M. Chesney granted a preliminary injunction on March 9, 2026, blocking Comet from touching Amazon's logged-in account pages. The Ninth Circuit stayed that order pending appeal, heard oral arguments in Seattle on June 11, 2026, and has now vacated the injunction entirely.
What the Court Actually Said
The panel's core holding is straightforward: Perplexity does not "access" Amazon's servers. Users do. Even where Perplexity received account information from users and used it to instruct the Assistant, the court found that fell short of the level of control required to pin the access on the developer.
The court acknowledged the novelty directly: per the opinion, there is "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context." It resolved the ambiguity through the rule of lenity, construing the statute against liability, per the Ninth Circuit's prior holding in Brekka. Because the CFAA is primarily a criminal statute and courts' interpretation of its provisions are equally applicable in civil and criminal contexts, the court construed any ambiguity in the statute against liability.
The Electronic Frontier Foundation filed an amicus brief in April 2026 arguing the same architecture point. The EFF amicus brief framed it cleanly: "Developers like Perplexity facilitate that access by creating tools that enable users to meaningfully engage with the web." Per the court's opinion, the panel cited EFF's explanation of how Comet's architecture works as particularly clarifying on this point.
Why This Matters Beyond Perplexity
The CFAA has been a preferred weapon for platform incumbents looking to criminalize competition dressed up as anti-hacking enforcement. Amazon's theory, that a developer violates the CFAA when a user authorizes that developer's tool to access a third-party system, is structurally identical to what a hostile regulator or incumbent platform could deploy against a Bitcoin wallet, a Lightning node client, a Nostr relay tool, or any agentic AI layer that touches external systems on a user's behalf.
The user-authorization principle is the moat. Most freedom-tech tools are built exactly this way: the user holds the keys, the user runs the software, the user initiates the connection. Developers building on that model now have published Ninth Circuit precedent that their act of building the tool does not constitute unauthorized access under the CFAA. The Ninth Circuit is the most influential circuit for tech law and covers California, where nearly every major platform company is domiciled. Published opinions carry weight nationwide.
The ruling also has a direct read-across to self-custody Bitcoin tools. Any argument that a wallet developer "accessed" a counterparty's system because a user broadcast a transaction through that wallet would run directly into this framework. Incumbents and regulators hunting for a legal theory to leash open-source developers now have a harder road in the Ninth Circuit.
What Comes Next
This is a battle won, not a war ended. The preliminary injunction ruling only resolves likelihood of success at the injunction stage. The case returns to the Northern District of California, where Amazon's trademark and California CDAFA claims remain live. The Ninth Circuit was explicit that its holding is narrow, limited to the "access" prong, and that "the legal understanding of agentic AI will doubtless change."
The thesis here collapses if: the district court ultimately rules for Amazon on the merits; Congress amends the CFAA to assign agentic AI access to the developer rather than the user; or circuits outside the Ninth reject the user-operates-the-tool framework entirely. Any of those outcomes reopens the door. Watch the district court docket and watch for any Congressional "clarification" of the CFAA that the platform lobby pushes through under the cover of AI safety.
Sources
Frequently Asked Questions
No. The court explicitly limited its holding to the "access" prong of the CFAA and to the preliminary injunction stage. It did not resolve the merits of the broader case, did not address all possible agentic AI configurations, and noted the law in this area will evolve. Other legal theories, including state computer fraud statutes and trademark claims, were not addressed.
The CFAA is a federal anti-hacking statute Congress originally enacted in 1984 as part of the Comprehensive Crime Control Act. It has increasingly been weaponized in civil litigation by platform incumbents seeking to block competitors who build tools that interact with their systems. Any developer building software that accesses third-party servers on a user's behalf, whether that's a Lightning wallet, a Nostr client, or an agentic AI browser, faces potential CFAA exposure under aggressive readings of the statute. The Ninth Circuit's ruling narrows that exposure for developers who build tools users operate rather than tools the developer operates autonomously.
The Ninth Circuit's jurisdiction covers California, Oregon, Washington, Nevada, Arizona, Idaho, Montana, Alaska, Hawaii, and two territories. Its published opinions carry persuasive authority in other circuits but are not binding outside its jurisdiction. Congress could override the ruling by amending the CFAA, and circuits in other regions could adopt a different framework. The Supreme Court has the final word, and it has not addressed this question.


