A federal appeals court handed Perplexity a significant win Tuesday, August 4, 2026, in an early test of whether AI agents can help people shop on major websites without the platform owner's permission.
The U.S. Court of Appeals for the Ninth Circuit vacated a preliminary injunction that had blocked Perplexity's Comet browser assistant from operating on Amazon.com. The panel said Amazon was unlikely to prove that Perplexity itself illegally accessed Amazon computers under the federal Computer Fraud and Abuse Act, because the user was the one visiting Amazon with the AI tool's help.
The ruling does not end Amazon's lawsuit, but it changes the immediate balance. Perplexity can keep fighting from a stronger position, while Amazon and other platforms face a harder path if they try to use anti-hacking law to stop consumer-directed AI shopping assistants.
What changed
Amazon sued Perplexity in November 2025 after the startup's Comet browser allowed users to ask an AI assistant to browse Amazon, compare products, and carry out shopping tasks. A federal district judge in San Francisco sided with Amazon in March 2026 and issued a preliminary injunction against the tool.
On Tuesday, a three-judge Ninth Circuit panel reversed that order and sent the case back for further proceedings. The court said Amazon had not shown that Perplexity was likely to win on the central access question needed for the Computer Fraud and Abuse Act, known as the CFAA, or California's similar computer-access law.
The panel's reasoning turned on how Comet works. According to the court, the browser runs on the user's machine. When the assistant helps with an Amazon task, the user's browser receives Amazon pages, takes screenshots, and sends information back to Perplexity's servers for instructions. The court said that setup made the user's access different from Perplexity directly entering Amazon's computers.
Why shoppers and platforms care
The practical question is bigger than one browser. AI companies are racing to build agents that can act across websites: booking travel, finding cheaper products, comparing subscriptions, filling carts, or managing routine account tasks. Retailers and publishers, meanwhile, want to control how outside tools interact with logged-in accounts, advertising surfaces, product rankings, and private customer data.
If Amazon had kept the injunction, large platforms would have had a stronger example for blocking third-party AI agents whenever the platform had not granted permission. Tuesday's ruling points the other way, at least at this early stage: when a user is authorized to view a site and uses software to help, the platform may not be able to treat the software maker as the hacker.
That does not mean AI agents have a blank check. The case is still active, and the opinion was about a preliminary injunction, not a final trial judgment. Amazon can continue to argue other facts and legal theories in the district court, and it can seek further review. The ruling also leaves room for platforms to enforce contracts, account rules, privacy controls, fraud systems, and technical safeguards that were not finally resolved in this appeal.

The legal line the court drew
The CFAA began as an anti-hacking law. Over the years, courts have wrestled with whether it should also cover violations of website terms, automated scraping, credential sharing, and other behavior that looks less like breaking into a server and more like using a digital tool in an unwanted way.
The Ninth Circuit leaned on that narrower view. It said Amazon was unlikely to show Perplexity had performed the kind of computer access the statute requires. The panel also said the remaining injunction factors favored Perplexity because blocking conduct that likely does not violate the CFAA or the California statute would not serve the public interest.
That public-interest question drew attention from outside groups. Digital-rights and civil-liberties organizations backed Perplexity's position, warning that a broad ruling for Amazon could chill journalists, researchers, and ordinary users who rely on software tools to work with web pages they are allowed to view. Publisher and business groups were more sympathetic to Amazon's concern that unauthorized automated access could weaken website protections and revenue models.
What happens next
The case now returns to the Northern District of California. Amazon said it disagrees with the ruling and is evaluating next steps, according to the San Francisco Chronicle. Those options could include asking for broader Ninth Circuit review or eventually seeking Supreme Court intervention, though neither step is automatic.
For consumers, the ruling is not a simple promise that every AI shopping assistant will work everywhere. Websites can still change their systems, update account terms, limit suspicious activity, and challenge tools under other legal theories. Users should also be careful about handing AI agents account access, payment details, delivery addresses, or screenshots from logged-in pages.
For the AI industry, the decision is an important signal: the first major fights over agentic commerce may be decided less by broad AI policy and more by older laws about computer access, user authorization, contracts, and who actually touches a server. That makes this ruling a marker for the next wave of disputes over whether the web is navigated by people, platforms, or assistants acting somewhere in between.