US Court Rules: An AI Agent Shopping on Amazon Isn't "Hacking" — the User Is the One Accessing It

Entercast Consulting·

In August, the US Ninth Circuit Court of Appeals struck down an injunction that had barred Perplexity's Comet shopping agent from operating on Amazon — a ruling that defines, for the first time, whether AI agents that browse and act on websites on a user's behalf violate the US federal hacking law (CFAA).

What Changed

According to Engadget, the Electronic Frontier Foundation (EFF), and law firm Jones Day, Amazon sued Perplexity in November 2025, alleging that its Comet agent accessed Amazon's servers without authorization, in violation of the CFAA. A federal judge granted Amazon a preliminary injunction in March 2026, halting the agent's use. The Ninth Circuit's three-judge panel just reversed that ruling, arguing that the one technically "accessing" Amazon's servers is the user's own browser — Perplexity's agent merely receives and processes screenshots the user's browser had already captured. That architectural distinction placed Perplexity's activity outside the CFAA's scope.

Why It Matters

Until this ruling, the legal framework for AI agents browsing and acting on third-party websites on a user's behalf was essentially undefined in the US. PayPal, Google, Apple, and OpenAI itself have all launched or announced agent systems with purchasing capabilities — all operating in a legal gray zone similar to what Perplexity faced. The Ninth Circuit's decision sets, at least for now, a precedent favorable to agent builders.

The Impact for Brazil

Brazilian companies using or building AI agents that interact with third-party websites — price comparison, automated purchasing, market research — get a relevant precedent to watch, even though the ruling is US jurisdiction and doesn't directly bind Brazil. The logic behind the decision (the action belongs to the user who authorizes the agent, not the agent itself) is an argument likely to surface in similar disputes in other jurisdictions, including eventual conflicts in Brazil between platforms and agent vendors.

Entercast's Take

This case reinforces a point that matters for any company evaluating AI agents that take real action in the world (not just generating text): the agent's technical architecture — who authenticates, who actually "accesses" what — has direct legal consequences, not just engineering implications. Companies that clearly document that the agent acts under authorization and on the user's behalf, rather than autonomously and unsolicited, are better protected if this kind of dispute shows up here too.