Ninth Circuit Rules AI Agents Act on Behalf of Users, Not Developers
When an autonomous AI agent accesses a password-protected website, who actually does the accessing? According to the federal Ninth Circuit Court of Appeals, the person who directed the agent to access the site is the one responsible, not the company that developed the agent and certainly not the agent itself. In a case involving Perplexity […] The post Ninth Circuit Rules AI Agents Act on Behalf…
When an autonomous AI agent accesses a password-protected website, the person who directed the agent to access the site is deemed responsible, according to the Ninth Circuit Court of Appeals. This ruling was made in a case involving Perplexity and Amazon.com. The appeals court determined that Amazon was not entitled to a preliminary injunction that blocked Perplexity from accessing password-protected Amazon accounts.
The premise of the case was that Perplexity's Comet browser and its AI agent, Assistant, could carry out tasks like searching Amazon's website at the direction of a user. Prior to Perplexity's Comet launch in 2025, Amazon had informed Perplexity's CEO that Perplexity's AI products would not be allowed to access the Amazon Store.
Even after Comet's launch, Amazon reiterated to Perplexity that it did not have authorization to access the store. When Comet users began using Assistant to scrape Amazon's Store, Amazon sued Perplexity under the Computer Fraud and Abuse Act (CFAA) and California's Comprehensive Computer Data Access and Fraud Act (CDAFA). The Ninth Circuit's emphasis was on the fact that plaintiffs cannot use the CFAA as a general law for policing unwanted online conduct.
The court stated that "the Supreme Court has instructed that, 'in the computing context, 'access' references the act of entering a computer system itself or a particular part of a computer system, such as files, folders, or databases.'" The decision clarified that AI agents are not recognized as persons under the law, and their statutory status is that of tools, not individuals.
However, the court acknowledged that the ruling is limited in scope. It noted that it does not establish a new legal regime for agentic AI or address whether AI can avoid liability for its actions in other contexts, such as tort claims. The ruling, while narrow, offers an early indication that technical architecture may significantly impact CFAA risk for companies developing agentic products.
The decision also serves as a reminder for website operators that the CFAA may not be a comprehensive remedy for unwanted access, despite its evolving role in web-scraping litigation.
Written by urgent.news from PYMNTS's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.