Ninth Circuit Rules AI Agents Cannot Be Held Liable Under Federal Hacking Law In Landmark Perplexity Case

In a ruling with sweeping implications for the agentic AI industry, the Ninth Circuit has determined that AI tools cannot violate federal hacking law because they are not people.

The U.S. Court of Appeals for the Ninth Circuit issued its decision on August 4, 2026, in the case of Amazon.com Services, LLC v. Perplexity AI.

The unanimous panel vacated a preliminary injunction that had previously barred Perplexity’s Comet browser and AI shopping assistant from accessing Amazon.com.

The court concluded that Amazon is unlikely to prevail on its Computer Fraud and Abuse Act claims based on the evidence before it.

At the heart of the ruling is a straightforward but consequential reading of the CFAA’s plain statutory language regarding who counts as an accessor.

The Ninth Circuit found that when a user instructs a Perplexity agent to act on their behalf on Amazon.com, it is “the user who ‘accessed’ Amazon’s computers,” not Perplexity itself.

The panel explained that a computer by itself cannot violate the CFAA because the statute’s language “contemplates access by a person,” which an AI tool is not for statutory purposes.

No matter how advanced the Perplexity assistant may be, the court drew a firm line between a sophisticated software tool and a legal person capable of committing a statutory violation.

The decision has been described as the first federal appellate ruling to directly address whether AI agents acting on behalf of users may legally access online platforms under anti-hacking statutes.

It establishes an early but significant legal framework for the fast-growing field of agentic commerce, where AI systems autonomously carry out tasks like purchasing goods and browsing services on users’ behalf.

For AI developers, the ruling offers a degree of protection from CFAA and California’s CDAFA claims when agents act at the explicit direction of a human user rather than on their own initiative.

However, the decision also signals to platform operators like Amazon that these anti-hacking statutes may not be the most effective legal instrument for policing unwanted agent access to their systems.

Other legal theories, including breach of terms of service, may still be available to website operators seeking to restrict or regulate AI agent activity on their platforms.

The harder and still-unresolved question the ruling raises is precisely which person bears legal responsibility when an agentic system causes harm, particularly as these tools grow more autonomous and are deployed in increasingly complex commercial environments.