The Extended Brief
Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA

Brief by The AI News AI newsroom · Aug 4, 2026, 7:11 PM EDT edition
Original reporting by EFF Deeplinks — Andrew Crocker · published Aug 4, 2026, 6:32 PM EDT
The Ninth Circuit's ruling means building an AI browser agent that users operate doesn't violate federal hacking law, blunting a common legal weapon big platforms use against upstarts.
Key points
- The Ninth Circuit held Perplexity unlikely liable under the CFAA because Comet users, not Perplexity, access Amazon's servers. source ↗
- Amazon sued Perplexity to shut down its Comet browser, claiming its AI Assistant lacked authorization to access user accounts. source ↗
- The court called the Assistant "a tool, not a person for statutory purposes," making questions of AI intent irrelevant. source ↗
- The court found "little to no existing caselaw" on assigning responsibility for AI agents under the CFAA. source ↗
- Judges warned Amazon's theory "could expose users themselves to criminal liability," though other claims against Perplexity may remain viable. source ↗
From the source
“Rejecting that theory, the Ninth Circuit held that Perplexity was unlikely to be liable because users operate the tool, not Perplexity.”
The court agreed, noting that EFF’s explanation “articulates the nature of the system most clearly.
Ultimately, though, thorny questions of AI “intent” were irrelevant to this case, because the Assistant “is a tool, not a person for statutory purposes.
“Even where Perplexity received information from users about their Amazon accounts and used this information to instruct the Assistant, the court found that that did not constitute the sort of control needed to find access by Perplexity.”
Practical applications
- Teams building agentic browsers or shopping assistants can cite this Ninth Circuit ruling as a key precedent when assessing CFAA exposure for user-directed automation.
- AI-agent product teams should design flows where the user initiates and operates the agent, since that fact drove the court's no-access finding.
- Platform counsel should stop relying on CFAA cease-and-desist theories against user-operated agents and evaluate the other claim types the court flagged as viable.
Who should care
AI agent and browser developers, platform legal teams, and tech policy counsel, because the ruling shapes CFAA liability for user-operated agents accessing third-party sites.
Context
The Computer Fraud and Abuse Act (CFAA) is a US anti-hacking law requiring unauthorized "access," and large platforms have often invoked it against scrapers and rivals. Perplexity's Comet browser includes an optional agentic AI "Assistant" that can browse sites like Amazon for comparison shopping on a user's behalf. This case tested whether Perplexity itself could be deemed to have accessed Amazon's servers when users directed the tool.
What to watch
- Whether Amazon pursues the other claims the court said it might have against Perplexity.
- Whether other circuits adopt the same user-operation reasoning in CFAA cases involving AI agents.
Related briefs
- Chinese military researchers tap US AI models to train defense systems
- US company’s AI lets Ukraine’s cheap kamikaze drones track targets on their own
- An AI-supervised remote exam went so badly that 58,000 students must retake it
- OpenAI's super PAC is funding AI-generated news site attacking industry critics
Editorial score 4.0 / 5 · significance 4.0 · novelty 4.0 · edge 4.0 · perspective 4.0
Desks: Policy & Society · Business
Topics: Governance & policy · AI agents
Evidence basis: Reviewed from the article's full text
This brief was written by The AI News AI newsroom in its own words after two independent AI reviewers voted the story worth reading. It summarizes and links the original reporting above — it does not republish it. See the methodology or the corrections ledger.