Back to News
PolicyAI Understanding briefing

Bristows reports US appeals court narrowed CFAA claim against Perplexity’s AI agent

Bristows reports that a US Circuit Court overturned an injunction against Perplexity after finding that Amazon had not shown Perplexity itself accessed Amazon’s servers under the Computer Fraud and Abuse Act. The ruling concerned interim relief, and Amazon’s underlying case remains ongoing.

By 6 min read
AI-generated editorial illustration accompanying Bristows reports US appeals court narrowed CFAA claim against Perplexity’s AI agent
The short version

Bristows reports that a US Circuit Court overturned an injunction against Perplexity after finding that Amazon had not shown Perplexity itself accessed Amazon’s servers under the Computer Fraud and Abuse Act. The ruling concerned interim relief, and Amazon’s underlying case remains ongoing.

What happened

Bristows reports that a US Circuit Court overturned a preliminary injunction preventing Perplexity’s Assistant from operating on Amazon.com. The court found that, for the specific CFAA claim at issue, the user—not Perplexity or the software itself—accessed Amazon’s computers. The decision did not resolve Amazon’s broader claims or determine whether Perplexity could avoid liability in other legal or contractual contexts.

Bristows reports that Amazon sued Perplexity in November 2025, alleging that Perplexity’s shopping Assistant wrongfully accessed Amazon customers’ accounts and disguised agent activity as human browsing. Amazon argued that the activity violated its Conditions of Use and the US Computer Fraud and Abuse Act, or CFAA. For the relevant CFAA theory, Amazon needed to show, among other elements, that Perplexity intentionally accessed a computer without authorization or exceeded authorized access and obtained information from it. The dispute concerns how existing computer-access law applies to an AI system performing tasks at a user’s direction.

Bristows says the District Court granted Amazon a preliminary injunction in March 2026, concluding that Amazon had shown a likelihood of success on its CFAA claim and likely irreparable harm without an injunction. The injunction barred use of the Assistant on Amazon.com. The Assistant can browse Amazon to locate products and make purchases. When activated by a user, it takes screenshots of the browser view and sends them from the user’s computer to Perplexity’s servers. Those servers send navigation instructions back to the Assistant, which acts on Amazon.com using both the user’s direction and the provider’s instructions.

Bristows reports that the Circuit Court overturned that decision on August 4, 2026, finding that Amazon was unlikely to succeed on the merits because it had not shown that Perplexity “accessed” Amazon’s computers for purposes of the CFAA. The court concluded that Perplexity itself did not directly communicate with Amazon’s servers. It also held that the Assistant could not be treated as the intentional accessor because the software was not a “person for statutory purposes.” On the facts described by Bristows, the court instead treated the user as the party accessing Amazon with the Assistant’s help.

Amazon argued that Perplexity should be treated as the accessor because its servers directed the Assistant’s behavior and the Assistant acted autonomously like a human shopper. Perplexity argued that no Perplexity computer entered the user’s Amazon account: Amazon data was first transmitted to the user’s computer and then to Perplexity through browser screenshots. Perplexity also argued that the Assistant had no independent intent and acted only on the user’s behalf. Bristows notes that the appeals court’s conclusion addressed the CFAA’s specific access requirement, not every possible basis for liability.

Read the primary source: inquisitiveminds.bristows.com

Why it matters

The ruling offers an early judicial treatment of responsibility when an AI agent acts through a user’s browser while receiving instructions from an AI provider’s servers. Bristows says the court adopted a narrow interpretation of “access” under a statute aimed at hacking, leaving unresolved how liability should be assigned when an agent’s actions are partly directed by a provider and partly initiated by a user.

Bristows’s account matters because the ruling separates technical control from statutory access. Perplexity’s servers reportedly supplied the instructions needed for the Assistant to complete a task, yet the court did not treat that role as equivalent to Perplexity directly entering Amazon’s computers. The result leaves a gap between how an AI agent operates in practice and how older statutes describe a human or company accessing a computer. That gap could affect disputes involving browsing agents, purchasing agents, coding systems, and other tools acting through a user-controlled environment.

The decision illustrates the limits of applying a statute designed to combat hacking to newer automated activity. Bristows reports that the Circuit Court stressed it was deciding only the meaning of “access” under the CFAA and did not treat the statute as a broad misappropriation law. The narrow reading may prevent the preliminary injunction from becoming a sweeping rule about AI-agent responsibility. It also should not be read as a general declaration that providers are insulated from consequences when their systems cause unauthorized or harmful outcomes.

The attribution question is important for businesses and consumers adopting agentic AI. Bristows says the court’s reasoning ascribed the relevant access to the user, even though the Assistant depended on Perplexity’s server-side instructions. If applied elsewhere, parties may face uncertainty about whether responsibility for an agent’s choices belongs to the person who initiated the task, the provider that designed and operated the agent, or both. The answer could influence procurement, insurance, platform rules, incident response, and agreements allocating responsibility for agent behavior.

Bristows also reports that the Circuit Court rejected Amazon’s argument that it would suffer irreparable cyber-risk harm without an injunction, describing the supporting evidence as limited. That narrows the ruling’s immediate significance: it did not establish that the Assistant’s activity was harmless, authorized in every sense, or safe for Amazon’s systems. It found only that the evidence and legal theory presented at the preliminary-injunction stage were insufficient. An interim ruling does not substitute for a final determination after fuller factual development.

What to watch next

Amazon’s substantive proceedings against Perplexity remain ongoing, according to Bristows. Key unresolved questions include whether other legal theories, contractual claims, or different facts could produce a different result; how courts will attribute an agent’s intent; and what remedies customers may have when an AI agent causes harm. The underlying judgment and broader case record were not independently reviewed here.

The most immediate development to watch is the continuation of Amazon’s substantive case against Perplexity. Bristows states that the underlying proceedings remained ongoing when it published its analysis. Future stages could address claims or evidence not resolved by the preliminary injunction appeal, including whether Perplexity violated Amazon’s contractual conditions, whether account information was handled improperly, and whether the Assistant’s operation caused a legally recognized harm. The source does not provide a trial date, final ruling, damages figure, or settlement information.

Courts may confront different technical arrangements. The outcome could differ if an AI provider’s own infrastructure directly connects to a target service, if the provider uses credentials controlled by the provider rather than the user, or if the agent operates without a clear user instruction for a particular act. Bristows’s article does not establish how the appeals court would treat those scenarios. It also does not establish whether another court, another statute, or a different jurisdiction would adopt the same interpretation of access or intent.

Contract language will be another important area to monitor. Bristows says customers of agentic AI tools may have limited recourse against suppliers if an agent goes rogue. That is a legal concern raised in the article, not a finding that all such contracts are inadequate. Organizations considering these systems will need to examine who authorizes actions, how credentials and browser sessions are controlled, what logs are retained, how disputed actions are investigated, and whether providers accept responsibility for provider-directed behavior. The source does not identify specific contract terms or customer disputes.

Finally, Bristows raises—but does not resolve—the possibility that courts might view the risks differently after other reported AI-agent incidents, including a later hack involving OpenAI agents and Hugging Face. That comparison is speculative and should not be treated as evidence in the Amazon case. The key unknown is whether future courts will develop a more tailored framework for assigning responsibility across users, providers, and software, or continue applying existing doctrines one element at a time. The underlying Circuit Court opinion was not independently reviewed for this assessment, so the account remains attributed to Bristows.

Related guides & quizzes

AI AgentsAI EthicsAI Models ExplainedTest what you know — try a free AI quizLook up an AI term in our glossary
Found this useful?