Ninth Circuit vacates Amazon injunction in landmark Perplexity AI CFAA ruling
The Ninth Circuit Court of Appeals vacated a preliminary injunction against Perplexity AI, ruling that its AI assistant does not 'access' protected servers under the Computer Fraud and Abuse Act (CFAA) because the user's local browser initiates the connection. The court clarified that AI agents are tools rather than persons for statutory attribution, though it noted that future cases involving different technical architectures could lead to different outcomes.
Key Takeaways
- The court ruled that AI agents are tools, not persons, for the purpose of statutory attribution under the CFAA.
- Perplexity's technical architecture, which uses local browser communication rather than direct server-to-server access, was decisive in the ruling.
- Amazon's claims under California's CDAFA failed because the user, not the AI provider, was deemed the party accessing the site.
- The Ninth Circuit applied the rule of lenity, citing concerns that broad CFAA interpretations could criminalize ordinary computer-assisted behavior.
Why It Matters
This decision establishes a critical legal distinction between AI agents operating locally versus those running on provider-controlled infrastructure. For streaming platforms and digital storefronts, it signals that traditional anti-hacking statutes may not be the primary mechanism for blocking unwanted AI scrapers or automated shoppers. Instead, the ruling shifts the burden to private terms of service and technical access restrictions to regulate agentic behavior. As AI assistants become more autonomous, the industry must move toward explicit contractual language regarding automated data collection and delegated authentication. Watch for whether future cases involving direct server-to-server AI communication trigger different liability outcomes under the CFAA.
Additional Context
Perplexity AI has been at the center of multiple legal disputes over how AI systems interact with web content and platform infrastructure. In June 2025, Perplexity AI faced a separate lawsuit from Dow Jones and the New York Post alleging copyright infringement through unauthorized scraping of news content, a case that tests different legal theories than the CFAA but targets the same underlying behavior of automated data collection. The Ninth Circuit's ruling in the Amazon case now creates a potential safe harbor for AI agents that operate through a user's local browser, but it leaves open questions about server-side architectures where the AI provider's own infrastructure initiates connections. This distinction matters for streaming platforms evaluating whether to rely on anti-hacking statutes or terms of service to block unwanted automated access.
The broader regulatory environment for AI agents accessing commercial platforms is tightening from multiple directions. In July 2025, the Federal Trade Commission launched a 6(b) study into how major AI companies collect and use consumer data to train their models, signaling that consumer protection enforcement may fill gaps left by narrow statutory interpretations like the CFAA. Meanwhile, Amazon itself has pursued aggressive technical countermeasures against AI scraping. In early 2025, Amazon updated its terms of service to explicitly prohibit AI crawlers from accessing its retail platform without authorization, adding language to its robots.txt file that specifically targets AI training bots. This combination of contractual restrictions and technical blocking represents the private-ordering approach that the Ninth Circuit's ruling effectively pushes platforms toward.
The technical architecture distinction drawn by the court has direct implications for how AI-powered shopping and content discovery tools operate in the streaming and e-commerce space. Perplexity's Comet browser, which integrates AI assistance directly into the browsing experience, represents a class of products where the AI agent runs locally on the user's device. Perplexity launched Comet as a standalone AI browser in July 2025, positioning it as a competitor to traditional browsers with built-in AI capabilities. The court's reasoning that the user's browser initiates the connection could protect similar local-first AI assistants, but would likely not extend to cloud-based agents that autonomously crawl or query servers without a user's browser session. For streaming platforms deploying AI-driven content recommendations or facing AI-powered content aggregation, this architectural line will determine which legal frameworks apply to unauthorized automated access. are also beginning to shape how these agents must be governed, alongside new proposals like the .
Read full article at jdsupra.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source