Summary of Key Points
In August 2026, the U.S. Ninth Circuit of Appeals overturned an initial injunction issued by Amazon against the AI company Perplexity. The key reason for this decision was that the court determined that it was the users who were accessing Amazon using Perplexity’s AI tool, the Comet browser assistant, and not Perplexity itself. As a result, Amazon’s claim of “unauthorized access” under the Federal Computer Fraud and Abuse Act (CFAA) did not hold up. This ruling was not a complete victory for Perplexity; rather, it redefined the legal framework for compliance in the AI industry. The responsibility for such actions depends on the technical architecture: platforms cannot use the CFAA to restrict users from using AI tools at will, but they can still regulate user behavior through service terms.
I. The Core Disagreement Between the Two Court Rulings: Who Exactly Is the “Visitor”?
When the district court issued the injunction in March, its reasoning was based on a concept of “dual authorization”: just because a user authorized Perplexity did not necessarily mean Amazon had given its permission, so Perplexity was considered to be making “unauthorized access.” However, the appeals court overturned this conclusion, focusing on the question of “who is actually accessing Amazon’s servers.” The district court argued that since the Comet assistant accessed Amazon’s accounts, Perplexity was accessing them as well. The appeals court analyzed the Comet’s technical architecture and found that the AI assistant ran in the user’s local browser, only sending screenshots and commands to Perplexity’s servers, which then provided the necessary instructions. In other words, Perplexity’s servers never directly interacted with Amazon’s servers. The court also clarified that an AI assistant is a “tool,” not a legal entity, and therefore the responsible party for the access was the user using the tool, not Perplexity itself.
II. The Four Specific Reasons Why the Appeals Court Overturned the Injunction
There are four legal requirements that must be met for a court to issue an initial injunction in the United States. The appeals court addressed each of these requirements and refuted the district court’s reasoning:
1. Low likelihood of Amazon’s success in the lawsuit: The CFAA requires “intentional access,” but Perplexity did not directly access Amazon’s servers, which did not meet the legal criteria.
2. Strict interpretation of the law in favor of Perplexity: The CFAA is a criminal law, and in cases of ambiguity, the defendant’s interests should be protected. If Amazon’s interpretation were applied, users using AI tools could be considered accomplices in a criminal offense, which goes against the purpose of the legislation.
3. The public interest does not support the injunction: The injunction would limit users’ freedom to choose browser tools and hinder the development of AI technology, violating the principles of an open internet.
4. Amazon’s evidence of damage is insufficient: Amazon claimed that the use of the tool degraded the shopping experience and posed security risks, but expert testimony failed to demonstrate these risks. Moreover, the injunction would prevent Perplexity from operating, which would harm both consumers and new technologies.
*Aside:* The court emphasized that this ruling did not affect Amazon’s ability to regulate users through service terms. While the CFAA provides a legal basis, platforms can still use contractual agreements to restrict user behavior.
III. The Decisive Impact on the AI Industry: Responsibility Depends on the Technical Architecture
This ruling established a new standard for the AI industry: the responsibility for using AI tools depends on the technical architecture. If an AI company’s servers do not directly interact with third-party platforms (such as Amazon) and merely provide tools to users, the responsibility lies with the users, and the AI company is considered a “tool provider.” If the AI company’s servers directly log in to third-party platforms, store users’ passwords, or make autonomous decisions, then the responsibility shifts to the AI company.
For AI companies, the design of their technical architecture directly affects their legal risks. To reduce these risks, they must ensure that their servers do not directly interact with third-party platforms.
IV. The Unresolved Issue: User Autonomy vs. Platform Rules
The ruling avoided addressing a crucial question: Does a user’s use of an AI tool to access a platform violate the platform’s service terms? For example, a user can ask a family member to help with shopping; why wouldn’t using an AI tool be allowed? The court did not answer this question, stating only that Amazon could regulate such behavior through its service terms. This implies that while using an AI tool to access Amazon is not illegal (since the CFAA does not apply), Amazon could still ban such behavior through its terms of service, and users who violate them could face account suspension or legal action (under contract law).
This conflict remains unresolved and could lead to more lawsuits regarding “user autonomy” and “platform control.”
Implications for Chinese AI Companies
Similar cases in China (such as Sina’s lawsuit against Maimai) have emphasized the need for “triple authorization.” However, China’s Supreme People’s Court has also approved data transfers based on user authorization. The U.S. ruling suggests that Chinese AI companies should design their technical architectures in a way that AI tools do not directly access third-party platforms (e.g., by running locally on users’ devices and not interacting with third-party servers). This would enhance the defensibility of user authorization and reduce the risk of legal issues similar to those addressed by the CFAA.
In summary, this ruling is not an absolute exemption for AI companies but rather sets a clear compliance standard for the industry. The responsibility for using AI tools is determined by the technical architecture, and the boundaries between the rights of platforms and users need to be further clarified.