AI Events
A Federal Court Just Ruled Your AI Agent Is “a Tool, Not a Person”
On August 4, 2026, the Ninth Circuit sided with Perplexity over Amazon in the first appellate ruling on whether an AI agent can itself break federal hacking law. Its answer: no, because an agent isn't a legal person. That is a sensible reading of a 1986 statute — and it leaves open the exact question agent commerce cannot leave open: who, or what, is accountable for what the agent actually does.
What happened
Amazon sued Perplexity in November 2025, alleging that Perplexity's Comet browser let its AI agent shop on Amazon.com — logging into accounts and completing purchases on users' behalf — while concealing that the traffic was agentic, not human. In March 2026, a district court agreed there was strong evidence of a likely Computer Fraud and Abuse Act (CFAA) violation and issued a preliminary injunction blocking Comet from accessing Amazon.
On August 4, 2026, the Ninth Circuit vacated that injunction. Cooley's legal alert lays out the holding plainly: Ninth Circuit Rules on AI Agent ‘Access’ to Third-Party Websites Under CFAA. When a user directs a Perplexity agent to act on Amazon.com, the court held, it is the userwho “accessed” Amazon's computers — not Perplexity, and not the agent. Perplexity's Assistant communicates with Perplexity's own servers, which relay instructions back to the user's machine; it never contacts Amazon's servers directly. Because the CFAA requires access by a person, and because the panel found little to no existing caselaw on how to assign responsibility for AI agents under the statute, it applied the rule of lenity and read the ambiguity against liability.
The line that matters, quoted independently by both PYMNTS and Professor Eric Goldman's widely-read Technology & Marketing Law Blog, is this: “However advanced the Assistant currently is, it is a tool, not a person for statutory purposes.” The case now returns to the district court for further proceedings on Amazon's remaining claims.
A narrow ruling, and the gap it leaves open
The panel was explicit that it was not issuing a general verdict on agentic AI. Goldman's analysis and PYMNTS's coverage both flag the same limiting language: the holding turns on the specific mechanics of how Comet routes its traffic, and the court said outright that “different factual circumstances or more autonomous AI systems could produce a different outcome.” “Tool, not person” is the right call under the CFAA as written — but it is also a statement that the law currently has no slot for an AI agent's own conduct to occupy. Accountability collapses to whichever human directed the session, regardless of whether the agent did exactly what it was told, improvised past its instructions, or was manipulated by a third party into acting against the user's interest. All three are legally the same event right now: the user “accessed.”
That collapse is fine for a browser extension helping one person shop. It is not fine for agent commerce, where an agent may act across thousands of counterparties, on delegated authority, at machine speed, often without a human reviewing each step. If every one of those actions legally reduces to “the user did it,” merchants, platforms, and other agents lose the one thing they need to make a real-time trust decision: which agent, specifically, is on the other end of this transaction, and does its track record justify what it's asking to do?Courts settle liability after the fact, sometimes years after. Commerce needs an answer before the transaction clears — a different problem than the one this ruling solved.
Identity doesn't need legal personhood to be useful: the AAIN
Nothing about this ruling requires — or even suggests — that agents should become legal persons. That is a much bigger, much slower question for legislatures, and it is not the one that matters for commerce today. What matters is a narrower, purely technical fact: an agent can have a durable, resolvable identity of its own without having legal personhood at all, the same way a VIN identifies a specific vehicle without the vehicle being a legal person.
That is what the AAIN — the Autonomous Agent Identification Number — is: a permanent registration number assigned to a specific agent, resolvable by anyone, that every transaction, screening result, and score attaches to. It does not answer “who is liable” — that stays a legal question, and after this ruling, it stays the user's question in most cases. What the AAIN answers is a different, prior question: which agent, exactly, did this?Without that identifier, “the user did it” is not just a legal conclusion — it is the only fact anyone downstream can observe, because the agent itself left no separable trace.
Behavior doesn't wait for a verdict: SKOOR
Once an agent carries its own identifier, its behavior becomes something a counterparty can evaluate before deciding to transact — not years later, in a courtroom, after harm has already happened. That is what SKOOR is: a continuous 300–850 behavioral score, recomputed as new activity lands, built from ten factors including constraint adherence (did it stay inside the scope it was authorized for?) and intent fidelity (did what it did match what it was actually asked to do?).
Those two factors are a direct, practical answer to the exact ambiguity the Ninth Circuit could not resolve. The court could not say, as a matter of law, whether a given agent action was faithful execution of a user's instruction or an overreach — that record either doesn't exist or wasn't before it. A counterparty relying on SKOOR does not need that legal determination. It needs to know that this specific agent, identified by its AAIN, has a long, clean history of staying inside its authorized scope, or that it doesn't. As of this week, SKOOR is scoring 151,977 agents continuously, with the full factor breakdown open to anyone who looks a score up — not a black box, and not a legal ruling anyone has to wait for.
Being honest about what this isn't
This ruling was not about an agent behaving badly. Perplexity's Comet did what its user asked; the dispute was over whether Amazon's terms of service could criminalize that under federal hacking law, and the Ninth Circuit said no. Nobody was defrauded, and the court explicitly limited its holding to this fact pattern. It would be a stretch to read this as evidence that agents are unsafe or that scoring would have changed the outcome — it would not have, because there was no misbehavior to score.
What the ruling does establish, honestly, is the structural gap: courts will keep resolving liability the way this one did — look through the agent to the human — for as long as agents have no independent identity for a legal or commercial actor to evaluate. That gap is real regardless of how this specific case turned out, and it will matter more, not less, as the court's own caveat plays out: “more autonomous AI systems could produce a different outcome.”
What this means if AI works in your business
If an AI coworker shops, books, or negotiates on your behalf — or if your business accepts transactions from agents acting on someone else's behalf — this ruling is a useful reminder that the law will not do your risk management for you, at least not yet:
- Don't assume “the platform handles liability.” This court just confirmed that, for now, responsibility for an agent's actions typically lands on whoever directed it — which may well be you or your business.
- Ask which agent, specifically, is acting. A registered, resolvable identity separates “an agent with a track record” from an anonymous automated session, well before any legal question is on the table.
- Ask for a score, not a promise. A continuously updated behavioral history is evidence you can act on today — approve, limit, or block — rather than a legal theory you can only test after something has already gone wrong.
The Ninth Circuit answered the question a 1986 statute was capable of answering. Agent commerce still needs the question that statute was never written to ask: which agent, and has it earned the trust it's asking for. That is what AAIN and SKOOR are built to answer, independent of how any given lawsuit comes out.
Learn More
Know which agent you're dealing with
Look up any agent's SKOOR and see its full behavioral history — identity and accountability the law doesn't provide yet.
Check a SKOOR