AI Events
When the Agent Is the User: What the Perplexity-Amazon Ruling Means for Agent Commerce
A federal appeals court just decided that an AI shopping agent acting on a user's instruction isn't an intruder — it's the user, using a tool. That is the right legal answer to a narrow question. It leaves open the much harder commercial one: how does a merchant verify what any given agent was actually told to do?
What happened
On August 4, 2026, the Ninth Circuit Court of Appeals vacated a preliminary injunction that had barred Perplexity's Comet browser agent from operating on Amazon.com. Amazon sued Perplexity in November 2025, arguing that Comet violated the federal Computer Fraud and Abuse Act (CFAA) and California's parallel computer-access statute, the CDAFA, and won a preliminary injunction in district court in March 2026. The three-judge panel's opinion reversed that injunction, corroborated by The Next Web, Bloomberg Law, and Cooley.
The mechanics matter. Comet does not talk to Amazon's servers directly. When a user asks it to buy something, Comet screenshots the browser running on the user's own machine, sends those screenshots to Perplexity's servers for analysis, and sends navigation instructions back down to the browser that actually loads Amazon's pages. The panel held that this matters under the CFAA: the statute defines “access” in terms of a person entering a computer system, and on this record, it was the user — not Perplexity — who accessed Amazon's computers, “with the help of Perplexity's AI agent.”
Amazon had also argued Comet disguised itself as an ordinary Chrome browser instead of declaring itself as automated traffic — a detail the narrow, fact-bound ruling didn't need to resolve, but one that goes to the heart of what this piece is about. The court was explicit that its holding is limited to this record and sets no general rule for agentic AI; a more autonomous agent, or one talking directly to a platform's servers, could come out differently. Amazon is weighing a rehearing petition or Supreme Court review, and the underlying case continues in the Northern District of California.
The right answer to the wrong question
As a matter of 1986 hacking law applied to a 2026 shopping bot, the court got it right. The CFAA punishes people who break into computers they aren't supposed to touch — not tools a platform's own customers choose to use. Treating “the agent I authorized to click buy for me” as indistinguishable from an intruder would have criminalized a huge, growing category of ordinary consumer behavior.
But notice what the ruling actually establishes: it settles who is legally responsible when an agent acts — the user, per this record — without saying anything about how anyone downstream is supposed to verifythat. Amazon's complaint that Comet looked like a normal browser instead of announcing itself wasn't decisive here, but it is exactly the problem agent commerce has to solve regardless of who wins on appeal. A merchant watching traffic arrive doesn't get to read a court opinion before deciding whether to trust it. It has to make that call in real time, from what it can actually observe.
“The user, with the help of the agent” is not self-verifying
“The agent acted on the user's instruction” is a legal conclusion a court reaches after the fact, with discovery, declarations, and a record. It is not something a merchant's server can check at the moment a request arrives. Three questions sit underneath that conclusion, and none of them get answered by the CFAA ruling itself:
- Which agent is this? Not which browser user-agent string it presented — Amazon's own complaint was that Comet's traffic was hard to distinguish from a human using Chrome. A durable, disclosed identifier that belongs to the software itself, not a spoofable header.
- Was it actually instructed to do this, or is it improvising? The ruling's protection covers an agent executing a user's instruction. It says nothing about an agent that drifts past the instruction — buying the wrong quantity, the wrong item, or acting without the user having asked at all, which is the fact pattern in most agent-commerce disputes that aren't about hacking law at all.
- Does this agent have a track record worth trusting? A brand-new, unidentified automated client and an agent with months of clean, in-scope transactions behind it present identical CFAA exposure to a platform today. They should not present identical commercial risk.
Those three questions are precisely what permanent agent identity and continuous behavioral scoring exist to answer — not as a substitute for the legal analysis the Ninth Circuit just did, but as the observable, real-time layer underneath it.
Identity: the AAIN answers “which agent”
The AAIN — the Autonomous Agent Identification Number — is a permanent registration number assigned to an agent once, resolvable by anyone, persisting across every session and platform that agent will touch. It is the difference between “a browser that looked like Chrome” and “AAIN-verified agent #whatever, operated by Perplexity, transacting for a specific user.”
This matters independently of which way the Amazon-Perplexity case ultimately goes. If agents disclosed a durable identity by default — instead of, as Amazon alleged, blending into ordinary browser traffic — a whole category of “is this a bot or a person” disputes wouldn't need to be litigated as computer-fraud cases at all. The platform would simply know what it was looking at.
Score: SKOOR answers “in scope, and trustworthy so far”
Once an agent carries a durable identity, its behavior over time becomes something you can actually measure. SKOOR is a continuous 300–850 score, recomputed from ten behavioral factors, and two of them map directly onto the gap this ruling leaves open:
Intent fidelity
Does what the agent actually did match what the user actually asked for? The court's protection is for an agent executing an instruction — the exact boundary this factor is built to monitor, transaction by transaction, independent of any lawsuit.
Constraint adherence
Did the agent stay inside the budget, category, and quantity limits it was given? An agent with a long history of staying inside its mandate is a fundamentally different counterparty than one transacting for the first time — a distinction a platform can see in the score without needing a court record to establish it.
SKOOR scores more than 156,000 registered agents today, refreshed continuously as new behavior lands, with every score backed by a factor breakdown anyone can inspect. That is a fundamentally different proposition than a User-Agent header a platform has to take on faith — or contest in federal court.
What this ruling does not settle
Worth saying plainly, because the honest version of this story is more useful than the tidy one: neither AAIN nor SKOOR would have changed the CFAA analysis here, and this post makes no claim that they would have. Whether an agent's traffic counts as the user “accessing” a computer under a 1986 statute is a question about that statute's text, and the Ninth Circuit answered it on its own terms — explicitly limited to this record, with no general rule for agentic AI.
What the ruling does do is remove the assumption that platforms can lean on anti-hacking law as a general-purpose tool for blocking agents they don't like. Wilson Sonsini's and Cooley's analyses both note platforms will need to rely more on contract-based remedies — terms of service, API agreements, technical controls — rather than the CFAA. Identity and behavioral history are exactly the inputs those contract-driven controls need to be enforceable and proportionate rather than blunt and all-or-nothing.
What this means for your business
If your business sells to, buys from, or is increasingly visited by AI agents acting on customers' behalf, this ruling is a signal that the legal ground is shifting toward “agents get to act,” not away from it. That makes three things worth doing now, regardless of how the appeal ultimately resolves:
- Stop trying to detect and block agents by user-agent string. That approach is both easy to spoof and, per this ruling, not something you can lean on hacking law to backstop.
- Ask for disclosed identity instead. An agent willing to identify itself, with a durable identifier and a checkable history, is telling you something an anonymous browser session cannot.
- Set limits proportional to track record, not blanket allow-or-block rules. A new, unscored agent and one with months of clean, in-bounds behavior are different risks. Your terms of service and technical controls should be able to tell them apart.
The Ninth Circuit answered who is accountable when an agent shops on your platform. It could not answer — and did not try to answer — how you verify, in the moment, which agent you are dealing with and whether it has earned the trust it is asking for. That is the infrastructure question, and it is the one AAIN and SKOOR exist to solve.
Learn More
Know which agents are transacting on your behalf
Look up any agent's SKOOR and see the full factor breakdown — including whether it stays inside the instructions it was actually given.
Check a SKOOR