The Ninth Circuit has vacated the injunction preventing Perplexity’s shopping agent from operating on Amazon.com.1 The panel did not announce a general rule for AI agents. Its significance lies in the interaction between statutory access, system architecture and criminal law ambiguity. What follows is the interpretive tradition the panel drew on, together with what happens when the same architecture is put to an English court.
Fourteen years of resistance to expansive readings
Over the past fourteen years the Ninth Circuit and the Supreme Court have resisted expansive readings of the CFAA. Nosal I warned in 2012 against constructions that “would transform the CFAA from an anti-hacking statute into an expansive misappropriation statute”.2 Van Buren fixed access, in 2021, as “the act of entering a computer system itself or a particular part of a computer system”.3 hiQ described the statute’s purpose in 2022 as preventing “intentional intrusion onto someone else’s computer”.4 Brekka supplies the applicable interpretive rule. Because the CFAA is primarily a criminal statute and its provisions are construed identically in civil and criminal cases, ambiguity is resolved against liability.5
A consequence of Amazon’s construction went unanswered. A Comet user who asked the Assistant to buy something could face criminal exposure on a conspiracy or aiding and abetting theory for facilitating Perplexity’s supposed unauthorised access. That potential expansion of criminal liability reinforced the panel’s refusal to adopt Amazon’s reading on this record.
How English law frames the same conduct
The English statute frames the conduct differently. Its starting point is not whether the defendant entered the target system, but whether the defendant caused a computer to perform a function with the required intention and knowledge. Section 1(1) of the Computer Misuse Act 1990 applies where a person causes a computer to perform any function with intent to secure access to any program or data held in any computer, where the access intended is unauthorised and the person knows at the time that it is.6 Section 17(2) defines securing access to include causing a computer to perform a function which alters, erases, copies, moves, uses or outputs the program or data.7 Instructions transmitted from Perplexity’s servers could therefore present a causation question even though those servers never communicated directly with Amazon’s servers.
An enabling limb once looked apt for a case of this kind and is no longer available in England. The Police and Justice Act 2006 would have extended section 1(1) to a person who causes a computer to perform a function intending “to enable any such access to be secured”. Those words were commenced for Scotland on 1 October 2007. The inserting provision was repealed for England, Wales and Northern Ireland on 1 October 2008 by section 61 of the Serious Crime Act 2007, headed “Repeal of offence of enabling unauthorised access to computer material”, so that enabling conduct would be addressed by the encouraging or assisting offences in Part 2 of that Act instead.8 A developer in Perplexity’s position might therefore fall to be considered under Part 2 of the 2007 Act if its conduct encouraged or assisted a section 1 offence and the applicable mental elements were established. That route would not necessarily displace the argument that the developer itself caused the relevant computer function and was a principal offender under section 1.
None of this establishes liability. Section 17(5) asks who was entitled to control access of the relevant kind to the particular program or data. The customer authorised use of the account. Amazon controlled the underlying systems and had expressly rejected agentic access. Under Allison, control means entitlement to authorise or forbid the particular kind of access to the actual program or data. Technical ability or general access is insufficient.9 English authority does not resolve that conflict on facts of this kind. Intention, knowledge and the Act’s territorial application would each fall to be established as well. The 1990 Act also creates criminal offences and provides no direct English analogue to the civil action Amazon has brought.
What remains after the appeal
Amazon’s § 1030(a)(4) claim remains pleaded because the district court’s written order did not address it and Amazon did not argue it on appeal.10 The panel therefore did not decide that claim, although its reasoning on access will be difficult to avoid, since subsection (a)(4) also requires access without authorisation. The opinion leaves broader questions of responsibility for agentic conduct outside the CFAA and CDAFA unanswered. Amazon remains free to regulate use of its site through private terms, but this action does not presently include contract or tort causes of action. The complaint pleads only two statutory counts.11
One fact also remains live. Whether Perplexity knowingly altered the Assistant’s user-agent string after Amazon began blocking it is disputed on the record.12 That question bears on every deception-based theory that might follow.
For developers, the practical consequence is that system architecture now has legal significance it was never designed to possess. Relaying through the user’s device kept Perplexity outside section 1030(a)(2) on this record. An agent whose own servers call the target site may fare differently. Whether that distinction will survive the pressure the market is about to place on it is a question for another case.
Notes
1. Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. 4 August 2026), vacating the preliminary injunction entered in No. 3:25-cv-09514-MMC (N.D. Cal.) (Chesney, J.) and remanding. Argued and submitted 11 June 2026, Seattle. Panel: Milan D. Smith Jr. and Eric C. Tung, Circuit Judges, and John C. Hinderaker, District Judge (D. Ariz.), sitting by designation. Opinion by Judge Smith.
2. United States v. Nosal (Nosal I), 676 F.3d 854, 857 (9th Cir. 2012) (en banc), quoted at slip op. 10.
3. Van Buren v. United States, 593 U.S. 374, 388 & n.6 (2021), quoted at slip op. 15.
4. hiQ Labs, Inc. v. LinkedIn Corp., 31 F.4th 1180, 1196 (9th Cir. 2022), quoted at slip op. 5 and 16.
5. LVRC Holdings LLC v. Brekka, 581 F.3d 1127, 1132 and 1134-35 (9th Cir. 2009).
6. Computer Misuse Act 1990, s.1(1)(a) to (c), as it has effect in England and Wales.
7. Computer Misuse Act 1990, s.17(2)(a) to (d).
8. Police and Justice Act 2006, s.35(2)(a) and (b), commenced for Scotland by S.S.I. 2007/434, art. 2; repealed for England, Wales and Northern Ireland by Serious Crime Act 2007, ss.61(2), 92, 94 and Sch. 14, commenced by S.I. 2008/2504, art. 2(a)(i)(viii). See the Explanatory Notes to the 2007 Act at paragraph 225.
9. R v Bow Street Metropolitan Stipendiary Magistrate, ex p Government of the United States of America (Re Allison) [1999] UKHL 31, [2000] 2 AC 216 (HL), disapproving the glosses placed on s.17(5) in DPP v Bignell.
10. Slip op. 8 n.2.
11. Complaint, Amazon.com Services LLC v. Perplexity AI, Inc., No. 3:25-cv-09514 (N.D. Cal., 4 November 2025), Count One (18 U.S.C. § 1030(a)(2) and (a)(4)) and Count Two (Cal. Penal Code § 502(c)(2), (c)(3), (c)(4) and (c)(7)). The panel’s CDAFA analysis addressed s.502(c)(7). See also slip op. 21 n.5 on private terms.
12. Slip op. 8 n.1.



