Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
Ninth Circuit Weighs Whether a 1986 Hacking Law Covers AI Shopping Agents. Amazon Probably Wins, but the Real Question Is Bigger.

What Happened and When
Amazon filed suit against Perplexity AI in November 2025, alleging that Perplexity's agentic browser, called Comet, accessed Amazon.com accounts and systems without authorization, violating the Computer Fraud and Abuse Act and California Penal Code § 502, according to court filings summarized by Jones Day and the International Association of Privacy Professionals.
On March 9, 2026, U.S. District Judge Maxine M. Chesney of the Northern District of California granted Amazon a preliminary injunction. Her order found "strong evidence" that Perplexity had continued accessing Amazon's systems after receiving a cease-and-desist letter and had deliberately evaded Amazon's technical blocking measures. She also ordered destruction of Amazon account data Perplexity had transmitted to its own servers, per Jones Day's case summary.
The Ninth Circuit heard oral argument on June 11, 2026 and temporarily stayed the district-court injunction pending appeal, according to CourtListener and contemporaneous reporting cited by Let's Data Science.
What Perplexity's Agent Actually Does
Comet is not a hacker in the traditional sense. It's software that browses the web on behalf of a paying user, including logging into that user's own Amazon account to help them make purchases. The user has the credentials. The user authorizes the action. The AI agent is executing the user's instructions.
That setup is the crux of the legal dispute. Amazon's position: it doesn't want third-party AI agents operating inside its platform, full stop. If Amazon tells a company to stay away and that company keeps making its service available to Amazon customers who want to use it, has the company committed federal computer fraud?
The Agency Question
Orin Kerr, a law professor writing at the Volokh Conspiracy hosted by Reason, laid out the sharpest doctrinal framework for thinking about this. In a 2016 law review article titled "Norms of Computer Trespass," Kerr argued that shared-credential situations should be analyzed using an agency test: a third party accessing an account on a user's behalf is authorized when acting as the user's agent, and unauthorized when pursuing its own ends.
Under that framework, Perplexity has a real argument. If a user authorizes Comet to act on their behalf inside their own Amazon account, the AI is arguably doing what the user would do, not breaking in. But if Perplexity's systems accessed Amazon data for Perplexity's benefit, or evaded Amazon's blocking tools to reach accounts beyond what users specifically directed, the agency defense collapses.
Judge Chesney's finding that Perplexity evaded Amazon's technical countermeasures matters here. Evasion is not neutral. It's hard to argue you're just helping a user shop when you're actively working around the platform owner's efforts to exclude you.
The Stronger Case for Perplexity's Concern
Perplexity's supporters and several amici raise a serious point. If platforms can wield the CFAA as a weapon against any AI agent that competes with their own native shopping tools, the incumbent always wins. Amazon sells its own AI shopping assistant. It also controls the platform. A legal rule that lets Amazon dictate which third-party agents can help users shop on Amazon is not really about security. It's about competitive control dressed up as access policy.
The International Center for Law and Economics, in a June 11, 2026 analysis co-authored by Geoffrey Manne and Kristian Stout, addressed this directly: Amazon will probably win and probably should, given the specific facts of evasion and continued access after a cease-and-desist. But winning on those facts doesn't validate the CFAA as the right tool for this category of dispute.
The Bigger Problem: A 1986 Law Running the AI Economy
The CFAA was written in 1984 — the same year the film "WarGames" inspired Congress to act — and revised in 1986. It was designed for human hackers breaking into mainframes, not for autonomous software acting at a user's direction inside the user's own accounts.
Manne and Stout at the International Center for Law and Economics argued that continuing to stretch 20th-century access statutes over 21st-century technology creates a recurring problem: incumbent platforms get to define "unauthorized access" in ways that conveniently exclude competitors, and courts are left applying language that was never built for the question in front of them. They favor common-law tools, trespass, contract, and agency, as more flexible and less prone to entrenchment.
Ninth Circuit precedents like Power Ventures v. Facebook (844 F.3d 1058) govern some of the doctrinal terrain here, but they were themselves contested decisions. Multiple amicus briefs have been filed in the Perplexity appeal, including from news and media organizations through the News/Media Alliance, suggesting the case's implications extend well beyond retail shopping.
Where It Stands as of June 19, 2026
The preliminary injunction is stayed while the appeal proceeds. Perplexity can continue operating Comet without a court order blocking it, for now. The Ninth Circuit has not issued a ruling on the merits.
The genuine unresolved question the court will have to answer is whether Amazon's act of sending a cease-and-desist letter, combined with its technical blocking efforts, is sufficient to make continued access by a user-authorized AI agent a federal crime, or whether that reading of the CFAA hands every major platform a legal kill switch over any AI company that wants to help users interact with their own accounts.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.