Skip to main content
2025-01-01

Question of the Day

Question of the day · 2026-08-04 ·

One question per day to look beyond the headlines.

Why did the court treat Perplexity’s Amazon access as user-authorized, not “unauthorized access” by an AI agent?

Take-away CFAA liability hinges on who initiates the server interaction: framing the AI as a user-operated browser extension makes access “by the user,” not the vendor.

The court treated Perplexity’s Amazon access as user-authorized rather than "unauthorized access" by an AI agent because it found that Perplexity itself did not access Amazon's systems. Instead, the Comet browser was used by the users, who were the ones accessing the website. The Ninth Circuit ruled that the tool was operated by the users and did not act autonomously in accessing Amazon's servers, satisfying the Computer Fraud and Abuse Act (CFAA) requirement that unauthorized access must be performed by the defendant [1], [2], [3]. Furthermore, the court noted that Perplexity's AI tool was treated as an extension of the user. This meant the AI assisted in actions like logging in and browsing, but the actual interaction with Amazon's systems was performed by the user, making the actions authorized under the CFAA [1], [2], [4].

Sources · 2026-08-05