When an AI Agent Shops for You, Anti-Hacking Law Sees Only You
In the summer of 1983 Ronald Reagan watched WarGames, the film in which a teenager's home computer dials into a Pentagon war machine, and asked his national security staff whether any of it could really happen. The answer was unsettling enough to help start federal computer-crime lawmaking, and the House report on the first bill cited the film by name. The statutes that followed were built around the film's central image: a computer intruder is a person at a keyboard, reaching into a machine where they do not belong. The Computer Fraud and Abuse Act of 1986 still carries that mental picture inside it.
On August 4, 2026, the Ninth Circuit had to fit that picture onto something the statute never imagined. A customer tells an AI assistant to buy something on Amazon. The assistant signs into the customer's account, browses, compares and completes the purchase. Who visited Amazon — the customer, or the software company whose model steered the cart? The panel answered from the system's wiring, and the answer now organizes the legal position of every shopping agent in the largest American circuit.
Practical takeaway. In Amazon v. Perplexity, the Ninth Circuit vacated Amazon's injunction against the Comet Assistant because Perplexity's servers never exchange a packet with Amazon's: the customer's own browser does the accessing, so the federal and California anti-hacking statutes see only the customer. Liability follows the network path. For agent builders, routing has become a legal decision; for storefronts, the perimeter defense moves to contract and code.
One question, answered from a wiring diagram
Amazon's suit contended that the Assistant inside Perplexity's Comet browser logged into customers' password-protected Amazon accounts, shopped at their direction without identifying itself as an agent, and did so against Amazon's terms of use. On March 9, 2026, the Northern District of California enjoined it, reasoning that Amazon had never authorized Perplexity's access, whatever the customers had permitted. Five months later the panel vacated that injunction in the first federal appellate decision to reach the question (Amazon.com Services, LLC v. Perplexity AI, Inc., 2026 WL 2237587, 9th Cir. Aug. 4, 2026).
What decided the case was a four-step description of how the product works, set out in Cooley's account of the ruling. The customer's browser retrieves the Amazon page. The Assistant captures screenshots from that browser and sends them to Perplexity's servers. Those servers return navigation instructions to the customer's computer. At no point does a Perplexity machine talk to an Amazon machine. On that record, the panel held, "it was the user who 'accessed' Amazon's computers, with the help of Perplexity's AI agent." The parallel claim under California's Section 502 computer-crime statute failed the same way. The statute punishes whoever does the accessing, and the only party on Amazon's wire was the customer's own browser.
A tool, not a person
The panel was direct about what the Assistant is in the eyes of a 1986 statute: "However advanced the Assistant currently is, it is a tool, not a person for statutory purposes." There is, as the court acknowledged, almost no caselaw on how to ascribe responsibility for an AI agent's acts, and it reached for the oldest instrument available: responsibility runs to the human who wields the tool.
Two further moves define the decision's temperament. The court invoked the rule of lenity, construing the statute's ambiguity against liability because Amazon's theory carried criminal consequences for ordinary people — a customer who lets software fill a shopping cart in their own account should be able to do so without first needing a criminal-law opinion. And the panel confined itself deliberately, writing that it would not "establish a new legal regime governing agentic AI." The holding covers unauthorized access, on these facts, under two statutes. Everything else — breach of Amazon's terms, contract claims, tort theories, Amazon's freedom to block agent traffic technically — survives, a point Kieran McCarthy's analysis on the Technology & Marketing Law Blog presses: the policy fight over who controls access to a public storefront is postponed for another case.
Architecture is now a compliance artifact
Read as an engineering document, the opinion gives agent builders a map with one marked road. The shelter extends to systems in which the customer's machine relays every communication with the target site. An agent that calls a storefront directly from its provider's cloud — the shape of most operator-style services, which run their browsers in the vendor's data center — sits on the far side of the line the court drew, and nothing in the August 4 reasoning promises it the same result.
Law has moved engineering before. Export controls once determined where cryptographic code could be written, and European data-protection law redrew the world's data-center map. The same mechanism is at work here at smaller scale: the anti-hacking statutes now price a packet route, and product architecture will follow the price. The commercially uncomfortable part belongs to the storefronts. An assistant that navigates by screenshot completes the purchase without ever seeing the shelf: the merchandising surface a retailer builds for human eyes — placements, banners, the choreography of search results — never reaches a customer who has stopped looking at the page. That, more than any security concern, is what makes agent traffic worth fighting over, and the fight now has to be waged with terms of service and technical countermeasures whose counterparty is the retailer's own customer.
Disclosure and supervision take the weight
Two days before the panel ruled, a different legal system answered the identification question by statute. The EU AI Act's Article 50 transparency duties became operative on August 2, 2026: systems that interact with people must disclose themselves, and AI-generated output must carry machine-readable marking — the duties examined in Quentir's analysis of the Article 50 transparency regime. Amazon's core factual grievance, an assistant that never announced itself, describes conduct that in Europe is now a statutory disclosure question with a named enforcement chain, whoever's browser carries the packets.
Financial supervisors are moving on a third track. In July 2026 Canada's prudential regulator OSFI published a bulletin on generative and agentic AI that treats deployed agents as an operational-risk surface: unique non-human identities for agents, least privilege, short-lived credentials, and approval checkpoints before an agent takes high-risk actions, all mapped onto its existing technology, operational-resilience and third-party guidelines. As the criminal statute steps back, supervision and disclosure are stepping forward — regimes with civil burdens, named supervisors and continuous jurisdiction over the institutions that deploy agents, and none of them turn on who touched whose server.
How Quentir Reads It
The decision is narrow by its own words, and it still sets the default rule for the agentic web in America's largest circuit: unauthorized-access law reads network diagrams. Three consequences follow. Design will chase the shelter — expect agent vendors to route through customer devices, and expect diligence questions about agent architecture to become as routine as questions about data residency. The perimeter fight moves to contract, where a platform's counterparty is its own customer and mass enforcement carries a commercial cost of its own. And the Atlantic now splits over the visitor's identity: an American appellate court holds that an unannounced agent is legally its user, while a European regulation operative two days earlier requires the same assistant to announce itself. For anyone building or buying agents, the identity of automated traffic has become jurisdiction-dependent — an input to product design, procurement and contract drafting at once.
Quentir tracks these instruments as they accumulate — the access-law line drawn on August 4, the Article 50 duties, the supervisory guidance now reaching agent credentials — and the daily record they come from, across law, engineering and markets, sits in one place: the All-access membership carries every analysis this one stands on, and the archive behind them.
The panel wrote that it would not build the law of agentic AI, and no legislature has stepped in behind it. The next case will arrive wearing a different architecture — an agent shopping from its provider's cloud, with no customer browser in the path — and nothing decided on August 4 promises it the same answer. Watch how that case is pleaded: as hacking, as breach of terms, or as a failure to disclose. The choice will reveal which body of law actually governs the agentic web. This week, the criminal one stepped back first.
Published intelligence, built to inform your own decisions. Published: August 8, 2026.
Sources: Amazon.com Services, LLC v. Perplexity AI, Inc., 2026 WL 2237587 (9th Cir. Aug. 4, 2026), vacating the preliminary injunction entered in the Northern District of California on March 9, 2026. Cooley LLP, "Ninth Circuit Rules on AI Agent 'Access' to Third-Party Websites Under CFAA" (August 6, 2026). Kieran McCarthy, "Ninth Circuit Lifts Restrictions on Agentic AI Accessing Amazon", Technology & Marketing Law Blog (August 6, 2026). Regulation (EU) 2024/1689, Article 50, transparency obligations applicable from August 2, 2026. Office of the Superintendent of Financial Institutions, "Generative and Agentic Artificial Intelligence: Implications for Technology, Cyber Security, and Operational Resilience" (July 2026), read with OSFI Guidelines B-13, E-21 and B-10. Computer Fraud and Abuse Act, 18 U.S.C. § 1030; California Penal Code Section 502; H.R. Rep. No. 98-894 (1984) on the statute's origins. Pages consulted August 8, 2026.
Published intelligence, built to inform your own decisions. Published: August 8, 2026.