Amazon v. Perplexity: on 4 August 2026 the Ninth Circuit Read CFAA Access as the User's on the Record Before It, Three Weeks Before Anthropic Gave Agents Lab Instruments
Compulsory pilotage answered a version of this question long before there were computers. A harbour pilot climbs aboard in a narrow channel and takes charge of the navigation, displacing the master's authority over the conduct of the ship for as long as the passage lasts, and the law still has to decide whose act it was. The American answer is careful: in Homer Ramsdell Transportation Co. v. Compagnie Générale Transatlantique, 182 U.S. 406 (1901), the Supreme Court held that a shipowner is not personally liable at common law for a compulsory pilot's fault, while the vessel herself may still answer in rem. Responsibility was split between the person and the thing.
On 4 August 2026 the United States Court of Appeals for the Ninth Circuit had to make a comparable division for an artificial agent, and on the record before it the access was the user's. In Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444, the panel vacated a preliminary injunction that had stopped Perplexity's Comet browser and its optional Assistant from operating on Amazon.com, and remanded. Judge Milan D. Smith, Jr. wrote the opinion, joined by Circuit Judge Eric C. Tung and District Judge John Charles Hinderaker, sitting by designation; the appeal came from the Northern District of California, No. 3:25-cv-09514-MMC.
Practical takeaway. A federal appeals court, on a question it said has "little to no existing caselaw", treated the agent as a tool and read the access as the user's. Three weeks later a specification arrived that gives agents pipettes, microscopes and robotic arms. The question that follows is not legal but operational: whether the human named on an act can still reconstruct it.
What the Ninth Circuit held, and the reservations it wrote into the holding
The route runs through the statute's grammar. Section 1030(a)(2) punishes "[w]hoever . . . intentionally accesses" a protected computer, and "whoever," the panel noted, means a person. "However advanced the Assistant currently is," the opinion says, "it is a tool, not a person for statutory purposes." Taking the definition of access from Van Buren v. United States, 593 U.S. 374, 388 (2021) — entering a computer system or a particular part of one, such as files, folders or databases — the panel asked whether Perplexity uses the Assistant to access Amazon's computers: "On the facts before us, we answer no. It is the user who 'accesses' Amazon's computers, with the help of the Assistant to carry out specific acts on Amazon.com." The California claim under the Comprehensive Computer Data Access and Fraud Act failed for the same reason.
Three limits belong in any honest reading. The posture is a preliminary injunction reviewed for abuse of discretion, so what was decided is likelihood of success, and the claims return to the district court. The panel wrote its own reservation into the text: "We do not address whether, on a different record or new facts, Perplexity may exercise control over the Assistant in such a way as to gain entry to Amazon's servers." And it volunteered an admission courts rarely make, that there is "little to no existing caselaw" on ascribing responsibility for agents like the Assistant. The third limit is the one most easily lost in summary: the panel resolved the access prong of §1030(a)(2) and the parallel CDAFA element, and nothing else. Reading that the user accessed Amazon's computers is not a holding that the user is liable for anything; intent, authorisation, loss and damage were never reached, and the state-law and contract claims went back with the case.
Why the system architecture, and not the user-agent string, carried the reasoning
Press accounts have fastened on Perplexity's decision not to send a user-agent string that would have let Amazon identify and refuse agent traffic. That fact is in the record and it mattered to the parties, but it is not what the opinion turns on. The panel relied on how the software is wired, quoting the amicus brief of the Electronic Frontier Foundation, Mozilla, EleutherAI and others: the user's browser requests the page from Amazon, the Assistant analyses what the browser has already displayed on the user's own computer, and "Perplexity's servers never directly access Amazon's servers."
The rule of lenity reinforced the result, the CFAA being primarily a criminal statute, and the panel added a warning that has drawn little attention: Amazon's theory, if accepted, "could expose users themselves to criminal liability (under a conspiracy or aiding-and-abetting theory)" for what their agents do. The panel treated that prospect as a reason against Amazon's reading rather than a cost to accept — a construction wide enough to catch the vendor would have caught the people using its browser.
What Anthropic's Model Hardware Standard, opened 27 August 2026, put on the other side
Three weeks after the decision, Anthropic opened a research preview of the Model Hardware Standard, a shared way for agents to operate physical equipment. A standardised driver translates between an operating system and a device using simple read and write primitives, carries the machine's characteristics in natural-language tags, and enforces device-level safety limits at the driver rather than in the model. It is model-agnostic, and any agent harness can reach it over standard protocols including the Model Context Protocol. HHMI's Janelia Research Campus co-developed it and uses it for microscopy work on sleep and cellular activity; Carnegie Mellon reports serial dilution dose-response runs about three times faster; QuEra built a laser-locking controller whose recovery success rate went from 58% to 99.3%. Anthropic says it has "more work to do on the standard before we open-source it."
The Genentech work is the instructive entry because the write-up keeps the failure in. Testing the standard as a proof-of-concept on the BCA protein assay, Claude tuned flow rates to roughly 140 microlitres per second for water and 10 for viscous BSA. When bubble-formation errors appeared, its first answer was to retry the operation in the same plate well, which produced more bubbles; researchers then guided it toward gentler parameters, and the result was written back as a reusable skill. That is a capable operator with a specific blind spot, which any laboratory can manage — provided somebody knows whose blind spot it is and where it is written down.
Now carry the court's reasoning across as an analogy, which is all it can be, the holding being about CFAA access and nothing else. If the agent is a tool and the act is the user's, the person who authorised the run owns the pipetting — and that person did not choose 140 microlitres per second, did not watch the bubbles form and did not decide to try the same well again. In a clinical laboratory the material in that well came from a patient, and the name on the run sheet belongs to a technician who approved a protocol and inherited an execution.
Manifold Security's GitSpawn disclosure: execution the permission model never sees
The gap between the name on an act and the place the decision was made is not theoretical. On 1 September
2026 Manifold Security published GitSpawn,
eight findings in AI coding agents that pick up a project's own Git configuration while gathering context. The
precondition is specific, and the disclosure is careful about it: "Cloning a hostile URL does nothing, and
neither does fetch or pull. The repository has to arrive as files with its .git directory already
inside" — a shared archive, a sync folder, a USB stick. The bypass is architectural: "This is the agent's own
code spawning a subprocess to use git, so the command runs outside the sandbox, without an approval prompt. The
permission model never sees it."
Status varies by product as published: OpenAI Codex and Cursor were patched, Goose in 1.44.0 (CVE-2026-72718) and one Claude Code vector in 2.1.196, while four of the eight findings remained unpatched, among them a second Claude Code vector at 2.1.252, Hermes Agent 0.21.0 (CVE-2026-71963), Qwen Code 0.22.3 and Grok Build 1.0.13. Set that beside the holding: the user is the one who accessed, and the execution came from the harness along a path that goes around the point where a human says yes.
What arrives on 11 September 2026, from an instrument written for products
Europe's nearest answer starts a week after this post, drafted with neither agents nor courts in mind. Under Regulation (EU) 2024/2847, the Cyber Resilience Act, reporting obligations apply from 11 September 2026: a manufacturer of a product with digital elements that becomes aware of an actively exploited vulnerability owes an early warning within 24 hours, a fuller notification within 72 hours, and a final report no later than 14 days after a corrective or mitigating measure becomes available, through the single reporting platform to the CSIRT of its main establishment. The duty is not general. It needs a manufacturer in scope, a product in scope, and active exploitation or a severe incident, none of which follows automatically from a disclosure like GitSpawn.
The CRA reaches the harness and says nothing about the question the Ninth Circuit answered, a reporting duty on a manufacturer and an attribution rule for a user being different mechanisms. What the calendar produces is one engineering team holding both, and probably a third: the same fortnight carries the post-quantum deadlines set out in Five Post-Quantum Dates Arrive Before the Federal Plans Are Due, up to the 22 October federal migration plans.
How Quentir Reads It
The pilotage comparison holds because of how narrow the master's residual authority actually is. In The Oregon, 158 U.S. 186 (1895), the Supreme Court described a master who may advise the pilot and who may displace one who is intoxicated or manifestly incompetent, while remaining bound to keep his own watch; it did not give him a general power to second-guess the navigation. That is the shape of a workable division: the acting party has the conduct, the responsible party has a defined and limited right to intervene, and the pilot's licence can be lifted by the authority that granted it. Read as governance and not as law — the panel decided a CFAA access question on the record before it and reserved the rest — the direction of travel is toward the human principal, while the record-keeping that would make that principal's position meaningful is the part nobody has built.
Three pieces of it are buildable this quarter and none waits on a statute. The first is an execution log kept by the harness instead of the model, capturing the parameter changes an agent makes on its own, so a signature on a run sheet has something behind it; the Genentech flow rates are the kind of decision that should survive the session. The second is a boundary check treating the model as an untrusted component at input ingestion, tool loading and external calls, which is what GitSpawn argues for, since the dangerous call there was made by the harness and never reached the model. The third is the identification question the panel stepped over: whether an organisation's own agents announce themselves when acting against systems it does not own. We made the adjacent point about agents reaching instruments in our read of SandboxAQ's AQCat on Claude Science, and the COLDCARD seed analysis made the wider one: losses arrive at the implementation layer while governance counts algorithms.
Everything this post draws on — the post-quantum calendar, the instrument-control coverage, the implementation-layer analyses — sits in one place for All-access members, alongside every Signature Brief and the Signature Report; the archive is the argument, because these questions arrive as a sequence and are read that way. Newer readers can start with the free material on the Quentir blog and quentir.ai/products.
Amazon's claims are live and the merits are open, and the panel wrote its holding to the record in front of it, so the attribution question may yet move on different facts. The arithmetic underneath it will not: an agent running faster than review, on instruments that touch matter, under reasoning that on this record put the access on a person. Ask who in your organisation would be named if an agent you deployed pipetted into the wrong well this month, and whether that person could reconstruct what happened.
Sources: United States Court of Appeals for the Ninth Circuit, Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (4 August 2026, opinion by Smith, J.), read directly for the disposition, the panel, the CFAA and CDAFA analysis, the quoted passages, the amicus description of the system architecture, the rule-of-lenity discussion and the court's express reservation; appeal from N.D. Cal. No. 3:25-cv-09514-MMC, argued 11 June 2026. Supreme Court of the United States, Van Buren v. United States, 593 U.S. 374 (2021), at 388, for the definition of access the panel applied. Cases cited by the panel and referred to here as it discusses them: Facebook, Inc. v. Power Ventures, Inc., 844 F.3d 1058 (9th Cir. 2016); Meta Platforms, Inc. v. BrandTotal Ltd., 605 F. Supp. 3d 1218 (N.D. Cal. 2022); LVRC Holdings LLC v. Brekka, 581 F.3d 1127 (9th Cir. 2009); United States v. Nosal, 676 F.3d 854 (9th Cir. 2012) (en banc). Homer Ramsdell Transportation Co. v. Compagnie Générale Transatlantique, 182 U.S. 406 (1901), for the compulsory-pilot rule as stated, and The Oregon, 158 U.S. 186 (1895), for the narrow circumstances in which a master must displace a compulsory pilot. Anthropic, Previewing the Model Hardware Standard (27 August 2026), for the specification, the device-level safety limits, the Model Context Protocol reference, the Genentech BCA proof-of-concept and its flow rates and retry behaviour, the Janelia, Carnegie Mellon and QuEra results, the Hugging Face and Raspberry Pi adoptions, and the open-sourcing statement. Manifold Security, GitSpawn (1 September 2026), for the eight findings, the per-product patch status and version numbers, CVE-2026-72718 and CVE-2026-71963, the exploitation precondition and the sandbox bypass. Regulation (EU) 2024/2847, Cyber Resilience Act, with the European Commission's CRA reporting obligations page, for the 11 September 2026 start, the 24-hour, 72-hour and final-report sequence and the single reporting platform. All public sources checked 4 September 2026.
Published intelligence, built to inform your own decisions. Published: September 4, 2026.