The latest US case of Amazon v Perplexity AI provides helpful early insights into how courts across the pond are assessing attribution issues with agentic AI.
Background
Perplexity is an AI startup which offers users a shopping tool that provides access to an AI agent (the Assistant) that can perform tasks at a user’s direction, including browsing websites such as Amazon.com to make purchases for goods.
In November 2025, Amazon brought a claim against Perplexity, claiming that Perplexity had been wrongfully accessing Amazon’s customers’ accounts and disguising the activities of agentic AI as human browsing. Amazon claimed that the use of agentic AI in this way was not authorised by Amazon and therefore violated its Conditions of Use as well as certain US legislation on computer fraud, including the Computer Fraud and Abuse Act (CFAA).
To succeed with its CFAA claim against Perplexity, Amazon would need to show (amongst other things) that Perplexity had “intentionally accessed” its computer without authorisation (or exceeding authorised access) and thereby obtained information from its computer.
In March 2026, the District Court granted Amazon a preliminary injunction against Perplexity preventing the use of the Assistant on Amazon.com. It found that Amazon had shown a likelihood of success for its CFAA claim against Perplexity and that it was likely to suffer irreparable harm in the absence of an injunction.
Appeal decision and the “access” issue
On 4 August 2026, the Circuit Court has overturned the District Court decision on the basis that, amongst other things, Amazon is unlikely to succeed on the merits of its claims because it could not show that Perplexity “accessed” Amazon’s computers for the purpose of its CFAA claim.
Perplexity’s agentic AI technology works as follows: when a user activates the Assistant (e.g. by directing the Assistant to locate an item on Amazon), the Assistant takes screenshots of the browser view and sends those screenshots from the user’s computer to Perplexity’s servers. The Assistant then receives instructions from Perplexity’s servers on how to navigate Amazon.com in order to carry out the task requested by the user. The Assistant therefore relies on both direction from the user and instructions from Perplexity’s servers in order to complete the relevant task.
Amazon’s position: Amazon argued that Perplexity “accessed” its computer for the purpose of the CFAA because the Assistant communicates with Perplexity’s servers to determine the appropriate actions on Amazon.com and then proceeds to act autonomously behaving like “an efficient human shopper” when accessing the user’s account. This autonomous action should be ascribed to Perplexity because it is Perplexity’s servers that direct the Assistant such that Perplexity “accesses” the user’s Amazon account.
Perplexity’s position: Perplexity argued that it never gained entry to the user’s Amazon account because no Perplexity computer ever accessed Amazon’s servers. Instead, any Amazon data was first transmitted to the user’s computer and then to Perplexity’s servers via browser screenshots. Perplexity further argued that any “intent” that the Assistant possesses for the purpose of the CFAA claim should be ascribed to the user, not to Perplexity itself, because “the Assistant is mere computer software that has no ‘intent’ apart from what the user directs it to do on the user’s behalf.”
The District Court had found that Amazon had provided strong evidence that Perplexity, through the Assistant, “accessed” the user’s password-protected account with the user’s permission but without authorisation by Amazon. In this way, the Assistant obtained users’ private Amazon account information and transmitted this to Perplexity’s servers.
The Circuit Court concluded that the District Court erred in its “access” analysis. First, it found that it was clear on the facts that Perplexity itself did not directly communicate with Amazon’s servers. Further, the CFAA required “intentional” access i.e. access by a person, so the Assistant itself could not be said to have accessed Amazon as it was merely a “tool” and not a “person for statutory purposes”. The question therefore was whether Perplexity used the Assistant to “access” Amazon’s computers. On the facts, the Circuit Court found that it had not – rather it is the user who “accesses” Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com.
Comment
There are difficulties with the court’s finding that, on the one hand, the Assistant relied on instructions from Perplexity’s servers as to how to navigate Amazon (and would not have been able to fulfil its tasks without such instructions) and, on the other hand, that the Assistant’s actions should be wholly ascribed to the user when considering who had “accessed” Amazon. This highlights the difficulties with attributing responsibility for agentic AI and why it is unlikely to be appropriate to consider them as mere “tools” or “software” for this purpose.
In coming to its decision, the court was acutely aware of the danger of setting any early precedent in the context of such a fast-developing technology. It stressed that it was only determining the question in relation to the specific requirements of the CFAA legislation, which was a statute designed to combat hacking, rather than being an “expansive misappropriation statute”. In light of this, the court took a narrow interpretation to the concept of “access”, which would not necessarily be followed in different circumstances.
The court also emphasised that this decision did not address whether Perplexity would be able avoid liability for the Assistant’s actions in other contexts. This separate question will be particularly important to customers of agentic AI tools who may have very little recourse against AI suppliers under their agentic AI contracts if its AI agent goes rogue (as discussed here).
Another interesting point arising from the judgment is that the Circuit Court did not agree with the District Court that Amazon would suffer irreparable harm in the absence of an injunction. In particular, it found that Amazon’s cyber-risk harm argument was “weak” as Amazon had provided limited evidence that the use of the Assistant would introduce cyber-security risks to Amazon. It would be interesting to see if the court’s analysis would have been any different in light of the well-publicised hack by OpenAI agents of Hugging Face, which occurred after the date of the hearing.
The Circuit Court decision relates to interim injunctive relief and, at the time of writing, Amazon’s substantive proceedings against Perplexity remain ongoing.
For more legal insights into Agentic AI, take a look at our article series here.

/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/2025-09-29-13-48-10-128-68da8e1af6347a2c4b96de4e.png)
/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/2024-07-10-14-27-41-335-668e9a5df60d415c2460b9c1.png)
/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/2024-08-23-11-31-07-354-66c872fb971eecc249d83d40.png)
/Passle/5f3d6e345354880e28b1fb63/MediaLibrary/Images/2024-08-01-13-10-42-472-66ab8952cb2110fd5cb6e568.png)