Note · August 8, 2026 · 2 min read

Ninth Circuit Rules Users, Not AI Providers, 'Access' Websites Under CFAA When Deploying AI Agents

On August 4, 2026, the U.S. Court of Appeals for the Ninth Circuit vacated a preliminary injunction that had barred Perplexity's AI 'Assistant' agent from accessing Amazon.com on…

On August 4, 2026, the U.S. Court of Appeals for the Ninth Circuit vacated a preliminary injunction that had barred Perplexity's AI 'Assistant' agent from accessing Amazon.com on customers' behalf. The decision offers important early guidance on how the federal Computer Fraud and Abuse Act (CFAA) and California's Comprehensive Data Access and Fraud Act (CDAFA) apply to agentic AI tools that browse third-party websites at a user's direction.

At the heart of the ruling is the panel's interpretation of who 'accesses' a computer when an AI agent carries out a user's instructions online. The Ninth Circuit held that when a user directs an AI agent to act on their behalf on a website, it is the user, not the AI provider, who accesses the computer for purposes of the CFAA and CDAFA. In the panel's view, the AI agent functions as an extension of the user, comparable to other tools an individual might employ to interact with a website, rather than as an independent actor engaging in unauthorized access on its own account.

The implications for companies deploying agentic AI browsing tools are significant. Providers of AI assistants that navigate the web on users' behalf may find themselves less exposed to access-based CFAA and CDAFA claims premised on their agents' interactions with third-party sites, at least within the Ninth Circuit. Conversely, website operators seeking to restrict or block AI agent traffic may need to reassess strategies that rely primarily on access-based liability theories against providers, and consider whether contractual, technical, or other legal frameworks are better suited to their objectives.

Companies on both sides of this issue should also anticipate continued litigation over the boundaries of the court's reasoning, including how it interacts with terms of service, technical access restrictions, and evolving state and federal legislative efforts addressing AI. Product, engineering, and compliance teams may wish to revisit how their agentic tools are designed, disclosed, and instructed, and how third-party access policies are drafted and enforced.

This alert is provided for general informational purposes only and does not constitute legal advice. Clients facing specific questions about the deployment or restriction of AI agents should seek tailored counsel based on their particular circumstances.