When an AI assistant browses a website for you, who’s actually there? You, sitting at your keyboard? Or the software doing the clicking? That question sounds almost philosophical, but it just decided a major court fight between two of the biggest names in tech. And the answer could reshape how AI tools are built for years to come.
The dispute comes to us through an analysis from the law firm Ropes and Gray. On August 4, 2026, the Ninth Circuit Court of Appeals ruled in Amazon v. Perplexity. Amazon had sued Perplexity over Comet, an AI-powered web browser with a feature called the Assistant. Point the Assistant at Amazon.com, ask it to find a product, and it handles the task for you. Amazon didn’t want Perplexity’s AI touching its site, and it leaned on a federal law called the Computer Fraud and Abuse Act, the country’s main anti-hacking statute. A lower court sided with Amazon and blocked the Assistant. Perplexity appealed. The appeals court reversed that decision.
The heart of the ruling came down to a single word in the law: “whoever.” The statute punishes whoever intentionally accesses a protected computer, and the court decided “whoever” means a person. The Assistant, no matter how clever, is a tool. Ropes and Gray points to the technical detail that settled it. The user’s own browser talked to Amazon’s servers. Perplexity’s servers never did. So the person using the browser was the one accessing Amazon, and the AI was just a fancy navigation aid. Think of it like using a GPS to drive to a store. The GPS gives directions, but you’re the one who walks through the door.
The court was careful not to hand AI companies a blank check. As Ropes and Gray highlights, the judges wrote plainly: “We do not establish a new legal regime governing agentic AI.” The ruling hinged on how Perplexity built its product. Change the design so the AI’s own servers reach out to a website directly, and the outcome might flip.
Read more: Antitrust Similarities and Differences Between Browser Competition and AI Competition
That distinction is the big takeaway for developers. Ropes and Gray notes that architecture decisions now carry real legal weight. Keep the user’s device as the point of contact, and you’re on safer ground. Let your servers query someone else’s systems without the user in the loop, and you could be inviting trouble. The firm also warns companies not to read this as permission to ignore access rules. A website’s terms of service still bind you, and breaking them can trigger other claims like breach of contract, even if the hacking law doesn’t apply.
For businesses on the other side, the message is a reminder that the anti-hacking law has limits. Companies that relied on it to keep automated tools off their sites need a new plan. Ropes and Gray suggests tightening terms of service, putting sensitive data behind login walls, and using tools like bot detection and rate limiting. The firm points out that the law protects data best when it sits behind clear technical gates, not when it’s sitting in the open.
So what’s next? Ropes and Gray frames this as early guidance rather than a final word. Big questions are still unanswered. What happens when AI agents get more independent and act with less human direction? Will the “tool versus person” line hold up then? And will Congress step in with new rules built for AI? The firm places this ruling alongside other recent cases, including the Anthropic fair use decision, where courts chose narrow answers over sweeping ones. For now, the industry gets a little clarity and a lot to watch.
Click Here For The Original Source.
