US Ninth Circuit rules user-directed AI agents do not violate federal anti-hacking laws when accessing web platforms

US Court Ruling on AI Browser Agents and Website Access

On 4 August 2026 the US Court of Appeals for the Ninth Circuit handed down a unanimous ruling in Amazon.com Services LLC v. Perplexity AI, Inc. (No. 26-1444) that vacates a preliminary injunction blocking Perplexity’s Comet browser and its agentic “Assistant” from operating on Amazon.com. The panel held that when a human user directs an AI agent to carry out a task on a website, it is the user, not the software developer, who is legally “accessing” that website’s computers. This is the first US federal appellate decision to squarely address whether AI browser agents acting under human instruction can be blocked using anti-hacking statutes.

While this is a US technology and platform law case rather than an environmental regulatory decision, it carries direct relevance for Australian environmental consultants, planning lawyers and corporate teams who increasingly rely on AI tools to query public spatial databases, contaminated land registers, EPA notification portals and planning certificate systems. The ruling clarifies the legal footing of AI-assisted research and automation at the exact moment these tools are becoming embedded in due diligence and site assessment workflows.

For environmental professionals and their clients, including developers, transactional lawyers and local councils, the case matters because it establishes a legal principle that could shape how platform operators, including government data portals and commercial land information services, treat automated or AI-assisted queries going forward. It does not create new environmental law, but it removes a layer of legal uncertainty that has been quietly hanging over AI-assisted research practices in professional services.

Amazon v Perplexity: the CFAA claim and the court’s reasoning

Amazon sued Perplexity under the federal Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer Data Access and Fraud Act (CDAFA), alleging that Perplexity’s Assistant unlawfully accessed password-protected Amazon accounts without authorisation. The district court granted Amazon a preliminary injunction stopping Comet’s Assistant from navigating Amazon.com. The Ninth Circuit reversed this, finding that Amazon was unlikely to succeed on the merits because the statutory “access” element of the CFAA was not met by Perplexity’s conduct.

The court’s reasoning turned on the technical architecture of the Comet Assistant. When a user instructs the Assistant to find or purchase an item on Amazon, the browser takes local screen captures of the user’s own active session, transmits those images to Perplexity’s servers for AI reasoning, and receives navigation commands back that are executed locally within the user’s authenticated browser. Because the tool depends on real-time human initiation and operates inside the user’s own session rather than as an independent server-to-server scraper, the court found that Perplexity itself was not the party accessing Amazon’s computers.

Circuit Judge Milan D. Smith Jr., writing for the panel, stated that “however advanced the Assistant currently is, it is a tool, not a person for statutory purposes” and that “it is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts.” This framing treats AI agents as extensions of the authorised human account holder rather than as independent actors capable of committing unauthorised access under the CFAA.

The ruling is deliberately narrow. The panel explicitly left open whether fully autonomous AI agents that operate server-to-server, without direct real-time human prompting or user authentication at the point of access, would still trigger CFAA liability. The court also noted that platforms retain other enforcement avenues, including contractual remedies through Terms of Service breach claims and technical measures such as rate-limiting, meaning platform operators are not left without any recourse against automated tools they consider undesirable.

eff.org
Image source: eff.org

Relevance to Australian environmental due diligence practice

Australia does not have a direct equivalent to the CFAA, but the Commonwealth Criminal Code Act 1995 (Cth) contains comparable computer offence provisions, and several state Crimes Acts include unauthorised access offences that operate on similar logic. As AI-assisted research tools become more common in environmental due diligence, this US precedent is likely to be referenced in future Australian disputes or legal advice concerning whether AI agents used to query planning portals, EPA contaminated land registers or NSW POEO public registers constitute unauthorised computer access when used under human direction.

Environmental consultants routinely rely on publicly accessible or subscription-based data sources when preparing Preliminary Site Investigations (PSI) and Detailed Site Investigations (DSI) under state contaminated land frameworks, including the NSW Contaminated Land Management Act 1997, the Victorian Environment Protection Act 2017, and Queensland’s Environmental Protection Act 1994. Section 10.7 planning certificates in NSW, EPA notice databases in Victoria, and contaminated land registers maintained by state EPAs are increasingly queried using automated tools or AI-assisted search agents to speed up records review. This ruling provides a useful reference point for how courts may view the legal status of the human operator versus the software tool in future Australian disputes over automated data collection from government or commercial platforms.

It is also relevant to how environmental consultancies structure their AI governance and internal policies when using large language model tools to cross-reference NEPM 2013 Schedule B guidance, ANZG default guideline values, or PFAS NEMP data during desktop assessments. The core legal principle, that a human-directed AI tool acting within an authorised session is functionally the human’s own access, gives consultancies a clearer footing for permitting staff to use AI-assisted browsing on external portals and registers, provided the underlying account or session access is itself properly authorised and any applicable terms of use are observed.

References and related sources

How iEnvi can help

iEnvi integrates technology and data-driven approaches into environmental consulting. We monitor AI and technology developments that affect how environmental professionals deliver services to clients.


This is an iEnvi Machete news summary. Prepared by iEnvi to summarise the source article for environmental professionals tracking AI, data, and technology developments that affect consulting and project delivery.

Published: 07 Aug 2026

Need advice on this topic? Speak to an iEnvi expert at info@ienvi.com.au or 1300 043 684, or contact us online.

Need advice on this issue? iEnvi provides practical, senior-led environmental consulting across contaminated land, remediation, ecology and environmental risk.

PSI services DSI services Contaminated land advice Environmental due diligence Talk to iEnvi