The Ninth Circuit Just Said the Bot Is the User
In March, Amazon had the thing every platform in a scraping fight has learned to want: a federal injunction. A district judge in California found strong evidence of unauthorized access and ordered Perplexity's Comet, a browser whose built-in agent can sign into your Amazon account and place orders for you, to stay away from the site. On August 4 the Ninth Circuit threw that order out, and the sentence carrying all the weight is short: it was Perplexity's users, not Perplexity, who accessed Amazon. The first federal appeals court to rule on the legality of an AI shopping agent did not split the difference. It said the bot is the user.
The rule it replaces
The weight only registers against the rule it displaces. In 2016 the same court decided Facebook v. Power Ventures, and that decision has governed account-touching automation ever since. Power.com gave people one dashboard for all their social accounts. Its users handed over their own credentials, willingly, to a tool doing exactly what they asked. Facebook sent a cease-and-desist letter, blocked Power's IP addresses, and sued under the Computer Fraud and Abuse Act, the federal statute that punishes access "without authorization." The court held that a user's yes does not survive the platform's no: once Facebook revoked permission, every further login by Power's servers was a violation, however many users had consented. Automation builders absorbed the lesson, because the ruling made it the price of existing. If your software touched accounts behind a login, the platform decided whether you were authorized, and your users' blessing counted for nothing.
The same case, run again at agent speed
Amazon v. Perplexity is that case with the roles recast. Comet's agent does what Power did, one account at a time and much faster: the user states a task, the agent signs into the user's own Amazon account and buys the thing. Amazon called the access covert and a security risk, demanded in writing that it stop, the exact trigger that has ended these fights for a decade, and sued in November. In March the script produced its usual ending. On appeal it did not: the panel found Amazon unlikely to succeed on its hacking claim because the people accessing Amazon were its own customers, signed into their own accounts, which is as authorized as access gets.
The one-line reason makes sense when you look at where each tool ran. Power's aggregation happened on Power's servers, which logged into Facebook from Power's machines. Comet is a browser. The agent executes on the customer's computer, inside the customer's session, clicking what its owner could click. Perplexity's spokesperson stated the theory plainly: agents should have "the same rights as human users." Amazon says it respectfully disagrees, and an appeals ruling at the injunction stage predicts an ending rather than writing one; the case continues. But the doctrine's center of gravity moved this week. Permission used to live with the platform. For software a person installs and instructs, this panel handed it back to the person.
View data table
| Stage | Facebook v. Power Ventures (2016) | Amazon v. Perplexity (2026) |
|---|---|---|
| The setup | Power.com signs into user accounts with the users' consent | Comet's agent signs into user accounts with the users' consent |
| The platform's response | Cease-and-desist, IP blocks, CFAA suit | Written demand to stop, CFAA suit, March injunction |
| Who did the accessing, and the result | The tool; consent died with the platform's no; liability and a permanent injunction | The users; consent travels with the tool; injunction overturned |
The wall moves to the wire
Nothing here covers crawlers fetching public pages; that fight has different case law and no user in the loop. What this ruling changes is the anatomy of a platform's wall. That wall has always had two layers, a legal one and a technical one, and against tools carrying real user intent the legal layer was the load-bearing one. Power was not out-engineered, it was out-lawyered: the IP blocks it slipped past mattered because dodging them proved the access was unwelcome, not because they kept anyone out. Take the legal layer away and everything rests on a question the statute no longer answers for you: can you even tell which of your logged-in sessions has an agent inside? An agent driving a real browser on a real customer's laptop, spending a real saved credit card, looks very little like the bot traffic defenses were built to catch.
Which is why I do not read this as the door swinging open. I read it as the strongest argument yet for the identity rails I wrote about last week: signed agent traffic, passports, rate cards. If courts will not separate agents from users, the network has to, and the way you govern traffic you cannot ban is to name it, meter it, and price it. So here is the position this essay should be graded on: Amazon does not get its ban back, and within a year it will not want it. Before this case reaches a verdict, Amazon will offer agents an official door, with verified identity, terms, and something to sign, because a rival's software spending your customers' money is intolerable only while it is anonymous and free. If Amazon instead wins on the merits and keeps agents locked out through 2027, I read this wrong. The Power Ventures era asked whose computer it was. The era that started August 4 asks whose instructions it follows, and it will be answered in onboarding flows, not opinions.