Amazon loses its case against Perplexity: the user is always responsible for what an AI does

A US court has attributed responsibility for access carried out via Perplexity’s AI assistant to the user, but has not ruled on a key issue: the liability of those who design software capable of operating on third-party infrastructure against the owner’s will by Andrea Monti – Originally published in Italian by Italian Tech – La Repubblica

An opinion of the US Court of Appeals for the Ninth Circuit published on 4 August 2026 has set an important precedent regarding liability for the use of AI agents, establishing that it is the end user who is responsible for how the tool is used, not the agent itself nor its developer.

According to the judge, the decision does not set a general precedent because its effects are limited to the interpretation of the federal Computer Fraud and Abuse Act (CFAA) and the State of California’s Comprehensive Computer Data Access and Fraud Act (CDAFA), and that there may be different situations requiring different assessments. However,  the reasoning grounding the decision offers several points for reflection.

The parties and the merits of the case

Amazon sued the AI start-up Perplexity, arguing that the features enabling the AI company’s browser to operate with a certain degree of autonomy constitute ‘access’ by Perplexity to Amazon’s infrastructure and that, as this access was not authorised by the e-commerce giant, Perplexity should be held liable for breaching the CFAA and the CDAFA.

Under scrutiny is the operation of Comet, the browser developed by Perplexity, which – in order to function in ‘assistant’ mode – captures a screenshot of what is displayed in the browser window, sends the image to Perplexity’s servers, which analyse the file and generate the instructions that the browser must execute to access the Amazon website. The procedure, therefore, requires the involvement of three elements: the assistant (which cannot operate independently), Perplexity’s infrastructure, and the user, who issues the commands. Amazon had made it clear to Perplexity that it would not permit the interaction of more or less autonomous assistants on its website, but Perplexity failed to comply with this request, and the matter consequently ended up in court.

The appeal judgement

At first instance, Amazon had obtained an interim injunction based on the assumption that, in fact, the way Comet operated allowed for the conclusion that it was Perplexity – and not the user – who was accessing the e-commerce site without authorisation. On appeal, however, the court, as stated in the judgement, ‘concluded that Amazon was not entitled to a preliminary injunction, as it was unlikely to succeed … in proving that Perplexity had “accessed” Amazon’s computers for the purposes set out in the CFAA. On the basis of the facts presented to the court, the court concluded that Perplexity had not used a tool to ‘access’ Amazon’s computers. Instead, it was the user who ‘accessed’ Amazon’s computers, with the aid of Perplexity’s artificial intelligence agent, the ‘Assistant’, to carry out specific actions on Amazon.com … the user (not Perplexity) accessed Amazon using the Assistant as an artificial intelligence tool.”

The positive aspect of the judgement

As the next paragraph explains, the appeal judgement is not entirely convincing, except on one point: that of holding the user accountable for the tools they use.

For some time now, the narrative put forward by Big Tech AI firms and poorly informed analysts and commentators has raised the issue of ‘AI’s legal liability’ and the need for ‘new laws’, thereby fostering the idea that human beings are absolved of responsibility for the way in which they use (any) technology. The Court of Appeal was therefore right to point out that responsibility lies with people, not machines. AI, in fact, is merely software — however complex it may be, but always and only software — whose operation is determined by human beings who bear the consequences of the way it is designed and subsequently used.

Issues not resolved by the decision

The false myth of cyberspace as a ‘place’

The ruling finds against Amazon on the basis of a rather simplistic line of reasoning, fundamentally flawed by the regulatory use of the ubiquitous – and erroneous – metaphor of ‘access’ to denote interaction with a computer, and by an underestimation of the way in which the interaction between the user, the browser and Perplexity’s infrastructure was designed.

It would take too long to explain how the concept of ‘access’ to a computer has evolved from a socio-psychological category into a legal institution; the fact remains that, almost everywhere, regulations and public policy strategies (including military ones) have adopted the cyberpunk narrative of cyberspace as a ‘place’ one can ‘enter’, giving rise to all the misunderstandings associated with it.

The real issue is the platform’s design liability

The link between this line of reasoning and the case between Amazon and Perplexity lies precisely in the meaning of the words. It was undoubtedly a user who ‘accessed’ the Amazon website, but the way in which Comet is designed and operates was determined by Perplexity, which must take responsibility for what it allows users to do.

When it comes to AI, this principle is beginning to gain ground in US courts, where the discussion centres on the liability of the manufacturer of AI systems rather than the AI itself. But as far back as 2001, it was the very same Court of Appeal that has now ruled on the case between Amazon and Perplexity which established the principle of liability for the design of software lacking systems to protect the rights of third parties. The case was A&M Records, Inc. v. Napster, which dealt a fatal blow to the ‘father of peer-to-peer’ on the grounds that the absence of systems to verify copyright compliance made the developer indirectly liable for what was done via the software.

Comet is not just any browser

So, to get back to the point: firstly, it is wrong to regard Comet as something separate from the rest of Perplexity’s infrastructure, just as it is wrong to think that Safari is ‘disconnected’ from services such as Private Relay or Tracking Prevention, or that Chrome is disconnected from the Google ecosystem. This is certainly not a new issue; as anyone who’s been around for a while will recall, back in the days of HTML 1.0, the great lengths one had to go to in order to develop a site compatible with Any Browser — specifically, with the now-defunct Internet Explorer.

In fact, Comet is the only browser that allows users to utilise Perplexity’s AI features and should therefore be considered, for all intents and purposes, not as stand-alone software but as an interface for running the AI services. Therefore, even if one were to start from the same premises as the judgement, in reality it is not only the user who accesses Amazon’s resources — or rather, who uses them — but Perplexity as well. The fact that this happens indirectly, because the screenshot is processed outside Amazon’s servers, is of little consequence, since ultimately Comet — that is, Perplexity — uses the results of that processing to ‘access’ the e-commerce site.

There is no ‘right’ to use certain features on third-party resources

Another issue the judgement does not address — perhaps because it was not brought to the judge’s attention — is the non-existence of a ‘right’ to use certain features. The fact that Perplexity — or anyone else — makes software available that functions in a certain way does not imply that anyone must agree to interact with that software. Amazon, therefore, was fully within its rights to ask Perplexity to make its assistant identifiable so that it could be blocked.

What does this ruling mean for the development of AI?

As mentioned, albeit within the limits set out by the judge, the ruling helps to reinforce the concept that human beings are solely responsible for the use of software tools, no matter how autonomous they may be.

The real issue, however – and this is where the ‘unspoken’ aspect of the ruling matters most – is ‘which’ human being should be held responsible, not so much for errors but for the deliberate choices made during the design phase of software intended to run on a single computer or to enable millions of people to use platform services. To be clear, we are talking about the core concept underlying the lawsuits brought against social media platforms, one of the most recent being the case against Meta, namely the claim that they were deliberately designed to cause harm to users.

R.I.P. the mammoth European regulation on AI, the pragmatic approach of the American courts has already begun to draw the line distinguishing the liabilities of users from those of software producers. This demonstrates two things: firstly, that no ‘new laws’ are needed to assign liability for the use of AI; and secondly, that the mere fact that something can be done — such as building autonomous assistants — does not necessarily imply that it should be done, nor that there is a right to impose this on those who disagree.