If you have ever asked an AI assistant to “find me a cheaper version of this and buy it,” you have used one of the new AI shopping agents — software that logs into your accounts, compares products and clicks the buy button for you. On 4 August 2026, a US federal appeals court decided whether that is legal, and the answer surprised a lot of people.
The Ninth Circuit Court of Appeals vacated an injunction that had banned Perplexity’s Comet browser from Amazon.com. Its reasoning was deceptively simple: when you tell an agent to shop, you are the one visiting Amazon. The software is just the hands.
What did the court actually decide about AI shopping agents?
The Ninth Circuit held that Amazon was unlikely to win its claim under the Computer Fraud and Abuse Act (CFAA), the US anti-hacking law. The court found that the user, not Perplexity, “accessed” Amazon’s computers, because the traffic flowed through the user’s own machine rather than from Perplexity’s servers directly to Amazon’s.
That is the whole hinge of the case. The CFAA punishes unauthorised access to a computer. If the person doing the accessing is the account holder — someone Amazon has already authorised — then no hacking law was broken, no matter how the clicks were generated.
The takeaway in one sentence: under this ruling, an AI agent that runs on your device and acts on your instruction is treated as a tool you are using, not as a trespasser in its own right.
According to the analysis published by law firm Cooley, this is the first federal appellate decision to address whether AI agents acting for users may lawfully access online platforms.
How does an AI shopping agent use your Amazon account?
An AI shopping agent runs inside a browser on your device. You give it a plain-English goal, it opens the retailer’s site using your existing logged-in session or your saved credentials, reads the page like a human would, fills in forms, and completes checkout. Nothing is “hacked” — it drives the same interface you see.
This is what makes the category legally awkward. There is no special API, no partnership, no permission slip. Perplexity’s Comet, launched as an AI-native browser, can log into accounts, search catalogues, compare options and complete purchases from a single natural-language instruction.
Amazon’s objection was not that the technology was impossible to detect. It was that Comet allegedly hid. In its November 2025 lawsuit, Amazon claimed Perplexity disguised Comet as ordinary Google Chrome and declined to identify it as an automated agent, then shipped new versions to evade detection after being warned.
Why did Amazon fight so hard to block it?
Retailers do not make money purely from transactions. They make money from the shopping experience — sponsored placements, recommendations, upsells, Prime signups, review ecosystems. An agent that skips straight to “cheapest item matching this description” strips all of that away and reduces the world’s largest retailer to a price-lookup table.
There is a genuine safety argument too. In October 2025, security researchers at Brave disclosed prompt-injection vulnerabilities in Comet, showing that hidden text on a web page could hijack an agent’s instructions. When the hijacked agent has your payment details and a logged-in session, the stakes rise sharply. We covered how badly agents can misbehave under test conditions in what the UK safety tests found about rogue AI agents.
Amazon won round one. In March 2026, US District Judge Maxine M. Chesney granted a preliminary injunction barring Comet from password-protected Amazon accounts. August’s appellate ruling undid that.
What the ruling does not settle
This is where the headlines oversimplified. The Ninth Circuit narrowed one law; it did not declare open season on agentic commerce.
- It was a preliminary ruling. The court assessed Amazon’s likelihood of success, not the final merits. The underlying case continues.
- Contract claims survive. Breach of terms of service, and tort-based theories, were expressly left open. Amazon has already updated its legal terms to restrict agent behaviour.
- Architecture matters. The court noted that a different design — where an AI company’s own servers talk directly to a retailer’s servers — could produce a different outcome entirely.
In other words: run the agent on the user’s machine and you look like a tool. Run it from your own data centre and you may look like a trespasser.
Are AI shopping agents safe to use right now?
Legally permitted is not the same as sensible. A shopping agent needs deep access — your logged-in sessions, saved addresses and stored cards — and that access is exactly what an attacker wants. Prompt injection remains an unsolved problem across the industry, not a Perplexity-specific bug.
Practical guidance if you want to try one:
- Set a hard spending limit, or require manual confirmation before any purchase completes.
- Use a virtual or low-limit card rather than your primary one.
- Do not let an agent browse untrusted sites in the same session it has your payment access.
- Read the retailer’s terms — the court protected the agent maker, not necessarily your account from suspension.
That last point matters and is widely missed. Nothing in the ruling stops Amazon from closing an account it believes is being automated.
What it means for retailers
The wider market has already moved past litigation. Amazon’s own Buy for Me feature lets customers purchase from third-party brand sites without leaving Amazon. Google introduced its Universal Commerce Protocol with Shopify at NRF 2026, an open standard for agents to browse catalogues and complete checkout. OpenAI’s Instant Checkout went live with partners including Etsy, Shopify and Walmart.
The strategic question for any online seller is no longer “how do I block agents” but “how does an agent find and understand my products”. That is the same shift toward machine-readable, answer-first content we explored in our guide to AEO, SEO and GEO.
Amazon’s own posture tells the story: after months of blocking agents and suing Perplexity, the company has been hiring for strategic partnerships in agentic commerce. As Engadget reported, the injunction’s reversal lets Comet back onto the platform while the case grinds on.
Frequently Asked Questions
Is it now legal for AI shopping agents to buy things on Amazon?
Under this Ninth Circuit ruling, using an agent that runs on your device and acts on your instruction does not violate the Computer Fraud and Abuse Act. But the decision is preliminary, and separate contract and terms-of-service claims remain unresolved.
Can Amazon still ban my account for using an AI shopping agent?
Yes. The ruling limited a federal hacking statute; it did not force Amazon to welcome agents. Retailers can still enforce their terms of service and suspend accounts they believe are automated.
What is the Computer Fraud and Abuse Act?
The CFAA is the main US federal anti-hacking law. It penalises accessing a computer without authorisation. The court found that an account holder directing an agent is authorised access, so the statute did not apply here.
What is prompt injection, and why does it matter for shopping agents?
Prompt injection is when hidden instructions on a web page hijack an AI agent’s behaviour. Brave researchers demonstrated this against Comet in October 2025. For an agent holding your payment details, a successful injection could mean unauthorised purchases.
Which companies offer AI shopping agents in 2026?
Perplexity’s Comet browser, Amazon’s Buy for Me, Google’s agentic checkout built on its Universal Commerce Protocol, and OpenAI’s Instant Checkout with partners including Etsy, Shopify and Walmart are among the most established options.


