← All Articles Radar Editorial
Regulation Deep Dive

Amazon v. Perplexity Will Decide Whether Your Own Login Counts as Hacking When an AI Agent Uses It

By AI SaaS Radar Team · Aug 2026 · 7 min read

In November 2025, Amazon sued Perplexity over Comet, its agentic browser that can log into websites and complete tasks on a user's behalf. Amazon's argument was not that Comet stole credentials or bypassed a login wall. The user's own valid username and password were used, on the user's own behalf, exactly as the user could have used them manually. Amazon argued that doing so through an automated agent, on Amazon's password-protected pages, violates the Computer Fraud and Abuse Act, a law passed in 1986 to prosecute hacking.

A federal judge agreed enough to grant Amazon a preliminary injunction in March 2026, blocking Comet from operating on Amazon's site while the case proceeds. Perplexity appealed, and the Ninth Circuit Court of Appeals stayed that injunction pending the outcome. As of now, Comet's access to Amazon sits in a legal holding pattern, and so does the actual question the case turns on.

What "unauthorized access" means when the user authorized it

The CFAA was built around a simpler world: a person with no rights to a system gets in anyway. Comet inverts the usual fact pattern. The person operating it does have rights, a paid Amazon account and a valid login. What Amazon is arguing is that the automation itself, not the credential, is what makes the access unauthorized, because Amazon's terms of service do not permit that kind of automated interaction with its site regardless of who is behind it.

If that argument holds, a website's terms of service become a mechanism for deciding which software is legally allowed to act on a logged-in user's behalf, backed by federal anti-hacking law rather than ordinary contract law. If it does not hold, sites lose a tool they might otherwise use to keep agentic browsers off their pages entirely.

Why every other agentic browser vendor is watching

Comet is not the only product built on the premise that an AI agent can browse the web and act inside authenticated sessions the way a human would. Every vendor building something similar is exposed to the same legal theory Amazon is testing, and the Ninth Circuit's eventual ruling on the merits, whenever it lands, will function as a de facto rulebook for the entire category. A win for Amazon narrows what agentic browsers can do on any site whose owner objects. A win for Perplexity establishes that acting through a user's own valid login is not, on its own, unauthorized access no matter what the terms of service say.

Nothing about the underlying product experience has changed while this plays out. What has changed is that anyone building an agent that logs into other people's sites now has a concrete, live case to point to, in either direction, when a client or investor asks whether that is legally settled ground. It is not settled, and the stay means it will not be for a while longer.

The practical takeaway

If your product or workflow depends on an AI agent authenticating into third-party sites on a user's behalf, the legal footing for that pattern is currently undecided at the appellate level in one of the most closely watched circuits in the country. Building on the assumption that a valid user login makes automated access self-evidently fine is, right now, an assumption, not a settled fact.

Stay ahead of the AI SaaS market

Sourced, dated analysis on security, funding, and benchmarks. Straight to your inbox.

No spam. Unsubscribe anytime.