Ninth Circuit Ruling Shields AI Agents From CFAA Claims

A federal appeals court has limited how companies can use a decades-old anti-hacking law against AI agents that browse and buy on users' behalf, a decision that could reshape the legal rules for agentic commerce.

August 07, 2026
Ninth Circuit Ruling Shields AI Agents From CFAA Claims Security

Summary: : The Ninth Circuit has narrowed the scope of the Computer Fraud and Abuse Act in a case involving Perplexity's AI shopping tools, ruling that automated agents acting on a user's authorization don't necessarily violate federal anti-hacking law. The decision matters for the fast-growing field of agentic commerce, where AI systems browse, compare and purchase products without direct human clicks. It's an early legal signal in a space with little settled case law and could influence how retailers, banks and AI companies structure access agreements going forward. &-Abuse-Act-(CFAA).

security aicybersecuritycomputer fraud

An AI agent that buys a pair of sneakers on your behalf isn't the same, legally, as a hacker breaking into a server.

That distinction just became much clearer.

The Ninth Circuit Court of Appeals has issued a ruling narrowing how the Computer Fraud and Abuse Act (CFAA) applies to AI systems acting autonomously on a user's instructions.

The case involves Perplexity, the AI search and answer platform that has been expanding into agentic commerce by allowing its AI assistant to browse merchant websites and complete purchases without users manually clicking through every step.

The CFAA is a federal law enacted in 1986 to combat computer hacking. It prohibits accessing computer systems "without authorization" or in excess of authorized access. Over the years, companies have increasingly relied on the statute in disputes involving web scraping, bots and, more recently, AI agents interacting with websites.

The Ninth Circuit's message, in this case, is clear: not every autonomous AI action amounts to unauthorized access.

Why the Ruling Matters

The court drew a sharper distinction between unauthorized hacking and AI agents acting with a user's permission, even if the website itself never intended automated tools to interact in that way.

That distinction matters for the entire category of AI shopping agents and browser-based assistants now emerging across the industry.

Companies including OpenAI, Amazon and Google are all developing or testing agentic shopping experiences that allow AI systems to search, compare products and complete purchases with minimal human involvement.

Had the court taken the opposite view, treating many AI agent interactions as CFAA violations, it could have exposed much of the emerging agentic commerce industry to significant legal risk.

One conclusion stands out: this is one of the first appellate-level rulings examining how a 1986 anti-hacking law applies to modern AI agents, and the decision favors a narrower interpretation of the statute.

Agentic commerce has advanced much faster than the legal framework governing it.

Retailers have argued that AI agents can bypass loyalty programs, pricing structures and bot-detection systems designed to regulate automated access. Perplexity has already faced disputes with online platforms over how its shopping assistant accesses their services.

The CFAA has been one of the strongest legal tools available to companies seeking to challenge that behavior because it carries both civil and criminal consequences.

The Ninth Circuit's ruling doesn't eliminate those disputes. Companies can still pursue breach-of-contract claims, enforce terms of service or rely on state computer access laws.

What the decision does is limit one of the most aggressive legal arguments available under federal law, at least within the Ninth Circuit, which includes California and much of the West Coast, home to many of the world's leading AI companies.

That geographic reach gives the ruling influence well beyond the parties involved, particularly as AI companies continue building increasingly autonomous products.

What This Means for Miami

South Florida has become a growing hub for fintech, payments and e-commerce infrastructure, with startups building AI-powered shopping, payments and checkout technologies.

Greater legal clarity around agentic commerce provides founders and investors with a better understanding of the regulatory landscape, even if many questions remain unresolved.

For Miami companies developing AI shopping assistants, comparison tools or automated purchasing systems, the ruling offers an encouraging signal that courts may distinguish between legitimate user-authorized automation and unlawful hacking.

As agentic commerce continues to evolve, businesses across South Florida will also need to rethink website access policies, terms of service and AI governance strategies as courts gradually define the rules for autonomous software.

← Back to MAIN