Editor’s Note: A user who sends an AI agent shopping is the one accessing the store, under both the federal Computer Fraud and Abuse Act and California’s CDAFA. That is the Ninth Circuit’s Aug. 4 answer, on a preliminary record, in Amazon’s case against Perplexity, and with it the court vacated the injunction that had restricted Perplexity’s Comet Assistant on Amazon. The panel weighed Amazon’s argument that an autonomous Assistant made the access Perplexity’s own and rejected it for this architecture, finding the remaining injunction factors wanting as well.
Beyond doctrine, the decision surfaces a problem eDiscovery, information governance and security teams will own together: the records of agent-assisted conduct, prompts, session histories and action traces, can sit split between user devices and an outside operator’s systems, on the operator’s retention clocks, held by a company on nobody’s custodian chart. Control tests, Stored Communications Act limits and preservation mechanics all meet a data source the standard instruments do not name.
The practical work starts now: inventory agent use, name agents in hold templates and custodian interviews, and treat agent telemetry retention as a legal decision. Watch the remand, the Aug. 18 rehearing default and the first motion to compel an agent’s logs.
Content Assessment: Ninth Circuit vacates Amazon injunction; AI agent logs emerge as eDiscovery issue
Information - 93%
Insight - 94%
Relevance - 93%
Objectivity - 92%
Authority - 91%
93%
Excellent
A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Ninth Circuit vacates Amazon injunction; AI agent logs emerge as eDiscovery issue."
Industry News – Artificial Intelligence Beat
Ninth Circuit vacates Amazon injunction; AI agent logs emerge as eDiscovery issue
ComplexDiscovery OÜ Staff
A user who sends Perplexity’s Comet Assistant shopping on Amazon, not Perplexity, is the party accessing Amazon’s systems under federal and California anti-hacking law, the Ninth Circuit concluded Aug. 4 on a preliminary record.
The ruling is narrow, and it decides no one’s final liability. What it surfaces is an evidence problem: records of agent-assisted conduct can sit split across the user’s device, the user’s account and systems an outside AI provider controls.
The decision from the U.S. Court of Appeals for the Ninth Circuit, Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444, vacated a March 9 preliminary injunction that had restricted Perplexity’s agentic shopping tool, the Comet browser’s Assistant, on Amazon, and returned the case to the district court. Writing for a unanimous panel, Judge Milan D. Smith Jr. concluded Amazon was unlikely to succeed on its claims under the Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer Data Access and Fraud Act (CDAFA), the state’s Penal Code Section 502, because Perplexity is not the party doing the accessing. The user is, the court reasoned, with the Assistant along as help, and the panel treated the federal and state access questions as rising and falling together.
Software in the statute’s eyes
The panel described the Assistant as software in service of the person who runs it, a tool rather than a person in the statute’s terms. Perplexity’s servers do not directly access Amazon’s, the court observed; the user’s browser does the communicating, while the Assistant reads the screen and passes instructions along. Drawing on Van Buren v. United States, the Supreme Court’s 2021 decision framing access as entry into a computer system or a part of one, and on its own 2022 hiQ Labs v. LinkedIn ruling describing the CFAA as an anti-intrusion statute, the panel declined to treat an agent’s assistance as its developer’s trespass. Ambiguity in a statute carrying criminal penalties, the opinion added, must be read against liability.
Amazon had put the opposite attribution squarely before the court. The Assistant, Amazon argued, acts like an efficient human shopper and proceeds on its own, with Perplexity’s servers directing its actions, which would make the access Perplexity’s. The panel rejected that account on this record, and it did not stop at the merits. Amazon’s evidence of irreparable harm read as abstract, the court found, with its expert unable to fully replicate the claimed cybersecurity risks, and the balance of equities and the public interest cut toward consumer choice and a developing technology rather than toward an injunction.
The court fenced its ruling to the record and the technology before it, declined to announce a general regime for agentic AI, and acknowledged that more autonomous architectures could present different facts. A footnote preserved Amazon’s ability to police automated shopping through its terms of service. The panel did not decide whether contract or tort theories might apply to agent operators in other contexts, and it did not reach a separate CFAA fraud provision that Amazon had not pressed on appeal. Nothing here is final: the opinion measures likelihood of success at the preliminary injunction stage, and Amazon’s pleaded CFAA and CDAFA claims continue in the district court.
How the fight got here
Amazon.com Services LLC sued Perplexity on Nov. 4, 2025, in the Northern District of California, alleging Comet logged into customer accounts with the account holder’s permission but not Amazon’s, wore Google Chrome’s user-agent string rather than identifying its agent, and put customer data at risk. Amazon pressed Perplexity’s chief executive twice in September 2025 and sent a cease-and-desist letter Oct. 31, according to the complaint; Perplexity answered with a blog post titled “Bullying Is Not Innovation,” accusing Amazon of trying to block innovation with legal threats. Judge Maxine M. Chesney’s March 9 injunction barred Perplexity’s agents from Amazon’s systems and ordered Perplexity to destroy every copy of Amazon data, customer data included, that the challenged access produced, reaching copies held by its service providers. The panel left the user-agent dispute unresolved; it became beside the point once the court found Perplexity was not the accessor.
Law firm alerts followed the ruling within days, and they agree on the practical result. Cooley’s Aug. 6 client alert read the decision to mean the CFAA may not restrict agents that route through a user’s device, pushing website operators toward contract enforcement. Wilson Sonsini attorneys Brian M. Willen, Demian Ahn and Edward Percarpio wrote in an Aug. 7 client alert that architecture now controls outcomes: developers who keep the user’s browser as the intermediary sit outside the statute, while server-to-server designs may not. Andrew Crocker of the Electronic Frontier Foundation, whose amicus brief the panel credited, said the ruling keeps the CFAA from converting browser makers into hackers. The Knight First Amendment Institute at Columbia University read the decision as a refusal to stretch computer crime law over tools that automate a person’s access to that person’s own information.
The exposure moves to the person who asked
Mike Masnick at Techdirt put the flip side plainly on Aug. 5: the toolmaker walks, and the person who sent the tool inherits the risk. Platforms frustrated by agents could work through users instead, with demand letters and civil claims, much as, he wrote, the recording industry once pursued its own customers. Wilson Sonsini’s alert traced the same concern inside the opinion itself, where the panel weighed that holding Perplexity liable could have exposed users to criminal liability for dispatching agents to their own accounts.
For the statutory access element, on this record, the accessor is the person who dispatched the agent. However the liability questions resolve, the authorization fights that arise will run user by user, each turning on what a specific person told a specific agent to do, and on what the agent then did.
Discovery inherits the holding
The doctrine-focused commentary has largely passed over the ruling’s biggest consequence, which is evidentiary. Deciding who acted shapes whose conduct must be proved, and the evidence of an agent-assisted transaction, where it survives, is a new species of record: the prompt the user typed, the session history, the agent’s action trace, the pages visited and the buttons pressed on the user’s behalf. In eDiscovery terms, the holder of much of that record is not a custodian at all. It is a nonparty evidence holder, a third-party data source on no custodian chart and answerable to no party’s litigation hold, and that is precisely the problem.
Where that record lives depends on architecture. Cloud-hosted agents may generate and retain it on the operator’s servers, under the operator’s retention schedule and settings. Browser-native designs split it: Perplexity has said user credentials stay on the device rather than on its servers, while the opinion describes an Assistant that reads what the user’s screen displays and relays information to Perplexity’s servers. In both of these patterns, part of the record can sit on infrastructure the user does not administer and cannot hold.
Rule 34 of the Federal Rules of Civil Procedure obligates a party to produce documents within its “possession, custody, or control.” The user possesses, at most, a slice of the agent record in any ordinary sense. Whether the user controls the rest is a test question, and the test varies by courthouse. The Sedona Conference’s commentary on the subject, reaffirmed in February 2024, counts three approaches across the federal circuits: control as a legal right to obtain records on demand, legal right plus a duty to notify the adversary about third-party holdings, and control as a practical ability to get the records. The commentary urges the legal right standard and places the Ninth Circuit, the court that just made the user the actor, in the legal right camp, while cautioning that courts have applied the standards inconsistently, even within circuits.
Run the agent record through that split and the answers diverge by record type and by jurisdiction. A consumer who can open the app and export a chat history arguably holds a legal right to that slice, which would put prompt logs within the user’s control and make them producible in litigation, and practical-ability jurisdictions may push control further. Backend telemetry is harder, and the routes to it run from cooperative to compulsory: an account export, the account holder’s consent, the operator’s voluntary cooperation and, failing those, a Rule 45 subpoena. Even the subpoena has a gate. The Stored Communications Act generally bars covered providers from disclosing stored communications content to civil litigants, with consent the standard workaround, routing the request through the account holder, as a K&L Gates alert by Philip M. Guess lays out. The bar reaches contents, though, not everything: metadata, security logs and action telemetry that do not capture a communication’s substance call for their own analysis, as does whether an agent operator is a covered provider for any given record. And if enforcement now moves toward users, as Masnick expects, the entity holding the richest record of the disputed conduct may not be at the table at all.
The remand tests only the easier half of that problem. Amazon’s CFAA and CDAFA claims continue in Chesney’s courtroom, where, because Perplexity remains a party, Amazon may seek relevant, proportional agent records within Perplexity’s possession, custody or control through ordinary party discovery. The harder half arrives in the disputes this ruling invites, where the operator is a stranger to the caption and the compulsory route runs through the subpoena, with its gates.
Preservation duties without possession
Preservation is where the mismatch bites first. A party’s duty to preserve attaches when litigation is reasonably anticipated, but a user’s litigation hold does not suspend an AI operator’s retention schedule, and consumer deletion features run on their own clocks. Counsel who anticipate a dispute over agent-driven conduct should assume the agent-side record is wasting from day one. A preservation letter to the operator may prompt voluntary retention and builds the record for later motion practice, but it does not by itself bind a nonparty; compelled preservation generally takes a subpoena or a court order in a pending case.
Courts have ordered AI providers to preserve logs at scale, though so far where the provider is itself a party. In The New York Times’ copyright case against OpenAI, Magistrate Judge Ona T. Wang ordered OpenAI, a defendant there, on May 13, 2025, to preserve and segregate output log data it would otherwise have deleted. U.S. District Judge Sidney Stein affirmed the order in June 2025, and in October 2025 the court ended the blanket going-forward obligation, keeping already-preserved data and accounts flagged by the plaintiffs within reach. The episode shows both the reach and the resistance, and it leaves the nonparty problem, the one this ruling sets up, unresolved. Jeffrey M. Kelly and colleagues at Nelson Mullins, writing on that dispute, urged companies to negotiate vendor agreements requiring notice when data lands under a hold, and to weigh zero-data-retention terms. Those terms cut both ways: an agent that retains nothing leaves nothing to produce, for either side.
The playbook writes itself into existing instruments. Litigation hold templates should name agentic tools alongside email and chat. Custodian interviews and data-source questionnaires should ask which agents a person used, on which accounts, personal or enterprise. Rule 26(f) conferences should treat agent logs as a named category with a stated operator and retention posture. Information governance teams should inventory agent use before the first dispute arrives; an agent an employee adopts on a personal account creates the same species of record, on the same outside infrastructure, without the enterprise controls or the export rights. Deletion rights under laws like the California Consumer Privacy Act carry exceptions for legal obligations and for legal claims, though when a litigation hold qualifies has been an open question since the statute’s early days, and only an organization that knows an agent record exists can invoke an exception before the record is gone.
Security budgets already treat agents as actors
The security market is already treating agents as actors to be governed. In the week the opinion issued, Zenity announced a $125 million Series C to secure AI agents, and Obsidian Security raised an $85 million Series D for its AI agent security platform at a valuation Axios reported at $1.1 billion. Vendors are selling identity, monitoring and audit controls for non-human actors, and the logs those controls generate are the records a litigator will someday request. Security teams setting retention for agent telemetry are, whether they intend it or not, making an eDiscovery decision.
Amazon said it disagrees with the decision and is evaluating next steps, according to PYMNTS and Engadget, while PYMNTS reported that Perplexity called the outcome a win for consumer choice in AI tools. Under Federal Rule of Appellate Procedure 40, a petition for rehearing in a civil case between private parties is ordinarily due within 14 days of the entry of judgment, a default that runs to Aug. 18 absent an extension.
The Ninth Circuit answered who acts when an agent acts, for now and for this architecture. Litigants will spend years answering what follows. When the first motion to compel an agent’s logs is filed, will your organization know where those logs live, who controls them, and whether they still exist?

News sources
- Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444, Opinion (U.S. Court of Appeals for the Ninth Circuit)
- Complaint, Amazon.com Services LLC v. Perplexity AI, Inc., No. 3:25-cv-09514, Doc. 1 (filed Nov. 4, 2025) (U.S. District Court, N.D. Cal., via Chat GPT Is Eating the World)
- Preliminary Injunction Order, No. 3:25-cv-09514-MMC (March 9, 2026) (U.S. District Court, N.D. Cal., via Courthouse News)
- Ninth Circuit Rules on AI Agent Access to Third-Party Websites Under CFAA (Cooley)
- Ninth Circuit Addresses CFAA and Agentic AI Tools in Groundbreaking Decision (Wilson Sonsini)
- Ninth Circuit: Your AI Agent Can’t Violate Hacking Law. But You Might. (Techdirt)
- Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA (Electronic Frontier Foundation)
- Ninth Circuit Narrows CFAA Reach in Perplexity Agentic Commerce Ruling (PYMNTS)
- Ninth Circuit Vacates Injunction Against Perplexity’s AI Agents (Knight First Amendment Institute)
- Ninth Circuit Lifts Restrictions on Agentic AI Accessing Amazon (Technology & Marketing Law Blog)
- Perplexity has successfully overturned Amazon’s injunction on its AI shopping bot (Engadget)
- Court blocks Perplexity’s Comet browser from Amazon’s accounts (PPC Land)
- Amazon sues Perplexity over covert AI agent access to marketplace (PPC Land)
- Amazon Sues Perplexity Over ‘Agentic’ Shopping Tool (Insurance Journal via Reuters)
- From Copyright Case to AI Data Crisis: How The New York Times v. OpenAI Reshapes Companies’ Data Governance and eDiscovery Strategy (Nelson Mullins)
- NYT v. OpenAI Preservation Order, May 13, 2025 (U.S. District Court, S.D.N.Y., via Ars Technica)
- OpenAI no longer has to preserve all of its ChatGPT data, with some exceptions (Engadget)
- Commentary on Rule 34 and Rule 45 Possession, Custody, or Control (The Sedona Conference)
- Federal Rule of Civil Procedure 34 (Legal Information Institute)
- Federal Rule of Appellate Procedure 40 (Legal Information Institute)
- Litigation Minute: Subpoenas and the Stored Communications Act (K&L Gates)
- How the CCPA Impacts Civil Litigation (IAPP)
- Zenity raises $125 million Series C as AI agent security startup accelerates global expansion (CTech by Calcalist)
- Obsidian Security raises at $1.1B valuation (Axios Pro)
Assisted by GAI and LLM Technologies
Additional reading
- Federal magistrate judge treats LinkedIn’s Relativity aiR workflow as TAR
- One benchmark, three directions: 2026 legal rates rise, flatten and fall at once
- Confidence cools, commitment holds: full results from the 1H 2026 eDiscovery Business Confidence Survey
- Complete look: ComplexDiscovery OÜ’s 2025 to 2030 eDiscovery market size mashup
- The workstream of eDiscovery: Considering processes and tasks
- Andrew Haslam’s eDisclosure Systems Buyers Guide at 14: What the 1H 2026 update reveals
- A Complete Analysis of the Winter 2026 eDiscovery Pricing Survey
- The M&A Risk of Confusing Market Velocity with Marketing Capability
Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.



























