Editor’s Note: A user who sends an AI agent shopping is the one accessing the store, under both the federal Computer Fraud and Abuse Act and California’s CDAFA. That is the Ninth Circuit’s Aug. 4 answer, on a preliminary record, in Amazon’s case against Perplexity, and with it the court vacated the injunction that had restricted Perplexity’s Comet Assistant on Amazon. The panel weighed Amazon’s argument that an autonomous Assistant made the access Perplexity’s own and rejected it for this architecture, finding the remaining injunction factors wanting as well.

Beyond doctrine, the decision surfaces a problem eDiscovery, information governance and security teams will own together: the records of agent-assisted conduct, prompts, session histories and action traces, can sit split between user devices and an outside operator’s systems, on the operator’s retention clocks, held by a company on nobody’s custodian chart. Control tests, Stored Communications Act limits and preservation mechanics all meet a data source the standard instruments do not name.

The practical work starts now: inventory agent use, name agents in hold templates and custodian interviews, and treat agent telemetry retention as a legal decision. Watch the remand, the Aug. 18 rehearing default and the first motion to compel an agent’s logs.


Content Assessment: Ninth Circuit vacates Amazon injunction; AI agent logs emerge as eDiscovery issue

Information - 93%
Insight - 94%
Relevance - 93%
Objectivity - 92%
Authority - 91%

93%

Excellent

A short percentage-based assessment of the qualitative benefit expressed as a percentage of positive reception of the recent article from ComplexDiscovery OÜ titled, "Ninth Circuit vacates Amazon injunction; AI agent logs emerge as eDiscovery issue."


Industry News – Artificial Intelligence Beat

Ninth Circuit vacates Amazon injunction; AI agent logs emerge as eDiscovery issue

ComplexDiscovery OÜ Staff

A user who sends Perplexity’s Comet Assistant shopping on Amazon, not Perplexity, is the party accessing Amazon’s systems under federal and California anti-hacking law, the Ninth Circuit concluded Aug. 4 on a preliminary record.

The ruling is narrow, and it decides no one’s final liability. What it surfaces is an evidence problem: records of agent-assisted conduct can sit split across the user’s device, the user’s account and systems an outside AI provider controls.

The decision from the U.S. Court of Appeals for the Ninth Circuit, Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444, vacated a March 9 preliminary injunction that had restricted Perplexity’s agentic shopping tool, the Comet browser’s Assistant, on Amazon, and returned the case to the district court. Writing for a unanimous panel, Judge Milan D. Smith Jr. concluded Amazon was unlikely to succeed on its claims under the Computer Fraud and Abuse Act (CFAA) and California’s Comprehensive Computer Data Access and Fraud Act (CDAFA), the state’s Penal Code Section 502, because Perplexity is not the party doing the accessing. The user is, the court reasoned, with the Assistant along as help, and the panel treated the federal and state access questions as rising and falling together.



Software in the statute’s eyes

The panel described the Assistant as software in service of the person who runs it, a tool rather than a person in the statute’s terms. Perplexity’s servers do not directly access Amazon’s, the court observed; the user’s browser does the communicating, while the Assistant reads the screen and passes instructions along. Drawing on Van Buren v. United States, the Supreme Court’s 2021 decision framing access as entry into a computer system or a part of one, and on its own 2022 hiQ Labs v. LinkedIn ruling describing the CFAA as an anti-intrusion statute, the panel declined to treat an agent’s assistance as its developer’s trespass. Ambiguity in a statute carrying criminal penalties, the opinion added, must be read against liability.

Amazon had put the opposite attribution squarely before the court. The Assistant, Amazon argued, acts like an efficient human shopper and proceeds on its own, with Perplexity’s servers directing its actions, which would make the access Perplexity’s. The panel rejected that account on this record, and it did not stop at the merits. Amazon’s evidence of irreparable harm read as abstract, the court found, with its expert unable to fully replicate the claimed cybersecurity risks, and the balance of equities and the public interest cut toward consumer choice and a developing technology rather than toward an injunction.

The court fenced its ruling to the record and the technology before it, declined to announce a general regime for agentic AI, and acknowledged that more autonomous architectures could present different facts. A footnote preserved Amazon’s ability to police automated shopping through its terms of service. The panel did not decide whether contract or tort theories might apply to agent operators in other contexts, and it did not reach a separate CFAA fraud provision that Amazon had not pressed on appeal. Nothing here is final: the opinion measures likelihood of success at the preliminary injunction stage, and Amazon’s pleaded CFAA and CDAFA claims continue in the district court.

How the fight got here

Amazon.com Services LLC sued Perplexity on Nov. 4, 2025, in the Northern District of California, alleging Comet logged into customer accounts with the account holder’s permission but not Amazon’s, wore Google Chrome’s user-agent string rather than identifying its agent, and put customer data at risk. Amazon pressed Perplexity’s chief executive twice in September 2025 and sent a cease-and-desist letter Oct. 31, according to the complaint; Perplexity answered with a blog post titled “Bullying Is Not Innovation,” accusing Amazon of trying to block innovation with legal threats. Judge Maxine M. Chesney’s March 9 injunction barred Perplexity’s agents from Amazon’s systems and ordered Perplexity to destroy every copy of Amazon data, customer data included, that the challenged access produced, reaching copies held by its service providers. The panel left the user-agent dispute unresolved; it became beside the point once the court found Perplexity was not the accessor.

Law firm alerts followed the ruling within days, and they agree on the practical result. Cooley’s Aug. 6 client alert read the decision to mean the CFAA may not restrict agents that route through a user’s device, pushing website operators toward contract enforcement. Wilson Sonsini attorneys Brian M. Willen, Demian Ahn and Edward Percarpio wrote in an Aug. 7 client alert that architecture now controls outcomes: developers who keep the user’s browser as the intermediary sit outside the statute, while server-to-server designs may not. Andrew Crocker of the Electronic Frontier Foundation, whose amicus brief the panel credited, said the ruling keeps the CFAA from converting browser makers into hackers. The Knight First Amendment Institute at Columbia University read the decision as a refusal to stretch computer crime law over tools that automate a person’s access to that person’s own information.

The exposure moves to the person who asked

Mike Masnick at Techdirt put the flip side plainly on Aug. 5: the toolmaker walks, and the person who sent the tool inherits the risk. Platforms frustrated by agents could work through users instead, with demand letters and civil claims, much as, he wrote, the recording industry once pursued its own customers. Wilson Sonsini’s alert traced the same concern inside the opinion itself, where the panel weighed that holding Perplexity liable could have exposed users to criminal liability for dispatching agents to their own accounts.

For the statutory access element, on this record, the accessor is the person who dispatched the agent. However the liability questions resolve, the authorization fights that arise will run user by user, each turning on what a specific person told a specific agent to do, and on what the agent then did.

Discovery inherits the holding

The doctrine-focused commentary has largely passed over the ruling’s biggest consequence, which is evidentiary. Deciding who acted shapes whose conduct must be proved, and the evidence of an agent-assisted transaction, where it survives, is a new species of record: the prompt the user typed, the session history, the agent’s action trace, the pages visited and the buttons pressed on the user’s behalf. In eDiscovery terms, the holder of much of that record is not a custodian at all. It is a nonparty evidence holder, a third-party data source on no custodian chart and answerable to no party’s litigation hold, and that is precisely the problem.

Where that record lives depends on architecture. Cloud-hosted agents may generate and retain it on the operator’s servers, under the operator’s retention schedule and settings. Browser-native designs split it: Perplexity has said user credentials stay on the device rather than on its servers, while the opinion describes an Assistant that reads what the user’s screen displays and relays information to Perplexity’s servers. In both of these patterns, part of the record can sit on infrastructure the user does not administer and cannot hold.

Rule 34 of the Federal Rules of Civil Procedure obligates a party to produce documents within its “possession, custody, or control.” The user possesses, at most, a slice of the agent record in any ordinary sense. Whether the user controls the rest is a test question, and the test varies by courthouse. The Sedona Conference’s commentary on the subject, reaffirmed in February 2024, counts three approaches across the federal circuits: control as a legal right to obtain records on demand, legal right plus a duty to notify the adversary about third-party holdings, and control as a practical ability to get the records. The commentary urges the legal right standard and places the Ninth Circuit, the court that just made the user the actor, in the legal right camp, while cautioning that courts have applied the standards inconsistently, even within circuits.

Run the agent record through that split and the answers diverge by record type and by jurisdiction. A consumer who can open the app and export a chat history arguably holds a legal right to that slice, which would put prompt logs within the user’s control and make them producible in litigation, and practical-ability jurisdictions may push control further. Backend telemetry is harder, and the routes to it run from cooperative to compulsory: an account export, the account holder’s consent, the operator’s voluntary cooperation and, failing those, a Rule 45 subpoena. Even the subpoena has a gate. The Stored Communications Act generally bars covered providers from disclosing stored communications content to civil litigants, with consent the standard workaround, routing the request through the account holder, as a K&L Gates alert by Philip M. Guess lays out. The bar reaches contents, though, not everything: metadata, security logs and action telemetry that do not capture a communication’s substance call for their own analysis, as does whether an agent operator is a covered provider for any given record. And if enforcement now moves toward users, as Masnick expects, the entity holding the richest record of the disputed conduct may not be at the table at all.

The remand tests only the easier half of that problem. Amazon’s CFAA and CDAFA claims continue in Chesney’s courtroom, where, because Perplexity remains a party, Amazon may seek relevant, proportional agent records within Perplexity’s possession, custody or control through ordinary party discovery. The harder half arrives in the disputes this ruling invites, where the operator is a stranger to the caption and the compulsory route runs through the subpoena, with its gates.

Preservation duties without possession

Preservation is where the mismatch bites first. A party’s duty to preserve attaches when litigation is reasonably anticipated, but a user’s litigation hold does not suspend an AI operator’s retention schedule, and consumer deletion features run on their own clocks. Counsel who anticipate a dispute over agent-driven conduct should assume the agent-side record is wasting from day one. A preservation letter to the operator may prompt voluntary retention and builds the record for later motion practice, but it does not by itself bind a nonparty; compelled preservation generally takes a subpoena or a court order in a pending case.

Courts have ordered AI providers to preserve logs at scale, though so far where the provider is itself a party. In The New York Times’ copyright case against OpenAI, Magistrate Judge Ona T. Wang ordered OpenAI, a defendant there, on May 13, 2025, to preserve and segregate output log data it would otherwise have deleted. U.S. District Judge Sidney Stein affirmed the order in June 2025, and in October 2025 the court ended the blanket going-forward obligation, keeping already-preserved data and accounts flagged by the plaintiffs within reach. The episode shows both the reach and the resistance, and it leaves the nonparty problem, the one this ruling sets up, unresolved. Jeffrey M. Kelly and colleagues at Nelson Mullins, writing on that dispute, urged companies to negotiate vendor agreements requiring notice when data lands under a hold, and to weigh zero-data-retention terms. Those terms cut both ways: an agent that retains nothing leaves nothing to produce, for either side.

The playbook writes itself into existing instruments. Litigation hold templates should name agentic tools alongside email and chat. Custodian interviews and data-source questionnaires should ask which agents a person used, on which accounts, personal or enterprise. Rule 26(f) conferences should treat agent logs as a named category with a stated operator and retention posture. Information governance teams should inventory agent use before the first dispute arrives; an agent an employee adopts on a personal account creates the same species of record, on the same outside infrastructure, without the enterprise controls or the export rights. Deletion rights under laws like the California Consumer Privacy Act carry exceptions for legal obligations and for legal claims, though when a litigation hold qualifies has been an open question since the statute’s early days, and only an organization that knows an agent record exists can invoke an exception before the record is gone.

Security budgets already treat agents as actors

The security market is already treating agents as actors to be governed. In the week the opinion issued, Zenity announced a $125 million Series C to secure AI agents, and Obsidian Security raised an $85 million Series D for its AI agent security platform at a valuation Axios reported at $1.1 billion. Vendors are selling identity, monitoring and audit controls for non-human actors, and the logs those controls generate are the records a litigator will someday request. Security teams setting retention for agent telemetry are, whether they intend it or not, making an eDiscovery decision.

Amazon said it disagrees with the decision and is evaluating next steps, according to PYMNTS and Engadget, while PYMNTS reported that Perplexity called the outcome a win for consumer choice in AI tools. Under Federal Rule of Appellate Procedure 40, a petition for rehearing in a civil case between private parties is ordinarily due within 14 days of the entry of judgment, a default that runs to Aug. 18 absent an extension.

The Ninth Circuit answered who acts when an agent acts, for now and for this architecture. Litigants will spend years answering what follows. When the first motion to compel an agent’s logs is filed, will your organization know where those logs live, who controls them, and whether they still exist?



News sources



Assisted by GAI and LLM Technologies

Additional reading

Source: ComplexDiscovery OÜ

ComplexDiscovery’s mission is to enable clarity for complex decisions by providing independent, data‑driven reporting, research, and commentary that make digital risk, legal technology, and regulatory change more understandable for practitioners, policymakers, and business leaders.

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is an independent digital publication and research organization based in Tallinn, Estonia. ComplexDiscovery covers cybersecurity, data privacy, regulatory compliance, and eDiscovery, with reporting that connects legal and business technology developments—including high-growth startup trends—to international business, policy, and global security dynamics. Focusing on technology and risk issues shaped by cross-border regulation and geopolitical complexity, ComplexDiscovery delivers editorial coverage, original analysis, and curated briefings for a global audience of legal, compliance, security, and technology professionals. Learn more at ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Gemini, Grammarly, Midjourney, and Perplexity, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).