Blockchain AcademicsBlockchain Academics
US Appeals Court Rules AI Agents Can Legally Act on Users' Behalf, Overturning Amazon Injunction

US Appeals Court Rules AI Agents Can Legally Act on Users' Behalf, Overturning Amazon Injunction

A U.S. appeals court has ruled that Amazon is unlikely to prove Perplexity AI violated federal hacking law when its AI agent made purchases on users' behalf, overturning a lower court injunction and setting the first appellate precedent on autonomous AI agents in digital commerce.

Blockchain Academics NewsroomEdited by Wael RajabAugust 6, 20263 min read
Share

US Appeals Court Rules AI Agents Can Legally Act on Users' Behalf, Overturning Amazon Injunction

A U.S. appeals court has ruled that Amazon is unlikely to prove Perplexity AI violated federal hacking law when its AI agent made purchases on users' behalf, overturning a lower court injunction and setting the first appellate precedent on autonomous AI agents operating within digital commerce.

The decision directly addresses whether AI agents, software systems that execute tasks autonomously on a user's instruction, can legally interact with online platforms without running afoul of the Computer Fraud and Abuse Act (CFAA). The court's answer was yes. Amazon had argued that Perplexity's shopping agent accessed its systems in an unauthorized manner, a claim the appeals court found unlikely to succeed under the CFAA's standards.

By establishing that an AI agent acting within a user's delegated authority does not constitute unauthorized computer access, the court has handed the broader AI agent industry a foundational legal shield. Perplexity's shopping feature, which allows users to complete purchases across retailers without leaving the app, had been blocked by the injunction. That block is now lifted.

Amazon's position reflected a stance common across large e-commerce platforms: that automated agents circumvent security protocols and terms-of-service agreements built around individual human users. Platform operators have long relied on those agreements to restrict bots and automated buyers, citing fraud prevention and account security. The appeals court's reasoning does not invalidate terms-of-service enforcement entirely, but it significantly narrows what qualifies as a federal crime under the CFAA when a user has explicitly authorized an agent to act for them.

The implications for decentralized finance are substantial. DeFi protocols increasingly rely on autonomous agents to execute trades, manage positions, and interact with smart contracts on behalf of wallet holders. The legal gray area around whether such agents constitute "authorized" access to third-party systems has been a persistent compliance concern. This ruling supplies the first appellate logic that user delegation confers legal standing to an agent's actions.

Consumer protection groups could push back on scenarios where AI agents execute transactions without per-transaction confirmation, raising questions about liability when an agent makes an error or is manipulated. Traditional retailers are likely to lobby for clearer statutory limits, arguing that the ruling creates openings for fraud if the authorization standard is interpreted loosely. The court's decision also leaves unresolved how platforms should distinguish between a legitimately delegated AI agent and a malicious bot claiming the same legal cover.

Prior CFAA cases established that unauthorized access requires exceeding permitted access, not merely automating it. The appeals court appears to have applied that logic here: if a user authorizes Perplexity to shop on their behalf, the agent is not exceeding the user's own access rights. That reasoning aligns with the 2021 Supreme Court ruling in Van Buren v. United States, which narrowed the CFAA's reach and rejected expansive interpretations of "unauthorized access."

For AI developers building agent-based products, the ruling is the clearest legal signal yet that user delegation is a viable and defensible framework. Platforms that want to restrict such agents will likely need to do so through contract law and technical controls rather than federal hacking statutes.

Discussion

Loading comments...