The Ninth Circuit held that when an agent reaches into someone else's system, the person who deployed it did the accessing. The industry read that as a win. Read it again with your vendor contract open.
On August 4, the Ninth Circuit vacated a district court injunction that had stopped Perplexity's agent from operating inside Amazon accounts. The reasoning is short enough to fit in a sentence: an AI agent is a tool, not a person, so it was the user who accessed Amazon's computers, with the agent's help.
Within a week, four major firms had client alerts out. Most of the commentary framed it as a green light — agents can shop, browse, transact, and the Computer Fraud and Abuse Act will not be the thing that stops them. That reading is correct and almost entirely beside the point for anyone running agents inside an enterprise.
Because if the agent is a tool, the tool has an owner. And the court just said the owner is the one doing the accessing.
The question the ruling actually answered
Amazon's complaint was not that Perplexity's agent did something destructive. It was that the agent entered customer accounts without identifying itself to Amazon as an agent. The claims were brought under the CFAA and California's equivalent, the CDAFA — the statutes that govern unauthorized access to a computer system.
The district court had already been unimpressed by Amazon's stated harms, describing the product-selection and cybersecurity injuries as comparatively weak and abstract. The Ninth Circuit went further and addressed the identity question directly. Where the plaintiff wanted the agent treated as an unauthorized third party in the room, the panel treated it as an instrument in the user's hand.
That is the first time a federal appeals court has answered the question at all. It resolves a live ambiguity in favor of the agent's continued operation. It also, quietly, resolves the question of whose conduct it was in a direction most enterprise AI contracts were not drafted for.
Where the exposure lands
Nearly every enterprise agent deployment involves the agent touching a system the enterprise does not own. It reads a partner's API. It pulls pricing from a supplier portal. It logs into a customer's tenant to do a support task. It scrapes a competitor's public site to keep a comparison table current. In each case there is a terms-of-service document somewhere that says something about automated access, and in most cases nobody has read it since procurement signed it.
Under the pre-ruling ambiguity, an enterprise could at least argue the vendor was a participant in whatever happened. After August 4, in the Ninth Circuit, that argument is harder. The agent is your instrument. The access is your access. The terms you are bound by are the ones you agreed to, not the ones your AI vendor agreed to.
Now open the AI vendor agreement and find the indemnity. In the overwhelming majority of enterprise AI contracts signed in the last two years, the indemnity covers intellectual property claims arising from the model's training data and output. That was the litigation everyone was watching. Unauthorized-access claims — CFAA, CDAFA, state computer-crime analogues, breach of a third party's terms of service — are usually somewhere else in the document, in a section that limits the vendor's liability rather than extending it, and often inside an acceptable-use clause that makes compliance with third-party terms explicitly the customer's responsibility.
The contract you negotiated anticipated being sued over what the model produced. The ruling concerns what the agent did, and to whom.
Figure 1
If your agent does this | Claim it can attract | Who the court now treats as the actor | What a typical AI vendor indemnity covers |
|---|---|---|---|
Logs into a partner or customer system on a user's behalf | CFAA / CDAFA unauthorized access; breach of contract | Your organization, as the accessing party | Generally not covered; often expressly the customer's responsibility under acceptable use |
Scrapes a third-party site to keep internal data current | Breach of terms of service; CFAA if access controls were bypassed | Your organization | Not covered |
Reproduces protected content in an output | Copyright infringement | Contested, and the subject of most existing indemnities | Usually covered, subject to caps and conditions |
Takes an action with financial consequence in a counterparty's system | Contract, agency and negligence claims | Your organization | Not covered; liability caps typically apply |
The gap is not new — the ruling made it legible. Indemnities written for the copyright wave do not reach the access question. Claim characterizations are illustrative and jurisdiction-dependent.
The $5,000 detail worth knowing
A civil CFAA claim requires the plaintiff to show at least $5,000 in aggregate loss over a one-year period. That threshold is trivially low for any organization that has to investigate an incident, and it is the number that determines whether a counterparty annoyed by your agent has a federal claim or only a contractual one.
It is worth internalizing what that means operationally. An agent that runs continuously against a partner's system, generating support tickets and engineering time on the other side, can manufacture the plaintiff's own damages figure over a few months. The threshold is not a shield. It is a clock.
What this changes on Monday
Not the AI strategy. The paperwork around it, and the inventory underneath.
Four things worth checking this quarter
Inventory outbound agent access, not just inbound.Most AI governance registers list which internal systems an agent can reach. Very few list which external systems it touches, under whose credentials, and against whose terms. That second list is the exposure list.
Read the acceptable-use clause before the indemnity.In several widely used enterprise AI agreements, compliance with third-party terms is assigned to the customer in a clause nobody negotiates, which now does more work than the indemnity everybody negotiated.
Decide your disclosure posture.Amazon's grievance was that the agent did not identify itself. The court did not require it to. That does not mean your partners will not, and a contractual obligation to identify automated access is the kind of term that starts appearing in renewals about six months after a ruling like this.
Give the agent its own identity.Agents operating under a human's credentials make the attribution question worse in both directions — harder to prove what the agent did, and easier for a counterparty to characterize the whole session as your conduct.
The pattern underneath
Every technology that acts on a person's behalf eventually forces a court to decide whether it is a party or an instrument. The answer has almost always been instrument, and the consequence has almost always been the same: responsibility flows back to whoever pointed it.
Enterprises spent 2025 and much of 2026 negotiating AI contracts as though the central risk was the model's provenance. That risk was real, and the indemnities addressed it. The risk that is now maturing is behavioral — what the thing does, in systems you do not control, at a volume no human could produce. The Ninth Circuit did not create that exposure. It just told everyone where it sits.
Sources and notes. Ninth Circuit decision in Amazon v. Perplexity, August 4, 2026, vacating the district court injunction of March 9, 2026; reporting and analysis via client alerts from Cooley, Wilson Sonsini, Ropes & Gray and Ballard Spahr, published the week of August 4. The CFAA's $5,000 aggregate-loss threshold for civil claims is statutory. This article describes a single appellate decision binding in the Ninth Circuit and is journalism, not legal advice — contract and litigation posture should be reviewed with counsel.



