Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA | Electronic Frontier Foundation
Skip to main content
AboutContact
Press
People
Opportunities
IssuesFree Speech
Privacy
Creativity and Innovation
Transparency
International
Security
Artificial Intelligence
Our WorkDeeplinks Blog
Press Releases
Events
Legal Cases
Whitepapers
Podcasts
Annual Reports
Take ActionAction Center
Volunteer
Follow EFF
ToolsPrivacy Badger
Surveillance Self-Defense
Certbot
Atlas of Surveillance
Cover Your Tracks
Street Level Surveillance
apkeep
Shop
DonateDonate to EFF
Shop
Giving Societies
Sponsorships
Other Ways to Give
Membership FAQ
Email updates on news, actions,
and events in your area.
Join EFF Lists
Copyright (CC BY)
Trademark
Privacy Policy
Thanks
Electronic Frontier Foundation
Donate
If you use technology, this fight is yours.Donate today
Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA
DEEPLINKS BLOG
By Andrew Crocker<br>August 4, 2026
Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA
Share It
Share on Mastodon<br>Share on Bluesky<br>Share on Facebook<br>Copy link
The Ninth Circuit Court of Appeals has endorsed a commonsense technical interpretation of the Computer Fraud and Abuse Act (CFAA), a law not usually given to such interpretation. Amazon had sued Perplexity AI to try to shut down its Comet browser, claiming the browser’s optional agentic AI “Assistant” that can browse websites like Amazon for comparison shopping purposes, violated the CFAA because Amazon did not “authorize” Perplexity to access Amazon users’ accounts. Rejecting that theory, the Ninth Circuit held that Perplexity was unlikely to be liable because users operate the tool, not Perplexity.
That’s the right conclusion, as both a legal and technical matter. As we explained to the court in our amicus brief, the CFAA requires unauthorized “access,” and Perplexity itself does not access Amazon’s servers—users of the Comet browser do. The court agreed, noting that EFF’s explanation “articulates the nature of the system most clearly.”
The court noted that agentic AI may present novel legal issues, and there is “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context.” Ultimately, though, thorny questions of AI “intent” were irrelevant to this case, because the Assistant “is a tool, not a person for statutory purposes.” And, the court concluded, it is a tool operated by users, not Perplexity. Even where Perplexity received information from users about their Amazon accounts and used this information to instruct the Assistant, the court found that that did not constitute the sort of control needed to find access by Perplexity. As the court noted, Amazon might have other viable claims against Perplexity, but invoking the CFAA was both legally baseless and bad policy that “could expose users themselves to criminal liability.
This is a gratifying decision because all too often, big players use the CFAA to bully upstarts and innovators who offer potentially helpful user tools. When we counsel clients as part of EFF’s Coders Rights Project, CFAA risk is a frequent topic of conversation, even for developers who merely create tools that allow others to access websites in new or different ways. We’ve stood up for these creators before, and we’ll do it again, but it’s helpful to have back up from one of the most influential appellate courts in the country.
Related Issues
Competition<br>Coders' Rights Project
Related Cases
Facebook v. Power Ventures
Share It
Share on Mastodon<br>Share on Bluesky<br>Share on Facebook<br>Copy link
Related Updates
This year the state of New York had the dubious honor of being the first to pass a controversial provision to mandate all 3D printers come with surveillance and censorship. That means not only is there a ticking clock to protect every artist, researcher, engineer, and hobbyist in the state...
Google owes its existence to the open web, but today, its technological “innovations” have much to do with locking users into a “walled garden.” The latest of these is “reCAPTCHA Mobile Verification,” an experimental initiative that will let companies block users if they are running independent, "de-googled" versions of Android...
Ignoring EFF’s warnings about the dangers and impossibility of implementing a new mandate for 3D print surveillance software, the California State Assembly has signed off on legislation to do just that. In the process, legislators amended the bill to make it even more confusing, while failing to address the risks...
There are now enshittification pins and stickers in the EFF shop, and all proceeds go directly to EFF's work defending digital rights. When someone sees the enshittification emoji, it signals that you understand what's happening to...