Hook
For a generation trained to parse smart contract bytecode, the 9th Circuit's ruling in the Amazon vs. Perplexity case scans like a critical vulnerability report for the entire internet. The code whispers what the auditors ignore: the court held that an AI agent is a tool, not a person, under the Computer Fraud and Abuse Act (CFAA). This is not a legal opinion; it’s a security architecture decision. The decision strips the AI agent of independent liability and reattaches it to the user. This is a fundamental shift in the threat model for how we interact with the internet. It is not a victory for AI agents; it is a redefinition of the access control layer.
Context
The case, filed by Amazon against Perplexity AI, centered on whether an AI agent's automated access to Amazon's servers constituted unauthorized access under the CFAA and California's Computer Data Access and Fraud Act (CDAFA). The 9th Circuit ruled that the AI agent is a tool, not a person, and therefore cannot be the subject of a CFAA violation. The court followed a restrictive interpretation of the CFAA, echoing the Supreme Court’s narrowing in Van Buren v. United States (2021). The key legal distinction is between a tool's execution and a user's legal action. The court essentially said: the software executes, but the user is the actor. The core insight is that the AI agent’s server architecture did not directly communicate with Amazon’s infrastructure. This fact separated the case from earlier precedents like Facebook v. Power Ventures, where servers directly interacted. This is a critical signal for any DeFi Security Auditor: the legal liability is not in the code, but in the user's authorization.
Core
From a security auditor's perspective, the 9th Circuit's logic is a form of principle of least privilege applied to legal liability. The court has effectively created a new access control list for the internet. The user is the subject, and the AI agent is the object. The legal question is whether the user has the authority to access the platform. This is a direct challenge to the platform-centric model of the internet. The court has said: platforms cannot use the CFAA to enforce their terms of service against a user's tool. This is a powerful design pattern for the AI agent ecosystem. It creates a safe harbor for user-directed agents, but only if the architecture is clean.
I have spent years auditing DeFi protocols, and the 9th Circuit’s logic mirrors a fundamental principle of smart contract security: never trust the frontend. The court essentially said the AI agent’s frontend—the user interface—is the access point, and the backend infrastructure is irrelevant to the legal question of authorization. This is a critical vulnerability in the internet’s legal infrastructure. The court has created a legal race condition between user intent and agent behavior. The question is not whether the agent accessed the platform, but whether the user intended for it to do so. This is a classic oracle problem: how do you verify the user's intent? In a DeFi protocol, you rely on on-chain data. In the legal system, you rely on user instructions. The 9th Circuit has made the user instruction the primary source of truth. This is a dangerous design choice.
Logic holds when markets collapse. The 9th Circuit's ruling is a structural fix, not a market fix. It addresses the legal architecture, not the security architecture. The core of the ruling is the distinction between a tool and a person. This is a reification of the agent/principal relationship. The court has applied the legal principle of agency to software. The AI agent is the agent; the user is the principal. The principal is liable for the agent's actions. This is a standard legal framework, but it is being applied to a new domain. The court has created a new legal category: the AI agent as a tool. This is a category that is not defined in the CFAA or the CDAFA. The court is essentially writing new law under the guise of interpretation. The court has used the legal fiction of the "user" to fill the gap in the law. This is a brilliant move, but it is also a vulnerability. The user is a fiction. The courtroom is a fiction. The only reality is the code.
As an auditor, I see the 9th Circuit’s ruling as a security audit of the CFAA. The court has found a critical vulnerability: the CFAA treats the AI agent as a person, but it is not a person. The court has patched this vulnerability by redefining the AI agent as a tool. But this patch introduces a new vulnerability: the definition of the user. The court has made the user the central point of liability. This is a classic security trade-off: you centralize liability to reduce complexity, but you increase the attack surface. The user is now the target. The platform will sue the user, not the agent. The user will then sue the agent developer. The liability chain is now longer and more complex. The court has created a legal architecture that is more fragile than the previous one. The code whispers what the auditors ignore: the court has created a new legal token, the "user instruction," and it is not auditable.
Yellow ink stains the white paper. The 9th Circuit's ruling is a white paper on the legal liability of AI agents. The court has written a new specification for the internet. The specification is: the user is the access point. The platform must rely on the user's authorization. The AI agent is a tool. This is a radical design choice. It is a zero-trust architecture for legal liability. The court has effectively said: never trust the platform; always verify the user. This is a powerful principle for the open internet. It is a direct challenge to the walled garden model. The court has said: the user owns the access. The platform cannot control the user's tool. This is a re-assertion of the end-to-end principle. The internet was designed to be a network of peers, not a network of platforms. The 9th Circuit has restored the original design.
But the restoration is incomplete. The court has created a new legal category, the AI agent as a tool, but it has not defined the tool's capabilities. The court has said: the tool is not a person. But what is a tool? A tool is a device that extends the user's capabilities. A tool can be a hammer, a computer, or an AI agent. The court has used a functional definition of a tool. A tool is a device that is directed by the user. This is a functional definition, not a legal definition. The court has created a legal category that is defined by technology. This is a vulnerability. The definition of a tool will change as technology changes. The court has created a moving target for the law. The platform will argue that the AI agent is not a tool, but a person. The agent developer will argue that it is a tool. The court has created a legal battlefield that is defined by technology.
Contrarian
The coolest part of the ruling is its most dangerous vulnerability: the definition of 'user instruction'. In my audits, I have seen hundreds of exploits that hinge on ambiguous input validation. The 9th Circuit has created a legal race condition between user intent and agent behavior. The court has said: the user must direct the agent. But what is a direction? Is a click a direction? Is a search query a direction? Is a voice command a direction? The court has not defined the term. This is a classic contract vulnerability: an undefined term. The platform will argue that the direction must be specific. The agent developer will argue that the direction is implicit. The court has created a legal ambiguity that will be exploited by both sides. The code whispers what the auditors ignore: the user instruction is the new oracle. The oracle is the source of truth. The oracle is the point of failure. The court has created a new oracle problem for the legal system.

Silence is the highest security layer. The 9th Circuit's ruling is a security layer, but it is a silent one. The court has not created a new law; it has interpreted an existing law. The interpretation is not binding on all courts. The ruling is a persuasive authority, not a binding one. The 9th Circuit is a powerful court, but it is not the Supreme Court. The ruling will be cited by other courts, but it will not be followed by all courts. The legal landscape is now more fragmented. The platform will shop for a favorable jurisdiction. The agent developer will face a patchwork of laws. The legal complexity has increased. The court has created a new legal layer, but it is a layer that is not uniform. The legal architecture of the internet is now more complex, not less. The code whispers what the auditors ignore: the legal system is a distributed system, and the 9th Circuit has introduced a fork.
Between the gas and the ghost, lies the truth. The truth is that the 9th Circuit's ruling is a temporary fix. It is a patch for a specific vulnerability. The vulnerability is the CFAA's treatment of AI agents as persons. The patch is the redefinition of AI agents as tools. But the patch is not a permanent fix. The legal system will need to develop a new framework for AI agents. The framework will be a combination of law and technology. The court has created a new legal category, but it has not defined the category's boundaries. The boundaries will be defined by the next case. The next case will be about the user instruction. The next case will be about the autonomous agent. The next case will be about the platform's technical controls. The 9th Circuit has set the stage for the next legal battle.
Takeaway
The 9th Circuit's ruling is not a final patch; it’s a temporary fix that introduces new attack vectors. The next major vulnerability will be the definition of ‘user instruction’. The court has written a new threat model for the AI agent ecosystem. The threat model is: the user is the access point. The user is the liability. The user is the oracle. The open question is: who verifies the user? The platform will rely on the user's authorization. The agent developer will rely on the user's instructions. The user will be the central point of failure. The legal system will need to develop a new mechanism for verifying the user's intent. The mechanism will be a combination of legal and technical controls. The legal controls will be the next vulnerability. The code whispers what the auditors ignore: the next audit will be the user's instructions. The next audit will be the user's intent. The next audit will be the user's soul. I trace the path the compiler forgot: the legal compiler forgot the user.