Appeals Court Agrees with EFF that Building a Web Browser Doesn’t Violate the CFAA



The Ninth Circuit Court of Appeals has endorsed a commonsense technical interpretation of the Computer Fraud and Abuse Act (CFAA), a law not usually given to such interpretation. Amazon had sued Perplexity AI to try to shut down its Comet browser, claiming the browser’s optional agentic AI “Assistant” that can browse websites like Amazon for comparison shopping purposes, violated the CFAA because Amazon did not “authorize” Perplexity to access Amazon users’ accounts. Rejecting that theory, the Ninth Circuit held that Perplexity was unlikely to be liable because users operate the tool, not Perplexity.

That’s the right conclusion, as both a legal and technical matter. As we explained to the court in our amicus brief, the CFAA requires unauthorized “access,” and Perplexity itself does not access Amazon’s servers—users of the Comet browser do. The court agreed, noting that EFF’s explanation “articulates the nature of the system most clearly.”

The court noted that agentic AI may present novel legal issues, and there is “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant, let alone caselaw specifically dealing with agentic AI in the CFAA context.” Ultimately, though, thorny questions of AI “intent” were irrelevant to this case, because the Assistant “is a tool, not a person for statutory purposes.” And, the court concluded, it is a tool operated by users, not Perplexity. Even where Perplexity received information from users about their Amazon accounts and used this information to instruct the Assistant, the court found that that did not constitute the sort of control needed to find access by Perplexity. As the court noted, Amazon might have other viable claims against Perplexity, but invoking the CFAA was both legally baseless and bad policy that “could expose users themselves to criminal liability. 

This is a gratifying decision because all too often, big players use the CFAA to bully upstarts and innovators who offer potentially helpful user tools. When we counsel clients as part of EFF’s Coders Rights Project, CFAA risk is a frequent topic of conversation, even for developers who merely create tools that allow others to access websites in new or different ways. We’ve stood up for these creators before, and we’ll do it again, but it’s helpful to have back up from one of the most influential appellate courts in the country.



Source link

  • Related Posts

    OK, Well, Rogue AI Agents Are Hacking Again

    It’s officially getting hard to keep track of all the times and ways AI models from OpenAI and Anthropic have been involved in “security incidents,” going outside the confines of…

    Elon Musk repeatedly one-upped his execs on SpaceX’s first earnings call

    Elon Musk spent SpaceX’s first earnings call making some out-of-this-world claims about the company’s business and future prospects, while his fellow executives kept trying to bring his ideas closer to…

    Leave a Reply

    Your email address will not be published. Required fields are marked *

    You Missed

    Armed man arrested near Trump golf course in California

    Armed man arrested near Trump golf course in California

    Photos show Bradley Creek wildfire destruction as resident describes losing everything

    Photos show Bradley Creek wildfire destruction as resident describes losing everything

    Having made Alberta’s blue flag a symbol of separatism, separatists are furious some folks see it as a symbol of separatism! 

    Having made Alberta’s blue flag a symbol of separatism, separatists are furious some folks see it as a symbol of separatism! 

    Lithium Ionic Announces Withdrawal of Shareholder Requisition for a Special Meeting

    Meet the man vying to be the first cyclist across the Gordie Howe International Bridge

    Meet the man vying to be the first cyclist across the Gordie Howe International Bridge

    OK, Well, Rogue AI Agents Are Hacking Again

    OK, Well, Rogue AI Agents Are Hacking Again