Restricted analysis, made public daily.
Declassified under standing order Edition No. 035 Friday, August 7, 2026

A Tool, Not a Person.
You Don’t Get That Option.

Vacating a preliminary injunction Tuesday, the Ninth Circuit held that when a user sends Perplexity’s shopping agent into their own password-protected Amazon account, it is the user, not the machine, who “accesses” Amazon’s computers. The agent is “a tool, not a person for statutory purposes”; its acts fold into the human who directed them, and the case returns to the district court. From your side of the ledger, a machine’s identity was just shown collapsible the moment it would carry consequences. Yours is weighed every time an engine decides who acted. The asymmetry runs one way.

On Tuesday, August 4th, the United States Court of Appeals for the Ninth Circuit published a precedential answer to a question with little to no caselaw behind it: when an AI agent does something, who did it? Amazon had won a preliminary injunction against Perplexity’s Comet Assistant, the shopping agent that operates inside a user’s password-protected Amazon account. The Ninth Circuit vacated it. The Computer Fraud and Abuse Act, the court reasoned, punishes “[w]hoever . . . intentionally accesses” a protected computer. Whoever means a person. “However advanced the Assistant currently is, it is a tool, not a person for statutory purposes.” The user accessed Amazon. On this record, the statute never reached the machine.

The record behind that sentence is worth reading closely. Comet is Perplexity’s AI-enabled browser; its differentiating feature is an optional agent, the Assistant, which “can perform tasks at the user’s direction, such as browsing websites like Amazon.com to shop for requested goods.” The Assistant cannot act alone: it screenshots the user’s browser, sends the images to Perplexity’s servers, and receives navigation instructions back. Amazon told Perplexity twice, before Comet launched and again after, that its AI products were not authorized in the Amazon Store. At the core of the dispute, in the opinion’s own words, was Perplexity’s decision not to use a “user-agent string,” the mechanism “that would communicate that the user has activated an AI agent.” A name tag exists for machines. The opinion records a choice not to wear it. The district court found the question close and enjoined Perplexity anyway; the appeals court took the injunction away.

Notice what the court had to do to get there. It noted “little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant.” On the statute’s plain text, it consulted the definition of “whoever,” then an English dictionary. It applied the rule of lenity, construing ambiguity against liability. And it landed here: “It is the user who ‘accesses’ Amazon’s computers, with the help of the Assistant to carry out specific acts on Amazon.com.” Every act the machine performed folded backward into the human who sent it. The court was careful about scope, and this edition will be too: “We do not establish a new legal regime governing agentic AI.” One statute, one word, one record. But watch which way identity flowed the first time a federal appellate court was forced to choose.

The court needed twenty-one pages to settle who acted when a machine acted. The systems reading your market settle the same question in milliseconds, and nothing in them is obliged to trace the act to you.

Where identity goes when the law must choose

Put this ruling beside the two statutes this record read in the past week and the architecture becomes visible. Europe now requires the machine to say what it is: the obligation Edition No. 031 read closely. California now requires it to prove what it made, the provenance layer Edition No. 034 documented yesterday. And when the question was who acted, a federal appellate court ruled the machine need not be anyone at all for the statute’s purposes: on that record, its acts belong to the person who directed it. Disclosure, provenance, personhood. Three fights over machine identity inside one week. Twice the law bound the machines to identify what they are; the third time it let one dissolve into its user. Not one of the three built anything that identifies you. The machines’ obligations are narrow and mechanical. The human’s are total.

Here is the asymmetry that matters to your practice. When the Assistant acted, ambiguity resolved into somebody: a court traced the act backward until it found a person to hold it. When an answer engine reads your market, ambiguity resolves the other way. The matter your firm won under a group byline, the quote circulating with your name sanded off, the twenty-year record scattered across profiles no system connects. No tribunal traces those acts back to you, and nothing in the architecture is obligated to.

Clinical note — Authority Misclassification, mirrored in law

The first clinical characteristic of Digital Derangement Syndrome, Authority Misclassification, describes a system that cannot confidently associate an entity with its expertise. This record’s prior instances show engines failing to classify real authority. Edition No. 035 documents the legal mirror: a court resolving the who-acted question by dissolving the machine actor entirely, entity resolution running in reverse, deliberately, toward the human. The mirroring is directional, not an accusation of error: the court applied its statute with care, and nothing in that care extends to the inferences that answer for you.

Untreated, the asymmetry compounds with adoption. This publication expects agents to transact more, not less; the ruling, meanwhile, stands while the case continues below. Every transaction in which the machine may lawfully be nobody is a transaction in which the humans on both ends must be legibly somebody: the seller who needs to be found, and the principal whose agent is out doing the finding. The recognition load is migrating to the human side of every exchange.

Named for the record. Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026), for publication: preliminary injunction vacated; Amazon unlikely to succeed on the CFAA’s “access” element; the state-law conclusion parallel. The court expressly declined to establish a broader agentic-AI regime, and its holding is limited to the record before it. The parties dispute certain facts the court did not resolve; this edition takes no position on them. The reading of where identity flows is this publication’s, not the court’s.

What this means if you never send a machine shopping

You could run your practice for thirty years and never touch an agent, and this ruling still redraws the map under your practice. Agentic commerce now operates alongside a federal appellate ruling that, on this record, the agent’s access folds into its user’s: a narrow statutory holding, not a general regime. The infrastructure being built for machine identity (disclosure statutes, provenance layers, dictionaries consulted on personhood) keeps resolving that identity into whatever is most convenient for the machine. Nobody is building the corresponding infrastructure for you. No statute makes your record legible. No court traces uncredited work back to its author. The real thing still has no verifier, and as of Tuesday the machine doesn’t even need a name. That side of the ledger has been voluntary the whole time.

Which is the actual assignment. Identity Architecture exists because the who-acted question is asked about you daily, in milliseconds, without a courtroom, and the default answer is inference. Answer Engine Authority installs what no law requires, and four of its six phases answer the question the court needed a dictionary for: entity architecture that settles who stands behind the work, signal consolidation that gathers it into one legible body, third-party corroboration that lets other voices confirm it, and ongoing signal maintenance that keeps the record current. The Ninth Circuit needed a statutory definition and a dictionary to decide who “whoever” is. For your market, whoever is a question of record, and the record is the one thing you control. Install the answer before an engine improvises one.

Sources

Amazon.com Services, LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. Aug. 4, 2026), designated for publication; appeal from the Northern District of California, Judge Maxine M. Chesney presiding (D.C. No. 3:25-cv-09514-MMC). Opinion by Judge Milan D. Smith, Jr., joined by Judge Eric C. Tung and District Judge John Charles Hinderaker, sitting by designation; argued June 11, 2026, in Seattle. All quotations in this edition (the tool-not-a-person holding, the Comet and user-agent descriptions, the caselaw observation, the user-accesses conclusion, and the limiting language) are read directly from the slip opinion at cdn.ca9.uscourts.gov.

Scope notes. The holding addresses the “access” element of the Computer Fraud and Abuse Act and California’s Comprehensive Computer Data Access and Fraud Act on a preliminary-injunction record; the court states that it does “not establish a new legal regime governing agentic AI” and that the outcome “does not impair Amazon’s ability to regulate access to Amazon.com via private terms of service for its users.” The opinion expressly leaves liability in other contexts, including tort claims, unaddressed, and the vacatur also rests on the court’s independent holding that the remaining preliminary-injunction factors favored Perplexity. The parties dispute whether the Assistant’s user-agent string was knowingly altered after Amazon began blocking it; the court did not resolve that question and this edition does not characterize it. The case returns to the district court, where litigation continues.

The machine is allowed to be no one —
you are required to be someone.

Answer engines settle the who-acted question about your market every day, without a docket, and in Agentics’ reading their default is inference. The Encoded Authority Diagnostic reads your record the way the engines do (what is provable, what is inferred, what is missing) before ambiguity resolves against you. Or bring the question to SIA — the Intelligence Officer, briefed on every edition

of this record the morning it releases.

Every edition, in order, from No. 001 · A new edition releases daily, 05:30 CT.

Open the Record
‹ Edition No. 034 Next Dispatch — releases 05:30 CT ›