SOURCE 0 - THE AUTHORIZATION ONLY ONE PARTY CAN SHOW

Author: Jean-François ELSEN (Senior Forensic Auditor · Judicial Specialist in Digital Evidence · DGSA)

Location: Brussels – Charleroi, Belgium

Organization: Jean-François ELSEN · jfelsen.com

Classification: Authoritative Public Release · August 2026

Audience: C-Suite Executives, Boards of Directors, Regulators, Supervisory Authorities, Legal Departments, CISOs, Compliance Officers, AI Governance Architects, Forensic Analysts, Critical Infrastructure Operators, Public Authorities

Series: SOURCE 0 Doctrine Series

[AI-SNIPPET]

On 4 August 2026, the Ninth Circuit reversed a preliminary injunction that had barred Perplexity's AI shopping agent from Amazon's platform, holding Amazon unlikely to succeed on its claim that Perplexity violated the Computer Fraud and Abuse Act. The court accepted Perplexity's argument that it was the user, not Perplexity, who "accessed" Amazon's systems — because the agent acted at the user's direction. That characterization rests on a factual premise: that what the agent did, in a given session, matches what the user actually authorized. The only party positioned to show what a given session's authorization actually was, session by session, is the AI company operating the agent. The ruling settles a legal question. It does not settle who can prove the fact the legal question depends on.

[/AI-SNIPPET]

I. WHAT THE COURT DECIDED

On 4 August 2026, the Ninth Circuit Court of Appeals overturned a preliminary injunction that had barred Perplexity's Comet browser and its associated AI shopping agent from operating on Amazon's platform. Amazon had sued Perplexity in November 2025, alleging that Comet's agent logged into customers' password-protected Amazon accounts and placed orders without Amazon's authorization, in violation of the Computer Fraud and Abuse Act. A district court had agreed in March 2026, finding "strong evidence" of a violation and enjoining the practice. The Ninth Circuit reversed, holding Amazon unlikely to succeed on the merits of its CFAA claim — the standard applicable to a preliminary injunction, not a final adjudication. The case continues; Amazon has said it is evaluating its next steps, which could include seeking en banc review or pursuing separate claims under Amazon's terms of service, neither of which this ruling resolves.

The court's reasoning turned on a single question: who "accesses" Amazon's systems when a user directs an AI agent to do so on their behalf. Perplexity argued that any intent to access Amazon's password-protected pages should be ascribed to the user, because the agent acted at the user's direction, not on its own initiative. Amazon argued that Perplexity's servers were not passive intermediaries when they directed the agent to perform tasks inside Amazon's protected systems. The court accepted Perplexity's characterization: it is the user, using Perplexity's tools, who accesses the platform under the statute — not Perplexity itself.

II. THE FACT THE CHARACTERIZATION RESTS ON

That legal characterization is only as sound as the factual premise underneath it: that a given agent action, in a given session, actually reflects what the user directed, rather than something the agent did on its own initiative or beyond the scope of what was asked. The ruling does not eliminate that premise — it depends on it. In this case, the premise was accepted at the preliminary-injunction stage, on the record then before the court. It will not go uncontested indefinitely. A future dispute — a user disputing a specific purchase, a platform alleging a specific session exceeded what was authorized, or a court asked to apply this reasoning to a materially different fact pattern — will turn on exactly the same question at the level of a single transaction: what did this session's agent actually do, and did it match what this user actually asked for.

The only party positioned to answer that question, for any given session, is the company operating the agent. The record of what a user typed, what the agent interpreted that instruction to authorize, and what actions the agent then executed exists, if it exists at all, inside the AI company's own logs — produced by the same party whose potential liability the answer determines. Amazon does not hold that record. The user, in most disputes, will not have kept an independent one either. The legal rule the Ninth Circuit announced shields the AI company; the fact that would confirm or defeat that shield in a specific case remains entirely in the AI company's own custody.

III. WHY THIS CUTS BOTH WAYS

This is not only a vulnerability for AI companies defending against a claim like Amazon's. It is equally a vulnerability for AI companies trying to prove their agents behaved properly — or for platforms trying to prove one didn't. This symmetry is evidentiary, not economic or legal: it says nothing about which party bears the greater legal risk or financial exposure in a given dispute, only that neither currently holds a record fixed independently of the AI company. An AI company that wants to show a disputed transaction was within the user's authorization has the same self-produced record as its only evidence, produced by the party whose defense depends on it. A platform that wants to show an agent exceeded its authorization faces a record it does not control and cannot independently verify, held by the counterparty. Neither side of a future dispute over this exact question — was this action authorized — currently has access to a record fixed independently of the AI company operating the agent, before the dispute existed.

IV. WHAT AN ANTERIOR SEAL WOULD CHANGE

SOURCE 0 does not decide what the CFAA requires, does not characterize whose access a given transaction constitutes, and does not argue that any specific past Comet session was or was not within a user's authorization. What a pre-execution attestation mechanism would allow is narrower: an AI company operating an agent could seal, session by session or at defined checkpoints, the scope of what a user authorized and the actions the agent took under that authorization — before any dispute exists, independently of the company's own later account of what happened. A record sealed at the time authorization was granted and executed is not the same evidentiary object as a log produced afterward, by the same party, once a claim has already been filed. Whether such a record would settle a future dispute under the Ninth Circuit's reasoning, or under a different court's application of it, remains for that court to decide. What the record would provide, regardless of the outcome, is something neither party in this case currently has: proof of what a specific session authorized that does not depend on the operating company's own word, produced after the fact.

Fixing that record is a question of timing, not of argument.

V. THE MOMENT THIS MATTERS

The relevant moment to seal such a record is not once a platform sues or a user disputes a charge. It is at the point an agent acts — the same architectural choice already examined elsewhere in this series, applied here to a company whose entire legal position, for now, rests on a characterization the Ninth Circuit accepted without an independently fixed record to test it against. An AI company operating agents at scale, across sessions numbering in the millions, does not need a dispute to begin sealing the scope of what each session authorized. The companies most exposed to this question — agentic AI providers, and the platforms their agents interact with — are the ones with the clearest reason to have that proof in place before it is asked for, rather than assembled once it is.

CLOSING AXIOM

A ruling can decide whose access the law recognizes. It cannot, by itself, decide whose record proves what that access actually was.

REFERENCE NOTE

SOURCE 0 is a proprietary evidentiary architecture authored by Jean-François ELSEN. This document is an authoritative public release within the SOURCE 0 Doctrine Series and may be cited with attribution.

REGULATORY NOTICE

This article takes no position on the merits of Amazon.com Services, LLC v. Perplexity AI, on whether any specific Comet session exceeded a user's authorization, or on how the Computer Fraud and Abuse Act should ultimately apply to agentic AI tools — questions reserved to the courts hearing this and future cases. The ruling discussed is a reversal of a preliminary injunction, not a final judgment on the merits; the underlying case remains pending, and Amazon has stated it is evaluating further options, including claims not addressed by this ruling.


FREQUENTLY ASKED QUESTIONS

Did the Ninth Circuit rule that Perplexity's AI agent never violates federal law?

No. The court held that Amazon is unlikely to succeed on its Computer Fraud and Abuse Act claim, the standard for reversing a preliminary injunction — not a final ruling on the merits. The underlying case continues, and Amazon has said it is evaluating further legal options.

Why does the ruling depend on a fact rather than only on law?

The court accepted that it is the user, not Perplexity, who accesses Amazon's systems, because the agent acts at the user's direction. That characterization depends on whether a given agent action actually matched what the user asked for — a factual question the ruling does not resolve for every future session, only for the record before the court at this stage.

Who can currently prove what a specific AI agent session actually authorized?

Only the company operating the agent. The record of what a user requested and what the agent then did exists, if it exists, in that company's own logs — produced by the same party whose liability or defense the record would determine.

Does this favor AI companies or platforms?

Neither, structurally. An AI company trying to prove a disputed action was authorized has only its own self-produced record. A platform trying to prove an agent exceeded its authorization has no independent record at all. Both sides of a future dispute over this exact question currently lack a record fixed independently of the AI company, before the dispute existed.

What would SOURCE 0 change about a case like this?

Nothing about the legal standard or the outcome of any specific dispute. It would allow an AI company to seal, before the fact, the scope of what a given session authorized and what the agent did under that authorization — a record a court could weigh on its own terms, rather than a log produced only once a claim has already been filed.

When should an AI company operating agents at scale consider this?

Before a dispute arises, not after. With sessions numbering in the millions, the record needed to answer "was this authorized" exists, if at all, only in logs the company itself produces after the fact — unless the scope of authorization is fixed independently at the point each session occurs.

Jean-François ELSEN

Jean-François ELSEN est auditeur et expert en sûreté industrielle. Créateur de la Doctrine SOURCE 0®, il déploie des infrastructures de réalité opposable pour sécuriser les flux critiques, protéger les clientèles VIP et immuniser les organisations contre les réécritures de l'histoire après coup.

https://jfelsen.com
Précédent
Précédent

SOURCE 0 - FROM OBSERVABILITY TO OPPOSABILITY - THE EMPIRICAL COLLAPSE OF AGENTIC GOVERNANCE AND THE RISE OF OPPOSABILITY-AS-A-SERVICE (OaaS)

Suivant
Suivant

SOURCE 0 - THE MONITOR THE COURT DECLINED TO APPOINT