Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Latest AI and industry news. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

News Trending Regulation

You're Liable When Your AI Agent Breaks the Rules

A landmark Ninth Circuit ruling says AI agents are tools, not persons. That shifts legal liability squarely onto the businesses deploying them.

Enterprise DNA | | via Wilson Sonsini Goodrich & Rosati
You're Liable When Your AI Agent Breaks the Rules

A federal appeals court just handed down the first ruling of its kind on AI agents and the law. The takeaway for business owners is simple but important: when your AI agent does something it shouldn’t, you are the one who could face consequences.

What the Court Decided

On August 4, 2026, the US Court of Appeals for the Ninth Circuit issued a decision in Amazon.com Services, LLC v. Perplexity AI that addresses how federal hacking law applies to AI agents operating on behalf of users.

The court’s central holding is that an AI agent is a “tool, not a person” under the Computer Fraud and Abuse Act (CFAA), which prohibits unauthorised access to protected computer systems. The statute references “whoever” accesses a system without authorisation, and the court found that “whoever” means a human being, not software.

In plain terms: an AI agent cannot violate the CFAA because it is not a person. But the person directing it can. The court found that “it was the user who accessed Amazon’s computers, with the help of Perplexity’s AI agent, to carry out specific acts.”

This is the first federal appellate ruling to weigh in on the legal status of agentic AI. The court acknowledged its holding is narrow and that “agentic AI law will doubtless change,” but the current legal reality is clear.

Why This Case Happened

The case stemmed from Amazon’s claim that Perplexity’s AI-powered Comet browser was accessing Amazon’s systems in ways that violated Amazon’s terms of service. The lower court had issued an injunction restricting how Perplexity’s agent could operate. The Ninth Circuit vacated that injunction, reasoning that the agent itself could not be the “person” whose access was unauthorised.

The ruling did not give Perplexity a complete win. It remanded the case for further proceedings and left open the question of whether the human users operating the agent might face CFAA liability.

What This Means for Businesses Using AI Agents

If you are deploying AI agents in your business, this ruling has direct implications for how you should think about risk and accountability.

You own what the agent does. If an AI agent you deploy accesses a competitor’s website in violation of its terms of service, scrapes data it shouldn’t, interacts with a third-party system without proper authorisation, or takes any action that a human actor would be liable for, the liability points back to you. The AI doesn’t absorb the legal risk. Your company does.

Vendor indemnity has limits. Many AI platform agreements include indemnification clauses, but those are written for specific scenarios. A court holding that says the human deployer is responsible for the agent’s actions means your terms of service with an AI vendor may not protect you in the scenarios you most care about.

Agent governance is now a compliance issue, not just an operational one. Businesses that have been slow to put guardrails around their AI agents now have a court ruling that makes the governance gap a legal exposure, not just a risk management talking point.

Terms of service for third-party platforms matter more than ever. If your AI agents access external services, APIs, or data sources, their terms of service are the boundary your agent must respect. Violating those terms is no longer just a technical infraction. It is potentially the act of a human (your business) under the CFAA.

The Broader Governance Gap

This ruling arrives as enterprise AI adoption is accelerating faster than governance frameworks can keep up. A recent survey found that 30% of organisations deploying AI agents in critical workflows have never tested those agents for potential failure modes or out-of-scope behaviour.

That number needs to come down. The Ninth Circuit just made the case that the governance gap is not just an internal risk. It is a legal one.

The court’s reasoning also matters for how AI vendors will position their products going forward. If liability for an agent’s actions flows to the deploying business rather than the AI provider, expect AI vendors to be more explicit about what their agents can and cannot do, and businesses to demand more granular controls over agent behaviour before deployment.

What to Do Now

A ruling like this doesn’t require immediate action, but it is worth adding to your AI governance review. A few practical steps:

  • Audit what your agents can access. Map every external system, API, or data source your AI agents interact with. Confirm your business has the right to access those systems.
  • Review agent permissions. Apply the principle of least privilege. Agents should only have access to what they need to complete their task, nothing more.
  • Document authorisation. If an agent is accessing a third-party system, have a written record of why your business is authorised to do so.
  • Talk to legal. If your business is running production AI agents that interact with external systems, this ruling is worth a conversation with your legal team.

The technology is moving fast. The law is catching up. Businesses that get ahead of the governance curve now will be better positioned as both continue to evolve.


Enterprise DNA helps businesses build and govern AI systems that work. Our Omni advisory service helps leaders understand what responsible AI deployment looks like in practice, not just in theory.

Working With Claude field guide cover

Free Resource

Going deeper with Claude?

Get the free 32-page implementation guide for ANZ teams.

No spam. Unsubscribe any time.