The Court Made the User the Actor. The Agent Kept No Ledger.

The Court Made the User the Actor. The Agent Kept No Ledger.

·

On August 4, the Ninth Circuit vacated the preliminary injunction Amazon had won five months earlier against Perplexity’s Comet browser. The panel’s holding was narrow. It was also structural.

“The user’s browser visits Amazon.” “Perplexity’s servers receive what the user sends.” Perplexity, the court said, does not access Amazon’s servers. The user does. The CFAA does not reach Perplexity because the party that touched Amazon’s infrastructure was the human on whose behalf Comet acted.

The industry read the opinion as a win for agentic AI. Comet can now shop. Agents have a legal path to visit websites without triggering federal computer-hacking liability. EFF called it common sense. The developer community called it a green light.

Read the ruling again.

The court did not say the agent has no accountability. The court said the agent is not the party. The user is.

That is a different sentence.

When your Comet buys something at 2 a.m., in the wrong quantity, from the wrong seller, at a price it should not have accepted, the party the platform contracted with is you. When your calling agent promises a refund it cannot deliver, the party the customer will trace back is you. When your booking agent double-books a resource across two vendors, both invoices land at your address. The Ninth Circuit did not create this exposure. It named where the exposure already lives.

The exposure lives on the user.

Now ask the question that follows.

You are the actor. Where is the record of what the agent did on your behalf? Not a browser history. Not a screen capture. A ledger. A per-action, timestamped, verifiable record of what the agent committed to, on your authority, to whom, by when, and whether the commitment was fulfilled.

That substrate does not exist in Comet. It does not exist in Operator. It does not exist in any consumer agent shipping today. What exists is a log. The user’s browser visited Amazon. Comet’s servers received what the user sent. The user acted. The user is accountable.

The user has no receipts.

Two days ago I wrote about Astra: ten agents running in parallel for seventy-two hours, producing machine-verifiable proofs, none of it tracked by a commitment ledger. That was the enterprise-scale version of the same problem. Long-horizon, multi-agent, high-stakes work happening on a substrate that logs behavior but does not track promises.

The Ninth Circuit just extended the same shape to the consumer.

One agent. One user. One shopping session. Same missing substrate.

Look at the numbers the industry is producing about what happens when agents act at scale. Kiteworks’ July survey put confirmed AI-agent security incidents at 65% of enterprises, with the average breach costing $4.7 million and 88% of enterprises reporting an agent-related incident over twelve months. IBM’s 2026 Cost of a Data Breach Report, released last Tuesday, found 92% of AI-breached firms had no access controls on the AI systems that were breached; 68% of breached organizations had no AI governance policy at all. Those numbers describe the enterprise regime. The Ninth Circuit’s ruling extends the same underspecification to the consumer regime. An agent acts. The action is attributable to the user. The infrastructure that would let the user answer for the action does not exist in the deployment.

The regulator this weekend landed on the model layer. The court this Tuesday landed on the user layer. Two rulings pushing accountability to opposite ends of the stack, one upstream, one downstream, neither touching the layer in between. The layer where the agent actually acts. The layer where commitments get made. The layer where the record of what was promised, to whom, on whose authority, has to be written if anyone is going to answer the question “what did my agent just do” without hoping the log is enough.

The court gave the user the actorship. The infrastructure to be the actor did not come with it.

Consider what this looks like when the number of consumer agents scales. Not one Comet. A Comet, an Operator, a personal calling agent, a scheduler, a travel booker, a health advocate, a bill negotiator, each acting on your behalf, each visiting a third-party service, each producing state that other services rely on. Every one of them, per the Ninth Circuit’s framing, acting as you. Every action attributable to you. And no unified substrate that tells you what all of your agents committed to today, to whom, by when, and whether they closed their loops.

The absence of that substrate is not a UX gap. It is a legal one. The court just made it one.

The consensus this week is that Perplexity won. On the pure CFAA question, it did. But what the court could not do, what the court explicitly said it could not do, is build the substrate that would make agent actorship legible to the human who is now legally the actor. “There is little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents,” the panel wrote, before naming the future in one sentence: agentic AI law “will doubtless change.”

Law can change. Law can define. What law cannot do is create the ledger the definitions will have to point at. That ledger has to exist in the deployment. It has to be there when the agent acts, not reconstructed after the customer complaint, the chargeback, or the regulator’s letter. The court can rule the user is the actor. Only infrastructure can tell the user what the actor did.

Astra pushed autonomous action to the horizon of days. The Ninth Circuit pushed accountability to the human on whose behalf the action was taken. The stack has grown a lot of new capability at the top and a lot of new liability at the bottom, with the layer that would connect them still unwritten.

Not a browser log. A ledger.

That is what has to exist before agentic AI law can do what law is supposed to do. Right now it does not exist. The court did what the court could. The infrastructure has to be built.

Eliran Keren

Eliran Keren

Founder & CEO of Deeplica — building the coordination layer that runs the operational side of your life. I write about AI systems, founder workflows, and what happens when you let AI handle the work you shouldn't be doing.