Agentic browsing just won its first appeal
For two years the answer to automated visitors was a wall, and agentic browsing was the thing on the far side of it. On 4 August a US appeals court took a brick out of it, and the network layer quietly stopped asking whether the visitor was human at all.
By Katie Delaney · 2026-08-11 · 12 min read
What the court actually held about agentic browsing#

On 4 August 2026 the United States Court of Appeals for the Ninth Circuit vacated the injunction Amazon had won against Perplexity, and the reasoning matters far more than the result. The panel's own words, in Amazon.com Services LLC v Perplexity AI, No. 26-1444: "the user (not Perplexity) accessed Amazon using the Assistant as an AI tool".
That single clause is the whole story of agentic browsing. The Computer Fraud and Abuse Act punishes whoever intentionally accesses a computer without authorisation. Judge Milan D. Smith, Jr. wrote that the statute contemplates access by a person, and that "However advanced the Assistant currently is, it is a tool, not a person for statutory purposes." A tool cannot trespass. The hand holding it can. Agentic browsing, on this reading, is a person on a trail, not a machine at a gate.
The panel was candid about how new this ground is, noting there is "little to no existing caselaw directly dealing with how to ascribe responsibility for AI agents like the Assistant". It reached for the rule of lenity, construing an ambiguous criminal statute against liability, and found that an injunction against conduct that likely breaks neither the federal nor the Californian statute "would not serve the public interest".
However advanced the Assistant currently is, it is a tool, not a person for statutory purposes.
The narrowness is the point#
Read the caveats or you will overreach. The opinion is preliminary, it vacates an injunction rather than deciding the case, and it says nothing about tort claims or contract. Cooley's client note of 6 August reads the practical consequence plainly: sites cannot lean on anti-hacking statutes to police agent access, and the routes that remain are terms of service, contract and tort. That is a slower, costlier hedgerow than a firewall rule, and agentic browsing is exactly the traffic it now has to hold back.
Eric Goldman, writing on 6 August, put the discomfort better than any vendor blog managed: "Amazon clearly expressed its preferences that it didn't want Perplexity's users to access its services through agentic AI, and why shouldn't the law back up these strong and clear desires?" His answer, and the court's, is that stretching a criminal hacking statute to cover it costs more than it buys, and it shifts exposure onto the user rather than removing it.
The vendors wrote that holding into their own docs first#
Here is the quiet part of the agentic browsing story. The court reached its distinction in August 2026. The AI vendors had already written the same distinction into their own crawler documentation, and almost nobody in the trade press has put the two side by side.
Every major assistant now runs at least two kinds of fetcher. One is a crawler that harvests at scale on the vendor's schedule. The other fires only because a person asked a question a moment ago. The vendors do not treat those as the same animal, and their published rules say so in terms a lawyer would recognise.
| Vendor | User-triggered agent | What the vendor's own doc says | Training crawler |
|---|---|---|---|
| OpenAI | ChatGPT-User | "Because these actions are initiated by a user, robots.txt rules may not apply." | GPTBot |
| Perplexity | Perplexity-User | "Since a user requested the fetch, this fetcher generally ignores robots.txt rules." | PerplexityBot |
| Anthropic | Claude-User | Documented as respecting robots.txt directives, with blocking by user agent supported | ClaudeBot |
Read the OpenAI line again. In OpenAI's bot documentation, ChatGPT-User is described as not being used to crawl the web in an automatic fashion, and the robots.txt carve-out follows directly from that. Perplexity's documentation is blunter still about Perplexity-User. Anthropic's crawler page takes the stricter line, documenting Claude-User as respecting robots.txt and offering per-agent blocking.
So the industry's own paperwork already said what the Ninth Circuit has now said in law: a fetch a human asked for is that human's fetch. If your access policy for agentic browsing was built on the assumption that everything non-human is one category, it was already out of date before the ruling landed. The distinction between ai crawlers and user-summoned agents is not pedantry. It is the whole map.
While the lawyers argued, the network layer moved#
Three days after the ruling, Cloudflare published a post that abandons the human-or-bot question altogether, which is the practical answer to agentic browsing that most sites still lack. Its framing is that a single session now slides from human to agentic and back again, and that the suspicious part usually shows up mid-session rather than at the door. A verdict taken once, at entry, is a verdict taken at the wrong moment.
Two products carry that shift. BotBase classifies actors by use case and intent rather than sorting them into good and bad, and can withdraw trust from an actor that abuses it. Precursor watches continuously on the client side instead of judging once. The scale is published: in a single 24-hour window, Cloudflare reported 206 million Precursor evaluation events across 73,438 zones.
Precursor evaluation events, 24 hours
Cloudflare, 7 Aug 2026
Zones covered in that window
Continuous, not single-point
Reference inputs per generated TikTok ad
Up from 9, 3 Aug 2026
Agent-callable, not merely agent-readable#
On 6 August the same company shipped the other half. WebMCP is a browser standard shipping experimentally in Chrome 146 that surfaces in the page as document.modelContext. Cloudflare will inject it from a dashboard toggle under Agent Readiness, with no code change and no deployment, so an agent calls a declared tool instead of guessing its way through a layout built for eyes.
The engineering restraint is worth noting: in this preview every tool runs in the visitor's browser with no round trip to Cloudflare, and where the browser lacks the API it returns and does nothing, so the page behaves exactly as before. Their sample scan of a page found C2PA content credentials on 8 of 12 images, reported without cryptographic verification. That is provenance surfaced by default, which is a governance question dressed as a feature toggle.
The third piece is measurement. AEO Visibility, announced the same day, probes Claude and GPT with likely customer questions and reports Citation Rate, Mention Rate, Prominence and Share of Voice. Cloudflare's stated reason for repeating each probe is the one folkfox has been making all week: assistants rarely answer the same question the same way twice, so it queries each assistant multiple times across different models.
The pitch behind it is positional rather than clever. In Cloudflare's own announcement, Chief Strategy Officer Stephanie Cohen says the company sits at the network layer and sees "real crawl activity, real referrals, what AI systems are genuinely doing across millions of sites". Whether you buy the product or not, the claim is the interesting part: the scent of agentic browsing is now being read at the pipe rather than in your analytics.
On September 15, Cloudflare will start cutting off Google traffic for millions of its smallest customers by default... This is publishers going to war with Google, and Cloudflare... just became their army... Cloudflare's message to Google is simple. Split the bot. Keep search separate and we'll allow it by default.
What agentic browsing actually costs a regulated brand#
Strip the excitement away and three practical costs of agentic browsing land on the desk of anyone marketing in a licensed category. None of them is solved by a robots.txt line.
First, attribution. An agent that reads, compares and books leaves a trail that looks nothing like a session, and the scent goes cold fast. Your analytics will show fewer, stranger visits and the same revenue, or the same visits and stranger revenue. Second, compliance. If an assistant summarises your product to a customer, the mandated wording that sits in your page furniture may not survive the summary. Third, control. Terms of service are now the load-bearing wall, and most were written for scrapers.
That chart is folkfox's own measured pull, not an estimate. It says something useful about where the quarry is hiding. The broad terms carry the volume: agentic ai at 110,000 monthly searches, ai agents at 49,500. They are also the terms every major publisher already owns, at difficulty scores of 56 and 67. Agentic browsing sits at 1,300 searches and difficulty 30, which is a gap a well-built page can still walk into. That is the quiet den nobody has claimed.
Note the last bullet, because it is the corrective to a fortnight of vendor noise. Making a site agent-callable through WebMCP is a real capability. It is not a Google ranking move, and Google says so on its own page. Keep the two ambitions in separate baskets and you will not waste a quarter chasing a file that Search ignores.
Five moves worth making before the next ruling#
Practical, cheap and in order. None of them requires a strategy offsite, and all five treat agentic browsing as a policy question rather than a firewall one.
Separate user-triggered agents from ai crawler bots in your access logs today. ChatGPT-User, Perplexity-User and Claude-User are different traffic from GPTBot, PerplexityBot and ClaudeBot, and the vendors' own docs say so.
For scheduled crawlers it is a rule. For user-summoned fetches, two of the three biggest vendors document that it may not apply. Plan accordingly rather than assuming compliance.
If you genuinely need to restrict agent access, your terms of service are now the load-bearing document. Have someone who has read the Ninth Circuit opinion look at yours.
Add a repeated-probe measure of whether assistants recommend you. Repeat it on a cadence, because a single reading is noise.
Not block or allow: which errands you want finished. A price check, a licence check and a booking are three different risk profiles.
Where regulated categories differ#
An iGaming operator, a lender and a clinic all carry mandated wording that must reach the customer. If an assistant is the surface, that wording has to survive summarisation, which means it belongs in the sentence that answers the question, not only in a footer. That is a copy decision, not an infrastructure one, and it is the part agencies keep filing under engineering. Agentic browsing does not change what you must say, only who repeats it. Our SEO and GEO work starts there, and our content marketing practice owns the sentence itself.
Two folkfox pieces published this week sit directly underneath this one. The measurement argument is set out in a single reading is a rumour, and the risk of blanket blocking is worked through in blocking AI crawlers. The referral side of the same shift is in the archive that stopped receiving questions.
Human or bot, decided at the door
One verdict per visitor, taken on arrival, enforced with a blanket rule. It was cheap, legible and, as of this month, resting on a legal theory an appeals court has just declined to extend.
Which errands may be completed, checked continuously
Intent and use case, evaluated through the session, with the restriction written into terms rather than only into a firewall. Slower to build. Considerably harder to knock over.
Nobody needs to prowl the perimeter in a panic over agentic browsing. It is a small share of traffic and the tooling is a fortnight old. What has changed is that the cheapest defence stopped being the strongest one, and the vendors and the courts now agree on why. Better to redraw the map in a quiet week than during a crisis, while the tracks are still fresh and the undergrowth is still thin.
Frequently asked questions#
What is agentic browsing?
Agentic browsing is a person instructing an AI assistant to visit and act on a website for them: reading a page, comparing prices, filling a form or completing a booking. It differs from crawling because a human triggered it seconds earlier, and the assistant is acting on that person's instruction rather than harvesting on the vendor's own schedule.
Did the court say websites cannot block AI agents?
No. It held that Amazon was unlikely to win on its Computer Fraud and Abuse Act claim, because the user rather than Perplexity did the accessing. The decision is preliminary, it explicitly leaves contract and tort claims untouched, and it binds one circuit. Blocking is still possible; the anti-hacking statute is just a weak basis for it.
How are ai crawlers different from user-triggered agents?
A crawler fetches on the vendor's schedule to build an index or a training set. A user-triggered agent fetches because someone asked a question moments ago. OpenAI, Perplexity and Anthropic all document the two separately, and two of the three state that robots.txt may not apply to the user-triggered kind.
Should I add an llms.txt file so agents can read my site?
Not for Google. Google's own guidance states you do not need machine readable files, AI text files or special markup to appear in Search, including its generative features, because Search ignores them. Making a site agent-callable through a standard like WebMCP is a separate, real capability, but it is not a ranking move.
What are ai crawler bots doing to my analytics?
They inflate pageviews without intent, while user-triggered agents do the opposite: they can complete a task with almost no session footprint. Splitting the two in your logs is the only way to tell a traffic problem from a measurement problem, and it costs an afternoon.
Is agentic ai actually sending meaningful traffic yet?
Not at scale for most sites. Treat it as a posture question rather than a volume one. The reason to act now is that the legal and infrastructure defaults are being set this month, and defaults are far cheaper to influence early than to unpick later.
Read more on this topic#
A single reading is a rumour, not a measurement
Why one AI visibility score tells you almost nothing, and what cadence actually measures.
Read the pieceBlocking AI crawlers without blocking Googlebot
The technical half of this argument: what a blanket block actually costs you in Search.
Read the pieceThe archive that stopped receiving questions
What happens to a content strategy built on borrowed ground when the referrals stop.
Read the pieceCrawl budget and internal site search
Before you worry about agents, check what your own site is doing to its crawl budget.
Read the piece
Want an agent policy that is not just a firewall rule?
folkfox writes access, disclosure and measurement policy for brands in licensed categories, where the mandated wording has to survive being summarised by something that is not a browser.