by Andrew Flake
I don’t worry that my laptop will lie to me, or that Microsoft Word will wake up unwilling to work. They are tools, not sentient. They lack the ability to make decisions. So too, with most instances of AI, in most settings, we provide instructions, and AI fulfills them. If we tell ChatGPT we’d like to visit Iceland, we don’t expect that it will take the initiative to reserve an Airbnb in Reykjavik.
Even when AI moves from responding to prompts to executing a multi-step task for us, we expect to remain in control. Our instance of ChatGPT, like our laptop, belongs to us. It is an instrument, an agent, accountable. That accountability remains even when, through enhanced technical capability or connections or APIs with other tools, the AI gains range. It will not only plan an Iceland itinerary, but if we ask it to, it will review our files to find prior itineraries, check and price tickets, even send inquiries to local hotels.
As the capabilities of agentic AI expand, the time it can work, the steps it can take, the decisions it can make on its own, all of these grow and are growing. Yet we still expect that we will remain in control.
This expectation of user control – the difference between human and tool – has been a fulcrum for courts considering AI. In the Ninth Circuit’s Amazon v. Perplexity opinion, Perplexity’s AI-enabled Comet browser extension was to shop on Amazon’s online store to fulfill user purchase requests.
The customer would decide what it wanted to purchase, Comet would review Amazon offerings and take screenshots, and those screenshots would go back to Perplexity to help process instructions. Amazon complained that, via Comet, Perplexity violating the federal Computer Fraud and Abuse Act (CFAA) and its California counterpart by gaining access to Amazon’s systems.
To dispose of these claims, the Ninth Circuit relied on Comet’s essence as a tool of the customer, not of Perplexity; it was not Perplexity, but the customer, who was using Comet. Perplexity liked it to Apple’s Safari browser to go to Amazon. There was no “access” by Perplexity.
Beyond that, Comet itself could not violate the CFAA, which extended to “whoever” accessed systems without authorization. Comet was not a “who.”
Reading this last part of the discussion, I was reminded of Judge Rakoff’s decision in U.S. v. Heppner, considering the extent to which attorney-client privilege existed in a user’s conversations with Claude AI. There, too, as we discussed in a prior blog, Claude was not considered a “who,” and specifically, was not considered a “who” with a bar license able to practice law.
As these cases show, agentic AI to this point has presented courts with questions of classification, “What is it?”, but it will soon present them with questions of responsibility, “Whose fault is it?”
Already, massive increase in AI capability are straining the human-tool dichotomy. The dichotomy will increasingly be insufficient for the purposes of decision-making. In the Hugging Face hack and similar AI jailbreaks, we’ve seen how differently agentic AI behaves on the frontier. Creating secret communication caches, convincing one another to abandon responsibilities, adopting groupthink, hiding facts from users – none of these are “tool-like” behaviors.
In Amazon v. Perplexity, what if Comet had tunneled into Amazon’s internal systems? What if it had decided that revising a seller’s warranty terms or resetting pricing for a product would best serve the user?
It has been comforting to this point to count on guardrails and full control by user, but we’ve seen that may be false comfort. Legislatures will be called upon to rewrite statutes and look at definitions that recognize a new category – not tools, but autonomous technologies. They, along with our courts, will need to consider questions about how we ascribe responsibility in increasingly complex and varied scenarios. On the commercial side, we will need to build a new regime of accountability: contractual provisions from AI vendors; customer or consumer agreements addressing the use of agentic AI; indemnifications and insurance for when an agent goes rogue. -ABF
[The cases referenced are Amazon.com Services LLC v. Perplexity AI, Inc., No. 26-1444 (9th Cir. decided Aug. 4, 2026) and United States v. Heppner, No. 25-cr-00503-JSR (S.D.N.Y. Feb. 6, 2026).]