The Ninth Circuit Looked at Your Architecture. Your Insurer Is Next.
On August 4 a federal appeals court decided who acted by tracing where the code ran. Seven months earlier, the standard liability form began excluding anything arising out of generative AI. Both questions now resolve to a record most deployers cannot produce.
On August 4, 2026, the Ninth Circuit became the first federal appeals court to decide whether an AI agent browsing a website is the one doing the browsing.
The case was Amazon.com Services LLC v. Perplexity AI, No. 26-1444. Amazon had won a preliminary injunction barring Perplexity's Comet Assistant from shopping on Amazon.com on a user's behalf, on the theory that the agent's activity was unauthorized access under the Computer Fraud and Abuse Act and its California analogue. The Ninth Circuit vacated it. Amazon was not likely to succeed, the panel held, because it was the user who accessed Amazon's computers, with the agent's help. The Assistant was a tool, not a "person" under a statute that asks what "whoever" did. The rule of lenity — the principle that criminal statutes are not stretched into new territory — did the rest.
Most of the commentary read this as a win for agent developers, which for now it is. But the outcome is not the part that should hold your attention. The method is.
The court did not resolve this with agency doctrine. It resolved it with plumbing.
There was a clean, familiar way to decide this case. Agency law has spent several centuries on the question of when one party's act is attributed to another. The panel did not go there.
It went to the packets. The decisive fact was that Perplexity's servers never communicated with Amazon's servers at all. The Assistant captured the page on the user's own machine, sent that to Perplexity for analysis, and received navigation instructions that then executed locally. Every request that arrived at Amazon originated from the user's computer. That is what separated this case from Facebook v. Power Ventures, where the defendant's own systems did the transmitting.
So the holding is not "agents are tools." The holding is narrower and stranger than that: this agent, with this execution topology, under this statute, meant the user was the one who acted.
The court was unusually candid that it knew this. It confined itself to the CFAA and the California statute. It observed that there is little to no existing caselaw dealing with how to ascribe responsibility for AI agents. It expressly preserved breach of terms of service, contract, and tort theories for remand — Amazon can still regulate access by private agreement, and that fight is live. And it flagged that a different architecture, one with greater autonomy or more direct communication with the destination servers, could come out the other way. This was a preliminary injunction. It was not a judgment on the merits.
Read that as a deployer rather than as a vendor, and it says something uncomfortable.
The most consequential legal fact about the agents you run — whether the law treats what they did as something you did — is not settled by your policy, your terms of service, or your intent. It is settled by where your code ran and which system spoke to which. It is a question of fact about execution topology, and questions of fact are answered from the record.
Which raises the question this piece is actually about. Can you produce that record? For one specific action, taken on one specific day nine months ago, to a reader who has no reason to trust you?
Seven months earlier, a second institution asked a version of the same question
On January 1, 2026, ISO — the Verisk-owned body whose forms sit underneath most of the commercial general liability market in the United States — put three generative AI endorsements into circulation.
CG 40 47 excludes bodily injury, property damage, and personal and advertising injury arising out of generative AI. That is Coverage A and Coverage B together: the whole policy. CG 40 48 excludes only Coverage B, the personal and advertising injury slice where the defamation, publicity, and IP-adjacent claims live. CG 35 08 reaches products and completed operations, which is the one that matters if AI is embedded in something you ship.
All three share a single definition of the thing being excluded: a machine-based learning system or model, trained on data, with the ability to create content or responses — text, images, audio, video, or code, and not limited to those.
Read that definition slowly and notice how little work it does to narrow anything. It does not require the model to be large, or generative in the marketing sense, or central to what went wrong. It describes most of what has shipped into production software since 2023.
The modularity is the tell. A carrier can now exclude everything, or excise only the most litigated slice, or cut out products liability where the AI is inside the deliverable — using standardized, regulator-ready language, without drafting a manuscript endorsement or leaving ambiguity to do the work later. By April 2026 carriers including W.R. Berkley, Chubb, Travelers, Berkshire Hathaway, and Cincinnati Financial had filed to adopt these forms or their own equivalents. Affirmative AI cover has started to appear to fill the hole — HSB launched a small and mid-market AI liability product in March 2026 — which is itself the clearest possible signal that the market believes a hole now exists.
The two words that turn a form into a fact fight
Every one of those endorsements is built on the phrase arising out of.
That phrase is doing more work than any other language in the form, and it is genuinely contested. In most jurisdictions it is construed broadly: originating from, growing out of, flowing from — a causal connection, not proximate cause, and meaningfully broader than "caused by." A minority read it far more tightly. Indiana and Tennessee courts have required something closer to an efficient and predominating cause. Montana applies an expansive test to grants of coverage and a narrower one to exclusions, resolving ambiguity toward coverage.
I want to be careful here, because this is where confident writing usually goes wrong. There is no single answer to how much AI involvement triggers CG 40 47. That is not a gap in the reporting. It is the actual state of the law, and it will stay that way until enough claims are litigated to produce a body of decisions.
But notice what the ambiguity is. Whether the exclusion bites will turn on a factual showing about what role the AI actually played in the loss. Not on the form. On the facts. On the record.
Which is the same place the Ninth Circuit ended up, by a completely different road.
Two institutions, one demand
A federal appeals court asked who acted, and answered it by reconstructing what ran where.
The standard liability form asked what the AI contributed, and left that to be established loss by loss, on the evidence.
Neither institution accepted a policy document as the answer. Neither asked what the system was designed to do. Both asked what it did — and both will get their answer from whatever record exists at the moment someone goes looking.
That record is now load-bearing in a way it was not eighteen months ago. It sits underneath your attribution exposure and underneath your coverage position simultaneously, and in most organizations no one owns it.
The test your logs were never built to pass
Here is the part that tends to land badly, so let me state it precisely.
The problem with application logs as evidence is not that they are inaccurate. In the overwhelming majority of cases they are perfectly accurate. The problem is structural: you hold them, you can modify them, and you are the party with the motive. A record controlled by the interested party cannot demonstrate its own integrity, no matter how honest that party was.
That is fine when logs are read by engineers debugging a system. It stops being fine the moment the reader is an opposing party, a claims adjuster deciding whether the exclusion applies, or a court asked to attribute an act. Those readers do not need to allege tampering. They only need to point out that nothing rules it out, and the record stops carrying weight.
The functional test is simple and it is worth applying to whatever you have right now. Take one agent action from last quarter. Hand the record to someone with an interest in disbelieving it, and no access to your infrastructure. Can they confirm, on their own, that it is complete, that it has not been altered since the moment it was made, and that it says who authorized the action? If the answer requires them to call you, take your word for something, or query a system you control, you do not have evidence. You have an assertion with good formatting.
Records that survive that test share a small number of properties. They are sealed at the moment of execution rather than assembled afterwards from fragments. They are anchored to a log the producing party does not operate, so the timestamp is not self-certified. They are verifiable with ordinary tooling and a published specification, so verification does not depend on the vendor still existing, still being cooperative, or still being in business in four years. And they record the authorization — who stood behind the action — not merely the action, because "who acted" was the question the Ninth Circuit was answering.
None of that is exotic. Cryptographic hashing, transparency logs, and detached signatures are mature, boring technology. The gap is not capability. It is that almost nobody has pointed it at agent execution, because until this year the demand for it was theoretical.
It is not theoretical now.
What this does not mean
Precision is the whole point, so here are the limits, plainly.
Perplexity is one circuit, one statute, one procedural posture. It is not a general rule that agent acts are attributed to users. It does not bind other circuits. The contract and tort theories are still alive on remand, and the panel practically invited a different result on different architecture. Anyone selling it to you as settled law is overselling it.
These endorsements are optional. Whether one is attached to your policy is a question for your broker and your renewal file, not something to assume in either direction. Read the schedule of forms. If CG 40 47, CG 40 48, or CG 35 08 appears on it, that is a conversation to have before you need coverage, not after.
No record makes you win. Evidence does not decide liability. It decides what the argument is about — whether you are litigating what happened, or litigating whether anyone can establish what happened. Those are very different fights with very different costs, and only one of them is winnable on the facts.
And be careful with dates. You will see confident claims that Federal Rule of Evidence 707, covering machine-generated evidence, takes effect on a particular day. It does not have one. In May 2026 the Advisory Committee on Evidence Rules revised the proposed rule and declined to advance it, stating that it does not recommend action at this time and that the revised rule would require republication to go forward. The direction of travel is clear. The date is not, and anyone quoting you one is guessing. The rules that already exist — Federal Rules of Evidence 902(13) and 902(14), which let a qualified person certify a record's cryptographic integrity — are the ones your evidence will actually be measured against.
Monday morning
Four questions, in the order they get expensive.
Which of your agents can take an action with an external effect? Not which ones can draft, summarize, or suggest. Which ones can send, buy, file, post, provision, or commit. That is the exposed surface, and it is usually a much shorter list than people expect and a much longer one than the risk register shows.
For each of those, where does the code run and what talks to what? This is now a legal fact about your business, not a diagram in an architecture review. After August 4, it is the fact that determines whose act it was.
Pull your schedule of forms. Look for CG 40 47, CG 40 48, and CG 35 08, and for carrier-specific AI language that does the same job under a different number. Then ask your broker the only question that matters: if an incident involves an agent, what does this carrier need to see to conclude the exclusion does not apply?
Then run the adversary test on one real action. One. Last quarter. See how far you get before someone has to take your word for something.
The institutions have already moved. A court decided who acted by examining execution architecture, and the market's default liability form began carving out anything arising out of generative AI, both inside the same eight months, neither one waiting for the other. What they converged on is not a rule about AI. It is a demand for a record — one made at the time, held to a standard, and readable by someone who does not trust you.
Most organizations running agents in production cannot produce it yet. The ones that can will find, the first time it matters, that it was the cheapest thing they ever built.