A Court Says the Agent Is the User, Cloudflare Issues Agents a Name and a Wallet, and Shopify’s AI Orders Triple
Period of July 28 to August 10, 2026. A federal appeals court ruled for the first time on whether an AI agent acting for a person can legally reach a website it was not invited to, and the answer reshapes what merchants can do about agent traffic. Cloudflare started issuing the two things an agent has never had, a stable identity and a way to hold money, with human-set spending limits attached. Shopify’s quarterly numbers put a size on the discovery shift and revealed which products agents actually buy. The Model Context Protocol landed the rewrite that makes live catalogue feeds cheap to run. And Europe’s chatbot disclosure obligation stopped being a deadline and became law.
Two weeks ago we covered agentic spend getting a 2026 number, an aggregator walking into ChatGPT with 500 million products, and Ant raising $1.2 billion for agent-era payment rails. The question there was who does the selling once agents are through your door.
This period answered a question underneath that one. For a year, every merchant conversation about agent traffic has assumed a fallback: if an agent becomes a problem, you block it, and if it comes back, you have a legal remedy. On August 4 a federal appeals court removed the most powerful version of that remedy. On the same day, Cloudflare made the opposite bet and started handing agents the two credentials that make them worth letting in. The week after, Shopify reported the numbers that explain why anyone would.
Here’s what happened.
The Ninth Circuit says the agent is the user, not the intruder
On August 4, the US Court of Appeals for the Ninth Circuit decided Amazon.com Services LLC v. Perplexity AI, the case we covered in March when a district court enjoined the Comet shopping agent. The court vacated that preliminary injunction, which had barred Comet’s Assistant from Amazon’s password-protected account pages rather than from Amazon.com generally. Circuit Judge Milan D. Smith, Jr. held that Amazon is unlikely to succeed on its Computer Fraud and Abuse Act claim, because Perplexity’s agentic Assistant is a tool operated by users rather than by Perplexity itself. The panel’s phrasing is the part that matters: when a user tasks the agent with acting on their behalf on Amazon.com, it is the user who accessed Amazon’s computers, with the help of Perplexity’s agent. The court noted there is little to no existing caselaw on ascribing responsibility for AI agents under the statute, and applied the rule of lenity to read the ambiguity against liability.
Update: the holding is not final. Amazon petitioned for rehearing en banc on 18 August, arguing that control rather than initiation is what matters. Nothing has changed operationally, but treat the reasoning below as the current state of the law rather than the settled state of it.
The mechanics mattered to the outcome. Cooley’s analysis notes the court leaned on the fact that the Assistant routed communications through the user’s own computer rather than contacting Amazon’s servers directly, and that the same reasoning covers California’s CDAFA. Just as important is what survived. The ruling expressly leaves open breach of terms of service, other contract claims, and tort theories, and Amazon’s underlying lawsuit continues. Amazon said it is evaluating next steps and remains confident in its case. The Electronic Frontier Foundation, which filed an amicus brief arguing exactly this reading, said the court found its explanation articulated the nature of the system most clearly.
Why it matters for merchants: Three weeks ago the question was which agents you let through the door. This ruling changes what happens when you decide the answer is none. The federal anti-hacking statute, which is the heaviest instrument a US site has ever had for keeping unwanted automation out, does not reach an agent that a real customer pointed at you and that runs through that customer’s machine. Practically, that means agent access is now a contract question and a technical question, not a criminal one. Your terms of service, your rate limits, and your bot management config are the levers you actually have, and the first of those only works if it says something specific about automated agents acting for users, which most merchant terms do not.
There is a second reading that is more useful than the first. The court did not say agents may do whatever they like. It said the agent is legally the customer’s hands. If a customer may look at your product page, compare your price, and buy from you, then so may the software they delegated that errand to. That is a workable principle, and it points the same direction the rest of this space has been moving: your defence against bad agent traffic is verification and rate control, not exclusion. Note too why the architecture mattered to the outcome. An agent relaying through the customer’s own machine arrives looking like that customer, from their IP, in their browser session, which is precisely why the anti-hacking argument failed and precisely why you cannot filter it. The traffic you can identify is the traffic that announces itself, which makes verified agent credentials the only workable sorting mechanism you have.
Cloudflare gives agents a name and a wallet, with the leash held by a human
Also on August 4, Cloudflare announced Cloudflare Wallets and cloudflare.pay, giving agents built on its platform a persistent, verifiable identity and a stablecoin wallet they can spend from within limits their owner sets. The design is two-tier. A human-controlled Account Wallet holds funds. The account holder delegates spending to per-agent Virtual Wallets operated by API, each with an allowance, an allowlist of who it may pay, and a maximum transaction size, with anomalous activity routed to a human before more money moves. The identity half, cloudflare.pay, gives each account a human-readable handle that agents can be issued under, so the agent carries a provable link to whoever is responsible for it. The protocol underneath is x402, the HTTP-native payment standard whose Linux Foundation standards body went operational last month with 40 members including Cloudflare. CEO Matthew Prince framed the identity piece directly: when an agent shows up at your door, you need to know who sent it, and Cloudflare can give agents a face, a link to the human or organisation that owns them, so that trust, accountability and real commerce can follow. Availability is staged: handles can be reserved now, while funding, Virtual Wallets, and programmable spending arrive over the coming months.
Why it matters for merchants: Put this next to the court ruling and the shape of the next twelve months is legible. On the same day the legal route to keeping agents out narrowed, one of the internet’s largest infrastructure providers started issuing agents the credentials that make keeping them out unnecessary.
The merchant-relevant idea here is not the wallet, it is the allowlist. Cloudflare’s guardrails let an agent’s owner specify which merchants it may pay. That is a purchase-side allowlist, and it is the mirror image of the bot allowlist you have been arguing about internally. Whether you are on it becomes a distribution question, and it is worth asking Cloudflare and your platform now what determines eligibility, because nobody has published criteria yet.
The wider point is what Cloudflare is quietly asserting: agent identity is an infrastructure product, not a card network product. Visa’s Trusted Agent Protocol, Mastercard’s agent credentials, the x402 members, and now a CDN are all issuing some version of an agent passport. You will end up accepting several. What you should refuse to accept is unsigned agent traffic that carries a payment credential, because that combination is exactly what Akamai found attackers exploiting. And whichever passport wins, the thing it will be checking is whether your prices, stock, and variants are readable to a machine, which is work most catalogues still have not done.
Shopify’s numbers: AI orders tripled, and three quarters of them were long tail
On August 5, Shopify reported Q2 2026 revenue of $3.58 billion, up 34 percent, on GMV of $115.6 billion, up 32 percent, with free cash flow up 55 percent to $654 million and an 18 percent free cash flow margin. The agentic commerce disclosures were the interesting half. AI traffic to merchant storefronts rose 3x year over year, orders originating from AI searches also tripled, and 75 percent of AI-attributed orders came from outside the top 100 categories. New buyers arrived from AI channels at nearly twice the rate of other channels, meaning AI surfaces are disproportionately bringing merchants customers they did not already have. Shopify used the call to frame agentic commerce as an extension of the existing platform rather than a separate business, and reported that its Sidekick assistant handled nearly 34 million merchant conversations in the quarter, with daily active merchants up 3.6x and 36,000 custom apps built through it, against 12,000 in Q1.
Why it matters for merchants: The long tail number is the one to keep. Three quarters of AI-attributed orders fell outside the top 100 categories, which says agents are not primarily a new way to sell the obvious things. They are a way for specific, hard-to-phrase demand to find a specific product, which is the search problem that keyword systems were always worst at and the one a conversation is naturally good at. If you sell something niche, unusually specified, or hard to name, this is the first hard evidence that the channel favours you rather than the category giants, and it partly answers the concentration worry from the PHD and WARC sizing two weeks ago.
The new-buyer figure is the other half. AI channels bringing new customers at nearly twice the rate of other channels reframes the budget conversation, because you are not comparing agentic readiness against your existing conversion rate, you are comparing it against your customer acquisition cost.
One caution on the framing: these are platform-wide figures from a vendor with an interest in the story, and tripling from a small base is still a small base. Shopify has not published what share of total orders AI-originated orders represent. Treat the growth rates as directionally real and the absolute size as unknown. The actionable version is to run the same cut on your own data: segment orders by AI referrer, then check what share are new customers and how many fall outside your top-selling categories. If your split looks like Shopify’s, the discovery shift is already paying you and the case for cleaning up your product data writes itself.
MCP ships the rewrite that makes catalogue feeds cheap
On July 28, the Model Context Protocol published its 2026-07-28 specification, which co-inventor David Soria Parra called MCP’s most important release since remote MCP launched more than a year ago. The core change is architectural: MCP moves from a bidirectional stateful protocol to a stateless request and response model, so any request can reach any server instance behind an ordinary load balancer without shared session storage. The release also promotes MCP Apps into a formal extensions framework, which is the piece that lets a server ship interactive content the AI host renders rather than describing a product in a paragraph of text.
Why it matters for merchants: This is plumbing, and you are not going to implement it. It matters for one reason, which is that the stateless rewrite is what makes MCP servers cheap to run at scale. A catalogue endpoint that had to hold a session per connected agent was an infrastructure problem for anyone but a hyperscaler. One that answers self-contained requests behind an ordinary load balancer is a normal web service. If your platform or an agency has told you that exposing a live product feed to AI agents is expensive or fragile, that quote was priced against the old design. MCP Apps is the other half: as we noted two weeks ago, it is the difference between your product appearing as a sentence and appearing as a real carousel with variant pickers. This is also the protocol that carries Shopify’s own MCP catalogue feed, which is what our Shopify Feed Previewer reads to show you what an AI actually sees of your products. Ask your platform when they plan to move, and treat a vague answer as information.
The European angle: the chatbot notice is law now, and Europe never had the blocking lever anyway
Europe’s date arrived. The AI Act’s Article 50 transparency obligations took effect on 2 August 2026, with non-compliance carrying fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. The guidance on what counts as compliance is stricter than most merchants assumed. Travers Smith’s briefing is explicit that information must be clear and distinguishable, and will not meet the standard if it can easily be overlooked, for example buried in terms and conditions or hidden under layers of menu options, and that the notice is owed at first interaction to each person, not once at deployment. The formal duty for interactive AI sits with providers, defined as whoever places the system on the market under their own name or trade mark, which is a line worth checking rather than assuming your vendor stands on the right side of it. The grace period to 2 December 2026 covers the Article 50(2) marking obligation for synthetic content on systems already on the market, and does nothing for the disclosure duty.
Now pair that with the Ninth Circuit. The US just decided its anti-hacking statute does not reach agents acting for users. European merchants never had the equivalent lever anyway: member states have computer-misuse offences under Directive 2013/40/EU, but those are criminal statutes enforced by prosecutors, not a private civil claim a retailer can bring against an agent developer the way Amazon brought its CFAA case. So the practical position on both sides of the Atlantic now converges on the same two levers: contract terms and technical controls. On payments, the picture is similarly unglamorous, and unchanged since spring. Osborne Clarke’s March analysis, still the clearest statement of the position, notes that agentic payments in the EU remain subject to PSD2 and the strong customer authentication rules with no special regime, and that disputes will increasingly turn on whether the user authorised all elements of the transaction.
Why it matters for merchants: Two jobs, and they are smaller than the fine suggests. First, if you run any AI assistant, chatbot, or agent-facing helper on an EU-facing store, look at it today as a first-time visitor would and confirm the AI notice is visible in the conversation itself. A line in your privacy policy is not compliance, and neither is calling the thing an assistant and hoping the name does the work. Second, note that your terms of service are now the agent-access instrument in Europe as well as in the US, which means the rewrite in action item one is not a US-only job.
The payments point is the one to raise with your PSP this quarter. Under PSD2 the question is not whether an agent paid you, it is whether the cardholder authorised what the agent actually did, and the evidence for that lives in whatever audit trail the agent’s issuer keeps. When a delegated purchase goes wrong, you want to know now who holds that record and whether you can obtain it during a dispute. This is the trust gap we covered in June, and Cloudflare’s spending caps and allowlists are one more party’s attempt to close it from the agent’s side rather than the merchant’s.
What moved this period
| Development | What happened | Why a merchant cares |
|---|---|---|
| Ninth Circuit ruling | Agent acting for a user is the user under the CFAA | Blocking agents is a contract question now, not a criminal one |
| Cloudflare Wallets | Agent identity at cloudflare.pay plus capped stablecoin wallets | Agents get a provable owner and a merchant allowlist |
| Shopify Q2 2026 | AI traffic and AI orders both 3x, new buyers at nearly 2x rate | AI channels bring new customers, not just cheaper ones |
| Shopify long-tail split | 75% of AI-attributed orders outside the top 100 categories | Niche and hard-to-name products are favoured, not penalised |
| MCP 2026-07-28 spec | Stateless core plus MCP Apps in a formal extensions framework | Live agent-facing catalogue feeds get cheap to run |
| EU AI Act Article 50 | In force 2 August, fines to 15M euros or 3% of turnover | The AI notice must be visible in the chat, not in the T&Cs |
What merchants should do this period
1. Read your terms of service as if they were your only defence, because they now are. The Ninth Circuit removed the anti-hacking route and expressly left contract claims standing. Most merchant terms prohibit scraping and automated access in language written for scalping bots a decade ago, which either sweeps up legitimate customer-delegated agents or says nothing useful about them. Decide what you actually want to permit, distinguish agents acting for an identified customer from unattended automation, and write that down. This is an hour with whoever handles your legal copy, and it is the highest-leverage hour available this period.
2. Ask your CDN or platform which agent credentials it can verify today. The ruling makes this the practical question, because an agent relaying through a customer’s own machine is indistinguishable from that customer at the network layer, so filtering is not an option and identity is. Visa’s Trusted Agent Protocol, Mastercard’s agent credentials, the x402 members and now Cloudflare are all issuing some form of signed agent identity. Get a list of which your stack can currently read, and treat any agent presenting a payment credential without one as the risk case.
3. Run the Shopify cut on your own orders. Segment the last two quarters by AI referrer, then measure two things: what share of those orders came from new customers, and what share fell outside your top-selling categories. Shopify saw nearly twice the new-buyer rate and 75 percent long tail across its platform. If your numbers rhyme with that, agentic readiness is an acquisition investment and should be budgeted from that line rather than from IT.
4. European merchants: check the AI notice with your own eyes today. Article 50 is in force, the disclosure is owed at first interaction to each visitor, and guidance says it fails if it is buried in terms or menus. Open your own store in a private window, start a chat, and see whether a reasonable person would know they are talking to software. Note also that the marking grace period to 2 December only helps systems that were live before 2 August, so anything you launch this autumn gets no relief.
5. Ask your payment provider the PSD2 question, not the protocol question. In Europe the live issue is not which agentic standard they support, it is what evidence exists that the cardholder authorised the specific purchase an agent made. Find out who holds that audit trail and whether you can get it during a chargeback. If the answer is unclear, that is your exposure on every delegated purchase you accept.
Sources
- Amazon.com Services LLC v. Perplexity AI, No. 26-1444 (9th Cir. Aug. 4, 2026), opinion - US Court of Appeals for the Ninth Circuit
- Ninth Circuit Narrows CFAA Reach in Perplexity Agentic Commerce Ruling - PYMNTS
- Ninth Circuit Rules on AI Agent ‘Access’ to Third-Party Websites Under CFAA - Cooley
- Ninth Circuit Addresses CFAA and Agentic AI Tools in Groundbreaking Decision - Wilson Sonsini
- Appeals Court Agrees With EFF That Building a Web Browser Doesn’t Violate the CFAA - Electronic Frontier Foundation
- Appeals Court Overturns Ban on Perplexity AI Shopping Agents on Amazon - PYMNTS
- Announcing Cloudflare Wallets: The programmable wallet for the agentic Internet - Cloudflare Blog
- Cloudflare Issues AI Agents a Wallet and Identity - PYMNTS
- Cloudflare just launched a permanent ID tool and wallet for AI shopping - Fortune
- Shopify Beats Expectations in Strong Q2 CY2026 - StockStory
- Shopify Q2 2026 slides: AI commerce drives 32% GMV growth - Investing.com
- Shopify Credits AI for 34% Revenue Growth in Q2 2026 - Retail TouchPoints
- The 2026-07-28 Specification - Model Context Protocol Blog
- EU AI Act: Transparency Obligations Take Effect 2 August 2026 - Cooley
- Is it a bot? EU AI Act transparency rules take effect 2 August 2026 - Travers Smith
- Agentic Payments: a new challenge for Europe’s payments ecosystem (March 2026) - Osborne Clarke