Something Inc.LoginSchedule a free consultation
STRATEGY

The EU AI Act Is Not Your Cold Email Problem

Article 50 went live on 2 August 2026 and a compliance industry sprang up overnight selling outbound teams an AI disclosure footer. Read the article it cites and the footer is not in there. The rule that decides whether your European outbound is legal is twenty-four years old.

STRATEGYCOLD EMAILSEP 2026

Since August a specific product has been selling well to outbound teams: an EU AI Act cold email compliance package, usually a policy document, a vendor questionnaire, and a line of copy to paste into your email footer saying the message was drafted with the assistance of an AI system. The pitch is that Article 50 went into application on 2 August 2026 and your sequences are now in scope.

The date is right. Article 50 of Regulation (EU) 2024/1689 has applied since 2 August 2026, and the fine ceiling attached to it is real money. Everything after the date is worth checking against the text, because the text is short, public, and says something narrower than the decks do.

We read it against the outbound stack we actually run for clients. The verdict: the footer disclosure is not required, the obligations that do exist mostly sit with the company that built your sending tool rather than with you, and the genuine legal exposure in European outbound is sitting in a place nobody is selling a product for.

TL;DR · 60 SECONDSArticle 50 puts the machine-readable marking duty for AI-generated text on the provider of the generative system, not on the sales team using it. The deployer disclosure duty in Article 50(4) attaches to deepfakes and to AI-generated text published to inform the public on matters of public interest, and a one-to-one prospecting email is neither. What does govern your European outbound is the ePrivacy Directive, transposed differently in every member state, plus GDPR Article 14, which requires you to tell a person where you got their contact details at the time of first contact. Fix the second thing. The footer can wait.

What the EU AI Act cold email rules actually say

The EU AI Act cold email rules are contained in one article, Article 50, which carries four operative transparency duties and splits them between two different parties, the provider who builds the system and the deployer who uses it.

Paragraph 1 says providers must design systems intended to interact directly with natural persons so that those people are informed they are dealing with an AI system, unless that is obvious to a reasonably well informed and observant person. Paragraph 2 says providers of systems generating synthetic audio, image, video or text must mark the outputs in a machine-readable format so they are detectable as artificially generated, with a carve-out where the system performs an assistive function for standard editing or does not substantially alter the input data. Paragraph 4 is the deployer paragraph: it covers deepfakes, and it covers AI-generated or manipulated text published with the purpose of informing the public on matters of public interest. Paragraph 5 sets the timing, which is that any required notice reaches the person no later than the first interaction.

That is the whole of it, and you can read the operative text of Article 50 in full in about four minutes. The penalty tier is set separately, in Article 99, paragraph 4, at up to 15 million euros or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, with the lower of the two applying to SMEs and start-ups.

2 Aug 2026
date Article 50 of Regulation (EU) 2024/1689 entered into application, per the Act's own Article 113 timetable
EUR 15M / 3%
fine ceiling for an Article 50 breach under Article 99(4), whichever figure is higher, or lower for SMEs and start-ups
EUR 20M / 4%
GDPR Article 83(5) ceiling covering breaches of the information duties in Articles 12 to 22, including Article 14
27
national transpositions of the ePrivacy Directive, which is what actually decides whether a given cold email is lawful in a given member state

Article 50 binds the provider before it binds you

The marking obligation for AI-generated text in Article 50(2) falls on providers of the generative system, meaning the company that develops and places the system on the market under its own name, which for most outbound teams is a sending platform vendor or a model vendor sitting behind it.

This distinction does most of the work in the argument, and it is the part the compliance decks skip. If you licence a sequencing tool and use its drafting feature, you are a deployer. The duty to make the output detectable as artificially generated attaches upstream of you. You cannot discharge a marking duty you do not hold by pasting a sentence into a footer, and the sentence in the footer is not machine-readable marking in any case, which is what paragraph 2 asks for.

Then read paragraph 4 for what it actually scopes. Deployer disclosure is triggered by deepfakes and by AI-generated text published with the purpose of informing the public on matters of public interest, with an exception where the content has undergone human review and someone holds editorial responsibility. A prospecting email sent to one named person at one company to sell them software is not published to inform the public, and it is not about a matter of public interest. It is commercial correspondence.

“The safe position is a disclosure in the email footer. That sentence is doing a lot of work in a lot of decks, and the article it claims to implement does not contain it.”

None of this makes the footer harmful. A team that wants to disclose can disclose. It makes the footer a preference rather than a control, and it matters because teams have finite compliance attention and are currently spending it on the wrong paragraph. The same failure shows up in outbound measurement, where teams read a complaint rate off a sample far too small to carry it and then act on the number with total confidence.

Where an AI SDR genuinely does touch Article 50

One outbound configuration does sit close to Article 50(1): an autonomous agent that holds a back-and-forth conversation with a prospect, replying in thread without a human drafting each response, because that is a system intended to interact directly with natural persons.

The duty in paragraph 1 still names providers, so the primary question is who built the agent. The question that follows is whether the person on the other end would find it obvious they are talking to software, because paragraph 1 carves out cases where the AI nature is obvious to a reasonably well informed, observant and circumspect person. An agent that signs off with a human name, a human job title and a human headshot is engineered to defeat exactly that test. That is the configuration to look at, and it is a design decision your team made, not a footer.

OUTBOUND CONFIGURATIONWHO HOLDS THE ARTICLE 50 DUTYPRACTICAL EXPOSURE
Rep drafts, model edits or rewritesProvider, under paragraph 2, and the assistive editing carve-out may applyEffectively none for the sending team
Model drafts at scale, rep reviews and sendsProvider, under paragraph 2Low. Human review and named sender responsibility are intact
Agent replies autonomously in thread under a human personaProvider, under paragraph 1, and the obvious-to-the-recipient test is in playReal. The persona is the risk, not the automation
Synthetic voice used for cold callingProvider and deployer both, plus national telecoms and consent rulesHigh, and the AI Act is the smaller of the problems

If you white-label a vendor's agent and put your own brand on it, get in writing which party that vendor considers the provider for Article 50 purposes before you launch. That single question belongs in every outbound vendor review from now on, and it is worth more than the entire questionnaire most teams are currently sending.

Whether a cold email may lawfully be sent to a European recipient is governed by the ePrivacy Directive of 2002 and its national transpositions, not by the AI Act, and that regime has been enforced against outbound teams for two decades.

Article 13 of the ePrivacy Directive sets prior consent as the default for unsolicited commercial email to subscribers. The reason B2B outbound into Europe is not uniformly illegal is Article 13(5), which leaves it to each member state to decide whether the protection extends to legal persons as well as individuals. That single deferral is why the answer changes at every border. France, the Netherlands, Ireland and Sweden broadly permit unsolicited email to corporate addresses provided the sender is identifiable and an opt-out is present. Germany does not: Section 7 of its Unfair Competition Act treats email advertising without prior express consent as unreasonable harassment and applies the same standard to business recipients as to consumers, with double opt-in as the practical evidentiary bar, a position documented in DLA Piper's Data Protection Laws of the World survey for Germany.

So the compliance question for a European sequence is not what wrote the email. It is which country the recipient sits in, and whether that country extended the consent requirement to companies. A team running one sequence across the EU on one legal theory is running twenty-seven experiments and reporting one result. Anyone who has watched Google's DMA changes play out differently across EU member states already knows how badly a single European average hides the variance underneath it.

01Geography is the first filter, not the copySegment the European portion of any list by member state before you write a line. The legal question resolves per country, and the answer materially changes whether the sequence can run at all.
02Germany is a hard stop, not a risk tierSection 7 UWG carries no B2B exemption. Competitors and trade associations can issue cease-and-desist warnings, which makes enforcement continuous and cheap for the complainant rather than dependent on a regulator opening a file.
03Identifiability is not optional anywhereEvery transposition that permits B2B outbound conditions it on the sender being clearly identifiable and an opt-out being present. Alias domains and unattributed personas undercut the exemption the campaign is relying on.
04Consent records are the artefact that gets requestedWhere a member state requires consent, the question asked later is always evidentiary. A list provider's assurance is not a consent record, and it will not read as one.

The disclosure you actually owe is where you got the address

GDPR Article 14 requires that when personal data is obtained from somewhere other than the person themselves, that person is told what was collected, why, on what legal basis, and critically from which source, at the latest at the time of the first communication with them.

Every cold email built on a purchased or scraped list is squarely inside that article. The data did not come from the person. You are communicating with them. The notice is due at first contact, which is the email itself. Most outbound programmes we audit have no Article 14 notice anywhere in the sequence, no link to one, and no record of the source that would let them write one honestly. That is a live gap under the tier of GDPR penalties that runs to 20 million euros or 4% of worldwide turnover, and it has nothing to do with any model.

There is a neat irony in it. The industry spent August buying a disclosure it does not owe while continuing to skip the disclosure it does. The one that is actually required is also the more useful of the two: telling a stranger how you found them is the single line most likely to defuse the reaction a cold email provokes, and it costs you one sentence.

REGIMEWHAT IT ACTUALLY ASKS OF AN OUTBOUND PROGRAMMEIS A PRODUCT BEING SOLD FOR IT
AI Act Article 50Mostly provider-side marking and interaction notices, narrow deployer duties that exclude commercial one-to-one mailYes, extensively, since August 2026
ePrivacy Article 13 as transposedPer-country determination of whether B2B addresses need prior consent, plus sender identifiability and opt-outRarely, and usually as a single EU-wide claim that is wrong somewhere
GDPR Article 6(1)(f)A documented legitimate interests assessment, with Recital 47 acknowledging direct marketing may qualifyOccasionally, as a template nobody completes
GDPR Article 14Tell the person what you hold and where you got it, at the latest at first communicationAlmost never, and this is the live gap
THE REFRAMEUnder the AI Act you are, in the ordinary case, a deployer of somebody else's system and the transparency duties largely sit with them. Under GDPR you are the controller, in your own name, with no upstream vendor to inherit the obligation from. Spend your attention where you hold the duty.

How to run an EU AI Act cold email review in an afternoon

A defensible EU AI Act cold email review takes about three hours and produces four artefacts: a provider determination for each sending tool, a persona audit, a per-country list segmentation, and an Article 14 notice wired into the first touch of every sequence.

Start with the vendor determination, because it is one email and it unblocks the rest. Ask each outbound tool in writing whether it considers itself a provider under Article 50 for the text its features generate, and whether it applies machine-readable marking under paragraph 2. Keep the answer. A vendor that cannot answer that question in September 2026 is telling you something useful about the rest of their compliance posture.

Then audit the personas, because that is where the only genuine AI Act exposure in most outbound stacks lives. Any automated agent replying in thread under an invented human identity should either get a human behind it or lose the human costume. Then segment by member state, and treat Germany as its own workflow rather than a risk score. Then write the Article 14 notice and link it from the first email in every sequence that touches an EU recipient.

None of that requires a new tool, and none of it is what was being sold in August. It also sits alongside the deliverability work rather than replacing it, because a legally impeccable sequence that lands in spam is still a dead sequence: the authentication and sending-domain discipline that DMARC enforcement now demands is a separate and equally unavoidable project. For B2B software companies selling into Europe, both are table stakes, and we build them into cold email engagements as standard rather than treating compliance as a bolt-on. The approach that worked for TechTrust's regulated pipeline was exactly this ordering: establish what is lawful per market first, then optimise the sending.

DO THIS NEXTOpen the first email of your highest-volume European sequence. If it does not say where you got the recipient's address, you have found a real compliance gap, and it is not the one you were sold a fix for in August. Write that sentence today, then send the provider question to your sending vendor.
Does the EU AI Act require me to disclose that AI wrote my cold email?No. Article 50(2) places machine-readable marking on the provider of the generative system, and the deployer duty in Article 50(4) covers deepfakes and text published to inform the public on matters of public interest.
When did Article 50 start applying?2 August 2026, under the application timetable in Article 113 of Regulation (EU) 2024/1689.
What is the fine for breaching Article 50?Article 99(4) sets a ceiling of 15 million euros or 3% of total worldwide annual turnover for the preceding year, whichever is higher. For SMEs and start-ups the lower of the two applies.
Am I a provider or a deployer of my sending tool?If you licence a tool and use it as supplied, you are a deployer. Ask the vendor in writing which party they consider the provider, especially if you white-label their agent under your own brand.
Is B2B cold email legal in the EU?It depends on the member state. Article 13(5) of the ePrivacy Directive lets each country decide whether the consent rule covers companies as well as individuals, so the answer changes at every border.
Why is Germany treated separately?Section 7 of the German Unfair Competition Act applies the same consent standard to business and consumer email with no B2B carve-out, and competitors can enforce it directly through cease-and-desist warnings.
What is the GDPR Article 14 obligation in a cold email?When you did not get someone's details from them, you must tell them what you hold, why, and from which source, at the latest at the time of first communication. For cold email that is the first email.
Can I rely on legitimate interests for outbound?Often yes. GDPR Recital 47 acknowledges direct marketing may be a legitimate interest, but Article 6(1)(f) requires a documented balancing assessment, and it does not displace the ePrivacy consent rules where those apply.
Does an AI SDR that replies on its own change the analysis?It is the one configuration that engages Article 50(1), which asks whether a person can tell they are interacting with an AI system. A synthetic human persona is what makes that test hard to pass.
Should I add the AI disclosure footer anyway?You can, and it does no harm. Treat it as a preference rather than a control, and do not let it absorb the attention that the per-country consent question and the Article 14 notice both genuinely need.

See where you are cited today

A free snapshot audit of your rankings and AI citations before we ever talk.

JB
Josh BernsteinMANAGING PARTNER, SOMETHING INC.

Josh leads work at the intersection of SEO and generative engines at Something Inc., helping B2B brands get ranked and cited across every major AI engine.

Free consultation

Let us be the last SEO agency you ever work with

A 30 minute call and a free audit of your SEO and GEO position. You keep the findings either way.