Something Inc.Schedule a free consultation
STRATEGY

The EU AI Act now reaches your cold email copy

Article 50 transparency obligations took effect on August 2, 2026, and the legal reads say they cover AI-generated sales email. Here is the part that actually applies to an outbound team.

TTTyler TruffiManaging Partner · AUG 15, 2026 · 11 MIN READ
Aug 2, 2026
date the EU AI Act Article 50 transparency obligations took effect
Dec 2, 2026
extended deadline for marking and detection duties on existing generative systems
EUR 15M
or 3% of global annual turnover, the stated ceiling for noncompliance
74%
of managers lacking full confidence they would pass a contact-data compliance audit (Propeller Insights, cited Aug 13, 2026)
TL;DR · 60 SECONDSThe EU AI Act cold email question stopped being theoretical on August 2, 2026, when Article 50 transparency obligations took effect. Law firm readings published that week say the rules cover AI-generated text, name sales and marketing explicitly, and attach to any provider or deployer whose outputs reach users in the EU. The practical exposure for an outbound team is narrower than the headlines suggest and wider than most teams assume, and the fixes are cheap. This is a summary of published legal commentary, not legal advice, and you should take the specifics to counsel.

Almost every outbound team now runs some version of the same machine: a model reads a prospect's site, writes a first line, and a sequencer sends it. Nobody in that chain has ever thought of themselves as deploying an AI system. As of August 2, 2026, European regulators disagree, and the reading that matters landed the following day.

Cooley published a client alert on August 3 walking through what came into force. The short version: Article 50 of the EU AI Act requires disclosure when a person is interacting with an AI system unless that is obvious, machine-readable marking of AI-generated synthetic content including text, and disclosure of AI-generated content published on matters of public interest unless a human has reviewed it. The alert states plainly that these rules apply to AI-generated emails and to any provider or deployer whose outputs reach EU users, across B2B, marketing and sales.

What changed on August 2

The AI Act has been law for a while. What happened on August 2 is that a specific chapter of it became enforceable, and it is the chapter about telling people when a machine made something. The obligations split into three that matter to a commercial team, and only two of them are likely to bite.

OBLIGATIONTRIGGERRELEVANCE TO AN OUTBOUND TEAM
Interaction disclosureA person is interacting with an AI system and it is not obviousHigh for AI SDR chat and reply-handling agents, low for a one-way send
Synthetic content markingContent is AI-generated or AI-manipulated, including textThis is the one that reaches cold email copy directly
Public-interest content disclosureAI-generated content published on matters of public interestLow for sales email, relevant to AI-written thought leadership
Extended marking deadlineGenerative systems already on the market before the dateBuys time to Dec 2, 2026 on the technical marking duty
Penalty ceilingNoncompliance with the transparency chapterUp to EUR 15M or 3% of global annual turnover

The third row is where most commentary goes wrong. A cold email pitching a security product is not content on a matter of public interest, and treating it as such produces compliance theater. The second row is the live one, and it is the row nobody in outbound has a process for.

Where the EU AI Act touches cold email

Work it through a normal sequence. A model enriches a prospect record, drafts a personalized opening line, and a human approves the template but not each individual send. The body of that email is, on any plain reading, AI-generated text delivered to a person. If that person sits in the EU, the marking obligation is in the frame.

Now change one thing. A human writes the template, the model only picks which of four pre-written variants to send, and the variable fields are pulled from a database rather than generated. That is closer to mail merge than to generation, and the risk profile drops sharply. The distinction between generated and selected is the single most useful line an outbound team can draw right now, and almost nobody has drawn it.

1Generated body copyThe model writes sentences that go to the prospect. Highest exposure under the marking obligation, and the most common pattern in 2026 outbound stacks because it is what every personalization feature ships by default.
2Generated research, human copyThe model reads the account and produces notes, a human writes the email from them. The output reaching the prospect is human-authored. This is the cleanest structure available and it also produces better email.
3Autonomous reply handlingAn agent answers inbound replies in the thread. This crosses from content marking into interaction disclosure, because a person is now conversing with a system. Treat this as the highest-risk pattern in the stack, not the most exciting one.

We have argued for a while that generated first lines underperform anyway, and there is data behind it: our teardown of AI-written versus human-written cold email spam flags found the generated variants carrying measurable deliverability cost before any regulator got involved. The compliance argument and the performance argument now point the same way, which is a rare and convenient thing.

The machine-readable marking problem

Here is where the obligation gets genuinely awkward for email. Machine-readable marking is a solved problem for images and audio, where provenance metadata standards exist and are shipping. For plain text in an email body, there is no widely adopted equivalent. You cannot watermark a sentence in a way a mail client will surface and a recipient will understand.

The extended deadline of December 2, 2026 for systems already on the market is the acknowledgement that this is unresolved. That is the window in which sending platforms will either ship a marking mechanism or lobby for a narrower reading. Either way, the operator response in the meantime is not to wait for the vendors.

THE PRACTICAL READVisible disclosure is available today and machine-readable marking is not. A short, plain line in the signature stating that parts of the message were drafted with AI assistance costs nothing, reads as candid rather than defensive, and demonstrates good faith if anyone ever asks. Pair it with a record of which sequences used generation, which is the artifact an audit would actually want. We build that record into the cold email programs we run as a matter of course now.
The obligation an outbound team can meet this month is not technical. It is telling the truth in one sentence and keeping a list of which campaigns a model wrote.

The EU AI Act, cold email, and senders outside Europe

The instinct of every US-based outbound team reading this is that it does not apply to them. That instinct has been wrong about European regulation four times running, and the alert language is explicit that the rules attach where outputs reach EU users regardless of where the deployer sits.

The realistic enforcement expectation is different from the legal scope, and it is worth being honest about both. Scope is broad. Early enforcement will concentrate on large deployers, consumer-facing systems, and cases with an obvious harm story. A twelve-person B2B company sending 4,000 emails a month is not the first target. That is a reason to be proportionate, not a reason to do nothing, because the cheap controls are cheap and the expensive ones are not required yet.

Autonomous AI reply agent, EU prospects in list90%
Model-written body copy, template approved once70%
Model-written research, human-written copy25%
Human template with database merge fields10%

Modeled exposure by outbound pattern, scored on the three factors that drive it: whether the model writes recipient-facing text, whether a human reviews before send, and whether EU recipients are in the list. Illustrative scoring, not a legal assessment.

The other reason to move now is that this is not arriving alone. The same week the obligations took effect, contact-data governance tooling started shipping explicitly against them: Convertr launched a product on August 13 aimed at enforcing source, supplier and policy controls on contact records before they reach a CRM, citing a Propeller Insights finding that 74% of managers lack full confidence they would pass a compliance audit of their lead data practices. Vendors do not build against a regulation they expect to be ignored.

The compliance work worth doing regardless

Strip out the legal framing and most of this is data hygiene an outbound team should already have. You need to know where every record came from, which supplier or scrape produced it, what basis you have for contacting that person, and which of your sequences were written by a machine. Three of those four are already required by GDPR for European contacts, which we covered when we looked at the legal exposure on guessed email addresses.

The fourth, the record of which sequences a model wrote, is new and trivial to build. It is a column in your campaign tracker. The reason nobody has it is that generation is buried inside the sending platform, applied per-send, and never logged at the campaign level. Logging it takes an afternoon and gives you the one artifact you cannot reconstruct after the fact.

If your record-of-origin discipline is weak more broadly, that is the deeper problem and the AI Act is only the newest symptom of it. The B2B data stack audit framework we published earlier this year is the version of this work that pays for itself independent of any regulator, and the same discipline underpins the outbound programs we run for regulated buyers across the B2B practice.

Your next two weeks

Two weeks is the right budget for this, and the reason is that the work is almost entirely discovery rather than engineering. Nothing here requires a platform migration, a legal opinion, or a new vendor. It requires knowing what your own machine is doing, which most outbound teams have never had to write down because generation arrived as a feature toggle rather than a decision.

Week one is inventory. List every sequence currently sending, mark which ones contain model-generated recipient-facing text, and flag which lists contain EU-based contacts. Most teams discover two things doing this: more sequences use generation than they thought, and their EU exposure is concentrated in one or two campaigns nobody remembers building.

Week two is the fix. Move your highest-volume EU-facing sequences from generated body copy to generated research with human-written templates, which lowers exposure and usually raises reply rate. Add a one-line disclosure to sequences that keep generation. Turn off autonomous reply agents on EU threads until your platform tells you how it handles interaction disclosure. Then write down what you did and when, because the record is the thing that matters if this is ever tested. Our work with regulated-sector clients like TechTrust starts from that same paper trail.

DO THIS NEXTThis week: inventory every sending sequence for model-generated recipient-facing text and flag EU contacts. Next week: convert your highest-volume EU sequences to human-written templates with AI-generated research behind them, add a plain disclosure line where generation stays, and pause autonomous reply agents on EU threads. Then keep a dated log of the change. This is a summary of published commentary and not legal advice, so route the specifics to your counsel before you rely on it.

The uncomfortable part of this rule is not the fine. It is that it forces outbound teams to say out loud how much of their personalization is a machine writing plausible sentences about a company it has never understood. Most teams will find the honest answer embarrassing, fix it, and send better email. The full alert is worth reading at Cooley's August 3 client update.

See where you are cited today

A free snapshot audit of your rankings and AI citations before we ever talk.

TT
Tyler TruffiMANAGING PARTNER, SOMETHING INC.

Tyler leads work at the intersection of SEO and generative engines at Something Inc., helping B2B brands get ranked and cited across every major AI engine.

Free consultation

Let us be the last SEO agency you ever work with

A 30 minute call and a free audit of your SEO and GEO position. You keep the findings either way.