Strategy·13 min read

AI Outbound Compliance in 2026: The Three August Rulings That Change How You Prospect

Updately Team·2026-08-28

AI outbound compliance stopped being a hypothetical in August 2026

For three years, every conversation about AI SDRs and regulation ended the same way: "something is coming, but not yet." As of this month, it arrived. Three separate developments landed inside nine days, and together they redraw the operating boundaries for any team running AI-assisted outbound into Europe or automating actions on third-party platforms.

Here they are, in order:

  • 2 August 2026 — Article 50 of the EU AI Act became applicable. AI systems that interact directly with people must disclose that they are AI, and generative systems must mark their outputs as machine-detectable. Fines run to €15 million or 3% of worldwide turnover, whichever is higher. (European Commission FAQ)
  • 4 August 2026 — The US Ninth Circuit vacated the injunction against Perplexity in Amazon's case, holding that when a user directs an AI agent, it is the user who "accessed" the site under the Computer Fraud and Abuse Act, not the AI company. (Cooley alert)
  • 11 August 2026 — France switched from an opt-out to a full opt-in regime for telephone marketing to individuals. Bloctel, the national do-not-call register, ceased to exist. (National Law Review)

None of these were aimed at B2B sales teams specifically. All three hit them anyway. And the practical consequence is not "stop using AI in outbound" — it is that the volume-first, spray-and-disclose-nothing model that a lot of AI SDR tooling was built on now carries real legal exposure, while signal-based, consent-aware, human-reviewed outbound gets comparatively easier to defend.

This post walks through what each rule actually says, what it does not say, and the specific changes worth making to your outbound motion before Q4 planning locks.

What EU AI Act Article 50 actually requires

Article 50 is the transparency chapter of the AI Act. It applies from 2 August 2026 to all in-scope systems regardless of when they were placed on the market, and it applies extraterritorially: if you are a US company whose AI system's output is used inside the EU, you are in scope. Enforcement sits mainly with national market surveillance authorities.

The Commission adopted its guidelines on 20 July 2026, and the FAQ published alongside them is unusually readable. Four obligations sit inside the article, split between providers (who build and place systems on the market) and deployers (who use systems under their own authority — that is you, the sales team).

The four obligations, and which ones touch outbound

ObligationWho it bindsDoes it touch B2B outbound?
50(1) — disclose that a person is interacting with an AI systemProviderYes, for AI chat, voice agents and live two-way AI conversations
50(2) — machine-readable marking of synthetic audio, image, video, textProviderIndirectly; narrow B2B/industrial exemption exists
50(3) — inform people exposed to emotion recognition or biometric categorisationDeployerYes, if you run sentiment or emotion scoring on calls
50(4) — label AI-generated text published on matters of public interestDeployerRarely; a one-to-one sales email is not "published to inform the public"

The one most people assume applies to outbound email — 50(4) — mostly does not. That obligation requires text to be published, informative to the public, and on a matter of public interest such as politics, public health, justice or economic developments subject to public debate. A personalised LinkedIn message about your data pipeline product fails all three tests. You do not have to stamp "written by AI" on every cold email.

The one that genuinely bites is 50(1). The Commission's guidance sets out four cumulative criteria: the system must be an AI system, designed for a genuine two-way exchange rather than one-way automated responses, communicating directly rather than through a human intermediary, and interacting with natural persons. That describes an AI voice agent qualifying inbound leads. It describes a website chat agent handling live conversations. It describes an autonomous AI SDR that replies in-thread without a human in the loop.

Critically, the "unless it is obvious" exception is to be read narrowly. The test is whether a reasonably well-informed, circumspect and observant person would find it obvious. An AI voice agent that opens with a human-sounding name and no disclosure fails that test comfortably.

The B2B carve-out that people are missing

Article 50(2)'s marking obligation — the watermarking one — has a narrow exemption envisaged for outputs used in business-to-business or industrial contexts, subject to conditions in the guidelines. There is also a grace period: providers with generative systems already on the market before 2 August have until 2 December 2026 to comply with marking and detection. Content generated before 2 August does not need retroactive labelling.

So the honest reading for most GTM teams is this. Your AI-drafted emails are not suddenly illegal. Your AI voice agent needs a disclosure line in its opening. Your call-sentiment scoring tool needs a notice. And the vendor questions you should be asking are about their Article 50(1) and 50(2) posture as the provider, because you inherit the operational consequences.

France just made consumer cold calling an opt-in channel

The French change is narrower in scope but far more absolute in what it prohibits. Under Law n° 2025-594 of 30 June 2025, from 11 August 2026 telephone canvassing of individuals in France — carried out directly or through a third party — is prohibited unless the caller has obtained prior consent to GDPR standard: free, specific, informed, unambiguous and revocable. The burden of proof sits with the caller.

Bloctel, the opt-out register businesses previously screened against, no longer exists. The default flipped.

The exceptions are tight:

  • Calls relating to an existing contract and connected to its subject matter, including performance of the contract, complementary products or service improvements. If the person objects, the call ends immediately and you do not call again.
  • Non-commercial communication, such as charitable fundraising, where the individual was informed at collection and can object easily and free of charge.

Layered on top are the rules already in force since March 2023: calls only Monday to Friday, 10:00–13:00 and 14:00–20:00, none on weekends or public holidays, and no more than four contact attempts to the same consumer in any 30-day period. Marketing calls from 06 and 07 mobile prefixes remain banned.

The penalties are the part that changes behaviour. Any contract concluded following canvassing in breach of these rules is void. Administrative fines reach €75,000 for a natural person and €375,000 for a legal person, and sanctions are published at the offender's expense.

Does this apply to B2B calls?

The law targets canvassing of individuals — consumers. Pure business-to-business calling to a company switchboard is not the intended target. But two things make complacency risky.

First, the line between "consumer" and "professional" is blurrier than sales teams assume. A sole trader, a freelancer, a one-person consultancy: these are natural persons whose mobile number is both personal and professional. If your data provider surfaced a mobile number scraped from a personal profile, you are relying on a classification you cannot prove.

Second, French regulators have been tightening telemarketing for years and the direction of travel is one-way. Building a French calling motion that depends on an aggressive reading of the B2B boundary is a bad bet for 2027.

The practical response is not to abandon France. It is to stop treating the phone as a top-of-funnel discovery channel there and start treating it as a second touch that follows an interaction the prospect actually initiated.

The Perplexity ruling: good news for agents, not a licence to scrape

On 4 August, the Ninth Circuit vacated the preliminary injunction that had barred Perplexity's AI agent from acting on Amazon.com on users' behalf. The panel held that "access" under the CFAA means entering a computer system, and the statute's "whoever" contemplates a person — so when a user directs the agent, it is the user who accessed Amazon's servers, with the agent's help.

The technical detail mattered enormously. Perplexity's Assistant took screenshots on the user's own machine and sent them to Perplexity's servers, which returned navigation instructions to the user's computer. Perplexity's systems never communicated directly with Amazon's. That routing is what distinguished the case from earlier precedent where the defendant's own servers transmitted directly onto the platform.

Three limits keep this from being the green light some people read it as:

  1. It is CFAA and CDAFA only. The court expressly left open contract and tort theories, including breach of terms of service. Platform ToS remains the live risk for anyone automating on LinkedIn, and the ruling does nothing to change that.
  2. It is fact-specific. The panel flagged that agents with greater autonomy, or whose company servers talk directly to the target site, could still create liability.
  3. It is a preliminary-injunction posture. This is a likelihood-of-success assessment on the current record, not a final merits ruling.

For GTM teams, the takeaway is architectural, not permissive. Tools that operate through the user's own authenticated session, at the user's direction, under the user's own account limits, sit in a materially better legal and platform position than tools that hit a platform's servers from a datacentre with a pool of stolen cookies. That distinction has been the difference between safe and reckless LinkedIn automation for years. A federal appeals court just gave it doctrinal weight.

What this collectively means for outbound strategy

Read the three developments together and the same pattern appears in all of them. Regulators and courts are not asking "was AI involved." They are asking three different questions:

  • Was the person told? (AI Act Article 50)
  • Did the person agree to be contacted? (French opt-in regime)
  • Whose account, and whose instruction, actually performed the action? (Perplexity)

Every one of those questions is harder to answer well when your outbound motion is built on volume and easier to answer well when it is built on signals. That is not a coincidence. Volume-first outbound depends on contacting people who have shown you nothing, from infrastructure that is not really theirs, with content nobody reviewed. Each of those is now a liability surface.

The compliance profile of volume vs signal-based outbound

DimensionHigh-volume cold outboundSignal-based warm outbound
Basis for contactPurchased list, no interactionProspect viewed your profile, engaged a post, posted a pain point publicly
Article 50(1) exposureHigh if AI agents reply autonomously in-threadLow if AI drafts and a human sends
French telemarketing riskSevere — no consent, no prior relationshipLower — phone follows an inbound-ish interaction
Platform ToS riskHigh — datacentre automation, volume far above human normsLower — actions inside the user's own session and limits
Evidentiary positionCannot show why this person was contactedCan point to the specific signal and timestamp

That last row is the underrated one. Regulators and platforms both ask a version of "why this person, why now." A team that can answer "she viewed our founder's profile on Tuesday and commented on a post about warehouse routing on Wednesday" is in an entirely different position from one that answers "she was in a 40,000-row export."

Seven things to change before Q4 planning locks

1. Inventory every AI system that talks to a human

Not every AI tool in your stack triggers Article 50. The ones that hold a two-way conversation with a natural person do. List them: voice agents, live chat, autonomous email responders, meeting-booking bots. For each, confirm the provider has addressed 50(1) and get it in writing.

2. Add a disclosure line to any conversational AI, then measure it

If you run an AI voice or chat agent in Europe, the disclosure must land at or before the first interaction, clearly and distinguishably. Teams fear this tanks conversion. Test it rather than assuming it — in most deployments the drop is smaller than expected, and being caught undisclosed is far more expensive than a few points of connect rate.

Segment your French data by whether you hold provable consent, an existing contractual relationship, or neither. The third bucket is not callable. Move it to channels where the rules differ, and route phone effort to the first two.

4. Keep a human in the send loop

The cheapest compliance control available is also good sales hygiene. AI drafting plus human approval keeps you outside 50(1)'s two-way-exchange criterion, keeps you inside the human-review carve-out where labelling questions arise, and stops the AI-slop messages that are already destroying reply rates independent of any regulation.

5. Audit how your automation actually connects

Ask every outreach vendor a direct question: does your system communicate with the platform from your servers, or through my authenticated session on infrastructure tied to me? The Perplexity reasoning makes the answer legally relevant, and it has always been operationally relevant to account safety.

6. Log the signal that justified every touch

Store, per contact, the signal that triggered outreach and its timestamp. This is a five-minute schema change that gives you a defensible record, a better retro on which signals convert, and a straight answer if a platform or regulator ever asks.

7. Cut volume and raise relevance, on purpose

The regulatory direction and the performance data now point the same way. Reply rates have been sliding for two years as inbox volume climbed. Every rule above raises the cost of untargeted contact and leaves targeted contact largely untouched. Volume was already a losing strategy commercially. It is now a losing strategy legally too.

Where signal-based tooling fits

The reason we build Updately around warm intent signals rather than list volume is a commercial one: people who just looked at your profile, engaged with your content, complained about a competitor or posted a hiring signal reply at multiple times the rate of a cold list. The compliance picture in August 2026 makes that architecture look better for a second reason.

Signal capture gives you a documented reason for every touch. Sending inside the user's own LinkedIn session and within human-plausible limits sits on the safer side of the Perplexity distinction and of platform ToS. AI that researches and drafts while a human approves and sends keeps you out of the two-way autonomous interaction category. None of that is legal advice, and none of it substitutes for counsel who knows your jurisdictions — but it is the shape of an outbound motion that does not need re-architecting every time a regulator moves.

Takeaways

  • Article 50 applies now, but narrowly. Conversational AI needs disclosure. One-to-one AI-drafted sales emails almost certainly do not fall under the public-interest labelling obligation. Fines reach €15 million or 3% of global turnover, so the assessment is worth doing properly.
  • Providers have until 2 December 2026 for marking and detection on generative systems already on the market. Ask your vendors where they stand and whether they signed the Code of Practice.
  • France is now opt-in for consumer telephone marketing. Bloctel is gone, contracts from non-compliant calls are void, and fines reach €375,000 for companies. Treat sole traders and freelancers as the risk zone.
  • The Perplexity ruling helps AI agents on CFAA grounds only. Terms-of-service claims survive intact, so LinkedIn automation risk is unchanged. How your tool connects — user session versus vendor servers — now matters legally as well as operationally.
  • Signal-based outbound is the compliant shape by default. Consent-adjacent basis for contact, human review before send, action inside the user's own account, and a logged reason for every touch.

The teams that will be worst affected by all this are the ones running the highest-volume, least-personalised, most fully autonomous outbound — which is to say, the teams already getting the worst results. If August 2026 forces a rebuild around fewer, warmer, better-justified touches, most GTM orgs will end the exercise with a better funnel than they started with.

Sources: European Commission — Transparency obligations under Article 50 of the AI Act · Cooley — EU AI Act: Transparency Obligations Take Effect 2 August 2026 · Cooley — Ninth Circuit Rules on AI Agent 'Access' to Third-Party Websites Under CFAA · National Law Review / Squire Patton Boggs — New Restriction to Telephone Canvassing in France · European Commission — Guidelines on transparency obligations