Strategy·14 min read

AI Sales Compliance: The Four US Deadlines Hitting Outbound Before November

Updately Team·2026-09-13

AI sales compliance stopped being a 2027 problem this month

Most revenue teams have filed AI regulation under "legal will tell us." That filing decision made sense for two years. It stopped making sense in the last three weeks, because the US now has a dated calendar and one of the items on it is already a final, binding order against companies that sold an AI marketing capability they could not substantiate.

Here is the part that matters for a sales leader: three of the four deadlines below do not regulate your outbound directly. One of them does, and it is the one nobody in sales is reading. If you only take one thing from this post, take the FTC section.

The wider context is that AI is no longer a fringe part of the sales motion. Salesforce's 2026 State of Sales report, built on 4,050 sales professionals, found 87% of sales organisations now use AI in some form and 54% of individual reps have already used an agent. When something moves from 10% adoption to 87% adoption, the regulatory surface area stops being theoretical and starts being an operating constraint. The question is no longer whether rules arrive. It is which ones land on your desk versus your vendor's.

The four dates on the calendar

DateWhat happensWho it actually bindsSales urgency
Already in force (27 Aug 2026)FTC final order against Cox Media Group, MindSift and 1010 Digital Works over the "Active Listening" AI ad productAnyone making AI capability or consent claims in a sales processHigh — read this week
23 Sep 2026Colorado AG's revised draft ADMT and Chatbot Safety rules expectedDeployers of automated decision-making tech touching Colorado consumersMedium — plan for 1 Jan 2027
30 Sep 2026California governor's deadline on SB 1000, an urgency rewrite of the AI Transparency ActGenerative AI providers, not most sales teams — but your vendorsMedium — vendor question
Already live (1 Sep 2026)Texas AG's TRAIGA consumer AI complaint routeAnyone deploying AI systems touching Texas consumersLow volume, high documentation burden

The dates come from the September 2026 US AI regulatory update, which tracks each item against primary sources. None of this is legal advice, and every one of these is worth reading with your own counsel. What follows is the operator's translation.

The one that already binds you: the FTC's "Active Listening" order

On 26 August 2026 the FTC signed, and on 27 August finalised, its order in the matter of CMG Media Corporation. The FTC's own announcement lays out the facts plainly: Cox Media Group and two partner firms marketed a product called "Active Listening" that they said used voice data captured by consumers' smart devices, in real time, to target local ads. Three settlements totalling $930,000 — $880,000 from CMG, $25,000 each from MindSift and 1010 Digital Works — plus, per reporting on the order's terms, two decades of compliance obligations.

The dollar figure is not the story. The two failure modes are.

Failure mode one: the capability claim you cannot substantiate

The FTC alleged the service did not use voice data at all, and did not place ads in the locations promised. That is a garden-variety deception case wearing an AI costume. But the reason it should make a revenue leader uncomfortable is that "our AI does X" claims are now standard issue in B2B sales decks, and very few of them have a substantiation file behind them.

Ask yourself, honestly, about the claims your team makes in a live deal:

  • When a rep says the product "learns from your data," can you produce the mechanism, or is that a marketing abstraction that has drifted into a factual assertion?
  • When a deck says "AI-powered personalisation," does the system genuinely personalise per recipient, or does it fill three merge fields from a template?
  • When someone answers a security questionnaire about what the model does with customer inputs, is that answer written by someone who has read the actual data flow?
  • When a case study quotes a lift number, do you have the underlying measurement, including the control?

The standard the FTC applies is substantiation at the time the claim is made. Not substantiation you assemble after an inquiry. If a claim about an AI capability is made in a sales conversation, someone at your company needs to be able to produce the evidence for it, and that someone should not be discovering the gap during a civil investigative demand.

This is the sharper edge. The FTC found the three firms told their small-business customers that end users had opted into Active Listening simply by accepting standard app terms of service. The Commission's position: clicking through mandatory terms does not constitute opt-in consent for collecting voice data inside someone's home.

That reasoning does not stay in the smart-speaker aisle. It is a general statement about the distance between a technical legal basis and a consent a regulator will recognise. Every outbound team in 2026 runs on data with a consent story attached — enrichment providers, intent vendors, contact databases, engagement signals. Most sales leaders have never read the consent story. They have read the vendor's one-line assurance about it.

The practical test is not "did our vendor say the data is compliant." It is: if a regulator asked how this specific person's data came to be in our sequence, could we answer with a mechanism rather than a contract clause?

That question has a very different answer depending on where your pipeline comes from. Which brings us to the structural point later in this post.

The SEC moved on a related theme the same week, charging GenesisAI Corp. and its founder over misleading statements about an AI marketplace's revenue, valuation, partnerships and customer demand, with consented proposed judgments including $50,000 in disgorgement and a $50,000 civil penalty against the founder. Different agency, different audience, same underlying pattern: AI capability claims are now being tested against evidence.

Colorado: 23 September, and the deployer duties most people misread

Colorado is the state doing the most detailed work. Its AI framework was repealed and reenacted by SB 26-189, signed 14 May 2026, which builds developer and deployer duties around automated decision-making technology with a 1 January 2027 commencement. A companion law, HB 26-1263, the Chatbot Safety Act, covers operators of consumer conversational AI services — age estimation, AI disclosure, protections for known minors, self-harm protocols, annual reporting to the attorney general.

On 11 August 2026 the attorney general filed proposed rules implementing both. Comments received by 4 September feed a revised draft expected by 23 September, with the formal comment period open through 26 October.

What this does and does not cover for a B2B sales team

A lot of GTM commentary has treated Colorado as "the AI law that regulates AI sales tools." That is imprecise enough to be misleading. The framework centres on consequential decisions about consumers — the classic categories are employment, lending, housing, insurance, education, healthcare. A B2B prospecting sequence is not, on its face, a consequential decision about a consumer.

Where B2B teams do get pulled in:

  • You sell into regulated buyers. If your ICP includes HR tech, lending, insurance or healthcare, your buyers are about to inherit deployer duties, and your security and procurement questionnaires will grow a new section. Sellers who can answer it cleanly in Q4 will move through evaluation faster than sellers who cannot.
  • Your own hiring uses automated screening. Most GTM orgs run resume screening on some AI-assisted tool. That is squarely a consequential decision, and it sits inside the sales org's own hiring process.
  • Consumer-facing chat. If the same company runs a consumer product with a conversational AI service, HB 26-1263's duties attach regardless of what the B2B side is doing.
  • Documentation habits transfer. The purpose, data, input and output, performance, and safeguard documentation the rules contemplate is the same documentation you will want when a large enterprise buyer's security review asks how your AI outbound works.

The honest read: Colorado is a 2027 planning item for most outbound teams and a 2026 emergency for a minority. Know which you are before you either panic or ignore it.

California SB 1000: a vendor question, not a sales question

SB 1000 is an urgency rewrite of the California AI Transparency Act. It passed the legislature on 27 August, was enrolled 30 August and presented to the governor on 2 September. The governor has until 30 September to act, and because the bill carries an urgency clause, its changes would take effect on signing rather than on 1 January 2027.

The consequential change, as summarised in Wiley's session wrap-up, is the removal of the one-million-monthly-user threshold from the definition of a covered provider. The Act, as amended by AB 853, became operative on 2 August 2026 for providers above that threshold. Strip the threshold out and a much longer tail of generative AI providers becomes covered — with a disclosure verification tool replacing the AI detection tool, and revised latent-disclosure and licensee-compliance provisions.

Unless you build and offer a generative AI system, this is not your obligation. It is your vendors'. Which makes it a procurement question with a real deadline attached:

  • Which of your GTM vendors are covered providers of generative AI systems accessible in California?
  • If SB 1000 is signed on, say, 28 September, which of them acquire duties that day rather than in January?
  • Does any of your outbound depend on a vendor feature that a disclosure or provenance requirement would change?
  • Has any vendor told you, unprompted, what its plan is? The ones who have are the ones to keep.

Texas rounds out the list quietly. TRAIGA required the attorney general to publish an online AI complaint mechanism by 1 September 2026, and the office's Consumer AI Rights page now carries a File an AI Complaint link into the consumer complaint portal. There is no private right of action for the AI-protection provisions, so the practical effect is not a wave of lawsuits. It is that a complaint can now start a chain that ends in a civil investigative demand — and the documentation an AG can request should exist before the demand arrives, not after.

The pattern underneath all four: provenance is becoming the product

Read the four items together and the common thread is not "AI is banned." It is that regulators are converging on two questions, and they are the same two questions in every jurisdiction:

  1. Can you substantiate the claim you made about what the system does?
  2. Can you explain, mechanically, why you had this person's data and why you were allowed to use it this way?

Neither question has anything to do with how much AI you use. Both have everything to do with whether your motion has provenance.

This is where volume-first outbound has a structural problem that no amount of compliance training fixes. If your pipeline is built by scraping a list, enriching it against three vendors whose sourcing you have not read, and sequencing it at 2,000 contacts a week, then question two has no good answer. Not because anyone did anything malicious, but because the motion was never designed to produce one. The audit trail for "why this person, why now" is an export ID.

Signal-based outbound answers both questions almost incidentally, because the answer is the reason the message exists:

  • The trigger is the audit trail. "This person viewed our profile," "this person commented on a post about the problem we solve," "this company posted a role that implies the pain," "this person asked publicly for a recommendation in our category." Each of those is a specific, timestamped, observable public action. It is a reason, and it is also a record.
  • Consent basis is narrower and cleaner. You are acting on a public professional signal on a platform built for professional contact, not on inferred data whose origin you cannot trace.
  • The claim you make is smaller. "I saw you asked about X" is a statement you can substantiate. "Our AI identified you as a high-intent buyer using 400 proprietary data points" is a claim someone may one day ask you to prove.
  • Volume falls, so the surface area falls with it. Fewer, better-warranted touches means fewer opportunities to be wrong about someone.

This is the design principle behind how Updately works: capture the signal that justifies the outreach, enrich and score against ICP from there, and write the message from the specific reason rather than from a persona template. The compliance benefit was not the original point — the reply rate was — but the two turn out to be the same discipline viewed from different angles.

What to do this week: a 60-minute audit

You do not need a compliance programme by Friday. You need to know where you stand. Block an hour with your RevOps lead and answer these in writing:

  • Claims inventory. List every factual claim about AI capability that appears in your deck, website, one-pagers and standard security questionnaire answers. Mark each one green (we can produce evidence today), amber (we could assemble it), red (it is marketing language pretending to be a fact). Fix the reds first — usually by softening the language, not by building the feature.
  • Data provenance map. For each source feeding your sequences, write one sentence on where the data originates and what the consent basis is. Any source you cannot describe in a sentence is a source you do not understand.
  • Vendor deadline list. Identify which GTM vendors would become covered providers if California SB 1000 is signed by 30 September. Email them one question: what changes for us if it is signed?
  • Regulated-buyer readiness. If your ICP includes employment, lending, insurance or healthcare, draft the Colorado section of your security questionnaire answer now, before a buyer asks in November.
  • Disclosure position. Decide, as a policy, whether AI-assisted outreach is disclosed in your motion and where. You want a stated position you can defend, not an ad-hoc answer a rep improvises on a call.
  • Named owner. One person owns the AI compliance calendar. Not "legal" as an abstraction. A name, with the 23 September and 30 September dates in their calendar.

Takeaways

  • The FTC's Cox Media order is the item that already binds you. Final since 27 August, $930,000 across three settlements, obligations running two decades, and built on two failure modes — unsubstantiated AI capability claims and consent that was really just terms-of-service click-through — that show up in ordinary B2B sales motions every day.
  • Colorado's 23 September revised draft is a planning item, not an emergency, unless you sell into regulated buyers or use automated screening in your own hiring. Read it against your inventory before the 26 October comment close.
  • California SB 1000 is a vendor question with a 30 September answer. Removing the one-million-user threshold pulls in a long tail of providers, and the urgency clause means it bites on signing.
  • Texas has opened the front door. A complaint route is live; the documentation an attorney general can demand should already exist.
  • The through-line is provenance. Regulators are asking whether you can substantiate your claim and explain why you had this person's data. Those are design questions about your motion, not paperwork questions about your policies.
  • Volume-first outbound answers neither question well. Signal-led outbound answers both as a side effect of being built around a specific, observable reason to reach out — which is also, conveniently, the thing that makes people reply.

The teams that will handle the next eighteen months comfortably are not the ones with the biggest compliance function. They are the ones whose outbound already has a reason attached to every message, because the reason is the answer to every question a regulator, a buyer's security team, or a sceptical prospect is going to ask.