Skip to content

AI SDR Disclosure: CAN-SPAM Asks Who Sent It, LinkedIn Bans the Bot

CAN-SPAM does not make your AI SDR admit it is a machine. The made-up name it signs with is the bigger exposure, and on LinkedIn the disclosure question barely matters, because the platform bans the bot.

That is the short answer from the texts I read on 24 September 2026. CAN-SPAM asks whether an email identifies the business that sent it, not whether a human typed it. California’s bot law is written for public-facing websites and apps, including social networks, which puts LinkedIn inside it more clearly than email. LinkedIn’s own User Agreement forbids bots sending messages at all. And since 2 August 2026, the EU AI Act has required AI systems that talk directly to people to say so. I build cold email infrastructure, so I read these from the sending side.

The persona your AI SDR signs with is a bigger risk than the fact that it is an AI.

The mistake: treating disclosure as the whole question

The obvious question is whether every email needs a “written by AI” line. It is the wrong first question.

An AI SDR can be three things in one box: software that writes, software that sends and replies on its own, and a persona with a human name. The rules treat those three very differently. The ones I read barely touch the writing. They reach the persona and the autonomous sending.

What US email law actually asks

CAN-SPAM’s requirements, as the FTC lists them, never ask who or what wrote a message. They ask whether the header is honest. Section 7704 makes materially false or misleading header information unlawful, and the FTC’s compliance guide spells it out: your From, To, Reply-To and routing information must identify the person or business who initiated the message. The Act gives a From line a safe harbour when it accurately identifies any person who initiated the message.

A persona called Sarah who does not work at your company is not a person who initiated anything, so her name alone does not earn that safe harbour. That is not automatically a violation. The Act’s definition of materially includes altering or concealing header information in a way that impairs anyone’s ability to identify, locate or respond to the sender, and with your real domain and postal address in the email, Sarah may never get there. I still would not build a campaign on the gap when the FTC puts the penalty at up to $53,088 for each violating email.

What the AI SDR pitch sells

A persona with a human name and a headshot, sending and replying with nobody reading first.

A composite of the pitch, not any single vendor.

What CAN-SPAM and PECR ask

A header that identifies the business behind the email, and a working way to opt out.

15 U.S.C. 7704 and PECR regulation 23, read 24 September 2026.

The UK rule has the same shape. Regulation 23 of PECR bars marketing email where the identity of the person on whose behalf it was sent has been disguised or concealed. It protects the identity of whoever the email is sent for. It says nothing about who drafted it.

Where a bot has to say it is a bot

California asks the other question. Its bot law, operative since July 2019, makes it unlawful to use a bot to communicate with a person in California online, with intent to mislead them about its artificial identity, in order to sell them something. Disclose that it is a bot, clearly and conspicuously, and you are not liable under that section.

Two definitions decide whether it reaches you. A bot is an automated online account where all or substantially all of the actions are not the result of a person. Online means a public-facing website or app, including a social network. A LinkedIn message fits those words squarely. An email is arguable either way, and I would not rely on either reading. The chapter itself names no penalty.

On LinkedIn, a disclosure line fixes nothing

Section 8.2 of LinkedIn’s User Agreement, in the version effective 3 November 2025, lists what members agree not to do. Two lines matter here. You will not create a false identity or a profile for anyone other than yourself, a real person. And you will not use bots or other unauthorized automated methods to add contacts or send messages.

So an autonomous agent sending connection requests from a persona account breaks that contract twice before California’s question comes up. Adding “I am an AI” to the message repairs neither breach. A disclosure can satisfy California. It cannot satisfy LinkedIn.

In the EU, the label became law on 2 August

Article 50(1) of the AI Act requires providers to design AI systems intended to interact directly with natural persons so those people are told they are dealing with an AI, unless that is obvious to a reasonably well-informed person. Article 50(5) says the information must arrive at the latest at the first interaction. An AI SDR that writes to a named person and answers their replies without a human is, on a plain reading, interacting directly with them.

2 Aug 2026the date the EU AI Act’s duty to tell people they are talking to an AI began to apply
€15Mor 3 per cent of worldwide turnover, the ceiling for an Article 50 breach
$53,088the FTC’s maximum penalty for each email that breaks CAN-SPAM

The duty has applied since 2 August 2026. The AI Omnibus that pushed back the high-risk rules left it in place. It reaches providers outside the EU when the system’s output is used in the Union, and a breach can cost up to €15 million or 3 per cent of worldwide turnover, whichever is higher, or whichever is lower for an SME.

Here is the part worth reading twice. A provider is not only the company that develops the system. It is also one that has an AI system developed and puts it into service under its own name. If a client commissions a custom AI SDR and runs it under the client’s brand, the definition points at the client. I read the Regulation’s text for this, not the Commission’s July guidelines, so treat it as a reading of the definition rather than settled practice.

Three moves before your next sequence goes live

01

Sign every email as a real person

Put the name of a real employee who owns the replies in the From line and the signature. That keeps you inside CAN-SPAM’s From line safe harbour and retires the persona problem everywhere else. The AI can still write every word.

02

Keep the AI off LinkedIn’s send button

Let it draft connection notes and replies, and let a person send them from their own account. Section 8.2 bans bots sending messages whether or not they announce themselves, and a person pressing send also makes California’s bot definition harder to meet.

03

Label the first email to EU prospects

One clear sentence at the top of the first message meets the timing in Article 50(5): this email was written by an AI assistant working for a named person at your company. If you commissioned the tool under your own brand, assume the duty is yours, not the vendor’s.

Which of these laws applies depends on where your prospect sits, not where your company is registered. I wrote separately about why the inbox decides which cold email law applies, and the same logic carries over to the AI rules.

The bottom line

The disclosure question is real, and narrower than it looks. CAN-SPAM asks who sent the message. California asks what sent it when a bot on a website or social network is selling. LinkedIn forbids the bot. The EU now wants the label at first contact.

I have built outbound systems for more than 200 businesses, and one setup answers all four: a real person’s name on every message, a person pressing send on LinkedIn, and one honest sentence for Europe. I am not a lawyer and this is not legal advice. It is what the texts say, read on the day I wrote this.

Frequently Asked Questions

In the US, CAN-SPAM does not ask whether a human wrote the email; it requires header information, including the From line, to identify the person or business who initiated the message. California’s bot law makes it unlawful to use an undisclosed bot to mislead a person in California online about its artificial identity in order to sell to them, and it defines online as a public-facing website or app, which reaches social networks more clearly than email. In the EU, Article 50(1) of the AI Act has required AI systems that interact directly with people to tell them so since 2 August 2026.
Not as an autonomous sender, under LinkedIn’s own terms. Section 8.2 of LinkedIn’s User Agreement, effective 3 November 2025, says members will not use bots or other unauthorized automated methods to add or download contacts or to send or redirect messages, and will not create a false identity or a profile for anyone other than themselves. A disclosure line in the message does not change either rule. Using AI to draft messages that a person then sends from their own account is a different thing.
It is a risk I would not take. CAN-SPAM gives a safe harbour to a From line that accurately identifies a person who initiated the message, and a fictional persona’s name does not earn it on its own. The Act’s definition of materially includes concealment that impairs anyone’s ability to identify, locate or respond to the sender, so the risk depends on what else the email shows. The FTC puts the penalty at up to $53,088 per violating email, so use the name of a real employee who owns the replies.
The Regulation defines a provider as whoever develops an AI system, or has one developed and puts it into service under its own name or trademark. On a plain reading, a client that commissions a custom AI SDR and runs it under its own brand fits the definition of provider and carries the Article 50(1) duty to tell people they are dealing with an AI. Fines for breaching Article 50 reach €15 million or 3 per cent of worldwide annual turnover, whichever is higher, or whichever is lower for an SME.

Running an AI SDR and not sure what it is allowed to say?

Send me your sequence, the tool and the countries you send to. I will show you where it needs a real name, where it needs a person pressing send and where it needs one line of disclosure. Book a 30 minute call: cal.com/zeeshanwaheed/30min.

Book a 30-Minute Call

Or email [email protected].