Skip to main content

The "Written by AI" Email Disclosure: What It Is and What It Means for Cold Outreach [2026]

ยท 9 min read
MarketBetter Team
Content Team, marketbetter.ai
Share this article

You've probably noticed it in your inbox: a small line reading "This email was drafted with the assistance of an AI system." Or a support reply that opens with "Hi, I'm the AI assistant at [Company]."

These "written by AI" disclosures are brief statements telling the recipient that a message was generated by artificial intelligence rather than a human. And they went from rare to routine almost overnight โ€” because in mid-2026, the legal ground under AI-generated communication shifted hard.

If you run outbound, this matters to you directly. This guide covers what the disclosure is, which laws force it, how it applies to cold email and LinkedIn specifically, and the one architectural decision that determines whether your team needs a disclosure at all.

What Is the "Written by AI" Disclosure?โ€‹

It's a transparency statement โ€” in an email body, footer, or support thread โ€” informing the recipient that AI generated the message. A compliant version typically does three things:

  1. Explicitly says "AI" โ€” not "virtual assistant" or a cute bot name
  2. Attributes the company responsible for the message
  3. Offers a path to a human (in support and sales contexts)

A good example, upfront: "Hi Maria, I'm Atlas, the AI support assistant at Acme. I've looked into your order and here's where it stands."

A non-compliant example: "Hi, I'm Robin, your virtual assistant" โ€” it never says AI. Burying the disclosure in 8-point font at the bottom of the email also fails; regulators have been explicit that the AI's nature must be obvious before any substantive exchange, not discoverable after forensic scrolling.

Why It's Suddenly Everywhere: The Mid-2026 Enforcement Waveโ€‹

Three forces converged:

The EU AI Act (Article 50)โ€‹

As of August 2026, the EU AI Act's transparency obligations are in full enforcement. Article 50 requires companies to clearly disclose when a person is interacting with an AI system โ€” and the disclosure must happen before any substantive exchange. Fine print in terms and conditions doesn't comply. Faint footer text doesn't comply. If your AI is talking to someone in the EU, that person has to know it's an AI.

The US FTC (Section 5)โ€‹

The FTC hasn't mandated a specific disclosure format, but its prohibition on "deceptive practices" under Section 5 covers AI impersonating a human representative. Passing an AI off as a person named "Sarah from Sales" โ€” complete with a generated headshot โ€” is exactly the kind of consumer deception that has drawn seven-figure penalties.

California's Bot Law (B.O.T. Act)โ€‹

California makes it illegal for a bot to interact with a person in the state to incentivize a commercial transaction โ€” which is precisely what a sales pitch is โ€” unless it clearly discloses that it's a bot. Given that you rarely know where a prospect is sitting, this effectively sets a US-wide floor for autonomous sales outreach.

Layer on corporate and academic policies that now require AI declarations internally, and you get the current reality: hiding AI authorship has become a legal liability, not a growth hack.

What This Means for Cold Emailโ€‹

Cold outreach is where these rules bite hardest, because it's commercial, unsolicited, and increasingly AI-touched. Here's the breakdown:

ScenarioDisclosure needed?Why
AI autonomously writes and sends the emailYesThe recipient is interacting with an AI system (EU AI Act Art. 50; CA bot law for commercial pitches)
AI drafts, human reviews/edits and clicks sendGenerally noThe human takes ownership; most legal teams treat this as human communication
AI personalizes at scale, no human review, EU recipientsYesArticle 50 applies; compliance guidance recommends a clear footer disclosure
Fake AI persona in the From field ("Sarah from Sales")Illegal regardlessCAN-SPAM requires accurate sender identity; FTC treats it as deception

For fully autonomous AI email to EU recipients, compliance guidance converges on a clear footer statement โ€” something like "This email was drafted with the assistance of an AI system. [Company] is responsible for its content" โ€” plus machine-readable marking of AI-generated content so filters and clients can parse it. Some practitioners implement this as a custom header field flagging the message as AI-generated.

And under CAN-SPAM, the basics still apply: your From and Reply-To fields must accurately identify the real sender. An autonomous agent sending under a fabricated employee identity violates US law even before any AI-specific rule enters the picture.

What This Means for Cold LinkedInโ€‹

LinkedIn adds a private layer of rules on top of government regulation, and it's stricter than any of them:

  • Automation is banned outright. LinkedIn's Terms of Service prohibit bots and automated software from sending messages or connection requests. An autonomous AI agent running your LinkedIn outreach isn't a disclosure problem โ€” it's an account-ban problem. Permanently.
  • Synthetic personas are banned. AI-generated profile photos and fabricated identities violate LinkedIn's Professional Community Policies on fake profiles.

The practical consequence: on LinkedIn, there is no compliant version of fully autonomous AI outreach. The only durable model is AI-assisted โ€” research, drafting, and prioritization done by AI, with a real human operating a real profile and sending each message. (We walk through what that looks like in practice in our Sales Navigator + AI workflow guide.)

The Human-in-the-Loop Line: The Distinction That Decides Everythingโ€‹

Read the rules above again and one pattern jumps out. Regulators and platforms aren't punishing the use of AI. They're punishing the impersonation of humans by AI.

That creates a bright line between two operating models:

AI-sent (autonomous): The AI writes the message and fires it off with no human review. Disclosure laws apply in full. EU footers, bot-law disclosures, machine-readable tags โ€” and on LinkedIn, it's prohibited entirely.

AI-assisted (human-in-the-loop): AI gathers the evidence, finds the signal, drafts the message โ€” and a human SDR reviews it, edits it, and clicks send. The human takes ownership of the message. Most legal teams treat this as human communication that happens to use good tools, the same way nobody discloses "this email was written in Grammarly."

This distinction isn't a loophole โ€” it's the point. The laws exist to stop machines from pretending to be people. A human who reads, owns, and sends a message isn't pretending anything.

Even where disclosure isn't legally required, the underlying dynamic matters: recipients are getting very good at detecting fully automated outreach, and they punish it with deletes, spam reports, and reputation damage to your domain. The same signals regulators care about โ€” no human judgment, no real accountability, synthetic personalization โ€” are the signals prospects and spam filters have learned to smell.

Human-reviewed outreach doesn't just sidestep the disclosure question. It reads better, lands better, and protects your sending infrastructure. Compliance and conversion point in the same direction.

How MarketBetter Handles Thisโ€‹

MarketBetter was built on the human-in-the-loop side of the line from day one โ€” not as a compliance retrofit, but because it's how outbound actually works:

  • AI does the research and drafting. MarketBetter identifies in-market accounts from person-level website visits and blended intent signals, then drafts personalized outreach grounded in real evidence โ€” the page a prospect visited, the tech they run, the trigger event that just happened.
  • Your SDR owns the send. Drafts land in a review queue. A real human โ€” with a real name, real email, real LinkedIn profile โ€” reviews, edits, and sends. Every message is a human communication with AI-grade research behind it.
  • No synthetic personas, ever. No fabricated "AI SDR employees," no generated headshots, no bot accounts. Your outreach comes from your actual team.

That architecture means MarketBetter customers didn't have to change anything in August 2026. The EU AI Act enforcement wave, the FTC's posture, California's bot law, LinkedIn's automation ban โ€” none of them touch outreach where a human reviews and sends.

If your current stack fires emails autonomously, you now have a choice: bolt disclosures onto robot messages that already underperform, or move the human back into the loop. We'd argue the second option was always the better outbound anyway โ€” see how we compare the models in our AI SDR tools breakdown.

FAQโ€‹

Do I need to disclose AI if a human edits the email before sending? Generally no. When a human gathers the evidence, chooses the premise, reviews the draft, and clicks send, most legal teams treat the message as human communication. The disclosure obligations target autonomous AI interaction.

Does the EU AI Act apply to B2B cold email? Yes, if the recipient is in the EU and an AI system is what they're interacting with. Article 50's transparency obligations don't carve out B2B.

Can I just put the disclosure in tiny text at the bottom? No. Regulators have specifically flagged buried or faint disclosures as non-compliant. The AI's nature must be obvious before substantive exchange.

What happens if I ignore this? In the EU: AI Act penalties. In the US: FTC deception actions with fines that have exceeded $5 million, plus state bot-law exposure. On LinkedIn: permanent account bans, no appeal that works.

Is AI-assisted outreach going to require disclosure eventually? Possibly โ€” regulation only moves one direction. But the human-in-the-loop model is the most defensible position under every current and proposed framework, which is a strong reason to build on it now.


The "written by AI" disclosure marks a real shift: AI is no longer something companies pass off as human โ€” it's a transparent digital worker, or it's a liability. For outbound teams, the winning move isn't better fine print. It's keeping a human in the loop, so your messages never needed the disclaimer in the first place.

Share this article