The Question, and Why No Regulator Has Answered It Directly Yet
An agency using an AI tool to draft, personalize, or even schedule the send of a cold-email or text campaign is common enough in 2026 to raise an obvious question: does that change anything about who is liable if the campaign breaks CAN-SPAM or TCPA. No dedicated FTC or FCC statement addressing this specific scenario was found for this piece. That is a genuine gap, not a research shortcut, and it is stated plainly rather than papered over with a source that doesn’t exist.
What Duguid Tests For, Applied to an AI-Drafted Message
The Supreme Court’s 2021 ruling in Facebook v. Duguid held that an automatic telephone dialing system under TCPA must have the capacity to store or produce phone numbers using a random or sequential number generator, a test built entirely around the calling or texting system’s technical capability. Nothing in that test asks who or what wrote the words in the message. A human-drafted text sent through a system with that capability triggers the same TCPA analysis as an AI-drafted text sent through the identical system, because the test was never about authorship in the first place.
What CAN-SPAM’s Sender Rule Tests For, Applied the Same Way
CAN-SPAM runs on a parallel logic from the email side. Per sender.net, liability cannot be outsourced to an ESP, cold-email tool, or agency partner, and the sending business, whoever’s product or service the message promotes, remains responsible regardless of who or what operated the send button. The ceiling itself, a maximum civil penalty of $53,088 per non-compliant email in 2026 by the same inflation-adjusted, secondary-sourced figure used elsewhere on this site, doesn’t move because an AI tool typed the message instead of a person; that figure is worth re-verifying against the FTC’s current guide before repeating it as fixed, the same caveat that applies wherever it’s cited. The rule was written to identify whose business the email is for, not to distinguish a machine-assisted draft from a manually typed one.
The Reasoned Answer, Stated Plainly
Put the two tests together and the conclusion follows directly from doctrine that already exists, rather than requiring a new AI-specific ruling: using an AI tool to draft or send outreach does not, by itself, change who bears CAN-SPAM or TCPA liability. Both frameworks ask what the message is and whose business it represents, questions that don’t change based on which tool assisted in producing the text. This is reasoned application of settled law, attributed to the underlying doctrine, not a quotation from a dedicated AI-specific ruling, because no such ruling was confirmed to exist in citable form for this piece.
What Using AI to Draft Outreach Doesn’t Change
It doesn’t change whether prior express written consent was obtained before an automated contact went to a wireless number. It doesn’t change whether the sending business had a functioning opt-out mechanism, or honored one within the required window. It doesn’t change whether the underlying system meets Duguid’s capability test for an automatic telephone dialing system. Every one of those questions is answered by facts about consent, the system, and the sender, not by whether a human or a tool typed the specific words.
What an Agency Should Still Document Regardless
Since the tool doesn’t change the underlying test, the documentation an agency needs doesn’t change either: consent records tied to the specific contact, a clear record of who approved the campaign and its targeting, and a clear designation of who is the sender or initiator of record for the specific send. Whether an AI tool helped write the message is a production detail, not a compliance variable, on the doctrine reviewed here.
None of this is legal advice for a specific campaign, and a qualified lawyer reviewing the actual facts is the right next step for any agency with a live compliance question. Human + AI SDRs keep every SMS conversation, and the consent behind it, on record as a timestamped transcript on the VA Horizon Private CRM, the same kind of record this reasoning keeps pointing back to as what matters, regardless of which tool touched the message along the way.
Sources
The external data in this article draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.
- Supreme Court of the United States, Facebook, Inc. v. Duguid (2021)
- sender.net, CAN-SPAM Act Compliance Guide
