Skip to main content
VA Horizon
Book a Call
AI & Compliance

What “the AI Wrote This Outreach” Means for CAN-SPAM and TCPA Liability When a Tool Drafts or Sends It

Quick answer

No FTC or FCC statement specifically addressing AI-drafted or AI-sent marketing outreach was found in the research behind this piece, and none is invented to fill that gap. This is genuinely novel, fast-moving regulatory ground, and a dedicated ruling on it may not exist yet in citable form.

What does exist is settled doctrine this piece applies by reasoning rather than by quoting a ruling that doesn’t exist: the Supreme Court’s Facebook v. Duguid decision defines an automatic telephone dialing system by the calling or texting system’s technical capability, not by who or what drafted the message, and CAN-SPAM’s sender-liability rule turns on whose business the message promotes, not on the tool used to write or dispatch it. Both tests ask what the message is and whose it is, not which tool assisted in producing it, which means using an AI tool to draft or send outreach does not, by itself, change who bears CAN-SPAM or TCPA liability.

The Question, and Why No Regulator Has Answered It Directly Yet

An agency using an AI tool to draft, personalize, or even schedule the send of a cold-email or text campaign is common enough in 2026 to raise an obvious question: does that change anything about who is liable if the campaign breaks CAN-SPAM or TCPA. No dedicated FTC or FCC statement addressing this specific scenario was found for this piece. That is a genuine gap, not a research shortcut, and it is stated plainly rather than papered over with a source that doesn’t exist.

What Duguid Tests For, Applied to an AI-Drafted Message

The Supreme Court’s 2021 ruling in Facebook v. Duguid held that an automatic telephone dialing system under TCPA must have the capacity to store or produce phone numbers using a random or sequential number generator, a test built entirely around the calling or texting system’s technical capability. Nothing in that test asks who or what wrote the words in the message. A human-drafted text sent through a system with that capability triggers the same TCPA analysis as an AI-drafted text sent through the identical system, because the test was never about authorship in the first place.

Want this handled for you?

Pay per booked meeting for your industry. No retainer.

Book a B2B Call

What CAN-SPAM’s Sender Rule Tests For, Applied the Same Way

CAN-SPAM runs on a parallel logic from the email side. Per sender.net, liability cannot be outsourced to an ESP, cold-email tool, or agency partner, and the sending business, whoever’s product or service the message promotes, remains responsible regardless of who or what operated the send button. The ceiling itself, a maximum civil penalty of $53,088 per non-compliant email in 2026 by the same inflation-adjusted, secondary-sourced figure used elsewhere on this site, doesn’t move because an AI tool typed the message instead of a person; that figure is worth re-verifying against the FTC’s current guide before repeating it as fixed, the same caveat that applies wherever it’s cited. The rule was written to identify whose business the email is for, not to distinguish a machine-assisted draft from a manually typed one.

The Reasoned Answer, Stated Plainly

Put the two tests together and the conclusion follows directly from doctrine that already exists, rather than requiring a new AI-specific ruling: using an AI tool to draft or send outreach does not, by itself, change who bears CAN-SPAM or TCPA liability. Both frameworks ask what the message is and whose business it represents, questions that don’t change based on which tool assisted in producing the text. This is reasoned application of settled law, attributed to the underlying doctrine, not a quotation from a dedicated AI-specific ruling, because no such ruling was confirmed to exist in citable form for this piece.

What Using AI to Draft Outreach Doesn’t Change

It doesn’t change whether prior express written consent was obtained before an automated contact went to a wireless number. It doesn’t change whether the sending business had a functioning opt-out mechanism, or honored one within the required window. It doesn’t change whether the underlying system meets Duguid’s capability test for an automatic telephone dialing system. Every one of those questions is answered by facts about consent, the system, and the sender, not by whether a human or a tool typed the specific words.

What an Agency Should Still Document Regardless

Since the tool doesn’t change the underlying test, the documentation an agency needs doesn’t change either: consent records tied to the specific contact, a clear record of who approved the campaign and its targeting, and a clear designation of who is the sender or initiator of record for the specific send. Whether an AI tool helped write the message is a production detail, not a compliance variable, on the doctrine reviewed here.

None of this is legal advice for a specific campaign, and a qualified lawyer reviewing the actual facts is the right next step for any agency with a live compliance question. Human + AI SDRs keep every SMS conversation, and the consent behind it, on record as a timestamped transcript on the VA Horizon Private CRM, the same kind of record this reasoning keeps pointing back to as what matters, regardless of which tool touched the message along the way.

Sources

The external data in this article draws on the sources below. Figures described in the text as estimates or industry triangulations are directional and are not attributed to a single dataset.

FAQ

Has the FTC or FCC issued a specific ruling on AI-drafted marketing outreach?
No dedicated statement addressing this exact scenario was found in the research behind this piece. This is genuinely novel regulatory ground, and a dedicated ruling may not exist yet in citable form.
Does using AI to write a cold email or text change who is liable under CAN-SPAM or TCPA?
By reasoned application of existing doctrine, no. Both CAN-SPAM’s sender rule and TCPA’s ATDS test, per Facebook v. Duguid, turn on the message and the system’s capability, not on who or what drafted the words.
What does the Facebook v. Duguid ruling test for?
Whether the calling or texting system has the capacity to store or produce numbers using a random or sequential number generator, a technical capability test that doesn’t reference who authored the message content.
What still matters if an agency uses AI to help draft outreach?
The same things that always mattered: documented consent tied to the specific contact, a functioning opt-out mechanism honored on time, and a clear sender or initiator of record. The drafting tool is a production detail, not a compliance variable.
Is this legal advice for a specific AI-assisted outreach campaign?
No. It is a reasoned reading of settled, general doctrine. A qualified lawyer reviewing the actual facts of a specific campaign is the right next step for any live compliance question.

The tool never was the compliance question. The consent record is.

Book a 15-minute call and see how Human + AI SDRs document consent per SMS conversation on the VA Horizon Private CRM, priced per booked meeting with no retainer.

Book a B2B Call

Pay per booked meeting · No retainer · Free no-show replacement