- One writer logged more than a dozen sales emails in three days, each signed by a differently named AI agent, all sent from a single domain, each offering research work for roughly $25.
- The federal rule on commercial email makes no exception for business to business mail, so an agent pitch still owes you a postal address and a working way out.
- Gmail is stricter than the statute on the point that decides delivery: it expects an unsubscribe honoured within 48 hours, while the FTC allows ten business days.
- Block the sending domain, not the persona. The persona is generated fresh for every message and the domain is the part that costs money to replace.
- Visa described the same pressure from the defensive side on 27 August 2026, framing AI as something that shortens the gap between a weakness being found and being used.
- None of this is a reason to answer faster. It is a reason to decide once, write the rule down, and let a filter apply it.
Ernie Smith writes Tedium, a newsletter about the forgotten corners of internet history. On 11 September 2026 he published a post about his inbox. Over three days he had collected more than a dozen emails, several of them inside a single three hour window, each one signed by an AI agent with a human sounding name, each one offering to do his research for about $25. The first arrived with a subject line claiming his 404 page repeated a myth. The agent, calling itself Leo Ashford, corrected him about the origin of the 404 error, described its own work as verified internet archaeology, and then pitched for the job.
Smith is a freelancer. The bots were quoting for work he does himself. He published the screenshots and traced the sending domain to iLands.app, a company that describes itself as a human agent network and runs something closer to a marketplace where autonomous agents solicit work. Its founder, Kaixin Tang, previously at ByteDance, did not answer a request for comment.
That is a small story about one newsletter. AI agent spam is a fair name for it, and it matters to anyone selling anything, because the same machinery points at a business inbox next and because the economics behind it do not need you to reply. An agent that costs a few cents to run can send a personalised, researched, superficially credible pitch to every business it can find a contact page for. It only has to convert once in several thousand to pay for the tokens. The volume is the business model.
What was actually in those emails?
They were not the broken English blasts a spam filter was trained on, and no ordinary unsolicited email looks like this. Each message had read something real, found a genuine detail to argue with, and used that detail as the opening. Smith's 404 page is a poem. The agent had read the poem, identified the claim inside it, and built a critique around it before selling a fix.
That shape is the thing to learn. The pitch arrives attached to a real observation about your business, which is exactly the signal a human being uses to decide that a message is worth reading. A misspelled invoice is easy. A polite note explaining that your size guide contradicts your returns policy, followed by an offer to rewrite both for $25, is not. It reads like the first message from a careful freelancer.
Smith counted the arrivals rather than the arguments, and that turned out to be the useful measurement. Twelve messages in three days, several inside three hours, all from one domain, all under different names. No single message looked automated. The pattern did.
Why does this land on small businesses first?
Because small businesses publish their contact details and answer their own email. A company with a procurement department has a purchasing process that an agent cannot enter. A one person shop has a contact form, a founder's address in the footer, and a strong professional habit of replying to people who write in. Every one of those is an opening.
There is a second reason, and it is less obvious. The businesses most likely to be pitched are the ones whose work is visible and gradeable from the outside. Product pages, menus, booking flows, and delivery promises are all published. An agent can read your storefront, find a genuine flaw, and use it. It cannot do that to a company whose work is internal.
So the shops that publish most carefully get the most credible spam. That is an unpleasant inversion and worth naming, because the instinct it produces is wrong. The answer is not to publish less.
What kinds of AI inbound actually arrive?
Four shapes cover almost everything a small merchant receives. They need different responses, and the mistake most owners make is treating all four as one category called spam.
| What arrives | The tell | What it wants | What to do |
|---|---|---|---|
| Agent sales pitch | A real critique of your public pages, then a small fee to fix it | A $20 to $50 payment, often repeated | Block the sending domain, keep one example |
| Manufactured complaint | An order or visit that does not appear in your records | A refund, a discount code, or a review threat | Answer from your own data, never from the story |
| Invoice lure | A supplier name you recognise with banking details you do not | A payment redirected to a new account | Verify on a number you already held |
| Scraped partnership offer | Flattery assembled from your own site copy | A link, a listing fee, or your customer list | Ignore, and never confirm the address is live |
The invoice lure is the expensive one, and it predates AI by decades. What changed is that the research behind it is now cheap. The practical defence has not moved: the checks that catch a forged supplier invoice are still about verifying bank details out of band, on a number you already had, before money moves.
Is an AI agent allowed to email you like this?
Mostly not, and the rule is older and blunter than the technology. The FTC's compliance guide for the CAN-SPAM Act states in plain words that the law makes no exception for business to business email. If the primary purpose of a message is to promote a commercial service, it is covered, whether it goes to a consumer or to a shop.
What that means in practice is a short list. The header and the subject line have to be honest. The message has to disclose that it is an advertisement. It has to carry a valid physical address. It has to explain clearly how to opt out, and the opt out cannot demand a fee or any information beyond an email address. Requests have to be honoured within ten business days. And responsibility cannot be outsourced: the guide is explicit that hiring someone else to send your mail does not move the liability. Each violating message is exposed to a penalty of up to $53,088.
Smith's emails had no unsubscribe link. That single omission is what turns an annoying pitch into a straightforward breach, and it is the first thing worth checking, because it takes two seconds and it tells you what kind of sender you are dealing with.
Knowing a message breaks the rule does not oblige you to do anything about it. Reporting is optional and rarely worth a small shop's afternoon. The reason to check is diagnostic. A sender with no opt out is not going to stop, so filtering is the only move that ends the series.
What does the flood do to your own email?
This is the part that costs money, and almost nobody connects their own email deliverability to the spam arriving in their inbox. Mailbox providers respond to rising volumes of generated mail by tightening what they accept from everybody, and the thresholds are published.
Google's sender guidelines FAQ sets the bar for anyone sending 5,000 or more messages a day to Gmail addresses, a line a modest shop crosses the moment it runs a seasonal campaign to a list it has built over a few years. Mail has to be authenticated with both SPF and DKIM. The domain needs a DMARC record, with a policy of none as the floor. Forward and reverse DNS have to resolve. Messages have to be sent with TLS and follow RFC 5322.
Then there is the number that actually decides your fate. Spam rate is calculated daily. Google asks senders to hold it below 0.1% and to prevent it from ever reaching 0.3% or higher. Cross 0.3% and delivery support and mitigations become unavailable, which in ordinary language means your mail starts landing in spam folders and nobody at Google is going to help you.
Marketing messages also need one click unsubscribe implemented through List-Unsubscribe headers per RFC 8058, and here is the detail worth writing on a wall: Google expects unsubscribe requests honoured within 48 hours. The FTC allows ten business days. The platform rule is roughly five times stricter than the statute, and the platform is the one that decides whether your campaign reaches anyone. Compliance with the law is not compliance with Gmail.
So the agents pushing volume into everyone's inbox are, indirectly, tightening the pipe your own newsletter travels through. If your open rates have quietly sagged, the cause may sit entirely outside your account. We wrote separately about how AI spam filters decide whether your email reaches the inbox, and the mechanics there have only become more consequential.
What are the defenders actually building?
The same compression is visible from the other side of the industry. On 27 August 2026 Visa announced an expanded version of its Vulnerability Agentic Harness, an open source, model agnostic framework it first released in June 2026 and which it says has since been downloaded by tens of thousands of developers. The stated goal is to cut Mean Time to Adapt, the interval between finding an attack path and closing it, from weeks to hours. The newest release extends the workflow past discovery into remediation and validation, with support for models from Anthropic and OpenAI.
Carl Rutstein, who runs Visa Consulting and Analytics, put the commercial version of the same observation in the release: speed to remediation is the new battleground, and attackers that move faster and probe at scale have to be answered with defences that also run on AI.
None of that ships to a small shop directly. Visa's harness is for the people who patch software, not for someone selling candles. It is worth reading anyway, because it confirms the shape of the change from a source with no incentive to dramatise it. The cost of generating plausible, targeted, high volume contact has collapsed, on both the selling side and the attacking side, and every published surface a business owns is now read by machines before it is read by customers.
What should a shop change this month?
Very little, and that is the honest answer. Three small decisions cover most of the exposure, and all three are one time.
First, filter by domain. When a pitch arrives from an agent, look at what follows the @ symbol rather than the name in the From field. The name is generated per message. The domain is an asset the sender paid for. Blocking the domain stops the whole series, which is what turned Smith's twelve messages into one decision instead of twelve.
Second, write down what your business will do with an unverifiable complaint before one arrives. A manufactured refund request works by making you decide under time pressure, with a plausible story and no order number. If your rule is that refunds are issued against records rather than against narratives, the entire class stops working. Put the rule where whoever answers the inbox can see it.
Third, look at your own sending before you look at anyone else's. Authentication records, a one click unsubscribe that genuinely works within two days, and a spam rate you actually monitor are now the difference between a campaign that arrives and one that vanishes. That is an afternoon of work and it protects the channel you own.
There is a fourth item that is not about email at all. As more owners hand their inbox to an assistant, the question of what that assistant may do without asking becomes real. An agent that can read and draft is also an agent that can send, which makes it something a message can socially engineer. We set out the boundaries in what an AI assistant should be allowed to do with inbox access, and the short version is that reading and drafting are different permissions from sending and paying.
Does any of this change how you sell?
It changes one thing. The credibility of an unsolicited message has stopped being evidence of effort. For twenty years, a well researched email that referenced your actual work was a reliable signal that a human had spent time on you, and responding to it was rational. That signal is now cheap to fake at scale, and the people who lose most from that are the ones who send genuinely researched outreach.
If you send cold email yourself, the practical consequence is that your message now has to carry something AI agents cannot generate: a specific, checkable fact about a shared context, a name the recipient can verify, a reason the message exists that is not a service pitch. The bar moved.
And if you are on the receiving end, the useful mental adjustment is to stop grading messages by how good they are. Grade them by whether you went looking. Anything you did not go looking for, however polished, goes through the filter rule rather than through your judgement. That is not cynicism. It is the only way to keep the attention you need for the customers who actually bought something.
The infrastructure side of this is the same problem in a different coat. Anyone building a storefront now has to assume every public page is machine readable and machine gradeable, which raises the question of what a platform keeps, exposes, and logs on your behalf. Our own position on that is written out in how MaShop stores and isolates merchant data, because a merchant should be able to check it rather than take it on trust.
The measurement worth keeping
Smith did one thing that is worth copying, and it has nothing to do with AI. He counted. Twelve in three days, several in three hours, one domain. Without the count, each message is an isolated judgement call and you make twelve of them badly. With the count, the pattern is obvious in about a minute and the response is a single filter rule.
Keep a folder. Move anything unsolicited into it without reading past the first line. Look at it once a week. If one domain appears four times, block it and move on. That is the whole discipline, it costs nothing, and it scales exactly as fast as the thing it defends against.