- United States law makes no exception for business to business email, and every separate message that breaks the rules carries a penalty of up to $53,088.
- In the UK you may email a limited company without consent, and you generally may not email a sole trader without it, which splits most prospect lists down the middle.
- Opt out requests have to be honoured within 10 business days under the American rule, and the obligation follows the message rather than the tool that sent it.
- Both the business promoted in a message and the business that sent it can be held responsible, so outsourcing outreach does not move the liability.
- Gmail has required authentication and one click unsubscribe from senders of more than 5,000 messages a day since 1 February 2024, with spam rates to stay under 0.3%.
- AI did not change any of these rules. It changed how many messages a person can send before anyone notices they were not thinking.
A maker who wants to get into twenty shops used to write twenty emails, which took an evening and forced a certain amount of thought about each one. The same person can now produce four hundred personalised messages before lunch, and the personalisation will be better than what they used to write by hand.
Nothing in the law moved to meet that. The obligations attach per message and per recipient, which means the cost of a mistake scaled by the same factor as the output. This is not an argument against using AI for outreach. It is an argument for knowing the three or four rules that were survivable at twenty messages and are not at four hundred.
Do you need permission before emailing a business?
It depends entirely on where the recipient is, and the answers are genuinely opposite rather than slightly different. The United States runs an opt out system. The United Kingdom runs a consent system with a carve out for companies.
The American position is set out in the FTC's CAN-SPAM compliance guide for business, and the sentence that matters most is the one people assume says the opposite: the law makes no exception for business to business email. Every commercial message has to comply, whoever receives it. What the law does not require is permission first. You may send a cold message, provided it meets the conditions in the next section.
The British position inverts that. The Information Commissioner's Office explains in its guidance on business to business marketing that the electronic mail rules distinguish corporate subscribers from individual subscribers. Corporate subscribers are companies, limited liability partnerships and Scottish partnerships. Individual subscribers include sole traders and non limited partnerships, and they are treated exactly like private individuals.
| Recipient | United States | United Kingdom | What that means for a list |
|---|---|---|---|
| A limited company | No consent needed, all message rules apply | No consent needed under the electronic mail rules | The straightforward case in both markets |
| A sole trader | No consent needed, all message rules apply | Consent needed, or the soft opt in | The row that splits most small business lists |
| A named person at a company | Same as above | Electronic mail rules relaxed, data protection law still applies | Personal data either way, so rights attach |
| Anyone who opted out | Must stop within 10 business days | Must stop, and honour the objection | The only row where the two regimes fully agree |
The second row is the one that breaks an AI built prospect list, because a scraped or generated list of local businesses will contain both kinds and nothing on a website reliably tells you which is which. A shop trading under a name might be a limited company or might be one person. The legal position flips completely depending on which, and the model that assembled the list has no way to know.
What has to be in the message itself?
Six things in the American rule, and they are all mechanical enough to check before sending rather than after. None of them are about tone.
Header information must not be false or misleading, so the from, to and reply to fields have to identify the sender truthfully. The subject line must reflect what the message actually says. The message has to be identifiable as an advertisement. It must include a valid physical postal address. It must tell the recipient how to stop receiving future email, clearly and conspicuously. And an opt out has to be honoured within 10 business days.
Two details in that list catch small senders repeatedly. The physical address is not optional because you work from home: a post office box or a registered mailbox satisfies it, and omitting it entirely does not. And the opt out route has to actually work when somebody uses it, which means an address created for one campaign and abandoned afterwards leaves you unable to honour a request you are obliged to honour.
The penalty is stated per message. Up to $53,088 for each separate email that breaks the rules, which is the number that turns a scaled campaign from a marketing decision into a financial one. Four hundred non compliant messages is not four hundred times more annoying than one. It is four hundred violations.
Does using a tool move the responsibility?
No, and the guide says so directly. Both the company whose product is promoted in a message and the company that actually sends it may be held legally responsible.
That sentence was written about email service providers and marketing agencies, and it applies without modification to an AI outreach tool, a freelancer running your campaign, or a platform that sends on your behalf. You cannot buy your way out of the obligation, and the guide's own summary of the last requirement is to monitor what others are doing on your behalf.
For a small business the practical form of that is one question asked before signing up to anything that sends on your behalf: what address appears in the from field, and whose postal address is in the footer. If the answer is that the tool handles it, you have not learned anything, because the tool's compliance is not a defence for your message.
What does AI actually change?
Volume, and the disappearance of the natural checkpoint that volume used to create. The rules did not get harder. The number of chances to break them went up by two orders of magnitude.
Writing twenty emails by hand forced you to look at twenty recipients. Somewhere in that process you noticed that seven of them were not really the right fit, and you did not send those. Generating four hundred removes the step entirely, and the recipients who would have been filtered out by boredom are now in the send queue.
There is a second, subtler change. Personalisation produced by a model reads as though it came from research, because it references something real from a website. The recipient reasonably concludes that a person looked at their business and wrote to them. When four hundred people conclude that and then compare notes, or simply recognise the pattern, the damage is not a spam complaint. It is a reputation in a small trade where everyone knows everyone, and that is not a legal problem with a legal remedy.
The inbox side of this is getting crowded from the other direction too, as automated messages arrive at small businesses in growing volumes, which we looked at in our piece on what AI generated spam is doing to a business inbox. Being one of four hundred senders doing the same thing is a worse position than it was two years ago.
Is a sole trader really treated as a person?
Under the British electronic mail rules, yes, and it is the single most expensive thing to get wrong on a European list. Sole traders and non limited partnerships sit with private individuals, which means consent or a narrow exception.
That exception is the soft opt in, and its conditions are cumulative rather than alternative. The ICO's guidance on complying with the electronic mail marketing rules sets out all four: you obtained the contact details in the course of selling or negotiating to sell a product or service, you are marketing only your similar products and services, you gave them a chance to opt out when you collected the details, and you give them a chance to opt out in every message after that.
Read the first condition closely, because it excludes almost everything a cold outreach tool does. Details found on a website, bought in a list, inferred from a directory or generated by a model were not obtained in the course of negotiating a sale. The soft opt in is for people you already dealt with, which makes it useless for prospecting and valuable for the customers you already have.
One more thing survives regardless of which category the recipient falls into. Where personal data is involved, and a named individual at a company is personal data, data protection law continues to apply. You need a lawful basis, you have to provide privacy information about using the data for direct marketing, and you have to honour an objection. Selling to shops rather than to consumers does not remove that, which is worth holding in mind alongside the practical side of using AI when you sell wholesale into other shops.
What happens before anyone reads it?
A filter decides, and the thresholds are published. Getting the law right and the delivery wrong produces the same outcome as not sending at all, so the two have to be handled together.
Google's email sender guidelines have required, since 1 February 2024, that senders of more than 5,000 messages a day to Gmail accounts authenticate with SPF, DKIM and DMARC, support one click unsubscribe on marketing messages with a visible unsubscribe link in the body, and keep spam rates reported in Postmaster Tools below 0.3%. The recommendation is to stay under 0.10% and never reach 0.30%.
Most small senders are far below 5,000 a day and conclude this does not concern them. Two parts of it do. Authentication with SPF or DKIM is asked of all senders regardless of volume, and it is the difference between arriving in an inbox and arriving nowhere. And the spam rate threshold is a rate rather than a count, so a small campaign with a high complaint rate is in worse shape than a large one with a low rate. The deliverability side of this is a subject of its own, covered in our piece on what AI spam filters do to a small sender's email.
What about phoning or texting them instead?
The rules change again, and not in the direction most people guess. Under the British regime a live phone call to a business is treated more permissively than an email to a sole trader, while an automated call is treated more strictly than either.
The ICO's table is worth committing to memory if you sell to other businesses. Live calls are allowed to both corporate subscribers and sole traders, unless the number is registered with the Telephone Preference Service or its corporate equivalent. Automated calls require consent in every case, for companies and sole traders alike. Email and text require no consent for corporate subscribers and consent for sole traders. Fax, which still appears in the guidance, follows the email pattern with its own preference service.
The automated call row is the one that matters now, because AI voice agents are exactly that. A tool that dials a list and plays a generated message, or holds a generated conversation, is an automated call whether or not it sounds like a person. Consent is required, and the fact that the voice is convincing makes no difference to the classification. If anything it sharpens the problem, because a recipient who believed they were speaking to a person and later works out they were not tends to complain rather than shrug.
The preference service check is a separate obligation from consent and it does not go away because your list came from a public directory. Screening against the register is a step, not a formality, and a tool that dials without doing it has not saved you the work. It has only moved the moment you find out.
Where did the addresses come from?
This is the question to answer before the campaign rather than after a complaint, and for an AI assembled list the honest answer is frequently that nobody knows. A list you cannot account for is a list you cannot defend.
Record the source next to every address, in the same file, at the moment it is added. Scraped from a public website on a date. Collected at a trade show with a form. Given by a customer. Bought from a named supplier. That column takes no effort at the point of collection and is unreconstructable afterwards, and it is what lets you answer the only question a regulator or an annoyed recipient actually asks.
It also makes the sole trader problem tractable. An address collected at a trade show came with a conversation in which you probably learned whether you were speaking to a company or a person, and that is worth writing down while you know it. An address generated by a tool from a directory came with nothing, which is itself useful information about how carefully that address should be treated. Personal data collected for outreach carries the same obligations as any other personal data you hold, which is the reasoning behind how we describe our own handling of personal data rather than leaving it to a general statement.
What is worth doing instead of four hundred emails?
Fewer messages to a list you can account for, with the model doing research rather than production. That inverts the usual setup and it is the version that survives contact with the rules.
Use AI to work out which twenty of four hundred businesses are genuinely a fit, which is a reading task and the thing models are good at. Have it summarise what each one sells, whether they already stock something like yours, and what they seem to care about. Then write the twenty messages yourself, or edit twenty drafts properly, which takes an evening and is what the old process cost anyway.
The compliance work collapses at that volume. Twenty recipients can be checked for company status. Twenty messages can carry a real address and a working opt out without any infrastructure. Twenty replies can be answered by a person. And the response rate on twenty considered messages is not a fifth of the rate on four hundred generated ones, it is usually higher in absolute terms, because the recipients can tell.
None of this is an argument for doing it the slow way out of principle. It is that the rules were written per message, the penalties are counted per message, and the reputational cost lands per recipient. Every one of those scales with the thing AI made free, and none of them scale with the thing it made valuable, which is knowing who to write to.