Skip to content
checklist

AI outreach compliance checklist

Send AI-assisted outreach into the EU, UK, and US and be able to show exactly why it was allowed. 40 checks across five gates cover the list, the lawful basis, EU AI Act transparency, the message itself, and the sending mechanics, each with the evidence a reviewer will ask for.

An AI outreach compliance checklist clears five gates before a campaign sends: a recorded lawful basis for every address, AI transparency where EU AI Act Article 50 applies from 2 August 2026, a one-click opt-out honoured immediately, deliverability guards (verified list, per-mailbox caps, warm-up, bounce handling), and proof that a named person approved the content. CommsOperator's checklist turns those five gates into 40 auditable checks, each with the evidence to keep.

For: Sales, marketing, and communications leads running AI-assisted outreach in or into the EU, UK, and US, who will be the one answering when a recipient complains ยท Published 2026-08-26

What is inside

  • 40 checks across five gates, each with the evidence a reviewer will ask for
  • EU AI Act Article 50: when a disclosure is required, what it must say, and when human approval replaces it
  • GDPR and ePrivacy: lawful basis, legitimate interest assessment, and the B2B carve-outs by country
  • CAN-SPAM, CASL, and PECR mechanics side by side
  • Deliverability gates: list verification, per-mailbox caps, warm-up, bounce and complaint thresholds
  • A one-page pre-send sign-off sheet to keep with the campaign

Get the Markdown copy

The complete text is on this page already. The form gets you a file to keep and share, downloaded right here. We ask for a work email so we can follow up about this document only.

Clear these 40 checks and you can answer the two questions that decide most complaints: where did this address come from, and who approved this message. This is the checklist we run before a campaign leaves a CommsOperator workspace, written from operating outreach for community, conference, sponsorship, and fund audiences across the EU, UK, and US. It is not legal advice; it is the operational shape of the obligations, with the evidence a reviewer will ask you for.

Gate 1: the list

  1. Every address has a recorded source: form submission, event registration, existing customer relationship, or a documented legitimate interest assessment. If you cannot name the source, do not send.
  2. The list has been verified for deliverability within the last 30 days. Catch-all and unknown results are kept, not dropped: enterprise domains are frequently catch-all.
  3. Employment has been re-checked for lists older than six months. On one aged list we tested, only 42 of 100 contacts were confirmed still at the company.
  4. Role addresses (info@, sales@, support@) are separated from personal addresses and treated under the applicable rules for each.
  5. Suppression has been applied before segmentation, not after: bounces, complaints, unsubscribes, opt-outs, and departed contacts.
  6. No purchased, rented, or scraped list is present. Record the confirmation.
  7. Duplicate identities across brands are resolved so one person does not receive the same campaign twice.
  8. Special-category data is absent from the segmentation criteria.

Gate 2: lawful basis and transparency

  1. For EEA and UK recipients: the basis is recorded per segment (consent, or legitimate interest with a completed balancing assessment).
  2. The legitimate interest assessment names the interest, the necessity, and the balancing outcome, and is dated and signed by a named person.
  3. For electronic marketing to individuals in the EEA and UK, the ePrivacy or PECR position is recorded per country, including the corporate subscriber carve-outs where you rely on them.
  4. A privacy notice reachable from the message describes the processing, and the sending entity is identified honestly in the message.
  5. For US recipients: a valid physical postal address appears in the message and the sender identification is accurate (CAN-SPAM).
  6. For Canadian recipients: express or implied consent is recorded with its expiry, and the message carries the required identification and unsubscribe (CASL).
  7. The data subject rights route (access, objection, erasure) is monitored and answers within 30 days.

Gate 3: AI transparency and oversight

The EU AI Act's transparency obligations under Article 50 apply from 2 August 2026 to AI systems that interact with people and to AI-generated content. Two questions decide what you must do: is a person accountable for the send, and is the recipient likely in the EEA?

SituationWhat is requiredEvidence to keep
A person reviewed and sent the messageNo AI disclosure obligation arises from Article 50; a human sender is accountableThe approval record: who approved, when, what content
AI drafted and sent automatically to an EEA recipientEither hold for human approval, or disclose the AI origin in the messageThe disclosure text as sent, or the downgrade record
A chatbot interacts with a personThe system must make clear it is an AI systemThe widget's identification copy and its version
AI-generated content published as textMachine-readable marking where the content is synthetic and public-facingThe marking mechanism and where it is applied
  1. Every AI-drafted message either passed a human approval or carries an AI-origin disclosure. There is no third state.
  2. The approval record names a person, not a role or a service account.
  3. The AI provider and model used are documented, along with whether the provider trains on the content (an API arrangement that excludes training is what you want to be able to show).
  4. Policy rules for the campaign are written down: banned topics, required disclaimers, risk tier, and whether a second approver is required.
  5. A kill switch exists and someone knows where it is.
  6. The agent activity log is retained long enough to answer a complaint, and its retention period is stated.

Gate 4: the message

  1. A working opt-out link is present in every commercial message and is one click, with no login and no preference maze.
  2. The opt-out suppresses immediately, not on the next sync, and cannot be reversed by a later import.
  3. Sender name, reply-to, and the physical sender identity match the organization actually writing.
  4. The reply-to address is a monitored mailbox that is connected to the system, so replies and opt-out requests in prose are seen.
  5. Personalisation tokens are all declared, so a missing value fails the draft rather than silently deleting a sentence.
  6. The message does not claim a relationship that does not exist.
  7. Links are first-party or clearly attributed, and tracking parameters carry the correct campaign identity.
  8. Attachments are avoided in cold outreach.

Gate 5: sending and aftermath

  1. Authentication is in place for the sending domain: SPF, DKIM, and DMARC with a policy beyond none.
  2. A per-mailbox daily cap is set explicitly for new mailboxes rather than inherited from a mature default.
  3. A warm-up ramp applies to any mailbox sending at volume for the first time.
  4. Bounce handling suppresses permanent (5.x.x) failures automatically and does not suppress temporary (4.x.x) ones.
  5. Complaint and bounce thresholds are configured at or below the provider bar (0.10 percent complaints, 0.30 percent as the hard ceiling; bounce warning at 2 percent).
  6. A circuit breaker can pause the campaign without a person watching the dashboard.
  7. Reply detection pauses the sequence for anyone who answers.
  8. Someone owns the approval queue with a same-day service target. A draft-for-review campaign with an unstaffed queue sends nothing at all: we have watched 53 drafts expire unapproved during an emergency campaign.
  9. The wave is segmented and staggered rather than sent in one burst.
  10. Post-send review is scheduled: bounces, complaints, replies, and opt-outs read within 48 hours.
  11. Attribution is checked: campaign parameters survive to the destination form, or a matching method exists (email matching works when forms strip parameters).

Pre-send sign-off

GateOwnerDateEvidence reference
List
Lawful basis and transparency
AI transparency and oversight
Message
Sending and aftermath
Keep this sheet with the campaign. When a recipient complains or a regulator asks, the question is never whether you meant well; it is what you can show.

Frequently asked questions

Does the EU AI Act apply to us if we are not in the EU?

It can. The transparency obligations attach to systems whose output reaches people in the Union. If you send AI-drafted messages to recipients in the EEA, plan for Article 50 regardless of where you are established.

Is a human approval really enough to avoid a disclosure?

A human-reviewed and human-sent message has an accountable human sender, which is a materially different situation from an automated AI send. Many organizations still choose to disclose. The checklist treats disclosure as always safe and never wrong.

This is how CommsOperator is run, not just written

If the practice makes sense to you, the product built around it is one request away. Tell us what you run and we will tell you if it fits.