LeadHaste

Your AI SDR Now Has to Introduce Itself: The EU AI Act Rule That Took Effect August 2

Book a Call →

Your AI SDR Now Has to Introduce Itself: The EU AI Act Rule That Took Effect August 2

Dimitar Petkov
Dimitar Petkov·Aug 6, 2026·9 min read

On 2 August 2026, the transparency chapter of the EU AI Act started to apply. Article 50 of Regulation (EU) 2024/1689 is short, plainly written, and aimed squarely at a design assumption that most AI sales tooling was built on: that the machine never has to say it is a machine.

For outbound teams the practical question is narrower than the headlines suggest. Article 50 does not ban AI in sales, does not require a warning label on every sequence, and does not treat a rep using a writing assistant the same way it treats an autonomous voice agent. What it does is draw a line through the middle of a typical AI sales stack, and a lot of buyers have not looked at which side their tools fall on.

What Article 50 Actually Requires

Four obligations matter, and they land on different parties.

50(1), interaction disclosure. Providers must design systems intended to interact directly with natural persons so that those people are informed they are dealing with an AI system, unless that is obvious from the context. The European Commission's own FAQ says the information must arrive "from the start of the first interaction in a clear and distinguishable manner."

50(2), machine-readable marking. Providers of generative systems must mark synthetic audio, image, video, and text in a machine-readable format that is detectable as artificially generated. Assistive editing functions and systems that do not substantially alter the input are carved out.

50(3), emotion and biometric categorisation. Deployers using those systems must inform the people exposed to them.

50(4), deepfakes and public-interest text. Deployers must disclose artificially generated image, audio, or video content. The text limb is narrower than it is usually quoted: it covers text "published with the purpose of informing the public on matters of public interest," with an exemption where a human exercised editorial review and holds editorial responsibility.

That last distinction is the one being misread across sales forums this week. A cold email is not published to inform the public on a matter of public interest. Article 50(4) does not require you to stamp "written by AI" on your sequences.

Which Parts of an Outbound Stack Are In Scope

ComponentIn scopeWho carries the obligation
AI voice caller that speaks to a prospectYes, 50(1)Provider designs the disclosure; deployer must not defeat it
Website or LinkedIn chat agent qualifying inboundYes, 50(1)Provider
Autonomous reply agent that answers prospects without reviewYes, 50(1)Provider
Generative model producing the copyYes, 50(2) markingProvider of the model
AI drafting a first-touch email a rep reviews and sendsLargely out of the disclosure limbsHuman editorial control applies
Enrichment, scoring, list building, routingNot covered by Article 50Data law still applies

The pattern is consistent. Once software is holding the conversation on its own, disclosure attaches. Once a person is reading the message and taking responsibility for sending it, the transparency chapter has much less to say.

Yes, This Reaches US Teams

The AI Act binds providers and deployers established outside the Union where the output produced by the system is used inside the Union. A Chicago company running an AI voice agent into Munich is squarely inside that description. The Cooley analysis published on 3 August puts the scope as providers, deployers, importers, and distributors that place AI on the EU market or whose AI outputs are used within the EU.

There is one date worth writing down beyond 2 August. Generative systems already on the market get until 2 December 2026 for the machine-readable marking and detection requirement, and content produced before 2 August 2026 does not have to be retroactively labelled.

What We Think Teams Should Actually Do

The honest read is that most outbound programmes need one afternoon of work, not a compliance project. The exception is AI voice, where we would move quickly.

Start with an inventory. Write down every tool in the motion that can produce output a prospect sees or hears without a person approving it first. Not the tools that draft, score, enrich, or route. The ones that speak.

Then get the answer in writing from each of those vendors. Ask where the disclosure appears in the flow, what the exact wording is, whether it can be disabled in the settings, and what their position is on the 2 December marking deadline. A vendor that cannot answer the first question has not read the regulation, which tells you what you needed to know.

Then check your own configuration. Several AI voice platforms ship a disclosure line in the opening turn and also ship a setting that removes it. A provider can build a compliant system and a deployer can switch the compliance off. Find out which state yours is in.

Finally, decide your own standard for the grey zone. We disclose on voice, always, at the top of the call. We do not put an AI label on a human-reviewed email, because the regulation does not ask for it and volunteering an inaccurate one invites a worse conversation about what else is automated.

The Ownership Argument Just Got Concrete

We argue constantly that a client should own the accounts, the data, and the infrastructure underneath their outbound. That has always been an argument about leverage and continuity. Article 50 turns it into an argument about answerability.

If your outbound runs inside a vendor's black box, you cannot say which model wrote what, whether an agent replied without review, whether voice disclosure fired, or where the logs live. When a prospect complains or a regulator asks, "our provider handles that" is not an answer that survives follow-up questions. A team that controls its own stack can open the call recording, show the disclosure, and produce the message history in an afternoon.

Regulation tends to reward the operators who already had their house in order and punish the ones who rented theirs. This one is no different.

Compliance questions are just ownership questions arriving with a deadline. If you cannot explain how your own outbound works, someone else will eventually ask you to.

Dimitar Petkov, LeadHaste

Want an Outbound System You Can Actually Answer For?

We build the data, sending, reply handling, and CRM workflow inside your accounts, document what is automated and what is human, and operate the whole thing against an agreed qualification bar. You keep the infrastructure, the logs, and the ability to answer any question about your own motion.

Book your free pilot →

Frequently Asked Questions

A strong positive reply rate for B2B cold email is 1.5–3%. Top-performing campaigns with tight targeting and personalized copy can hit 4–5%. If you're below 1%, it usually signals a deliverability or messaging problem — not a volume problem.

The safe range is 30–50 emails per inbox per day for warmed inboxes. That's why outbound systems use multiple inboxes (we use 80) — to reach 40,000+ monthly sends while keeping each inbox well within safe limits. Sending more than 50/day from a single inbox risks spam folder placement.

Yes. The CAN-SPAM Act permits unsolicited commercial email as long as you include a physical address, an unsubscribe mechanism, accurate headers, and non-deceptive subject lines. Unlike GDPR in Europe, the US does not require prior opt-in consent for B2B cold outreach.

Domain warm-up typically takes 2–3 weeks. During this period, sending volume gradually increases while the email warm-up tool generates positive engagement signals (opens, replies) to build sender reputation. Skipping or rushing warm-up is the most common cause of deliverability problems.

Cold email is targeted, relevant outreach to a specific person based on their role, industry, or company — with a clear business reason. Spam is untargeted mass messaging with no personalization or relevance. The distinction matters legally (CAN-SPAM compliance) and practically (deliverability depends on relevance signals).

eu-ai-actcomplianceai-sdrcold-emailoutbound
Dimitar Petkov

Dimitar Petkov

Co-Founder of LeadHaste. Builds outbound systems that compound. 4x founder, Smartlead Certified Partner, Clay Solutions Partner.

Newsletter

Get outbound strategies that work — delivered weekly.

Join 500+ B2B leaders getting one actionable outbound insight every week.

No spam. Unsubscribe anytime.

Ready to build outbound that compounds?

We'll build the entire system for your business — and the infrastructure it runs on stays yours.

Book my free review →