July 23, 2026

Do AI Email Disclosure Laws Apply to My Business?

Do AI Email Disclosure Laws Apply to My Business? — Magic Teams AI editorial cover
Photo: Magic Teams AI / generated in the build

For most businesses sending everyday email, no single “AI email disclosure law” forces you to label AI-drafted messages. What the law actually polices is deception and autonomous bots pretending to be human. Magic Teams AI installs email layers on exactly that principle: a founder reviews and approves the drafts, so the message is theirs even when a machine did the typing. The FTC, the EU AI Act, and a handful of state laws all converge on the same line. If a person could reasonably think they’re dealing with a human when they’re not, you disclose. If AI simply helped you write a good email that you stand behind, you almost never do.

That’s the short version. The long version matters, because the rules differ by where your customers live, what your email does, and whether a human is in the loop.

Get it wrong in California, Utah, or the EU and the fines get real. Let’s map it precisely.

Is there one law that governs AI disclosure in email?

No. There is no federal “AI email disclosure act” in the United States, and no global standard either. Instead you’re navigating a patchwork: an FTC deception standard that applies everywhere, a few state laws that trigger on specific conditions, and the EU AI Act for anyone emailing Europeans.

The important reframe is that almost none of these laws care whether AI wrote your email. They care whether your email deceives someone about who or what they’re interacting with. That distinction is the whole ballgame.

Here’s the map of what actually touches email in 2026, and how hard.

Does the FTC require me to disclose AI in emails?

Not for authorship, but yes for deception. The FTC has no rule that says “label AI-written email.” What it enforces is Section 5 of the FTC Act, which bans unfair or deceptive practices, and it has said plainly that AI content gets judged by the same deception, endorsement, and testimonial rules as human content. There is no AI exemption and no AI carve-out (The STACC, 2026).

The test the FTC uses is substantive versus cosmetic. If AI materially changes how a consumer interprets your message, disclosure may be required. If AI use is cosmetic and doesn’t affect interpretation, it isn’t (The STACC, 2026).

So a personalized follow-up email that AI helped write? Cosmetic. An email with an AI-generated “customer testimonial” that never happened, or a bot posing as a named human rep to close a sale? Deceptive, and squarely in enforcement territory.

The stakes aren’t theoretical. FTC civil penalties rose to $53,088 per violation as of January 2025 and stayed there through 2026, and each non-compliant message can count as a separate violation (FTC, 2025). In May 2026 the FTC required Cox Media Group and two other firms to pay nearly $1 million to settle charges they deceived customers about an AI-powered “active listening” marketing service (FTC, 2026).

The Cox case is the tell. The FTC didn’t punish anyone for using AI. It punished a claim about AI that was false, plus a bogus consent story. Use AI all you want. Just never let it lie about who’s talking or what’s true.

What about CAN-SPAM? Doesn’t it cover marketing email?

CAN-SPAM governs your marketing email, but it says nothing about AI. It polices honesty in the envelope, not the identity of the author. The Act requires that you don’t use false or misleading header information, don’t use deceptive subject lines, identify the message as an ad, include a valid physical postal address, and honor opt-outs promptly (FTC CAN-SPAM guidance).

None of those core requirements mention artificial intelligence. An AI-drafted marketing email is exactly as legal as a human-drafted one, provided the “from” line is accurate, the subject isn’t a bait-and-switch, and the unsubscribe works.

Where AI could get you in trouble under CAN-SPAM is indirect. If an AI system spins up misleading subject lines at scale, or generates a fake sender identity, you’ve violated CAN-SPAM, and the fact that AI did it is no defense. Each separate email in violation can draw penalties up to $53,088.

Personal insight

On every install, the CAN-SPAM basics are the thing founders assume they’ve handled and usually haven’t. The AI didn’t break it. Their old templates did, with a stale postal address and an opt-out link that pointed to a dead page. AI just made the volume higher, which made the gap louder.

Do the state AI laws apply to my email?

Sometimes, and it depends on the state and the situation. Three states matter most for email-adjacent AI: Utah, California, and Colorado. The headline is that all three narrowed their rules in 2025 and 2026, so the reality is far softer than the 2024 panic implied.

Here’s how they stack up.

Utah AI Policy Act

Utah was the first state to enact an AI-specific consumer protection law, and its 2025 amendments under SB 226 narrowed it sharply. For most businesses, you must disclose that a consumer is dealing with generative AI only when the consumer makes a “clear and unambiguous request” to know whether they’re talking to a human or a machine (Davis Polk, 2025).

There’s a stricter tier for “regulated occupations.” If you’re in a licensed field, or the interaction collects sensitive personal data or gives personalized advice someone could rely on for a significant decision, you must disclose prominently at the outset (Hunton, 2025). That’s the tier your law firm or accounting practice needs to watch.

For a marketing email a founder reviews and sends? Utah doesn’t force a label.

California

California’s headline AI laws mostly miss your email. The California AI Transparency Act (SB 942, amended by AB 853) applies to “covered providers” running generative AI systems with more than one million monthly users, and its disclosure duties cover AI-generated image, video, and audio content, not text (Mayer Brown, 2025). Its operative date was moved to August 2, 2026, to line up with the EU. Unless you’re a foundation-model provider, that law isn’t about your outbound email.

The one California rule to respect is older: the Bolstering Online Transparency (B.O.T.) Act. It makes it unlawful to use a bot to communicate with a Californian to incentivize a sale or influence a vote without disclosing it’s a bot. That bites when an autonomous reply bot converses back and forth, not when AI drafts an email a human sends.

Colorado

Colorado wrote the strictest AI transparency law in the country, then delayed and rewrote it before it ever took effect. The original Colorado AI Act would have required systems to disclose they’re not human at the start of a consumer interaction. Its effective date slipped from February 2026 to June 2026 during an August 2025 special session, and then in May 2026 Governor Polis signed SB 189, repealing and replacing the original Act and pushing the new framework to January 1, 2027 (Hunton, 2025; Troutman, 2026).

The practical takeaway: as of mid-2026, Colorado’s sweeping “disclose you’re not human” mandate is not in force, and the replacement is narrower, aimed at automated decisions that materially influence consequential outcomes, not everyday email.

Do I have to disclose AI in emails to customers in the EU?

Yes, but only for specific triggers, and a drafted marketing email usually isn’t one of them. The EU AI Act’s Article 50 transparency obligations take effect August 2, 2026, and they apply to anyone whose AI systems reach people in the EU (EU AI Act, Article 50).

Two Article 50 triggers touch email-adjacent activity. First, if you deploy a chatbot or AI system that interacts with people, users must be told they’re dealing with AI, unless it’s obvious to a reasonably observant person. Second, providers of generative AI must mark AI outputs (text, image, audio, video) in a machine-readable way so they’re detectable as artificially generated (European Commission FAQ).

Non-compliance is expensive: fines can reach €15 million or 3 percent of worldwide annual turnover, whichever is higher (SSL.com, 2026).

But note the shape. The chatbot rule is about conversational systems, not a founder-approved newsletter. The marking rule falls hardest on the model provider generating the content, not the small business using a tool. If you draft, review, and send an email as a human, you’re not running an unattended chatbot at your recipient.

What about GDPR and other countries?

GDPR governs how you handle a recipient’s personal data, not whether AI wrote your email. If your AI system profiles contacts or makes automated decisions with legal or similarly significant effects, GDPR’s Article 22 and transparency duties can apply, but that’s a data-processing question, separate from any “AI wrote this” label. Outside the EU and the US, most jurisdictions still lean on general consumer-protection and anti-deception law, which lands you back at the same test: don’t mislead people about who they’re dealing with.

When do I actually have to disclose AI in an email?

Boil the whole patchwork down and disclosure obligations cluster around a single question: could the recipient reasonably believe a human is on the other end when there isn’t? The signature rule we give every founder is simple enough to fit on a sticky note.

If the answer to question one is yes and to questions two and three is no, you don’t need a label. If a human is not in the loop, you almost always do. This is the same logic we build into whether AI emails should disclose they’re not human.

Should I disclose AI even when the law doesn’t require it?

Usually no, and the trust research is why. This is the counterintuitive part. Slapping “written by AI” on a good email tends to hurt you more than help you.

Only 7 percent of consumers say visible AI-generated marketing content makes them trust a brand more, while 31 percent say it makes them trust the brand less, according to December 2025 data from Klaviyo and Datalily (ContentGrip, 2025). That’s roughly four times more likely to cost trust than build it.

An Adobe Express survey of 1,007 US consumers from December 2025 sharpened it: 46 percent said they’d be more likely to unsubscribe from a marketing email if they knew it was clearly written by AI, and nearly one in five had already unsubscribed because they suspected it (Adobe, 2025).

Half of consumers would prefer to give business to brands that don’t use generative AI in consumer-facing content, per an October 2025 Gartner survey of 1,539 US consumers (eMarketer, 2025).

So there’s a genuine tension. The law doesn’t require a label, and the research says a gratuitous label drives people away. The answer isn’t to hide AI. It’s to keep a human genuinely in the loop so the email is authentically theirs, and to be ready to answer honestly if anyone asks.

Personal insight

The founders who obsess over “should we disclose” are usually solving the wrong problem. The email that gets flagged as AI is never the one that says “written by AI.” It’s the one that sounds like nobody. Fix the voice and the disclosure question mostly evaporates. This is why we spend install time on tone before volume.

Sales outreach is the sharpest case. As one practitioner framing puts it, you don’t owe an apology for using AI to write a good email; simply using AI as a drafting tool doesn’t trigger a disclosure obligation (Wonit, 2026). The line you never cross is letting AI impersonate a human or converse autonomously as if it were one.

How should my business set up an email layer that stays compliant?

Build it human-in-the-loop, keep a paper trail, and disclose the bot only where a bot actually talks. Here’s the sequence we run on every install, and it maps cleanly onto the laws above.

The first four steps handle the FTC deception standard and CAN-SPAM. The bot-disclosure step handles California’s B.O.T. Act and the EU chatbot rule. The logging step is your defense if a regulator ever asks who approved a message.

If your email touches EU recipients, the compliance surface widens. Here’s a quick jurisdiction cheat sheet.

Jurisdiction What triggers disclosure Applies to a drafted, human-sent email? Max penalty
FTC (US federal) Deception, fake testimonials, impersonation No, unless the email deceives $53,088 per violation
CAN-SPAM (US federal) False headers, deceptive subjects, no opt-out No AI rule; honesty rules always apply $53,088 per violation
Utah AI Policy Act Clear consumer request; regulated/high-risk interactions Only on request or in high-risk fields Administrative fines
California B.O.T. Act Undisclosed bot conversing to drive a sale No; only for autonomous bots Deception liability
EU AI Act Art. 50 Chatbot interaction; unmarked synthetic media Rarely; targets chatbots and providers €15M or 3% of turnover

For the plumbing side of keeping this safe, see how to connect AI to Gmail and Outlook safely and our broader take on AI data privacy for agencies.

Compliance in AI email is a workflow question, not a labeling question. Keep a human who reviews and stands behind every message, and the legal risk mostly takes care of itself.
SPSatya Phanindra ReddyFounder, Magic Teams AI

What happens if I get this wrong?

The exposure is real but avoidable, and it almost never comes from the AI itself. It comes from deception or a broken CAN-SPAM basic that AI scaled up. A 100-message campaign built on a deceptive claim could, in theory, stack past $5 million in FTC penalties at $53,088 apiece (The STACC, 2026).

But regulators don’t wake up hunting for AI-drafted newsletters. They act on complaints, on obvious deception, and on scaled harm. The Cox Media Group settlement is the pattern: a false claim about what AI did, not the mere fact that AI was involved.

Keep a human in the loop, tell the truth, respect opt-outs, and disclose bots where bots actually talk, and you’re on the right side of every framework above.

Key takeaways

  • There’s no single “AI email disclosure law.” You’re navigating an FTC deception standard, CAN-SPAM, a few narrowed state laws, and the EU AI Act.
  • The law polices deception, not authorship. AI drafting an email a human reviews and sends almost never requires a label.
  • CAN-SPAM still fully applies to AI-drafted marketing email: accurate headers, honest subjects, valid address, working opt-out.
  • Utah requires disclosure on a clear consumer request, and prominently in regulated or high-risk interactions.
  • California and Colorado’s broad “you’re not human” mandates are narrower or not yet in force as of mid-2026.
  • The EU AI Act’s Article 50 (effective August 2, 2026) hits chatbots and synthetic-media providers, with fines up to €15M or 3% of turnover.
  • Voluntary AI labels usually backfire: 46% would unsubscribe from a clearly AI-written email, and only 7% trust visible AI content more.
  • The safe pattern is human-in-the-loop review, truth-checking, bot disclosure only where a bot converses, and audit logging.

Frequently asked questions

Is there a federal law requiring AI disclosure in emails?

No. There is no US federal law that requires you to label an email as AI-written. The FTC enforces a general ban on deceptive practices, and CAN-SPAM governs honesty in marketing email, but neither mandates an “AI-generated” tag. Disclosure is triggered by deception or impersonation, not by the use of AI as a drafting tool.

Does CAN-SPAM say anything about AI?

No. CAN-SPAM predates the AI era and says nothing about artificial intelligence. Its requirements are about accurate sender information, non-deceptive subject lines, identifying ads, a valid postal address, and honoring opt-outs. Those rules apply to AI-drafted email exactly as they do to human-written email, and each violating message can draw penalties up to $53,088.

Do I have to disclose AI if a customer asks whether they’re talking to a human?

In many cases you should, and in Utah you legally must. Utah’s AI Policy Act requires businesses to disclose generative AI use when a consumer makes a clear and unambiguous request to know. Even outside Utah, answering honestly is the safest posture, because dodging the question edges toward the deception the FTC polices.

Do AI email disclosure laws apply if my customers are in the EU?

Partly. The EU AI Act’s Article 50 transparency rules, effective August 2, 2026, require that people be told when they interact with a chatbot and that AI-generated content be machine-readable as AI. A founder-reviewed marketing email is generally not a chatbot interaction, so the chatbot rule usually doesn’t fire. But if you run an autonomous AI reply system reaching EU users, disclosure applies, with fines up to €15 million or 3 percent of worldwide turnover.

Generally yes, as long as a real person is behind it and it isn’t deceptive. Using AI to draft outreach that a named rep sends does not, by itself, trigger a disclosure obligation. The line you cannot cross is letting AI impersonate a specific human or conversing autonomously as if it were a person, which can be treated as a deceptive practice.

What’s the difference between AI helping write an email and an AI bot sending emails?

It’s the difference between a tool and an actor. When AI drafts and a human reviews and sends, the human is the sender and no disclosure is typically owed. When an autonomous bot converses with a recipient without a human in the loop, laws like California’s B.O.T. Act and the EU AI Act require you to disclose that a bot is involved.

Should I add a “written with AI” label to be safe?

Usually no. Voluntary labels tend to reduce trust: 46 percent of consumers say they’d be more likely to unsubscribe from a clearly AI-written email, and only 7 percent say visible AI content makes them trust a brand more. Since the law doesn’t require the label for reviewed, human-sent email, adding one often creates a marketing problem without solving a legal one.

Do state AI laws like Colorado’s apply to my email right now?

Not the broad ones, as of mid-2026. Colorado’s original AI Act, which included a “disclose you’re not human” mandate, was repealed and replaced by SB 189, with a narrower framework not effective until January 1, 2027. Utah’s law is in force but narrow. California’s AI Transparency Act targets large AI providers and image, audio, and video content, not your email text.

Does GDPR require me to disclose that AI wrote an email?

No, not directly. GDPR regulates how you collect and process personal data, not whether AI drafted a message. It can still apply to your email program if you use AI to profile contacts or make automated decisions with significant effects, which brings in transparency and Article 22 rights. That’s a data-handling obligation, separate from any “written by AI” disclosure.

What penalties am I actually exposed to?

FTC civil penalties run up to $53,088 per violation, and each non-compliant message can count separately. CAN-SPAM violations carry the same per-email exposure. The EU AI Act tops out at €15 million or 3 percent of worldwide annual turnover. In practice, exposure comes from deception or broken CAN-SPAM basics scaled up by automation, not from AI authorship itself.

How do I make my AI email setup compliant without hiring a lawyer for every send?

Build it human-in-the-loop. Have AI draft, a named person review and approve, and a system truth-check for fake claims or misleading senders. Disclose a bot only where an autonomous bot actually converses. Keep opt-outs working and log approvals. That workflow satisfies the FTC, CAN-SPAM, and the state and EU rules for the vast majority of business email.


Most founders discover their real risk isn’t the AI. It’s the stale opt-out link, the missing postal address, or the reply bot nobody told them was conversing on its own. An AIOS install starts by mapping exactly where your email touches a customer, then builds the human review and audit trail around it so speed and compliance stop fighting each other. If you want to see where your email layer sits against these rules, that’s a conversation worth having before August rolls around.