Hype Index: 'The EU AI Act Now Requires You to Label Your AI Cold Email'
Aug 15, 2026 · 7 min read · by Jordan Kwan
TL;DR: Article 50 of the EU AI Act became applicable on 2 August 2026, and on the face of the text it does not tell a B2B sender to label an AI-written cold email. I mapped all seven paragraphs to the party each binds: two bind providers (the vendors who build the tools), two bind deployers (of emotion and biometric systems, and of deepfakes or text published to inform the public on matters of public interest), and zero of the seven reach a one-to-one sales email. Then I fetched 280 pages across 20 named cold-email and AI-SDR vendors: all 20 talk about GDPR, and 0 of 20 mention the AI Act at all. We score it 85% noise / 15% signal. I am not a lawyer and this is not legal advice.
Thirteen days ago the transparency chapter of the EU AI Act became applicable, and behind the law firm alerts came the vendor and agency content, compressing it into one instruction for anyone running outbound.
What is the claim?
Stated the way it circulates:
The EU AI Act now requires you to disclose that your cold email was written by AI.
It usually travels with a fine attached, and that figure is in the statute, not just the alerts. Article 99(4) sets fines "up to 15 000 000 EUR or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover," and its point (g) is the "transparency obligations for providers and deployers" of Article 50. The penalty attaches to the article. The question is whether the article attaches to you.
I am not a lawyer and nothing here is legal advice. What I can do is read the text and count who it names.
What does Article 50 actually say, paragraph by paragraph?
Article 50 has seven paragraphs. Here is each against the party it binds.
| Para | Binds | Covers | Reaches a 1:1 sales email? |
|---|---|---|---|
| 50(1) | Providers | Systems "intended to interact directly with natural persons" must say they are AI | No |
| 50(2) | Providers | Synthetic audio, image, video or text marked "in a machine-readable format" | No |
| 50(3) | Deployers | Emotion recognition and biometric categorisation | No |
| 50(4) | Deployers | Deepfake image, audio, video; and text "published with the purpose of informing the public on matters of public interest" | No |
| 50(5) | Derivative | How and when to give the information required by 1 to 4 | Only if 1 to 4 apply |
| 50(6) | Savings clause | Does not displace other Union or national obligations | No standalone duty |
| 50(7) | The AI Office | Encourage codes of practice on detection and labelling | No |
Four paragraphs impose a substantive duty. Two land on providers, the company that builds and places the system on the market, not the company that sends email with it. The other two land on deployers, covering emotion and biometric systems (50(3)) and deepfakes plus one category of published text (50(4)).
The 50(4) text limb is the one every guide points at, so here it is verbatim: deployers of a system "that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated." It then carves out content that "has undergone a process of human review or editorial control."
A cold email to one buyer is not published, and a request for fifteen minutes on a Tuesday is not a matter of public interest. Both halves have to be true and neither is. Count reaching a one-to-one sales email: zero of seven.
One honest complication, the strongest version of the other side: 50(2) binds providers, and if you build your own in-house sending agent rather than buying one, the provider in that sentence may well be you. It also carves out systems that "perform an assistive function for standard editing" or "do not substantially alter the input data." Where a templated tool sits on that line is a question for your counsel, not a blog post.
Do the vendors selling AI outreach think it applies to them?
If the deadline landed on outbound, the vendors would say so, because compliance features sell. So on 2026-08-15 I fetched 280 URLs: 14 candidate paths each (trust, security, legal, compliance, privacy, changelog, eu-ai-act, responsible-ai and similar) across 20 named vendors: Outreach, Salesloft, Apollo, Instantly, Smartlead, lemlist, Clay, Regie.ai, 11x, Artisan, Reply.io, Woodpecker, Amplemarket, Lavender, Unify, Warmly, Cognism, ZoomInfo, Seamless.ai and Saleshandy.
83 returned 200, 185 returned 404, 12 returned 403 (all twelve from ZoomInfo), and every vendor returned at least one readable page.
The result: 0 of 20 mention the EU AI Act. Not "AI Act," not "Artificial Intelligence Act," not "Article 50." Zero mention C2PA, content credentials, watermarking or provenance. No vendor serves a page at /eu-ai-act or /ai-act. Five changelogs were readable (Clay, Regie.ai, Warmly, Unify, Woodpecker) and none shipped a disclosure feature.
The control matters. Across the same 280 responses, 110 files contain the string "GDPR," and all 20 vendors have at least one that mentions it. These companies write about EU data law constantly. They wrote nothing about this. Two weeks after the deadline, the count of Article 50 readiness statements in that sample is zero.
Caveat on method: I measured server-returned HTML. Several vendors run JavaScript-rendered trust centers, and my sweep found no "SOC 2" string anywhere either, so that content did not render. Read this as nothing on the pages a crawler receives, which is what an AI assistant gets.
Where does the confusion come from?
Dates, mostly, because two different obligations share an August 2 anniversary. The general-purpose AI model obligations in Chapter V applied from 2 August 2025. Article 50 applied from 2 August 2026, per Article 113. A 2025 guide about model providers marking outputs describes a real duty on a real date, just not this one. Check the article number against the date on every explainer you read.
The Digital Omnibus added a second layer by moving deadlines around it. The Goodwin alert of 3 August 2026 maps the current state: transparency live 2 August 2026, new prohibitions and a legacy marking deadline 2 December 2026, Annex III high-risk pushed to 2 December 2027, embedded high-risk to 2 August 2028. Article 50 was left where it was. When a post says "the AI Act deadline just hit" without naming a chapter, it could mean any of five things.
What should you do instead?
Worry about the laws that have always covered you, because they are stricter about cold email than Article 50 is. GDPR governs the personal data in your sequence: lawful basis, retention, and your ability to answer a subject access request from someone who never asked to hear from you. ePrivacy and its member-state implementations govern the sending, and they are not uniform across the bloc, which is why "it is B2B so it is fine" has been wrong for fifteen years.
The AI in your stack changes none of that. It changes your volume, which is the real exposure, because the fastest way to attract a complaint is to send more mail to people who did not ask for it, and the mailbox providers, unlike Brussels, put a number on that: 30 spam reports per 10,000 delivered. That is also where the performance case gets thin, and the evidence that AI personalization beats a mail merge is thinner than the category admits. Write a disclosure line because it is honest, not because you think Article 50 ordered it.
Verdict
The deadline is real, the fine is real, the article is real. The claim that it lands on your cold email is an inference nobody in the text made, sold off a deadline that applies to somebody else. The market agrees with the text: not one of 20 vendors told a customer otherwise, the same silence you find whenever an outbound claim gets traced to its source. It mirrors the other number the industry is quoting this month, where the source says something more interesting than the marketing does.
Verdict: 85% noise / 15% signal. The 15% is for anyone building their own sender: read 50(2) with your lawyer, not with a listicle.
Written by Jordan Kwan, founder of Reachium.
I build Reachium, the LinkedIn outreach platform behind the tactics you just read. Same brain, live product.
See what Reachium does ↗