Do you have to disclose AI in emails?

It turns on who sends. An AI agent that writes and sends email to people generally has to say it is an AI and whom it acts for. A draft you review and send yourself carries fewer duties.

An email you draft with AI and send yourself generally needs no label. An AI agent that writes and sends email to people carries a duty: since 2 August 2026, the EU AI Act expects it to disclose that it is an AI and, per the Commission, on whose behalf it acts. Utah, California and AI vendors add narrower rules.

Who this applies to

This page covers email written or sent with AI, by a person or by an AI agent acting for one. The EU AI Act binds the provider of the AI system, which includes a company that builds its own agent and puts it into use under its own name, and it reaches providers outside the EU when the output is used in the EU. In the US there is no single federal AI-disclosure rule for email; Utah and California have narrower state rules. The sender-identity laws (CAN-SPAM in the US, PECR and the ePrivacy Directive in the UK and EU) apply whoever, or whatever, writes the message, and so do the professional rules for brokers and lawyers.

What it actually requires

Work out who is actually sending
The Commission's Article 50 guidelines treat an AI system's capability "to write and send messages to natural persons" as direct interaction with people. They leave out "AI assistance tools" that help a person communicate, and AI output passed on by a person rather than by the system itself. A draft you read, edit and send as your own sits on the assistance side; an agent that sends by itself sits on the other.
If an agent sends, say it is an AI in the first email
Article 50(1) of the EU AI Act requires that people "are informed that they are interacting with an AI system, unless this is obvious", and Article 50(5) asks for that "in a clear and distinguishable manner at the latest at the time of the first interaction". The Commission's own example is "an email generated by an AI agent sent to a natural person that features an AI label at the top".
Name the person or company the agent acts for
The guidelines say AI agents "managing correspondence" must "disclose both their artificial nature and the person on whose behalf they are acting". The email signature is where readers already look for who is writing, which makes it a natural home for that second half. That placement is our reading of the guidelines.
Answer truthfully when someone asks "is this an AI?"
In Utah, a supplier using generative AI in a consumer transaction must disclose it when the person makes "a clear and unambiguous request" to know (Utah Code 13-75-103). A disclosure made at the outset and throughout the interaction earns a safe harbor (13-75-104). California makes it unlawful to use a bot online with intent to mislead about its artificial identity to drive a sale or influence a vote, and a clear disclosure removes liability (Bus. & Prof. Code 17941).
Keep the sender identity accurate
CAN-SPAM bars materially false or misleading header information on commercial and on transactional or relationship email (15 U.S.C. 7704(a)(1)). PECR regulation 23 and Article 13(4) of the ePrivacy Directive bar marketing email that disguises or conceals the identity of the person on whose behalf it is sent. The FTC's impersonation rule (16 CFR 461.3) bars falsely posing as a business or its officers.
Follow your AI vendor's policy
Anthropic's Usage Policy says "All consumer-facing chatbots, including any external-facing or interactive AI agent, must disclose to users that they are interacting with AI rather than a human", and prohibits using outputs to convince people they are talking to a human. OpenAI's Usage Policies prohibit using its services for "deceit, fraud, scams, spam, or impersonation".
In regulated work, supervise and keep records
FINRA's advertising FAQ D.8 says "Firms are responsible for their communications, regardless of whether they are generated by a human or AI technology", including supervision and recordkeeping. ABA Formal Opinion 512 says lawyers "must disclose their GAI practices if asked by a client" and that firms need clear policies on generative AI use.

Myths we hear often

The myth

A human glance before sending exempts the agent.

What the source actually says

The Commission's guidelines say "the mere possibility for humans to intervene or review the AI system's outputs should not be used to circumvent" the disclosure duty. The exemption covers output "properly reviewed and sent by humans as the main interlocutors". On our reading, a one-click approval of mail the agent wrote and sends itself sits closer to the agent side.

The myth

The AI Act only applies to EU companies.

What the source actually says

Article 2(1) covers providers placing AI systems on the EU market "irrespective of whether those providers are established or located within the Union or in a third country", and providers and deployers abroad "where the output produced by the AI system is used in the Union". A US company whose agent emails people in the EU is generally in scope. The guidelines add that incidental, unforeseeable downstream use alone should not trigger it.

The myth

You must label every AI-assisted email.

What the source actually says

Article 50(1) is about AI systems that interact with people directly, and the guidelines exclude AI tools that help a person write. The separate labeling duty for AI text in Article 50(4) covers text "published with the purpose of informing the public", and the guidelines list "private, interpersonal correspondence (for professional purposes)" as text that is not published. Labeling assisted email remains a choice many people make.

The myth

If the AI wrote it, the AI is responsible for it.

What the source actually says

Utah Code 13-75-102 says it "is not a defense" to a consumer protection violation that generative AI made the statement or undertook the act. Under CAN-SPAM, whoever procures a commercial message "initiates" it (15 U.S.C. 7702(9)). FINRA holds firms responsible for AI-generated communications.

A worked example

A fictional example: Tallowmere Foods
Tallowmere Foods, a fictional food wholesaler with suppliers in the US and the EU, runs an AI agent that sends follow-ups on late deliveries and open purchase orders. Each email opens with one line: "This message was written and sent by an AI agent." The agent signs with its own signature block: "Ordering assistant (AI agent), on behalf of the Purchasing team, Tallowmere Foods Ltd", followed by the team's direct email and phone number and the company's registered details. The top line answers whether the reader is dealing with an AI; the signature answers on whose behalf it writes and how to reach a person. Because the agent fetches the same signature block on every send, a supplier sees the same disclosure on the first email and on the tenth.

Questions people ask

Do I have to disclose AI in emails?

If you write an email with AI help and send it yourself, generally no: no EU, UK or US federal rule covered here requires a label on it. If an AI agent writes and sends email to people, the EU AI Act expects it to disclose that it is an AI and, per the Commission, on whose behalf it acts. Utah adds a duty to answer truthfully when a consumer asks.

Do I have to tell customers an email was written by AI?

Generally only in three cases: when the AI sends on its own to people in the EU, when a Utah consumer clearly asks whether they are talking to an AI, and when a California bot would otherwise mislead someone about its artificial identity to make a sale. Sector rules can add more, such as a lawyer whose client asks how the work was done.

Do AI-written emails need a disclaimer?

For an AI agent, the EU AI Act asks for a clear notice at the first email that the reader is dealing with an AI, plus the name of whom it acts for. A short line the reader sees first does that job better than a block of small print at the bottom.

Is it legal for an AI agent to send cold email on your behalf?

Generally yes, if the email meets the same rules a person would: accurate sender details, a postal address and opt-out on US commercial email under CAN-SPAM, an undisguised sender, a valid opt-out address and, where PECR requires it, consent or a soft opt-in in the UK. In the EU, the agent should also disclose that it is an AI and whom it acts for.

Where should the AI disclosure go, the top of the email or the signature?

The Commission's worked example puts an AI label at the top of the email. The signature suits the second half of the disclosure, the person or company the agent acts for, because readers already look there for who is writing. Using both is our reading of the guidelines.

What is a good AI disclosure statement for an email?

Short, plain and placed where the reader sees it first, for example "This email was written and sent by an AI assistant on behalf of [name or team]."

Put your own details on every signature you send

Signatoro puts your name, title and contact details on every signature, free for one person. From the Up to 15 plan, a company adds one compliance footnote to everyone's signature.

Related guides

Other pages in this series

Sources