AI SDR Compliance Checklist 2026: EU AI Act, GDPR, and Deliverability Rules in One Page
Updated on 2 September 2026 · educational content, not legal advice
Short answer: three rule layers apply to AI-assisted outbound, and teams consistently over-worry about the newest one. In enforcement-probability order:
Layer 1 — Provider rules (days to bite): Gmail, Microsoft, Yahoo
- SPF + DKIM + DMARC aligned on every sending domain (hard requirement since 2024-25; grade yours).
- Spam-complaint rate under 0.1%, never sustained above 0.3%.
- One-click unsubscribe honored within 48h on bulk sends.
- Volume ramps measured in weeks on new domains; Microsoft's 2026 ML detection punishes burst patterns and low engagement.
Layer 2 — GDPR / ePrivacy (months to bite)
- Lawful basis documented for B2B prospecting (usually legitimate interest + balancing test on file).
- Business-capacity data only; suppress on objection immediately; honor erasure requests.
- Country nuances matter (Germany/Austria stricter on B2B email than e.g. UK/IE).
Layer 3 — EU AI Act (newest, narrowest for outbound)
- AI-drafted + human-reviewed email: no labeling duty (Article 50 details).
- Autonomous AI reply agents talking to EU prospects: disclose the AI.
- Don't use AI systems for prohibited practices (no emotion-inference targeting on individuals).
- After Dec 2, 2026: assume AI text is machine-detectable; don't build strategy on disguise.
Print this, check quarterly. The technical layer is the one that kills pipelines this week — and the only one that's fully monitorable: continuous checks, free for 2 domains.
Compliance starts at the DNS layer
Whatever the regulators require, Gmail and Microsoft enforce authentication first. Aurelius monitors SPF, DKIM, DMARC and 10 blacklists continuously. Free for 2 domains.
Start monitoring free
EU AI Act series: Labeling overview · EU AI Act Article 50