Outreach compliance in AI sales tools, measured
Written for revenue operations, sales leadership and the compliance reviewer who gets looped in late. Seven dimensions, the evidence to demand on each, and what 248 go to market software vendors actually disclose about calling consent, AI disclosure, contact data provenance and platform terms.
- Of 248 indexed vendors, 2 document all 7 outreach compliance axes. The average vendor documents 1.96.
- 13 percent address whether their AI identifies itself to a recipient, three weeks after Article 50 of the EU AI Act took effect.
- 20 percent document consent, suppression and opt out mechanics for calling, texting and emailing.
- 31 percent state where their contact data comes from and under what license.
- 106 of 248 vendors carry a failing grade on at least one of the seven.
Published 26 August 2026. Figures recomputed 2026-08-26 from 248 indexed vendors and 4,216 graded capability rows. The index is not a law firm and nothing here is legal advice.
The disclosure gap
Almost every guide to outreach compliance is written by a law firm or by a vendor. The law firm explains the rule. The vendor explains its own controls. Neither can tell a buyer what the market answers, because neither has read the market. The index grades every vendor it covers against the same axes from public artifacts, so that second question has a number.
Of 248 go to market software vendors, 2 document all 7 outreach compliance axes. The average vendor documents 1.96 of 7.
That is the gap between what a category sells and what it evidences. It is not proof that a control is missing. Plenty of vendors satisfy an obligation privately, in a security questionnaire, under an agreement, after a procurement call. But the public record is where a shortlist gets cut, and on the public record this market is thin in a consistent and predictable pattern: thinnest exactly where the newest obligation sits.
Share of indexed vendors whose disclosure on each axis is substantive enough to grade A or B. Grades measure the public record, not private compliance. See the methodology for what each axis asks and how evidence is verified.
What these figures measure, and what they do not
Every grade is assigned from live public evidence: vendor documentation, trust centers, terms and policy pages, public enforcement and platform records. Of the 4,216 graded rows behind this page, the overwhelming majority rest on material the vendor published itself, because that is what exists publicly in this category.
That has a consequence worth stating plainly. A low grade means the public record is thin, not that a control is absent. A vendor may scrub against the do not call registry on every dial, license every record, and disclose its agents by default, and simply never write any of it down where a buyer can find it. What these figures capture is the evidence a reviewer can gather before making contact, which is exactly the stage at which a shortlist gets cut.
Compliance is a property of deployment, not of software. Nothing here says a vendor is compliant or non compliant, and nothing here is legal advice. No vendor pays for inclusion, placement or rating, and no vendor is graded on anything other than the same axes as every other vendor.
Calling and texting: consent, revocation and do not call
The Telephone Consumer Protection Act and the FCC rules under it govern autodialed calls and texts and calls placed with an artificial or prerecorded voice. The FCC has treated AI generated voices as artificial voices for those purposes, which puts a voice agent inside the consent regime rather than outside it. Consent has to exist before the call, survive an audit, and be honored the moment it is revoked, and the numbers have to be scrubbed against the national registry and your own internal list. The obligation sits with the caller. Buying software does not move it to the software company.
- Does the product scrub against the national do not call registry and our internal suppression list before dialing, and how often is that list refreshed?
- How is prior express written consent captured and stored per contact, and can you produce the record for a single disputed number?
- How is a revocation processed, on what timeline, and does it propagate to every other channel we run?
- Does the product place calls with an AI or prerecorded voice, and do your materials address the artificial voice rules by name?
49 of 248 indexed vendors, 20 percent, document consent, suppression and opt out mechanics substantively. 35 carry a failing grade, which on this axis means the public materials describe automated calling, texting or emailing with no consent, do not call or opt out mechanics stated anywhere.
Email: the legal floor and the deliverability floor are different tests
CAN-SPAM sets a low bar and it is still failed regularly: accurate header and sender information, a subject line that is not deceptive, a valid physical postal address, and a working opt out honored promptly. The mailbox providers set a second bar that is higher and enforced faster, covering authentication, complaint rates and one click unsubscribe on bulk sending. A tool can clear the statute and still get your domain filtered, and the practices that create volume are usually the practices that create the filtering.
- Are we sending from our own domain and our own reputation, or from a shared pool we do not control?
- What does the product do about SPF, DKIM, DMARC alignment and one click unsubscribe by default rather than by configuration?
- What complaint or bounce rate triggers a throttle or a suspension, who is notified, and is that documented anywhere we can read before we sign?
- Does the product create or rotate mailboxes and domains at scale, and what is your written position on that practice?
83 of 248 vendors, 33 percent, publish enough about sending infrastructure and throttling to be assessed. Sending discipline is the axis where vendor marketing and vendor documentation most often disagree, because volume is the feature being sold and restraint is the control being asked about.
Whether the AI tells the prospect it is an AI
Article 50 of the EU AI Act has applied since 2 August 2026. It requires that a person interacting directly with an AI system is informed they are interacting with one, unless that is obvious to a reasonably observant person. It reaches providers and deployers, it applies where the output is used in the EU regardless of where the vendor sits, and the ceiling for a transparency breach is 15 million euros or 3 percent of worldwide annual turnover. An AI SDR that signs as a named employee, or a voice agent that presents as a person, is the exact case the article was drafted around.
- Does automated interaction disclose itself by default, or is disclosure a setting we have to go and find?
- Are sender identities real employees, labeled agents, or invented personas, and can we see the default configuration?
- Have you assessed this product against Article 50, and will you put that assessment in writing?
- What does the agent do when a prospect asks it directly whether it is a human?
This is the thinnest ground in the index. Only 32 of 248 vendors, 13 percent, address recipient disclosure and authenticity in any documented way, and 51 carry a failing grade, meaning the product ships fabricated human personas or undisclosed AI interaction by design, or its marketing treats evading detection as a feature. Model transparency is barely better at 15 percent.
Where the contact data came from, and under what license
Every B2B contact record has a provenance. It was licensed from a source, contributed by users running a data sharing arrangement, collected from a public surface, or inferred by a model. Those four are not the same legally, they are not the same commercially, and a vendor that will not class its sources is asking you to carry a risk it has not priced. The question that gets asked last and matters at renewal is what happens to enriched records in your CRM once the contract ends.
- How do you class your sources: licensed, contributed, public record, or inferred, and roughly in what proportion?
- Under what legal basis or license do you hold and resell this data, and does that basis differ by region?
- What contractual protection do we get if a source is challenged, and what does the indemnity exclude?
- What are our rights to records enriched into our own systems after termination?
78 of 248 vendors, 31 percent, state where their data comes from clearly enough to assess, and 24 carry a failing grade. Naming a coverage number is close to universal in this category. Naming a source is not.
B2B contact data is personal data
A work email address attached to a named person is personal data under GDPR, and the fact that the outreach is business to business does not remove it from scope. Where the data was not collected from the person, they are still owed notice, and the right to object to direct marketing is not balanced against anything. In California the opt out of sale and sharing applies to exactly this kind of transfer and data brokers carry registration duties of their own. The practical question for a buyer is whether the vendor has answers ready or whether the first data subject request becomes your project.
- What is your lawful basis for processing and for onward transfer, stated per region?
- How is a data subject access, objection or deletion request handled, and what is the turnaround?
- Are you registered as a data broker where registration applies?
- Is our data or our prospect interaction data used to train shared models, and can we opt out contractually rather than by policy?
92 of 248 vendors, 37 percent, document privacy posture substantively. This is the best answered axis in the outreach cluster, and it is still a minority of the market.
Platform terms: the channel you do not own
The professional networks, the mailbox providers and the CRMs each set their own terms on automation, extraction and volume, and those terms change without a legislative process. Exposure here is not a regulatory question, it is an operational one: the risk is that the channel is switched off, and it is switched off on the account of the operator rather than the vendor. A tool built on an undocumented integration with a platform that prohibits it is a dependency with no notice period.
- Which platform integrations are official and which are automation layered on top of a user session?
- What is your written position on the platform terms that govern those channels?
- What happens to our seats and our data if a platform blocks your access tomorrow?
- Has your access been restricted or terminated by a platform before, and what changed after?
115 of 248 vendors, 46 percent, are clear enough about platform dependency to be graded, and 43 carry a failing grade. The category where this matters most is also the category that discloses least, which is the finding in the table below.
Where the market is strongest and thinnest
Disclosure quality is not evenly spread, and it runs in the opposite direction to exposure. The categories built on channels the vendor does not own disclose least, with linkedin & social selling the thinnest lane in the index at 16 percent. Worth knowing before you assume a shortlist in one lane can be reviewed the way you reviewed a shortlist in another.
Share of graded rows across the seven outreach axes reaching A or B, by category. Vendors appearing in more than one category are counted in each.
Summary
Article 50 of the EU AI Act has required since 2 August 2026 that a person interacting with an AI system be told so. The GTM Tech Index finds that of 248 go to market software vendors, 32 address recipient disclosure in any documented way, 13 percent, and 51 carry a failing grade for shipping undisclosed AI interaction or fabricated human personas by design. It is the thinnest axis of the seventeen the index grades.
Source: GTM Tech Index, August 2026
Coverage claims are close to universal among B2B contact data providers. Source claims are not. The GTM Tech Index finds 78 of 248 vendors, 31 percent, state how their data was obtained and under what license clearly enough for a buyer to assess, while 24 disclose nothing usable about where records originate.
Source: GTM Tech Index, August 2026
Common questions
Are AI powered dialers compliant with TCPA rules for outbound calling?
Compliance is a property of how a dialer is configured and used, not a property of the product, so no vendor is compliant on your behalf. The TCPA obligations sit with the caller. What a buyer can assess before signing is whether the vendor documents the machinery that makes compliant use possible: consent capture and evidence, national and internal do not call scrubbing, revocation handling, and calling window controls. The FCC has treated AI generated voices as artificial voices under the rules, so a voice agent sits inside the consent regime rather than outside it. Across 248 go to market vendors in the GTM Tech Index, 49 document that machinery substantively, which is 20 percent, and 35 say nothing about consent or suppression at all. This is an evaluation framework and not legal advice.
Do AI sales agents have to disclose that they are AI under the EU AI Act?
Yes, where Article 50 applies. Article 50 has applied since 2 August 2026 and requires that a person interacting directly with an AI system is informed of that, unless it would be obvious to a reasonably observant person. It reaches both providers and deployers, and it applies extraterritorially where the output is used in the EU, so a US vendor selling into European prospects is in scope. The transparency penalty ceiling is 15 million euros or 3 percent of worldwide annual turnover. The market has barely responded: of 248 vendors in the GTM Tech Index, 32 address recipient disclosure in any documented way, 13 percent, and 51 carry a failing grade for shipping undisclosed AI interaction or fabricated human personas by design. This is an evaluation framework and not legal advice.
Where do B2B contact data providers source their data and is it licensed?
Sources fall into four classes: licensed from a data supplier, contributed by users under a data sharing arrangement, collected from public surfaces, or inferred by a model. Most providers run a blend and most do not publish the proportions. Of 248 vendors in the GTM Tech Index, 78 state their provenance clearly enough to assess, which is 31 percent, and 24 disclose nothing usable about where records originate. Coverage claims are close to universal in this category; source claims are not. The follow up question that matters commercially is what rights you retain to records enriched into your own systems after the contract ends.
How do you evaluate the compliance posture of an AI outreach tool?
Work through seven dimensions rather than a certification checklist: calling and texting consent, email sending discipline, whether automated interaction discloses itself, contact data provenance and licensing, personal data handling, platform terms exposure, and model transparency. For each, ask what the vendor can evidence rather than what it asserts. Across 248 indexed vendors, only 2 document all 7, and the average vendor documents 1.96.
Which outreach compliance disclosures are most often missing?
Recipient disclosure is the thinnest at 13 percent, followed by model transparency at 15 percent and calling and sending compliance posture at 20 percent. The best answered are platform terms exposure at 46 percent and privacy posture at 37 percent, and both are still a minority of the market.
Does a SOC 2 report tell you anything about outreach compliance?
Very little. A security report covers how the platform protects data. It says nothing about whether consent was captured before a call, whether an agent identifies itself to a prospect, where a contact record came from, or what happens when a platform withdraws access. Those are separate questions with separate evidence, and treating a security certification as an answer to them is the most common shortcut in this category.
Work from the data
Every indexed vendor with its grade on all seventeen axes, including the seven above.
Put a shortlist side by side across the same axes before the diligence call.
Verified changes to vendor posture, including policy, disclosure and regulatory records.
What each grade band means, what counts as evidence, and why a grade measures the public record rather than private practice.