Quick answerWho owns tracking the consent record the agent checks before sending? Treat consent status as its own structured, auditable field per customer per channel per message category, not something inferred from account activity, so both the agent and a human reviewer can verify the same source of truth. What should the agent do if a customer opts out mid-conversation? Apply the opt-out immediately and confirm it back to the customer in the same conversation; a delay between the opt-out request and it taking effect is itself a compliance gap under most cadence and consent statutes.
Quick answer
The decision to send a proactive marketing or promotional message is governed by consent and frequency law, CAN-SPAM for email, the TCPA for text and calls, separately from whether the message content itself is compliant and separately from whether the agent discloses that it's an AI. Confirm the specific channel-appropriate consent exists (opt-in for TCPA-covered text and calls, a lower opt-out-based bar for CAN-SPAM email in most cases), give the agent a hard cap on how often it can proactively reach out per customer per period, and never let the agent treat an open-ended support relationship as blanket consent to initiate unrelated promotional contact.
A different layer than copy compliance and AI disclosure
Whether AI-generated marketing copy needs the same compliance review as human-written content is a question about the content of the message, the claims it makes, the language it uses. Whether customers need to be told they're talking to an AI agent is a question about identity disclosure during an interaction. Neither answers the question this post is about: whether the agent had the right, under consent and cadence law, to initiate that contact at all in the first place. An agent can produce perfectly compliant copy, disclose its AI nature perfectly, and still violate the TCPA by texting a customer who never opted into promotional texts.
Channel-specific consent bars
Text messages and outbound calls fall under the TCPA in the US, which generally requires prior express written consent for marketing content, a materially higher bar than the consent a customer gives just by providing a phone number for order updates or support. Email marketing under CAN-SPAM has a lower entry bar, an existing business relationship plus a working unsubscribe mechanism is often sufficient, but CAN-SPAM's requirements around honoring opt-outs promptly and not using deceptive subject lines still apply in full. Build the agent's outreach permission as channel-specific, not account-wide: consent to receive order-status texts does not transfer to consent for promotional texts, and the agent needs to check the specific consent record for the specific channel and specific message category before sending.
Setting a hard cadence cap
Beyond the binary consent question, set a hard cap on proactive marketing touches per customer per period, independent of how many separate reasons the agent might generate for reaching out. Without an explicit cap, an agent that can independently decide "this customer might want to know about X" for multiple values of X will out-cadence what any human marketing team would consider reasonable, and cadence complaints are one of the fastest ways an automated outreach program draws regulatory or platform-level scrutiny even when every individual message was technically consented to.
Cross-border consent adds another layer, not a replacement
If the customer is outside your home jurisdiction, layer in the local consent-law differences (several markets require opt-in even for channels where the US allows opt-out-based marketing) rather than applying a single global cadence and consent rule. Treat the domestic TCPA and CAN-SPAM baseline described here as the floor, not the ceiling, once outbound contact crosses a border.

