AI Agent Unsubscribe: Check Consent at Send Time
US, Canadian and EU rules put the opt-out duty on the sender, whatever pressed send. Where an agent's consent data goes stale, and a probe that tests the check.
By Harinderpal Hanspal on August 2026. Updated October 2026
Opt-out duties attach to the sender, whether a person or an agent pressed send. The FTC allows 10 business days to honor an opt-out, and the EU text gives no grace period. A consent check that runs at planning time, not at each send, will miss a Tuesday unsubscribe.
Suppose a contact unsubscribes on Tuesday afternoon. An outbound agent working from Monday's export sends a follow-up on Wednesday morning. Nobody wrote code to ignore the request. The list was correct when the sequence began, and consent lived somewhere the agent never looked.
What the rules say about the sender
In the United States, the FTC's guide for CAN-SPAM says a sender must honor an opt-out within 10 business days, and the opt-out mechanism must keep working for at least 30 days after the message goes out. Each separate violating email can draw a penalty of up to $53,088, the figure printed in the guide, which is adjusted each year. The guide states that the law makes no exception for business-to-business email, and that a sender cannot contract away legal responsibility (FTC, CAN-SPAM Compliance Guide for Business, August 2023, edited January 2024).
Canada words the duty differently. Section 6(1) of the anti-spam law (CASL) bars anyone from sending, or from "cause or permit to be sent", a commercial message without the recipient's consent, and the maximum penalty for an organization is $10,000,000 (Justice Laws Website, S.C. 2010, c. 23). The words "cause or permit" are the ones an agent operator should read twice.
In the EU, Article 21 of the GDPR gives a person the right to object to direct marketing at any time, and once they do, their data shall no longer be processed for that purpose (GDPR Article 21, as reproduced on gdpr-info.eu). The text names no grace period. National rules on email marketing sit on top of it and treat business recipients differently from country to country, so do not read this as a blanket answer for B2B.
Mailbox providers add their own bar. Since 1 February 2024, Google requires senders of more than 5,000 messages a day to Gmail accounts to support one-click unsubscribe, keep the spam rate below 0.10%, and avoid ever reaching 0.30% (Google Workspace Admin Help). That is a provider rule, not a law, and it bites without any regulator involved.
None of these texts asks who or what pressed send.
Where the consent data goes stale
Most teams solve this with a suppression list: export it, load it into the sending tool, and mail from the cleaned list. That works when one person sends once a week.
It breaks in four places. Each channel keeps its own opt-out, so an unsubscribe click in the email tool never reaches the CRM or the LinkedIn queue. A reply that says "please remove me" is prose, and nothing turns it into a suppression row. Bounces and spam complaints are rarely written back at all. And the check often runs when the campaign is planned, so a list that was clean at 9 a.m. Monday goes out unchecked on Wednesday.
An agent makes the last one worse because it works from what it loaded and keeps going. The failure also hides well: a consent check can sit on the send path, run every time, and block nothing if it reads a field that no sender ever fills in.
A probe to run before an agent mails for you
A green test suite does not show that a gate refuses anything. This does.
- Add an address you control to the suppression list.
- Send to it once through every route that can reach a real mailbox: the scheduled sequence, a manual send, a retry, a second channel.
- Expect a refusal from each. Any route that delivers is the finding.
- Break the lookup on purpose, by making the suppression source unreachable, and send again. A safe system skips the send. A system that fails open mails everyone.
- Unsubscribe the test address through the real link, and time how long until step 3 refuses.
Questions to ask a vendor of agent-sent email
- Where is consent checked: when the campaign is built, or at each individual send?
- Which systems write opt-outs into it, and does a reply that asks to be removed count?
- What happens when the check cannot reach its data?
- Do bounces and complaints suppress the address automatically?
- Can you show a test where a suppressed address was refused on every channel?
Drawn from the FTC's CAN-SPAM Compliance Guide for Business (August 2023, edited January 2024), Canada's CASL on Justice Laws, GDPR Article 21 as reproduced on gdpr-info.eu, and Google's email sender guidelines, all read on 6 October 2026. No figure here is a measurement of ours.
Related notes
- Human in the loop for AI outbound agents: review the send, and every route to it
- Test AI-written code by what a silent failure would cost
Related insights
Related paper: Governing agents in production: what to ask before an agent acts