The line between AI personalization and AI impersonation just got official
The FTC's 2026 policy statement on deceptive AI and LinkedIn's crackdown draw the same line: AI is fine, fabricated claims aren't. Cold email sits on that line.
By Norbelys Chirinos, Co-founder
Founder-reviewed ·How we research and correct articles
Two unrelated organizations drew the same line within about six weeks of each other in 2026, from very different directions. Neither one was talking about cold email. Both conclusions apply to it directly.
What the FTC actually said
On July 1, 2026, the FTC announced a proposed policy statement, formally published in the Federal Register on July 7, applying the FTC Act’s long-standing prohibition on unfair-or-deceptive practices to AI systems specifically. The core principle: using AI-generated content is deceptive when it creates a false impression that would likely affect a consumer’s decision — regardless of whether that false impression came from a human or a model.
The examples the FTC’s own guidance points to are things like AI-generated before/after photos showing impossible results, fabricated customer reviews, and synthetic endorsements presented as real people who genuinely used a product. The common thread isn’t “AI was involved.” It’s “the content implies something true about a real person or a real outcome that isn’t actually true.” That’s a standard the agency has applied to marketing claims for decades. What’s new in 2026 is the explicit statement that AI doesn’t get a pass on it.
Two things worth being precise about: this is a policy statement, not a final rule, and it was open for public comment through the end of July 2026 — its exact enforcement scope wasn’t settled at time of writing. And it doesn’t mention cold email or B2B outreach anywhere. But the underlying legal logic — a claim that implies something specific and untrue about a real person is deceptive, whether or not AI produced it — doesn’t stop at consumer reviews.
What LinkedIn did, independently
Six weeks earlier, LinkedIn published its own authenticity policy, tightening how the platform ranks and enforces against AI-generated content that lacks a real, disclosed perspective behind it. The policy targets public content — posts, comments, profile material — not private messages, so it’s not a direct statement about outreach personalization. But the principle it codifies is the same one the FTC applied from a different angle: AI assistance is fine. Content that implies more authenticity, expertise, or firsthand experience than actually exists is the problem, and platforms are now willing to algorithmically or contractually act on that distinction rather than treat it as an unenforceable gray area.
Where that leaves personalization in cold email
Personalization in outreach has always lived close to this line, because the entire pitch of a personalized opener is “I know something real and specific about you.” That claim is either true or it isn’t, and 2026’s tooling makes it easier than ever to generate a plausible-sounding version of it without it being true — a line that references a funding round that didn’t happen quite the way it’s described, a “shared connection” that’s a database match rather than an actual mutual acquaintance, a “loved your recent post” that names a post the sender never read.
That kind of fabrication used to be a bad-copy problem: it read a little off, maybe cost you a reply. What the FTC’s policy statement and LinkedIn’s enforcement stance both signal, from different directions, is that it’s becoming a detectable, policy-relevant pattern instead of just weak writing. A regulator is now on record treating AI-generated false impressions as a deception question. A major platform is now willing to suppress or penalize content whose implied authenticity doesn’t hold up. Neither trend requires cold email to be named directly for the practical takeaway to apply.
The practical line for legitimate senders
The standard that survives both of these, and that’s worth adopting whether or not either policy ever names outreach directly: personalization has to be true, not just plausible. Concretely:
- If you reference a trigger — a funding round, a hire, a product launch — it needs to be something you actually verified happened, not a plausible guess a model generated from a company’s general profile.
- If you imply a connection — “noticed we’re both in the same group,” “saw your post on X” — you need to have actually seen it, not have a tool infer it’s statistically likely to exist.
- If a claim about the recipient could be wrong and you haven’t checked, it doesn’t belong in the email, regardless of how much better it makes the personalization read.
None of this requires disclosing that AI helped write the email — that’s a different question, and not one either the FTC statement or LinkedIn’s policy require for private B2B outreach. What both point at is narrower and harder to argue with: the personalization itself has to be real. Cold email personalization at scale still works exactly the way it always did — real research, applied to a real recipient. What’s changed in 2026 is that faking that research is no longer just a copy problem you might get away with. It’s a pattern regulators and platforms are now explicitly built to catch.
Where Norbelys draws the same line
Norbelys’s AI campaign builder drafts copy and personalization from research a sender actually supplies — a real trigger, a real field value, a real segment — rather than inventing a plausible detail about a recipient it has no data on. That draft is a starting point a human reviews before it sends, not a claim that goes out unchecked because a model produced it fluently, and the same principle governs Norbelys’s guardrails around AI-assisted sending more broadly: a human stays accountable for what a real recipient reads as a factual claim about themselves. That’s the same distinction the FTC’s policy statement and LinkedIn’s enforcement stance are both drawing, just applied one step earlier — before the personalization ships, not after a regulator or a platform catches it.