← BACK TO ENGINEERING
Architecture 10 min read

Who May a 24/7 AI Agent Team Contact? Outreach Channels in Portugal, and the Gate in Front of Every Send

In February I wrote about mining 47,000 businesses from OpenStreetMap and scoring the ones whose websites were failing them. That article ends where the hard part begins. It finds the leads and says almost nothing about how you're allowed to contact them.

That was fine while a person sent every message. It's not fine now.

We're rebuilding that pipeline as Oak Prospector: a team of pi coding agents running around the clock. They discover businesses, gather evidence about their websites, build each promising one a preview of a better site, and then reach out. "Around the clock" and "reach out" in the same sentence should make you nervous. It made me nervous. So before the agents were allowed to send anything, we did the homework: Portuguese law, EU law, what each sending provider permits, and what Gmail will quietly punish.

This is what we found, what we decided, and the part that changed the product.

One caveat up front: this is our research, not legal advice. Where we're unsure, I say so, and there's a list at the end. We'll get an opinion from a Portuguese data-protection lawyer before we scale.


I – The Question Isn't "Can an AI Send Email?"

It's easy to frame this as an AI question. It mostly isn't. The law doesn't care whether a person or a model typed the message. It cares about three things:

  1. Who the recipient is: a company, or a person.
  2. Which channel carries the message: email, SMS, phone, post, a platform DM.
  3. What the recipient can do about it: object, opt out, find out where you got their data.

AI changes one thing specifically: volume without fatigue. A person who sends 40 careful emails a day naturally limits the damage of a mistake. An agent team sends 4,000 overnight if nothing stops it. So the design problem isn't "make the AI polite". It's "make it impossible for the system to send anything a careful person wouldn't have sent", enforced in code, not in a prompt.


II – Portugal Splits Recipients in Two

The core rule is in Portugal's ePrivacy law, Lei 41/2004 as amended by Lei 46/2012:

  • Art. 13.º-A(1): unsolicited marketing to natural persons by automated calling, fax, email, SMS, MMS "and similar applications" requires prior express consent.
  • Art. 13.º-A(2): legal persons (companies) may receive it until they refuse, including by registering on a national opt-out list. That's an opt-out regime.
  • Art. 13.º-A(4): every message must identify the sender and give a valid address for opting out.
  • Art. 13.º-B: the Direção-Geral do Consumidor (DGC) keeps that opt-out list for legal persons. Senders must consult it, updated monthly, available from the DGC on request.
  • Art. 14.º: fines for legal persons run from €5,000 to €5,000,000, enforced by the CNPD.

The regulator's position is in CNPD DIRETRIZ/2022/1. For natural persons with no prior relationship, prior express consent is the only lawful basis. It also treats human-dialled calls like automated ones, which reads broader than the statute. We treat that as the regulator's view and plan around it.

Then comes the sentence that reshaped our product:

Sole traders, empresários em nome individual, are natural persons.

The tasca on the corner and the hairdresser two doors down are usually not companies. They are a person trading under their own tax number. Cold email to them needs consent, even at a business address.


III – Telling a Company From a Person

The practical signal in Portugal is the tax number. By NIF prefix:

NIF starts with Usually means
5 Legal person (company, Lda, S.A., Unipessoal Lda)
6 Public body
9 Irregular entities and other special cases
1, 2, 3 Natural person, which is how most sole traders operate
45 Non-resident individual

OpenStreetMap almost never carries a NIF. Where we find it:

  • in the website footer;
  • on the Livro de Reclamações link;
  • in the public registries.

A company-form suffix in the trading name ("Lda", "S.A.") is a hint, not proof.

So the rule the code enforces is blunt:

No confirmed NIF starting with 5 (or 6/9), with its source stored = treat as a natural person.

For those, email isn't an autonomous channel. Neither is SMS. What's left?


IV – The Channel That Survives: Paper

Addressed post sits outside the ePrivacy consent regime:

  • Lei 6/99 bans addressed advertising once the recipient has objected;
  • GDPR allows it under legitimate interest (Art. 6(1)(f), recital 47), with an absolute right to object (Art. 21);
  • the AMD Robinson list is self-regulation, but checking it is the decent thing to do.

That turns a letter into the only channel an agent may use on its own for most of our market. It turns out to be a good one. Our pipeline already builds each prospect a preview site from their own public content. A letter with a QR code that opens their restaurant's new site is more persuasive than an email, and much harder to mistake for spam.

The letter APIs are there, with caveats:

  • Pingen has a free API, but Portugal isn't a local-print country: letters are printed elsewhere and delivered in about 4–18 business days.
  • LetterXpress has an API and ships internationally via Deutsche Post.
  • CTT's e-carta and direct-mail services print locally but need a contract; we couldn't confirm a public API.
  • Lob sends from the US, which is a poor fit.

Our cost estimate is €1.5–3.0 per letter. That's a guess, not a quote.


V – Email, for Companies Only, and Not From Just Any Provider

For confirmed legal persons, one-to-one email grounded in evidence is lawful until they object. The obstacle is providers, not law. Most transactional email services forbid cold outreach in their acceptable-use policies:

We use those for transactional mail only: the preview link after someone replies, the payment link, receipts.

Cold outreach platforms exist for exactly this and have the APIs agents need: campaigns, reply webhooks, unsubscribe handling, warmup.

Deliverability rules are not optional either:

  • send from secondary domains, never oakoliver.com itself, with SPF, DKIM and DMARC;
  • 30–50 sends per mailbox per day, after 2–4 weeks of warmup;
  • plain text, few links, no tracking pixel;
  • verify every address first, and keep bounces under 2%.

Gmail's sender rules want spam complaints under 0.3%; we aim for under 0.1%. DMARC and one-click unsubscribe (RFC 8058) are mandatory for bulk senders, and we do both at any volume.


VI – The Channels We Ruled Out

Some of these were tempting. None survive contact with the rules:

  • SMS. Opt-out for companies on paper, but carriers and Twilio expect opt-in, and for sole traders it needs consent anyway.
  • AI voice calls. Consent for natural persons, CNPD's broad reading of calls, and since 2 August 2026 the EU AI Act Art. 50 requires systems that interact directly with people to disclose they are AI (background). A cold AI caller is the worst of every world.
  • WhatsApp. Business-initiated messages need prior opt-in and an approved template, billed per message. Cold WhatsApp to scraped numbers breaks Meta's policy and gets the number banned. We use it only after a prospect opts in or writes first.
  • Website contact forms, submitted automatically. A legal grey zone, usually against the site's terms, and CAPTCHA exists precisely to stop this.
  • Google Business Profile chat. It shut down on 31 July 2024.
  • LinkedIn, Instagram and Facebook DMs. Their terms ban bots and automated messaging. Humans only.

VII – The Channel Table the Agents Live By

Everything above collapses into one table, and the agent teams can't go outside it:

Tier Channel Provider Who acts
A 1:1 cold email to confirmed legal persons, generic addresses preferred, at most 3 touches in 14 days lemlist or Woodpecker on warmed secondary domains Agents, autonomously, behind the gate
A Letter or postcard with a QR code to the preview and an opt-out URL, for everyone, including sole traders Pingen or LetterXpress Agents, autonomously, behind the gate
A Transactional mail after opt-in: preview link, payment link, receipts Postmark or Resend Agents, autonomously
A WhatsApp only after opt-in or a first message from them WhatsApp Business Platform Agents, autonomously
B New country, new sending domain, named employees, any claim outside stored evidence the same An agent drafts, a human approves
C Phone calls (legal persons only), LinkedIn/Instagram, visits in person, complaints, legal questions none Humans only; agents plan routes and brief them
✗ SMS, AI voice calls, automated contact forms, DMs to scraped contacts none Nobody

Tier B exists because some rules differ by country. Portugal's opt-out regime for companies is relatively permissive; Germany's UWG §7 requires consent even for B2B email. So every new country needs its own rule set, reviewed by a person, before agents touch it.


VIII – The Gate: Ten Checks, Written in Code

The agents never call a sending provider. They call one endpoint, submit_for_gate, and deterministic code decides. There's no model in this loop and no "the agent was confident". The gate refuses the send if any check fails:

  1. Global suppression. Opt-outs, bounces, complaints and "not interested" replies, on every channel, for every tenant, kept forever as hashes.
  2. Legal-person check. A NIF starting with 5 (or 6/9), with the source of that NIF stored. Otherwise the only channel is post.
  3. DGC freshness. The local copy of the DGC list is less than 31 days old and has no match. If the copy is stale, nothing goes out by email. For post: the AMD Robinson list plus our own objection list.
  4. Caps. 30–50 per mailbox per day, sent during business hours in Lisbon, one active sequence per business.
  5. Evidence-backed claims. Every factual statement ("your site has no HTTPS", "it's not mobile-friendly", "the homepage takes 6 s") maps to a stored evidence record younger than 30 days: a fetch, a DNS check, a screenshot. No invented urgency.
  6. Identity. Oak Oliver's legal name, NIF, address and a named person, as art. 13.º-A(4) requires.
  7. Art. 14 GDPR notice. Where the data came from (OpenStreetMap or the business's own site), why we're writing, and how to object.
  8. Opt-out. A working reply address and a one-click List-Unsubscribe header.
  9. AI disclosure. "Mensagem preparada com apoio de IA". Arguably not required for a plain drafted email under Art. 50, but cheap and honest. Chat or voice agents must always say they're AI.
  10. Audit log. Every decision, pass or refuse, with the reasons and the evidence ids.

Check 5 is my favourite. It makes the pipeline's discipline visible to the recipient. The agents are good at writing persuasive copy, and persuasive copy is exactly where invented facts creep in. The gate doesn't read the copy for tone. It checks that every claim points to a record.


IX – Replies Stop Everything

Any real reply stops the sequence immediately. The reply webhook feeds an agent that classifies the message as one of:

  • interested;
  • question;
  • not now;
  • not interested;
  • unsubscribe;
  • wrong person;
  • auto-reply;
  • bounce;
  • complaint.

Then code applies the rule:

  • Unsubscribe, not interested, complaint: permanent suppression, the same day, across the business's other contacts too.
  • Interested: the preview and payment links go out by transactional email.
  • Not now: snoozed for 90 days, only if they agreed to that.
  • Anything about money, legal matters or a complaint: a human.

The classifier can be wrong. The consequences of it being wrong are limited by design: the worst mistake is a person reading a message they didn't strictly need to.


X – The Honest Accounting

What this research changed:

Before After
Default channel cold email to anyone with an address letters for sole traders, email only to confirmed companies
Who decides a send whoever pressed the button a 10-check gate in code
Factual claims written by whoever wrote the email each tied to a stored evidence record
Opt-outs per campaign global and permanent, across channels and tenants
AI disclosure not considered on every message

What we have not verified yet:

  • The DGC request process and file format. Their pages refused our requests (HTTP 403), so we don't yet know how the list is delivered.
  • Amendments after 2012. We read the 2012 text of art. 13.º-A. We need a consolidated version to confirm nothing changed since.
  • Named employees at companies (joao@empresa.pt). The ePrivacy "subscriber" is arguably the company, but GDPR still protects the named person. For now, generic addresses only, and named ones go to Tier B.
  • Human cold calls to legal persons. The statute and the CNPD's reading don't obviously agree. Tier C, and cautious.
  • Postage. Real quotes, not estimates.
  • Unverified providers. Reply.io, Saleshandy and Vonage.

Before the agents send anything at scale, a Portuguese data-protection lawyer reviews the gate and this table. That's not a formality. It's the last check.

The lesson I'd keep: compliance didn't just limit the product, it improved it. The only autonomous channel for most of our market turned out to be a letter with a QR code to a site we've already built for them. That's a better pitch than any email. The rules pointed at it before we did.

– Antonio

"Simplicity is the ultimate sophistication."