The EU AI Act's rules for general-purpose AI models became enforceable today.
The obligations have applied since last August; what arrives now is enforcement.
The direction was never subtle: when AI acts on a company's behalf transparency should be in place and someone identifiable should answer for it.
GTM teams already run AI that decides who gets contacted and what gets said.
That question was never hypothetical.
Now it has teeth.
Europe slows down in August. Most teams read that as a reason to wait until September.
We read it as the build window: the one month where nothing is lost by not sending.
A 30-day build started now is a documented, working system by September 1, when Europe starts answering again.
“They opted out” is not a workflow.
A defensible process shows where the request entered, which systems were updated, and how future outreach is suppressed.
If the answer is “the rep remembers,” the process has left the building.
If Cognism sits in your prospect-data layer, you have prospect data.
You still need the operating decisions: who fits, which market rules apply, how opt-outs flow, and what gets recorded.
A database is an input. Governance turns it into a motion.
"Why am I being contacted?" is small talk in the US.
In Europe it can be a data subject access request.
The AI picked the prospect; the company answers the question.
“Which EU market first?” is not answered by market size alone.
Score the shortlist on ICP density, channel fit, data-protection constraints, sales-cycle reality and messaging culture.
The client chooses the market. The framework makes the trade-offs visible.
An opt-out can reach the data tool, sequencer and CRM, then disappear in all of them.
A suppression process must survive system handoffs.
Otherwise, automation keeps resurrecting the lead.
Excellent prospect data does not fix an ownerless EU outbound motion.
Someone has to connect targeting, legal basis, message rules, opt-outs, suppression and records.
When that role is blank, every tool can work and the motion still breaks.
No deal was ever won by a vendor privacy review.
Plenty were lost there. Around 87% of EU enterprise buyers run one before they sign.
A DPA that shows up the same day it is requested is the least glamorous closing technique we know.
Nobody has ever read a regulation and decided to expand.
You expand because your buyers are in Amsterdam.
GDPR shows up four months later, as a constraint on a plan that's already moving, which is exactly why it feels like an obstacle instead of a line item.
So why don't tackle it before all of this?
Outbound compliance gets you into Europe.
Company GDPR readiness helps you close there.
One is about how you reach buyers.
The other is whether you survive their privacy review.
AI outbound is not a volume problem.
It is a decision system: who qualifies, which market rules apply, what the message may say, when outreach stops, and who owns exceptions.
Automation should execute those decisions. It should not improvise them.