TL;DR: Email deliverability now sits between two decisions it does not control. The sender’s stack decides whether the message should exist, and the recipient’s inbox decides whether it deserves attention. Authentication and reputation still determine whether the message is trusted, but the larger architectural question has moved upstream into the decisioning layer.
In April 2026, two European regulators published guidance on tracking pixels in email, and the difference between their positions is more useful than a superficial claim that Europe has settled on one rule.
The French CNIL permits individual open measurement without consent when it is used strictly for deliverability. The sender has to limit the purpose to adjusting frequency, stopping sends to inactive recipients, cleaning the database or selecting another contact channel. The Italian Garante takes a narrower route. It describes an exemption for anonymised, aggregate measurement of campaign open rates when that measurement supports deliverability and anti-spam work, while individual measurement used to improve promotional performance, adapt frequency or infer interests requires consent.
That distinction matters because it separates three activities that email platforms have spent years presenting as one feature: proving that a message can be delivered, maintaining the health of the sending programme and measuring an individual’s marketing response. The first two can support the service. The third observes the person.
The timing is awkward. Engagement platforms are adding models that choose the audience, channel, message, timing and frequency, while mailbox providers are adding models that summarise and rank the result before a person reads it. Deliverability used to be treated as a technical checkpoint near execution. It is becoming the narrow middle of a decision chain that starts before the email exists and ends after it reaches the inbox.
The claim worth making plainly is this: AI does not rescue deliverability at send time. It changes who decides whether there should be a send at all.
Infrastructure still determines whether you are trusted
Nothing about AI changes the deterministic foundation of email.
Google requires domains sending more than 5,000 messages a day to personal Gmail accounts to use SPF, DKIM and DMARC, align the visible sender domain with SPF or DKIM, support one-click unsubscribe for promotional messages and keep the user-reported spam rate below 0.3 percent. Its operational recommendation is stricter: remain below 0.1 percent and avoid ever reaching 0.3 percent. Microsoft applies comparable authentication requirements to high-volume senders reaching Outlook.com consumer domains and rejects non-compliant traffic with a 550 5.7.515 response.
A model cannot negotiate with any of that. It can identify a better hour, choose a better subject line or predict a better audience, but it cannot make an unauthenticated domain trustworthy. It cannot repair an acquisition programme that collected addresses carelessly, remove a spam trap after the damage has been done or make a sudden volume spike look like established behaviour.
I have worked one of these recoveries, and its shape is why I am confident about the claim. The client had ruined its sending reputation in the most ordinary way available, by mailing a poor address list repeatedly until the bounces and the spam complaints did the rest. Nothing could be fixed at send time, because by then the damage was already recorded in the places that decide whether a sender is trusted. The recovery meant moving to a new IP, warming it patiently, and cleansing the list with far more discipline than anyone had wanted to apply when the addresses were first collected. It was slow, and almost none of the work happened inside the campaign tool.
This is why the ESP remains an infrastructure category, even when the surrounding platform calls itself a CEP and puts an agent above it. The intelligence layer decides what to attempt. The infrastructure layer decides whether the attempt is credible.
What has changed is where the risk is created. A campaign can be perfectly authenticated and still damage the programme because it should never have been sent.
AI makes unnecessary email cheaper to produce
Most demonstrations of AI in email begin with production. The model writes the copy, creates the variants, translates the message, proposes the subject lines and assembles the campaign. Each capability can reduce useful work, particularly where localisation and content operations have become bottlenecks.
It also removes a constraint.
Human production capacity was never a sensible contact policy, but it limited how many campaigns a team could create. Once the marginal effort of another variant, another audience and another journey falls sharply, volume can grow without an equivalent increase in expected customer value. The batch-and-blast problem returns with better grammar and more precise personalisation.
That does not mean generated content is inherently bad for deliverability. It means the control that used to come accidentally from production effort has to be replaced deliberately. A mature organisation needs cross-channel contact policies, arbitration between journeys, audience-quality thresholds, publication gates and an explicit view of how much incremental value justifies another interruption.
The useful contribution of AI therefore begins one step before generation. It begins with selection, including the option to select nothing.
The useful AI decision is whether to send
Send-time optimisation is not new. Platforms have used engagement history for years to estimate when an individual is most likely to respond. Bloomreach’s current Optimal Send Time documentation is revealing because it now defaults to clicks and has removed the choice to optimise for opens, explicitly citing the unreliability of open data. The model is still useful, but it answers a narrow question: when should a message that has already been approved be delivered?
The architectural shift appears when the model chooses among email, push, in-app, SMS, a different offer and no message.
BrazeAI Decisioning Studio describes channel, message, creative, offer, incentive, time, day and frequency as dimensions that can be optimised together, and its own implementation guidance includes a no-message option. Klaviyo’s Audience Optimization runs against the final eligible population and removes profiles predicted to be unlikely to engage or convert, or likely to unsubscribe. The exclusion is campaign-specific, and a 30-day cooling safeguard prevents the model from permanently sidelining a recipient. These are materially different from a send-time recommendation because they change the marketer’s audience after the campaign has been defined.
Across the market, three postures remain visible.
The first keeps deliverability infrastructure prominent and adds intelligence on top. Bloomreach combines operational support, warming, reputation work, optimal timing and adaptive frequency, while Adobe combines channel and journey caps, conflict detection, prioritisation and decisioning. This posture keeps the deterministic layer visible, but it still has to prevent easier campaign creation from increasing avoidable volume.
The second begins with cross-channel decisioning. Braze is the clearest example because email competes against other actions and against silence. This is structurally stronger than trying to rehabilitate an address after engagement has collapsed, but it still depends on the same authentication, list quality and reputation controls underneath.
The third prioritises production and leaves governance unchanged. It is the market default whenever a vendor launches faster content, faster journeys and more variants without changing how contact pressure is decided. Klaviyo is the interesting counter-example here, because it comes from an ecommerce tradition where send volume is rarely the thing anyone questions, and it still shipped a feature whose job is to take people out of the send. The technology is not the failure. The unchanged operating rule is.
Figure 1. The feature lists converge quickly, but the posture reveals where each platform expects control to live.
The difference between the three is not whether they contain AI. It is whether AI is being used to produce more messages, optimise approved messages or question the send itself.
What the frequency cap cannot see
The obvious response is that customer engagement platforms already have frequency caps, channel caps and journey-priority rules. They do, and the current Adobe Journey Optimizer model shows how far those controls have developed. Rule sets can combine message caps, journey-entry limits and quiet hours, while conflict detection and priority scores decide which communication wins when several qualify at once.
The important question is not whether the cap exists. It is what the cap can count.
A CEP governs the messages that pass through its own execution perimeter. It can usually count campaigns and journeys, separate promotional from other communication types and apply caps by channel or rule set. It cannot automatically count a payment reminder from a billing platform, a policy document from an insurance administration system, a service notification from a contact-centre workflow, a loyalty message from a separate engine or a campaign sent by a second CEP in another business unit.
Transactional and regulated communication also creates a legitimate exception. Nobody wants a password reset, fraud alert or claim update suppressed because the customer has reached a promotional cap. The individual exemptions are correct, but together they create a customer-level load that no single marketing platform owns.
Consider a deliberately simple example. A bank configures a cap of three promotional messages per week in its engagement platform and respects it perfectly. In the same week, the customer also receives a statement notice, a card-security alert, two payment reminders and a service follow-up generated by systems outside that platform. The marketing cap reports three. The customer experiences eight. Nothing is misconfigured, because the control was applied to the population it was designed to govern.
Figure 2. A platform cap can be correct while the customer’s total contact load is still wrong.
A cap also answers only whether a threshold has been crossed. It does not tell the decisioning model that the third email costs more than the first, that reputation is a shared resource or that one additional interruption needs more incremental value than the previous one. A cap is a wall. Decisioning needs a price.
This is a data-boundary problem as much as a messaging problem. If the meaningful outcome sits in a warehouse, CRM or policy system while the model optimises the channel engagement held by the CEP, then both the objective and the cap are local. The same CDP and CEP boundary appears again, this time as a deliverability constraint, and the argument I made about zero-copy activation applies here too: what matters is never whether the vendor says the word, but whether the data model makes the claim possible.
The inbox now makes its own decision
The sender-side change is happening while the inbox becomes an active decision layer.
Google introduced Gmail’s AI Inbox in January 2026 as a view that filters unimportant mail and surfaces what matters, alongside thread summaries and natural-language answers over the mailbox. Microsoft’s Prioritize My Inbox reviews messages as they arrive, assigns high, normal or low priority using the people, their roles and the message content, and can replace the first line in the message list with a short summary. Microsoft is explicit that this happens in parallel with delivery.
For years, deliverability practice distinguished acceptance, placement and engagement. The receiving server accepted the message, the provider placed it in a folder or tab, and the recipient chose whether to respond. There is now another state between placement and attention: interpretation.
A message can reach the inbox and still be demoted, summarised rather than opened or converted into a task without the recipient reading the original. That does not make sender recognition, design or subject lines irrelevant, and it does not justify a new discipline of optimising copy for inbox AI. It means semantic clarity has become part of visibility. A message composed as one large image, vague urgency and a generic call to action gives both the person and the inbox very little evidence about why it matters. When I argued that email was being rebuilt from the inbox up, this is the part that has moved fastest.
The shift arrives as opens become less useful. Apple Mail Privacy Protection prevents senders from learning whether Apple Mail recipients opened a message and masks their IP address by downloading remote content privately in the background. European regulation constrains when individual open tracking may be used. AI inboxes can allow a recipient to understand and act without producing the behaviour that an open was meant to approximate.
Bloomreach’s move from open-based to click-based optimal timing is one concrete platform response. The broader response has to move measurement closer to outcomes. Clicks remain incomplete, but purchases, account activity, product usage, service actions, subscription changes and explicit preference updates say more about value. Holdout groups remain the only reliable way to establish whether the communication created incremental value rather than merely appearing before an action that would have happened anyway.
Figure 3. Deliverability now sits between a sender-side eligibility decision and an inbox-side interpretation decision.
The open does not become useless overnight. It becomes a signal whose meaning depends on the client, the legal basis and the purpose for which it is retained. The French and Italian guidance makes that last distinction unavoidable.
Deliverability must become a decisioning constraint
Deliverability cannot remain a review performed after the audience, channel, pressure and commercial objective have already been settled. By then, most of the future reputation risk has been created.
The specialist discipline still owns authentication, domain strategy, warming, bounce handling, complaint analysis, monitoring, provider relationships and incident response. It now needs a voice in the configuration of the decision layer above those controls. That does not require the deliverability team to own every model. It requires somebody to answer five questions before the model is trusted:
- What outcome is the model maximising, and is it an open, a click, a purchase, margin or incremental value?
- Does inactivity reduce the probability that email is chosen, or does it only trigger suppression after the damage has accumulated?
- Which communications sit outside the frequency policy, and where is their combined pressure visible?
- Which constraints are suggestions in a prompt, and which are enforced rules?
- What measurement survives when the message is summarised or acted on without an open?
The word “best” should trigger the same questions, because the best channel, time or audience exists only relative to an objective and the data available to the model. A CEP reasoning from recent channel behaviour, a CRM reasoning from relationship status and a warehouse model reasoning from lifetime value can each produce a rational decision and still disagree. The model is not wrong because it is irrational, but because its context is narrower than the customer relationship, which is the test I would apply to any agentic marketing claim.
Deliverability therefore belongs inside customer decisioning as a cost and a constraint, not only after execution as a report. Another email spends reputation, attention and future eligibility even when its marginal delivery cost is almost zero.
Two decisions surround every email
There is no new product category called AI deliverability hiding inside these changes. The problem is being distributed across the stack.
Infrastructure decides whether the sender is trusted, and data determines how much of the customer’s real contact load is visible. Decisioning chooses the action and whether to act, generative tooling makes the communication cheaper to create, and the mailbox interprets the result. Measurement tries to determine whether any of it created value using signals that are becoming less direct.
The same technology can reduce unnecessary contact or industrialise it. It can move a customer to a better channel or produce thousands of variants for an audience nobody questioned. The difference comes from the operating rules around the model and the data perimeter inside which those rules can work.
Deliverability used to ask whether an email could reach the inbox, whether it would avoid the spam folder and whether anyone would engage. AI adds an earlier question that makes the other three conditional:
Should this email be sent at all?
The sender’s stack answers first. The recipient’s inbox increasingly answers again after the message arrives. Everything we used to call deliverability now sits between those two judgements.
The architecture determines which decision you can influence, and which one you can only observe.
Sources
Regulators
- CNIL, Recommendation on tracking pixels in emails, adopted 12 March 2026.
- CNIL, Questions and answers on the recommendation, 22 July 2026.
- Italian Data Protection Authority, Guidelines on tracking pixels in email, 17 April 2026.
Mailbox providers and standards
- Google, Email sender guidelines and sender-guidelines FAQ.
- Microsoft, Requirements for high-volume senders.
- Google, Gmail is entering the Gemini era, 8 January 2026.
- Microsoft, Prioritize my inbox.
- Apple, Use Mail Privacy Protection.
Platform documentation
- Adobe, Message and journey capping rules.
- Braze, BrazeAI Decisioning Studio and AI decisioning implementation guidance.
- Klaviyo, Audience Optimization.
- Bloomreach, Optimal Send Time predictions.
