Article

Israel's Spam Law and AI Agents: What You May Send, What You Must Disclose

Regulation for an AI agent selling in Israel: the Spam Law (opt-in, damages up to ₪1,000 per message), Amendment 13 to the Privacy Protection Law, and the duty to disclose AI. Educational, not legal advice.

Illustration of a bridge resting on four compliance pillars: consent, privacy, fair disclosure and consumer rights, with a conversation crossing it toward the close

Israel's Spam Law and AI Agents: What You May Send, What You Must Disclose

An AI agent selling in Israel is subject to the same laws as any business. The Spam Law requires prior consent (opt-in) before commercial outreach, with damages of up to ₪1,000 per message. Amendment 13 to the Privacy Protection Law governs the data you store. Israel has no binding AI law yet, but the direction, at home and worldwide, is transparency: tell the customer they are talking to an automated system.

As more businesses run AI agents that manage sales conversations, answering, reaching out, closing, a question comes up that few stop to ask: what is allowed, and what exposes us? Regulation here is not "coming someday". It is already here, and parts of it are enforced aggressively. This article puts it in order: what the law requires of an AI agent selling in Israel, what is about to change, and how to do it right.

One important clarification first: this is an educational explainer, not legal advice. The law is complex and keeps evolving, and every business should consult a lawyer about its specific situation.

The Spam Law, the single most important rule for outbound outreach

If your agent reaches out to customers, rather than only answering people who wrote to you first, this is the law to know first.

The Spam Law is Section 30A of the Communications Law (Bezeq and Broadcasts), added in Amendment 40 and in force since December 2008. It applies to "marketing material", a message distributed commercially to encourage a purchase, sent by fax, automated dialing, "electronic message" or SMS. Its core rule is simple and strict: you may not send marketing material without the recipient's explicit prior consent (opt-in). The consent must be in writing, and the law explicitly recognizes consent given by electronic message or in a recorded call.

Here is the point many businesses miss: accepting a website's "terms of use", with a consent clause buried inside, does not count as explicit consent under the law. A 2024 ruling established that. Consent must be clear and dedicated to receiving marketing messages, not something the customer "approved" in passing while clicking through a form.

There is a narrow exception for existing customers (Section 30A(c)): outreach without prior opt-in is allowed only if all the conditions hold, the customer gave their details during a purchase or negotiation, was told they would be used for marketing, was given a chance to refuse and did not, and the marketing concerns products of the same kind. Even then, every message must carry an opt-out option.

Enforcement is real. Whoever knowingly sends marketing material in violation of the law is exposed to exemplary damages of up to ₪1,000 per message, with no need for the recipient to prove harm. It is also clear grounds for a class action, and such claims are filed in Israel at scale. To be precise: the Supreme Court (the Glasberg case, 2014) held that the ₪1,000 is a ceiling and a deterrence-oriented starting point, not an automatic fine per message, but the cumulative exposure, especially in a class action, is significant.

And WhatsApp? Caution is needed here. Content decides: a sales message is "marketing material" on any app. The question is the channel. The Ministry of Communications' official FAQ treats the prohibition as applying to "messages on instant-messaging apps (such as WhatsApp)", and lower courts have required that the opt-out be available by a simple WhatsApp reply. That said, and for accuracy, no unambiguous Supreme Court precedent has been located that explicitly holds a WhatsApp message is covered by the law. In practice, WhatsApp marketing is treated as covered. The right caution: treat it as subject to the law, and do not lean on a gray area.

What this means for an AI agent that reaches out to leads

Let's make it practical. If your agent sends outbound messages promoting a product or service, every such message is "marketing material", and therefore:

  • You need opt-in before the first outreach. A lead who left details in a campaign has not necessarily consented to marketing messages, you need clear, dedicated consent.
  • Every marketing message must identify itself: the word "advertisement", the advertiser's name and contact details, and the right to opt out with a simple way to exercise it.
  • Accepting "terms of use" is not enough. If the consent rests on a click through a generic form, it likely fails the explicit-consent requirement.
  • Opt-out must work, at any time, free of charge, in the same channel the message arrived on.

Note that this applies to outbound outreach. Answering a customer who wrote to you first is a different story, there the conversation was opened by them. That distinction, outbound versus responsive, is the practical boundary of the Spam Law.

Privacy, Amendment 13 to the Privacy Protection Law

An AI agent that stores conversations, leads and customer details is running, in the law's eyes, a database, and that triggers the Privacy Protection Law. In August 2025 that law went through its biggest change in decades.

Amendment 13 to the Privacy Protection Law (5784-2024) passed the Knesset in August 2024 and took effect on August 14, 2025. It was designed to align Israel with the European standard (GDPR), and it changes several things that matter to a business running a conversational agent:

  • Database registration, mostly abolished, but the substantive duties remain. Even without a registration duty, you must comply with everything else.
  • A notice at the point of data collection. When the agent collects details from the customer, you must tell them, under Section 11, for what purpose, that providing the data is voluntary, who it will be passed to, and their rights to access and correct it.
  • Data security. The Data Security Regulations (2017) apply: classifying the database's security level, a security procedure, access controls, documentation, and reporting security incidents.
  • A privacy protection officer (DPO). Required, among other cases, when the core activity is systematic monitoring at large scale, or the processing of specially sensitive data (health or financial, for example) at significant scale.

Enforcement got much stronger. The amendment gave the Privacy Protection Authority the power to impose significant monetary sanctions, which can, depending on the scope and type of violation, reach millions of shekels, alongside statutory damages of up to ₪10,000 per violation, in some cases with no proof of harm. In short: a database of sales conversations is not "just data", it is a legal asset that must be managed responsibly.

The duty to disclose AI, where things stand

This is the question people ask most: must you tell the customer they are talking to AI? The answer, as of today, is precise and interesting.

Israel has no binding law yet that explicitly requires disclosing that the interaction is run by an AI system. Israel chose "soft regulation": a policy, regulation and ethics principles document for artificial intelligence (the Innovation and Justice Ministries, 2023) that sets principles, fairness, accountability, transparency, human oversight, but applies them through sector regulators, without a binding cross-sector AI law.

The closest thing to a disclosure duty is a draft guideline from the Privacy Protection Authority (April 2025), under which the notice duty also includes telling a person that the interaction is run by an automated, AI-based system. But, and this matters, it is a draft, it is not binding, and it is contested. It must not be treated as an existing duty; it is an indication of direction, not law.

Worldwide, by contrast, the direction is already binding. The EU AI Act (Regulation (EU) 2024/1689) provides in Article 50 that systems intended to interact directly with people must ensure the person knows they are interacting with an AI system, unless it is obvious. That transparency duty applies from August 2, 2026, and violating it is exposed to fines of up to 15 million euros or 3% of global turnover. An Israeli business serving customers in the EU is subject to it. The US is heading the same way: California's BOT Act (2019) prohibits using a bot to mislead about its identity when driving a purchase, with a safe harbor for clear disclosure; and Utah's AI act requires disclosing the use of generative AI.

And here is our angle. At Upperfloor we do not claim the AI cannot be recognized, and we do not sell an "undetectable bot". We build an agent that runs a natural, human conversation, and always leaves a path to a person. That position is not only right in principle; it is also ahead of the law. While regulation worldwide moves clearly toward mandatory transparency, whoever built on integrity from the start is already on the right side.

Closing and payment in chat, consumer protection

One more layer, for whoever's agent closes and collects payment in the conversation. Such a transaction is a "distance sale" under the Consumer Protection Law, and it triggers duties of its own:

  • Identifying the seller: name, business registration number, and address, alongside the product details, the total price and the cancellation terms.
  • The right to cancel: in a distance sale the consumer may cancel, under the conditions set in the law, generally within 14 days. Certain groups (people with disabilities, people aged 65+, new immigrants) have an extended cancellation period of up to four months when the transaction included a conversation, by phone or in chat.

In other words, when the agent closes a deal, it is not just "making a sale", it enters the space of consumer disclosure duties. A properly built system includes those disclosures in the closing flow.

How to do it right

Boiling all the regulation down to practice, it looks like this:

  1. Real opt-in before outbound outreach, clear, dedicated consent, not "terms of use".
  2. Identification and opt-out in every marketing message, "advertisement", the advertiser's name, and a simple way to opt out.
  3. A collection notice at the point of data collection, and compliance with the data security regulations.
  4. A path to a person and fair disclosure, no "disguise", in line with the regulatory direction at home and worldwide.
  5. Consumer disclosure at the close, the seller's identity and the right to cancel.

The list looks long, but notice: almost every item on it is what a managed sales system does anyway when it is built right, consent, clear identity, a path to a person, and orderly documentation. Regulation does not clash with good management; to a large extent, it is the definition of it. Legal responsibility always stays with the business, but a system built with these rules from the start turns "doing it right" from a burden into a built-in.

Frequently asked questions

Can you send sales messages on WhatsApp without the customer's permission? No. Israel's Spam Law (Section 30A of the Communications Law) requires explicit prior consent (opt-in) before sending marketing material. Sending without consent exposes you to damages of up to ₪1,000 per message, with no proof of harm required. Accepting a website's terms of use does not count as explicit consent, as a 2024 ruling established.

Is there a duty to tell a customer they are talking to AI? Israel has no binding law that explicitly requires it yet, only a draft guideline from the Privacy Protection Authority (2025) that leans that way and is not yet binding. Under the EU AI Act, by contrast, from August 2, 2026 you must inform people they are interacting with an AI system. The global direction is clear: transparency.

What is the penalty for sending spam in Israel? The Spam Law lets the court award exemplary damages of up to ₪1,000 for every marketing message knowingly sent in violation of the law, with no need to prove harm. It is also grounds for a class action. Case law treats the amount as a deterrence ceiling, not an automatic fine.

An AI agent that stores customer conversations, what are the privacy duties? A database of conversations and leads is subject to the Privacy Protection Law. After Amendment 13 (in force since August 14, 2025) you must give the customer a notice at the point of data collection, comply with the data security regulations, and at large scale or with sensitive data, appoint a privacy protection officer. Violations are exposed to monetary sanctions and statutory damages.

If you run, or are considering, an AI agent that talks to customers.

See if it fits your business →

When the path is managed, you don't have to chase.

Two quick questions, and we'll show you how it would work for you

How many leads a month?