Yes, if the consent was already valid for that recipient and that purpose — CASL doesn’t have a separate rule for who, or what, hit send.
Short answer
Yes, provided the underlying consent already covers the recipient and the purpose of the message. Canada’s anti-spam law regulates the commercial electronic message itself — who consented to receive it, and whether it identifies the real sender and offers a working unsubscribe — not the software that composed or dispatched it. An AI tool sending on a consent record that was already valid changes nothing. An AI tool that expands who gets messaged, or what they get messaged about, can quietly step outside it.
Section 6(1) of CASL prohibits sending a commercial electronic message “unless the person to whom the message is sent has consented to receiving it, whether the consent is express or implied,” and the message meets the identification, contact and unsubscribe requirements in s.6(2). None of that turns on authorship. Section 6(4) goes further and defines sending in purely mechanical terms: “an electronic message is considered to have been sent once its transmission has been initiated,” and it is “immaterial whether the electronic address… exists or whether an electronic message reaches its intended destination.” (CASL s.6(4)) The trigger event is transmission, full stop — a person clicking send and an AI agent executing a send action are the same event under the Act.
Where consent isn’t express, CASL allows implied consent from an existing business relationship — broadly, a purchase, lease or contract within the prior two years (CASL s.10(9)–(10)). That consent is scoped to the relationship and the kind of message it supports. An AI agent that keeps sending the same category of message — a renewal reminder, a service update — to the same list rides on exactly that consent. An AI agent that starts messaging a new purpose (a cross-sell campaign the recipient never agreed to) or a list built by having the tool infer or scrape contacts is not covered by the old record just because a human isn’t typing each message. Treadstone Law’s breakdown of implied vs express consent walks through how that line gets drawn in practice.
Section 6(2) requires the message to identify “the person who sent the message and the person — if different — on whose behalf it is sent,” and to include a working unsubscribe mechanism under s.11. If an AI tool auto-generates the sender line, it still has to name the real sending business, not the AI product. And it doesn’t buy extra time: unsubscribe requests still have to be honoured “without delay, and in any event no later than 10 business days” (CASL s.11(3)) no matter how much volume the automation produces. The penalty for getting any of this wrong is not scaled down for good intentions — s.20(4) sets a maximum administrative monetary penalty of $1,000,000 for an individual and $10,000,000 for any other person.
For the email-specific version of this question, see whether AI email marketing is legal in Canada. Outbound calling is a different regime entirely — see whether an AI voice agent counts as an automated dialler.
See how AI fits into a compliant growth and marketing engine.