Cold outreach

Using AI to Personalise Cold Email Without Sounding Like a Robot

What language models are genuinely good at in outbound, what they are reliably bad at, and the workflow that produces first lines a human would have written — plus the failure modes that make replies stop.

Every outreach tool now offers AI personalisation. Most of it produces a recognisable genre of sentence: "I was really impressed by Acme Plumbing's commitment to quality service in the Manchester area!" — grammatically perfect, factually empty, and instantly identifiable as machine-written by anyone who has received three of them.

That is not a limitation of the models. It is a consequence of asking the wrong thing. This is the distinction that matters, and the workflow that comes out of it.

What the model is actually good at

Language models are strong at three jobs in this pipeline, and all three are unglamorous.

Summarising input you supply. Given a page of website copy, a model reliably answers "what does this business do, in six words" or "does this page mention online booking". That is reading comprehension, not creativity, and it is dependable.

Classifying at scale. Sorting four hundred businesses into "has a booking system" and "does not", or "single site" and "chain", is the kind of judgement that is easy for a person and tedious at volume. The model does it in a minute and gets it right the overwhelming majority of the time.

Rewriting to a constraint. "Make this three words shorter." "Rewrite this as one question." "Remove every adjective." Deterministic, checkable, useful.

Notice what these have in common: you supply the facts, and the model transforms them. That is the safe operating mode.

What it is reliably bad at

Knowing anything specific about a business it was not told about. Asked to personalise for "Acme Plumbing, Manchester" with nothing else, it will produce something plausible and unverifiable, because that is the only thing it can do. Sometimes the invention is embarrassing — the wrong service, a location they left, an award they never won. That email does not just fail; it tells the recipient you did not check.

Judging what matters. A model given a whole website will pick the most prominent fact, not the most useful one. The homepage banner is what it sees; the fact that the booking form has been broken for a month is what would have earned the reply.

Sounding like a specific person. Default model prose has a texture — balanced clauses, gentle enthusiasm, adjectives that carry no information. It reads as marketing copy, which is precisely the register cold email needs to avoid.

Being interesting. Averaged-out phrasing is the model's core competence. Cold email works by being unexpectedly specific.

The rule that fixes most of it

The model may transform facts. It may not supply them.

Everything else follows. If a claim in the email came from the model rather than from a page you actually fetched, it is a guess, and it is being sent to someone who can check.

In practice, that means separating collection from writing:

  1. Collect real facts about each business — from their site, listing, reviews, job adverts.
  2. Extract a specific data point with the model, from that text only.
  3. Compose the line from the extracted point, in your voice, with the model doing the phrasing and nothing else.

Step one is the part people skip because it is the only part that is actual work. It is also the part that decides whether any of it produces replies.

A workflow that produces usable lines

Take a list of businesses with websites — however you built it, whether that is Google Maps or a web search.

Fetch the pages worth reading. Homepage, services, about, contact. Not the whole site; four pages is plenty and keeps the cost per contact negligible.

Extract, with a prompt that permits failure. Ask for one concrete detail and give the model an explicit way to say no:

From the text below, extract ONE specific, checkable detail about
this business that a stranger could reference in a first sentence.

Rules:
- Use only facts stated in the text. Invent nothing.
- Prefer: services listed, areas covered, team size, years trading,
  how enquiries are handled, tools visibly in use.
- Avoid: adjectives, praise, anything about "quality" or "passion".
- If no specific detail exists, output exactly: NONE

Text:
"""
{page text}
"""

That NONE option is doing most of the work. Without it, every prompt is answered — because a model asked for a detail will produce one whether or not the input contains it. With it, you get a clean split between the contacts you can personalise and the contacts you cannot.

Segment on the result. Detail found: send the personalised version. NONE: send the segment-level version, which references something true of every business in the niche. Both are honest; neither invents anything.

Compose in your own voice. Give the model your best three human-written openers as examples and ask it to write in that register, with a hard word limit. Then read every line before it sends, at least for the first hundred. You will find the tells fast.

The tells to strip out

Search-and-destroy list, from reading a great deal of machine-written outreach:

Pattern Why it fails
"I was impressed by..." Nobody opens an email to a stranger this way
"I came across your website and..." True of every cold email ever sent
"your commitment to quality/excellence/service" Contentless — could be pasted onto any business
"in the [city] area" Filler that signals a merge field
"I hope this email finds you well" The most recognisable opener in the genre
Em dashes in every third sentence A texture readers now associate with machine writing
Three-item lists everywhere Ditto
Exclamation marks Enthusiasm nobody feels toward a stranger's plumbing

A useful test before sending: could this sentence be pasted, unchanged, into an email to a different business? If yes, it is not personalisation, and it costs more than plain text would — because it advertises the automation.

Where AI actually pays off

The honest answer is that the biggest gains are not in the first line at all.

Qualification. "Read this site and answer yes or no: do they take online bookings?" — run over four hundred businesses, this removes the ones your pitch cannot help. That is worth more than any opener, because the largest single cause of no replies is contacting businesses that do not have the problem.

Segmentation. Sorting a list into three groups that each need a different message, automatically.

Reply triage. Classifying inbound replies into interested, not now, wrong person, and unsubscribe requests — and flagging the last of those for immediate processing, which is a legal obligation and an easy thing to lose track of.

Second-language outreach. Writing correct, natural German or Spanish when you do not speak it well. Have a native speaker check the template once; the model handles the variations. Worth noting that markets like Germany and Austria publish contact details far more consistently, so the list quality is often better there too.

Research summaries for the twenty accounts worth real attention, so a human writes a better email faster.

Every one of those is upstream or downstream of the writing. The writing was never the bottleneck.

What to be careful about

Disclosure and honesty. Nothing wrong with drafting with a model. There is something wrong with claiming a specific observation you never made. The line is factual accuracy, not tooling.

Data protection. Sending business contact data to a third-party model is a processing activity. Check what your provider retains and whether it trains on inputs; use a business tier with retention controls if you handle EU data. The general framework for handling public business data sits in is scraping Google Maps legal.

Volume creep. The cheapest thing about AI personalisation is that it removes the natural brake on list size. Sending more, worse-targeted email faster is the most common outcome of adopting these tools, and it lands you above the complaint-rate thresholds that providers actually enforce — the numbers are in the infrastructure guide.

Verification is not optional. A model does not know whether an address exists. It will happily compose a beautiful email to a mailbox that has not existed since 2021, and that bounce damages your domain exactly as much as an ugly email would. Verify first, always.

The test

Print twenty of your generated first lines with the business names removed. Hand them to someone who has not seen the campaign and ask them to match each line to a business.

If they cannot, the lines are not personalised — they are decorated. That is a two-minute test and it is more reliable than any A/B result you will get from a sample of forty sends.

FAQ

Does AI-personalised cold email actually get more replies?

When the personalisation is built from real, per-business facts, yes — the same as any specific opener would. When it is generated from just a company name and city, it performs worse than a plain, honest email, because recognisable machine phrasing signals mass mail.

Will spam filters detect AI-written email?

Filters do not classify by authorship. What they measure is authentication, sending history, engagement and complaint rate. AI writing hurts you indirectly, by lowering reply rates and raising complaints when the personalisation is obviously fake.

What should I use AI for in outbound?

Qualification and classification first, then segmentation, reply triage and second-language drafting. Use it to decide who to contact and to transform facts you collected — not to invent details about businesses you did not look at.

Should I tell recipients the email was AI-assisted?

There is no expectation that you disclose drafting tools, any more than you would disclose a spellchecker. What matters is that every factual claim in the message is true and was actually checked.

How do I stop AI copy sounding generic?

Feed it real facts, give it three examples of your own writing, set a hard word limit, forbid adjectives and praise, and allow it to return "NONE" when the input contains nothing specific. Then read the output before sending.

Keep reading