---
title: "Is Instagram DM Automation Safe in 2026? An Honest Answer"
slug: is-instagram-dm-automation-safe
author: "Leonardo Maldonado"
category: "Safety & Platform Limits"
articleType: pillar-page
tags: ["DM automation account risk","can you get banned for Instagram automation","safe Instagram DM automation","is Instagram DM automation illegal","how to verify an Instagram DM tool is API approved"]
publishedAt: 2026-08-03T09:00:00.000Z
updatedAt: 2026-08-13T09:00:00.000Z
canonical: https://setluca.com/blog/is-instagram-dm-automation-safe
---# Is Instagram DM Automation Safe in 2026? An Honest Answer

> Instagram DM automation is safe in 2026 when it runs on Meta's official Instagram Messaging API, replies to people who messaged you first inside the 24-hour window, and keeps a human review queue before sending. Luca works this way. Password-based browser bots and cold outreach are what get accounts restricted.

## Key takeaways

- Instagram DM automation is safe when it runs on Meta's official Instagram Messaging API. Meta's Platform Terms say a developer "must not separately request or collect a Meta user's login credentials," so a password prompt is a policy violation on its face.
- Meta gives businesses a 24-hour window to reply after a person's last interaction, and automated replies must respond within 30 seconds.
- Breaking Meta's terms is a contract problem, not a crime. Disclosure laws are different: the EU AI Act's Article 50 transparency duty applies from 2 August 2026, with fines up to EUR 15 million or 3% of worldwide turnover.
- Enforcement escalates: warning, short action block, multi-day feature block, reach reduction, then a disable. Instagram's Account Status is where you see it and appeal it.
- No tool can promise zero risk. Anyone who does is selling you something.

---

So, is Instagram DM automation safe in 2026? Yes, with conditions, and the conditions are the whole article. Meta wrote the rules down. Its developer docs set a 24-hour reply window, a 30-second responsiveness requirement for automated replies, published per-account rate limits, and a ban on any tool that asks for your Instagram password. Tools that respect all four do what the API was built for. Tools that ignore them are what enforcement is hunting.

This guide covers how to check any tool against that standard and what the official connection does under the hood. It also covers which automation types are safe, what enforcement looks like on the way down, and how to recover if it already happened to you.

## Is Instagram DM automation safe, or will it get my account banned?

It's safe when it's built on Meta's rules and risky when it isn't. Meta doesn't ban automation as a category. It bans behaviour that reads as spam, and its Developer Policies name the pattern outright: spam "includes behavior creating bots either manually or automatically, at very high frequencies." How often you send and whether anyone asked you to are what move the risk, not the word "automation."

There are two ways a tool can be wired. One connects through Meta's approved [Instagram Messaging API](https://developers.facebook.com/docs/instagram-platform/instagram-api-with-instagram-login/messaging-api) using an OAuth login -- the Meta-hosted screen where you grant access without ever handing over a password -- and Meta can see and cap every call it makes. The other is a browser bot that logs in as you and clicks through the app, which Meta can neither cap nor allow.

Luca is on the first path. It works like an [AI setter for coaches](/ai-setter): it connects through the official API and drafts replies to people already in your inbox. No password sharing, no cold outreach engine.

## Is Instagram DM automation illegal, or just against Meta's terms?

For almost every coach, it's a terms question. Breaking a platform's terms is a breach of contract, and courts have narrowed the criminal side for years. In *Van Buren v. United States* (2021), the Supreme Court read "exceeds authorized access" under the Computer Fraud and Abuse Act to mean obtaining information from off-limits areas of a system. Misusing information you were already allowed to see doesn't count. In January 2024, in *Meta Platforms v. Bright Data*, a Northern District of California judge found that logged-off scraping of public data didn't breach Meta's terms, because the defendant never "used" the platform as a logged-in user.

Neither case makes automation legal across the board. What they show is the shape of the risk: break Meta's terms and Meta's answer is to cut you off. The real legal danger sits elsewhere, and it grew in 2026.

**Disclosure.** California's bot law makes it unlawful to use a bot to mislead someone "about its artificial identity" in order to incentivize a sale, with a safe harbor: you aren't liable "if the person discloses that it is a bot," clearly and conspicuously. The EU went further. Article 50 of the AI Act, applicable from 2 August 2026 with no grace period, requires that people be told they're interacting with an AI system "from the start of the first interaction in a clear and distinguishable manner," unless it's obvious. The European Commission reads that exception narrowly. Penalties reach EUR 15 million or 3% of annual worldwide turnover.

**Lead data.** The DM is also a place where you collect personal details. The UK's Information Commissioner's Office requires a valid lawful basis before you use someone's details for direct marketing, and for most electronic marketing to individuals that basis is consent. Under the CCPA, California's Attorney General says a notice at collection must list what personal information you collect and why, given "at or before" collection. Deletion requests get 45 calendar days; opt-outs get 15 business days. Meta's Developer Policies stack on top: you must "immediately respect all requests" to block, discontinue, or opt out. If you save DM contacts into a CRM, you're a data controller. Write the notice, honour the stop.

## How do you verify a tool is actually API-approved?

Run these six checks before you connect anything. They take about ten minutes and catch nearly every unsafe tool on the market, because unsafe tools can't fake the first three.

**1. Watch the connection screen.** A compliant tool sends you to a Meta-hosted OAuth screen at facebook.com or instagram.com, where you approve named permissions and come back with a token. If a signup form asks for your Instagram password, stop. Meta's Platform Terms state that developers "may use Meta Products to authenticate users, but you must not separately request or collect a Meta user's login credentials."

**2. Ask which permissions it requests.** The real answer is `instagram_business_basic` and `instagram_business_manage_messages`. A vendor who can't name them hasn't been through App Review, which requires business verification, a screencast showing the permission in use, and a successful live API call.

**3. Check whether they publish rate limits.** Meta publishes hard per-account numbers: 2 calls per second on the Conversations API, 100 per second on the Send API for text, 10 per second for audio or video, and 750 per hour for private replies to comments on posts and reels. Vendors on the API inherit those ceilings and usually say so. Vendors promising "unlimited DMs" are telling you they aren't on it.

**4. Look for browser-automation language.** "No API needed," "works with any personal account," "we handle the login for you," or a required Chrome extension all describe a browser bot.

**5. Check the directory.** Meta runs a public Business Partner directory and a Tech Provider program. A listing is a positive signal. Absence proves nothing on its own, so weigh it against checks 1 to 3.

**6. Ask what happens when Meta changes a rule.** A vendor on the official API gets deprecation notices and keeps a changelog. A browser-bot vendor finds out when the tool breaks, and you find out when your account does.

| Check | Green flag | Red flag |
| --- | --- | --- |
| Login | Meta-hosted OAuth screen | Password field on the vendor's site |
| Permissions | Names `instagram_business_manage_messages` | "We don't need permissions" |
| Limits | Publishes per-account rate limits | "Unlimited DMs," "no daily caps" |
| Method | Cloud-based, no extension | Chrome extension or desktop app |
| Account type | Requires a professional account | "Works with any account" |
| Change handling | Public changelog | Unexplained outages |

We compared the market on these criteria in [the safest Instagram DM automation tool](/blog/safest-instagram-dm-automation-tool).

## How does the official flow work, step by step?

The official path lets Meta see every step, which is why it carries less risk. Here's what happens after you click connect.

1. **OAuth handshake.** You're redirected to a Meta-hosted login and approve `instagram_business_basic` and `instagram_business_manage_messages`. Meta issues the tool a token scoped to those permissions. Your password never touches the vendor.
2. **Webhook subscription.** The tool subscribes to messaging events on your account: `messages`, `messaging_postbacks`, `messaging_reactions`, `messaging_seen`.
3. **A lead messages you.** Meta fires a webhook to the tool's server with the sender's Instagram-scoped ID and the message body. The 24-hour clock starts there.
4. **The draft is written.** The tool reads thread history through the Conversations API and drafts a reply. Nothing has been sent yet.
5. **A human approves.** The draft sits in a review queue. You read it, edit it, send it.
6. **Delivery through the Send API.** The message goes out under your account's rate limits, inside the window. If the window has closed, a person can apply the Human Agent tag, which lets a business manually respond within a 7-day period, for support rather than promotion.
7. **Ongoing compliance.** Automated replies must answer within 30 seconds. Opt-outs must be honoured immediately. Meta may audit the app and can suspend it at any time, "with or without notice."

Step 5 is the one most tools skip. Meta doesn't require a human in the loop, but your report rate is the reason to keep one there.

## Which types of DM automation are safe, and which get you flagged?

Safety tracks who started the conversation. Every low-risk trigger in the table below fires because a person did something first: messaged, commented, replied to a story. Every high-risk one fires because you decided to contact a stranger.

| Automation type | What triggers it | Inside Meta's window? | Risk |
| --- | --- | --- | --- |
| Inbound reply drafting | They DM you | Yes | Low |
| [Comment keyword to DM](/blog/comment-to-dm-automation) | They comment on a post or reel | Yes. Private replies are an approved endpoint, capped at 750/hour | Low |
| [Story-reply automation](/blog/instagram-story-reply-automation) | They reply to your story | Yes | Low |
| FAQ auto-reply or welcome message | They open the thread or tap an ice-breaker | Yes | Low, if it answers in 30 seconds and discloses |
| Follow-up inside a live thread | You reply within 24h of their last message | Yes | Low |
| Timed follow-up after the window closes | A timer, not the lead | No, unless a person applies the Human Agent tag | Medium |
| Auto-DM to every new follower | They followed; they never messaged | Grey. A follow doesn't open a window | Medium to high |
| Cold DM to a scraped list | Your list | No | High |
| Mass DM from a browser bot | Your list, via your password | No, and it breaks Meta's Platform Terms | Highest |

Auto-DM-on-follow is where most coaches get burned. It feels warm to you, and Meta's systems read it as unsolicited contact at volume. If you run one, keep it to a single message and don't chase a non-reply. The full rulebook lives in our [Instagram DM automation rules for 2026](/blog/instagram-dm-automation-rules-2026).

## What still carries account risk in 2026?

Four behaviours carry it, all of them choices about how you send rather than whether you automate. Password-based browser bots break Meta's Platform Terms outright. Cold DMs to people who've never interacted with you are the classic spam signal. Volume spikes on a young account read as automated abuse. High report rates get noticed fastest, because a report is a person telling Meta what your tool is. A coach replying to warm inbound leads at a sane pace trips none of them, which is why an inbound-first [multi-channel DM strategy](/blog/multi-channel-dm-playbook) holds up better than any cold-blast tactic.

### Device, IP, and login hygiene

Meta doesn't only look at what you send. It builds a picture of you from device details, IP ranges, session cookies, and login patterns, and uses it to work out whether one person is behind one account. Automation on the official API never touches that system, because the calls come from a registered app holding a token rather than a fake browser session. Browser bots do touch it, which is where the trouble starts. Four habits keep that picture clean:

- **One account, one set of credentials.** Don't share a login with a VA. Give them access through Meta Business Suite, which is the supported path and leaves an audit trail.
- **Don't route through residential proxies.** Proxy vendors sell them as safety. Meta reads a sudden IP-country change as account takeover, and the response to that is a lock, not a warning.
- **Log in from your normal devices.** A new phone plus a new IP plus a burst of sends in one hour is the combination that triggers a verification challenge.
- **Agencies: connect, don't log in.** Each client account should authorise your app through its own OAuth flow. Ten Instagram passwords in a spreadsheet is a single point of failure and a policy breach.

## What does enforcement actually look like, and how do you recover?

It arrives in stages, and most coaches only notice it at stage three. Meta says most first breaches get a warning rather than a penalty, and that account restrictions usually start around the seventh. Meta doesn't publish how long temporary blocks last, so treat any article quoting an exact hour count as guesswork.

| Rung | What you see | What Meta publishes | What to do |
| --- | --- | --- | --- |
| 1. Warning | A notice in Account Status naming a policy. Nothing is blocked | Most people get "a warning and explanation" on a first violation | Read which policy it names. Change that behavior today |
| 2. Short action block | "Action Blocked" or "Try Again Later" on sends, follows, or comments. Clears on its own | Durations aren't published | Stop the action that triggered it. Don't retry in a loop; repeats extend it |
| 3. Multi-day feature block | DMs stop working while the rest of the account is fine | Developer side: 7 days to fix a responsiveness violation before Meta limits your app's sending | Disconnect the tool. Reply manually and lightly for a few days |
| 4. Reach reduction | Traffic drops. Account Status says your content isn't eligible to be recommended | Account Status shows recommendation eligibility and offers a "Request a Review" button | Request the review. Keep posting. Don't buy engagement to compensate |
| 5. Disable or permanent ban | Login fails, or the account is gone | Restrictions typically begin at the seventh violation, after warnings | Appeal in-app once, with specifics. Export your lead data from your CRM |

### The recovery protocol

If you're in it right now, work through this in order.

1. **Disconnect the tool.** Not pause. Revoke it under Settings, Apps and Websites. If the block is automation-related, continued API calls keep the signal alive.
2. **Stop sending for 48 hours.** Use the app like a person. Read, scroll, reply to two or three DMs by hand.
3. **Open Account Status.** It tells you whether this is a content decision, a recommendation decision, or a feature block, and those need different responses.
4. **Appeal once, and be specific.** Name what you think happened and what you changed. Repeat appeals on the same decision don't speed anything up.
5. **Resume at a third of your old volume.** If you were sending 60 replies a day, come back at 20 and add ten a day.
6. **Find the cause before you reconnect.** If you can't name the behavior that caused it, you'll repeat it. The usual answers are volume, cold contacts, or one template people kept reporting.

We go deeper in Instagram action blocked and on the ban question in [can you get banned for Instagram automation](/blog/can-you-get-banned-for-instagram-automation).

## How do pacing, a review queue, and warm-up lower your risk?

You lower risk by making the whole thing look like a person answering their inbox, because that's what Meta's systems are grading. Keep auto-send off so someone reads every reply, which is what holds your report rate near zero. Build volume up instead of jumping to it. Say openly that a tool helps you answer, and honour any request to stop the moment it arrives.

A workable ramp for a newer account: days 1 to 3, reply by hand only, ten to fifteen DMs a day. Days 4 to 7, turn drafting on, approve everything, cap at 25. Days 8 to 14, cap at 40. After two clean weeks, add ten a day until you hit your natural inbound volume. There's no magic in those numbers. The curve is gradual, and your account has a history before it has a tool. Our [Instagram account warm-up guide](/blog/instagram-account-warm-up) goes further, and [how many DMs you can send per day](/blog/how-many-dms-can-you-send-on-instagram-per-day) covers the ceilings.

This is how Luca ships by default. Every AI reply lands in a **human review queue first, auto-send off** unless you turn it on. The AI does the typing; you keep the judgment.

## A worked example: Marisa's fourteen days from action block to clean inbox

*Illustrative example, anonymised.* Marisa is a strength coach with a mid-sized following. Her twelve-week programme sells at $2,400. In June she installed a Chrome extension promising "unlimited DMs" and set it to message every new follower, plus 900 accounts scraped from a competitor's follower list. It ran six days at roughly 150 messages a day. On day seven she got "Action Blocked" on every DM. Two days later the block came back longer, and her reels stopped showing in Explore.

**Day 1.** Uninstalled the extension and revoked its access under Apps and Websites. Changed her password, since the tool had it. Sent nothing for 48 hours.

**Day 3.** Opened Account Status. It showed her content was not eligible to be recommended. She requested a review and left it alone.

**Day 4.** Replied by hand only, about a dozen DMs a day, and read what the bot had sent. The template opened with "Hey! Saw you follow @competitor, you'd love my programme." That went to 900 strangers. The template was the cause, not the volume.

**Day 6.** Connected an API-based tool through the Meta OAuth screen, confirmed it asked for `instagram_business_manage_messages`, turned auto-send off, and capped approvals at 25 a day.

**Day 10.** The reach flag cleared. She raised the cap to 40.

**Day 14.** No further blocks. Her inbox was slower than the bot had made it look, and every conversation in it had started with the other person.

The reply she uses now, drafted and approved rather than blasted:

> **Lead:** Saw your reel on cutting without losing strength. Do you take 1:1 clients right now?**Marisa (draft, approved before sending):** Hey, glad it landed. Yeah, I've got a couple of 1:1 spots open. Quick one so I don't waste your time: are you training consistently now, or starting fresh? Either's fine, it just changes how I'd set you up.

The lead opened the conversation. The reply went out in her voice, inside the window, with a qualifying question attached. Nothing in it looks like spam because nothing in it is.

## What edge cases do most safety guides skip?

**The lead replies at 2am, or from a timezone twelve hours away.** The 30-second rule applies to automated experiences, so a greeting should still fire at 2am. The sales reply is different. Queue the draft, send it when you wake, and open with an acknowledgement rather than pretending you were up. The window runs on their last message, not your business hours, so you still have 24 hours. What you shouldn't do is let a follow-up timer fire at 4am local for them.

**The window closed at 23 hours and 58 minutes.** You can't reopen it with the standard flow. The Human Agent tag extends it to seven days, but a person has to apply it and it's meant for support, not a pitch. If your only reason to reach back is to sell, let the thread go and catch them with content.

**They already bought.** Existing clients should never sit in the same automation as leads. Tag them out of it. A qualifying question sent to someone who paid you last month reads as carelessness, and clients screenshot that.

**Someone screenshots your AI-assisted reply.** This is the disclosure question in practice. If your bio or your first reply says a tool helps you answer, the screenshot is a non-event. If you've claimed every message is personally typed, it isn't.

## Troubleshooting: symptom, cause, fix

| Symptom | Likely cause | Fix |
| --- | --- | --- |
| Replies fail to send on older threads | The 24-hour window closed on that conversation | Nothing to fix there. The Human Agent tag gives 7 days, applied by a person, for support rather than a pitch |
| "Action Blocked" when the tool sends, never when you send by hand | Volume or velocity above what the account has established | Pause automated sends 48 hours, resume at a third of the volume, ramp from there |
| The tool disconnects every few days and asks you to reconnect | Token expiry, or the vendor mishandles long-lived tokens | Reconnect once. If it repeats weekly, ask which token type they use. A weak answer is a build-quality signal |
| Comment-to-DM works, but the DM never arrives | Private replies are one-per-comment, or the commenter blocks business messages | Reply publicly asking them to DM you. Don't fire a second private reply on the same comment |
| Reach drops right after you connect a tool | Usually unrelated. Recommendation eligibility and message sending are separate systems | Check Account Status. If it flags recommendations, that's a content decision, not a DM one |
| Every reply gets reported | The message content, not the automation | Read your last twenty sent messages aloud. If one would embarrass you in a screenshot, that's your cause |
| Replies go out but nobody answers | Drafts approved too fast, so they read generic | Slow the queue down. Approving 40 messages in four minutes produces 40 messages that sound identical |

## What mistakes get coaches restricted?

Six, and every one of them is a choice about how you send rather than whether you automate.

**1. Treating followers as inbox.** A follow isn't a conversation. Auto-DMing every new follower is the most common way a warm-seeming tactic becomes an unsolicited-contact signal at volume.

**2. Buying the browser extension because it was cheaper.** The price gap is the cost of App Review and API compliance. You aren't saving money; you're moving the risk onto your account.

**3. Turning auto-send on during week one.** You haven't read enough drafts to know what the tool sounds like when it's wrong. Read a hundred first.

**4. Copying a template that worked for someone else.** Report rate is driven by message content, and an opener that lands for a business coach can read as predatory in a nutrition niche. Write your own and test it by hand.

**5. Retrying through a block.** Every retry after "Action Blocked" is another data point confirming automated behavior. Retrying turns a few hours into a few days.

**6. Never checking Account Status.** Coaches spend weeks guessing about a shadowban when Instagram publishes the answer in Settings.

## Should you automate at all? Decision criteria

**Answer by hand if** you get fewer than about ten DMs a day and you're already replying within the hour. A tool would add a step, not remove one.

**Use drafting with a review queue if** you're getting more DMs than you can answer inside a day, or you're losing threads, or you reply fast on Monday and go quiet by Thursday. This is the default for most coaches and the safest configuration that still saves time.

**Turn auto-send on for one narrow trigger if** the reply is purely factual -- a welcome message, an FAQ answer, a link to your intake form -- and you've read at least a hundred drafts from the same tool. Keep the sales conversation in the queue.

**Don't automate at all if** your account is under 30 days old, you're currently under a block, or your plan involves messaging people who haven't contacted you. None of those get safer with better software.

## The one honest limit

No tool can promise you zero risk, and Luca is no exception. Meta changes its rules, deprecates tags, and runs enforcement sweeps that occasionally catch clean accounts. Its Platform Terms reserve the right to act "at any time, including while we investigate your App(s), with or without notice to you." Anyone guaranteeing you'll never get flagged is lying to you. What good automation does is stack the odds hard in your favour and leave your behavior defensible if you ever have to explain it.

There's a second limit worth naming, and it's about judgment rather than policy. A person can read that a lead is grieving, joking, or testing them, and shift tone in the same breath. AI drafts a solid reply, but it won't always feel the room. Two weeks ago a coach we work with had a lead answer a qualifying question with news of a bereavement. The draft was competent and completely wrong. She deleted it and typed four sentences herself, which is exactly what the review queue exists for.

That's the honest version of whether Instagram DM automation is safe: the wiring is a solved problem, the pacing is a discipline, and the judgment is still yours.

Want to see how the review queue and official-API setup work on your plan? Check [Luca's pricing](/pricing) and start inside the rules from day one.


## FAQ

### Is Instagram DM automation against Meta's terms?

Not when it runs on the official Instagram Messaging API. Meta built that API for businesses to reply to customers, and its docs allow replies within the 24-hour window. What breaks the terms is password-based browser bots -- Meta's Platform Terms bar developers from collecting your login credentials -- and cold, unsolicited messaging.

### Is Instagram DM automation illegal?

Breaking a platform's terms is a contract issue, not a crime. In Van Buren v. United States (2021) the Supreme Court read the Computer Fraud and Abuse Act narrowly, limiting it to accessing off-limits areas of a system. Disclosure law is separate: the EU AI Act's Article 50 has applied since 2 August 2026.

### Can you get banned for Instagram automation in 2026?

You can, but usually for spam-like behavior: cold DMs to strangers, sudden volume spikes, high report rates, or unofficial tools. Meta says most first violations get a warning, with account restrictions typically starting around the seventh. Answering warm inbound leads through the official API avoids those triggers.

### How do I know if a DM tool really uses Meta's official API?

Watch the connection screen. A compliant tool sends you to a Meta-hosted OAuth page and never asks for your password, because Meta's Platform Terms forbid developers from collecting credentials. It should also name the permissions it needs and publish rate limits, like the 750 private replies per hour Meta allows.

### What should I do if Instagram blocks my account for automation?

Revoke the tool under Settings, Apps and Websites, then send nothing for 48 hours. Open Account Status to see whether it's a content, recommendation, or feature decision, and use "Request a Review" once. Resume at roughly a third of your previous volume and ramp back up over two weeks.

### What makes safe Instagram DM automation different from a spam bot?

Three things: it uses Meta's approved API instead of your password, it replies to people who contacted you first, and it keeps a human reviewing before anything sends. Automated replies also have to answer within 30 seconds under Meta's responsiveness rules. Spam bots do the opposite on all counts.

### Does Luca auto-send messages for me?

No, not unless you switch it on. By default, auto-send is off. Luca drafts replies in your voice and puts them in a review queue, and you approve or edit before anything goes out. That human check keeps your report rate low, which is the signal Meta's enforcement systems weigh most heavily.

### How do I warm up a newer Instagram account for DM automation?

Ramp slowly. Reply by hand for the first three days, cap approvals around 25 a day through week one, then 40 through week two. Meta's per-account rate limits allow far more, but a young account with no behavioural history is judged on its own curve, not the ceiling.


## Sources

1. [Meta for Developers -- Messenger Platform and Instagram Messaging API policy](https://developers.facebook.com/documentation/business-messaging/messenger-platform/policy)
2. [Meta for Developers -- Messenger Platform policy (responsiveness requirements)](https://developers.facebook.com/docs/messenger-platform/policy)
3. [Meta for Developers -- Instagram Platform overview and rate limits](https://developers.facebook.com/docs/instagram-platform/overview/)
4. [Meta for Developers -- Instagram messaging API with Instagram Login](https://developers.facebook.com/docs/instagram-platform/instagram-api-with-instagram-login/messaging-api)
5. [Meta Platform Terms](https://developers.facebook.com/terms/)
6. [Meta Developer Policies](https://developers.facebook.com/devpolicy/)
7. [Meta for Developers -- Instagram Platform App Review](https://developers.facebook.com/docs/instagram-platform/app-review)
8. [About Meta -- How we're improving Facebook's penalty system](https://about.fb.com/news/2023/02/meta-is-improving-facebooks-penalty-system/)
9. [Instagram -- Understanding Instagram outages and Account Status](https://about.instagram.com/blog/announcements/instagram-outages-and-account-status)
10. [European Commission -- Transparency obligations under Article 50 of the AI Act](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act)
11. [California Business and Professions Code § 17941](https://law.justia.com/codes/california/code-bpc/division-7/part-3/chapter-6/section-17941/)
12. [California Attorney General -- California Consumer Privacy Act (CCPA)](https://oag.ca.gov/privacy/ccpa)
13. [Information Commissioner's Office -- Sending direct marketing: choosing your lawful basis](https://ico.org.uk/for-organisations/direct-marketing-and-privacy-and-electronic-communications/sending-direct-marketing-choosing-your-lawful-basis/)
14. [Supreme Court of the United States -- Van Buren v. United States, No. 19-783 (June 3, 2021)](https://www.supremecourt.gov/opinions/20pdf/19-783_k53l.pdf)
15. [Farella Braun + Martel -- Major Decision Affects Law of Scraping and Online Data Collection: Meta Platforms v. Bright Data](https://www.fbm.com/publications/major-decision-affects-law-of-scraping-and-online-data-collection-meta-platforms-v-bright-data/)

---

Published by SetLuca, the company behind Luca.