I almost got summoned by market regulation last week
My friend Lao Zhang runs a knowledge-payment business (online courses, info products) in Hangzhou. He got summoned by the market regulation bureau in December — he'd been using AI tools to push coupon after coupon at "high-intent" customers, and got reported for "harassment marketing." He told me his legs went weak on the spot.
It's the same thing as DraftKings
EFF (Electronic Frontier Foundation) just published a deep-dive investigation: US betting company DraftKings (Nasdaq-listed) uses AI for behavioral-targeted ads, specifically identifying users prone to gambling addiction, then pushing precisely at them. It's caused a huge uproar in the US.
The AI marketing tools we small teams use — ManyChat, Dianxiaomi, the "smart segmentation" built into every CRM — all basically do the same thing: infer user weaknesses from behavior, then push repeatedly. Just at smaller scale, so nobody's watching yet.
I also made this mistake myself: I used AI to pull out users who'd viewed the pricing page 3 times in the past 7 days, then sent 5 days of different promotional SMS in a row. Only later did I learn this already crosses the red line of Article 24 of China's Personal Information Protection Law on "automated decision-making."
What you can do today: 30-minute self-check
Cost: $0
Time: 30 minutes
Barrier: No coding needed — just being able to read your marketing dashboard
First step: Open your usual AI marketing tool, find the "customer segmentation" or "smart tags" feature, list out every auto-generated tag. Ask yourself one question: which tags are "inferring user weaknesses from behavior"? Things like "price-sensitive," "in decision limbo," "easily persuaded" — these are all high-risk tags.
Stage-specific advice
Just starting (0-10 customers): Don't rush to use AI marketing tools right now. Wait until you have 100 real customers before considering it — before then, sending messages manually is actually more stable and more human.
Got 1-2 stable customer sources: If you're already using AI segmentation, I'd immediately kill all "behavior-prediction" tags, keeping only "info users actively told you" (interests they filled in at signup, content they explicitly clicked).
Scaling up (annual revenue 1M+ RMB / ~$140K USD): I'd spend half a day learning Article 24 of the Personal Information Protection Law, and have a legally-savvy friend review your current AI segmentation rules. This isn't fear-mongering — DraftKings, a multi-billion-dollar market cap company, got flagged. For us small teams, one incident is an extinction-level event.