By mid-2026, marketing teams that had spent 2023 and 2024 chasing paid social were quietly rebuilding SMS pipelines, hiring specialists, and paying premium rates for compliance software. The comeback narrative gets told as a technological one — better AI, smarter segmentation, richer data. The real story is the legal exposure hiding inside it.

The tension is this: marketing teams are creating significant legal risk by pasting customer data — phone numbers, purchase history, location signals — into general-purpose AI tools to optimize text campaigns. Shadow AI drove 43% of breaches last year, and the campaign brief has quietly become one of the most common entry points.

The structural reason SMS came back is straightforward. Platforms have tightened the terms of access to their audiences, algorithmic reach has become something closer to a rental agreement, and marketers have rediscovered the appeal of a channel where the recipient’s phone number belongs to the sender’s database, not to a third party that can change the rules overnight. Marketers have increasingly recognized that borrowed access to an audience keeps changing terms, and SMS is the direct response to that recognition.

Text messaging is one of the last mass channels where the sender owns the connection. SMS messages consistently achieve exceptionally high open rates — a function of how phones work. A push notification for a text message is architecturally different from a social feed impression. It arrives. It sits there. It gets read.

But the money is moving into a channel that has become significantly harder to operate inside legally, and this is where most of the industry commentary has been slow to catch up. In the United States, the Telephone Consumer Protection Act continues to be actively enforced, with class actions targeting brands that treated consent as a checkbox rather than a documented process. In the European Union, the layered rollout of the AI Act has created obligations that reach into any marketing operation using automated tools to segment, score, or personalize outbound messaging.

The AI Act’s phased implementation matters here in ways that most SMS vendors are not advertising. According to reporting on the regulation’s rollout, the Act introduces inventory, data governance, audit logging and transparency obligations for general deployers of AI systems, with high-risk use cases — including certain forms of automated profiling — facing stricter requirements and compliance timelines. The AI literacy obligations have come into force, and penalties for high-risk breaches are substantial.

A marketing team using an AI tool to decide who gets which text, when, and with what offer is now, in the language of the Act, a deployer. The tool doesn’t have to be exotic. A consumer-grade large language model being used to draft campaign copy, or to score customer segments, can pull an organization into the framework.

Compliance directors at European retail groups describe the internal shift bluntly to colleagues: the question is no longer whether the marketing team can use AI, but whether anyone can prove what it did and why. Shadow AI — employees pasting customer data into unsanctioned tools — has become the documented risk sitting at the center of this.

Text messaging sits directly in the path of that exposure. A campaign brief pasted into a general-purpose AI tool may contain phone numbers, purchase history, and location data. That data, once submitted, is outside the organization’s control — retained in prompt logs, potentially incorporated into training data, held in jurisdictions the sender cannot audit.

None of this makes SMS a worse channel. It makes it a channel that has to be operated with genuine seriousness by teams that spent the last decade treating marketing tech as a self-service problem.

The AI half of the comeback is more interesting than the marketing press has generally allowed. The useful applications are not the flashy ones. Generative copy for a 160-character message is not where the value sits. The value sits in the boring middle: identifying which customer is likely to unsubscribe if they receive a fourth message this month, which message length correlates with conversion for a specific segment, which time window produces reply rates rather than opt-outs.

These are pattern-recognition problems, and they are exactly the kind of problem where machine learning has always been strong — provided the underlying data is clean, consented, and traceable.

This is the shift many marketing teams have gone through: SMS copy was once drafted in public AI tools, with segmentation prompts run against exported customer files and an audit trail that would have been almost impossible to reconstruct if a regulator came asking. The tools now in use tend to be narrower, slower, and internal. Every message that goes out can be traced to the segment logic that selected the recipient, the consent record that authorized the send, and the human editor who approved the wording. It is a trade a lot of teams are making — slower workflows in exchange for a paper trail that holds up.

That kind of operational rigor was, until recently, considered overkill for a marketing channel. It is now the baseline for staying inside the law in several major jurisdictions.

The data-rules half of the story runs deeper than the AI Act. Geofencing and location-based targeting, once a growth area for SMS, have been complicated by recent Supreme Court reasoning on geofence warrants, which — while directly about law enforcement — has shifted the legal atmosphere around bulk location data. Connected devices are quietly transmitting more information than most consumers understand — a pattern visible across smart appliance data flows more broadly. And attribution itself — the basic question of whether a campaign worked — has become contested, as divergent measurement models across the industry continue to show.

The marketers who are winning at SMS in 2026 are not the ones with the cleverest creative. They are the ones who treated the last two years as an opportunity to rebuild their permission infrastructure from scratch. Explicit opt-in with documented timestamps. Clear opt-out on every message. Segmentation based on first-party purchase behavior rather than inferred demographics. AI use limited to systems the compliance team has inventoried.

What this looks like, day to day, is unglamorous. It is legal review of message templates. It is quarterly audits of consent records. It is training programs for the marketing team on which tools they can and cannot paste customer data into. It is the recognition that trust has become the actual product, and the message is secondary.

There is a temptation, whenever a channel comes back into fashion, to treat the revival as a vindication of the medium. SMS is not back because texting is having a moment. It is back because the alternatives have become more expensive to rent, more legally exposed to operate, and less reliable as a durable connection to a customer. It is a rational response to the enclosure of the open web, not a nostalgic return to something older and simpler.

The organizations that will do well in this next phase are the ones that understand what they are actually being sold when a vendor pitches AI-powered SMS. They are being sold speed. They are also being sold a set of obligations, exposures, and documentation requirements that did not exist three years ago. The urge to chase the next capability tends to obscure the older question of whether the current one is being run properly.

SMS didn’t need to be reinvented to come back. The environment around it changed, and it turned out that owning the connection to the customer — and being able to prove how you use it — was worth more than anyone had priced in.