The Social Media Automation Rulebook for AI Agents 2026
None of 10 platforms' rules clearly let an AI agent reply or DM unapproved and uninvited. Bluesky, LinkedIn, TikTok and YouTube are unclear.
10 platforms, 5 actions, 470 quotes from 175 platform documents, checked 8 October 2026
Which automated actions do the platforms ban outright?
These automated actions are prohibited outright by the platform's own rules, as of 8 October 2026. This study reads written rules and does not measure which actions lead to a ban.
- X, like. Banned: you may not like posts in an automated manner. Source
- LinkedIn, using its APIs to automate posting. LinkedIn's API Terms say developers agree not to use the Content or the APIs to automate posting, a term LinkedIn does not define. Source
- TikTok, like. Banned: the Community Guidelines list using bots or scripts to increase likes or shares as spam that is not allowed. Source
- Bluesky, sending DMs. The developer guidelines count automated or bulk messages that notify someone as spam. Source
- Bluesky, follow. Automated or bulk follows that notify someone count as spam. Source
Can an AI agent reply to comments or send DMs on its own?
| Platform | Publish a post | Reply or comment | Send a DM | Follow | Like |
|---|---|---|---|---|---|
| X | Owner consentUnclear | Recipient firstOwner consentPlatform approval | Recipient firstOwner consent | Docs disagreeOwner consent | Banned |
| Banned | Unclear | UnclearPlatform approval | Not stated | Unclear | |
| Owner consentPlatform approval | Owner consentPlatform approval | Recipient firstOwner consentPlatform approval | Not stated | Owner consentPlatform approval | |
| Owner consentPlatform approval | Owner consentPlatform approval | Recipient firstOwner consentPlatform approval | Unclear | Owner consent | |
| Threads | Owner consentPlatform approval | Owner consentPlatform approval | Not stated | Not stated | Owner consent |
| TikTok | Owner picks eachOwner consentPlatform approval | Unclear | Unclear | Unclear | Banned |
| YouTube | Owner consentUnclearDocs disagree | Owner consentUnclear | Not stated | Owner consentUnclear | Owner consentUnclear |
| Owner picks eachOwner consentPlatform approval | Owner consentPlatform approval | Owner consentPlatform approval | Owner picks eachOwner consentPlatform approval | Platform approval | |
| Bluesky | No gate stated | Docs disagree | Banned | Banned | Docs disagree |
| Platform approval | Platform approval | Platform approvalUnclear | Not stated | Owner picks eachPlatform approval |
Source: Blotato, The Social Media Automation Rulebook for AI Agents 2026, checked 8 October 2026. "Owner consent" may be given once, so it is not counted as blocking. "No gate stated" means the checked documents set no per-action condition. TikTok's reply, DM and follow cells depend on region. Download PNGLink to chart
On X the recipient must opt in first and AI reply bots also need X's written approval. On Facebook and Instagram a DM must answer a message or a comment. With approval, Threads lets an app reply to public posts the user recently searched for, and Reddit asks for no prior action from the other person, though it requires automated accounts to register for an App label.
Source: Blotato, The Social Media Automation Rulebook for AI Agents 2026, checked 8 October 2026. A platform counts in a row if its reply or DM rules carry that gate, and can carry several. The headline counts a platform as unclear when its reply or DM rule is unclear and that action has no other gate. Reddit's unclear DM rule also needs platform approval, so it counts as gated. Download PNGLink to chart
Can an AI agent publish posts on its own?
On 5 of 10 platforms, yes, with no per-post choice by the account owner: Bluesky, Facebook, Instagram, Reddit and Threads. On Facebook, Instagram and Threads, an app needs Meta's approval to publish for anyone beyond the developer's own and test accounts, and Reddit requires approval for any API access. Reddit stops accepting new requests for public API access on 31 October 2026, and existing access starts to close on 12 January 2027.
LinkedIn's API Terms say developers agree not to use the Content or the APIs to automate posting. The same API lists posting on a member's behalf as an open permission, which grants access but does not settle what the terms allow, and LinkedIn does not define "automate posting". On X and YouTube the rules are unclear: X says a service must show exactly what will be published before publishing, and YouTube says users must have final control over what is published.
Do you have to label AI-generated posts?
For realistic AI media, yes on YouTube and TikTok. LinkedIn requires disclosure of synthetic media showing a person saying or doing something they did not, and Meta announced it requires a label on photorealistic video and realistic-sounding audio. 6 of 10 platforms' APIs let an app mark a post as AI-made. None marks that field required in its API docs. That describes the API schema and says nothing about the policy. The platforms that label AI content themselves read signals such as C2PA metadata, so a missing flag does not mean a missing label.
| Platform | Disclosure rule | Covers AI-written text? | AI field in the API | Platform labels AI content itself? |
|---|---|---|---|---|
| X | no general disclosure duty | not stated | made_with_ai (not marked required) | not stated |
| required for synthetic media showing a person saying or doing something they did not, and generally for artistic or humorous uses | no (on-post rule covers media) | none found | yes (C2PA credentials icon), partial | |
| required by announcement: photorealistic video and realistic-sounding audio | no | is_ai_generated (Reels), provenance_info.is_gen_ai (Photos) (not marked required on Reels, provenance_info is optional, its child fields are required only when it is sent) | yes (announcement) | |
| required by announcement: photorealistic video and realistic-sounding audio | no | is_ai_generated (optional, not available on carousel children) | yes (announcement) | |
| Threads | required by announcement: photorealistic video and realistic-sounding audio | no | none found | yes (announcement) |
| TikTok | required: realistic-looking people or scenes made or significantly edited with AI | no | is_aigc (Required column reads false) | yes |
| YouTube | required: realistic altered or synthetic content | no | status.containsSyntheticMedia (the page says the property 'allows' disclosure, not called required) | yes |
| not stated | not stated | ai_disclosures (AI_MODIFIED, SYNTHETIC_PERFORMER) (not marked required) | yes | |
| Bluesky | not stated | not stated | none found | not stated |
| tag requested (guidance), AI content presented as human-generated prohibited | yes | none found | not stated |
Source: Blotato, The Social Media Automation Rulebook for AI Agents 2026, checked 8 October 2026. Meta's disclosure requirement comes from a company announcement, not a policy page. Download PNGLink to chart
Check an action
Pick a platform and an action.
Only after the person opts in, with one automated reply per interaction. AI reply bots need X's prior written approval. On self-serve API tiers, a reply goes through only if the post's author mentioned or quoted you.
Documented API path: restricted
in advance of sending the automated reply, the recipient or mentioned user(s) have requested or have clearly indicated an intent on ... to be contacted by you (i.e. opted in), for example by replying to a post from your account, or by sending you a Direct Message;
help.x.com
What this means if your agent runs your social media
Where a platform allows automated engagement at all, inbound events such as comments, mentions and messages are the safer trigger, and each platform's own conditions still apply. Get the account owner's consent to the automation explicitly, plan for the platform's app review before launch, and set the AI disclosure field where a platform's API offers one. Guides: running social media with AI agents, the DM automation API, removing an AI label and, if the account earns creator payouts, what payout rules say about automated posting.
Where Blotato lands in this study
Blotato publishes this study and sells a hosted social media API and MCP server. Its facts below come from help.blotato.com, read on 8 October 2026.
- Blotato's engagement tools cover 2 of its 9 platforms, Instagram and Facebook. They comment only on the account's own posts, and its DM automations answer only people who comment or message first. On the other 7 it publishes, including threads of its own posts on X, Bluesky and Threads, and offers no replies to other people's posts, DMs, follows or likes. Blotato docs
- Blotato's optional Instagram follow gate asks someone to follow before the automated DM, sent through Meta's messaging API, goes out. It is a soft gate: Blotato proceeds when Instagram does not share the person's follower status, and any text reply triggers the follower check. Meta's Spam standard bars requiring people to engage with content before they can view promised content, and a separate list, on deceptive URLs, domains or applications, bars like/share-gating, including follows. Meta does not say how either applies to a follow gate in a DM. Blotato docs
- Blotato schedules posts to LinkedIn and Pinterest. LinkedIn's API Terms say developers agree not to use the APIs to automate posting, and Pinterest says the end user must choose each Pin an app schedules. Neither says whether a post a person schedules through a tool counts. Blotato's own docs warn that a Pinterest account will be shadowbanned if it starts using automation too soon. Blotato docs
- Blotato's TikTok publish call requires a privacy setting with each post. TikTok's guidelines say users must manually select the privacy status, with no default value. TikTok does not say how that applies when a person's agent passes the setting through a tool. Blotato docs
- Blotato's publish call carries 2 AI flags: TikTok's, which Blotato requires with every TikTok post although TikTok's own API marks it optional, and YouTube's, which is optional. Blotato does not pass through the AI fields that X, Instagram, Facebook and Pinterest offer. Blotato docs
- Blotato adds its own posting caps on top of the platforms' limits, for example 25 posts per TikTok account per rolling 24 hours on all plans. Blotato docs
Where the platforms' own documents disagree
This list covers the disagreements that change a cell on this page. Every other one we found, such as Instagram's publishing cap stated two ways, is in the dataset download.
X: how strict is the automated-following rule?
X's Automation rules bar following in a bulk, aggressive or indiscriminate manner. Its Developer Guidelines table says no bulk, aggressive or automated following, which would cover any automated follow.
YouTube: do uploads from unverified apps stay private?
The videos.insert reference and the Videos resource say uploads from unverified API projects are not restricted to private viewing. YouTube's API revision history says uploads from unverified projects created after 28 July 2020 will be restricted to private viewing.
Bluesky: may a bot reply to or like posts?
Bluesky's Developer Guidelines count automated or bulk interactions that notify a user, including a reply or a like, as spam. Its own bot tutorial says to interact only when the user tagged the bot, and walks through building a bot that writes AI replies. The tutorial names likes, reposts and replies, so this page treats only those cells as disputed, and the follow and DM cells stay with the guidelines.
All 50 cells, with sources
| Platform | Action | What the rules require | Summary | Source |
|---|---|---|---|---|
| X | Publish a post | Owner consent, Unclear | X's Automation rules allow automated posts for entertainment, informational or novelty purposes, provided you comply with all other rules. Acting through someone else's account needs their express consent, and OAuth alone does not count. X also says a service must show exactly what will be published before publishing. | Source 1Source 2 |
| X | Reply or comment | Recipient first, Owner consent, Platform approval | Only after the person opts in, with one automated reply per interaction. AI reply bots need X's prior written approval. On self-serve API tiers, a reply goes through only if the post's author mentioned or quoted you. | Source 1 |
| X | Send a DM | Recipient first, Owner consent | Only if the person asked to be contacted by DM, with an easy opt-out. Automated welcome DMs to new followers are not allowed. | Source 1Source 2 |
| X | Follow | Docs disagree, Owner consent | X's two rule pages word it differently: no bulk, aggressive or indiscriminate following, or no bulk, aggressive or automated following. Self-serve API tiers lost follow writes on 20 April 2026. | Source 1Source 2Source 3 |
| X | Like | Banned | Banned: you may not like posts in an automated manner. Self-serve API tiers also lost like writes on 20 April 2026. | Source 1Source 2 |
| Publish a post | Banned | LinkedIn's API Terms say developers agree not to use the Content or the APIs to automate posting, a term LinkedIn does not define. Posting on a member's behalf is an open API permission, which grants access but does not settle what the terms allow. | Source 1Source 2 | |
| Reply or comment | Unclear | The User Agreement bars bots or other unauthorized automated methods to comment, without saying whether an approved API app counts as authorized. Commenting as a member uses an open API permission, and commenting as a Page sits in a vetted program. | Source 1Source 2Source 3 | |
| Send a DM | Unclear, Platform approval | No member-to-member DM API is documented. Page messaging sits in the vetted Marketing program, and the User Agreement bars unauthorized automated messaging. | Source 1Source 2 | |
| Follow | Not stated | Not stated: no rule names following, and no follow endpoint is documented. | Not stated | |
| Like | Unclear | The User Agreement bars bots or other unauthorized automated methods to like posts. It does not say whether an approved API app counts as authorized. | Source 1 | |
| Publish a post | Owner consent, Platform approval | Apps need the person's consent before publishing on their behalf, and Page permissions need App Review before live use. | Source 1Source 2 | |
| Reply or comment | Owner consent, Platform approval | A Page can comment on its own posts and mention people who commented on them or created them. Meta's Pages guides cover only the Page's own posts, and the Graph API reference describes publishing comments to any object without saying whether that includes posts outside the Page. | Source 1Source 2 | |
| Send a DM | Recipient first, Owner consent, Platform approval | The person must start the conversation. A Private Reply to a comment is one message, sent within 7 days. | Source 1Source 2 | |
| Follow | Not stated | Not stated: no follow endpoint or rule is documented. | Not stated | |
| Like | Owner consent, Platform approval | A Page can like an object through the API with Page permissions that need App Review. No automation rule specific to likes is stated. | Source 1Source 2 | |
| Publish a post | Owner consent, Platform approval | Apps need the person's consent before publishing, and App Review before requesting Advanced Access. | Source 1Source 2 | |
| Reply or comment | Owner consent, Platform approval | Apps can reply on the account's own media. On anyone else's media, only where that account was @mentioned first, through the Mentions API. | Source 1Source 2Source 3 | |
| Send a DM | Recipient first, Owner consent, Platform approval | Only after the person messages first, or as one Private Reply within 7 days of a comment. Messaging apps must offer an escalation path to a human. | Source 1Source 2Source 3 | |
| Follow | Unclear | Unclear: Meta says not to use the Instagram Platform to simply display User Content, import or back up content, or manage Instagram relationships without its prior permission, without saying whether relationships means follows. No follow endpoint is documented. | Source 1 | |
| Like | Owner consent | No like endpoint is documented. Meta requires consent before taking any action on a person's behalf, and its Spam standard bars engaging with content, manually or automatically, at very high frequencies. | Source 1Source 2 | |
| Threads | Publish a post | Owner consent, Platform approval | Apps need the person's consent, and advanced access to post for anyone beyond their own and tester accounts. | Source 1Source 2 |
| Threads | Reply or comment | Owner consent, Platform approval | An approved app can reply to public posts the user recently searched for, with no prior action from the other person. Replying to others needs keyword-search or mentions permissions. | Source 1Source 2 |
| Threads | Send a DM | Not stated | Not stated: Threads documents no messaging API. | Not stated |
| Threads | Follow | Not stated | Not stated: there is only a web link where the person completes the follow in Threads. | Source 1 |
| Threads | Like | Owner consent | No like endpoint is documented. Meta requires consent before taking any action on a person's behalf, and its Spam standard bars engaging with content, manually or automatically, at very high frequencies. | Source 1Source 2 |
| TikTok | Publish a post | Owner picks each, Owner consent, Platform approval | Users must manually pick the privacy setting for each post, with no default. Apps need approval before API access, and posts stay private until the app passes an audit. | Source 1Source 2 |
| TikTok | Reply or comment | Unclear | Depends on region. TikTok's rest-of-world Terms bar using automated scripts to interact with the service, and its US and EEA terms contain no such clause. No comment API is documented. | Source 1 |
| TikTok | Send a DM | Unclear | Depends on region, as with replies. Direct messages are available only through TikTok's Business Messaging API. | Source 1Source 2 |
| TikTok | Follow | Unclear | Depends on region, as with replies. No follow API is documented. | Source 1 |
| TikTok | Like | Banned | Banned: the Community Guidelines list using bots or scripts to increase likes or shares as spam that is not allowed. | Source 1 |
| YouTube | Publish a post | Owner consent, Unclear, Docs disagree | Apps must not automate uploads without the user's prior specific and express consent, and users must have final control over what is published. YouTube's own pages disagree on whether unverified apps upload privately. | Source 1Source 2 |
| YouTube | Reply or comment | Owner consent, Unclear | Comments need the user's prior specific and express consent, and any action an app starts must be clearly initiated by the user. YouTube does not say how that applies to an automation. | Source 1 |
| YouTube | Send a DM | Not stated | Not stated: YouTube's API has no messaging. | Not stated |
| YouTube | Follow | Owner consent, Unclear | Subscribing needs the user's prior consent and must be clearly initiated by the user. | Source 1 |
| YouTube | Like | Owner consent, Unclear | Liking needs the user's prior consent and must be clearly initiated by the user. Artificially increasing likes with automatic systems is not allowed. | Source 1Source 2 |
| Publish a post | Owner picks each, Owner consent, Platform approval | If an app schedules Pins, the user must choose each Pin to be published. Apps need review and approval, and Pinterest's terms count MCP servers and agents as tools. | Source 1Source 2 | |
| Reply or comment | Owner consent, Platform approval | No comment API is documented. Commenting on someone's behalf needs their specific knowledge and consent, and automation needs Pinterest's approval. | Source 1Source 2 | |
| Send a DM | Owner consent, Platform approval | No messaging API is documented. Messaging on someone's behalf needs their specific knowledge and consent, and automation needs Pinterest's approval. | Source 1Source 2 | |
| Follow | Owner picks each, Owner consent, Platform approval | The user must choose each account to follow, and the follow endpoint is in beta and not available to all apps. | Source 1Source 2 | |
| Like | Platform approval | No like API is documented. Pinterest's rule against automation it has not approved covers automated actions generally. | Source 1 | |
| Bluesky | Publish a post | No gate stated | No approval step is documented. Bluesky's bot tutorial welcomes bots that post on a regular interval, and spam is not allowed. | Source 1Source 2 |
| Bluesky | Reply or comment | Docs disagree | Bluesky's developer guidelines count automated replies that notify someone as spam. Its bot tutorial says to reply only when the user tagged the bot. | Source 1Source 2 |
| Bluesky | Send a DM | Banned | The developer guidelines count automated or bulk messages that notify someone as spam. | Source 1 |
| Bluesky | Follow | Banned | Automated or bulk follows that notify someone count as spam. | Source 1 |
| Bluesky | Like | Docs disagree | The developer guidelines count automated likes as spam. The bot tutorial says to like only when the user tagged the bot. | Source 1Source 2 |
| Publish a post | Platform approval | Approval is required before any API access. Reddit stops accepting new requests for public API access on 31 October 2026, and existing access starts to close on 12 January 2027. | Source 1Source 2 | |
| Reply or comment | Platform approval | Approval is required before any API access, and spam through automated comments is prohibited. | Source 1 | |
| Send a DM | Platform approval, Unclear | Apps must get a user's explicit consent for private messages, without saying whose consent. Approval is required first. | Source 1 | |
| Follow | Not stated | Not stated: no rule covers automated following, though a friend endpoint exists. | Source 1 | |
| Like | Owner picks each, Platform approval | Votes must be cast by humans. An app may pass on a person's vote one-for-one, but bots may not decide how to vote. | Source 1 |
Method
Every cell comes from the platform's own documents, quoted verbatim and sorted into gates under rules written before collection, with one disclosed amendment.
Full method
- The question, set before collection. For each of 10 platforms and 5 actions, what must happen before an automated account may act? We wrote both possible headlines before classifying, and a ratio is reported only over at least 6 platforms. One rule was amended after the first count: the publishing count now excludes platforms whose rules ban automated posting, which lowered it from 6 to 5 because LinkedIn's API Terms bar using the APIs to automate posting.
- The gates. Recipient first: allowed only after the recipient mentions, comments, messages or opts in. Owner picks each: the account owner must choose or approve each individual action. Owner consent: the owner's prior consent to the automation, which may be given once, so it is not counted as blocking. Platform approval: the platform must approve the app, access tier or use. Banned: prohibited outright. Unclear: the text exists but does not settle the question. Not stated: no checked document addresses it, and the dataset download names the documents checked for each one. "Should" and "we recommend" count as guidance, not rules.
- Which platforms. X, LinkedIn, Facebook, Instagram, Threads, TikTok, YouTube, Pinterest, Bluesky and Reddit. Nine are the platforms Blotato supports, plus Reddit, the same set as our API breaking changes report. The headline holds on a core six (X, LinkedIn, Facebook, Instagram, TikTok and YouTube) and with Meta's three platforms counted once.
- Sources. Only each platform's own pages, including help pages read in a browser where plain downloads returned no text, and dated archived copies of two X help pages that block automated reads and of a Bluesky page that has since been removed. A script confirmed every quote appears on the saved page, and a separate verification pass, run apart from collection and classification, re-read every source live except pages that block automated reads or no longer exist (two X help pages and a removed Bluesky bot page, checked in dated archived copies), checked each claim against its context, and searched for missed rules. Reddit is classified on its Data API, not its in-app Developer Platform, whose rules differ.
- Limitations. This study reads written rules. It does not measure enforcement, and a platform may restrict an account that follows every rule here. Rules change, so each cell is as of 8 October 2026. Pinterest's terms and community guidelines change on 12 November 2026. National law is out of scope.
Social media automation rules FAQs
01 Can an AI agent reply to comments or send DMs on social media?
02 Which social media platforms let an AI agent publish posts automatically?
03 Which automated actions do social media platforms ban outright?
04 Do you have to label AI-generated social media posts?
05 Do AI labeling rules cover AI-written text?
06 Can an AI agent still use the Reddit API?
Cite this study, and press
Free to quote, cite and reuse these charts and data with a link to this page.
Ramonov, S. (2026). The Social Media Automation Rulebook for AI Agents 2026. Blotato. https://www.blotato.com/research/social-media-automation-rulebook
- Charts: the gate grid (PNG), what replies and DMs wait for (PNG), AI labels (PNG).
- Data: rules table (CSV) and full dataset with quotes and source links (JSON).
- Press and data questions: seo@blotato.com. Sabrina Ramonov, Blotato's founder, is available for comment.
Disclosure: Blotato sells a hosted social media API and MCP server, and its own product sits next to several of these rules, as shown above. That is why each quoted rule links to its source on the platform's own site: you can check each one without trusting us.