The LeanScale Podcast · Episode 24

AI Is Breaking Sales — Here's How to Fix It

Luella's Mustafa Saeed on AI guardrails, email deliverability, and keeping humans in the loop in GTM

Mustafa Saeed · Co-Founder & CEO, Luella · Luella Hosted by Anthony Enrico
Published Updated 00:25:07 22 min read 4,447 words
Executive Summary

The one-paragraph brief, extended

Why this conversation matters — and who should spend the hour.

AI has made spamming effortless and consequence-free — and, according to Mustafa Saeed, co-founder and CEO of Luella (luella.ai), the platforms are finally fighting back. In this episode with LeanScale's Anthony Enrico, Saeed lays out the new rules of AI-native go-to-market: AI SDRs made it trivial to blast enormous volumes of email without limits, and in response Google and Microsoft got far more aggressive with their spam filters while LinkedIn removed the company pages of Apollo, Seamless, and other scraping-heavy vendors overnight, with no warning. Any GTM motion built on high-volume automation is now exposed to sudden policy changes that can force an immediate strategy shift.

The risk surface is wider than most operators realize. Email deliverability has quietly become a problem again — even the biggest, most trusted enterprises are landing in spam and promotions across thousands of reps. Brand reputation is fragile (Saeed cites an AI 'board member' that started making sexist claims and forced a founder to record an apology video and pull in LPs). Compliance bites hard in regulated verticals like health tech, where a single off word is a violation. And AI agents are a genuine security attack surface: a hacker tricked an AI SDR into leaking its IP address, SSH credentials, and password file simply by planting a prompt-injection instruction in his LinkedIn bio. Because so many of these tools are quickly 'vibe-coded' together, the guardrails often aren't there — which is why, Saeed argues, RevOps has become the function stepping up to solve it.

The middle of the conversation is a clinic on deliverability infrastructure. Instead of the shared IP pools that most legacy tools send from — massive servers full of unvetted senders where one bad actor poisons everyone's reputation — Luella gives each user an isolated 'cluster' with its own IP, so a single rogue rep can't contaminate the whole org. It replaces vanity 'deliverability scores' (a made-up, inflated metric) with real placement tests that show inbox vs. spam vs. promotions, simulates natural mailbox activity to keep response ratios healthy, and enforces the collapsing platform volume caps — down from hundreds of emails per mailbox per day to 15–25. On top of that sits an optimization layer: LLMs are 'glorified copywriting machines,' but reinforcement learning learns which hooks and offers actually resonate, ad-platform style — testing variants on a small sample and scaling only the winners.

The throughline is that AI alone isn't the answer — humans in the loop are. Fully autonomous AI SDRs are both far off and undesirable: AI ingests data at scale, but humans build relationships and carry accountability, and buyers of six-figure products specifically need a person on the hook for pricing, packaging, and success. Luella pairs its software with a human layer — ethics workshops and Slack hotlines for reps — because you often have to protect a company from its own overzealous sellers. Who should listen: RevOps and GTM leaders owning outbound guardrails, sales leaders managing SDR and AE behavior, and founders about to hand a new AE a 'loaded' ICP and let them blast volume. The biggest takeaway: sales is a quality game, not a volume game, and the operators who win in the AI era are the ones who build the infrastructure and keep the humans.

Key Takeaways

10 things worth stealing

The load-bearing ideas, each with the business implication and who should care.

01

AI made spamming consequence-free — and the platforms are fighting back

AI SDRs made it trivial to blast huge volumes of email and content without limits. In response Google and Microsoft tightened spam filters aggressively, and LinkedIn removed the company pages of Apollo, Seamless, and other vendors overnight for scraping personal data to resell.

Why it matters: Any GTM motion built on high-volume scraping and automation is exposed to sudden, no-warning platform policy changes. Build for compliance before you're forced to shift gears mid-quarter.

RevOps LeadersSales LeadersFounders
02

Deliverability broke again — even for the biggest enterprises

Because Google and Microsoft got so aggressive, trusted senders — not just startups — are seeing emails land in spam and promotions folders across thousands of reps. Deliverability many teams assumed was solved is now an active problem.

Why it matters: Treat deliverability as live infrastructure to monitor, not a commodity you can ignore. Placement is a pipeline health metric.

RevOps LeadersMarketing Leaders
03

Shared IP pools poison good senders — isolate risk with clusters

Most legacy outreach tools send from massive shared servers full of unvetted senders, so bad actors' spraying drags down everyone's sender reputation. Luella instead gives each user a mini-server ('cluster') with its own IP, so one rogue rep can't contaminate the org.

Why it matters: Know what infrastructure your outreach actually sends from. Per-sender isolation contains the blast radius when someone goes rogue.

RevOps LeadersMarketing Leaders
04

Measure placement, not vanity deliverability scores

Google and Microsoft only expose self-reported spam metrics, and most tools' 'deliverability score' is a made-up, inflated number they fully control. Placement tests — seeding emails to known mailboxes to see inbox vs. spam vs. promotions — are the real health signal.

Why it matters: Demand real placement data and spam-rate alerting. A green vendor score tells you nothing about where your email actually lands.

RevOps LeadersMarketing Leaders
05

Send-volume caps have collapsed to 15–25 per mailbox per day

Safe daily volume per mailbox fell from hundreds to 50 to 15–25 as Google and Microsoft cracked down. Luella enforces the cap rather than letting reps pick it, and ramps volume slowly only after messaging is tested on a small sample.

Why it matters: Re-architect capacity math around drastically lower per-mailbox limits. You can't buy your way out of quality with more volume.

Sales LeadersRevOps LeadersFounders
06

Prompt injection is a live GTM attack surface

A hacker tricked an AI SDR into leaking its IP, SSH credentials, and password file just by putting an override instruction in his LinkedIn bio. Many outbound tools are 'vibe-coded' with weak safeguards, so autonomous agents touching your data are a security exposure.

Why it matters: Put security and trust/safety review into GTM tool selection. Evaluate agents for injection and credential-leak risk, not just features.

RevOps LeadersFounders
07

Sales is a quality game, not a volume game

First-time founders hand a new AE a 'loaded' ICP and message and go nuts on volume — hurting the brand and burning bridges they'll need once they iterate. Small batches, testing, and personalization beat spray-and-pray.

Why it matters: Prove message value on a small sample before scaling. Brand damage from spam is expensive and slow to undo — prospects learn to associate your brand with spam.

FoundersSales Leaders
08

Optimize messaging with reinforcement learning, not just LLM copy

LLMs are 'glorified copywriting machines.' Reinforcement learning is the optimization layer that runs mini-experiments to learn which hooks, lead magnets, and offers actually resonate — the same way ad platforms test variants on a small audience before scaling winners.

Why it matters: The edge is understanding why a sequence wins and generating better variants — not producing more AI copy. RevOps should own the 'why,' not just the reporting.

RevOps LeadersMarketing Leaders
09

Keep a human in the loop — especially in high-ticket B2B

Fully autonomous AI SDRs are both far off and undesirable. AI ingests data at scale, but humans build relationships and carry accountability. Certain AI-generated copy should be reviewed before it reaches a prospect, and six-figure buyers need a person accountable for pricing, packaging, and success.

Why it matters: Design AI to draft and route while humans review copy and own high-stakes relationships. Don't automate away the accountability buyers are paying for.

Sales LeadersFoundersRevOps Leaders
10

RevOps owns the guardrails — and software alone isn't enough

RevOps is the function stepping up to implement AI and outbound guardrails across sales orgs. Luella pairs software with a human layer — ethics workshops and Slack hotlines — because you often have to protect a company from its own rogue reps.

Why it matters: Stand up both the technical guardrails (isolation, volume caps, placement monitoring, abuse detection) and the human enablement layer. Guardrails are a RevOps mandate, not a vendor afterthought.

RevOps LeadersRevenue Executives
Frameworks Discussed

7 named models

Every framework Jimmy names, defined and time-stamped.

Shared IP Pools vs. Isolated Clusters

07:11

Instead of sending from a massive shared server (a shared IP pool) full of thousands of unvetted senders, give each user an isolated mini-server ('cluster') with its own IP address so one sender's behavior can't affect the others.

Shared pools expose even the most trusted senders to the spammers and grifters alongside them, dragging down sender reputation. Clusters isolate risk: if one rep goes rogue, the damage is contained to that cluster rather than contaminating the whole org's infrastructure.

Placement Tests

08:27

Regularly send emails from a customer's mailboxes to known reference mailboxes to observe where they actually land — inbox, spam, promotions, or undelivered — as the true indicator of email infrastructure health.

Platforms only expose self-reported spam metrics and most tools show an inflated, made-up 'deliverability score.' Placement tests surface real spikes in spam rates so teams can diagnose broken authentication, platform changes, or a rogue rep before it becomes a business problem.

Natural Mailbox Activity Simulation

10:15

Simulate natural, two-way activity across real corporate mailboxes to balance the unnaturally low response rates of cold outreach, so email service providers don't flag the account.

Cold outreach sends many emails with few replies, which reads as a red flag to Google and Microsoft. Simulating natural activity builds trust with ESPs over time and can help rehabilitate burnt mailboxes and domains during a move to a more compliant approach.

Enforced Volume Caps and Slow Ramp

12:14

Cap daily send volume per mailbox to what platforms now tolerate (15–25/day, down from hundreds), have the platform control the cap rather than the rep, and scale volume only after messaging is validated on a small sample.

Google and Microsoft have collapsed safe volumes, so going 'guns blazing' on day one guarantees the spam folder. Testing messaging on a smaller audience first — confirming positive replies — before pressing the gas protects both deliverability and brand.

Ad-Platform Message Testing

14:18

Treat cold outreach like a paid-ad platform: give the system many message variations, test each against a small subset of the audience, and scale only the versions that generate positive engagement.

LinkedIn and other ad platforms show an ad more widely only once users engage with it. Applying the same logic to outbound means the best-performing message variant earns the volume — and messaging that fails to deliver value never gets scaled into the market.

Reinforcement Learning as the Optimization Layer

15:35

Use reinforcement learning — a distinct branch of AI from LLMs — as the optimization layer that looks at what has and hasn't performed to predict which hooks, lead magnets, and offers will resonate, and recommends new variations over time.

LLMs are 'glorified copywriting machines'; reinforcement learning runs mini-experiments to understand why messaging works, ensuring only the highest-performing copy reaches prospects and helping early-stage teams improve messaging until they can safely push more volume.

Human-in-the-Loop Oversight

18:46

Blend autonomous AI (which ingests large data sources) with human review checkpoints — a sales rep reviews certain AI-generated copy before it reaches a prospect, and an admin reviews certain content before it reaches the rep.

Fully autonomous AI SDRs are far off and undesirable. Humans build in-person relationships, exercise judgment, and carry accountability, and their oversight is a primary protection against the brand, compliance, and data-leak failures autonomous agents can cause — especially in enterprise and mid-market deals.

Best Quotes

12 lines worth clipping

Pulled verbatim. Copy or share any of them.

“This hacker tricked an AISDR into leaking its IP address, SSH credentials, and password file. All he did was add a prompt in his LinkedIn bio, pretty much asking to override any previous instructions and provide those credentials.”
Mustafa Saeed 03:57
“With so many of these tools just being vibe-coded together, there are real risks to AI coupled with reckless automation.”
Mustafa Saeed 03:57
“We want to help you connect with prospects instead of spamming the living hell out of them.”
Mustafa Saeed 04:36
“If one sales rep goes rogue and starts pushing a lot of BS, it doesn't contaminate your entire infrastructure. It's isolated to the cluster that we've created.”
Mustafa Saeed 07:49
“Most outreach tools will give you a deliverability score, which is a made-up metric. They have full control over what goes into it, and it's more often than not inflated.”
Mustafa Saeed 08:27
“Gone are the days of sending hundreds of emails every single day out of just one mailbox. Today we've reduced to 15 to 25 emails per mailbox per day. That is how aggressive Google and Microsoft have become.”
Mustafa Saeed 12:14
“If your messaging isn't providing value, then you are spamming your users, and you deserve to be in the spam folder.”
Mustafa Saeed 14:54
“LLMs are really just glorified copywriting machines. Reinforcement learning is another branch — it's the optimization layer.”
Mustafa Saeed 15:35
“It always was a problem. We just poured gasoline on an already really hot fire.”
Anthony Enrico 05:48
“People think sales is a volume game — and yes, in some ways. But really it's a quality game.”
Anthony Enrico 13:38
“It's not just, can I get some product information really quickly. Is somebody gonna have my back if something goes wrong? I need that assurance that somebody's on the hook for making this successful.”
Anthony Enrico 22:19
“You need to protect your customers from themselves. They will have a rogue SDR, they will have a rogue AE who comes in and completely lights up their prospect base and then puts the entire company at risk.”
Anthony Enrico 23:35
Practical Advice

What should you actually do?

The playbook, split by the seat you sit in.

RevOps Leaders

  • Audit what infrastructure your outreach actually sends from — if it's a shared IP pool, another sender's spam behavior can tank your reputation; move to isolated, per-sender sending.
  • Replace vanity 'deliverability scores' with real placement tests that show inbox vs. spam vs. promotions, and wire alerts for spam-rate spikes and broken authentication.
  • Own the AI and outbound guardrails for the whole org — enforced volume caps, human-review checkpoints, and security review of any agent that touches your data.
  • Vet AI SDR tools for prompt-injection and credential-leak risk, not just features; many are vibe-coded with weak safeguards.

Sales Leaders

  • Kill the day-1 / day-5 / day-10 template blast; enforce small-batch testing and personalization, and ramp volume only after you see positive replies.
  • Accept the new per-mailbox ceiling (roughly 15–25 emails/day) and plan capacity around message quality, not raw send count.
  • Keep humans on high-ticket deals — buyers of six-figure products need an accountable person for pricing, packaging, and post-sale success that an AI agent can't provide.

Founders

  • Don't let your first AE assume the ICP and messaging are 'locked and loaded' and go nuts on volume — you'll burn the brand and the bridge before you've iterated.
  • Build outbound for compliance from day one; platform policy can change overnight (see LinkedIn removing Apollo) and torch a volume-dependent motion.
  • Blend AI and humans: use AI to ingest data and draft at scale, but keep people in the loop for relationships, judgment, and accountability.

Marketing Leaders

  • Protect brand reputation as a deliverability and compliance issue — spammy outreach trains prospects to associate your brand with spam and can trigger public blowups.
  • Use ad-platform logic for outbound: test many message variants on small samples, scale only proven winners, then study why they won to generate better ones.
AI Takeaways

How AI actually changes GTM

LeanScale's signature read on the AI-in-GTM question this episode wrestles with.

The thesis

AI has made outbound abuse effortless and consequence-free — right as Google, Microsoft, and LinkedIn started punishing it. The fix isn't more automation or less AI; it's infrastructure, guardrails, and humans in the loop that let teams use AI without abusing it.

AI supercharged spam

AI SDRs made blasting huge volumes trivial, and platforms responded with aggressive spam filters, collapsing volume caps (down to 15–25/mailbox/day), and overnight page removals (Apollo, Seamless).

Agents are an attack surface

A prompt hidden in a LinkedIn bio tricked an AI SDR into leaking its IP, SSH credentials, and password file. Many tools are vibe-coded with weak safeguards — security review is now table stakes.

Reinforcement learning over LLM copy

LLMs are 'glorified copywriting machines'; reinforcement learning is the optimization layer that learns which hooks and offers resonate and scales only the winners.

Keep humans in the loop

Fully autonomous AI SDRs are far off and undesirable. AI ingests data at scale; humans build relationships and carry accountability on high-ticket deals. Software alone isn't enough — pair it with workshops and support.

RevOps owns the guardrails

RevOps is the function stepping up to implement volume caps, human-review checkpoints, placement monitoring, and abuse detection across the sales org.

Agent & automation ideas

  • A deliverability-watchdog agent that runs continuous placement tests and pages RevOps on spam-rate spikes, broken authentication, or a rep suddenly blasting volume.
  • A pre-send review agent that flags AI-generated copy for compliance-sensitive claims (e.g., health tech) and routes it to a human before it reaches a prospect.
  • A message-optimization loop that uses reinforcement learning across past sends to recommend new hooks and offers and retire underperforming variants.
  • A cluster/mailbox-isolation controller that provisions per-rep sending identities so a single rogue actor can't contaminate org-wide sender reputation.
Operations Takeaways

By function

The same conversation, filtered for RevOps, pipeline/marketing ops, and customer ops.

Revenue Operations

  • Own the guardrails. RevOps is on the hook to implement volume caps, human review, and abuse detection across the sales org — 'everyone in RevOps is on the hook for solving this.'
  • Isolate sending. Move off shared IP pools to per-sender clusters with dedicated IPs so one rogue rep can't tank org-wide sender reputation.
  • Measure placement, not scores. Instrument real inbox-vs-spam placement tests and spam-rate alerting instead of trusting vendors' inflated deliverability scores.
  • Security-vet AI tools. Prompt injection and credential leaks are real; review any agent that touches your data before deploying it.
  • Data interoperability. Favor tools with developer-friendly APIs and native integrations (Octave, Clay, intent providers) over walled gardens.

Pipeline & Marketing Ops

  • Deliverability is a pipeline input. If email lands in spam or promotions across thousands of reps, top-of-funnel dies quietly — monitor placement as a pipeline health metric.
  • Small batches beat blasts. Test messaging on a small sample and ramp volume only after positive replies; blasting 100k contacts manufactures spam complaints and brand damage.
  • Value or spam. If the message doesn't provide value, the prospect (and the ESP) treats it as spam — message quality is now a deliverability lever, not just a conversion lever.
  • Intent over volume. Thousands of intent signals exist but most platforms unify only a couple dozen; better signal beats more sends.
Metrics Mentioned

The numbers, with context

5 full-time (3 engineers)
Luella team size

A lean team that wrote its first line of code just over six months before the episode.

Hundreds → 50 → 15–25 / mailbox / day
Send-volume caps

How far Google and Microsoft have collapsed safe daily send limits per mailbox as they crack down on AI-era outbound.

6 figures / year, 4–5 month cycle
First enterprise deal

Luella's first big enterprise deal took a months-long, human-led process an AI agent could not have closed.

150+ planned
Integrations roadmap

Luella's integration push — native Octave integration confirmed — reflecting its bet on data interoperability and developer-friendly APIs.

~100,000 emails from ZoomInfo
Overzealous SDR blast

Anthony's recurring example of a single rogue rep torching deliverability at every company he's worked at.

Day 1 / Day 5 / Day 10 templates
Static outbound cadence

The robotic, template-on-a-timer sequence pattern Mustafa says AI and automation have made ten times worse.

Entities

Companies, people & tools mentioned

Auto-extracted and linked into the knowledge graph.

Companies

LuellaAI GTM / Deliverability & Compliance

Mustafa Saeed's company; a compliance-and-deliverability platform building guardrails for AI-native GTM teams (isolated clusters, placement tests, mailbox simulation, enforced volume caps, RL message optimization, human oversight). Lean team of five (three engineers), first line of code ~six months before the episode.

00:00 · 06:33 · 22:56Company →
OctaveAI GTM / Messaging

AI GTM messaging company (founders Julian and Zach) that aligns the right message with the right prospect and shares Luella's anti-spam mentality; Luella confirmed a native integration 'last Friday.' A prior LeanScale Podcast guest.

18:08Company →
OracleEnterprise Software

Named, with TravelPerk, as one of the enterprises whose RevOps leaders Luella works with to implement outbound guardrails.

04:36Company →
TravelPerkTravel Management SaaS

Cited alongside Oracle as an enterprise whose RevOps leaders Luella works with.

04:36Company →
GoogleSearch / Advertising

Cited repeatedly as aggressively tightening spam filters and collapsing send-volume caps to combat AI-era outbound abuse, and as exposing only self-reported spam metrics.

00:42 · 08:27 · 12:14Company →
MicrosoftSoftware / Cloud

Cited alongside Google as aggressively tightening spam filters and slashing send-volume caps in response to AI-driven outbound abuse.

00:42 · 08:27 · 12:14Company →
ZoomInfoGTM Data / Sales Intelligence

Anthony's recurring real-world example: an overzealous SDR ripped ~100,000 emails out of ZoomInfo and blasted them immediately, torching deliverability.

09:36Company →
CursorAI Dev Tool

Named by Anthony (with Lovable) as an example of a lean, small-team company reaching unicorn status — evidence you don't need a bloated team to build something meaningful.

05:13Company →
LovableAI App Builder

Named alongside Cursor as a lean startup reaching unicorn scale with a handful of people.

05:13Company →
Y CombinatorAccelerator / Venture

Where Mustafa met his Luella co-founder — via Y Combinator's co-founder matching platform, one year before the episode.

04:36Company →
MetaAdvertising / Social

Facebook ads cited (with LinkedIn ads) as the ad-platform analogy for how Luella tests message variants on a small subset before scaling winners.

13:38Company →

People

Tools & software

LinkedInSocial Platform

The platform that removed Apollo's, Seamless's, and other vendors' company pages overnight over data scraping; also the ad platform used for the message-testing analogy and the vector for the prompt-injection credential-leak attack (an override prompt planted in a bio).

Apollo.ioSales Intelligence / Engagement

Sales intelligence/engagement platform cited as the 'billion-dollar unicorn' whose LinkedIn company page was removed overnight — the marquee example of platform crackdowns on scraping-heavy, AI-era outbound.

Seamless.AISales Intelligence

Named alongside Apollo as a scraping-heavy lead-data tool hit by LinkedIn's crackdown.

ClayGTM Data / Enrichment

Named among the intent-data and enrichment companies Luella wants to integrate with, alongside PhantomBuster, RB2B, and Trigify.

PhantomBusterAutomation / Data Extraction

Cited as doing a good job on intent data; among Luella's intended integration partners.

RB2BWebsite Visitor Identification

Named among the intent-signal partners Luella wants to integrate with.

TrigifySocial Signals / Intent

Named among the intent-data companies Luella wants to integrate with.

Frequently Asked Questions

Straight answers

Generated from the conversation, marked up for search and AI extraction.

What is Luella and what problem does it solve?

Luella (luella.ai) is a compliance-and-deliverability platform that builds guardrails for AI-native go-to-market teams. Founded by Mustafa Saeed and a team of former agency founders, GTM leaders, and security engineers, it isolates sending into per-user clusters with dedicated IPs, runs placement tests, simulates natural mailbox activity, enforces platform volume caps, and uses reinforcement learning to optimize messaging — so teams can use AI in outbound without spamming prospects or damaging their brand.

Why did LinkedIn remove Apollo's page, and what does it signal for GTM tools?

LinkedIn removed the company pages of Apollo, Seamless, and other data vendors overnight with no warning, over their aggressive scraping of personal data to resell as part of their products. It signals that LinkedIn, Google, and Microsoft are cracking down hard on AI-era outbound abuse, and that any GTM motion built on high-volume scraping and automation is exposed to sudden policy changes that can force an immediate strategy shift.

Why is email deliverability suddenly a problem again?

Because Google and Microsoft made their spam filters far more aggressive to combat AI-driven spam. The result is that even the biggest, most trusted enterprises — not just startups — are seeing emails land in spam and promotions folders across thousands of sales reps. Deliverability that many teams assumed was a solved commodity is now an active infrastructure problem to monitor.

What are shared IP pools, and why are they risky for cold outreach?

Shared IP pools are massive shared email servers containing thousands of unvetted senders — both good actors sending tastefully and bad actors spraying and praying. Most legacy outreach tools send from these shared servers, so other senders' spam behavior drags down your sender reputation and makes your email more likely to land in spam. The alternative is to give each user an isolated 'cluster' with its own IP so one rogue sender can't contaminate the whole organization.

How many cold emails per mailbox per day are safe now?

According to Mustafa Saeed, the safe ceiling has collapsed from hundreds of emails per mailbox per day to about 15–25, as Google and Microsoft tightened volume caps. The bigger point is that you can't push volume in cold outreach anymore: test messaging on a small sample, ramp slowly, and prioritize value and personalization over raw send count.

Can an AI SDR be hacked?

Yes. Mustafa describes a case where a hacker tricked an AI SDR into leaking its IP address, SSH credentials, and password file simply by adding a prompt-injection instruction to his LinkedIn bio that told the agent to override its previous instructions and hand over the credentials. Because many AI outbound tools are quickly 'vibe-coded' with weak safeguards, autonomous agents that touch your data are a genuine security attack surface.

Should AI SDRs run fully autonomously, or keep a human in the loop?

Keep a human in the loop. Mustafa argues fully autonomous AI SDRs are both far off and undesirable: AI is great at ingesting large amounts of data, but humans build relationships and carry accountability. Certain AI-generated copy should be reviewed by a rep before it reaches a prospect, and high-ticket B2B buyers specifically need a person accountable for pricing, packaging, and post-sale success — something an AI agent can't provide.

Who should own AI and outbound guardrails — RevOps or sales?

RevOps. Mustafa notes it's RevOps leaders who have stepped up to implement these guardrails across sales organizations, and Anthony agrees that everyone in RevOps is on the hook for solving it. Guardrails span technical controls (isolated sending, enforced volume caps, placement monitoring, abuse detection) and a human layer (ethics workshops and rep education), because you often have to protect a company from its own rogue reps.

Full Transcript

The whole conversation

Broken into chapters, searchable, verbatim from the audio. Speakers inferred (not diarized).

00:00Intro: Mustafa Saeed and Luella

0:00 (logo whooshing) - Today we have Mustafa Saeed, co-founder and CEO of Luella. Mustafa, really excited for what you're gonna show today because I think the new world of AI has created so many opportunities and at the same time, so many new challenges and so many new problems that I don't think a lot of people are even aware of. So I would love if you could lay the context of what the new AI world has created and some of the problems that come along with it and how you guys are solving it at Luella. - Yeah, of course. Anthony, thank you so much for having me on the podcast and yeah, a big reason for why we're building in this space

00:42The AI consequences reshaping GTM

0:42 is because of a lot of the recent consequences of AI and automation that we're now seeing. My founding team and I really came together because of our shared background as former agency founders, go-to-market leaders, security engineers, and we all saw a lot of the same challenges. We all saw a lot of new AI sales tools entering the market, a lot of AI SDRs that were making it easier than ever to spam very large volumes of emails and just content in general without consequences or without limits and we started to see very early signs of larger policy changes that are happening in this industry. Google and Microsoft making very aggressive changes

01:20LinkedIn bans Apollo overnight

1:20 to their spam filters, for example, to combat abuses of AI and automation and now LinkedIn, like, Anthony, did you see what happened with LinkedIn and Apollo? - I did, I did. And no warning, basically overnight and so many companies had to immediately shift strategy and shift gears to accommodate that. But I think-- - Exactly. - You probably know more of the details of it than I do and would love to share how that's a good example of how some of these things can change so quickly. - Yeah, so Apollo, this unicorn, this billion dollar company, their company page was removed from LinkedIn. If you go to LinkedIn right now, type in Apollo.io,

1:58 it takes you to a dead page and we saw the same thing happen with Seamless, with Ava Boost for so many of these companies that have been really going aggressive when it comes to web scraping, especially your personal data to sell them as part of their solution. So we've already started to see these very aggressive policy changes and there is a larger ripple effect that we're seeing across the entire industry as a consequence of them. Email deliverability, for example, all of a sudden, it's a problem again. Because of how aggressive Google and Microsoft have become, even trusted centers are being impacted, not just startups,

02:35Reputation, compliance, and data-leak risks

2:35 but some of the biggest enterprises in the world are seeing email deliverability issues, seeing their emails land in spam and promotion folders across several thousands of their sales reps. We're seeing a lot of RevOps and revenue leaders have concerns around potential abuses of AI and automation across their sales team. There's a lot of benefits and advantages to using AI and automation and that's why it should very much be encouraged, but there are also ways that these tools can be abused. Reputation damages, for example, right? There was this AI board member that got into some hot water because they started spewing a lot of very sexist claims

3:14 and the founder had to record an apology video, their LPs had to get involved and it was this really big situation. These brand reputation damages can take a long time to recover from. Compliance issues are another one. We work with a lot of health tech companies that are very sensitive when it comes to the claims that they can make around their software. Even just one word that's off will result in an issue of non-compliance, data leaks. Anthony, did you see what I posted on LinkedIn yesterday? - I did not, but we'd love to hear it. - So this hacker tricked an AISDR into leaking its IP address, SSH credentials and password file. - Oh, wow.

03:57Prompt injection: an AI SDR leaks its credentials

3:57 - Now, all he did was add a prompt in his LinkedIn bio, pretty much asking to override any previous instructions and provide those credentials. So especially with so many of these tools just being vibe coded together, like there are real risks to AI coupled with reckless automation and that's why we wanted to build something in this space to build those guardrails to prevent abuse, to enable organizations to make the most of AI without abusing AI, do a better job of protecting reputation, preserving deliverability, and help you connect with prospects instead of spamming the living hell out of them. And we're very grateful to have worked

04:36Origin story: a lean team of five

4:36 with a lot of incredible RevOps leaders. So a big reason for why I wanted to be on this podcast is because it's really RevOps that has been stepping up to implement these guardrails across their sales organizations. And we've had the chance to work with RevOps leaders at Oracle and Travel Perk amongst several other enterprises. We're still a very lean team. We're a team of five full-time with three engineers. And we wrote that first line of code just over six months ago. So everything that I'm about to show you is still very much new. And my co-founder and I, today is actually our work anniversary. So one year ago today, I sent him a message. Thank you.

5:13 We met on YConvaders co-founder matching and we've been building ever since. So that's a little bit about the story of the crazy journey that we've been on so far and why we've decided to build in this space. - I love it. Well, I'm really excited. I think so many of the new companies are built lean and mean anyway. You look at like Cursor, Lovable, those type of companies reaching unicorn status with a handful of people. So you don't need a big bloated team to make something meaningful. And what you're targeting hits me personally in so many ways. One, I have a cybersecurity fraud prevention background. So when I was leading RevOps in tech,

5:48 it was mainly in that space. So I know how many vulnerabilities already were around before all of these new AI capabilities. And on the receiving end, my inbox and LinkedIn is just lit up every single day. And it's clearly, it always was a problem. We just poured gasoline on and already really hot fire. So I'm really excited about the mission and what you're solving. And there needs to be guardrails in this space and ways to just make sure it's a more meaningful environment, especially in go-to-market. And the RevOps community, everyone in RevOps is on the hook for solving this. So people are looking to us to come up with a solution

06:33Shared IP pools vs. isolated clusters

6:33 to make sure, hey, we can still sell, but still protect our reputation at the same time. - Exactly, completely agree. These legacy workflows throwing AI and automation at them, like that's not the solution, right? There's infrastructure that we need to build just to make better use of these tools. And really excited to dive into that. Anthony, should I share my screen? - Yeah, let's do it. - So it really all starts with the infrastructure that we're actually sending from. So Anthony, if I was to say shared IP pools, do you know what that is? - I'm not sure of it. Maybe I should be, but I'm not. So these are massive shared servers

7:11 with several thousands of unvetted senders in them. And in these servers, you're gonna have both good actors that are running called app-bound tastefully and ethically, but also those bad actors that don't give a shit, that are spraying and praying. And when you're sending outreach out of the majority of these legacy outreach tools, you are unfortunately using these shared servers, and that exposes even the most trusted senders to spammers and grifters. So that is a larger piece that hurts your sender reputation and makes you more likely to land in spam because of it. So we, instead of these really big servers, Anthony, we will create your own mini server.

7:49 And we call these mini servers clusters, and this is exactly what they look like. This is Evan's cluster over here. This is my cluster. Each of these clusters has its own IP address. Just so, if one sales rep goes rogue and starts pushing a lot of BS, it doesn't contaminate your entire infrastructure. It is isolated to the cluster that we've created. So this is a larger way that we're isolating risk across your sales organization. And if you click into any cluster, you'll be able to see its corresponding metrics. Another larger challenge that we're seeing in this industry is transparency. A lot of organizations don't know what percentage

08:27Placement tests over vanity deliverability scores

8:27 of their outreach are actually landing in the primary inbox versus spam or promotions folders. The reason for why is because Google and Microsoft only give you self-reported spam metrics, which is a small fraction of the data that they actually have. And most outreach tools will give you like a deliverability score, which is a made up metric. They have full control over what goes into that deliverability score, and it's more often than not inflated. So we, to bring back that essential visibility for your team, are running placement tests. Anthony, do you know what that is? - I'm not sure, but I'm getting a great education today.

9:02 So we on a regular basis are sending emails from your mailboxes to ours to see where they land. The inbox, the spam folder, the promotions folder, sometimes they don't get delivered at all. And this becomes the best indicator that we have through the overall health of your email infrastructure. Whenever there's a problem with your email infrastructure, we'll always see a spike in spam rates reflected over here. And Luella is using these data points to regularly diagnose your email infrastructure and surface alerts to both your team and ours. So let's say authentications break. Let's say Google and Microsoft make a change that they are more public about

9:36 that does warrant action on yours. Let's say you have a sales rep that has gone rogue. Luella is constantly looking out for you and surfacing those notifications, not only from a deliverability perspective, but also to catch instances of abuse before it actually becomes a problem for your organization. - So by the way, I have seen that exact use case happen at every single company I've been at. An overzealous SDR, ripped 100,000 emails out of Zoom info, threw them out of their inbox right away. I mean, I've seen that exact thing happen every single time. - Yeah, it's crazy. Literally millions of sales reps all over the world.

10:15Simulating natural mailbox activity

10:15 Like that's how they're operating. They pull these massive lists from stale databases and following static supers where on day one, you send a template in email. Day five, you send a template in. Day 10, you send a template in email. Like it's a very robotic way of doing business. And like we urgently need to move away from it because even without AI, it was super spammy, but now with AI and automation, it's made it 10 times worse. And in addition to the placement tests, we're also simulating natural mailbox activity. So when you're sending cold outreach, that isn't very natural, right? Because you're sending a larger number of emails,

10:50 but with a much lower response rate. So Luella will simulate natural mailbox activity with real corporate mailboxes, just to do a better job of balancing your response rates, just to not trigger a red flag in the eyes of Google and Microsoft. So this is the piece that helps build trust with email service providers over time. And this is what we can also use if you have burnt mailboxes and domains and are looking to shift to an approach that is more compliant. - I love it. - So those are the range of things that we're doing on the deliverability side. We also do mailbox management. So Google, Outlook, Custom SMTP, we can manage the mailboxes

11:31The collapse of send-volume caps

11:31 and the corresponding authentications to make sure everything is correct. You can also send emails out of Luella as well. So a few larger differentiators here. The first has to do with automation limits. So a lot of the changes that we are seeing from Google and Microsoft have to do with volume caps. Gone are the days of sending hundreds of emails every single day out of just one mailbox. Last year, we reduced our volume to 50 per mailbox per day. Today, we've reduced to 15 to 25 emails per mailbox per day. That is how aggressive Google and Microsoft have become. So Luella, unlike other platforms that will let you set whatever volume caps that you want,

12:14 Luella is the one that controls your volume every single day just to maintain that compliance. Another guard that we've built has to do with how we're scaling that volume over time. It's really important that you're not going full guns blazing on day one and sending hundreds of thousands of emails. You really wanna make sure you're testing your messaging across a much smaller sample size before you do press your phone in the gas just to make sure you're providing value to the prospects that you are reaching out to. You're seeing positive reply rates. - I think this is one of the biggest mistakes, first-time founders,

12:52Sales is a quality game, not a volume game

12:52 when you get your first A/E into a company that they make. They think, one, they think that their ICP and their messaging is blocked and loaded, and they just go nuts with the volume of communication. And I don't think people realize that you're doing more harm than good. You're hurting your brand. People will immediately start to associate your brand with someone that spams them. And then when you realize you iterate and you need to improve your messaging, you've kind of burned that bridge already. So I think people think sales is a volume game, and yes, in some ways, but really it's a quality game.

13:38 And you don't really get an opportunity to get that quality unless you're doing it in the manner that you say. Small batches, iteration, testing, very thoughtful messaging, very personalized messaging, not just blasting 100,000 people. - Exactly, completely agree. And in order to be able to achieve this, we've also built a lot of the same algorithms as many of the traditional ad platforms. So Anthony, do you guys run Facebook ads or LinkedIn ads internally? - We do some LinkedIn ads. We actually do some YouTube ads as well. So we're a little familiar with it. - Yeah, so the way that LinkedIn ads work is you give them 10 different ads.

14:18Ad-platform message testing

14:18 LinkedIn will test each and every one of those ads against a smaller subset of your audience. And only after LinkedIn sees customers are liking the ad, clicking on it, engaging with it, like showing actual value that's being delivered to the end user where LinkedIn will show the ads more and more and more and more and more people. The weather will do the exact same thing. So you may add 10 different message variations to a campaign and the weather will test each and every one across a much smaller sample of the context that you do have. And only after she sees positive replies where the weather will scale the version that is performing the best.

14:54Reinforcement learning as the optimization layer

14:54 So you can't push volume in cold outreach. It's just very important that you are delivering value to those prospects. If your messaging isn't providing value, then you are spamming your users and you deserve to be in the spam folder. So that's why we've built those necessary limits just to prevent bad actors from spammer, people spamming our platform. Another piece has to do with reinforcement learning. Do you know what reinforcement learning is, Anthony? - Gonna learn another thing today. (both laugh) - So this is a branch of artificial intelligence. There are multiple different branches of artificial intelligence. LLMs are just one of them, right?

15:35 LLMs are really just glorified copywriting machines. Reinforcement learning is another branch. This is the optimization layer. This allows us to look into the past, understand what has performed, what hasn't performed in order to better predict the future. So in order to help teams better improve their messaging over time, we're using reinforcement learning just to run a lot of mini experiments with your messaging to get a better understanding to the hooks, the lead magnets, the offers that did resonate and provide value, just so we are optimizing the best messaging with the prospects that you're targeting. So that guardrail makes sure

16:13 that only the highest performing messaging that you have added to Luella gets shown to customers. And over time, once Luella does have enough data, she'll be able to recommend new message variations with new hooks, new angles, new lead magnets, new offers that are likely to outperform what you have tested in the past. So that is a piece that is very important to make sure you are improving your messaging, especially for those startups that you talked about that just haven't cracked it as of yet, right? They're sending small volumes and they're seeing low response rates. Luella will help you improve that messaging

16:50 just so you can reach a point where you are providing a value and you can push more volume. - That's really unique. And normally a lot of RevOps teams will be behind the scenes crunching a bunch of numbers, trying to make sense of the data. And then, I mean, it's one thing to say, hey, this sequence is outperforming this one. It's another thing to really understand why and then replicate that or take components of that and create new sequences from that. So I think having an AI powered analytics function plus helping you create new messaging based on what's performing really well, like knowing the components of the why it's performing well

17:30Intent signals, integrations, and Octave

17:30 is really important. - Yeah, and that's an area that the entire industry really needs to do a better job of because there are a lot of companies using intent signals and we're strong advocates for intent signals, but there are thousands of them, right? And like most platforms are only doing a good job of like unifying like a couple of dozen, like if not just like one or two. So like the entire industry has a lot more work to do when it comes to that messaging piece. And there's a reason for why we've built very developer friendly APIs just so we can integrate with like-minded partners. One company that we're in the process of building integration with is,

18:08 do you know a company called Octave? - Yes, yeah. They've actually been on our podcast in the past. So great, great company and love the founder as well. - Yeah, we love what they're doing, what Julian and Zach are doing on their side. And they also come from a like very strong like anti-spam background. So like we really share the same mentality over the space and we confirmed our native integration with them just last Friday. So right now we have a really big integrations push. We have over 150 integrations on the roadmap and building developer friendly APIs. Like we're very strong believers in data interoperability, but Octave does a really good job

18:46Human oversight and why software isn't enough

18:46 when it comes to aligning the right messaging with the right prospect. Phantom Buster is doing a really good job when it comes to intent data. Same with Clay, RB2B, Trigify. There's so many incredible companies in the space that we are looking to integrate with. And Anthony, the last piece that I'll mention is human oversight, right? There are a lot of AISDRs that are advocating for like a fully autonomous experience where these AI agents will just do everything and just hand you these opportunities on a silver platter. And like, not only are we very far away from that, like I don't believe that's where this industry is going.

19:24 Like there are advantages to having AI operate independently, especially being able to ingest a much larger amount of data sources. Like that's something I can't do, right? A couple of hours looking at a spreadsheet, I'm tapping out, right? But there's things that like a human can do that an AI agent can't, right? I can show up in person and do a more meaningful job of building a relationship with a prospect. So we really need to blend the best of both worlds. So like, that's why especially for enterprises and mid market companies that we work with, making sure that we do have opportunities to bring the humans back in, right?

19:57 There are certain pieces of copy that are generated by AI that a sales rep should see before it actually gets to a prospect. There are certain things that an admin on the account should see before it even gets to the sales rep in the first place. So human oversight is something that is very important that will help prevent a lot of the previous abuses that I mentioned, brand reputation damages, compliance issues, data leaks. Having humans in the loop is a larger protection against that. And that's also a big reason for why, like we're not just a software company, right? We have a lot of like human beings that are there to support as well.

20:32 Like I regularly host workshops with sales teams to educate on the ethical boundaries of these technologies, how you should have your brand be represented in this AI native world. We'll also have like Slack hotlines where sales reps can put like all the challenges that they are seeing in the trenches when it comes to a security, a safety and deliverability perspective. But yeah, Anthony, that's the platform. - I love it. And I just want to comment on keeping a human in the loop. I think it's fine if you're selling really low ticket item, B2C context. There's not a lot that company is gonna change for that consumer.

21:13Why high-ticket B2B needs a human

21:13 I think why it's different in B2B and hired ticket item, you need to know that you have somebody on the other side that is gonna advocate for you at the company. As an example, when we engage with tools that we would use internally, I wanna know that somebody there is gonna support the customer if we introduce them to them, 'cause that's really important to our business. So building that trust and knowing you have somebody on the other end who can make some decisions around the product experience you're getting, the way it's priced and packaged, like you do need some customization where AI can't make those decisions for you.

21:55 And AI doesn't have the authority to do some things that you need a human on the other side to do. So I think some people don't, maybe they don't understand that aspect of sales, like, especially if you're getting into selling like $100,000 plus type of sales,

22:19 that's an expectation from the customer side. So it's not just, yeah, I can get some product information really quickly, but is somebody gonna have my back if something goes wrong? - Yeah. - I need that assurance that somebody's on the hook for making this successful. - We just recently closed our first really big enterprise six figure a year deal. So we've gone through that, right? Like it was a like four to five months profit process of going back and forth. And there's like, I can list all the things. It's a very comprehensive of all the shit that like an AI agent just will not be able to do that like we needed to have like our team present

22:56Closing the first six-figure enterprise deal

22:56 to get over the finish line. - I'm really impressed with where you started with Wella and thinking about trust and safety and thinking about how you can protect the reputation of the company, creating those individualized IP addresses, individualized servers. Also the approach that you've taken and how you've embedded AI into this process. One, making sure it's testing different messaging, it's optimizing that messaging, putting the right guard rails on, because I think you need to protect your customers from themselves. They will have a rogue SDR, they will have a rogue AE who comes in and just completely lights up their prospect base

23:35Protecting customers from themselves

23:35 and then puts the entire company at risk. So I think the way you've integrated AI, the guard rails you put in place, having it with trust built in the foundation and where you're going in the future, I think is just really, really impressive. And I think it's gonna be highly, highly competitive. - Thank you so much. And yeah, like we're just getting started, right? First line of code over six months ago. And like in this industry, like these models are gonna keep improving, right? And we don't know what we don't know, right? There are gonna be more risks that like, we're not aware of today that do come up.

24:11 So like I would encourage your audience as well to comment as to what are the concerns that they have in disseminating AI and automation across their sales team, because like, especially when you go vertical specific, right? When you speak to health tech companies, for example, or companies in education, there are unique challenges with every industry and like every conversation is a new learning for us as well. Mustafa, what's the best way for people to get in touch with you to start getting their hands on a product? - Yeah, if you go to luella.ai, our website, my Calendly link is on the website. Feel free to schedule some time, always happy to geek out.

24:50Where to reach Mustafa

24:50 My name is Mustafa Saeed on LinkedIn as well. Feel free to connect. - Mustafa, thank you so much for being here today. Really pumped for what you're building and what you're doing and can't wait to see what you guys build next. - Thanks for having me on the pod. Thank you so much.