TCPA Compliance for AI Voice Agents: What US Law Requires Before You Dial

Aug 2, 2026

The current TCPA position on AI voice calls, with primary sources: consent, the revocation rule that is in force, the one to one rule that is not, and damages.

TCPA Compliance for AI Voice Agents: What US Law Requires Before You Dial

You have an AI voice agent that sounds human, books meetings, and never gets tired. Then somebody in the room asks the question that stops the project: are we allowed to call people with this?

The answer in the United States is yes, with conditions, and the conditions are written down. Most of the confusion in this market comes from teams repeating half remembered versions of rules that changed, were struck down, or were never in force. This page is the current state of the law with the primary sources attached, so you can check every line of it yourself.

None of this is legal advice. It is the map an operator needs before a first dial, and it should make the conversation with your counsel shorter.

$500

Statutory damages per violating call, trebled at the court's discretion for willful violations.

10days

Business days to honour a request to stop calling, from the moment it is received.

2024

The year the FCC confirmed AI generated voices count as an artificial voice.

An AI voice is an artificial voice, and that settles more than it seems

On 2 February 2024 the Federal Communications Commission adopted a Declaratory Ruling holding that the Telephone Consumer Protection Act's restrictions on an "artificial or prerecorded voice" cover current AI technologies that generate human voices. It was released on 8 February 2024 as FCC 24-17.

Read plainly, that means your synthetic voice agent sits in the same regulatory box as a recorded message from 1995. Calls made with it require the prior express consent of the person you are calling, unless there is an emergency purpose or a specific exemption.

This is the single most useful thing to internalise, because it collapses a lot of speculation. There is no separate, softer regime for AI calls waiting to be written. The existing regime already applies, it has thirty years of case law behind it, and the plaintiffs' bar knows it well.

What kind of consent, and for which calls

The statute distinguishes by what the call is for and where it lands. Marketing calls made with an artificial voice to a mobile number need prior express written consent. Calls to residential landlines using an artificial voice need prior express consent, and marketing raises that to written consent too. Purely informational calls to someone who gave you their number sit differently again.

Written consent has a specific meaning here. It is a signed agreement, electronic signatures count, that clearly authorises calls using an automated system or artificial voice, discloses that agreeing is not a condition of purchase, and names the seller doing the calling. A tick box buried in terms of service does not carry it.

The practical translation for a voice AI deployment: know, per contact record, what they agreed to and when, and be able to produce it. Consent you cannot evidence is consent you did not get.

Consent you cannot evidence is consent you did not get.

the Kaigen team

The revocation rule is in force, and it is stricter than most teams assume

This is where current write ups most often mislead, because part of the rule was delayed and the delay gets reported as though the whole rule were on hold. It is not.

Rule 47 CFR 64.1200(a)(10) took effect on 11 April 2025. It says a person may revoke consent "by using any reasonable method", and it lists methods that count automatically: an interactive voice or key press opt out on the call itself, the words stop, quit, end, revoke, opt out, cancel or unsubscribe in reply to a text, or a website or phone number you designated for the purpose.

Three parts of it catch teams out. Other words count too, if a reasonable person would read them as a request to stop. You must honour any such request within a reasonable time "not to exceed ten business days". And you may not designate an exclusive means of revocation, so building a lovely opt out portal does not let you ignore someone who tells your agent to stop talking to them.

That last point has a direct design consequence for voice AI. If a person says "take me off your list" mid conversation, your agent has to recognise it as a revocation and your systems have to act on it. An agent that cheerfully continues the script is generating evidence against you on a recorded line.

What was delayed is narrow: the requirement to treat a revocation given in response to one kind of informational message as applying to all future unrelated messages from you. The FCC waived that slice to 11 April 2026, then extended it again to 31 January 2027 in an order adopted on 6 January 2026 (DA 26-12). Everything else in the rule has been live since April 2025.

The rule everyone prepared for, which is not law

In December 2023 the FCC adopted a "one to one consent" rule aimed at lead generation, requiring consent to name a single seller and cover topics logically and topically related to the interaction that produced it. A great deal of compliance tooling was built for it.

On 24 January 2025, one business day before it would have taken effect, the Eleventh Circuit vacated it in Insurance Marketing Coalition v. FCC, holding that the Commission had exceeded its statutory authority because the new restrictions conflicted with the ordinary meaning of prior express consent. The FCC subsequently removed the rule.

Two conclusions follow, and they point in opposite directions, which is why this one is worth stating carefully. You are not obliged to comply with a rule that no longer exists. You also should not read the vacatur as a green light for buying lead lists and calling them with an artificial voice, because the underlying consent requirement never went anywhere, and a purchased consent record you cannot trace to the person answering the phone is the weakest possible position to litigate from.

What it costs when it goes wrong

The Telephone Consumer Protection Act carries a private right of action. Under 47 U.S.C. 227(b)(3) a person can recover actual losses or $500 per violation, whichever is greater, and a court may treble that for willful or knowing violations.

Per violation means per call. The arithmetic is what makes this an existential rather than an annoying risk: an automated system that dials a bad list does not make one mistake, it makes the same mistake at machine speed until somebody stops it. That asymmetry is the argument for rate limits, list hygiene, and a kill switch that a non engineer can reach.

Federal law is also a floor rather than a ceiling. Several states run their own telemarketing statutes with their own consent standards and their own damages, Florida and Oklahoma among the more active. If you dial nationally, your consent model has to satisfy the strictest state you touch, not the average one.

What a defensible setup looks like before the first dial

01

Evidence consent

Per contact, store what they agreed to, when, and through which form. Retain the record, not a flag.

02

Scrub the list

National and internal do not call lists, checked before the dial rather than nightly.

03

Hear the opt out

The agent recognises a request to stop in natural language, not only a key press, and writes it back.

04

Act within ten days

Suppression propagates to every channel and campaign inside the window, provably.

Identification matters too. Say who is calling and on whose behalf, early, and give a way to reach a human. Recording adds its own layer: a number of states require every party on the call to consent, so a national recording policy has to default to the strictest rule you touch. Our global compliance guide maps recording and consent rules across the other markets you are likely to dial, and if India is on that list, the TRAI rules work on entirely different machinery.

The part that is operational, not legal

Every item above is a build decision at launch and a maintenance decision forever after. Consent records drift as forms change. Suppression lists break quietly when a CRM field is renamed. A prompt edit six months in can remove the disclosure nobody remembered was load bearing.

So the honest question when you evaluate a platform is not whether it can do these things. Most can. It is who is watching them in month six, which is the same question that decides most of the six layer stack underneath any deployment.

Q1

Can you produce the consent for a given call?

Within minutes, from a record, without asking anyone to remember. That is the standard a claim will hold you to.

Q2

What happens when someone says stop?

If the answer involves a person reading a transcript later, the ten day clock is already running against you.

Q3

Who reviews the script after a change?

Disclosures live in prompts. Prompts get edited. Unowned prompts drift out of compliance silently.

KEY TAKEAWAYS

  • AI generated voices are artificial voices under the TCPA, confirmed by the FCC in February 2024. The existing consent regime applies in full.
  • The revocation rule has been in force since April 2025. Only the cross topic slice of it is waived, now to 31 January 2027.
  • You may not designate an exclusive way to opt out, so your agent must recognise a spoken request to stop and act on it within ten business days.
  • The one to one consent rule was vacated in January 2025 and is not law. The underlying consent requirement is unchanged.
  • Damages run at $500 per call and treble for willful violations, which is why automated dialing needs rate limits and a reachable stop.

BEFORE YOU DIAL

Want a second pair of eyes on your calling setup?

Twenty minutes on your consent model, suppression flow, and what your agent does when somebody says stop. We run this on live deployments every week.

Book a 20 minute review →

FAQ

Is it legal to use an AI voice agent for outbound calls in the United States?

Yes, with consent. The FCC confirmed in a Declaratory Ruling released on 8 February 2024 that AI generated voices fall within the TCPA's restrictions on artificial or prerecorded voices, so those calls require the prior express consent of the person called, absent an emergency purpose or an exemption. Marketing calls to mobile numbers require prior express written consent.

Has the TCPA consent revocation rule been delayed?

Only in part. Rule 47 CFR 64.1200(a)(10) took effect on 11 April 2025 and is in force. The FCC waived one narrow requirement, that a revocation given in response to one type of informational message must apply to all future unrelated messages, first to 11 April 2026 and then to 31 January 2027 by an order adopted on 6 January 2026. Every other part of the rule applies now.

How quickly must we stop calling someone who opts out?

Within a reasonable time not exceeding ten business days from receipt of the request. The rule also lists methods that count as reasonable per se, including an interactive voice or key press opt out on the call, and it forbids designating any single exclusive route for revoking consent.

Do we still need to follow the one to one consent rule?

No. The Eleventh Circuit vacated it on 24 January 2025 in Insurance Marketing Coalition v. FCC, holding the Commission exceeded its statutory authority, and the FCC then removed it. The ordinary requirement to obtain prior express consent, and to be able to evidence it, is unaffected.

What are the penalties for getting this wrong?

The TCPA gives individuals a private right of action for actual losses or $500 per violation, whichever is greater, which a court may increase up to three times for willful or knowing violations. Because the figure is per call, an automated dialer working from a bad list accumulates exposure quickly. Several states also run their own telemarketing statutes with separate standards.

MORE BLOGS

Continue Reading