TCPA Compliance for AI Voice Agents, Calls and Texts

A company builds an AI voice agent to handle outbound sales calls. It sounds natural, adjusts to what the person says, nothing like the robotic auto-dialers from twenty years ago. Legal, right? A federal law written in 1991, before the internet had a dial tone, says otherwise. The fine is $500 to $1,500 per call.
That law is the Telephone Consumer Protection Act (TCPA), passed to stop robocalls and fax spam. It was never written with generative AI in mind. But regulators have spent the past two years closing that gap, and the result is a set of rules that most companies deploying AI voice or SMS haven’t caught up with yet.
Table of contents
Quick Answer
-
AI-generated voices can fall under the TCPA’s restrictions on “artificial or prerecorded voice” calls even when the AI generates speech dynamically in real time.
-
Outbound AI calling campaigns may require prior express written consent before the call is made.
-
AI disclosure requirements are developing at both federal and state levels, so businesses operating across the US need to consider where each interaction takes place.
-
Consent management, opt-out detection, Do Not Call screening, and revocation handling should be built into the AI system rather than treated as an afterthought.
The Rule That Changed Everything: AI Voices Count as “Artificial”
For years, companies argued that a live, adaptive AI conversation was categorically different from a pre-recorded robocall: the AI generated speech in real time based on what the person said, rather than playing back a fixed script. That argument is no longer available.
On February 8, 2024, the Federal Communications Commission ruled, unanimously, that AI-generated voices fall within the TCPA’s existing restriction on “artificial or prerecorded voice” calls. It doesn’t matter that the voice is synthesized on the fly, responds dynamically, or was never recorded in advance. If it’s not an actual human speaking live on the call, the TCPA treats it the same way it treats a decades-old auto-dialer.
The practical consequence: any outbound call using an AI voice agent now needs prior express written consent from the person being called, the same standard that applied to old-fashioned robocalls. No consent, no exemption: it’s a violation, at $500 to $1,500 per call, with no cap on how many calls a court can count.
Businesses Now Have to Tell People They’re Talking to AI
Getting consent to call isn’t the end of it. A second, separate obligation is emerging: telling the person, during the call, that they’re talking to AI.
At the federal level, the FCC has moved toward requiring an up-front disclosure at the start of AI-assisted calls. Some states have already gotten there first. Utah’s AI disclosure law, in effect since May 2025, requires businesses using generative AI to interact with a consumer to disclose that fact, orally, at the start of the interaction, if asked, and automatically in certain regulated contexts.
This isn’t a one-state curiosity. It’s the direction the regulatory trend is moving nationally, and a company running AI voice campaigns across state lines needs to plan for disclosure requirements that already exist in some places and are actively being written into law in others.
Chatbots and Automated SMS Carry the Same Exposure
The AI-voice-call analysis doesn’t stay contained to phone calls. A generative AI system sending personalized SMS messages, or running an automated chat conversation, without a human directly initiating each message, can be classified as an “automatic telephone dialing system” (ATDS) under the same statute. That classification triggers the same consent requirements as a voice call.
There’s a second, quieter risk layered on top: AI systems get trained on large contact databases, and those databases don’t always filter cleanly. A number that revoked consent last year, or sits on the National Do Not Call Registry, can end up back in an outbound campaign simply because the training data wasn’t scrubbed against current opt-out records. The AI didn’t do anything wrong technically. It just wasn’t given a clean list to work from.
The Consent Can Disappear Mid-Conversation
Consent isn’t a one-time checkbox that stays valid indefinitely. A consumer can revoke it at any point, in almost any words: “stop calling me,” “take me off your list,” or any other reasonably clear request to stop.
For a human agent, catching that is intuitive. For an AI system, it has to be built in deliberately: real-time detection of revocation language, immediate logging of the opt-out, and a hard stop on any further contact, including a callback later that day. An AI voice agent that keeps talking past a clear “stop” request, or a chatbot that gets scripted around a revocation phrase instead of honoring it, is a fresh violation each time it happens, independent of whatever consent existed before.
What “Prior Express Written Consent” Actually Requires
The phrase gets thrown around loosely, but the standard has specific components, and an AI deployment that skips any one of them doesn’t actually have valid consent. It just has a paper trail that looks like one.
Valid prior express written consent needs a clear written agreement, signed physically or electronically, that specifically authorizes calls or texts using an automated or artificial voice system, names the entity that will be calling, and isn’t buried inside unrelated terms and conditions as a precondition of some other transaction. A checkbox agreeing to generic “marketing communications” during a website signup rarely covers this. It needs to speak specifically to automated or AI-generated calls.
This matters because a company that collected consent for a different purpose, say a general newsletter opt-in, and then routes that same contact list into an AI voice campaign is very likely operating without valid consent for that specific channel, even though a consent record technically exists somewhere in the system.
The Litigation Reality: Why TCPA Claims Move Fast
TCPA cases are structurally attractive to plaintiffs’ firms in a way most consumer protection statutes aren’t. The statute provides for statutory damages of $500 to $1,500 per violation, without the plaintiff having to prove any actual financial harm occurred. A single bad list of a few thousand numbers, called or texted even once without valid consent, can turn into a class action with damages calculated in the millions before any argument about the underlying conduct even starts.
That math is exactly why TCPA has produced some of the most active class-action litigation in US consumer law for over a decade, well before AI entered the picture. Layering a new, actively regulated AI angle on top of an already litigation-heavy statute doesn’t reduce that exposure. It gives plaintiffs’ counsel a second, fresher theory to add to a complaint.
Where This Actually Bites: Two Questions to Answer First
Most of the legal exposure here comes down to two decisions a business makes before it ever launches an AI calling or texting program:
Voice or Text?
A voice AI agent triggers the “artificial voice” rules directly under the February 2024 FCC ruling. A chatbot or automated SMS system gets analyzed under the ATDS standard instead. The consent and disclosure requirements differ enough between the two that a compliance approach built for one won’t automatically cover the other.
Inbound or Outbound?
A customer who calls your AI support line has, by initiating contact, generally already established a different consent posture than someone your AI system calls cold. Outbound AI campaigns — including sales, collections, and appointment reminders sent to numbers that never gave real-time consent — carry meaningfully higher exposure than inbound AI handling calls customers placed themselves.
Answering both before deployment is what determines whether a company needs a full prior-express-written-consent capture flow, a disclosure script, or both.
It’s Not Just the Marketer on the Hook
The exposure here doesn’t stop at the company running the calling campaign. A business that builds or licenses the underlying AI voice or chat platform can also be pulled into liability, particularly where it configured the calling behavior, supplied the contact-scrubbing logic, or marketed the tool specifically for outbound consumer contact.
That matters for a growing category of company: AI voice-agent platforms and conversational-AI vendors selling directly into sales, collections, and customer outreach use cases. A vendor that ships a product without consent-capture tooling, disclosure logic, or revocation handling built in isn’t insulated just because its customer made the actual call. Courts have repeatedly held that TCPA liability can extend beyond the party that physically initiated contact to reach the party that materially participated in making it happen.
For an AI company building this kind of product, that’s a reason to treat TCPA compliance as a product requirement, not a customer’s separate legal problem. Building consent verification, disclosure prompts, and revocation detection into the platform itself is both a real compliance safeguard and, increasingly, a feature buyers are starting to ask about directly.
A Practical Starting Checklist
Before an AI voice agent or automated messaging system goes live in the US, a handful of concrete questions need documented answers, not assumptions:
-
What does the consent record actually authorize? Confirm it specifically covers automated or AI-generated calls and texts, not just general marketing contact.
-
Where did the contact list come from, and when was it last checked? A list that hasn’t been scrubbed against current Do Not Call and revocation records recently is a liability sitting in a spreadsheet.
-
Does the AI disclose it’s AI, and when? Confirm whether the specific state and use case requires disclosure at the start of the interaction, on request, or both.
-
How does the system detect and log a “stop” request? Test it directly: say the words a frustrated customer would actually use, not just a scripted “unsubscribe,” and confirm the system reliably catches them.
-
Who reviews this before every new campaign or use case launches? A one-time compliance review at build time doesn’t cover a system that keeps getting reused for new calling lists and new scripts months later.
None of these are one-time boxes to check. An AI system that passed review at launch can drift out of compliance the moment someone points it at a new contact list or a new state without re-checking the same questions.
What This Means Before You Deploy
If a business is building or buying an AI system that calls, texts, or chats with consumers in the US, the TCPA analysis needs to happen before launch, not after the first complaint. That means confirming what kind of consent the specific use case requires, building a disclosure into the interaction where the law calls for one, and making sure revocation is detected and honored in real time rather than handled as an afterthought.
This is exactly the kind of gap that doesn’t show up until a regulator, a plaintiff’s firm, or a class action lawsuit finds it first. TCPA cases are a well-established and active area of litigation, and an AI system that wasn’t reviewed for this exposure is an easy target.
If you’re deploying, or planning to deploy, AI voice agents or automated messaging in the US, our team can review the consent model, disclosure requirements, opt-out handling, and overall TCPA compliance position before launch.
Conclusion
A law from 1991 now governs some of the most advanced AI products being built in 2026, and the gap between “this feels different” and “this is legally different” is smaller than most companies assume. AI-generated voices need the same consent an old robocall needed. Some states already require telling the person they’re talking to a machine. Chatbots and automated SMS carry the same exposure under a different label. And consent can vanish the moment someone says stop.
That’s not a reason to avoid AI in customer communications. It’s a reason to finish the legal groundwork before the first call goes out, not after.



