AI cold calling compliance is not a grey area. The moment you deploy an automated voice agent to make outbound calls, you enter a heavily regulated space governed by the Telephone Consumer Protection Act (TCPA) in the US, similar frameworks in the UK and EU, and sector-specific rules that vary by industry and geography. Get it wrong and you face penalties ranging from thousands to millions in damages. Get it right and you can scale lead generation safely.
This guide covers the mechanisms of compliance, the specific rules that apply to AI calling, real examples of enforcement actions, and the technical and operational controls you need in place before your first call dials out.
What Makes AI Cold Calling Different From Traditional Outbound Calling
Human cold callers have always needed to comply with the TCPA and similar laws. But AI voice agents introduce a new layer of legal complexity because they operate without human judgment in the moment. A human can hear skepticism in a voice and skip the pitch. An AI agent running a script does not. This difference matters to regulators because it amplifies the potential for harm to consumers and creates liability for the business deploying it.
The TCPA defines automatic telephone dialing systems (autodialers) as any equipment that stores numbers and dials them using random or sequential patterns. Most AI outbound calling platforms meet this definition. That means they are subject to TCPA restrictions even if a human wrote the script the AI reads. The AI is the mechanism; the law applies to the mechanism, not the operator's intention.
The Federal Communications Commission (FCC) has issued guidance specifically on AI and robocalls. The agency views AI-generated voice calls with the same scrutiny as traditional robocalls. In 2023 and 2024, the FCC began enforcing rules against spoofed and unpermitted AI calls, with particular focus on political and scam calls, but the legal framework applies equally to business cold calling. If you do not have explicit prior written consent (EPWC) or an established business relationship (EBR), you are breaking the law.
The key difference is consent. A human cold caller can call almost anyone if they respect the Do Not Call Registry and hang up when asked. An AI calling system must have documented proof of consent before dialing. No proof, no call. That is the line.
Understanding TCPA Regulations For AI Outbound Calls
The Telephone Consumer Protection Act was written in 1991. It does not mention AI because AI did not exist then. But the rules it set are strict enough that they apply regardless. The TCPA makes it illegal to call cell phones using an autodialer or artificial voice without prior express written consent. It also restricts SMS and fax messages. Violation carries a fine of $500 to $1,500 per call. Class-action lawsuits have settled for tens of millions.
There are two paths to legal outbound calling under the TCPA. The first is prior express written consent (EPWC). This is consent to receive calls specifically from your company using an autodialer. It must be in writing, signed by the consumer (a checkbox on a web form counts), and it must clearly disclose that the person is agreeing to receive autodialed calls. A vague terms-of-service clause is not enough. An explicit, dated, attributable signature is the minimum. The second path is an established business relationship (EBR). If a consumer has done business with you in the past (bought something, opened an account, made an inquiry), you can call them about related matters without fresh consent, but only to a number they provided to you during that relationship. If they gave you a number five years ago and changed it, you cannot call the new number.
The TCPA also requires that you maintain an internal Do Not Call list separate from the national registry. Anyone who asks to be removed from your calling list must be removed within 30 days and remain on your list forever. You must check this list before every call attempt. The national Do Not Call Registry is free to access via the FTC website and must be scrubbed against your list at least every 31 days. Calling someone on the national registry is a separate violation, even if they never asked you to stop.
The TCPA applies to businesses of all sizes. A five-person SaaS company calling leads is as liable as a 500-person call center. The penalty is per call. If you make 1,000 illegal calls and get caught, that is $500,000 to $1.5 million in damages. The FTC has been actively prosecuting TCPA violations since 2020, with increasing focus on businesses that automate their dialing without proper consent infrastructure.
Prior Express Written Consent and Documentation Requirements
Prior express written consent (EPWC) is the safest path to legal AI cold calling because it removes the ambiguity of an established business relationship. But it only works if you have proof. The consent document must be clear, specific, and stored where you can retrieve it the moment a regulator or plaintiff's attorney asks for it. Courts have thrown out entire calling campaigns because the business could not produce the signed consent at scale.
When you collect EPWC, the consumer must explicitly agree to be contacted by your company using automated calling. The consent form should say something like: "I agree to receive calls from [Your Company] using an automated telephone dialing system." The form must be separate from other terms (not buried in a general terms-of-service agreement), dated, and retained indefinitely. If someone's cell phone number changes, their consent does not transfer to the new number. You need fresh consent for the new number. If they sign up for SMS consent but not call consent, you cannot call them. The consent categories must match the contact method.
The technical side matters as much as the legal one. Your system must link each phone number in your calling queue to the date and document ID of the consent that covers it. If you cannot produce that link during an audit or lawsuit, you cannot prove you had consent, and you lose the case. Many businesses deploy AI calling without this infrastructure and assume retrospective compliance will work. It does not. You must have the mechanism in place before the first call. Platforms like Sysevo that integrate built-in CRM functionality can store consent records, but the onus is on you to collect them correctly and verify them before calling.
Consent can be revoked at any time. If someone says "stop calling me," you must honor that request immediately and not call again (except to confirm removal). This means you need a documented process for opt-out requests, a way to log them in real time, and a way to remove them from active calling campaigns within seconds. A human taking a voicemail opt-out request and updating a spreadsheet is not fast enough if you are making thousands of calls daily. The system must handle it automatically or you will violate the TCPA again by calling someone after they asked to be removed.
Established Business Relationships and Who Can Be Called
An established business relationship (EBR) allows you to call customers without fresh consent, but the definition is narrow. The FCC states that an EBR exists if a consumer has made a purchase, made a payment, or made an inquiry about a product or service within the past 18 months. After 18 months with no contact, the EBR expires and you need consent again. If you met the consumer at a conference and exchanged business cards, that is usually not an EBR unless they explicitly asked you to follow up about a specific product. If they filled out a lead form on your website, that is an inquiry and an EBR exists, but only for calls related to that inquiry. You cannot use an EBR from a form submission about pricing to call them about a job opening.
The phone number matters. An EBR only covers the phone number the consumer gave you during the business relationship. If a customer gave you their work number three years ago and you are now calling their personal cell phone, you do not have an EBR for that cell number. You need fresh consent. Many businesses buy lead lists that include both old and new numbers for the same person and assume the EBR from the old transaction covers all numbers. It does not. This is one of the most common compliance failures in outbound calling. Every phone number must have its own source of legal authority, either consent or EBR, tied to that specific number.
The type of business matters too. If you are calling about a related product or service, an EBR is usually valid. If you are calling about an unrelated offer, you may need consent even if an EBR exists. A bank can call an account holder about a mortgage refinance because the mortgage is related to banking. But if the bank is now calling to pitch auto insurance, courts have held that a fresh consent requirement may apply because it is a separate line of business. The lines are not bright. This is where legal advice from someone who understands TCPA case law becomes valuable.
For B2B calling, the rules are different. The TCPA does not restrict calls to business lines, only residential and cell phone lines. If you are calling a business switchboard or published business line, the TCPA consent requirement does not apply. But other laws may. If you are calling a person at a business number and that person does not consent, and you are harassing them, they may have a state-law claim against you. Also, if you are dialing a published business number but the person who answers is using it as a personal line (common in small businesses), the TCPA may still apply. The safest approach is to treat all numbers as potentially residential unless you have proof otherwise.
State Laws and Regulations Beyond the TCPA
The TCPA is a federal floor. States can and do impose stricter rules. California, New York, and Florida have particularly aggressive state-level caller protections. Some states require prior express written consent for all automated calls, not just those to cell phones. Some require you to identify your company and state the purpose of the call within the first 30 seconds. Some ban certain times of day entirely. If your AI calling operates across state lines, you must comply with the strictest rule that applies to any state you are calling into.
California's rules are among the strictest. The state requires prior express written consent for any automated call to a residential or cell phone line, even if an EBR exists. This means California consumers get more protection than federal law provides. If you are calling a California number without explicit signed consent, you are breaking California law even if you think the TCPA allows it. The Telephone Records Protection Act in California adds another layer by restricting your ability to obtain phone numbers. New York has similar requirements. Florida does not impose as much additional restriction as California, but violations still carry state penalties on top of federal ones.
New Hampshire has a particularly odd rule: it is a two-party consent state for recording, which means if you are recording calls as part of your compliance process (to prove what was said), you need the other party's consent to record. This is a state-level rule separate from the TCPA. If you are deploying AI calling that records calls, you need explicit consent to record in two-party consent states, or you need legal advice on how to operate within those constraints.
The best approach is to assume EPWC is required everywhere unless you have a clear, documented EBR. This means collecting dated, signed consent for every cold call you make via AI. It is more friction in the lead funnel, but it eliminates ambiguity and regulatory risk.
Do Not Call Registry Compliance Mechanisms
The National Do Not Call Registry is maintained by the Federal Trade Commission (FTC). Anyone can register their number for free at donotcall.gov. If you call a registered number without consent or an EBR, you violate the TCPA and may also violate FTC regulations. The registry is not a blocking mechanism; you still have to screen against it yourself. This is not optional and not an afterthought. It is a required step before every campaign.
You must scrub your calling list against the national Do Not Call Registry at least once every 31 days. The FTC provides a free tool to check small volumes, but if you are making hundreds or thousands of calls, you need to use a paid list-scrubbing service or have a system that checks numbers in real time. The scrub must happen within 31 days of your call attempts. If you scrub on day one and call on day 35, you are in violation because the registry may have changed. Many businesses scrub once a month and assume they are covered for the whole month; that is not quite right legally. The safer approach is to scrub immediately before dialing.
You must also maintain your own internal Do Not Call list. This is separate from the national registry. Anyone who tells you "stop calling," whether they say it to the AI agent, reply to a text, or email you, must be added to your internal list within 30 days. They must remain on that list forever. The internal list can be kept in a spreadsheet, a CRM, or a dedicated compliance tool, but it must be accessible and auditable. If you get a lawsuit and the plaintiff's attorney asks for your internal Do Not Call list and you cannot produce it, the court will assume you violated the TCPA by calling people who asked to be removed. Producing a list that shows only 10 opt-outs from 100,000 calls is also a red flag that suggests you did not have a proper opt-out mechanism.
The FTC actively pursues businesses that violate the Do Not Call Registry. In 2023, the agency settled cases against robocall and AI calling operations that had not scrubbed the registry for months. Penalties were in the $100,000 to $1 million range for small businesses and higher for larger ones. The mechanism is simple: scrub every 31 days, log when you scrubbed, log who you removed, and keep those logs. This is not complicated. What is complicated is doing it at the speed and scale of modern AI calling, which is why many platforms now integrate this as an automatic step.
AI Cold Calling Compliance in Regulated Industries
Some industries face additional compliance layers on top of the TCPA. Financial services, healthcare, insurance, and debt collection all have specific rules about outbound calling. If you are using AI cold calling in any of these sectors, you are subject to those rules in addition to TCPA compliance. Missing either set is a violation.
Financial services companies fall under FCC regulations for telemarketing and the Gramm-Leach-Bliley Act (GLBA), which restricts how they handle consumer financial information. If your AI calling system handles any financial data (account numbers, SSNs, credit card numbers), that data must be encrypted at rest and in transit. The GLBA also requires that you have a documented information security program. A financial services company can comply with the TCPA and still violate GLBA by not protecting data properly. The FTC has fined financial services firms millions for GLBA violations tied to telemarketing.
Healthcare entities and HIPAA-covered businesses face the Health Insurance Portability and Accountability Act. If you are calling patients or healthcare consumers, you cannot use automated calls without explicit consent, and you cannot use a non-secure line to leave detailed health information on a voicemail. An AI agent cannot say "Hi, this is a reminder about your colonoscopy on Tuesday." You can say "Hi, this is a reminder call from your doctor's office. Call us back at [number]." The call itself can be automated, but the content must protect privacy. HIPAA violations carry penalties of $100 to $50,000 per violation. If a patient receives a thousand calls from an automated healthcare system and one of them plays a voicemail message breaching privacy, that is 1,000 violations.
Debt collection is heavily regulated by the Fair Debt Collection Practices Act (FDCPA). If your AI calling system is used for debt collection, you cannot call before 8 AM or after 9 PM in the consumer's time zone, you cannot call more than once per week without permission, and you cannot threaten or deceive. If your AI agent is programmed to say "This is an urgent legal matter," when it is not, you have violated the FDCPA. The penalties are $1,000 to $10,000 per violation, and class actions are common. Third-party debt collectors face even stricter rules than creditors collecting their own debt. Check the FDCPA and your state's debt collection laws before deploying AI calling for any collection purpose.
Setting Up Your Consent and Compliance Infrastructure
Before your first AI call goes out, you need four infrastructure pieces in place: a consent collection system, a consent storage and retrieval system, an opt-out mechanism, and a calling queue system that checks consent before dialing. These can be separate tools or integrated into a single platform. But if they are separate, they must be linked and auditable. A business deploying AI calling without these four pieces is knowingly taking legal risk.
Consent collection means building a web form or a process that asks permission and captures the consent document. The form should say: "I agree to receive calls from [Company] using automated calling systems at the number I provide below." The form should capture the date, time, the consumer's name, phone number, and email (if available), and ideally a digital signature or confirmed checkbox. Store this data in a database, not a spreadsheet. You need to be able to search by phone number and pull up the consent record in seconds. If an audit happens, you need to export 10,000 consent records in 10 minutes. A spreadsheet does not scale.
Consent storage must be linked to your calling system. This is where integration matters. If your CRM is separate from your calling platform, and they do not talk to each other, you will have orphaned records and compliance gaps. Voice AI systems that integrate consent data with outbound calling reduce that risk because the system checks consent before dialing. Manual systems are slower and more error-prone. The system should not allow a call to be placed to a number unless the calling system can query the database and find a valid consent record. If the number is on your internal Do Not Call list, the system should flag it or block it before the call goes out.
Opt-out needs to work in real time. If a consumer says "remove me" during a call, the AI agent should be programmed to say "I will remove you from our calling list" and immediately log that request. Within 24 hours, that number must be added to your internal Do Not Call list and removed from any active calling campaigns. If you are in the middle of a 10,000-call campaign and someone opts out, they should not receive another call that day. Manual review creates a 24-hour lag minimum. The FTC accepts some delay for manual processes, but best practice is same-day removal.
The calling queue should check four things before dialing: Is this number on the national Do Not Call Registry (refreshed within 31 days)? Is this number on our internal Do Not Call list? Do we have valid EPWC or an EBR for this number? Is this call being made within legal calling hours (no calls before 8 AM or after 9 PM in the consumer's time zone)? If any of those checks fail, the number should be removed from the queue. This is not a suggestion; it is the minimum legal requirement. A platform that makes calls without running these checks is not compliant, and any business using it is liable for violations.
Caller ID and Transparency Requirements
The TCPA requires that your AI calling system identify your company clearly and state the purpose of the call within the first 30 seconds. Many automated calling systems skip this or bury it because it reduces answer rates. Skipping it is a violation. The FTC and FCC have both issued guidance stating that the caller ID must display your actual company name or callback number, not a fake number or spoofed number. Spoofing caller ID is illegal under the Truth in Caller ID Act, even if the call itself is legally compliant under the TCPA. If your AI agent is calling from a spoofed number, you are breaking two laws at once.
The opening of the call should follow this structure: "Hi, this is [Agent Name] calling from [Company Name] regarding [Purpose of Call]. Is this [Consumer Name] at [Phone Number]?" This takes about 10 seconds. It is transparent, identifies the source, and confirms the right person is on the line. If someone says "I am not interested," you should say "I will remove you from our calling list," and end the call. Do not argue, do not push. That is how you avoid FDCPA violations and state consumer protection violations.
The callback number on caller ID must be real and must be answered. If someone gets a call from your AI system and tries to call back the number in caller ID, the call should connect to a real person or voicemail who can help them. A spoofed number that does not accept calls back is illegal. If your AI calling system uses a VoIP number, that number must be tied to your business and supported by your team. If it is a local number, it should be a local number for the area the AI agent represents or a clear callback line for your main business. Using a 555 number (fictional numbers used in movies and TV) or a clearly spoofed number is illegal and will trigger FCC enforcement.
The Caller ID information should also include a way for the consumer to opt out. Some platforms now add a prompt: "Press 1 to be added to our Do Not Call list." This is excellent compliance practice because it provides a documented opt-out right in the call itself. But the system must actually process the opt-out. If someone presses 1 and nothing happens, or they get added to a Do Not Call list that does not prevent future calls, you have made the problem worse because you can now be accused of knowingly ignoring an opt-out request.
Technical Controls and Call Recording Compliance
If you are recording AI calls for compliance, quality, or training purposes, you need to comply with both federal and state recording laws. Federal law requires one-party consent, meaning at least one person on the call must consent to recording. But many states require two-party consent, meaning both parties (the consumer and your company) must agree. States like California, Florida, Pennsylvania, and Illinois have two-party consent rules. If you record a call in a two-party state without the consumer's explicit consent, you have violated state wiretapping law in addition to any TCPA violations. The penalties are separate and can be severe.
The safest approach is to ask for consent to record during the initial greeting. "This call may be recorded for quality and compliance purposes. Do you consent?" If they say no, you should either hang up or continue without recording. Many AI calling systems continue without recording, which is fine, but you lose the compliance benefit of having a recording. Some systems treat refusal to consent to recording as an implicit opt-out request and end the call. Check your state's law or get legal advice specific to your jurisdiction. The technical control is simple: tag calls with consent-to-record status and only store recordings that have it.
Beyond recording, your system should log every call attempt, every successful connection, the duration of the call, and the outcome (interested, not interested, do not call). This creates an audit trail. If you get sued and cannot produce call logs showing that you called someone on the Do Not Call list, the court will assume the worst. If you can produce detailed logs showing the exact date, time, duration, and that the person asked to be removed, your evidence is strong. Logging is not optional and not something you do after the fact. It must be automatic and real time.
The system should also detect if a number has been called more than once in a short time period and flag it. Many regulations restrict call frequency. Some state laws limit businesses to one call per week per consumer. If your AI system is set to call the same person five times in one day because they keep declining the first call, you are now in violation. The system should track this and either skip numbers that have been called recently or require manual approval before re-dialing. This is a technical control that prevents violations without human review.
When AI Cold Calling Is the Wrong Choice
AI cold calling is not suitable for every business model or situation. If you are working with a small list of warm leads (people who have expressed clear interest), AI calling is overkill and may introduce more compliance risk than it prevents. A human cold caller working with 100 engaged prospects will have higher success rates, fewer compliance issues, and better brand outcomes than an AI agent working the same list. AI calling makes sense when you have hundreds or thousands of numbers to dial and you want consistent messaging at scale. If your list is small, the math does not work.
AI cold calling is also a poor fit if you do not have documented consent infrastructure in place. Many businesses think they can deploy an AI calling system, make calls, and sort out compliance later. This is how businesses end up in FTC enforcement actions. The FTC has explicit guidance that deploying a calling system without consent infrastructure in place is reckless. If you do not have the ability to store, verify, and retrieve consent records, do not start AI calling. Build the infrastructure first. This takes time and costs money, but it is non-negotiable.
If you are selling products or services where the consumer has explicitly said they do not want unsolicited calls, AI calling will not change their mind and will damage your brand. Some consumers will never accept an AI calling system, no matter how compliant it is. They will hang up immediately, leave bad reviews, or file complaints with the FTC. If your conversion rate from AI calls is less than 1 percent and your complaint rate is 5 percent, the business model is not working. Before deploying AI calling, calculate the lift in conversion rate you need to justify the cost and the compliance overhead. If you cannot hit that target, do not deploy.
AI calling is also not appropriate for sensitive topics. Debt collection, healthcare, financial services, and legal matters have complex consent and privacy rules. Deploying an AI agent to cold call people about debt, medical treatment, or legal issues without careful legal review and industry-specific compliance is dangerous. These sectors are heavily regulated, and the regulatory bodies actively prosecute violations. Get legal advice before deploying AI calling in these industries. The cost of a compliance review now is less than the cost of a settlement later.
Documenting Your Compliance Program
You need a written, documented compliance program that describes how your business handles consent, opt-outs, Do Not Call checking, and call logging. This program should be a public-facing document that you can show to regulators or a court. It should describe the specific steps your team takes before, during, and after each call. It should name the roles responsible for compliance (compliance officer, legal team, operations lead). It should outline how often you audit your calling practices and what you do when you find violations. If you get audited and cannot produce a compliance program, regulators will assume you have no compliance process at all.
Your compliance program should also describe your training process. Anyone with access to the AI calling system, the calling lists, or the consent database should receive annual training on TCPA rules, state-level rules, and your company's specific compliance policies. The training should be documented and signed off by attendees. If someone on your team makes a compliance mistake and cannot point to training they received, the liability falls on you. Regular training also catches drift. Teams naturally cut corners over time. Annual training resets expectations and reminds people why compliance matters.
Auditing is the third pillar. Quarterly or semi-annually, you should audit your calling logs, consent records, and opt-out list to ensure the system is working as designed. Pull a random sample of 100 calls. For each call, verify that the number had valid consent or an EBR. Verify that the number was not on the Do Not Call Registry at the time of calling. Verify that any opt-out requests were processed within 24 hours. If you find gaps, document them and fix the process. If you have to report to regulators, the fact that you audited, found issues, and fixed them is much better than having no audit trail at all.
Keep records of all of this. Consent documents, call logs, audit reports, training records, compliance procedures. If you do not have a records retention policy, create one now. The TCPA does not specify how long you must keep records, but best practice and other regulations (like GLBA for financial services) require keeping them for at least five years. Longer is safer. If you delete records and then get sued, the court may infer that you deleted them to hide violations. Keep everything in a way that is organized, searchable, and auditable. A CRM or compliance-specific platform is better than email folders or shared drives.
Monitoring and Enforcement Actions
The FTC is actively monitoring AI calling and robocalling. In 2024, the agency has prioritized this area, issuing guidance on AI-generated voices and initiating enforcement actions against companies that use AI calling without proper consent. The FCC is also monitoring and has shown willingness to fine businesses for TCPA violations. Between the two agencies, along with state attorneys general, there are multiple pathways for regulators to identify and punish violations. Additionally, private citizens can file TCPA lawsuits directly. A single consumer can sue a business for TCPA violations, and if the business made illegal calls to multiple people, the lawsuit may be certified as a class action. Class-action settlements in TCPA cases have exceeded $100 million. The risk is real and rising.
How do agencies catch violations? Some of it is consumer complaints. A person gets an illegal call and files a complaint with the FTC or FCC. The agency investigates. But a lot of it is proactive monitoring. The FTC has intelligence systems that detect patterns of calling. If a particular phone number is generating high complaint volumes, the agency will investigate the business behind that number. The FCC can also monitor calling patterns through telecom carriers. If millions of calls are being placed from a small set of numbers and those calls have characteristics of robocalls (all the same script, all the same duration), that triggers investigation.
The penalties are not just regulatory. Consumers can sue directly under the TCPA and can win statutory damages of $500 to $1,500 per call. If a plaintiff's attorney can prove that you made illegal calls to 1,000 people, the damages are $500,000 to $1.5 million. The business does not have to intend to violate the law or profit from violations. Even innocent or negligent violations carry the full statutory penalty. In 2023, a business paying $5 to $8 per lead via cold calling could suddenly face $500 in liability per lead if the calls were not compliant. That is a business model that breaks instantly once compliance fails.
If you receive notice that you are under investigation or that a class-action lawsuit has been filed against you, contact a lawyer immediately. Do not delete records, do not tell your team to stop making calls quietly, and do not assume the matter will go away. The TCPA is one of the most prosecuted consumer protection statutes in the United States. Settlements are common, and they typically include penalties, disgorgement of profits, and injunctions preventing future violations. Early legal intervention, cooperating with investigators, and demonstrating that you have since fixed your compliance practices can reduce penalties significantly.
Choosing a Compliant AI Calling Platform
If you decide to deploy AI calling, choose a platform that has compliance built in, not bolted on. This means the platform should have features like automatic Do Not Call Registry scrubbing, built-in consent management, call logging, and opt-out processing. The platform should also provide documentation of its compliance mechanisms and ideally have undergone third-party audit or certification. Platforms that sell AI calling without these features are shifting compliance risk to you, their customer. You are still liable if violations occur, even if the platform made the mistake.
When evaluating platforms, ask specific questions. How does the system check consent before dialing? How often is the Do Not Call Registry updated? Can you export call logs and consent records for audit? How quickly are opt-out requests processed? What happens if a Do Not Call conflict is detected? Can you set calling hours that respect time zones? What is the caller ID infrastructure and is it spoofable? Ask for a copy of their compliance documentation and read it. If they do not have formal documentation, they probably do not have a formal process either. Check whether the platform offers compliance training or documentation that you can use for your team.
If you are a regulated business (financial services, healthcare, debt collection), ask whether the platform has experience in your industry and understand industry-specific rules. A platform designed for tech lead generation may not have the compliance controls needed for healthcare calling. If you are working with a platform that integrates CRM capabilities, confirm that consent data is stored securely and segregated from other data. Ask whether they offer custom solutions for your industry's specific requirements. Some platforms are happy to customize; others are not. If customization is essential to your compliance, make sure it is contractually committed to before you sign up.
State-by-State Compliance Variations
Beyond the federal TCPA and the Do Not Call Registry, individual states have their own rules. If you call across multiple states, you must comply with the strictest rule in any state you call into. This sounds simple but is often overlooked. A business in Texas assuming TCPA compliance is sufficient may not realize that California calls require prior written consent even for EBR situations. Texas has no such additional requirement, so the Texas team thinks they are fine. They are not fine for California calls.
A few states worth highlighting: California and Illinois have the strictest requirements. California requires EPWC for almost all automated calls. Illinois has two-party recording consent requirements. If your AI system records calls, Illinois calls need consent to record, in addition to consent to call. Florida requires that you comply with both the TCPA and the Telemarketing Sales Rule, which has overlapping but distinct requirements. New York requires the same information in the opening of the call as the FTC rule, plus you must maintain a state-specific Do Not Call list. Texas has fewer additional requirements than other large states, but you still must comply with the TCPA. Wyoming and a few other rural states have lower population density but the same legal rules. If you call them, you comply.
The practical approach is to assume EPWC is required everywhere. If you have EPWC for every call, you are compliant in all states. If you are relying on EBR, map which states allow EBR without additional consent and which do not. California, Illinois, Florida, and a few others do not. Segment your calling list by state and apply the strictest rule to each segment. This overhead is a cost of operating in a multi-state environment. If that cost is too high, you might consider focusing on states with fewer restrictions, but that is a business decision, not a compliance one.
Building a Sustainable Compliance Culture
Compliance is not a one-time setup. It is an ongoing practice. Businesses that stay compliant have built compliance into their culture and their processes. This means having a named compliance owner, regular team meetings about compliance issues, quarterly audits, and annual training. It also means creating feedback loops so that when the FTC issues new guidance or a court rules on a TCPA case, your team knows about it and assesses whether your practices need to change.
A sustainable compliance culture also accepts that compliance costs money. Do Not Call Registry scrubbing costs money. Consent database infrastructure costs money. Compliance training costs time. Legal review costs money. A business that tries to deploy AI calling on the cheap, using free tools and minimal infrastructure, will eventually face compliance violations and penalties that cost far more. Budget for compliance. Treat it as a cost of doing business, like customer support or sales commissions. It is.
Finally, plan for the possibility of enforcement. If you are making hundreds of thousands of AI calls, the probability of getting audited or sued approaches certainty eventually. Rather than assuming it will not happen, assume it will and plan accordingly. Keep records, document your process, and maintain evidence of compliance. If an investigation comes, you want to be able to say "We have been consciously compliant since day one," not "We are trying to figure this out after the fact." The first position is defensible. The second one is not.
If you are ready to implement AI calling with a compliant foundation, start with a platform that has built-in compliance controls and integrate it with your legal and operational teams. Schedule a call to discuss how to structure your deployment safely, or review our plans and pricing to see which tier includes the compliance features your business needs. Compliance is not a feature that makes AI calling better; it is the foundation that makes it legal and sustainable.
Frequently Asked Questions
Can I use AI to call people if I have no prior relationship with them?
Only if you have prior express written consent (EPWC). EPWC must be documented, dated, and kept on file. An EBR (established business relationship) does not apply if there is no prior relationship. Without EPWC or EBR, calling is illegal under the TCPA. Consent must be specific to your company and to automated calling.
How often do I need to scrub the Do Not Call Registry?
At least once every 31 days. The FTC requires that you check your calling list against the national registry within 31 days before calling. If you call more frequently than daily, you should scrub more often, ideally immediately before each campaign. Waiting 31 days creates risk because the registry changes daily.
What is the penalty for one illegal AI call?
Between $500 and $1,500 per call under the TCPA. If you make 100 illegal calls, you face between $50,000 and $150,000 in liability. In class-action suits, settlements often hit the higher end. Individual state laws may add penalties on top of federal ones. The penalties are per call, not per campaign.
Can I call someone if they have an established business relationship with my company but I do not have written consent?
Yes, if the relationship is current (within the past 18 months) and you are calling about a related matter using a number they provided during that relationship. However, if the state is California or Illinois, you may need written consent anyway. If the person is on the national or your internal Do Not Call list, the EBR does not apply. Always check your internal Do Not Call list first.
What should happen if someone asks to be added to my Do Not Call list?
They must be added to your internal Do Not Call list within 30 days. They must remain on that list permanently. You cannot call them again except to confirm that they have been removed. This must be a documented process in your system, and the person must be removed from active campaigns before the next call cycle. Ideally, same-day removal.
Do I need to identify my company and the purpose of the call on every AI call?
Yes. Within the first 30 seconds, the AI agent must state the company name and the purpose of the call. Failing to do this is a separate violation. The caller ID must also display your actual company name or a real callback number, not a spoofed number. If someone calls back the number in caller ID, it should connect to your business.
What is the difference between the TCPA and other state laws?
The TCPA is federal law that applies everywhere. States can impose stricter rules on top of the TCPA, but they cannot be more lenient. California, Illinois, and Florida have additional restrictions beyond the TCPA. If you call across multiple states, you must comply with the strictest requirement that applies to any state you call into. When in doubt, assume prior written consent is required everywhere.