Written by Silvana Lucido-BalestrieriUpdated on September 10, 2026

TCPA Compliance Checklist for AI Voice Calls: 10 Steps to Follow

AI voice calls are legal in the US, but outbound calls must follow TCPA rules. Learn the key requirements for consent, opt-outs, DNC lists, calling hours, and more.

TL;DR:

AI voice calls are legal in the US, but outbound calls are regulated under the TCPA (Telephone Consumer Protection Act). Here are some key rules to keep in mind:

  • Consent: Required for certain outbound calls.
  • AI voices: Covered by the TCPA's “artificial or prerecorded voice” rules.
  • Do Not Call: Check applicable DNC lists before telemarketing calls.
  • Calling hours: Follow federal and state time restrictions.
  • Opt-outs: Honor requests to stop future calls.
  • Disclosure: Identify your business and follow applicable disclosure rules.
  • State laws: May add stricter requirements.
  • Penalties: TCPA violations can result in $500–$1,500 per violation.
  • AI-specific rules: Additional FCC requirements have been proposed but are not currently federal law.

Bottom line: AI doesn't make outbound calling exempt from TCPA rules. Use the TCPA compliance checklist below to build a TCPA compliant AI calling workflow.

75% of customers want to know when they're talking to an AI agent. But transparency isn't the only consideration when using AI for phone calls. But transparency isn't the only thing businesses need to consider when using AI for phone calls. They also need to understand the regulations that govern how AI can make and handle calls.

In this TCPA compliance guide, we'll explain what the TCPA means for AI voice calls*, how inbound and outbound calls differ, and the key steps to keep your AI calling workflow compliant.

*This is general information, not legal advice, and it won't tell you whether your own setup is compliant. For CloudTalk's compliance commitments and calling features, see our Terms of Service and Help Center, and talk to qualified TCPA counsel.

Yes, AI voice calls are legal in the US, but they're regulated under the TCPA (Telephone Consumer Protection Act). While the TCPA doesn't mention AI voice agents specifically, as it was written in 1991, the Federal Communications Commission (FCC) clarified in 2024 that AI-generated voices fall under its existing rules for “artificial or prerecorded voice” calls.

For outbound calls, businesses generally need to obtain the required consent, identify themselves, and provide an opt-out for telemarketing calls (Paragraph 9, FCC). Violations can result in $500–$1,500 in damages per call (§ 227 TCPA).

State laws can add further requirements, including AI-specific disclosure rules. So businesses making calls across the US need to consider both the federal TCPA and the laws that apply in each state.

In August 2024, the FCC proposed additional AI-specific requirements, including disclosing AI use at the start of calls and in consent language. As of September 2026, these requirements remain a proposal.

Here’s a quick overview of what the TCPA means for AI voice calls:

AI voice calls and the TCPA at a glance

The fast answers to the questions this TCPA checklist covers.
QuestionAnswer
Are AI voice calls legal in the US?Yes
Are they regulated?Yes, under existing TCPA rules
Do AI voices fall under the TCPA?Yes, since the FCC's 2024 clarification
Is consent required for outbound calls?Yes, depending on the type of call
Is AI disclosure federally required?Not yet
Can state laws add requirements?Yes
Can violations result in fines or damages?Yes, potentially $500–$1,500 per call
General information, not legal advice. Confirm specifics for your markets with counsel.

Does the TCPA Apply to Inbound and Outbound AI Calls?

The TCPA and the FCC's 2024 ruling focus on calls initiated by businesses to consumers. The FCC ruling specifically refers to AI technology that initiates an outbound call using an artificial or prerecorded voice, while the relevant TCPA provisions prohibit businesses from making or initiating calls to consumers using such voices.

This means the TCPA's artificial-voice consent requirements generally apply to outbound AI calls, rather than calls a consumer initiates to your business.

But Inbound Doesn’t Mean Compliance-Free

The fact that these TCPA provisions are framed around outbound calls doesn't mean inbound AI calls are exempt from all legal requirements. Other federal, state, or local laws may still apply, including state call-recording consent rules and AI disclosure requirements.

For any AI voice deployment, consider who initiates the call, what the AI does during the conversation, who you're calling, and which laws apply to the interaction.

In summary:

Inbound, outbound, and callbacks under the TCPA

Who starts the call decides which rules apply.
Call typeWho initiates it?TCPA considerations
Inbound AI callConsumerGenerally not subject to these TCPA restrictions, but other rules may apply
Outbound AI callBusinessTCPA requirements can apply, including applicable consent rules.
Automated callbackBusinessA callback is still an outbound call and should be assessed under the applicable TCPA requirements.
General information, not legal advice. Assess each call type against current TCPA requirements.
When in doubt, consult a qualified legal professional to assess your specific use case, call flows, and the laws that apply to your business.

The TCPA Compliance Checklist for AI Voice Calling

If your AI voice agent makes outbound calls, use this checklist as a practical starting point. The exact requirements depend on the type of call, the consent you have, and the states you're calling into.

10 Steps to TCPA-Compliant AI Voice Calling

  • Get the right consent before making marketing calls.
    For AI-initiated marketing calls or texts, you generally need prior express written consent. Keep a record of when and how consent was given, including the source and the disclosure the person saw.
  • Apply the consent standard you'd use for a prerecorded message.
    The FCC treats AI-generated voices as “artificial or prerecorded voices” under the TCPA. So use the same consent standard you would apply to a prerecorded call. A natural, two-way AI conversation doesn't change that requirement.
  • Check Do Not Call lists before dialing.
    Scrub your contacts against the National Do Not Call Registry and your own internal do-not-call list. This helps prevent the AI from calling people who have asked not to receive telemarketing calls.
  • Call only during allowed hours.
    Schedule calls based on the recipient's local time, not your team's time zone. The Telemarketing Sales Rule generally limits telemarketing calls to between 8 a.m. and 9 p.m., and some states have stricter limits.
  • Honor opt-outs promptly.
    If someone asks your AI agent to stop calling, treat that as a revocation request and suppress future calls. Opt-outs can be made in any reasonable way, so don't force people to use one specific channel. It's also good practice to apply the opt-out across both voice and SMS.
  • Identify your business at the start of the call.
    Make it clear who is calling and provide a working callback number. If your AI agent also identifies itself as AI, keep that disclosure clear and easy to understand.
  • Check state-specific telemarketing rules.
    Federal TCPA rules are only part of the picture. States can impose additional requirements around calling hours, consent, disclosures, and telemarketing practices, so check the rules that apply where you're calling.
  • Verify consent for purchased or third-party lists.
    Don't assume a purchased contact list comes with valid consent for your AI agent. Before uploading it to your dialer, make sure you can trace who gave consent, when, where, and what they agreed to.
  • Monitor and audit your AI calls regularly.
    Compliance doesn't end when your AI agent goes live. Review calls regularly to ensure it follows approved rules, handles opt-outs correctly, identifies the business properly, and avoids unapproved claims. Keep clear records so you can quickly investigate and fix issues.
  • Provide a clear path to human support.
    People are 45% more likely to use an AI agent when there's a clear escalation path. Build that option into your call flow and route complaints, consent disputes, and complex opt-out requests to a human agent instead of relying entirely on AI.

In short

Think of AI calling compliance as six core disciplines: consent, identification, list scrubbing, calling hours, opt-outs, and record-keeping. State laws and the specific purpose of the call can add further requirements.

Why Do TCPA Rules Keep Changing?

TCPA guidance and state telemarketing laws continue to evolve, with some states adding requirements on top of federal rules. Treat this checklist as a starting point for your AI outbound calling program. Always check the current requirements for your state and industry, and consult qualified legal counsel when needed.

How to Build TCPA Compliance Into an AI Voice Calling Workflow

Adding AI to an existing calling workflow shouldn't mean starting your compliance process from scratch. The key is to make your existing rules part of the AI's workflow, so compliance doesn't depend on someone remembering to check each call.

  • Define the rules. Document which calls need consent, when the AI can call, and how opt-outs are handled.
  • Build them into the workflow. Use automated checks for consent, suppression lists, calling hours, and opt-outs before and during calls.
  • Monitor the AI. Review calls regularly to make sure the agent follows those rules and handles edge cases correctly.
  • Escalate when needed. Give the AI a clear path to a human for complaints, consent disputes, or situations it shouldn't handle alone.

Know the Rules Before You Dial

AI voice calling doesn't create a separate set of TCPA rules. The key is making sure your AI workflow follows the consent, calling-hour, Do Not Call, opt-out, and disclosure requirements that apply to your calls.

Treat the checklist above as a starting point, keep your processes up to date as regulations change, and consult qualified legal counsel for your specific use case.

Automate calls without losing control

Run outbound AI calls with the tools you need to manage consent, calling hours, opt-outs, and more.

Frequently asked questions

Consent, identification, suppression, timing and records: prior express written consent for marketing calls and texts, your business named on the call, DNC and suppression-list scrubbing, local-time calling hours, fast opt-outs.

The FCC has confirmed AI-generated voices count as an artificial voice under the TCPA, and its consent-revocation rule gives you ten business days to honor a revocation made by any reasonable method. Several states now cover texts too.

Five TCPA violations recur: calling or texting without prior express written consent; using an artificial or prerecorded voice, AI included, without it; contacting numbers on the Do Not Call Registry or your internal suppression list; calling outside permitted hours; and missing the opt-out deadline. The statute prices each the same way: $500 per call or text, up to $1,500 for a willful violation.

No federal rule sets an expiry date for TCPA consent: it stands until the person revokes it, and in practice it lasts as long as your records can evidence it. The FCC's one-to-one consent rule never took effect, and the FCC has since removed it.

Within ten business days, under the FCC's consent-revocation rule, however it arrives: a keypress on a call, a "stop" reply to your SMS opt-in flow, or a spoken request to your AI agent.

Yes, in the United States, if you follow the rules that already govern robocalls. The FCC's February 2024 ruling confirms AI voices fall under existing artificial-voice restrictions rather than banning them.

A growing number, including Texas, Oregon and Virginia, which all narrowed their telemarketing rules recently. State rules stack on top of the federal baseline rather than replacing it.

TCPA compliance means following the rules of the Telephone Consumer Protection Act when making certain calls or sending texts to consumers. This includes requirements around consent, Do Not Call lists, calling hours, caller identification, and opt-outs.