TCPA risk in voice AI turns on the campaign: who is called, why, which technology speaks or dials, what consent or exemption applies, and which controls preserve proof. A platform cannot make that campaign compliant. This guide shows production teams how to translate counsel-approved U.S. federal requirements into eligibility gates, suppression, release tests, and audit evidence. It is educational information, not legal advice; qualified counsel should review every campaign, jurisdiction, and industry overlay.
What the Telephone Consumer Protection Act means for voice AI
The Telephone Consumer Protection Act (TCPA) is a U.S. federal law governing specified calls made with an automatic telephone dialing system or an artificial or prerecorded voice. It also authorizes federal rules for telephone solicitations and Do Not Call (DNC) practices. The statute and the current FCC rules are the baseline for campaign analysis.
The Federal Communications Commission determined in 2024 that an AI-generated voice counts as an “artificial or prerecorded voice” under the TCPA. That means the artificial-voice restrictions can apply even when the dialing system is not an automatic telephone dialing system. It does not mean every AI-assisted call is prohibited. Purpose, destination, consent, exemptions, and other applicable laws still matter. (FCC 24-17; 47 U.S.C. § 227)
Marketing or advertising calls using an artificial or prerecorded voice generally require prior express written consent under the current federal rules, subject to the exact destination and a valid exception. Other consent standards or exemptions may apply to other calls. Your campaign policy must identify the rule that counsel approved for the actual call rather than reducing eligibility to “customer,” “lead,” or “existing business relationship.” (47 C.F.R. § 64.1200(a), (f))
State mini-TCPA and DNC laws, call-recording consent, privacy law, consumer-protection rules, carrier requirements, and sector rules can create separate or stricter duties under the statute’s state-law savings clause. The Federal Trade Commission’s Telemarketing Sales Rule is a separate federal regime that may apply to a telemarketing campaign. TCPA review does not replace those analyses.
Current, proposed, and vacated rules
Voice AI teams need a versioned policy because rulemaking and litigation can leave outdated requirements circulating as current advice.
| Status | Rule position | Engineering consequence |
|---|---|---|
| Current | The FCC’s position in FCC 24-17 is that AI-generated voices fall within the TCPA’s artificial or prerecorded voice restriction. Courts independently interpret the statute in private cases. The current FCC rule contains the operative consent, revocation, identification, calling-time, and DNC provisions. (FCC 24-17; McLaughlin; 47 C.F.R. § 64.1200) | Classify the AI voice and the call facts before creating an outbound call. Build from the current rule text and counsel’s approved interpretation. |
| Proposed only | The FCC proposed an AI-generated-call definition and AI-specific disclosure requirements in 2024. The proposal remains pending, so federal TCPA rules do not currently impose a stand-alone “this is AI” disclosure. Existing identity and opt-out rules may still apply. (FCC proposal; 2026 rulemaking agenda) | Do not encode a proposal as law. Track it as a policy watch item, and implement any separate disclosure that counsel requires under current federal, state, contractual, or sector rules. |
| Vacated | A court vacated the FCC’s 2023 revision that would have required consent to one seller at a time and required the called content to be logically and topically associated with the consent interaction. The FCC removed the vacated language in 2025. (Eleventh Circuit opinion; FCC conforming rule) | Do not represent the vacated test as the current federal TCPA rule. Still preserve the exact seller, scope, disclosure, and provenance that support the consent your counsel relies on. |
Classify the campaign before building or dialing
A production system should consume a counsel-approved campaign policy. It should not invent one. Give each campaign a policy ID, version, owner, approval date, and defined review triggers. Then make call creation depend on deterministic inputs tied to that version.
| Campaign input | Question for counsel and the owner | System control and evidence | Release blocker |
|---|---|---|---|
| Purpose | Is the call advertising, telemarketing, informational, servicing, or mixed? | Approved purpose code, script or prompt version, allowed outcomes | Mixed or undefined purpose |
| Audience and destination | Who is called, what type of number is used, and how was it sourced? | Account and number reference, source, destination classification, jurisdiction | Unknown source or destination type |
| Technology | Does the flow use an AI-generated or prerecorded voice, an automatic telephone dialing system, transfers, or fallback messages? | Dialer and voice configuration, fallback path, runtime version | Unreviewed technology or fallback |
| Consent or exemption | What consent is required, what does it cover, or which narrow exemption applies? | Consent record or exemption code linked to evidence and limits | Missing, ambiguous, expired, or out-of-scope basis |
| DNC and revocation | Which federal, state, seller-specific, and campaign suppressions apply? | Current suppression result with list version and reason code | Lookup failure, stale data, or active suppression |
| Jurisdiction and overlays | Which location, recording, privacy, TSR, sector, and contract rules apply? | Jurisdiction decision, approved disclosures, policy references | Unresolved rule or inconsistent location data |
| Accountability | Who approved the policy, owns the data, and can pause calls? | Named legal, business, engineering, and incident owners | No current approval or pause owner |
The gate should return an explicit allow, block, or review result plus a reason code. A missing field is not consent. A model inference is not consent. review should prevent automatic dialing until the ambiguity is resolved.
Design consent as evidence, not a checkbox
The current FCC definition of prior express written consent requires a signed written agreement, allows electronic and digital signatures, and specifies clear authorization and disclosures. The exact requirement depends on the call. Preserve the agreement and the surrounding evidence rather than a single Boolean value. (47 C.F.R. § 64.1200(f)(9))
A useful consent record includes:
- the person or account reference and the exact telephone number;
- the seller or responsible brand, purpose, and campaign scope;
- the complete consent language and disclosure version shown;
- the collection source, date, time, and signature method;
- the source record or immutable evidence location;
- any limits, expiration, or category rules specified by counsel;
- the current revocation and seller-specific DNC state; and
- the policy version and owner that interpreted the record.
Use append-only history or equivalent change evidence. Keep the source-system identifier so an incident reviewer can reproduce what the eligibility gate saw. If a lead is transferred between systems, preserve provenance and scope through the transfer. Never ask the language model to infer consent from a transcript, customer relationship management note, or relationship label.
Revocation needs the same evidence discipline. Under the current FCC rule, a person may revoke consent by any reasonable method that clearly expresses a desire to stop covered communications, and a caller cannot force one exclusive channel. The rule requires covered revocations and company-specific DNC requests to be honored as soon as practicable and no later than 10 business days. (47 C.F.R. § 64.1200(a)(10)–(12), (d)(3))
Treat 10 business days as an outside legal limit, not an operating target. A clear oral stop request should enter a deterministic suppression workflow during the call. If the write cannot be confirmed, stop the automated interaction, place the record in a monitored exception queue, and prevent another call attempt.
Put DNC, identity, time, and opt-out controls in the call path
A list scrub performed when leads are imported is insufficient. Eligibility can change after import, so recheck every attempt against the current policy and data.
Before the call
- Load the approved campaign and policy version.
- Resolve the called party’s location and applicable time zone using the method counsel approved.
- Check consent, exemption conditions, revocation, company-specific DNC, National DNC, and other suppression sources.
- Confirm seller identity, calling number, script or prompt, voice, routing, and approved fallback.
- Record the allow or block decision, reason code, source versions, and timestamp before submitting the call.
The FCC’s federal calling window prohibits residential telephone solicitations before 8 a.m. or after 9 p.m. at the called party’s location. That rule is not a universal time window for every type of call, and state rules may be broader. The National DNC safe-harbor conditions include written procedures, training, records, an entity-specific list, and a Registry version obtained no more than 31 days before the call. Registry access alone does not establish compliance. (47 C.F.R. § 64.1200(c))
During the call
The runtime should execute the approved requirements without giving the model authority to omit or rewrite them. Depending on the call, these can include:
- identifying the responsible business by its registered name at the beginning of an artificial or prerecorded voice message;
- providing a working number for the responsible party during or after the message;
- transmitting caller-ID information under the applicable rule;
- exposing the required automated opt-out path for covered calls; and
- recognizing a clear spoken stop request and passing it to a deterministic update.
The FCC’s artificial or prerecorded voice rules contain the identity and callback-number requirements. Covered prerecorded telemarketing calls and certain exempt residential calls also need an automated interactive opt-out mechanism within two seconds after the required identification information, with a toll-free callback mechanism for voicemail. Counsel should map those requirements to each AI voice and fallback path. (47 C.F.R. § 64.1200(b))
Natural-language detection can identify a likely opt-out. It should not be the final record. Confirm the structured suppression write, associate it with the called number and responsible seller, and prevent the conversation from continuing as a sales interaction. Test phrases beyond one keyword, including “don’t call me again,” interruptions, corrections, and requests made immediately before a hang-up.
After the call
Reconcile runtime events with the systems that own consent and suppression. Capture the call outcome, disclosure events, opt-out or revocation request, transfer outcome, tool results, failed writes, retry status, complaint signal, and reviewer action.
A failed post-call webhook can be a compliance-relevant incident even when the conversation sounded correct. Keep it visible until a named owner confirms the system of record and suppression state. Pause the campaign when the team cannot prove that a stop request propagated to every connected dialer or vendor.
Treat campaign changes as compliance-relevant releases
Counsel approves a set of facts. A production change can alter those facts without changing the campaign name.
Send a campaign back through policy and release review when you change:
- the seller, purpose, offer, disclosure, script, prompt, or knowledge source;
- the audience, lead source, consent rule, or exemption;
- the voice, model, fallback recording, language, or conversation flow;
- the calling number, caller-ID configuration, carrier, routing, or transfer behavior;
- the suppression connector, DNC source, time-zone logic, pacing, or retry behavior; or
- a vendor, data flow, evidence store, access rule, or retention policy.
Each release should carry the policy version, approved disclosures, implementation version, and test evidence. At minimum, test allowed, blocked, revoked, DNC, wrong-time, opt-out, dependency-failure, and transfer scenarios. Verify the final system state, not just the transcript. Start with a bounded call volume, name the person who can pause it, define stop criteria, and sample the resulting records before expanding.
Prompt review alone is not enough. Test the telephony path, fallback messages, webhook failures, duplicate events, delayed suppression, and the behavior of every vendor that can initiate another attempt.
Keep an auditable campaign evidence pack
An evidence pack should let an authorized reviewer reconstruct why a specific call was allowed, what the recipient experienced, and how the team handled any exception.
Keep these records linked by stable identifiers:
- campaign policy, approvals, responsible seller, and owner;
- consent or exemption provenance and the exact disclosure version;
- pre-dial decision, reason code, suppression sources, and list versions;
- called and calling numbers, timestamps, and local-time evaluation;
- runtime, prompt, voice, flow, and integration versions;
- identity, disclosure, opt-out, and transfer events;
- tool or webhook requests, responses, retries, and failures;
- complaint, incident, reviewer, and corrective-action records; and
- the applicable retention and access-control policy.
Do not assume that a transcript, recording, or platform dashboard is legally sufficient by itself. Separate the factual control log from call content, which may carry recording-consent, privacy, security, and retention obligations. Apply data minimization and role-appropriate access. Our guide to voice AI data-security controls covers that adjacent system design.
Retention must follow the rules that actually apply. The FCC’s company-specific DNC rule requires those requests to be retained for five years. It does not create a universal five-year federal TCPA retention period for every consent artifact. The separate TSR requires five-year retention of specified records for covered campaigns, including certain consent, DNC, call, script, Registry-access, and service-provider records. (47 C.F.R. § 64.1200(d); 16 C.F.R. § 310.5)
Assign responsibility across counsel, the campaign owner, and vendors
Contracts and technical capabilities should make responsibility explicit. They do not make the voice AI platform the legal decision-maker.
| Owner | Operational responsibility |
|---|---|
| Counsel or compliance | Interprets the campaign facts, approves the policy and disclosures, identifies overlays, and defines review triggers |
| Campaign operator or seller | Owns purpose, audience, lead sourcing, vendor instructions, approval, and pause authority |
| Product and engineering | Implements deterministic gates, failure behavior, versioning, tests, observability, and evidence correlation |
| Consent and DNC data owner | Supplies governed records, source versions, suppression updates, provenance, and reconciliation |
| Telephony or carrier provider | Supplies contracted calling and caller-ID behavior plus the evidence the operator requires |
| Voice AI platform | Executes the configured conversation and integrations within its verified product contract; it does not decide the legal basis for the call |
| Human reviewer or incident owner | Reviews exceptions and complaints, confirms remediation, and decides when restart conditions are met |
If a vendor maintains a company-specific DNC list, the person or entity on whose behalf the call is made remains responsible for failures to honor the request. Under the TSR, a written agreement can allocate specified recordkeeping, but the rule preserves responsibility and access requirements. Design vendor handoffs so the seller can retrieve evidence and propagate a stop request without delay. (47 C.F.R. § 64.1200(d); 16 C.F.R. § 310.5(e))
Build a bounded production pilot
Start only after counsel and the campaign owner approve a narrow workflow. A useful first production boundary has:
- one permitted audience and one approved purpose;
- a low daily attempt limit;
- a per-attempt eligibility gate;
- a tested oral opt-out and revocation path;
- human escalation for ambiguous states;
- daily evidence and exception review; and
- a named owner with authority to pause immediately.
With Dasha, keep legal eligibility in your application. After your gate returns an explicit allow result, the application can schedule an outbound call through the outbound call API and attach campaign or record identifiers as call data. Tools and webhooks can connect approved external systems. Teams can exercise scenarios through browser and phone testing and examine completed-call transcripts, tool executions, and timeline events in Call Inspector.
Those capabilities do not decide consent, supply a DNC source, apply your legal time window, propagate a revocation by themselves, or certify compliance. Your team owns the policy, data, integrations, tests, evidence, and incident process.
For the wider launch workflow, use our compliance-first cold-calling pilot after you define the TCPA controls. If you already have a counsel-reviewed campaign design, evaluate Dasha as your managed production voice layer against the gates and failure paths above.
Frequently asked questions
Does an AI-generated voice change the TCPA analysis?
Yes. The FCC treats an AI-generated voice as an artificial or prerecorded voice, so that restriction must be analyzed independently of whether the dialer is an automatic telephone dialing system. The ruling is not a blanket ban. Consent, purpose, destination, exemptions, and other laws remain relevant. (FCC 24-17)
Does using a voice AI platform make a campaign TCPA compliant?
No. The campaign owner still needs a counsel-approved legal basis, governed consent and suppression data, correct integrations, validated disclosures and opt-outs, evidence records, and incident ownership. A platform can execute configured behavior and expose operational evidence, but it cannot determine that a campaign is lawful.
Is a DNC check enough?
No. National and company-specific DNC controls are one part of the analysis. Artificial or prerecorded voice consent, purpose, destination, identification, opt-out, timing, exemptions, state law, and the TSR may create separate requirements. A Registry check does not replace those controls. (47 C.F.R. § 64.1200)
When should a team pause a voice AI campaign?
Pause when eligibility evidence is missing or ambiguous, a suppression lookup or write fails, a stop request cannot be confirmed across systems, an unapproved change reaches production, required disclosures or opt-outs fail, or a jurisdiction or policy question remains unresolved. Resume only after the named owner records the correction, validates the affected path, and confirms restart conditions.
