Summarize with AI
For many sales leaders, AI outbound calling arrives as an opportunity and a compliance question at the same time.
The opportunity is straightforward. AI voice agents contact leads faster, qualify prospects, book appointments, reactivate old opportunities and route warm conversations to human closers. For teams dealing with high lead volume, slow speed to lead and expensive SDR headcount, the business case holds up.
The compliance question is where most teams stall. Can you legally use AI to call prospects, what consent do you need, what happens when a lead asks you to stop, and what applies when state law is stricter than federal law. The answer in 2026 is not to avoid AI outbound calling. It is to stop treating compliance as a manual checklist and move the controls into the system that places the calls.
TL;DR
AI outbound calling is lawful when the campaign satisfies the TCPA, the FCC rules, the FTC Telemarketing Sales Rule, Do Not Call obligations and the state telemarketing law that applies to the person you are calling. In February 2024 the FCC confirmed that AI generated voices fall under the TCPA rules for artificial or prerecorded voice calls, so consumer telemarketing campaigns using an AI voice generally need prior express written consent. Statutory damages run from 500 dollars per violation up to 1,500 dollars for willful or knowing violations, and the FTC lists Telemarketing Sales Rule civil penalties of up to 53,088 dollars per violation. Consent revocation must be honored within a reasonable time not exceeding 10 business days, by any reasonable means the consumer chooses. No platform removes your legal exposure though, because the seller remains responsible for the campaign whatever the vendor contract says.
Key Takeaways
- AI voice calls sit inside the TCPA framework for artificial or prerecorded voice, so the consent standard is the same one that applies to prerecorded telemarketing.
- The FCC one to one consent rule was vacated by the Eleventh Circuit in January 2025, so it is not a current federal requirement, but seller specific consent is still the safest operational standard.
- Consent is evidence rather than a checkbox, and a record you cannot produce later is the same as no record.
- Do Not Call obligations do not relax because a machine is dialing, and the Telemarketing Sales Rule safe harbor expects a Registry version downloaded no more than 31 days before the call.
- Opt-outs have to be recognized by meaning rather than by matching exact keywords, because consumers may revoke by any reasonable means.
- Calling windows follow the recipient location, not your office, and several states are stricter than the federal 8 a.m. to 9 p.m. limit.
- Automation multiplies whatever your process gets wrong, which is the real reason controls belong before the dial rather than in a monthly review.
Table of contents
- What TCPA compliance means for an AI voice call
- The consent standard, and what the vacated rule changed
- Consent is evidence, so store it that way
- Do Not Call obligations when a machine is dialing
- Opt-outs have to be understood, not pattern matched
- Calling windows follow the recipient
- State telemarketing law sits on top of federal law
- Disclosing that the voice is AI
- Audit trails, and the difference between compliant and provable
- Managed and unmanaged AI calling compared
- Why the vendor handling compliance is not enough
- What getting it wrong actually costs
- TCPA compliance FAQ
- The bottom line
What TCPA compliance means for an AI voice call
TCPA compliance means the call you placed satisfies the consent, timing, identification and suppression rules that the Telephone Consumer Protection Act and its implementing FCC rules impose on that specific call. The Act was passed decades before neural text to speech, voice cloning and real time AI conversation existed, which is why teams assume it has a gap in it.
It does not. In February 2024 the FCC confirmed that AI generated voices fall under the existing TCPA rules for artificial or prerecorded voice calls. A company cannot escape the obligation by arguing that nothing was recorded because an AI responded live. For a consumer telemarketing call using an artificial or prerecorded voice, prior express written consent is the standard to work to.
The part that trips teams up is that the AI voice is not really the risk. The system around it is. Where did the lead come from, what did the person actually agree to, was the seller named in the consent language, was the number on the National Do Not Call Registry, had the person opted out before, is the call inside the recipient legal calling window, does the script make claims you can prove, and can you produce all of that six months from now. A campaign that cannot answer those questions is not ready to scale, whatever the technology stack looks like.
The consent standard, and what the vacated rule changed
The largest recent TCPA development was the FCC one to one consent rule, which would have required lead forms to obtain consent separately for each seller. It would have reshaped comparison sites, lead aggregators and every multi seller lead form.
That rule is not in force. In January 2025 the Eleventh Circuit vacated the FCC one to one consent and logically and topically related restrictions, holding that the agency had exceeded its statutory authority and departed from the ordinary meaning of prior express consent.
Two conclusions follow, and teams tend to draw only the convenient one. One to one consent is not a current federal requirement. Broad, bundled, unclear consent is still not safe. Seller specific consent remains the standard worth operating to, because it is the version you can defend when someone challenges the call.
What to ask about an aggregator lead
If a lead arrives from a third party, the questions are the same every time.
- Did the person clearly agree to receive calls.
- Was the seller identified clearly enough to be recognizable.
- Is the phone number connected to the consent record rather than sitting beside it.
- Was the consent language clear and conspicuous where it was displayed.
- Was the consent captured before the call rather than reconstructed after it.
- Can the record be produced if it is challenged.
- Does the consent support an artificial or AI generated voice call specifically.
A managed operation validates that before the campaign starts. It does not push a list into a dialer because the spreadsheet contains phone numbers.
Consent has enough detail to deserve separate treatment, and we cover what counts as valid permission in TCPA consent requirements for AI voice calls.
Consent is evidence, so store it that way
A useful consent record shows the name, the phone number, the timestamp, the form source or IP address where available, the exact consent language displayed, the seller identified, the type of communication authorized, and where the lead came from.
The phrase verified lead is not a record. A vendor telling you these are compliant leads is not a record. A CSV of names and numbers is definitely not a record. If a complaint arrives, you need to show why that specific number was called on that specific day.
This is why storage matters as much as capture. The consent record should connect to the call record, the campaign record, the CRM record and the suppression record, so that when a number is dialed the system already knows why it was eligible. Unmanaged tools tend to skip this, because letting a user upload and dial is easier to build than checking whether each lead qualifies for AI voice outreach. Friction before launch is the point rather than a flaw.
For the federal ruling that brought AI generated voices inside these rules, see our breakdown of the FTC AI calling ruling for outbound sales.
Do Not Call obligations when a machine is dialing
The National Do Not Call Registry remains the most consequential suppression layer in outbound sales. Under the FTC Telemarketing Sales Rule, sellers and telemarketers may not call consumers whose numbers appear on the Registry, subject to the stated exceptions, and violations carry civil penalties.
The safe harbor is specific about what a routine business practice has to include. Written procedures, personnel training, entity specific Do Not Call records, a process that prevents calls to numbers on your internal list or the Registry, and a Registry version downloaded no more than 31 days before the call is placed.
That is the floor rather than the target. When AI is dialing, a monthly scrub is not a control. Eligibility should be checked before the campaign runs, suppressed numbers should be blocked at dial time, internal Do Not Call records should update immediately, and an opted out number should never be recycled into a later campaign because someone re-imported an old list.
Before you dial
See the controls that run before a call
We will walk through consent validation, suppression and calling window logic on a live campaign rather than a slide. Thirty minutes, your own lead source, and you keep the notes.
30 minutes · screen shared · no obligation
Opt-outs have to be understood, not pattern matched
Keyword matching used to be adequate. If the caller said stop, remove me, or do not call, the number got flagged.
That is no longer sufficient. The FCC strengthened revocation rights by confirming that consumers may revoke consent through any reasonable means, and that callers must honor revocation and do not call requests within a reasonable time not exceeding 10 business days.
People do not revoke consent in keywords. They say things like the following.
- I am not interested, do not call again.
- Take me off whatever list this is.
- Please stop reaching out.
- Remove my number.
- Do not contact me anymore.
- These calls are getting annoying, I do not want them.
A brittle system misses most of that. The AI should detect the intent, suppress the number immediately, timestamp the request, store the transcript and update the CRM and suppression database in the same moment. When a prospect revokes during a call or a text exchange, the number should be suppressed across active voice and SMS campaigns. Broader internal suppression across other outreach channels is a reasonable house rule to adopt, but it is a Bigly practice rather than a TCPA requirement, and the two should not be confused.
Calling windows follow the recipient
Federal telemarketing rules restrict outbound telemarketing calls before 8 a.m. or after 9 p.m. in the recipient local time, and the Telemarketing Sales Rule treats calling outside permitted hours as an abusive practice.
That is one layer. State law may be tighter, with earlier evening cutoffs, Sunday and holiday restrictions, registration requirements, call frequency limits or industry specific conditions.
So a national campaign cannot run on the call center time zone. A team in New York dialing leads in California, Texas, Florida, Oregon, Maine or Rhode Island needs the system to know where the recipient is and which rule applies. Area code is an imperfect proxy and it is far better than ignoring geography. The platform should block the call when the recipient sits outside the permitted window, and record which timing rule it applied, because that record is what you produce later.
State telemarketing law sits on top of federal law
State telemarketing statutes, often called mini-TCPA laws, change frequently and several impose stricter requirements than federal law. Depending on the state that can mean registration, tighter consent standards, call frequency caps, narrower calling hours, extra recordkeeping, or a private right of action that makes litigation cheap to bring.
The honest framing is that federal compliance is necessary and not sufficient. A campaign is not automatically in violation because a state has a mini-TCPA law, and a single national default is not a defensible way to run a multi state campaign either. Controls should be applied from the recipient location and the campaign type, and reviewed when you enter a new state rather than annually.
Disclosing that the voice is AI
The FCC has confirmed AI generated voices fall inside the artificial or prerecorded voice framework, and has proposed additional rules that would require disclosure at the start of a call that AI generated technology is in use. That disclosure requirement is proposed rather than final, and it should be described that way until it is adopted.
Disclosing anyway is the better operational choice. An opening that names the company, states the purpose and acknowledges the automated nature of the call reduces confusion and reduces the chance the call is later characterized as deceptive. Something as plain as this works.
Hi, this is an automated assistant calling on behalf of [Company Name] about your recent inquiry. Is now a good time?
Whether you announce the AI is a separate decision from whether you were permitted to call at all, and we work through the wording in our guide to AI disclosure.
Audit trails, and the difference between compliant and provable
Following the rule is half the job. Proving you followed it is the half that decides how a complaint ends.
When a regulator, a plaintiff attorney or your own compliance reviewer asks why a number was called, nobody should be reconstructing the answer from dialer exports, lead vendor emails and CRM notes. A managed system keeps the campaign record intact, which means the consent source and timestamp, the lead source, the seller name, the number, the campaign, the script version, the call timestamp, the recipient location logic, the Do Not Call check, the internal suppression check, the opt-out status, the result, the transcript, the recording where recording is lawful, the disposition, the CRM update, the human handoff and the follow up action.
That record is also an operating advantage rather than pure overhead. It tells you which lead sources generate complaints, which scripts create confusion, and which prospects are actually ready for a human.
Managed and unmanaged AI calling compared
Unmanaged tools let your team upload contacts, configure a voice agent, run a campaign and read the results. That is genuinely useful, and it leaves every hard question with the user. Who checked consent, who scrubbed the Registry, who configured state calling windows, who reviewed the script for claims you cannot support, who watches opt-outs, who keeps the audit trail, and who stops a risky campaign before it launches.
| Compliance area | Unmanaged AI calling tool | Managed AI outbound calling |
|---|---|---|
| Consent review | Usually left to the user | Built into campaign intake and lead review |
| DNC suppression | Often manual or batch based | Enforced by the system before a campaign runs |
| Internal opt-outs | Depend on the user updating a list | Suppressed across active workflows |
| State calling windows | User configured, one national default | Applied from the recipient location |
| AI disclosure | Depends on the script the user wrote | Built into approved call flows |
| Audit trail | Fragmented across tools and exports | Campaign, call and CRM records in one place |
| Ongoing monitoring | Limited | Reviewed as campaigns change |
A managed service closes those gaps by putting the controls inside the workflow, so the campaign is reviewed, filtered, logged and monitored before it scales. It does not eliminate legal risk, and no honest provider claims otherwise. It makes compliance systematic instead of dependent on someone recalling the right rule at the right moment.
Why the vendor handling compliance is not enough
Buying AI calling software does not make your campaign compliant. Your company still needs valid consent, accurate lead data, defensible scripts, correct campaign settings, working suppression, a real opt-out process and awareness of the state law that applies. A vendor supports those controls. The obligation stays with you.
So the useful question in a sales conversation is not whether the platform is compliant. It is what the platform prevents before the call is placed, and what it can show you afterwards. A strong system blocks ineligible calls, documents eligible ones, captures opt-outs the moment they happen, and hands you a defensible record of what your campaign did.
What getting it wrong actually costs
TCPA exposure is dangerous because it scales per call. Statutory damages are 500 dollars per violation, and a court may raise that to 1,500 dollars for a willful or knowing violation. Multiply either figure by an automated campaign and the arithmetic gets serious quickly.
The Telemarketing Sales Rule adds separate civil penalty exposure, currently listed by the FTC at up to 53,088 dollars per violation.
That is the whole argument for moving controls before the dial. A small manual call center makes mistakes slowly, and a person notices. An AI calling system can repeat the same mistake thousands of times in an afternoon. If the lead source is bad, the script is risky, the opt-out logic is brittle or the suppression process is broken, automation does not cause the problem. It scales it.
The safest teams are not the ones placing the most calls. They are the ones who know who they may call, when, what they may say, and how to prove all three.
If you would rather see the failure modes than the rules, the same ground from the other direction is in the top TCPA compliance mistakes that get call centers sued.
Consent, revocation and suppression terms are defined alongside the rest of the vocabulary in the AI calling glossary.
TCPA compliance FAQ
Is AI outbound sales legal in 2026?
Yes, when the campaign follows the applicable TCPA, FCC, FTC, Do Not Call, consent, disclosure, opt-out, calling window and state telemarketing rules. Using AI is not itself the question. What matters is whether the campaign has documented consent, working suppression, correct call timing, scripts you can support and records you can produce when somebody asks why a particular number was dialed.
What is the biggest TCPA risk in AI sales dialing?
Volume applied to a broken control. Placing high volume AI voice calls without solid consent, suppression and opt-out handling means one flawed lead source or one silent failure in the suppression process produces thousands of violations rather than a handful. The risk is rarely the technology behaving unexpectedly. It is a known process weakness being executed faster than anyone reviews it.
What happened to the FCC one to one consent rule?
The Eleventh Circuit vacated it in January 2025, holding that the FCC had exceeded its statutory authority and departed from the ordinary meaning of prior express consent. It is not an active federal requirement today. Seller specific consent is still worth operating to, because it makes consent easier to prove and removes the lead source ambiguity that causes most disputes in the first place.
What does revocation by reasonable means actually mean?
Consumers may revoke consent by any method that reasonably communicates they want the calls or texts to stop, rather than by a specific keyword or channel you have chosen. Callers must honor revocation and do not call requests within a reasonable time, not exceeding 10 business days. In practice that means your system needs to catch the request wherever it arrives and act on it immediately.
Do Do Not Call rules apply if the lead filled in my form?
An established business relationship or express written consent can support calling a number listed on the Registry, within the limits and durations the rules set out. That is why the consent record and its date matter so much. Relying on a relationship you cannot document is the same as relying on nothing, and consent captured for one seller does not automatically extend to another.
What counts as a strong consent record for AI calling?
One that shows who consented, when, the number submitted, the exact language displayed, the seller identified, the form or source used, and the type of communication authorized. Just as important, it should be stored so that it connects to the campaign and the call history, because a consent record you cannot tie to the specific call it justified will not do much work for you later.
Does Bigly handle quiet hours and state calling windows?
Yes. Time zone and calling window controls are applied from the recipient location rather than defaulting to wherever your team sits, and the rule applied to each call is recorded. For national campaigns that is the only workable approach, because federal hours are the outer boundary and several states are tighter than the federal 8 a.m. to 9 p.m. window.
Does an AI voice agent have to say it is AI?
Not yet under federal rules. The FCC has proposed disclosure at the start of an AI voice call, and until that is finalized it should be treated as proposed rather than binding. Disclosing anyway is the stronger position, because it lowers confusion and deception risk, and because a rule you have already implemented costs nothing to comply with when it does arrive.
Why is managed AI calling safer than using a voice API?
An API hands your team capability. A managed service hands your team controls around that capability, including lead eligibility checks, Do Not Call and suppression enforcement, calling window logic, opt-out detection, transcript storage, CRM updates and audit trails. Both can place a call. Only one of them is designed to stop a call that should not be placed.
The bottom line
AI outbound calling is not in tension with compliance. Uncontrolled automation is. Treated as a dialing engine, AI multiplies whatever your process already gets wrong. Treated as a controlled revenue workflow, it lets a team move faster while depending less on anyone remembering the right rule at the right moment.
Bigly Sales helps outbound teams qualify leads, book appointments, route warm prospects to closers and keep the core calling controls inside the campaign workflow rather than beside it. For a high volume sales team that is not only speed. It is the ability to answer, months later, exactly why any given number was called.
Proof, not promises
Ask us what the system blocks
Bring the question a regulator would ask and we will show you where the answer is stored. If we cannot produce the record, you should not buy the platform.







