Summarize with AI
TCPA consent is the documented permission a business must hold before it places certain regulated calls or texts, including consumer telemarketing calls that use an artificial, prerecorded, or AI-generated voice. It is not a general goodwill idea about being polite before you dial. It is a record you either have or do not have, tied to a specific person, a specific phone number, a specific seller, and a specific type of call.
That distinction matters more once AI voice agents enter the dial queue. A human rep who calls the wrong record makes one mistake. An AI calling platform that runs an unvetted list makes the same mistake several thousand times in an afternoon.
This guide explains what TCPA consent means for AI voice campaigns, what a defensible consent record contains, what happened to the FCC one-to-one consent rule, and how to review leads before you dial. None of it is legal advice. Confirm your own position with counsel before you launch a campaign.
TL;DR
For consumer telemarketing calls placed with an artificial, prerecorded, or AI-generated voice, the operative federal standard is prior express written consent, and the record must name the seller, name the authorized phone number, describe the calling technology, and state that consent is not a condition of purchase. The FCC one-to-one consent rule was vacated by the Eleventh Circuit in January 2025 and never took effect, so treat seller-specific consent as internal policy rather than as current federal law.
Revocation is the harder operating problem. Consumers may revoke through any reasonable method, and requests must be honored within a reasonable time not to exceed 10 business days, which means opt-outs have to be system events rather than call notes. If your leads come from broad partner forms you cannot inspect, no AI calling platform will make that list safe, and you should fix the source before you buy software.
Key takeaways
- TCPA consent is campaign-specific, so a contact sitting in your CRM is not automatically callable with AI voice.
- Every TCPA consent record has to be retrievable by phone number, not buried in CRM notes.
- The FCC has treated AI-generated voices as falling within the artificial or prerecorded voice rules.
- Prior express written consent has six components, and a record missing any one of them is weak in a dispute.
- The one-to-one consent rule was vacated in January 2025 and is not active federal law, but seller-specific consent is still the safer internal standard.
- Purchased leads carry the most risk because the buyer never controlled the original form.
- Revocation must propagate to every active campaign, not just the one that took the call.
- No platform removes compliance risk, and no vendor warranty replaces your own counsel review.
Table of contents
- What TCPA consent is
- Why TCPA consent is different for AI voice calls
- What prior express written consent requires
- TCPA consent levels compared
- What makes a consent form strong
- What makes TCPA consent invalid or risky
- How lead buyers should handle purchased leads
- What happened to the FCC one-to-one consent rule
- Consent documentation and TrustedForm
- How to handle revocation
- How long to retain TCPA consent records
- State rules that go beyond federal requirements
- How to build a compliant consent capture process
- The 12-point pre-dial review
- TCPA consent mistakes to avoid
- How Bigly Sales supports consent-aware AI calling
- TCPA consent FAQ
- The bottom line
What TCPA consent is
TCPA consent is the permission a caller must obtain, and be able to prove, before making a call or sending a text that the Telephone Consumer Protection Act regulates. The statute sits at 47 U.S.C. 227, and the statutory text on govinfo.gov is the primary source worth reading before you rely on any summary, including this one.
Most sales teams understand the basic principle. Get permission before calling. The requirement is narrower than that. A prospect being in your CRM does not mean you can call them with AI. A lead vendor saying the leads are compliant does not mean your company holds the right consent. A checkbox buried inside generic terms does not authorize automated or AI voice telemarketing. The consent has to match the campaign you are actually running.
To know whether it matches, a business needs answers to the following:
- Who gave consent, and when
- Which phone number they authorized
- Which seller was authorized to call
- What type of calls were authorized
- Whether the call is telemarketing, informational, or service-related
- Whether the call uses AI-generated, artificial, prerecorded, or automated voice
- Whether consent was written, electronic, verbal, or implied
- Whether the consumer has since revoked
- Whether state rules add requirements on top
- Whether the record can be produced later if challenged
If your team cannot answer those ten questions for a given record, you do not have a documented TCPA consent position for that record. You have a phone number.
Why TCPA consent is different for AI voice calls
AI voice calls can trigger the artificial or prerecorded voice rules, which means many consumer telemarketing campaigns need prior express written consent before the first dial.
An AI voice call is not the same as a live manual call from a human rep. The voice is dynamic. It responds naturally. It does not play a fixed recording. For TCPA purposes, that does not remove the issue. The FCC has stated that technologies generating human-sounding voices fall inside the artificial or prerecorded voice framework. For covered consumer telemarketing, that usually pushes the campaign to the written consent standard.
That does not mean every AI voice call is treated the same way. The analysis can shift based on:
- Whether the call is telemarketing or purely informational
- Whether the number is wireless or residential
- Whether a recognized exemption applies
- Whether there is an emergency purpose
- Whether the recipient is a consumer or a business
- Whether the call was requested by the recipient
- Whether state law sets a different standard
- Whether the script contains marketing content
Where the campaign is consumer telemarketing and the voice is synthetic, the conservative position is simple. Do not dial until someone has read the TCPA consent record. Speed is the reason teams buy AI calling, so that review has to happen at intake rather than at dial time.
What prior express written consent requires
Prior express written consent is a written or electronic agreement in which a consumer clearly authorizes a named seller to deliver telemarketing calls, using the relevant calling technology, to a phone number the consumer provided.
It is the highest TCPA consent standard most outbound teams encounter, and it has six parts. A record that satisfies five of them is not a record that satisfies the standard.
A written or electronic agreement
The agreement can be captured electronically. A web form, checkbox, or clickwrap flow can support written consent when the process meets applicable electronic signature standards and the business can retrieve what the consumer agreed to.
Clear authorization
Vague language is the weak point. A form saying only that the person agrees to be contacted may not carry an AI voice telemarketing campaign. It should say the person agrees to receive telemarketing calls using automated, artificial, prerecorded, or AI-generated voice technology where applicable.
The seller identity
This is where lead buyers get into trouble. If the form names only the lead generator or comparison site, the buyer may not be clearly covered. Seller-specific consent is the safer standard. The consumer should be able to tell which company is being authorized.
The authorized phone number
Consent is not a general right to reach a person on any number connected to them. If the consumer submitted one number, call that number. A second number found through appending or skip tracing is a separate question.
Not a condition of purchase
The disclosure has to make clear that agreeing to receive telemarketing calls is not required in order to buy anything. A consumer forced into consent to complete a purchase does not produce a valid record.
A retrievable record
Consent you cannot produce is not much of a defense. The record should show the form, the language displayed, the timestamp, the number, the seller named, the source, and any later revocation, and it should be searchable by phone number.
TCPA consent levels compared
Teams often talk about consent as a single yes or no. In practice there are several levels, and they support different campaigns. The table below is a planning aid, not a legal opinion, and the right classification for your campaign is a question for counsel.
| Consent level | Typical basis | Record must show | Fit for AI voice telemarketing |
|---|---|---|---|
| Prior express written consent | Signed or electronic opt-in form | Seller, number, technology, non-condition disclosure, timestamp | Yes, this is the standard covered campaigns are held to |
| Prior express consent | Consumer gave the number for a specific purpose | How and when the number was provided | Generally non-telemarketing only, such as transactional calls |
| Established business relationship | Prior purchase or inquiry | Transaction date and scope | Does not substitute for written consent on covered telemarketing |
| Broad partner consent | Form naming partners or providers generally | Partner list shown at capture | Weak, review with counsel before dialing |
| No documented consent | Purchased list, appended number, scraped data | Nothing retrievable | No, suppress and do not dial |
The bottom row is the one that causes most of the damage. Lists arrive as spreadsheets, spreadsheets look identical to each other, and nothing in a CSV tells you which rows have a certificate behind them.
What makes a consent form strong
A strong form is clear, specific, visible, seller-identifying, technology-aware, and tied to a proof record you can retrieve later.
A strong form does not hide the call authorization inside a wall of legal text. It places the language near the submit button. It identifies the seller. It explains the type of communication and the technology used. It states that consent is not required for purchase. Illustrative language looks something like this:
“By checking this box, I agree to receive telemarketing calls and messages from [Company Name] at the phone number I provide, including calls using automated technology, artificial or prerecorded voice, or AI-generated voice where applicable. I understand that my consent is not required to purchase goods or services.”
That example is illustrative only. The exact wording should be reviewed by counsel against your campaign, industry, state footprint, lead source, and customer journey. The FTC guidance on the Telemarketing Sales Rule is a useful companion read, since the TSR carries its own disclosure and record obligations that sit alongside the TCPA.
A strong form also preserves proof. The business should be able to show the page where consent was captured, the exact language displayed, the timestamp, the submission data, the number submitted, the seller named, the campaign source, the certificate record, and any later revocation.
What makes TCPA consent invalid or risky
TCPA consent becomes risky when it is vague, hidden, outdated, borrowed from another seller, attached to the wrong number, or already revoked. Most failures here are operational rather than legal. They come from old forms, purchased lists, weak vendor controls, and unclear suppression workflows.
Consent buried in generic terms
A general agreement to terms of service is not a clear authorization to receive AI voice telemarketing. The language has to be clear and conspicuous. If a reasonable consumer would not understand that they agreed to these calls, the position is weak.
Broad partner language
Lead forms often say consumers may hear from partners, providers, or trusted companies. Even with the one-to-one rule vacated, a lead buyer still needs a defensible argument that the consumer knew about calls from this seller.
Consent captured for a different company
A consumer who agreed to hear from a comparison site did not necessarily agree to AI voice calls from every company that later bought the lead. Review the language, the named seller, the vendor contract, and the certificate before dialing.
Outdated language
Forms written before AI voice agents existed often say only that the consumer may receive phone calls. That wording may not carry a 2026 campaign, and reusing it because it is already deployed is a common and avoidable mistake.
The wrong number
If a record holds several numbers, confirm which one was submitted with the consent. Calling a different number creates exposure, particularly where that number has been reassigned.
Already revoked
Consent can be withdrawn, and calls placed after a withdrawal create fresh exposure. A consumer does not need precise legal wording for it to count.
How lead buyers should handle purchased leads
Do not assume purchased leads are callable because the vendor says consent exists. Verify that the record supports calls from your company, using your calling method, to that number.
Purchased leads concentrate the risk because the buyer never controlled the original form. Before those records reach a dial queue, ask:
- What page captured the lead, and what did it show
- What consent language did the consumer actually see
- Was your company named, or only a category
- Did the language cover automated, artificial, prerecorded, or AI voice calls
- Was consent optional rather than required to submit
- Did the consumer type the phone number themselves
- Is there a TrustedForm certificate or equivalent proof
- Was the lead sold to multiple buyers
- How old was the lead at delivery
- Has the consumer revoked since
- Does the vendor contract require consent documentation
- Who indemnifies whom if the consent fails
The safest process holds purchased leads out of the queue until consent documentation is validated. A high-volume platform should never dial every uploaded row by default. If the record is missing, incomplete, stale, or unclear, suppress it or route it to review.
Consent-aware calling
See how leads get screened before dialing
We will walk your team through intake validation, suppression, and revocation tracking on a real campaign setup. The call takes about 30 minutes.
What happened to the FCC one-to-one consent rule
The FCC one-to-one consent rule was vacated by the Eleventh Circuit in January 2025 and never took effect, so it should not be described as active federal law in 2026.
The rule would have required telemarketing consent to be given to one identified seller at a time, and would have required calls to be logically and topically related to the interaction that produced the consent. It was expected to reshape lead generation. The Eleventh Circuit vacated it on January 24, 2025, before the compliance date arrived. Plenty of vendor pages and blog posts still describe it as binding, sometimes with a 2025 or 2026 effective date. Those pages are wrong.
Two things follow. First, prior express written consent under the TCPA remains the operative standard for covered telemarketing calls, and that standard did not change when the one-to-one rule fell. Second, seller-specific consent is still worth adopting as internal policy. The underlying evidentiary problem never went away, because you still have to show that the consumer knew your company would be calling. A record naming your company is easier to defend than a record naming a category.
The genuinely effective 2026 item is different. The cross-channel revocation requirement means a consumer who revokes through one channel has revoked for related calls and texts, and your systems need to treat it that way. That is the date-bound obligation worth putting on the roadmap. Confirm the current status of both items with counsel before you rely on this summary, since litigation and rulemaking both keep moving.
Practically, the recommendation is unchanged. Name the seller wherever possible. Avoid vague partner language. Store the proof. Review vendor forms yourself. Get counsel involved before a lead buying program scales.
Consent documentation and TrustedForm
TrustedForm and similar tools create a third-party record of what the consumer saw, when they submitted, and what language was on the page at that moment.
Documentation matters because disputes turn on evidence. It is not enough to say the consumer opted in. The question is whether you can show it. A documentation record may capture the timestamp, the page URL, the consent language, the number submitted, the user interaction, the submission data, a replay or snapshot of the form, the certificate URL, and the lead source.
That record is valuable because it is created at the point of capture rather than reconstructed afterward. It does not guarantee the consent is valid. The language may still be weak. The wrong seller may be named. The consumer may have revoked later. Without it, you are arguing from CRM notes, and CRM notes are not proof. Our approach to data handling and security covers how those records are stored.
How to handle revocation
Revocation should be captured through any reasonable method, honored quickly, logged permanently, and applied across every active campaign.
Consumers can withdraw consent, and the FCC has clarified that they may do so through any reasonable method that clearly expresses a wish to stop receiving calls or texts. Requests must be honored within a reasonable time not to exceed 10 business days. For high-volume AI calling, suppress immediately rather than working to the outer limit of that window.
The AI should recognize common revocation phrasing, including stop calling me, take me off your list, remove me, do not contact me again, I did not ask for this, do not call this number, I opt out, and unsubscribe.
The system should then:
- End or redirect the conversation appropriately
- Mark the record as opted out
- Add the number to internal suppression
- Stop future outreach from all active campaigns
- Push the update into the CRM
- Retain the revocation record with its timestamp
- Make that record available for audit or complaint response
Manual revocation handling breaks at scale. If a person has to remember to update three systems, one of them will be missed. Opt-outs need to be system events, not notes.
How long to retain TCPA consent records
Retain consent records at least as long as you could plausibly need to defend a claim, and set the policy against federal limitations periods, state law, contracts, and your own compliance rules.
The federal TCPA statute of limitations is four years, which is a reasonable minimum planning reference for many teams. It is not a universal answer. Some states, contracts, industries, and internal policies call for longer. Your counsel should set the number.
A workable retention policy covers the consent certificate or proof record, the form snapshot or replay, the consent language, the lead source, the timestamp, the authorized phone number, the seller named, the campaign source, call records, transcripts, recordings where permitted, dispositions, opt-out history, revocation timestamps, suppression status, and complaint history.
The record set should be searchable by phone number. When a complaint arrives, nobody should be spending three days reconstructing a lead path from exports.
State rules that go beyond federal requirements
Federal rules are the starting point, not the whole obligation. States add their own requirements for telemarketing, robocalls, texts, lead generation, and consumer privacy.
Common additions include stricter calling windows, state telemarketing registration, state do-not-call lists, extra consent language requirements, privacy disclosures, and different damages frameworks. Financial, insurance, healthcare, and home services campaigns face the most layering.
This matters most for national campaigns. A team dialing Florida, California, Texas, and New York is working against several rule sets at once. Account for destination state, recipient location, and campaign type. Do not build one national default and assume it covers everything.
How to build a compliant consent capture process
A working process starts before the lead enters the dial queue and runs through intake, validation, calling, revocation, documentation, and retention. It has five components.
Component 1. Clear consent language
Every lead form should make the authorization obvious. The consumer should understand who may call, why, what technology may be used, and that consent is optional. Do not reuse pre-AI language for AI campaigns.
Component 2. Consent documentation
Every submission should produce a record of what the consumer saw. Store the proof with the contact and make it retrievable by phone number rather than by lead ID alone.
Component 3. Intake validation
Validate leads before they reach the queue. If the record lacks proof, hold it. If it does not support the calling method, suppress it. This is the step most teams skip, and it is the cheapest one to add.
Component 4. Revocation tracking
Capture opt-out language during the call, update the contact record, suppress the number, and block future campaigns unless a new and reviewed TCPA consent record exists.
Component 5. Record retention
Keep the TCPA consent record, form language, lead source, timestamp, number, seller identity, call log, transcript, opt-out history, and suppression status. If it cannot be produced on request, the workflow is incomplete.
The 12-point pre-dial review
Before an AI voice campaign starts dialing, walk the list through these twelve checks. They are the practical translation of everything above.
- Call purpose. Telemarketing, informational, service, or reactivation
- Calling technology. AI-generated, artificial, prerecorded, or human voice
- Recipient type. Wireless, residential, business, or unknown
- Consent level required. Written, express, or another basis
- Seller identity. Does the record cover the company causing the call
- Phone number. Is consent tied to the exact number dialed
- Documentation. Can you retrieve form, language, timestamp, proof
- DNC status. Scrubbed against required sources in the applicable window
- Internal suppression. Has this person opted out of this seller before
- State law. Do state consent, window, or disclosure rules apply
- Script approval. Does the AI opening identify the caller
- Revocation workflow. Will opt-outs reach every active campaign
Where an answer is unclear, hold the record. That is cheaper than dialing and correcting later. For definitions of the terms in this list, our AI calling glossary covers the vocabulary your vendor calls will use.
TCPA consent mistakes to avoid
The recurring failures are not exotic. They are the same dozen shortcuts, made under volume pressure.
- Dialing purchased leads without reviewing the consent chain
- Relying on broad partner language without counsel review
- Treating the vacated one-to-one rule as active federal law
- Dropping seller-specific consent because that rule was vacated
- Reusing forms that never mention AI, artificial, or prerecorded calls
- Calling numbers other than the one the consumer submitted
- Working old CRM records without checking revocation history
- Failing to retain the proof record
- Leaving opt-outs in call notes instead of suppression systems
- Treating DNC as a one-time import
- Assuming a platform guarantees compliance
- Assuming a vendor warranty replaces your own review
How Bigly Sales supports consent-aware AI calling
Bigly Sales supports consent-aware AI calling by validating documentation at intake, flagging incomplete records, tracking revocations, suppressing opted-out numbers, and retaining call-level records that can be produced later.
For TCPA consent workflows specifically, the platform handles lead-source review, certificate handling where available, intake checks, holding incomplete records, DNC and internal suppression, calling-window logic by destination state, AI opt-out detection during the call, revocation tracking, CRM-ready records, transcripts, and disposition tracking. Teams comparing platforms on these controls can start with our overview of TCPA compliant AI calling platforms.
Here is the honest limit. Bigly does not remove compliance risk, and no platform can. Your exposure still depends on lead source, consent language, campaign purpose, number type, state law, script content, and how your team configures the system. If your leads come from partner forms you have never seen, software will not fix that. Fix the source first. What the platform does is move TCPA consent review out of a manual checklist and into the calling workflow, so nobody dials a bad record because it was in the spreadsheet.
Bigly is also not a dialer or a CRM, and it is not sold as one. It sits alongside those systems as a managed calling layer. If what you need is a cheaper predictive dialer, this is a different approach and probably the wrong fit.
Watch
Compliance does not have to slow you down
The common assumption is that consent rules cap your volume. What they really cap is undocumented volume.
TCPA consent FAQ
What is TCPA consent?
TCPA consent is the documented permission a business must hold before placing certain regulated calls or texts under the Telephone Consumer Protection Act. For consumer telemarketing calls using an artificial, prerecorded, or AI-generated voice, that generally means prior express written consent. The record should identify the seller, the authorized phone number, the type of calls, and the calling technology, and should state that consent is not required to make a purchase.
Do AI voice calls require prior express written consent?
For covered consumer telemarketing calls, generally yes. The FCC has treated AI-generated voices as falling within the artificial or prerecorded voice rules, which pushes those campaigns to the written consent standard. Informational, transactional, and service calls may sit under a different standard, and exemptions can apply. Classify each campaign before you dial rather than applying one policy to every list, and confirm the classification with counsel.
Is the FCC one-to-one consent rule in effect?
No. The Eleventh Circuit vacated the FCC one-to-one consent rule in January 2025 and it never took effect. Prior express written consent under the TCPA remains the operative federal standard. Many vendor pages still describe the one-to-one rule as binding law, sometimes with a 2025 or 2026 date attached. Treat those pages as out of date, and treat seller-specific consent as internal policy worth keeping rather than as a current requirement.
How long can a consumer take to revoke consent?
A consumer can revoke at any time, through any reasonable method that clearly expresses a wish to stop receiving calls or texts. There is no required magic wording. The business side has the deadline, since revocation requests must be honored within a reasonable time not to exceed 10 business days. High-volume calling teams should suppress immediately rather than using the full window, because campaigns running in parallel will otherwise keep dialing.
Does buying leads transfer the seller consent?
Not automatically. Consent captured by a comparison site or lead generator does not by itself authorize every downstream buyer to place AI voice calls. Review the language the consumer saw, the seller named, any partner disclosures, the vendor contract, and the certificate record before dialing. Where your company was not named and the partner list was broad, treat the record as weak and get counsel involved before scaling that source.
How long should consent records be kept?
The federal TCPA statute of limitations is four years, which makes four years a common minimum planning reference. State law, industry rules, customer contracts, and internal policy can all require longer, so the retention number should come from your counsel rather than from a blog post. Whatever period you set, keep the certificate, the form language, the timestamp, the authorized number, the call log, and the opt-out history together and searchable by phone number.
Does TCPA consent apply to business-to-business calls?
The analysis differs, and many business calls sit outside the consumer telemarketing rules that drive the written standard. That is not a blanket exemption. Wireless numbers, mixed-use numbers, and sole proprietors complicate the picture, and some state laws reach further than the federal rules. Confirm how your target list is actually composed before assuming a business campaign carries no TCPA consent obligations.
What is TrustedForm and do I need it?
TrustedForm creates a third-party certificate at the moment a consumer submits a form, capturing the page, the language displayed, the timestamp, and the submission data. It is not legally required, and it does not make weak consent language valid. It is widely used in lead generation because it produces contemporaneous evidence rather than a reconstruction. If you buy leads at volume, requiring certificates from vendors is one of the cheaper controls available.
Can a calling platform guarantee TCPA compliance?
No, and any vendor that says otherwise is worth a second look. A platform can enforce calling windows, scrub against DNC sources, check for consent documentation at intake, detect opt-out language, and retain records. It cannot vouch for the language on a form it never saw or for how your team configures campaigns. Compliance stays with the business placing the calls, which is why counsel review belongs in the launch process.
The bottom line
TCPA consent for AI voice calls is a workflow requirement, not a legal footnote at the end of a launch checklist. AI calling gives outbound teams speed and scale, and speed is exactly why the records have to be clean before the campaign starts. Clean records plus honored opt-outs plus retained proof lets AI voice agents do useful work. Weak records plus the same speed produces a problem at volume.
The operating rules are short. Use clear consent language. Name the seller. Document the opt-in. Validate before dialing. Track revocations immediately. Retain the chain. Check state rules. Do not call records that cannot support the campaign. Treat the vacated one-to-one rule as history rather than law, and put the cross-channel revocation requirement on your 2026 roadmap. Then confirm all of it with counsel, because this page is an operating guide and not legal advice. For the wider obligation set beyond consent, our guide to TCPA compliance for AI outbound calling covers Do Not Call, calling windows, and audit trails.
Before you dial
Get your lead sources reviewed with us
Bring one list and we will show you where the consent record is thin and what to hold back. No commitment and about 30 minutes.






