ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Do Not Call Rules

Can AI agents cold call?

Back to InsightsCan AI agents cold call?

Can AI agents cold call?

Key Facts

  • The FCC's February 2024 ruling classified AI-generated voices as 'artificial or prerecorded voice' under the TCPA, ending legal ambiguity per the official Declaratory Ruling.
  • TCPA penalties run $500 per negligent violation and $1,500 per willful violation, applied per call with no aggregate cap according to compliance research.
  • An AI calling platform settled with the FTC for $28 million, largely over unconsented cell phone calls placed by AI dialers per enforcement records.
  • The Established Business Relationship exemption that lets live agents call past customers does not extend to AI agents, requiring fresh prior express consent per legal analysis.
  • 47 states require prior express written consent for marketing calls; only Texas, Louisiana, and Mississippi accept oral consent after a Fifth Circuit decision per the TCPA compliance playbook.
  • TCPA class-action filings are up 95% year over year, with recent settlements landing in the $5M–$20M range per recent enforcement data.
  • The legal standard ignores how convincing an AI voice sounds — what matters is whether technology generates the words, not a live person per legal analysis of the ruling.

The FCC Ruling That Changed Everything for AI Cold Calling

For years, a gray zone existed around AI-generated voices on the phone. If a synthetic voice sounded human enough, did the robocall rules even apply? In February 2024, the FCC closed that question for good.

The FCC's Declaratory Ruling classified AI-generated voices as "artificial or prerecorded voice" under the Telephone Consumer Protection Act (TCPA). That single classification eliminated the legal ambiguity that some outbound-calling operations had been quietly relying on. AI voice calls now face the same prior express consent requirements that have governed traditional robocalls for decades.

The legal standard, as legal analysis of the ruling makes clear, has nothing to do with how convincing the voice sounds. What matters is whether a live person is speaking in real time or whether technology is generating the words. Even hybrid systems — where an AI opens the call and a human agent joins later — trigger full TCPA coverage from the first synthetic word.

The consequences of getting this wrong are steep. TCPA statutory damages run $500 per negligent violation and $1,500 per willful violation, applied per call with no aggregate cap. Recent enforcement backs that up: an AI calling platform settled with the FTC for $28 million, largely over unconsented cell phone calls placed by AI dialers.

For businesses weighing AI outreach, the practical implications are straightforward:

  • Most cold AI calls to wireless numbers are illegal without documented prior express consent — the EBR exemption that lets live agents call existing customers does not extend to AI agents.
  • In 47 states, marketing calls require prior express written consent; only Texas, Louisiana, and Mississippi accept oral consent following a recent Fifth Circuit decision.
  • Liability follows the hiring company. Under emerging case law, the entity on whose behalf calls are made bears responsibility regardless of which vendor dialed.

That last point deserves emphasis: you cannot outsource compliance risk along with the dialing. This is why permission-based approaches matter. At CallMyCustomers, outreach runs only from lists of real customers with consent documented in the booking flow, and every script is approved by the owner before a single call goes out — the structure the FCC ruling effectively demands.

The 2024 ruling didn't ban AI voices. It simply confirmed that AI plays by the same rules as every other dialing technology — and that the cost of pretending otherwise is measured in millions.

The Established Business Relationship (EBR) exemption is one of the most misunderstood concepts in telemarketing compliance, particularly when AI agents are involved. Many businesses assume that because they have served a customer before, they can use AI to call them without additional consent — even if that customer is on the National Do Not Call Registry. This assumption is not only incorrect but represents the single most expensive compliance error companies make when deploying AI calling systems.

Under the TCPA, the EBR exemption allows live agents to place telemarketing calls to consumers with whom they have an existing relationship, even if the number is on the DNC list, after specific time periods (such as 18 months for inquiries or 3 months for transactions). However, the FCC’s February 2024 Declaratory Ruling made it unequivocally clear that AI-generated voices are classified as “artificial or prerecorded voice” under the TCPA, which means they are subject to the same consent requirements as traditional robocalls. As a result, the EBR exemption does not apply to AI calls — regardless of how recent or strong the customer relationship may be.

This distinction is critical because violating TCPA consent rules carries steep penalties: $500 per negligent violation and $1,500 per willful violation, applied per call — not per recipient. For a business calling hundreds or thousands of past customers with AI, assuming EBR provides cover could trigger liability in the hundreds of thousands or even millions of dollars. The risk is amplified by vendor chain liability, where the hiring company remains responsible for compliance failures even if a third-party AI provider placed the call.

To stay compliant, businesses must treat AI outreach to past customers as requiring fresh prior express consent — just like calling a new lead. For marketing calls to wireless numbers in 47 states, this means obtaining prior express written consent (PEWC) that meets TCPA standards: clear disclosure, specific authorization for the phone number, and consent not buried in terms or fine print. In Texas, Louisiana, and Mississippi, oral consent may suffice post-Bradford, but PEWC remains the safest standard nationwide. Without this foundation, even a well-intentioned reactivation campaign can become a costly compliance misstep.

Even if your AI calling program is fully compliant at the federal level, state law can still sink it. The federal TCPA sets a floor — an 8am–9pm local calling window, for example — but many states tighten those hours, and a handful are now writing AI-specific rules the federal government hasn't finalized yet.

Florida and Massachusetts both cut the calling window to 8am–8pm, while Washington allows calls only from 9am–8pm, according to state TCPA compliance guidance. If your dialer runs on the federal 9pm cutoff, you're violating state law in every one of those markets. The safest operational standard is to build campaigns around the strictest applicable window.

Consent rules are also splitting into two tiers. Following the Fifth Circuit's decision in Bradford v. Sovereign Pest Control, legal analysis of the AI calling landscape identifies a carve-out allowing oral consent for AI calls in Texas, Louisiana, and Mississippi. The other 47 states require Prior Express Written Consent for marketing calls — and courts interpret "marketing" broadly, covering even account check-ins that pivot to an upsell.

The third layer is disclosure. Texas SB 140, effective September 2024, requires AI callers to identify themselves within 30 seconds of the call starting, and commentary on emerging AI disclosure rules notes that California, Colorado, Illinois, and Utah have implemented their own disclosure mandates. A pending FCC rulemaking is expected to make in-call AI disclosure federally mandatory within 12–24 months.

Key state-level requirements to track:

  • Calling windows — 8am–8pm in Florida and Massachusetts, 9am–8pm in Washington, versus the federal 8am–9pm baseline
  • Consent tiers — written consent in 47 states; oral consent accepted only in Texas, Louisiana, and Mississippi post-*Bradford*
  • AI disclosure — mandatory in Texas (within 30 seconds), California, Colorado, Illinois, and Utah, with a federal rule pending
  • DNC registry scrubbing every 31 days, with failure treated as strict liability

The stakes justify the diligence. Statutory damages run $500 to $1,500 per call with no aggregate cap, and recent enforcement data shows TCPA class-action filings up 95% year over year, with 2025–2026 settlements in the $5M–$20M range.

For businesses running reactivation outreach to known customers rather than true cold calls, the calculus improves — but it doesn't disappear. This is why CallMyCustomers builds every campaign around lists of real customers with owner-approved scripts and immediate opt-out handling, so state-by-state requirements are met before a single call goes out. Whatever approach you take, jurisdiction-specific protocols aren't optional; they're the difference between a compliant campaign and a class action.

Vendor Liability: Why You Can't Outsource Your TCPA Risk

Hiring an AI calling vendor doesn't move your legal risk — it multiplies it. Under the TCPA, the company on whose behalf the calls are made bears liability regardless of which vendor actually dialed the phone.

This principle, known as vendor chain liability, was cemented in Lamb v. Mortgage One Funding, a case filed in February 2026. The court's reasoning was straightforward: the contracting entity chose the vendor, initiated the campaign, and benefited from the calls, so it cannot point the finger downstream when violations occur. For any business outsourcing outbound calling, the compliance responsibility stays squarely with you.

The enforcement record makes the stakes clear. In April 2026, Air AI reached a $28 million settlement with the FTC, driven primarily by unconsented cell phone calls placed through AI dialers. Around the same period, QuoteWizard paid $19 million in a case that became a reference point for failing to trace consent through vendor chains — a reminder that you must be able to document where every phone number's permission originated, not just assume your vendor handled it.

Class-action exposure compounds the danger. TCPA statutory damages run $500 to $1,500 per call with no aggregate cap, and recent class settlements have landed in the $5M–$20M range. One industry tracker cited filings up 95% year over year, with aggregate verdicts exceeding $925 million.

Here's the part that catches businesses off guard: contractual indemnification clauses don't shield you from regulators or class-action plaintiffs. The FTC and state attorneys general pursue the hiring company directly, and plaintiffs' attorneys name whoever placed or commissioned the calls. A vendor's promise to reimburse you offers no protection against enforcement in the first place — and if the vendor lacks the assets to pay, you're left holding the full judgment.

So what does responsible vendor management look like?

  • Verify the vendor's compliance capabilities before signing — real-time DNC scrubbing, consent verification, and comprehensive call logging.
  • Maintain active oversight of calling practices rather than treating it as "set it and forget it."
  • Ensure consent records are properly maintained and accessible to you, not locked inside the vendor's systems.
  • Confirm scripts, disclosures, and targeting before any call goes out on your behalf.

That last point is why we built CallMyCustomers the way we did: the owner approves every script, offer, and message before anything is sent, and every campaign starts with a free list review so you know exactly what's being called and why. When a vendor invites you into the process instead of hiding behind it, vendor liability becomes a shared discipline rather than a silent risk.

Compliance Infrastructure: The Technical Requirements That Make or Break AI Outreach

A written compliance policy sitting in a binder does nothing when an AI dialer places 5,000 calls before lunch. The infrastructure layer is where compliance either holds or breaks — consent forms, do-not-call lists, and call records are compliance artifacts, but whether they function at call volume depends entirely on how the systems underneath them are built, as compliance analysts note.

The stakes are unforgiving. TCPA penalties run $500 per negligent violation and $1,500 per willful violation, applied per call, with no aggregate cap — and industry compliance research shows class-action settlements in 2025–2026 regularly landed between $5 million and $20 million. At AI calling volumes, a single systemic flaw multiplies into thousands of violations in hours.

Five technical capabilities separate defensible AI outreach from liability exposure:

  • Real-time DNC scrubbing every 31 days. The National DNC Registry must be checked at that interval, and failure to scrub constitutes strict liability. Batch scrubbing from last week's list is not enough — real-time checks at call initiation are the only way to avoid dialing a number that registered after your last batch.
  • Consent verification before every dial. If consent cannot be confirmed in the moment, the call does not go out. This matters especially because courts have grown skeptical of "warm cold" list language, making re-verification before AI dialing the defensible standard.
  • Abandonment rate tracking under 3%. Federal rules cap abandoned calls at 3% of answered calls, measured over a 30-day period per campaign under the FCC's framework — which requires continuous monitoring, not periodic spot checks.
  • STIR/SHAKEN attestation. A-level attestation improves call completion rates and keeps compliance metrics accurate, since spoofed or mislabeled calls undermine both deliverability and record-keeping.
  • Call log retention of 4–7 years. The federal statute of limitations for TCPA claims is four years, dictating the minimum retention period; some compliance providers retain records for seven years to stay ahead of late-filed claims.

Why does policy alone fail? Because human-run processes degrade at scale. A manual DNC check performed weekly leaves a seven-day window of strict liability; a consent file that isn't queried at dial time is just paper. The FCC's February 2024 ruling confirmed that AI-generated voices are treated as artificial or prerecorded voice under the TCPA, so every call an AI agent places carries the same legal weight as a traditional robocall — with none of the ambiguity to hide behind.

This is also why liability follows the contracting business, not the technology vendor. Under cases like Lamb v. Mortgage One Funding, the entity on whose behalf calls are made bears responsibility regardless of which vendor dialed. It's the reason CallMyCustomers works only from lists of real customers, honors opt-outs immediately, and requires owner approval of every script before a single call goes out — the infrastructure enforces what the policy promises.

For US service businesses, the takeaway is simple: before any AI outreach runs on your customer list, ask exactly how consent is verified at dial time, how often the DNC registry is scrubbed, and how long call logs are kept. If those answers live only in a document rather than in the calling infrastructure itself, the exposure is yours.

Frequently Asked Questions

Is it legal for AI agents to make cold calls?
Only with prior express consent. The FCC's February 2024 Declaratory Ruling classified AI-generated voices as "artificial or prerecorded voice" under the TCPA, so AI calls face the same consent rules as robocalls — meaning most cold AI calls to wireless numbers without documented consent are illegal.
Does having an existing business relationship let me call past customers with AI?
No — this is the most expensive misconception in AI outreach. The EBR exemption that lets live agents call existing customers does not extend to AI agents, so AI outreach to past customers requires fresh prior express consent, and in 47 states that means prior express written consent for marketing calls (only Texas, Louisiana, and Mississippi accept oral consent post-Bradford).
What are the penalties if my AI calls violate TCPA rules?
Damages run $500 per negligent violation and $1,500 per willful violation, applied per call with no aggregate cap. Enforcement is real: an AI calling platform settled with the FTC for $28 million over unconsented cell phone calls, and 2025–2026 class settlements have landed in the $5M–$20M range.
If I hire an AI calling vendor, are they liable for compliance violations — or am I?
You are. Under vendor chain liability, established in cases like Lamb v. Mortgage One Funding, the entity on whose behalf calls are made bears responsibility regardless of which vendor dialed — and contractual indemnification clauses don't shield you from regulators or class-action plaintiffs.
Do AI callers have to tell people they're AI?
In a growing number of states, yes. Texas SB 140 requires AI callers to identify themselves within 30 seconds, and California, Colorado, Illinois, and Utah have their own disclosure mandates, with a pending FCC rulemaking expected to make in-call AI disclosure federally mandatory within 12–24 months.
Does it matter if my AI voice sounds really human, or if a live agent joins the call later?
Neither creates a loophole. The legal standard depends on whether technology is generating the words, not how convincing the voice sounds, and even hybrid systems trigger full TCPA coverage from the first synthetic word — the initial AI portion of a call brings the whole call under robocall rules even if a human agent joins later.

Your Permission Is the Real Competitive Edge

The FCC ruling settled the debate: AI voices are robocalls under the TCPA, and that means consent isn’t optional—it’s the foundation. From the EBR exemption not applying to AI, to state-specific calling windows and disclosure rules, to the hard truth that vendor liability sticks with you, the message is clear: cutting corners on compliance isn’t just risky, it’s financially reckless. The businesses that win with AI outreach aren’t the ones calling the most numbers—they’re the ones calling the right people, with the right permission, at the right time. That’s where CallMyCustomers comes in: we build every campaign around your verified customer list, require your script approval before dialing, and handle opt-outs instantly—so your reactivation efforts stay compliant, effective, and focused on what matters: turning past customers into booked work. Ready to see what your list can do? Get your free list review and find out how many booked appointments are waiting in your existing customers.

Stay in the Loop