ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Do Not Call Rules

Is it illegal to have AI call people?

Back to InsightsIs it illegal to have AI call people?

Is it illegal to have AI call people?

Key Facts

For years, some marketers operated on the assumption that AI voices existed in a legal gray zone — too new to be covered by robocall rules written decades before the technology existed. That assumption died on February 8, 2024, when the FCC closed the door for good.

In a Declaratory Ruling issued February 8, 2024, the FCC classified AI-generated voices as an "artificial or prerecorded voice" under the Telephone Consumer Protection Act. The ruling settled what had been an open question: no matter how human an AI voice sounds, it triggers the full weight of TCPA consent requirements. Legal experts note this was not merely a clarification but a substantive expansion of TCPA coverage — as Ricardo J. Ordonez of Teams Plus puts it, "AI voice agents are both" auto-dialers and prerecorded messages, "which means every enterprise deploying them into outbound workflows is operating in TCPA territory whether they have thought about it or not."

The financial stakes are not theoretical. TCPA violations carry statutory damages of $500 to $1,500 per call, with no aggregate cap, according to compliance attorneys. A 10,000-call campaign that runs afoul of the rules can generate $5M–$15M in exposure. And plaintiffs' attorneys know it: TCPA class-action filings are up 95% year over year, with aggregate verdicts exceeding $925 million across the docket, per recent TCPA litigation analysis. Recent settlements reinforce the trend:

  • Gen Digital (Norton/LifeLock) paid $9.95 million in January 2026 for prerecorded calls to non-customers
  • Hy Cite Enterprises settled for $4.75 million, with class members eligible for $600–$1,000 each
  • QuoteWizard paid $19 million for failing to trace consent through its vendor chain

The most dangerous misconception is the Established Business Relationship (EBR) exemption. EBR does exempt manual, human-placed calls from Do Not Call Registry restrictions — but the artificial voice itself triggers the consent requirement, meaning an AI agent cannot dial even a longtime customer on the DNC list without separate consent, as TCPA compliance guidance makes clear.

This is why the compliance architecture behind any outreach program matters as much as the campaign itself. CallMyCustomers builds its reactivation campaigns on consented customer lists with opt-outs honored immediately, and every script approved by the business owner before a single call goes out — the operational discipline the FCC's ruling effectively demands. As attorney Marc Jacobs warns, "One misstep — a missing opt-out, a failure to disclose voice synthesis, a bad number — risks sparking a lawsuit."

The consent framework for AI-driven calls operates on two distinct tiers, and confusing them is where most businesses expose themselves to liability. For marketing calls to cell phones, 47 states require Prior Express Written Consent (PEWC) — a signed agreement naming your business, identifying the specific phone number, and confirming consent isn't a condition of purchase. Informational calls like appointment reminders need only Prior Express Consent (PEC), which can be oral. The FCC's February 2024 ruling confirmed that AI-generated voices are "artificial or prerecorded voice" under the TCPA, so this distinction applies regardless of how human the technology sounds.

A critical exception exists in the Fifth Circuit. The February 2026 decision in Bradford v. Sovereign Pest Control of Texas carved out Texas, Louisiana, and Mississippi, permitting oral consent for marketing calls in those three states. Everywhere else, written consent remains the standard. This patchwork means a campaign dialing across state lines must default to the stricter PEWC requirement unless you can segment and prove jurisdiction-specific consent for every number. An Established Business Relationship does not override this — the artificial voice itself triggers the consent requirement even when an EBR exists.

Documentation standards are your only defense when challenges arise. The TCPA carries a four-year statute of limitations, but defense counsel recommends retaining consent records for seven years to cover edge cases and class-action discovery. Every record should capture the timestamp, method of consent (web form, verbal recording, signed document), the exact language presented to the consumer, and the phone number authorized. Class actions in 2025–2026 have settled in the $5M–$20M range, with a 10,000-call non-compliant campaign facing up to $15M in statutory exposure at $500–$1,500 per call.

  • Capture consent with timestamp, method, exact disclosure language, and authorized number
  • Retain records for seven years minimum — four-year statute of limitations plus litigation buffer
  • Segment lists by state to apply the correct consent tier (PEWC vs. PEC)
  • Verify consent provenance before every campaign launch, not after

Vendor chain liability makes this your problem even when you outsource. The Lamb v. Mortgage One Funding case (filed February 2026) explicitly extends liability to consumers called by the company "or from any of the company's vendors, lead generators, or agents." You cannot contract away TCPA responsibility. When CallMyCustomers runs reactivation campaigns for service businesses, we treat consent verification as a pre-flight check — if consent cannot be confirmed for a specific number, that call does not go out. The same infrastructure-first approach that protects our clients protects your business: real-time DNC scrubbing, consent linkage at call initiation, and abandonment tracking under the FCC's 3% cap.

State-Level AI Disclosure Laws You Cannot Ignore

Even if your AI calls clear every federal TCPA hurdle, a second layer of rules is waiting at the state level — and violating them can be just as expensive, with statutory damages running $500 to $1,500 per call and no aggregate cap.

Texas moved first and hardest. SB 140 requires AI disclosure within 30 seconds of the call starting, effective September 2024, and the state's broader TRAIGA framework (HB 149) takes effect January 1, 2026. California follows with AB 489 and SB 1001, which impose their own disclosure requirements for calls to California residents.

Florida, Colorado, Illinois, and Utah round out the patchwork. Colorado's AI Act deserves special attention: it may classify most voice AI as "high-risk" in certain domains, triggering point-of-interaction notices and a three-year record retention requirement. If you operate in regulated sectors — healthcare, finance, housing — assume Colorado applies to you.

The practical fix is a single disclosure script that satisfies every jurisdiction:

  • "This is an AI assistant calling from [Company] on a recorded line. Is this a good time to talk?"
  • Deliver it within the first 30 seconds — Texas's deadline is the strictest, so it becomes your national standard
  • Log the disclosure with a timestamp on every call, so you can prove compliance years later

A federal rule may eventually simplify this. The FCC's September 2024 NPRM proposes mandatory in-call AI disclosure nationwide, but it remains unfinalized as of April 2026. Until then, you are navigating state-by-state rules — and attorneys warn that a single missing disclosure can spark a lawsuit with statutory damages attached.

Why does this matter so much? TCPA class-action filings are up 95% year over year, with aggregate verdicts exceeding $925 million across the docket. Plaintiff's lawyers are actively looking for the "failure to disclose voice synthesis" angle.

This is why CallMyCustomers builds disclosure language into every campaign script before the client signs off — the owner approves the message, and the compliance language rides along with it. For a reactivation campaign built from a list of real past customers, that disclosure is the difference between a warm follow-up call and a statutory liability. When in doubt, disclose early, disclose clearly, and keep the records.

Operational Compliance Infrastructure That Scales

Operational compliance infrastructure transforms legal requirements into real-time systems that prevent violations before calls are placed. For AI-driven outreach, this means implementing real-time DNC scrubbing at call initiation—checking numbers against the National DNC Registry the moment a dial is attempted, not relying on outdated nightly batches that leave businesses exposed to immediate liability. Call logging must capture consent linkage at the point of contact, creating an auditable trail that connects each call to a specific, documented consent record, whether prior express written consent for marketing or prior express consent for informational purposes.

Abandonment rate tracking operates continuously to ensure compliance with the FCC’s 3% cap over a 30-day period per campaign, where an abandoned call is defined as one that connects but delivers no response within two seconds of the consumer’s greeting. Opt-out mechanisms must be instant and functional on the first try—honoring revocation requests like “stop,” “quit,” or “end” within 10 business days, as mandated by the April 2025 TCPA amendments. These systems are not optional add-ons; they form the foundation of lawful AI calling, especially given that vendor chain liability means businesses using third-party services remain legally responsible for compliance failures, as confirmed in cases like Lamb v. Mortgage One Funding.

For healthcare clients—including dental practices, med spas, and clinics—CallMyCustomers operationalizes the FCC’s TCPA healthcare exemption by integrating BAA/HIPAA requirements directly into outreach workflows. Voice messages are limited to under one minute, texts to 160 characters, and all communication avoids promotional or financial solicitation, focusing solely on appointment reminders, service notifications, or care coordination sent to patient-provided numbers. Consent is verified at the booking stage, and opt-outs are honored immediately, aligning with clinical-grade outreach standards that prioritize patient trust and regulatory adherence over scale alone. This infrastructure-first approach ensures that compliance isn’t just documented—it’s enforced in real time, every time a call is placed.

How CallMyCustomers Builds Compliance Into Every Campaign

Reactivating existing customers with AI-powered calls requires more than good intentions—it demands a compliance-first approach to avoid costly missteps. Under the TCPA, AI-generated voices are treated as artificial or prerecorded calls, meaning prior express consent is required before dialing U.S. cell phones, with statutory damages ranging from $500 to $1,500 per violation and no aggregate cap. A single non-compliant campaign of 10,000 calls could expose a business to up to $15 million in liability, underscoring why permission-based outreach isn’t just ethical—it’s essential for financial protection.

CallMyCustomers builds compliance into every campaign by starting with a free list review that includes consent verification and compliance screening before any fee is charged. This ensures businesses only outreach to verified customer lists with documented consent, eliminating guesswork about whether a relationship qualifies for contact. Every script, offer, and message is submitted for owner approval before deployment, giving clients full control over what is communicated and how. Outreach is executed exclusively from lists of real customers who have previously engaged with the business, distinguishing reactivation from cold acquisition and aligning with the permission-based, relationship-first model that defines the service.

To maintain ongoing compliance, the platform honors opt-outs immediately upon receipt—whether via voice command, key press, or reply—and routes all responses directly into the client’s existing booking flow for seamless follow-up. For healthcare-adjacent clients such as dental offices, med spas, and wellness clinics, outreach operates under required privacy agreements including BAA/HIPAA adherence, with messaging designed to meet clinical standards and avoid promotional solicitation that would void TCPA healthcare exemptions. By managing the entire campaign end-to-end—without requiring clients to buy software, learn new systems, or pay per-seat fees—CallMyCustomers removes operational complexity while ensuring that consent, disclosure, and opt-out protocols are consistently applied. This done-for-you model allows service businesses to safely reactivate dormant customers, old quotes, and inactive members knowing every call is placed within legal boundaries and with their explicit approval.

Frequently Asked Questions

Is it illegal to use AI to make outbound calls to customers?
AI-driven outbound calls are not inherently illegal but are strictly regulated under the TCPA, requiring prior express consent before dialing U.S. cell phones, with violations carrying $500–$1,500 per call and no aggregate cap. See research on TCPA compliance for AI voice calls
Do I need written consent to use AI for marketing calls, or is verbal okay?
For marketing calls to U.S. cell phones, 47 states require Prior Express Written Consent (PEWC), while informational calls like appointment reminders need only oral Prior Express Consent (PEC). However, Texas, Louisiana, and Mississippi permit oral consent for marketing calls due to a Fifth Circuit ruling. Learn about consent tiers and state variations
Can I call my existing customers with AI if we have an established business relationship?
No—an Established Business Relationship (EBR) does not exempt AI calls from TCPA consent requirements. The artificial voice itself triggers the consent obligation, meaning you cannot dial even a longtime customer on the DNC list without separate consent, regardless of EBR. Review why EBR doesn’t override AI call consent rules
What happens if I use a third-party vendor for AI calling and they make a compliance mistake?
You remain legally responsible for TCPA violations even when using third-party AI calling services. Courts have ruled that liability extends to consumers called by the company 'or from any of the company's vendors, lead generators, or agents,' so you cannot contract away TCPA responsibility. Understand vendor chain liability in AI calling
Do I have to disclose that I'm using AI when I call people?
Yes, in several states including Texas, California, Florida, Colorado, Illinois, and Utah, AI disclosure is required—Texas mandates disclosure within 30 seconds of the call start. A recommended script that works nationally is: 'This is an AI assistant calling from [Company] on a recorded line. Is this a good time to talk?' See state-specific AI disclosure requirements
How long should I keep records of consent for AI calls?
While the TCPA has a four-year statute of limitations, defense counsel recommends retaining consent records for seven years to cover litigation risks and class-action discovery. Each record should include timestamp, method of consent, exact disclosure language, and the authorized phone number. Get details on consent documentation best practices

The Bottom Line: AI Calling Is Legal — Cutting Corners Isn't

So, is it illegal to have AI call people? No — but the FCC's February 2024 ruling made one thing unmistakably clear: AI voices are robocalls under the TCPA, and every consent, disclosure, and opt-out rule applies in full. With statutory damages of $500 to $1,500 per call and no aggregate cap, a single careless campaign can turn a growth channel into a multimillion-dollar liability. The businesses that win with AI outreach aren't the ones that skip the rules — they're the ones that build compliance in from the start: verified consent, immediate opt-outs, clear AI disclosure, and records that hold up years later. That's exactly why CallMyCustomers runs reactivation campaigns only from lists of real past customers, with every script approved by the business owner before a single call goes out — and a free list review that screens consent before you spend a dollar. Your next booked customer already knows your business. If you've got a list of past customers, old quotes, or lapsed members sitting idle, the safest first step is a no-cost review to see what it can produce — legally, and with your sign-off on every message.

Stay in the Loop