
Why is AI cold calling illegal?
Key Facts
- AI cold calls face statutory damages of $500 to $1,500 per violation with no aggregate cap
- Aggregate TCPA class-action verdicts exceed $925 million across the docket
- Gen Digital settled for $9.95 million in January 2026 over prerecorded AI calls to non-customers
- Hy Cite Enterprises paid $4.75 million in early 2026 for similar AI voice call violations
- 47 states require prior express written consent for marketing AI calls to wireless numbers
- Texas, Louisiana, and Mississippi allow oral consent for marketing calls under the Fifth Circuit's Bradford ruling
- Call records must be retained for 7 years to defend against TCPA litigation
The FCC Ruling That Changed Everything
For years, a quiet question hovered over the telemarketing industry: if a machine sounds human, is it really a robocall? On February 8, 2024, the FCC answered that question once and for all.
In a unanimous Declaratory Ruling (CG Docket No. 23-362, FCC 24-17), the FCC classified AI-generated voices as an "artificial or prerecorded voice" under the TCPA. The official FCC announcement left no ambiguity: voice cloning technologies cannot sidestep the robocall restrictions that have governed automated calls since 1991.
The legal logic is straightforward. The TCPA restricts calls made using an artificial or prerecorded voice, and the FCC confirmed that AI technologies that generate human voices fall squarely within that definition. The ruling was triggered in part by real-world abuse — including robocalls to New Hampshire voters using an AI-generated voice of President Biden, which led to a proposed $2 million forfeiture against the carrier Lingo Telecom for 3,978 spoofed calls.
Under this framework, the consent requirements are:
- Prior express consent for informational calls made with an AI voice
- Prior express written consent for telemarketing or advertising calls
- No exemption for established business relationships — AI calls to past customers still require separate consent
Some vendors argued that a sufficiently sophisticated AI voice functions as the "equivalent of a live agent" and should escape robocall rules. The FCC rejected this outright, stating that the statute "does not allow for any carve out of technologies that purport to provide the equivalent of a live agent." Legal experts reinforce the point: there is no grace period for AI voice — programs must immediately comply with every existing TCPA rule.
The stakes are substantial. TCPA statutory damages run $500 to $1,500 per illegal call, and aggregate verdicts across the TCPA docket exceed $925 million. That exposure is why many service businesses choose a human-agent model for outbound calling — the approach CallMyCustomers takes, where real people make the calls, the owner approves every script, and automation handles scale rather than conversations.
The FCC's message was clear: sounding human is not the same as being human, and the law treats the difference seriously.
The Financial Risk of Non-Compliance
A single AI cold call made without proper consent can cost up to $1,500 — and the math only gets worse from there. Under the TCPA, statutory damages run $500 to $1,500 per illegal call with no aggregate cap, meaning a campaign that dials 10,000 numbers without documented consent creates theoretical exposure in the tens of millions of dollars. There is no volume discount for breaking the rules.
The settlement record confirms this is not theoretical. According to recent TCPA litigation tracking, Gen Digital (Norton/LifeLock) settled for $9.95 million in January 2026 over prerecorded AI calls to non-customers, while Hy Cite Enterprises paid $4.75 million in early 2026 for similar AI voice call violations. QuoteWizard's $19 million settlement stands as the upper-bound reference for consent-traceability failures.
Here is the detail many businesses miss: the bigger financial threat is not the FCC — it is private plaintiffs. Industry experts note that class-action exposure now exceeds FCC enforcement risk, with aggregate verdicts across the TCPA docket surpassing $925 million. Aggregate TCPA class-action filings have also jumped 95% year over year, per an industry tracker cited in compliance analyses.
Recent enforcement and litigation highlights:
- AbleTo (with Aetna) received preliminary approval on a class settlement in February 2026 for unauthorized AI voicemails
- The FCC proposed a $2 million forfeiture against Lingo Telecom for carrying 3,978 spoofed robocalls using an AI-generated voice
- Settlements in 2025–2026 have consistently ranged from $5 million to $20 million
The exposure window is long, too. The TCPA carries a four-year statute of limitations, and defense counsel recommend retaining call records for seven years. A compliance mistake made today can surface in a class action years later, when the evidence to defend yourself may already be gone.
This is precisely why the operational model matters as much as the technology. Legal experts like John H. Henson of Henson Legal warn that the single biggest point of failure is the consent process itself. Human agents making approved calls to actual customers sidestep the artificial-voice classification entirely — the approach CallMyCustomers takes, with owners signing off on every script before outreach begins. When real people handle the judgment and automation only handles the scale, the per-call statutory penalty never enters the equation.
Common Compliance Traps That Trigger Lawsuits
Most businesses that get hit with TCPA lawsuits over AI calls didn't act maliciously — they fell for one of a handful of compliance myths that sound plausible but collapse under legal scrutiny. Understanding these traps is the difference between a defensible outreach program and a class action.
The Established Business Relationship (EBR) myth tops the list. Many business owners assume that if someone is a past customer, they can be called with any technology. That's only half true: compliance analyses confirm that live agents may call past customers on the DNC list under EBR, but AI agents cannot without separate consent. Once an artificial voice enters the picture, the full consent framework applies — and with statutory damages of $500 to $1,500 per call, past-customer lists offer no protection.
The one-to-one consent rule created its own confusion. Adopted by the FCC in December 2023, it was vacated by the Eleventh Circuit in January 2025 days before its effective date and never took effect. As one compliance expert puts it, the lesson isn't that requirements relaxed — it's that the rules keep moving, with state analogues filling the gaps.
And those state gaps are widening. The compliance landscape now splits sharply:
- 47 states require Prior Express Written Consent for marketing AI calls to wireless numbers
- Texas, Louisiana, and Mississippi allow oral consent under the Fifth Circuit's Bradford v. Sovereign Pest ruling (February 2026)
- In-call AI disclosure is already mandatory in Texas (within 30 seconds), California, Florida, Colorado, Illinois, and Utah
The consequences of misreading any of this are severe. Aggregate TCPA verdicts now exceed $925 million, class-action filings rose 95% year over year, and recent settlements — including $9.95 million from Gen Digital and $4.75 million from Hy Cite Enterprises — show courts aren't distinguishing between sloppy and intentional violations.
This is exactly why CallMyCustomers routes outbound calls through human agents rather than AI voices, keeping reactivation campaigns on the compliant side of the EBR line while automation handles scale behind the scenes. As legal counsel warn, the FCC's ruling means there is no grace period for AI voice — your program must immediately comply with every existing rule for artificial and prerecorded voice calls.
The Compliant Path: Human Agents with Smart Automation
If the FCC's February 2024 ruling closed the door on AI cold calling, it left one open: real humans can still pick up the phone. The compliant model that has emerged is simple — AI and automation handle the scale, people handle the judgment.
Industry analysts describe this as the "AI qualifies, humans close" approach, where automation manages repetitive qualification and routing while live representatives focus on the conversations that actually convert. As one practitioner put it, "AI as teammate, not replacement. We use AI to handle the first 80% of qualification so human representatives can focus on the 20% that closes deals" (Percepture).
The legal logic is straightforward. A live agent making a call is not an "artificial or prerecorded voice," so the strictest consent requirements triggered by the FCC's ruling (FCC-24-17) don't attach to the call itself. Human agents may also contact past customers under the Established Business Relationship doctrine — a pathway that AI agents cannot use without separate consent, a misunderstanding that has already fueled multiple class actions (compliance analyses note).
CallMyCustomers operationalizes this model for US service businesses. Automation segments the customer list by recency, surfaces old quotes and expiring memberships, schedules campaign waves, and routes replies into the client's booking process — but every outbound call is made by a person. The compliance infrastructure behind it includes:
- Client-approved scripts and offers — nothing goes out until the owner signs off
- Explicit consent collected in the booking flow, with opt-outs honored immediately
- BAA/HIPAA agreements and TCPA-aligned practices for dental, med spa, and clinic clients
- Real human judgment on every call, with no software for the client to buy or learn
This matters financially, not just legally. Statutory damages run $500 to $1,500 per illegal call with no aggregate cap, and settlements in 2025–2026 ranged from $4.75 million to $19 million (TCPA litigation tracking). Legal experts warn that "your single biggest point of failure is your consent process" (Henson Legal).
The takeaway: compliance at scale requires infrastructure, not policy documents — call logging, consent linkage, and real-time DNC scrubbing built into operations (Teams Plus). A human-agent model delivers exactly that, turning past customers into booked work without the regulatory exposure of AI dialing.
Building a Defensible Compliance Program
Building a defensible compliance program starts with recognizing that AI-generated calls face the same TCPA restrictions as traditional robocalls, requiring explicit consent for any outbound telemarketing. A dual consent architecture at lead capture is essential—one checkbox for transactional follow-up (prior express consent) and a separate, unchecked-by-default box for marketing calls requiring prior express written consent. This approach directly addresses the consent documentation failures that have triggered settlements ranging from $4.75 million to $19 million, as noted in recent enforcement actions.
State-specific protocols must meet the strictest requirements, especially given that 47 states require prior express written consent for marketing AI calls to wireless numbers, while Texas, Louisiana, and Mississippi allow oral consent under the Fifth Circuit’s Bradford ruling. Infrastructure investment is non-negotiable: real-time DNC scrubbing, abandonment tracking (capped at 3% of answered calls federally), and consent verification at call time are where compliance either holds or fails at scale. Call records must be retained for 7 years—exceeding the 4-year TCPA statute of limitations—to defend against potential litigation.
CallMyCustomers supports this framework by offering a free list review and campaign setup, using human agents for outbound calls while leveraging automation for scale and judgment, ensuring every script and message is client-approved before outreach begins. This model aligns with the "AI qualifies, humans close" approach endorsed by compliance experts as a practical path to TCPA adherence.
Frequently Asked Questions
Is AI cold calling actually illegal in the US?
Can I use AI to call past customers if we already have a business relationship?
What happens if my business makes AI calls without the right consent?
Doesn't a sophisticated AI voice count as a live agent?
Are the rules different depending on which state I'm calling?
So how can I legally run outbound calling campaigns?
Your Next Booked Customer Is Already Waiting
The FCC’s 2024 ruling settled the debate: AI-generated voices are artificial voices under the TCPA, triggering the same consent rules and financial exposure as traditional robocalls—up to $1,500 per call with no aggregate cap. Missteps like relying on past-customer relationships or overlooking state-specific nuances have fueled settlements exceeding $925 million in aggregate verdicts. The compliant path forward is clear: let automation handle scale and qualification, while real people make the calls—exactly how CallMyCustomers operates, with owner-approved scripts, explicit consent in the booking flow, and human judgment on every outreach. This model turns inactive lists into booked work without the regulatory risk. If you’re ready to reactivate your customer base the right way, start with a free list review to see what your data can produce—no obligation, no software to learn.