Compliance hub · Updated 16 July 2026

AI Calling Compliance: TCPA, DNC, GDPR & AI-Disclosure (2026 Guide)

AI outbound calling is governed by five bodies of law that stack rather than substitute: TCPA consent and quiet hours, Do Not Call scrubbing and internal suppression, AI disclosure, CAN-SPAM on the email the call produces, and GDPR/CCPA erasure of the contact data underneath. Satisfying four of the five does not make a program lawful. Using an AI voice does not create a new regulatory category with its own lighter rules — FCC Declaratory Ruling 24-17, released 8 February 2024, held that AI-generated voices are “artificial” under the TCPA, which lands an AI call in the strictest existing category rather than beside it.

This hub states each pillar, the citation that governs it, and the deadline that actually bites — then links the page that works it through in full. It is general information about the law as of 16 July 2026, not legal advice.

AI calling compliance is the set of legal duties an outbound program must satisfy when the voice on the call is generated by software rather than spoken by a person: a lawful consent basis under the TCPA, do-not-call scrubbing and internal suppression before dialing, disclosure of the business responsible for the call and — in a growing number of jurisdictions — of the AI itself, CAN-SPAM rules on any email the call produces, and erasure of the underlying contact data on request under GDPR and CCPA.

For the category this sits inside, see what an AI Business Aide is. For the narrower legal question of whether AI cold calling is permitted at all, see is AI cold calling legal?

The five pillars at a glance

Each row is a separate legal regime with its own enforcer, its own clock, and its own penalty. They are listed in the order a single outbound call encounters them.

PillarGoverning ruleThe clock that bitesRead it
TCPA consent & quiet hours47 U.S.C. § 227; 47 CFR § 64.1200(c)(1)Checked before every call — 8 a.m.–9 p.m. recipient local timeTCPA quiet hours
Do Not Call & suppression47 CFR § 64.1200(c)(2), (d); 16 CFR Part 31010 business days to honor; 31-day Registry scrub; 5-year retentionDo-Not-Call & suppression
AI disclosure47 CFR § 64.1200(b); EU AI Act Art. 50(1); state AI statutesAt the start of the message; EU duty applies 2 August 2026AI caller disclosure laws
CAN-SPAM (email follow-up)15 U.S.C. §§ 7701–7713; 16 CFR Part 316; RFC 805810 business days to honor; 48 hours in practice for bulk sendersCAN-SPAM & one-click unsubscribe
GDPR & CCPA erasureGDPR Arts. 17, 21; Cal. Civ. Code § 1798.105One month (GDPR Art. 12(3)); 45 days (CCPA)GDPR & CCPA erasure

Pillar 2 — Do Not Call and internal suppression

The National Do Not Call Registry is not a rounding error. The FTC's National Do Not Call Registry Data Book for Fiscal Year 2025, released in December 2025, reports more than 258 million active registrations — up over 4.8 million on the prior year — and more than 2.6 million Do Not Call complaints received in FY2025, the majority reporting robocalls rather than live telemarketers.

Two different lists are in play, and complying with one does not satisfy the other. The Registry (47 CFR § 64.1200(c)(2)) is the government list a consumer joins once; registrations have been permanent since the Do-Not-Call Improvement Act of 2007 took effect in February 2008. An internal do-not-call list (47 CFR § 64.1200(d)) records requests made to your company specifically — a Registry listing is not an internal request, and a number absent from the Registry can still be on your internal list.

Three numbers govern the mechanics: an internal request must be honored within ten business days under 47 CFR § 64.1200(d)(3), honored for five years under § 64.1200(d)(6), and the Registry must be re-scrubbed at least every 31 days to hold the safe harbor. Suppression is a before-dialing check, not an after-the-fact report.

Do-Not-Call and suppression lists for AI outbound calling →

Pillar 3 — AI disclosure

This is the pillar moving fastest. As of 16 July 2026 no general federal rule compels an AI caller to announce itself; the FCC proposed one in its Notice of Proposed Rulemaking FCC 24-84, adopted 7 August 2024, and has not adopted it. That is a narrower gap than it sounds: 47 CFR § 64.1200(b) already requires every artificial or pre-recorded voice message to identify the business responsible for the call at the start of the message and to state a contact number.

The date to plan against is 2 August 2026, when Article 50(1) of the EU AI Act (Regulation (EU) 2024/1689) begins to apply. It requires that people be informed they are interacting with an AI system, at the latest at the time of first interaction. Article 99(4) puts penalties for transparency breaches at up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher.

States already impose narrower duties — but the statute most often cited at AI callers is not one of them. California's B.O.T. Act (SB 1001, Cal. Bus. & Prof. Code §§ 17940–17943, effective 1 July 2019) makes it unlawful to use a bot to mislead someone about its artificial identity in order to incentivize a purchase or sale, but it reaches only bots communicating online: § 17940 defines a bot as an “automated online account” and defines “online” as appearing on a public-facing internet website, web application, or digital application. A phone call is none of those, so the B.O.T. Act governs a web chat widget rather than a dialer. Utah's Artificial Intelligence Policy Act (SB 149, as amended by SB 226 effective 7 May 2025) carries no such limitation and does reach a call: it requires a supplier using generative AI in a consumer transaction to disclose that fact on a clear and unambiguous request. Colorado's SB 24-205 was repealed and replaced by SB 26-189, signed 14 May 2026 and effective 1 January 2027, before it ever took effect.

AI caller disclosure laws: what you must tell people →

Pillar 4 — CAN-SPAM and the email the call produces

A call that ends in “send me the details” has just moved the program into a second statute. The CAN-SPAM Act of 2003 (15 U.S.C. §§ 7701–7713), implemented by the FTC's CAN-SPAM Rule at 16 CFR Part 316, governs the follow-up: the message needs a functioning opt-out that works for at least 30 days after sending, the opt-out must be honored within ten business days under 15 U.S.C. § 7704(a)(4)(A), and no fee or extra information may be demanded as a condition of honoring it.

Penalties are assessed per message. Under the FTC's inflation adjustment at 16 CFR § 1.98, effective 17 January 2025, each non-compliant email carries a maximum civil penalty of $53,088 — a figure that compounds across a single campaign.

The stricter deadline is private, not statutory. RFC 8058 (January 2017) defines one-click unsubscribe through the List-Unsubscribe and List-Unsubscribe-Postheaders. Google and Yahoo's bulk sender requirements took effect on 1 February 2024, but the one-click duty ran on its own clock: Google gave senders already carrying an unsubscribe link until 1 June 2024 to implement it in commercial and promotional mail. Senders pushing 5,000+ messages a day are now expected to support it and to process the resulting opt-out within 48 hours. Ten business days is the law; 48 hours is what your deliverability depends on.

CAN-SPAM and one-click unsubscribe (RFC 8058) →

Pillar 5 — GDPR and CCPA erasure

The first four pillars govern the call. This one governs the data that made the call possible. GDPR Article 17 gives a data subject the right to obtain erasure without undue delay on any of six grounds, and Article 12(3) puts a concrete clock on “without undue delay”: one month from receipt, extendable by two further months for complex cases only if the data subject is told inside the first month. Article 19 requires you to pass the erasure on to each recipient of the data. Article 83(5) sets the ceiling at €20,000,000 or 4% of total worldwide annual turnover, whichever is higher.

Article 21(2) is the provision outbound teams underestimate: the right to object to processing for direct marketing is unconditional. There is no balancing test and no legitimate-interest argument to win — once the objection lands, the processing stops.

Regulators are actively auditing this. The EDPB's Coordinated Enforcement Framework report on the right to erasure, published 18 February 2026, covered 32 data protection authorities examining 764 controllers, and set out seven recurring challenges — among them a lack of appropriate internal procedures to handle requests, insufficient information provided to individuals, reliance on inefficient anonymisation techniques in place of deletion, and the deletion of personal data held in back-ups.

California runs a parallel regime on a different clock. Cal. Civ. Code § 1798.105 gives a right to delete, § 1798.130(a)(2) allows 45 days to respond, extendable once by a further 45, and § 1798.155 sets penalties of $2,500 per violation and $7,500 per intentional violation.

GDPR and CCPA erasure for outbound contact data →

The order the checks have to run in

The five pillars are not a checklist to review quarterly. Four of them are gates that must close before a specific event, and the order matters because a later gate cannot repair an earlier one — a disclosure at connect does not cure a call placed to a suppressed number, and an erasure honored next month does not unring a call placed at 6 a.m. local time.

  1. Before the contact enters the campaign: establish and record a lawful consent basis, and know which one it is.
  2. Before the number is dialed: scrub against the National Do Not Call Registry (re-scrubbed inside 31 days) and against your own internal do-not-call list.
  3. At the moment of dialing: resolve the recipient's local time and hold the call if it falls outside 8 a.m.–9 p.m. there.
  4. At the start of the message: identify the business responsible for the call, and disclose the AI where the jurisdiction requires it.
  5. Before any follow-up email: check suppression again, and ship a working one-click unsubscribe with the message.
  6. Whenever a request arrives: honor revocation within ten business days and erasure within one month (GDPR) or 45 days (CCPA), and propagate both to every system holding the record.

How Veera enforces each pillar by default

Veera's AI voice calling is live. Three of the controls above are enforced by the product rather than left to the operator to remember, which is the distinction that matters when the gate has to close before the call rather than appear in a report after it.

Quiet hoursare evaluated per call against the recipient's own timezone — not the area code, and not the sending account's timezone — so a call outside the local 8 a.m.–9 p.m. window is not placed. Opt-outs are written to a suppression list that is checked before the next send, and the email path carries a one-click unsubscribe built on the RFC 8058 headers. Erasure is honored on request: when a contact asks to be forgotten, their data is erased.

Being precise about what is live: Veera's SMS, WhatsApp, and email channels are built and activating rather than available today. The one live send exception is in-call WhatsApp document delivery, which is transactional and bound to an active, consented call.

Consent state is only useful where your team already looks. Veera syncs into GoHighLevel and HubSpot two ways rather than replacing them, so opt-outs and call outcomes land on the contact record in the CRM your agency already runs — not in a second system nobody checks before dialing. Veera is free to start.

These are product controls, not legal advice and not a compliance certification. Consent capture, AI disclosure scripting, Do Not Call Registry subscription, and record retention remain the operator's responsibility — see how the compliance layer sits inside AI cold calling software for where the boundary falls in the category generally.

Frequently asked questions

What laws apply to AI outbound calling?

Five bodies of law, and they stack rather than substitute. The Telephone Consumer Protection Act (47 U.S.C. § 227) governs consent and calling hours. The FCC’s delivery restrictions at 47 CFR § 64.1200(c) and (d), alongside the FTC’s Telemarketing Sales Rule (16 CFR Part 310), govern Do Not Call Registry scrubbing and internal suppression. Disclosure duties come from 47 CFR § 64.1200(b) federally, from state AI statutes such as Utah’s Artificial Intelligence Policy Act, and from Article 50 of the EU AI Act. (California’s B.O.T. Act is frequently miscited here: it reaches only bots communicating online, so it does not govern a phone call.) The CAN-SPAM Act (15 U.S.C. §§ 7701–7713) governs any email follow-up the call produces. GDPR Article 17 and Cal. Civ. Code § 1798.105 govern erasure of the contact data behind all of it. A program can satisfy four of the five and still be unlawful under the fifth.

Does using an AI voice change what the law requires?

It adds duties rather than removing them. FCC Declaratory Ruling 24-17, adopted 2 February 2024 and released 8 February 2024, held that AI-generated voices are “artificial” within the meaning of the TCPA because the technology artificially simulates a human voice. The consequence is that an AI voice agent inherits the consent burden of a pre-recorded robocall — prior express consent, and prior express written consent where the call is marketing — on top of every rule that already applied to the call. AI does not create a new regulatory category with its own lighter rules; it lands the call in the strictest existing one.

Which AI calling compliance deadline is the shortest?

Quiet hours, because they are not a deadline at all — they are a precondition checked before each call, and a call placed outside the recipient’s local 8 a.m. to 9 p.m. window under 47 CFR § 64.1200(c)(1) is already a violation the moment it connects. After that the shortest clock is a private one: Gmail and Yahoo expect bulk senders to process a one-click unsubscribe within 48 hours, well inside the ten business days CAN-SPAM allows at 15 U.S.C. § 7704(a)(4)(A) and the ten business days a do-not-call request gets under 47 CFR § 64.1200(d)(3). Erasure is the longest — one month under GDPR Article 12(3), extendable by two further months, and 45 days under Cal. Civ. Code § 1798.130(a)(2).

Do you have to disclose that the caller is an AI?

It depends on the jurisdiction, and the direction of travel is toward yes. No general federal rule compels an AI caller to announce itself as of 16 July 2026 — the FCC proposed one in its Notice of Proposed Rulemaking FCC 24-84, adopted 7 August 2024, and has not adopted it. But 47 CFR § 64.1200(b) already requires every artificial or pre-recorded voice message to identify the business responsible for the call at the start of the message. From 2 August 2026, Article 50(1) of the EU AI Act requires people to be informed that they are interacting with an AI system, at the latest at the time of first interaction, with penalties under Article 99(4) reaching €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. Utah’s Artificial Intelligence Policy Act imposes a narrower duty today: a supplier using generative AI in a consumer transaction must disclose that on a clear and unambiguous request. California’s B.O.T. Act is often cited alongside it but does not apply to calls — Cal. Bus. & Prof. Code § 17940 defines a bot as an “automated online account” and limits “online” to public-facing websites and web or digital applications.

Does compliance software make my outbound program compliant?

No, and a vendor who says otherwise is describing a division of responsibility that does not exist. Software enforces the mechanical rules well: the timezone check before a call is placed, the suppression lookup before a send, the erasure job when a request arrives. It cannot supply the parts that live outside the tool — a lawful consent basis for each contact, a National Do Not Call Registry subscription and the 31-day scrub behind the safe harbor, disclosure scripting for the jurisdictions you actually dial, and record retention such as the five years an internal do-not-call request must be honored under 47 CFR § 64.1200(d)(6). Enforcement by default is a floor, not a certification.

How does Veera enforce these rules by default?

Veera’s AI voice calling is live, and three controls are enforced by default rather than left to the operator. Quiet hours are checked per call against the recipient’s own timezone, so a call outside the local 8 a.m. to 9 p.m. window is not placed. Opt-outs are written to a suppression list that is checked before the next send, and the email path carries a one-click unsubscribe. When a contact asks to be forgotten, their data is erased on request. Veera’s SMS, WhatsApp, and email channels are built and activating rather than live today; the one live send exception is in-call WhatsApp document delivery, which is transactional and bound to an active, consented call. Veera syncs into GoHighLevel and HubSpot two ways rather than replacing them, so opt-out state lands on the contact record your team already reads. These are product controls, not legal advice and not a compliance certification — consent capture, AI disclosure scripting, and Do Not Call Registry subscription remain the operator’s responsibility.

This hub anchors the Veera AI calling compliance cluster. It cites the Telephone Consumer Protection Act (47 U.S.C. § 227), FCC Declaratory Ruling 24-17 and NPRM 24-84 (CG Docket No. 23-362), 47 CFR § 64.1200, the FTC Telemarketing Sales Rule (16 CFR Part 310) and its FY2025 Do Not Call Registry Data Book, Insurance Marketing Coalition Ltd. v. FCC(11th Cir. 2025), the CAN-SPAM Act (15 U.S.C. §§ 7701–7713) with 16 CFR Parts 316 and § 1.98, RFC 8058, Regulations (EU) 2016/679 and 2024/1689, the EDPB's February 2026 erasure report, and the California Consumer Privacy Act. It is general information about the law as of 16 July 2026 — not legal advice, and not a substitute for counsel familiar with your jurisdictions. See also: the Veera glossary.