AI Calling Compliance · Updated 16 July 2026
Do-Not-Call & Suppression Lists for AI Outbound Calling (2026)
A suppression list is the set of contacts an outbound system must never dial or message again, and honoring it is a legal duty under the TCPA — not a courtesy. Two separate lists govern AI outbound calling in the United States: the National Do-Not-Call Registry (47 CFR 64.1200(c)(2)), which carries about 258.5 million active registrations, and your internal, company-specific do-not-call list (47 CFR 64.1200(d)), which records people who told you directly to stop.
The two lists are governed by different paragraphs of the same rule, and satisfying one does not satisfy the other. Scrubbing against the National Registry does nothing about a person who told youto stop. Honoring your internal list does nothing about the 258.5 million numbers on the Registry. Both duties run at the same time, and both attach to AI voice calls exactly as they attach to human ones — the FCC’s Declaratory Ruling FCC 24-17(adopted 2 February 2024, released 8 February 2024) confirmed that AI-generated voices are “artificial” under the TCPA, 47 U.S.C. § 227.
The operational rule that follows from all of it is one sentence: check every suppression source before the send, not after. A do-not-call request must be honored within ten business days (47 C.F.R. § 64.1200(d)(3), as amended effective 11 April 2025) and must stay honored for five years (§ 64.1200(d)(6)). Statutory damages are $500 per violation, up to $1,500 where the violation was willful or knowing (47 U.S.C. § 227(c)(5)) — assessed per call, which is why a suppression check that runs a step too late is an expensive place to be wrong.
Two lists, two rulebooks
The most common compliance failure in outbound calling is not ignoring do-not-call rules. It is complying with one list and assuming the other is covered. 47 C.F.R. § 64.1200(c)(2) governs the National Registry; § 64.1200(d) governs the list you keep yourself. They differ on who maintains them, how a number lands on them, how long they last, and how fast you have to act.
| Property | National Do-Not-Call Registry | Internal (company-specific) list |
|---|---|---|
| Governing rule | 47 C.F.R. § 64.1200(c)(2) | 47 C.F.R. § 64.1200(d) |
| Who maintains it | The FTC, through the registry administrator | You do |
| How a number lands on it | The consumer registers once, with the government | The consumer asks your company to stop |
| How long it lasts | Indefinitely — permanent since Pub. L. 110-187 (15 February 2008) | 5 years from the request — § 64.1200(d)(6) |
| Your deadline | Scrub against a version obtained no more than 31 days before the call — § 64.1200(c)(2)(i) | Honor within ten business days — § 64.1200(d)(3) |
| What it costs to get wrong | $500 per violation, up to $1,500 if willful or knowing — 47 U.S.C. § 227(c)(5), assessed per call | |
Two details in that table do more damage than their size suggests.
- The 31-day window is a freshness requirement, not a subscription requirement. The safe harbor at § 64.1200(c)(2)(i) is only available if the Registry version you scrubbed against was obtained no more than 31 days before the call was placed. A list scrubbed once at import and dialed six months later has no safe harbor, because the scrub is stale even though it happened.
- A Registry listing is not an internal request. § 64.1200(d) is triggered by a request made to your entity specifically. The general “stop calling me” a consumer expresses by joining the Registry does not populate your internal list, and a number absent from the Registry can still be on it. Calling that number is still a violation.
The Registry is not a niche list. The FTC’s National Do Not Call Registry Data Book for Fiscal Year 2025, released December 2025, reports about 258.5 million active registrations as of 30 September 2025 — roughly 4.7 million of them added during FY 2025 — alongside more than 2.6 million do-not-call complaints received that year. Registrations stopped expiring when the Do-Not-Call Improvement Act of 2007 (Pub. L. 110-187) was signed on 15 February 2008; before it, numbers dropped off automatically after five years. The FTC still removes numbers that are disconnected and reassigned, which is the one reason the Registry changes underneath you and the reason the 31-day rule exists at all.
Why an AI voice does not get a different rulebook
On 2 February 2024 the FCC unanimously adopted Declaratory Ruling FCC 24-17, released 8 February 2024, confirming that calls using AI technologies to generate human voices are “artificial” within the meaning of the TCPA — including voice cloning that emulates a specific real person. The immediate consequence is a consent requirement: an AI-voiced call falls under 47 U.S.C. § 227(b)(1)(A)–(B) — the cellular and paging provision and the residential-line artificial-voice provision, which FCC 24-17 cites together — and needs prior express consent, and prior express written consent when the call is telemarketing.
The consequence people miss is the one that matters here. FCC 24-17 did not extend do-not-call rules to AI calls, because those rules never turned on who was speaking. § 64.1200(c)(2) asks whether a call is a telephone solicitation to a residential subscriber. § 64.1200(d) asks whether that person asked you to stop. Neither question has a field for “human,” “recording,” or “neural network.” What changed in 2024 is that an AI voice agent now carries the artificial-voice consent duties on top of every duty that already applied — the Registry scrub, the internal list, the calling window under § 64.1200(c)(1), and caller identification under § 64.1200(d)(4), which requires giving the called party the name of the caller, the name of the entity on whose behalf the call is made, and a telephone number or address at which that entity can be reached.
Read the direction of travel correctly: automation is not a compliance discount. It is a volume multiplier applied to a per-call penalty. The reason to build suppression as an enforced gate rather than a campaign setting is that an AI dialer will execute a bad list faster and more completely than a human team ever could.
What counts as an opt-out, and how fast you must honor it
In its consent-revocation order FCC 24-24 (CG Docket No. 02-278, released 16 February 2024), the FCC settled two questions that outbound systems had been answering inconsistently.
First, the words. A consumer revokes consent by replying with stop, quit, end, revoke, opt out, cancel, or unsubscribe. Those seven are a floor, not a ceiling: revocation may be made through any reasonable means, and where a reply uses different words the caller must treat it as valid if a reasonable person would understand it as a request to stop. A system that pattern-matches only on the literal keyword list and ignores “please take me off your list” is not complying — it is failing in a way that is easy to demonstrate from the transcript.
Second, the clock. A revocation must be honored within a reasonable time not exceeding ten business days from receipt. That amendment to § 64.1200(d)(3) took effect 11 April 2025, narrowing a window that had been thirty days. The request must be recorded when it is made, and honored for five years under § 64.1200(d)(6).
One provision of that order is still not in force. The “revoke-all” rule at § 64.1200(a)(10) — which would require a revocation made in response to one kind of message to stop that caller’s future messages on unrelated topics — has been waived since its original 11 April 2025 effective date. On 6 January 2026the FCC’s Consumer and Governmental Affairs Bureau issued a Second Extension Order pushing its effective date to 31 January 2027, while the Commission reviews comments on whether the rule should be modified or replaced. The waiver is narrow: it covers only the unrelated-topics element. Everything else in the revocation rules — the keywords, the ten-business-day window, § 64.1200(d)(3) — has been in force since April 2025.
Building to the waiver is a bad trade. Honoring a revocation across your topics costs you messages a person already asked not to receive; the waiver expires on a date certain, and rebuilding suppression semantics under a deadline is worse than having them now.
Suppression before send is the only checkpoint that counts
Every rule above collapses into a single engineering requirement: the suppression check must be the last thing that happens before a number is dialed or a message leaves. Not at import. Not at campaign build. Not nightly. The gap between when a list is assembled and when it is executed is exactly where opt-outs arrive, and a check that runs at the start of that gap is a check that runs against a list that no longer exists.
Three properties separate a suppression list that works from one that only looks like it works:
- 1.It is a gate, not a filter. A filter is applied to a list when someone remembers to apply it. A gate is in the send path and cannot be routed around, which means a suppressed recipient produces a skipped send and a recorded reason rather than a delivered message and an after-action report.
- 2.It fails toward over-suppression. When the check cannot complete or the data is ambiguous, the defensible default is to skip the send. Over-suppressing costs one message to someone who might have wanted it. Under-suppressing costs $500, multiplied by the size of the list.
- 3.It survives re-ingestion. A suppression that a CRM sync can overwrite is a suppression with an expiry date measured in hours. If a contact is re-imported from a connected CRM, an existing suppression has to outrank the incoming record — otherwise the list heals itself back into a violation.
The channels beyond voice have their own deadlines, and they are tighter than the TCPA’s. For commercial email, the CAN-SPAM Act (15 U.S.C. § 7704) gives you ten business days to honor an opt-out and requires the opt-out mechanism to keep working for at least thirty days after the message was sent. Gmail and Yahoo’s bulk-sender requirements — aimed at senders of roughly 5,000 or more messages a day — took effect in February 2024, but one-click unsubscribe per RFC 8058 (the List-Unsubscribe and List-Unsubscribe-Post headers) carried a later deadline of its own: senders had until 1 June 2024 to implement it, and enforcement began that month. Both providers expect those requests to be processed within two days. The practical deadline is therefore set by the mailbox providers, not by the statute — and unlike the statute, they enforce it by degrading your delivery. Under the GDPR, Article 17 adds a different obligation entirely: erasure on request is not an opt-out you can later reverse, so the record of it has to be permanent even though the personal data is not.
How Veera enforces suppression
Veera’s AI voice calling is live, and the suppression check runs before every send it makes. It is not a campaign setting and not skippable: a suppressed recipient returns a skipped send with a recorded reason instead of being dialed or messaged. Four properties describe what is actually implemented:
- 1.One list, two scopes, either one wins. A suppression can be written agency-wide across the whole organization or scoped to a single client workspace. Both scopes are checked in parallel before a send, and a hit at either scope blocks it. An agency-wide block cannot be undone by a client-level setting.
- 2.Five reasons, recorded at write time. An identifier is suppressed as bounced, complained, unsubscribed, replied, or erasure, with the source that triggered it. Replies suppress automatically — a person who answers should not keep receiving the sequence — and the reason survives for the audit, so “why was this contact skipped” has an answer that does not require reconstruction.
- 3.Erasure is a tombstone, not an opt-out. A suppression written by a GDPR Article 17 erasure request is permanent: the removal path refuses to lift it, and it additionally blocks the contact from being re-ingested by a later CRM sync. Every other reason can be reversed by a genuine opt-in; an erasure cannot, because it is a right the person exercised rather than a preference an operator set.
- 4.The list stores hashes, not addresses. Each entry is keyed by a SHA-256 hash of the normalized identifier, using the same normalization the contact write path uses. Suppression therefore does not require retaining a readable copy of the address of someone who asked to be left alone — which is what makes the tombstone compatible with erasure rather than in tension with it.
Scope, stated honestly. Voice calling is the channel that is live today; SMS and WhatsApp outreach are still being activated and email outreach is building. In-call WhatsApp document delivery — sending a brochure or quote during a live call — is the one send path already running alongside voice. The suppression gate, the one-click unsubscribe implementation, and the erasure cascade are built and enforced in the send path ahead of those channels going live, which is the correct order to build them in and not a claim that the channels are available now.
The honest limit matters more than the feature list: Veera does not scrub the National Do-Not-Call Registry for you. Veera enforces the internal list — the § 64.1200(d) duty. The Registry subscription through the FTC, the scrub against a version obtained within 31 days, and the safe-harbor records under § 64.1200(c)(2)(i) remain yours as the seller or telemarketer. Any platform implying otherwise is describing a subscription it does not hold on your behalf. Veera also enforces TCPA quiet hours per call in the recipient’s time zone, honors CAN-SPAM one-click unsubscribe with suppression checked before every send, and honors GDPR Article 17 erasure requests. None of that is a certification, and this page is not legal advice — these are controls, not a legal opinion about your program.
Veera syncs into the CRM an agency already runs — GoHighLevel or HubSpot — rather than replacing it. Suppression events and call outcomes are written back to the contact record there, so the do-not-call state lives where the rest of the relationship already lives. Veera is free to start.
Frequently asked questions
Does the National Do-Not-Call Registry apply to AI voice calls?
Yes. On 8 February 2024 the FCC issued Declaratory Ruling FCC 24-17, confirming that AI-generated voices are "artificial" within the meaning of the TCPA (47 U.S.C. 227) because a person is not speaking them. The Registry rules at 47 CFR 64.1200(c)(2) turn on whether a call is a telephone solicitation to a residential subscriber — not on whether a human or a synthetic voice does the talking. Using AI does not create a new category of call and does not relax any existing duty; it adds the artificial-voice consent requirements on top of the ones that already applied.
What is the difference between the National Do-Not-Call Registry and an internal do-not-call list?
They are different lists with different rules, and complying with one does not satisfy the other. The National Registry (47 CFR 64.1200(c)(2)) is the government-run list a consumer joins once; registrations are honored indefinitely until the consumer cancels them, and have been permanent since the Do-Not-Call Improvement Act of 2007 took effect in February 2008. An internal do-not-call list (47 CFR 64.1200(d)) records requests made directly to your company — the request must be made to your entity specifically, and a Registry listing is not an internal request. A number absent from the Registry can still be on your internal list, and calling it is still a violation.
How quickly must a do-not-call request be honored?
Within ten business days of receipt, under 47 CFR 64.1200(d)(3). The request must be recorded at the time it is made, and the honoring window narrowed from 30 days to ten business days effective 11 April 2025. Under 47 CFR 64.1200(d)(6) the request must then be honored for five years. For email, the CAN-SPAM Act sets a separate ten-business-day deadline, while Gmail and Yahoo require bulk senders to process one-click unsubscribes within 48 hours — so the practical deadline is often far shorter than the legal one.
Which opt-out keywords must an AI calling system recognize?
In its 2024 consent-revocation order (FCC 24-24, CG Docket No. 02-278), the FCC standardized a set of words that must be treated as an explicit revocation of consent: stop, quit, revoke, opt out, cancel, unsubscribe, and end. A consumer may revoke consent through any reasonable means, so these keywords are a floor rather than a ceiling — a plainly worded request in different words still revokes consent. One related provision, the "revoke-all" rule requiring a revocation on one topic to stop unrelated messages from the same caller, remains waived; the FCC extended that waiver to 31 January 2027 in an order dated 6 January 2026.
Does Veera scrub the National Do-Not-Call Registry for me?
No, and no platform should let you assume otherwise. Veera maintains an internal suppression list scoped to your organization and checks it before every call, but it does not hold a subscription to the National Do-Not-Call Registry on your behalf. Accessing the Registry through the FTC, scrubbing your lists against it, and keeping the safe-harbor records required by 47 CFR 64.1200(c)(2)(i) — including using a Registry version obtained no more than 31 days before the call — remain your responsibility as the seller or telemarketer. Veera enforces the list you build; it does not replace the Registry subscription the rules require.
Do I still need consent if a number is not on the Do-Not-Call Registry?
Yes. Scrubbing against the Registry is necessary but not sufficient. Because FCC 24-17 places AI voices under the TCPA's artificial-voice provisions, a call using an AI voice requires prior express consent, and prior express written consent when the call is telemarketing — regardless of whether the number appears on the Registry. The Registry governs one duty; consent, caller identification under 47 CFR 64.1200(d)(4), calling hours under 47 CFR 64.1200(c)(1), and your internal list are separate duties that apply independently.
This page is part of Veera’s AI calling compliance guide, a reference for the rules that govern automated outreach. Legal citations are to 47 U.S.C. § 227, 47 C.F.R. § 64.1200(c) and (d), 15 U.S.C. § 7704 (CAN-SPAM), RFC 8058, GDPR Article 17, the Do-Not-Call Improvement Act of 2007 (Pub. L. 110-187), FCC Declaratory Ruling FCC 24-17 (8 February 2024), FCC Order 24-24 (CG Docket No. 02-278, 16 February 2024), and the FCC Consumer and Governmental Affairs Bureau Second Extension Order of 6 January 2026; registration figures are from the FTC National Do Not Call Registry Data Book for Fiscal Year 2025. Reviewed 16 July 2026. This page describes the suppression enforcement Veera implements and the rules it is built against. It is not legal advice, and it is not a substitute for counsel who knows your program. See also: What is an AI Business Aide? and State of Outbound Business AI 2026.