Compliance · Updated 16 July 2026
Is AI Cold Calling Legal? TCPA, DNC & AI-Disclosure Rules (2026)
AI cold calling is legal in the United States when the call has a lawful consent basis, runs inside the recipient's local 8 a.m.–9 p.m. window, is scrubbed against the National Do Not Call Registry before dialing, and identifies the business responsible for it. It is illegal robocalling the moment any one of those four fails. The technology is not what decides it. Consent, timing, list hygiene, and identification decide it.
The pivotal authority is FCC Declaratory Ruling 24-17 (CG Docket No. 23-362), adopted unanimously on 2 February 2024 and released on 8 February 2024. It held that AI-generated voices are “artificial”under the Telephone Consumer Protection Act, 47 U.S.C. § 227 — which has restricted artificial and pre-recorded voice calls since 1991. An AI voice agent therefore carries exactly the same consent burden as a pre-recorded robocall: prior express consent for any artificial-voice call, and prior express writtenconsent when the call is telemarketing. Get it wrong and 47 U.S.C. § 227(b)(3) prices each call at $500 — an amount a court may, in its discretion, increase to up to three times that, $1,500, if the violation was willful or knowing.
AI cold calling is outbound telephone outreach in which the voice on the call is generated by software rather than spoken by a person, placed to a recipient who has not requested the call.This page sets out what the law actually requires, where the widely-repeated “B2B is exempt” belief breaks, and what changes on 2 August 2026 in the EU. It is general information, not legal advice.
What the FCC actually ruled in February 2024
In January 2024, voters in New Hampshire received a call using a cloned voice of President Biden telling them to skip the state primary. The FCC responded within a month — not by writing an AI statute, but by applying the one already on the books.
Declaratory Ruling FCC 24-17 found that AI technologies such as voice cloning “fall within the TCPA's existing prohibition on artificial or prerecorded voice messages because this technology artificially simulates a human voice.” The Commission grounded that in the ordinary meaning of the statute and in case law describing an artificial voice under the TCPA as “a sound resembling a human voice that is originated by artificial intelligence.” The reasoning is blunt: the voices are artificial because a person is not speaking them.
Three consequences follow, and they took effect on release rather than after a phase-in:
- Consent attaches. Callers must obtain prior express consent before placing a call that uses an artificial or pre-recorded voice generated through AI. For telemarketing and advertising, 47 CFR § 64.1200(a)(2) raises that to prior express written consent.
- Identification attaches. 47 CFR § 64.1200(b) requires every artificial or pre-recorded voice message to state the identity of the business responsible for the call at the start, and to give a callback number.
- Opt-out attaches. Where the message introduces an advertisement or constitutes telemarketing, it must offer an automated, interactive opt-out mechanism.
What the ruling did not do is ban AI voices. It classified them. Unconsented AI robocalls became unambiguously illegal; consented AI calls remained lawful. That distinction is the whole subject of this page.
The four tests that decide legality
Every compliant outbound AI calling program passes the same four tests. They are cumulative — passing three is failing.
| Test | Authority | What it requires |
|---|---|---|
| Consent | 47 U.S.C. § 227(b)(1); 47 CFR § 64.1200(a)(2) | Prior express consent for any artificial-voice call; prior express written consent when the call is telemarketing or introduces an advertisement. |
| Calling window | 47 CFR § 64.1200(c)(1) | No telephone solicitation before 8 a.m. or after 9 p.m., local time at the called party's location — not the time zone implied by the area code. |
| List scrubbing | 47 CFR § 64.1200(c)(2), (d) | Suppress the National Do Not Call Registry and your own internal company-specific do-not-call list before dialing — and keep a written policy for the latter. State do-not-call lists are a separate obligation arising under state law. |
| Identification & opt-out | 47 CFR § 64.1200(b) | Name the business responsible at the start of the message, give a callback number, and offer an automated opt-out on telemarketing calls. |
The scrubbing test is the one operators most often underestimate. The FTC's National Do Not Call Registry Data Book for Fiscal Year 2025, released in December 2025, reports roughly 258.5 million active registrations as of 30 September 2025 — about 1.9% more than FY2024, with over 4.7 million numbers added during the year. That is not a niche list. It is most of the reachable US phone population, and it is the first thing a plaintiff's lawyer checks.
The consent test also runs in reverse. In FCC 24-24, adopted in February 2024 and effective 11 April 2025, the Commission confirmed that a consumer may revoke consent by any reasonable means. The words stop, quit, end, revoke, opt out, cancel and unsubscribe must be treated as revocation, other phrasings are not precluded, and the request must be processed within a reasonable time not exceeding 10 business days. One element remains waived: the requirement that a revocation made in response to one type of informational message be applied across the sender's unrelated messaging programs (47 CFR § 64.1200(a)(10)). The FCC extended that waiver a second time on 6 January 2026 — Order DA 26-12 — to 31 January 2027. Everything else above — reasonable-means revocation and the 10-business-day deadline — has been in force since 11 April 2025.
One test that disappeared: the FCC's one-to-one-consent rule, which would have required consent to name a single seller, was vacated by the Eleventh Circuit in Insurance Marketing Coalition Ltd. v. FCC, No. 24-10277 (11th Cir. 24 January 2025), on the day before it was to take effect. The court held the FCC had exceeded its statutory authority: to give prior express consent, a person need only “clearly and unmistakably” state beforehand that they are willing to receive the call. Bundled consent survives — but the underlying TCPA requirements did not move an inch.
The legal difference between compliant B2B outreach and illegal robocalling
Here is the most expensive misconception in outbound: that “we only call businesses” is a legal defence. It is a partial one, and the part it misses is the part that matters for AI voice.
The FTC's Telemarketing Sales Rule (16 CFR Part 310) genuinely does exempt most business-to-business calls. Section 310.6(b)(7) exempts telephone calls between a telemarketer and a business to induce the purchase of goods or services, with a carve-out for retail sales of nondurable office or cleaning supplies. That exemption is real — and it is an exemption from the FTC's rule, not the FCC's statute. The TCPA has no equivalent B2B carve-out for artificial voice.
Read the TCPA text closely. Section 227(b)(1)(A)(iii) restricts calls using an artificial or pre-recorded voice to any telephone number assigned to a cellular telephone service. It does not ask who pays the bill or whether the handset sits on a desk. And under 47 CFR § 64.1200(e) and the FCC's 2003 Report and Order, a wireless number listed on the Do Not Call Registry is presumptively residential — a presumption rebuttable only case by case, and one that courts have continued to litigate. Meanwhile the TSR exemption itself reaches calls to induce a sale to a business entity, not to individuals employed by it.
So the modern B2B prospect — a decision-maker whose “work phone” is a personal mobile — sits in the exact gap where the TSR exemption stops and the TCPA keeps going. Dialing that number with an AI voice and no consent is the single most common way a program that calls itself B2B becomes a TCPA case.
| Dimension | Compliant B2B AI outreach | Illegal AI robocalling |
|---|---|---|
| Consent basis | Prior express written consent captured, logged, and revocable | None — a scraped or purchased list |
| Number type | Business landline, or a mobile with consent on file | Any mobile, unscrubbed, assumed exempt because “it's B2B” |
| Timing | Recipient's local 8 a.m.–9 p.m., resolved per call | Whenever the dialer happens to run |
| Identification | Business named in the first seconds, callback number given | Anonymous or spoofed caller ID |
| Opt-out | Honored by any reasonable means, within 10 business days | Ignored, or buried behind a phone tree |
| Exposure per call | Managed; consent record is the defence | $500 per call, which a court may increase to as much as $1,500 if willful or knowing — under § 227(b)(3) |
Notice what is not in that table: the word AI. Every row applies identically to a human rep with a power dialer. The AI changes the volume, not the rules — which is precisely why it changes the stakes. Damages accrue per call, so exposure scales linearly with the thing AI is best at.
Do you have to say it is an AI?
Federal law does not yet have a general answer. Every trend line says the answer is becoming yes.
- Federal (proposed). The FCC's Notice of Proposed Rulemaking FCC 24-84(CG Docket No. 23-362, adopted 7 August 2024, released 8 August 2024) proposes to define an “AI-generated call,” to require callers to disclose AI use at the start of such calls, and to require that disclosure during the consent process. It also proposes to exempt people with hearing and speech disabilities who use AI voices on non-advertising calls. As of July 2026 it remains a proposal, not a rule.
- Federal (already binding). 47 CFR § 64.1200(b) already requires an artificial-voice message to identify the business responsible for the call. You do not have to say “I am an AI” federally; you do have to say who is calling.
- Utah.The Artificial Intelligence Policy Act (S.B. 149, effective 1 May 2024, amended by S.B. 226, effective 7 May 2025) requires a person using generative AI in a consumer transaction to disclose that fact in response to a clear and unambiguous request. For regulated occupations, disclosure must come at the outset — and orally when the interaction is verbal. S.B. 226 added a safe harbor: no enforcement for disclosure failures if the AI itself clearly and conspicuously identifies as non-human at the start of and throughout the interaction.
- California.The Bolstering Online Transparency (B.O.T.) Act (S.B. 1001, Bus. & Prof. Code §§ 17940–17943, effective 1 July 2019) makes it unlawful to use a bot to mislead a person in California about its artificial identity in order to incentivize a sale, with a safe harbor for disclosure that is clear, conspicuous, and reasonably designed to inform. Its text reaches bots operating online, which § 17940 defines by reference to public-facing websites and applications — so its reach over a voice phone call is unsettled rather than established.
- European Union (binding from 2 August 2026). Article 50(1) of the EU AI Act (Regulation (EU) 2024/1689) requires AI systems intended to interact directly with natural persons to be designed so that those persons are informed they are interacting with an AI system — unless it is obvious to a reasonably well-informed, observant and circumspect person. Article 50(5) requires that information to be given clearly and distinguishably “at the latest at the time of the first interaction or exposure.” An AI voice good enough to be worth deploying is, by construction, not “obvious.”
Be careful with secondary sources here. A widely-repeated claim that Texas S.B. 140 imposes a 30-second AI-disclosure requirement does not survive reading the bill: S.B. 140 (89th Legislature, effective 1 September 2025) expands the Texas telephone-solicitation regime to cover text and multimedia messages and adds a Deceptive Trade Practices Act hook. It is a telemarketing-registration law, not an AI-disclosure law.
The operational conclusion is straightforward. Disclosure costs one sentence at the top of the call. It eliminates an entire category of exposure, it satisfies Utah's safe harbor and the EU's Article 50 in one move, and it pre-complies with the rule the FCC has already proposed. Disclose.
Calling into the EU: GDPR still applies
The EU AI Act governs whether you must announce the AI. The GDPR (Regulation (EU) 2016/679) governs the data underneath the call, and it applies whether the caller is a person or a model.
- Article 21(2) — objection to direct marketing. Where personal data is processed for direct marketing, the data subject has the right to object at any time, and once they object the processing must stop. There is no balancing test to run and no grace period to argue over.
- Article 17 — right to erasure. A contact can require their personal data to be erased, including where they have objected under Article 21. Your outbound stack has to be able to actually delete, not just flag.
- A record you can produce. Where you rely on consent, you must be able to demonstrate it. Call recordings and transcripts are themselves personal data, and in some jurisdictions voiceprints attract separate biometric regimes.
The through-line across all of it — TCPA, TSR, the AI Act, the GDPR — is that the obligations are per contact and per call. They cannot be satisfied by a policy document. They have to be enforced by the system that places the call.
How Veera handles this
Veera's AI voice calling is live, and three compliance controls are enforced by the platform rather than left to the operator to remember:
- Quiet hours, per call, timezone-aware. Every call is checked against the recipient's own local window before it is placed — resolved from the contact's timezone, not the sender's clock and not an area-code guess. This is the 47 CFR § 64.1200(c)(1) test, applied at dial time.
- Suppression before send. An opt-out is written to a suppression list that is checked before the next send, so a revocation cannot be outrun by a queued message. The email path ships with a CAN-SPAM one-click unsubscribe header (RFC 8058
List-Unsubscribe-Post) wired in. - Erasure on request. When a contact asks to be forgotten, their data is erased — the Article 17 mechanic, implemented rather than promised.
Being precise about what these controls are — and are not. They are product controls. They are not legal advice, not a compliance certification, and not a claim of blanket GDPR compliance. Veera does not capture consent for you, subscribe to the Do Not Call Registry on your behalf, or write your AI-disclosure script. Those remain the operator's responsibility, and you should confirm your obligations for your own jurisdictions.
Being honest about what is live. AI voice calling is live today. SMS, WhatsApp, and email as standalone outbound channels are built and activating — we describe them as launching, not as things you can run today. The one live send exception is in-call WhatsApp document delivery, which is transactional and bound to an active, consented call.
Consent state is only useful where your team already looks. Veera syncs into GoHighLevel and HubSpot two ways rather than replacing them, so opt-outs and call outcomes land on the contact record in the CRM your agency already runs — not in a second system nobody checks before dialing. Veera is free to start.
Frequently asked questions
Is AI cold calling legal in the United States?
Yes, with conditions. AI cold calling is legal when the call has a lawful consent basis, runs inside the recipient’s local 8 a.m. to 9 p.m. window under 47 CFR 64.1200(c)(1), is scrubbed against the National Do Not Call Registry and the caller’s own internal suppression list before dialing, and identifies the business responsible for the call under 47 CFR 64.1200(b). It becomes illegal robocalling the moment any one of those fails. The FCC’s Declaratory Ruling FCC 24-17, released 8 February 2024, confirmed that AI-generated voices are “artificial” under the TCPA, so an AI voice agent carries the same consent burden as a pre-recorded robocall. This is general information, not legal advice.
Did the FCC make AI voice calls illegal in 2024?
No. Declaratory Ruling FCC 24-17 (CG Docket No. 23-362, adopted 2 February 2024, released 8 February 2024) did not ban AI voices — it classified them. The Commission held that AI technologies such as voice cloning fall within the TCPA’s existing prohibition on artificial or prerecorded voice messages because the technology artificially simulates a human voice. The practical effect is that an AI-generated call needs the same prior express consent as any other artificial or pre-recorded voice call. Unconsented AI robocalls became unambiguously illegal; consented ones remained lawful.
Does the TCPA have a business-to-business exemption for AI calls?
Not the one most people assume. The FTC’s Telemarketing Sales Rule exempts most business-to-business calls at 16 CFR 310.6(b)(7), but that is an exemption from the TSR — not from the TCPA. TCPA section 227(b)(1)(A)(iii) restricts artificial or pre-recorded voice calls to any number assigned to a cellular service, and it does not ask whether the handset is used for business. Under 47 CFR 64.1200(e) and the FCC’s 2003 Report and Order, a wireless number listed on the National Do Not Call Registry is presumptively a residential subscriber, rebuttable only case by case. Dialing a prospect’s mobile with an AI voice and no consent is the most common way a program that calls itself B2B becomes a TCPA case.
Do you have to disclose that the caller is an AI?
It depends on the jurisdiction, and the direction of travel is toward yes. No general federal rule compels an AI caller to announce itself as of July 2026; the FCC proposed one in its Notice of Proposed Rulemaking FCC 24-84 (adopted 7 August 2024), which is still a proposal. But 47 CFR 64.1200(b) already requires every artificial or pre-recorded voice message to identify the business responsible for the call. Utah’s Artificial Intelligence Policy Act (SB 149, effective 1 May 2024, amended by SB 226 effective 7 May 2025) requires a person using generative AI in a consumer transaction to disclose that fact on a clear and unambiguous request, and to disclose it up front and orally in regulated occupations. From 2 August 2026, Article 50(1) of the EU AI Act requires people to be informed that they are interacting with an AI system, at the latest at the time of first interaction.
What are the penalties for an illegal AI robocall?
Under 47 U.S.C. 227(b)(3) a private plaintiff recovers actual monetary loss or $500 per violation, whichever is greater. For a willful or knowing violation the court may, in its discretion, increase that award to an amount not more than three times the base — so $1,500 per call is the ceiling, not an automatic penalty. Each call is a separate violation, so exposure scales linearly with dial volume — which is why TCPA claims aggregate into class actions. The FCC and state attorneys general bring enforcement actions independently of any private suit.
How does Veera handle TCPA and DNC compliance on AI calls?
Veera’s AI voice calling is live, and three controls are enforced by default rather than left to the operator. Quiet hours are checked per call against the recipient’s own timezone, so a call outside the local 8 a.m. to 9 p.m. window is not placed. Opt-outs are written to a suppression list that is checked before the next send. When a contact asks to be forgotten, their data is erased on request. Veera’s SMS, WhatsApp, and email channels are built and activating rather than live today; the one live send exception is in-call WhatsApp document delivery, which is transactional and bound to an active, consented call. These are product controls, not legal advice and not a compliance certification — consent capture, AI disclosure scripting, and Do Not Call Registry subscription remain the operator’s responsibility.
This page is part of the Veera AI calling compliance hub. It cites the Telephone Consumer Protection Act (47 U.S.C. § 227), FCC Declaratory Ruling 24-17 and NPRM 24-84 (CG Docket No. 23-362), 47 CFR § 64.1200, the FTC Telemarketing Sales Rule (16 CFR Part 310) and its FY2025 Do Not Call Registry Data Book, Insurance Marketing Coalition Ltd. v. FCC (11th Cir. 2025), the Utah Artificial Intelligence Policy Act, and Regulations (EU) 2024/1689 and 2016/679. It is general information about the law as of 16 July 2026 — not legal advice, and not a substitute for counsel familiar with your jurisdictions. See also: the Veera glossary.