Channels

What your AI voice agent needs before it places a call in the US (and what it does not)

The first decision in an AI telephony rollout is not latency or the model. It is what consent you hold for each number on the list, and that framework has moved twice since 2024.

15 min readBy the SignalCore team
OUTBOUND CALLS · DAYALLOWED WINDOW8 a.m. – 9 p.m.Outside hours06912182124ConsentDo-not-call list

An AI voice agent placing outbound calls in the United States is not operating in a legal vacuum, and it is not operating under a ban either. On February 2, 2024 the FCC adopted a declaratory ruling, released on February 8, 2024 in CG Docket No. 23-362, whose operative sentence is a confirmation rather than a prohibition: the TCPA's existing restrictions on artificial or prerecorded voice already reach AI technologies that resemble human voices. The practical consequence is that a synthetic voice call needs prior express consent, and needs prior express written consent the moment it introduces an advertisement or contains telemarketing.

What follows is the operational detail of that regime: which consent applies to which call, what the message has to say in its first seconds, why the calling window runs on the recipient's clock and not yours, where an AI disclosure is genuinely required today, and what it costs when a campaign gets it wrong.

Every claim here comes from a primary source, quoted before it is explained. Where there is no verifiable public answer, we say so instead of filling the gap.

What the FCC actually confirmed in 2024, and who it binds

The Commission adopted the ruling on February 2, 2024 and released it on February 8, 2024, in CG Docket No. 23-362, a docket opened to examine what AI technologies mean for consumers receiving unwanted robocalls and robotexts. The verb the Commission chose matters more than any headline written about it.

Confirm, not declare, and not prohibit. The ruling anchors itself in the Commission's earlier notice of inquiry on AI and places the technology inside a restriction that already existed, rather than building a new category for it. The FCC's own press release said the ruling makes AI-generated voices in robocalls illegal; that is press language, not the language of the order. Calls placed with an AI voice are lawful when the caller holds the consent the rule requires, which is the entire premise of a voice agent business.

The second point is about who carries the obligation. It runs to the caller, meaning the business or the agency that initiates the call. Not the carrier, and not the software. When a campaign goes out on the wrong list, the party that answers to the FCC and to a plaintiff's attorney is the one whose offer was in the script.

That also means no vendor can hand you compliance as a feature, and any vendor claiming to should be read carefully. What a platform can supply is the controls the rule assumes you already have: an identification line at the top of every message, dialing windows set per recipient time zone, suppression lists a live call can write to, and a consent record you can still produce two years later.

we confirm that the TCPA's restrictions on the use of 'artificial or prerecorded voice' encompass current AI technologies that resemble human voices
FCC Declaratory Ruling 24-17, CG Docket No. 23-362, released February 8, 2024

If the 2024 ruling were the whole picture there would be a single consent standard to satisfy. There are two, and the line between them is whether the call carries an offer.

An informational call placed with an artificial or prerecorded voice needs the called party's prior express consent, absent an emergency purpose or one of the exemptions in 47 CFR 64.1200(a)(1) and (a)(3). Those exemptions carry their own limits on frequency and content, which is why nobody should assume an appointment reminder, a collections call or a survey is automatically covered. The second standard is the one that catches most commercial deployments.

If these robocalls introduce an advertisement or contain telemarketing, the Commission's rules require that the caller obtain the prior express written consent of the called party.
FCC Declaratory Ruling 24-17, CG Docket No. 23-362
  1. Who started the contact?If the consumer called you, you are answering, not soliciting, and the do-not-call and calling-hours rules written for telephone solicitations do not attach to that call. If you dial, they do. Two flows, two rule sets, and they do not mix.
  2. Does anything in the script sell?Written consent is triggered by content, not by intent. A satisfaction survey that closes with an upgrade offer became telemarketing at the moment the offer appeared.
  3. Keep the consent record, not just the flagTimestamp, channel, and the exact wording the person saw or heard when they agreed. A boolean in a CRM column proves nothing two years later, and consent is the caller's burden to prove.
  4. Screen against two lists, not oneThe federal registry, whose entries are honored indefinitely, and your own entity-specific do-not-call list. The second one is the one companies forget they are required to keep.
  5. Set the window by the recipient's clock8 a.m. to 9 p.m. local time at the called party's location. On a national list that is a per-record calculation, not a per-campaign setting.
  6. Treat revocation as final and immediateSince April 11, 2025, a revocation made by any reasonable method ends consent. The agent has to recognize it mid-sentence and write to suppression before the call ends.
  7. Write down which consent record each campaign runs onIf you cannot name the source of consent for a list before you dial it, the list is not ready. A campaign launched on the wrong list is a violation per call, not an incident.
Consent required by call type, position as of August 2, 2026
Call typeConsent requiredSourceWhat to watch
Informational call using an artificial or prerecorded voice, AI-generated includedPrior express consentFCC 24-17; 47 CFR 64.1200Exemptions exist in 64.1200(a)(1) and (a)(3), with limits on frequency and content
Call that introduces an advertisement or contains telemarketingPrior express written consentFCC 24-17The written standard has form and disclosure requirements of its own
Telephone solicitation to a number on the National Do Not Call RegistryNot permitted47 CFR 64.1200(c)(2)Registrations are honored indefinitely; the exceptions differ between the FCC rule and the FTC's telemarketing rule
One-to-one consent naming a single sellerNo longer requiredInsurance Marketing Coalition Ltd. v. FCC, No. 24-10277 (11th Cir., January 24, 2025)Vacated before it ever took effect; anything published in 2024 about it is out of date

That last point is where things break in practice. As soon as the same agent handles inbound bookings and also dials lapsed customers, someone reuses the audience that was already loaded in the console. It is the fastest route to a violation nobody intended.

What every automated voice message has to say, and when

Three obligations sit in 47 CFR 64.1200(b), and they attach at three different moments of the same call.

Read the timing, because it drives the script. Identity comes at the beginning of the message, before anything else the agent wants to do. The callback number comes during or after, it cannot be the number the dialer placed the call from, and it cannot cost the consumer more than a local or long distance call. The opt-out has to be automated and interactive, key press or voice activated.

(b) All artificial or prerecorded voice telephone messages shall: (1) At the beginning of the message, state clearly the identity of the business, individual, or other entity that is responsible for initiating the call. (2) During or after the message, state clearly the telephone number (other than that of the autodialer or prerecorded message player that placed the call) ... (3) provide an automated, interactive voice- and/or key press-activated opt-out mechanism for the called person to make a do-not-call request
47 CFR 64.1200(b), 2024 edition of the Code of Federal Regulations

For a voice agent, the third obligation is the one that quietly fails. An automated opt-out is not a model that answers politely when someone says take me off your list. It is a path that recognizes the request, confirms it out loud, and writes to the suppression list before the call ends. Ask your vendor two questions: does that write happen during the call or in a nightly batch, and what happens when the person says it and hangs up in the same breath. If the answer is a transcript that a human reviews later, you do not have an automated opt-out, you have a note.

Now notice what is not in that list. Nothing in 64.1200(b) requires the caller to say the voice is artificial. It requires you to identify the business responsible for the call. Those are two different disclosures, and they get confused constantly, in both directions.

Outbound and inbound do not carry the same rules

The 2024 ruling says nothing about direction, because it did not need to: it attaches to a calling method. The rules that do distinguish are the ones written for telephone solicitations, and those bite only on the calls you place.

The federal calling window is the clearest example, and the clock that counts is not yours.

No person or entity shall initiate any telephone solicitation to: (1) Any residential telephone subscriber before the hour of 8 a.m. or after 9 p.m. (local time at the called party's location)
47 CFR 64.1200(c)(1)

The scope of that section matters as much as the hours. It is written for telephone solicitation, which is commercial in nature, not for every call that exists. A call the consumer requested, or an inbound call your agent answers, sits outside it. That is a real design difference rather than a technicality: the inbound agent can run around the clock while the outbound one runs on a per-time-zone schedule, and treating them as one deployment is exactly how a 6 a.m. dial gets made.

The same asymmetry shows up in the script. An outbound agent has to state a callback number under 64.1200(b), so the callback path is not optional here. Before you launch, check that the number you publish actually reaches something that answers, because you are required to give it and consumers will use it.

Saying it is an AI: what is required today and what is only proposed

This is the most misreported point in the category, so here is the position plainly. At the federal level, as of August 2, 2026, there is no rule requiring you to tell the person that the voice is AI-generated.

There is a proposal. The FCC adopted a notice of proposed rulemaking, FCC 24-84, on August 7, 2024, in the same CG Docket 23-362. Comments closed on October 10, 2024 and reply comments on October 25, 2024.

it proposes to define AI-generated calls, require callers to disclose to consumers when they receive an AI-generated call, ensure consumers affirmatively consent to receive such calls
FCC notice of proposed rulemaking FCC 24-84, adopted August 7, 2024

Proposed, not final. No final rule had been adopted as of August 2, 2026, and every date circulating for one comes from law firm forecasting rather than from the Commission. What federal law does require in the opening seconds is the identity of the business, under 64.1200(b), not the nature of the technology producing the voice.

Two states moved on their own, in opposite directions. California's AB 2905 (2024), Chapter 316, amended Public Utilities Code section 2874 so that the announcement made by an automatic dialing-announcing device has to, in the words of the statute, inform the person called if the prerecorded message uses an artificial voice. The bill defines an artificial voice as one generated or significantly altered by artificial intelligence. It carries no urgency clause, so California's ordinary effective date of January 1, 2025 applies; that date follows from the state's general rule rather than from anything printed in the bill, and it is worth confirming before you rely on it. The duty also hangs on the definition of an automatic dialing-announcing device, which has exemptions of its own that we did not verify, so do not assume it reaches every voice deployment.

Utah went reactive. Under Utah Code 13-75-101 through 13-75-106, created by SB 226 in the 2025 general session and effective May 7, 2025, a supplier using generative AI to interact with an individual in a consumer transaction has to disclose that the individual is interacting with generative AI and not a human if the individual asks. The request has to be clear and unambiguous. Proactive disclosure is narrower: regulated occupations, and high-risk interactions involving health, financial or biometric data or financial, legal, medical or mental health advice, where the disclosure must be given verbally at the start of a verbal interaction. Section 13-75-104 provides a safe harbor for suppliers who disclose clearly and conspicuously at the start and throughout.

One statute to leave alone here. California's bot disclosure law, Business and Professions Code sections 17940 to 17943, is written for the online environment: it defines a bot as an automated online account and requires the interaction to be with a person in California online, and it only bites where there is intent to mislead about artificial identity in order to incentivize a sale or influence a vote. Stretching it to telephone voice is interpretation, not citation. For California voice, the statute is AB 2905.

Whichever way the map moves next, the script that survives all three positions is the one that discloses up front anyway. Two openers you can copy:

Inbound: You have reached the virtual assistant for [company]. I am an automated voice system. If you would rather speak with a person at any point, just say so and I will transfer you. How can I help?

Outbound: Hi, this is [company] calling with an automated voice system about [specific reason for the call]. If you would rather have a person call you back, tell me now and I will note it. Do you have a minute?

Three things this changes in the rest of the script. The disclosure goes before the first question, not at the end of a thirty-second introduction. It is said once, not every third turn. And if the call goes to a person and then comes back to the agent, disclose again, because by then the person on the other end no longer knows who is speaking.

One thing we cannot resolve for you. When an agency resells an agent under its own brand, which party is the caller for TCPA purposes and which is the supplier under Utah's chapter is not answered by any of the sources above. Neither is whether consent captured through a web form, an SMS reply or a chat thread meets the prior express written consent standard, which carries form and disclosure requirements that need review. Those are the first two questions for counsel, not for a blog.

The handoff to a human: what context has to travel with the call

A badly designed handoff is the fastest way to lose the call the agent had already won. The rule is simple: the person who picks up cannot start from zero. If the customer has to repeat their name, their order and their problem, every second the agent saved disappears in the first twenty of the human conversation.

This is the minimum payload that has to travel across. Configure it as required fields, not as a free-text summary.

  • The caller's number and a call identifierSo the call can be returned if it drops, and matched to the recording afterward.
  • The full transcript, plus a three-line summaryThe summary is what gets read in two seconds; the transcript is what gets pulled up when there is a dispute.
  • Detected intent and confidenceA request the agent classified confidently is not the same object as one it could not place.
  • Data the customer already gaveOrder number, policy number, appointment date, whatever it was. Asking for it a second time is the clearest signal that the handoff is broken.
  • What the agent promised, in its own wordsAlmost nobody configures this field, and it is the most important one on the list.
  • Why it escalatedExplicit request, detected frustration, a limit of the automation, or missing data. This one improves the agent, not just the call in front of you.
Inbound call
AI voice agent, business identified at the top of the message
Person with the transcript, the promises made, and the data already loaded

On promises, one decision is worth keeping in mind even though it binds nobody in the United States. In February 2024 the Civil Resolution Tribunal of British Columbia, a Canadian small claims body, ordered Air Canada to pay a customer 812.02 Canadian dollars after its chatbot gave incorrect information about a fare. The airline's position amounted to arguing that the chatbot was responsible for its own actions; the tribunal called that submission remarkable and rejected it, holding that the chatbot is part of the company's website and the company is responsible for all the information on it. It added the part that travels furthest: it saw no reason a customer should have to check one part of a website against another. Not precedent in any US court, but a criterion that keeps reappearing wherever the question is asked. Whoever deploys the agent answers for what it says.

We did not find a verified US decision on the same question in this pass, so we are not claiming one exists. What we would do regardless is log the promise field on every call and review it weekly, because that is where the exposure is created, one sentence at a time.

What it costs to get this wrong: the private right of action

The number that shapes behavior in this market is not an FCC fine. It is the fact that the called party can sue, and that the count runs per call.

The statute gives the recipient the greater of actual monetary loss or $500 for each violation, and lets the court, in its discretion, increase the award to up to three times that amount for willful or knowing violations. The $1,500 figure that circulates is that ceiling, not a standard penalty, and it is not automatic.

What each route can cost, under 47 U.S.C. 227 and Utah Code 13-75
What is breachedRouteConsequenceWho enforces
Artificial or prerecorded voice call without the required consentPrivate suit, 47 U.S.C. 227(b)(3)$500 per violation, which a court may in its discretion increase up to three times for willful or knowing violationsThe called party, in court
Calls to a number on the do-not-call registryPrivate suit, 47 U.S.C. 227(c)(5)Statutory damages per violation, with an affirmative defense for callers who maintain adequate routines and proceduresThe called party, in court
Violation committed with the intent to cause itFCC enforcement, 47 U.S.C. 227(b)(4)(B)An additional penalty not to exceed $10,000, on top of the forfeiture computed under 47 U.S.C. 503(b)(2)FCC
Generative AI not disclosed in Utah after a clear and unambiguous requestUtah Code 13-75-105Administrative fine of up to $2,500 per violation, and up to $5,000 for failing to comply with an orderUtah, administratively

We are deliberately not printing an aggregate maximum for the FCC route. The $10,000 in 227(b)(4)(B) is an addition to a forfeiture calculated under 503(b)(2), whose base amounts are adjusted annually for inflation and which we did not verify. Anyone quoting you a single headline maximum has skipped that step.

The exposure that should actually move your roadmap is arithmetic, not regulation. Five hundred dollars is trivial once. Multiplied across a list of forty thousand numbers dialed on consent you cannot document, it is a class action, and that is the shape this risk takes in practice. It is also why the boring controls matter more than the model: the consent record, the suppression write, the per-time-zone schedule.

One more reason to revisit this page rather than bookmark it. The framework moved twice in eighteen months, the revoke-all waiver runs only to January 31, 2027, and the FCC opened a further notice of proposed rulemaking in October 2025 that could change the revocation rules again.

When an outbound AI voice agent is not worth it

Holding the right consent does not make a campaign a good idea. There are cases where an outbound voice agent subtracts, and they are worth writing down before the project gets signed:

  1. When you cannot show where the consent came fromIf the list arrived with an acquisition, from a partner, or from a form nobody kept a copy of, the risk is not theoretical: damages accrue per call and consent is the caller's burden to prove. Fix the record before you dial, not after the demand letter.
  2. When the offer is the whole point and you only hold informational consentPrior express consent for appointment reminders is not prior express written consent for an offer. Running a sales script through an informational list is the most common way this goes wrong.
  3. When the conversation is bad newsPast-due balances, cancellations, serious service failures, anything with emotional or medical weight. A disclosure that the voice is automated, which is exactly what you should be giving, works against you there for good reason. Have a person call.
  4. When you cannot guarantee a human is available at that momentAn outbound agent that offers to transfer at 8 p.m. with nobody behind it creates more friction than it saves. If there is no coverage, do not offer the exit; schedule the callback instead.
  5. When the volume does not justify the setupConsent records, suppression lists, per-time-zone scheduling, opening disclosures and handoff payloads all carry a fixed cost. On small lists that cost does not amortize and a person does the job better.
  6. When you have not checked the recipient's stateAbove the federal floor, some states narrow the calling window and some add disclosure duties. We verified California and Utah and nothing else, and we are not going to list states we did not read. Call recording is a separate question again, with all-party consent states in the mix, and it is not covered here at all.

How we verified this

The quotations come from primary documents, not from summaries. FCC 24-17 was read on docs.fcc.gov, along with Orders DA 25-312 and DA 26-12 in full. The text of 47 CFR 64.1200 comes from the 2024 edition of the Code of Federal Regulations on govinfo, because the eCFR blocked automated access; confirm the current wording there before you rely on a specific clause. The text of 47 U.S.C. 227 comes from Cornell's Legal Information Institute, and a dollar figure taken from it is worth cross-checking against uscode.house.gov. Utah SB 226 was read in its enrolled version on le.utah.gov, and California AB 2905 on leginfo.legislature.ca.gov.

Three weak points, stated rather than hidden. The Eleventh Circuit decision vacating the one-to-one consent rule is triangulated across Justia and several firm analyses that agree on the holding; we did not read it in the court's own repository, so verify it there before citing the case by name in your own materials. The literal text of the FTC's telemarketing rule at 16 CFR 310.4 came back truncated, so the FTC position is described in paraphrase and only the FCC wording is quoted. And the January 1, 2025 effective date for AB 2905 is inferred from California's ordinary effective-date rule for non-urgency bills, not read in the bill itself.

Things we could not verify and therefore did not write: which states impose calling windows narrower than the federal one, which states beyond California and Utah impose AI disclosure duties, an aggregate maximum for FCC forfeitures, and how enforcement works against a company incorporated outside the United States calling into it. Checked against these sources as of August 2, 2026. Two dates move: the revoke-all waiver expires January 31, 2027 and the FCC's AI disclosure proposal is still pending. This is informational content, not legal advice.

Sources

Every figure in this article comes from one of these sources. If a source changes, the article is revised and the date above is updated.

  1. 1.FCC Declaratory Ruling 24-17, CG Docket No. 23-362 (released February 8, 2024)Confirms that TCPA restrictions on artificial or prerecorded voice reach current AI voice technologies, and sets out the two consent levels.
  2. 2.FCC Order DA 26-12, CG Docket No. 02-278 (adopted January 6, 2026)Extends the waiver of part of 47 CFR 64.1200(a)(10) to January 31, 2027.
  3. 3.47 CFR 64.1200, 2024 edition of the Code of Federal RegulationsIdentification and opt-out duties in (b), calling window in (c)(1), do-not-call registry in (c)(2).
  4. 4.47 U.S.C. 227, Telephone Consumer Protection ActPrivate right of action in (b)(3) and (c)(5); additional penalty for intentional violations in (b)(4)(B).
  5. 5.FCC proposes first AI-generated robocall and robotext rules (NPRM FCC 24-84)The federal AI disclosure requirement is proposed, not final.
  6. 6.California AB 2905 (2024), Chapter 316, amending Public Utilities Code section 2874Requires the announcement to inform the person called if the prerecorded message uses an artificial voice.
  7. 7.Utah SB 226 (2025 General Session), enrolled text creating Utah Code 13-75Reactive disclosure duty, proactive duty for high-risk interactions, safe harbor and penalty amounts.
  8. 8.Insurance Marketing Coalition Ltd. v. FCC, No. 24-10277 (11th Cir., January 24, 2025)Vacated the one-to-one consent rule. Read here and in firm analyses, not in the court's own repository.
  9. 9.Moffatt v. Air Canada, 2024 BCCRT 149 (Civil Resolution Tribunal, British Columbia)Full decision. Canadian small claims body; not precedent in any US court.

Frequently asked questions

Did the FCC make AI voices in phone calls illegal?

No. The declaratory ruling adopted February 2, 2024 and released February 8, 2024 in CG Docket No. 23-362 confirmed that the TCPA's existing restrictions on artificial or prerecorded voice already reach AI technologies that resemble human voices. That places AI voice inside a consent rule that existed before it, rather than creating a prohibition. The illegal framing comes from the FCC's press release, not from the order itself.

What consent does an AI voice call need?

Two levels. An informational call placed with an artificial or prerecorded voice needs the called party's prior express consent, absent an emergency purpose or an exemption. If the call introduces an advertisement or contains telemarketing, the FCC's rules require prior express written consent. The written standard carries its own form and disclosure requirements, so a checkbox somewhere in a signup flow is not a safe assumption.

Do I have to tell people they are talking to an AI?

At the federal level, not as of August 2, 2026. The FCC proposed such a requirement in a notice of proposed rulemaking adopted August 7, 2024, but no final rule has been adopted. California is different: AB 2905 amended Public Utilities Code section 2874 to require that the announcement inform the person called if the prerecorded message uses an artificial voice. Utah requires disclosure when the individual asks, with a clear and unambiguous request.

What hours can an AI voice agent place calls?

Federal rules put telephone solicitations between 8 a.m. and 9 p.m., local time at the called party's location, and the FTC's telemarketing rule sets the same window. The clock that counts belongs to the person receiving the call, so on a national list the window has to be computed per record rather than set once for the campaign. Some states narrow it further.

Is the FCC's one-to-one consent rule in force?

No. The Eleventh Circuit vacated it on January 24, 2025 in Insurance Marketing Coalition Ltd. v. FCC, No. 24-10277, finding that the rule exceeded the FCC's statutory authority, and the Commission then removed the vacated text and reinstated the previous version. The rule had been due to take effect on January 27, 2025 and never applied. Any guide published in 2024 that describes it as current is out of date.

What does a TCPA violation cost?

Under 47 U.S.C. 227(b)(3) the called party can recover actual monetary loss or $500 per violation, whichever is greater, and a court may in its discretion increase the award up to three times that for willful or knowing violations. The $1,500 figure is that ceiling, not a standard penalty. Because the count runs per call, the real exposure on a campaign is a class action rather than a single claim.

Can a software vendor make my calls compliant?

No, and treat any claim otherwise as a warning sign. The obligations run to the caller, meaning the business that initiates the call, not to the platform that generates the voice. What a platform can provide is the controls the rules assume you have: an identification line at the top of the message, per-time-zone dialing windows, suppression lists a live call can write to, and a consent record you can produce later.

Keep reading

All articles