Is AI Cold Calling Illegal? How to Comply With New FCC Rules & Global Regulations in 2026
8 July 2025

Is AI Cold Calling Illegal? How to Comply With New FCC Rules & Global Regulations in 2026

Is AI Cold Calling Illegal? How to Comply With New FCC Rules & Global Regulations in 2026

If you are using - or planning to use - AI calls to reach your customers, you need to understand what is legally allowed, what has recently changed, and how to protect your business. This guide has been updated for 2026: since it was first published, a federal appeals court has struck down the FCC’s one-to-one consent rule, new consent-revocation rules have taken effect, and several US states have passed their own AI disclosure laws. From the latest FCC guidance in the US to global compliance rules, you’ll learn all the key requirements for AI calls, plus the common pitfalls to avoid and practical steps to stay compliant.

Understanding the New Rulebook: What Changed With the FCC?

Any outbound cold calls made with AI-generated voices - synthetic or cloned voices created with machine learning or other AI tools, as well as with human-prerecorded voices - are defined as “robocalls” and are subject to FCC (Federal Communications Commission) restrictions in the US. 

In February 2024, the FCC issued a declaratory ruling confirming that AI-generated voices count as “artificial voice” under the Telephone Consumer Protection Act (TCPA). That means telemarketing robocalls made with AI voices require prior express written consent of the called party, clear disclosure of who is calling and why, and an immediate opt-out option. This was not a brand-new law - the TCPA already regulated robocalls - but the ruling removed any doubt that AI-generated and cloned voices are covered. The Telemarketing Sales Rule (TSR), which works alongside the TCPA, additionally prohibits deceptive practices and bans calls to numbers on the Do‑Not‑Call Registry.

The 2024-2026 Regulatory Timeline at a Glance

  • February 2024 - the FCC rules that AI-generated voices qualify as “artificial voice” under the TCPA, so all TCPA consent and disclosure requirements apply to AI calls in full.

  • January 2025 - the Eleventh Circuit Court of Appeals vacates the FCC’s “one-to-one consent” rule, which would have required a separate written consent for each individual seller. The rule never took effect, and the FCC formally repealed it later in 2025. A single documented consent can still cover multiple sellers, as long as it is clear and specific.

  • April 11, 2025 - new FCC revocation rules take effect: consumers may revoke consent through any reasonable means (saying “stop” during a call, texting back, using an opt-out form), and businesses must execute the revocation within 10 business days.

  • 2026 - an FCC proposal that would require callers to disclose the use of AI at the very start of a call is still pending. AI disclosure is not yet a separate federal mandate for every call, but several states already require it, and it is standard practice for reputable platforms.

If you last researched this topic in 2024, note the biggest change: the one-to-one consent rule that many compliance articles described as incoming law was struck down in January 2025 and never became effective. Do not build your consent process around a repealed rule - build it around documented prior express written consent, AI disclosure, and fast opt-out execution.

The violation of FCC rules can pose significant fines. In May 2024, the FCC proposed a $6 million fine against political consultant Steven Kramer for using an AI-generated voice of President Biden in robocalls to mislead voters. Additionally, the telecom company that helped send those calls - Lingo Telecom - had to pay $1 million. These cases show that with enforcement getting stronger, businesses that use AI voice calls must be careful or face fines.

Consent, Disclosure, and Opt-Out: The Core Compliance Pillars

For AI calls to be legal according to the FCC rules, you need to consider three compliance pillars: consent, disclosure, and opt-out mechanisms.

The prior express consent should be given through a signature, a written or online form, or an SMS opt-in. The consent must be documented with timestamps, IP addresses, the phone number to be called, and other collected data.

Disclosure comes with the caller identifying themselves and stating the purpose of the call. For calls made using AI or prerecorded voices, the disclosure of AI involvement should be included as well. 

The opt-out mechanism includes some methods for the called party to press a digit, text, or say "STOP” to avoid receiving future calls. Since April 11, 2025, FCC rules require callers to accept consent revocation made through any reasonable means - you cannot limit customers to one designated opt-out channel. The caller must execute this request within 10 business days - otherwise, it may be considered a violation of FCC rules and could lead to significant fines, legal complaints, or further enforcement actions.

US and International Regulatory Comparison

So far, the discussed rules are applicable only to the US. To summarise, the key laws are:

  • TCPA (Telephone Consumer Protection Act) - all robocalls made with AI-generated or prerecorded voices require prior written consent, disclosure, and opt-out methods, as well as Do-Not-Call compliance, caller ID, and timing limits. (Calls can only be made between 8 a.m. and 9 p.m. local time to avoid disturbing recipients during early or late hours.)
  • TSR (Telemarketing Sales Rule) - bans misleading telemarketing calls and requires disclosures and record-keeping for AI calls. Note: the separate FCC “one-to-one consent” rule was vacated by the Eleventh Circuit in January 2025 and formally repealed, so it is no longer part of the compliance baseline.
  • Do-Not-Call Registry - a national list where people can register their phone numbers to avoid unsolicited telemarketing calls. Telemarketers must regularly check the list and avoid calling registered numbers.

Specific states in the US require stricter regulations regarding robocall timelimits, caller IDs, etc. Therefore, make sure to check the laws in the state of the called party - the dedicated state-law section below covers the AI-specific statutes that appeared by 2026.

Globally, the legal landscape for AI calls is similar, with some regions having stricter regulations:

  • Europe/UK PECR (Privacy and Electronic Communications Regulations) - require explicit opt-in consent, meaning individuals must clearly agree - unambiguously and specifically - to receive telemarketing calls. Pre‑checked boxes or vague statements don’t count. Also, under GDPR (General Data Protection Regulation), any call made is treated as data processing, so the law requires the called party to permit the collection and handling of personal data.

  • CASL (Canada’s Anti‑Spam Legislation) - covers AI calls under its Unsolicited Telecommunications Rules, and requires express consent, identified caller ID, and compliance with the national Do-Not-Call List. Additionally, the business is required to keep an internal Do-Not-Call List and keep track of all the calls.

  • Indian UCC (Unsolicited Commercial Communication) Regulations - require telemarketers to use specific number series (like 140/1600) and check calling lists against the National Customer Preference Register (DND). Violations of these rules can lead to fines and call blocking through the TRAI DND app.

  • Australian Spam Act - states that all voice calls must not be fraudulent or spam and must include a valid opt-out method. Similar to other countries, there is a national Do Not Call Register, which prohibits marketing calls to listed numbers unless consent exists. 

Here are the key requirements for each mentioned region:

Region

Consent Required

Disclosure

DNC (Do-Not-Call) Compliance

United States

Written express  consent (documented, signed agreement)

AI disclosure

National DNC

EU/UK

Explicit opt-in

AI disclosure and purpose

National DND

Canada

Express consent (written or oral, can be implied)

Identity disclosure (business name or number) with caller ID

National DNC

India

Registered consent

AI disclosure

National DND

Australia

Express consent (written or oral, can be implied)

AI disclosure

National DNC

State AI Calling Laws in the US: What Changed by 2026

Federal law is only the floor. By 2026, several states have their own AI-specific calling and disclosure requirements, and they apply based on where the called party is located - not where your business is registered:

  • California - AB 2905 (effective January 1, 2025) requires robocalls to disclose when the voice was generated or materially altered by artificial intelligence. Separately, the B.O.T. Act (SB 1001) requires bots to identify themselves when they try to sell something or influence a vote.

  • Utah - the AI Policy Act requires businesses to disclose that a consumer is interacting with generative AI whenever the consumer asks, and proactively in regulated services.

  • Colorado - the Colorado AI Act, taking effect June 30, 2026, imposes risk-management and documentation duties on “high-risk” AI systems; large automated calling operations can fall under these obligations depending on how the calls are used.

  • Florida, Oklahoma, Washington and other “mini-TCPA” states - state telemarketing laws (such as the Florida Telephone Solicitation Act) add their own consent standards, calling-hour limits, and private rights of action on top of the federal rules.

The practical consequence: a national AI calling campaign must be checked against the strictest state on your calling list, not only against the TCPA.

Legal vs Illegal: Common, Edge-Case, and Non-Solicitation Scenarios

So, what AI calls are clearly legal? These are the ones that are directly necessary to the called party, such as appointment reminders, support messages, billing notifications, etc. Emergency alerts or calls with clear social value (public safety updates, government notifications, accessibility services for people with disabilities) are always legal.

Sales, promotions, or cold calls made with AI need prior express consent and all of the previously discussed requirements (AI disclosure, opt-out methods, etc.) in order to be legal. Some grey areas that might be risky are:

  • Implicit consent might not be enough, such as a vague note or a buried checkbox.

  • Existing customer interactions may allow some flexibility, but it is still recommended to follow the same rules as for cold outreach.

  • B2B calls made with AI may also allow some flexibility, but be cautious with misleading or frequent AI calls, which could trigger enforcement.

Compliant vs. Non‑Compliant Scenarios at a Glance

Use Case

Compliant?

Notes

Appointment reminder with AI/prerecorded voice

Allowed without consent

Emergency alert with AI/prerecorded voice

Allowed under emergency exemptions

Cold AI calls without consent 

Requires prior written express consent 

Cold AI calls with implicit consent 

⚠️

Risky - safe to get explicit consent 

Political calls with AI

Illegal with significant fines 

Cold calls with AI disclosures, opt-out methods and consent  

Compliant


Be careful with implicit consent. This can come in the form of informal permission, which is assumed because the customer gave their phone number. For instance, a dentist making an AI call to confirm the appointment works with implicit consent. However, a business using AI to pitch a product without prior explicit consent is illegal.

Business Risks & Enforcement: What’s at Stake?

Violations of AI call regulations can pose the following fines:

  • TCPA (Telephone Consumer Protection Act) violations pose fines of $500-$1500 per call. The amount depends on whether the violation was “willful or knowing.”

  • FCC (Federal Communications Commission) fines for AI or prerecorded voice violations can exceed $23,000 per call. The exact amount is based on severity, intent, volume of calls, history of violations, and the company’s efforts to comply.

  • GDPR (General Data Protection Regulation) violations in Europe can result in fines of up to 4% of the company’s global revenue.

The number of lawsuits related to AI call violations is growing. Court filings increased from 331 to 691 in just one year. Most of these are customer complaints triggered by unsolicited robocalls. Besides fines, robocall complaints can also damage your brand reputation. The trend has continued through 2025 and into 2026: TCPA class actions remain one of the most active areas of US consumer litigation, and AI-voice campaigns are a visible target because the calls are easy to identify and record.

Deploying AI Responsibly: Ethical and Technological Considerations

Despite the legal landscape surrounding AI calls, you might still wonder whether they’re ethical. They absolutely can be as long as you're transparent and honest with your disclosures. Be upfront about using AI and clearly explain the purpose of the call. This helps your business build trust and avoids confusion with your customers.

You should also be aware of the risks of AI errors, which can sometimes introduce bias or lead to discrimination. For example, AI-generated voices might misinterpret certain accents or speech patterns, causing slightly offensive outcomes. To prevent this, regularly test and review your generated voice. 

Human-like AI voices that sound very natural should also be used carefully. Always let the recipient know that the call is made by a bot to avoid misleading them or creating false impressions.

Finally, data privacy is a major concern when it comes to AI-powered calls. Make sure all call records, consent logs, and personal information are stored securely to protect against data leaks or misuse.

Here is a checklist for the responsible use of AI calls:

  • Be transparent about the use of AI during the call
  • Review your AI voice models to check for biases
  • Secure data: use encryption, access controls and privacy procedures

Pathways to Compliance: Practical Steps for Business and Sales Leaders

To deploy AI-powered calls responsibly, inspect your script for proper AI disclosures and test the opt-out methods are working correctly. Verify that consent records are accurate. 

Upon choosing the AI calling platform, ensure the platform offers the following features:

  • AI-voice disclosures at call start

  • Real-time compliance monitoring

  • Encrypted storage of all the call recordings 

  • Rate limits to prevent mass unsolicited calls

When you finally launch AI calls, do not stop compliance monitoring. Use AI compliance tools (such as RingCentral, insight7, etc.) to monitor real-time calls. Stay updated on the updates of AI calls regulations in your country/region.

A practical example of what these controls look like in production: EVE.calls runs outbound AI voice campaigns on protocol scripts - the bot follows an approved conversation flow instead of generating unrestricted answers - records every contact, and holds SOC 2 Type II attestation. TCPA and GDPR requirements (consent lists, disclosure lines, opt-out handling) are part of campaign setup rather than an afterthought. Whichever platform you choose, ask the vendor to demonstrate the same controls before you route a single call through it.

For a broader look at how AI phone calling works in practice - numbers, use cases, and platform selection - see our 2026 guide to AI phone numbers to call.

The last good practice is to join professional associations and compliance-focused organisations (e.g, Linux Foundation's Trustmark Initiative) to stay informed about the best practices. Participate in user forums or advocacy groups to stay updated on all the compliance trends and constantly evolving consumer expectations. 

2026 Compliance Checklist for Outbound AI Calls

Before launching or continuing an outbound AI calling campaign in 2026, verify every item on this list:

  • Prior express written consent is documented for every telemarketing contact (timestamp, source, phone number, and the exact consent text).
  • Your consent process does not rely on the vacated one-to-one consent rule or any other repealed guidance.
  • The call script identifies the caller, states the purpose of the call, and discloses that the voice is AI-generated.
  • Opt-out works through any reasonable channel (voice, keypress, text), and revocations are executed within 10 business days.
  • Calling lists are scrubbed against the National Do-Not-Call Registry and the applicable state registries.
  • Calls go out only between 8 a.m. and 9 p.m. in the called party’s local time, with stricter state windows applied where they exist.
  • State AI disclosure laws (California, Utah, and others) are checked for every state on your calling list.
  • Every call is recorded and stored securely together with the consent log, so you can prove compliance if a regulator asks.

FAQ: AI Cold Calling Legality in 2026

Is AI cold calling legal in the US?

Yes - if it follows TCPA rules: prior express written consent for telemarketing calls, caller identification, and a working opt-out. The February 2024 FCC ruling confirmed that AI-generated voices are treated as “artificial voice” robocalls, so all robocall requirements apply to them in full. Cold AI calls without documented consent are illegal and expose the caller to statutory damages of $500-$1,500 per call.

Do I need consent for AI cold calls?

For telemarketing - yes: prior express written consent from the called party, collected before the call and documented. The one-to-one consent rule (a separate consent per seller) was vacated in January 2025 and later repealed, so a single clear consent can cover multiple sellers. Informational calls such as appointment reminders rely on regular prior express consent, which is a lower standard.

Does the AI have to say it is an AI?

A federal FCC rule requiring AI disclosure at the start of every call is still pending as of 2026, so it is not yet a universal mandate. However, California already requires robocalls to disclose AI-generated or materially altered voices, Utah requires disclosure when the consumer asks, and deception-based liability applies everywhere. In practice, disclosing AI at the start of the call is the standard - and the safe - answer.

What are TCPA fines per call?

Statutory damages are $500 per call, rising to $1,500 per call for willful or knowing violations, and they multiply across every call in a campaign - which is why TCPA class actions settle for millions of dollars. On top of private lawsuits, FCC forfeitures for robocall violations can exceed $23,000 per call.

Are AI cold calls legal in the EU and UK?

Yes, but under stricter conditions than in the US. PECR requires explicit opt-in consent for automated marketing calls, and GDPR treats every call and its recording as personal data processing that needs a lawful basis. GDPR fines can reach 4% of global annual revenue, so EU and UK campaigns need documented opt-in consent and a clear privacy notice before the first call.

Are AI-generated robocalls/cold calls illegal everywhere?

  • No. The AI-generated or prerecorded “robocalls” are legal if they adhere to local laws. In the U.S., the FCC (Federal Communications Commission) requires telemarketing robocalls to have prior express written consent, AI disclosure and opt-out methods. Violation of these rules can make robocalls illegal. Similarly, other regions have their own rules that must be followed.

What’s the legal definition of “AI-generated voice” vs. pre-recorded messages?

  • The FCC in the US defined “AI-generated voice” as any artificial voice created by machine learning, voice cloning, or other AI tools. FCC treats both AI-generated and prerecorded human voice calls as robocalls. 

How do requirements differ for B2B vs. B2C calls?

  • No clear difference is established between B2B and B2C calls currently in the US when AI prerecorded voices are used. In some cases (like the EU), B2B calls might have more relaxed rules, but still the safest practice is to follow the same rules for both types of calls.

How should consent and records be managed and stored?

  • Consent should be documented, but depending on the jurisdiction in your region, it can be written, oral, form-based, etc. It should be stored for at least 5 years, with timestamps, IP addresses and call/web-form logs. 

Can AI calls be used for non-sales purposes?

  • Yes. AI calls can be used for appointment reminders, support notifications, billing alerts, emergency alerts, accessibility services (for people with disabilities) or other high social value messages. In such cases, these calls often do not need strict consent, though they typically still require disclosure and opt-out options. 

What are the top three compliance mistakes businesses make?

  • Assuming implicit consent (e.g, your customer gave their phone number without a clear and documented agreement for AI telemarketing calls)
  • Forgetting to state “This is an AI-generated voice” at the start
  • Weak opt-out mechanisms - not providing a clear, real-time option for your customers to stop calls

What should my company do if we receive a regulatory inquiry?

  • Immediately pause all the AI outbound campaigns.
  • Gather all the audit logs, consent records, and call scripts.
  • Hire a compliance attorney to review the regulator’s notice and the gathered materials.
  • Respond in time and demonstrate your remediation steps.
  • Update your compliance procedures, pivot script if necessary and document all the other changes.

Do you want to automate your cold calls with our AI solutions? Book Consultation

We value your privacy

We use necessary cookies to run the site and, with your consent, analytics and marketing cookies. See our Cookie Notice and Privacy Notice.

Your cookie preferences

Necessary cookies are always on. Choose the rest. You can change this anytime via Cookie settings in the footer.

Strictly necessary

Security, core functions and remembering your choice. Always active.

In the US (for example California), rejecting non-essential cookies also means: do not sell or share my personal information.

Explore cost savings

Access Forbidden
Applications send limit exceeded
Enter a valid first name
Enter a valid last name
Enter a valid phone number
Enter a valid email
Error while saving the request, please contact us directly: team@evecalls.com
You need to give us permission to store and collect data
Thank you for contacting us. We will get back to you soon!

Become A Partner

Access Forbidden
Applications send limit exceeded
Enter a valid first name
Enter a valid last name
Enter a valid phone number
Enter a valid email
Error while saving the request, please contact us directly: team@evecalls.com
You need to give us permission to store and collect data
Thank you for contacting us. We will get back to you soon!