
How do you know if your vendor is legit?
Key Facts
- AI-generated voices are legally treated as robocalls under TCPA with no exemptions
- Statutory damages for TCPA-violating calls range from $500 to $1,500 per call with no statutory cap
- In August 2025 alone, the FCC removed 185 providers from the Robocall Mitigation Database for non-compliance
- 73% of production AI deployments are affected by prompt injection attacks
- Deepfake voice attacks surged 1,300% in 2024, from ~1 attempt/month to 7/day
- 86% of consumers do not answer calls from unrecognized numbers
- AI disclosure must occur within the first 30 seconds of a call to comply with current state rules
The Hidden Risks of Unverified AI Calling Vendors
Many businesses assume their AI calling vendor handles all compliance, but this misconception creates serious legal and operational exposure. Unverified vendors often lack the regulatory proof and technical controls needed to prevent costly violations, leaving the hiring entity liable for every non-compliant call placed on their behalf.
Working with an unverified AI calling vendor risks TCPA liability of $500 to $1,500 per violating call, with no statutory cap, meaning even a small campaign can trigger six-figure penalties. In August 2025 alone, the FCC removed 185 providers from the Robocall Mitigation Database for non-compliance, resulting in mandatory traffic blocking by other networks—a clear sign that regulatory enforcement is active and escalating. More critically, the Lamb v. Mortgage One Funding precedent establishes that the entity on whose behalf calls are made bears full liability, regardless of which vendor placed the call, making vendor legitimacy a direct shield against financial and reputational harm.
- Vendors unable to produce current SOC 2 or ISO 27001 audit evidence or explain how they handle PCI/PHI data in transit are not ready for regulated calling programs.
- Legitimate vendors enable live demonstrations of their full compliance chain—consent ingestion, DNC scrubbing, disclosure enforcement, and per-call audit export—rather than relying on slide decks.
- The most revealing legitimacy test is asking: "Which parts of compliance remain our responsibility once we sign?"—vendors that answer precisely are easier to trust than those claiming "everything is handled."
My AI Call Center evaluates vendors using these exact criteria to ensure every campaign runs on approved, permissioned lists with full compliance visibility, protecting clients from hidden risks while delivering measurable outcomes.
Four Evidence-Based Criteria to Assess Vendor Legitimacy
Marketing claims are cheap. Evidence is not — and in AI calling, the difference between the two can cost you $500 to $1,500 per violating call, since the FCC treats AI-generated voices as robocalls under the TCPA with no exemptions (per compliance analysis). Four criteria separate vendors that can prove legitimacy from those that merely assert it.
1. Proof of RMD registration and STIR/SHAKEN attestation. Ask for documentation, not verbal assurance. In August 2025 alone, the FCC removed 185 providers from the Robocall Mitigation Database for non-compliance, resulting in mandatory traffic blocking by other networks (enforcement data shows). A vendor without current registration risks your calls being silently dropped before they ring (carrier-filtration research).
2. Current SOC 2 or ISO 27001 audit evidence. A vendor that cannot produce a current audit report or explain how it handles PCI or PHI data in transit "isn't ready for a regulated call program" (compliance guidance notes). One caution: SOC 2 attests to infrastructure security, not TCPA compliance — conflating the two is "a common and expensive mistake" (vendor evaluation analysis).
3. Live demonstration of compliance controls. Trust vendors that show their compliance chain running in real time, not in a slide deck (audit-readiness research). Ask to see:
- Consent ingestion — where consent records enter the system and how they are validated
- DNC scrubbing — how do-not-call requests are captured and enforced across campaigns
- Disclosure enforcement — AI disclosure delivered within the first 30 seconds, as state rules like Texas require
- Per-call audit export — a single call's full compliance trail exported in one file within minutes
At My AI Call Center, this is why list source and consent records are checked before any campaign launches, and why bought lists without clear permission records are flagged or declined.
4. Transparent disclosure of residual responsibilities. The most revealing question is simple: "Which parts of compliance remain our responsibility once we sign?" (vendor evaluation research). A vendor that answers precisely is easier to trust than one claiming "everything is handled." This matters because liability follows the entity on whose behalf calls are made, regardless of which vendor placed them — the lesson of Lamb v. Mortgage One Funding (legal analysis explains).
Vendors that refuse legally risky practices — such as cold outreach to purchased lists — demonstrate legitimacy through what they decline, not just what they promise (industry guidance). Treat that candor as a feature, not an obstacle.
How My AI Call Center Embeds These Legitimacy Signals in Practice
My AI Call Center embeds legitimacy signals directly into its operational workflow to ensure every campaign meets rigorous compliance and security standards. This begins with verifying RMD registration and STIR/SHAKEN attestation before any call is placed, as carriers increasingly filter traffic lacking proper attestation and vendors without registration risk silent call blocking. The company maintains current SOC 2-aligned data controls, including TLS 1.3 encryption, tenant isolation, and immutable audit logging, which are demonstrated through exportable per-call audit trails that clients can review in real time.
Before launch, My AI Call Center conducts a thorough list and consent review, checking source validity and permission records while declining bought lists without clear consent documentation. This disciplined approach ensures only approved, permissioned, or reviewed contacts are called, eliminating indiscriminate outreach. Clients receive explicit clarification of their residual responsibilities—such as maintaining accurate consent records and honoring opt-outs—through the pre-campaign review process, directly addressing the critical question of where compliance obligations reside post-signature.
- Real-time compliance monitoring with exportable audit trails enables live verification of consent ingestion, DNC scrubbing, and disclosure enforcement
- AI disclosure occurs within the first 30 seconds of every call, aligning with Texas state rules and anticipated federal requirements
- Opt-outs and DNC requests are logged immediately and honored across all campaigns, with data retained for the recommended seven-year period
By treating AI-generated voices as artificial voices under TCPA—requiring prior express consent and honoring state-specific quiet hours—My AI Call Center operationalizes the understanding that entities on whose behalf calls are made bear liability regardless of vendor placement. This proactive stance on compliance boundaries, combined with transparent business details including its Halifax and Austin bases and AIQ Labs ownership, provides the verifiable track record and architectural clarity that legitimate vendors must demonstrate. The service never invents metrics or testimonials, reporting only what actually happened in each campaign to maintain trust and accountability.
Frequently Asked Questions
How can I tell if an AI calling vendor is actually legit and not just good at marketing?
If my AI calling vendor breaks TCPA rules, am I liable or are they?
Does SOC 2 certification mean a vendor is TCPA-compliant?
What should I ask a vendor before signing to make sure compliance is covered?
What happens if my vendor isn't registered in the Robocall Mitigation Database?
Are there other signs a vendor is trustworthy beyond compliance paperwork?
Your Shield Against AI Calling Risk
Verifying your AI calling vendor isn't just about checking boxes—it's about protecting your business from real financial and reputational harm. As we've seen, unverified vendors expose you to TCPA liability of $500 to $1,500 per violating call, with enforcement actions like the FCC's removal of 185 non-compliant providers in August 2025 alone proving regulators are actively blocking bad actors. Legitimate vendors prove their legitimacy through RMD registration, current SOC 2 or ISO 27001 evidence, live demonstrations of compliance controls, and transparent clarity about where your responsibilities begin and end. My AI Call Center builds these safeguards into every campaign, ensuring only approved, permissioned lists are used and that compliance chains—from consent ingestion to per-call audit exports—are verifiable in real time. The next step is simple: before your next campaign, ask your vendor exactly which parts of compliance remain your responsibility. If they can't answer precisely, it's time to look for a partner who treats compliance not as a feature, but as the foundation. Learn more about TCPA enforcement trends to strengthen your vendor evaluation process.