
Is there a law for using AI?
Key Facts
- TCPA fines start at $500 per call
- 95% year-over-year surge in TCPA filings
- Gen Digital paid $9.95 million in TCPA settlement
- FCC proposes real-time AI disclosure rules
- Texas requires AI disclosure within 30 seconds
The Legal Tightrope of AI Voice Calls
Yes — and the consequences of ignoring them can cost millions. AI voice calls sit squarely inside a regulatory framework built decades ago, and regulators have made clear it applies to the newest technology on the block.
The foundation is the Telephone Consumer Protection Act (TCPA), which requires prior express consent for outbound calls using artificial or prerecorded voices. In its 2024 Declaratory Ruling, the FCC confirmed that AI-generated voices count as "artificial or prerecorded voice" under the TCPA. Commissioner Rosenworcel put it bluntly: "the statute does not allow for any carve out of technologies that purport to provide the equivalent of a live agent" (FCC ruling).
The legal test is how the voice is produced, not how human it sounds. As one compliance analysis notes, a call using computational technology or machine learning to generate speech falls under TCPA rules regardless of how natural it seems to the listener. That means consent requirements apply to even the most convincing AI agents.
The stakes are substantial. Statutory damages start at $500 per call and can reach $1,500, with class-action settlements ranging from $5 million to $20 million. Gen Digital paid $9.95 million and Hy Cite Enterprises $4.75 million in TCPA-related settlements, and filings have surged 95% year-over-year (TCPA compliance research).
Beyond the federal baseline, states layer on their own rules:
- Texas requires AI disclosure within 30 seconds of the call starting.
- California prohibits AI from falsely claiming healthcare credentials.
- Florida mandates written consent that specifically references AI use.
Proposed FCC rules would go further, requiring real-time AI disclosure at the start of calls and clearer consent language covering AI-generated voices (FCC proposed rules analysis). Some industry groups, like America's Credit Unions, argue that separate AI consent could confuse consumers and block critical communications such as fraud alerts (industry opposition).
For businesses running AI calling campaigns, the practical takeaway is simple: verify consent before dialing, disclose the AI on every call, and document everything. My AI Call Center applies this approach by reviewing list source and consent records before any campaign launches, and flagging bought lists that lack clear permission records.
Because campaign requirements vary by location, industry, and consent status, businesses should obtain their own legal guidance before launch — the rules are real, and they apply to you.
Compliance as a Competitive Advantage
When the FCC confirms that AI-generated voices count as "artificial or prerecorded voice" under the TCPA, compliance stops being paperwork and becomes a business asset. Statutory damages start at $500 per call, and class-action settlements have reached $5 million to $20 million — numbers that make disciplined consent management worth far more than it costs.
The economics tell the story. Industry compliance analysis shows TCPA filings surging 95% year-over-year, with aggregate verdicts exceeding $925 million. Companies like Gen Digital ($9.95 million) and Hy Cite Enterprises ($4.75 million) paid heavily for consent failures. Every call made without verified permission carries that risk.
This is why list discipline comes before dialing. My AI Call Center runs campaigns only against approved, permissioned, or reviewed contact lists — never indiscriminate cold calling. Before any campaign launches, the list source and consent records are checked. Bought lists without clear permission records are flagged, and in most cases declined. If a list will not support the campaign, clients hear that plainly before spending anything.
The same discipline extends to what happens on the call itself. The FCC's 2024 Declaratory Ruling makes clear that prior express consent is required for AI-voiced calls to U.S. cell phones, and proposed rules would require real-time AI disclosure at the start of each call. Disclosure is built into every script: recipients can ask whether the call is AI-assisted, request a human, or opt out at any point.
Key safeguards that turn legal mandates into structured process include:
- Consent verification before launch, with permission records matched to contact type and campaign purpose
- AI disclosure on every call, aligned with proposed FCC requirements
- Keyword opt-outs (STOP and REVOKE) logged and honored immediately
- DNC requests respected across all campaigns and carried into client DNC records
- State-specific rules honored, including Texas's 30-second disclosure rule and California's restrictions on AI claiming healthcare credentials
Documentation matters as much as the safeguards themselves. Consent interactions, opt-out logs, and disposition records are what defend a business in litigation — a lesson from cases like Lamb v. Mortgage One Funding. That is why every My AI Call Center campaign delivers opt-out and DNC logs alongside a named outcome report with disposition codes.
None of this limits effective outreach — it enables it. Calls that confirm appointments, qualify leads, and retain members work precisely because they reach the right people with proper consent and honest disclosure. As compliance research notes, the legal status of a voice depends on how it is produced, not how human it sounds. Treating that reality as a design principle, rather than an afterthought, is what makes campaigns both lawful and useful. Clients remain responsible for obtaining appropriate legal guidance before launch, since requirements vary by location, industry, and consent status.
Building a Bulletproof AI Calling Process
Knowing the law is only half the battle. The businesses that stay out of TCPA trouble are the ones that build consent, disclosure, and opt-out handling into the calling process itself — before a single dial happens.
Start with consent documentation. The stakes are real: statutory damages start at $500 per call and can reach $1,500, with class-action settlements running from $5 million to $20 million. Marketing calls generally require prior express written consent, while informational calls need prior express consent. Every list should be traceable to a documented permission source — a signed form, a website checkbox, an existing business relationship. Bought lists without clear permission records should be declined, not "cleaned up." Log where each contact came from and what they agreed to, because documentation is your only real defense in a dispute.
Next, build real-time disclosure into every script. The FCC's 2024 Declaratory Ruling classifies AI-generated voices as "artificial or prerecorded voice" under the TCPA, and proposed FCC rules would require AI disclosure at the start of each call. Don't wait for the rules to finalize. State the AI nature of the call upfront, let recipients ask whether the call is AI-assisted, and offer an immediate path to a human or an opt-out.
Finally, adapt to state-specific requirements:
- Texas requires AI disclosure within the first 30 seconds of a call.
- California prohibits AI from falsely claiming healthcare credentials.
- Florida mandates written consent that specifically references AI use.
A campaign that is compliant in one state may be a violation in the next, so scripts and consent language need to flex by geography. Legal analyses also note that a voice's legal status depends on how it is produced, not how human it sounds — so a "very realistic" voice gets no free pass.
This is exactly why My AI Call Center runs a structured pre-launch process: list and consent review, script and disclosure approval, and keyword opt-outs like STOP and REVOKE honored immediately and logged. Nothing launches until the campaign owner approves the script, disclosure, and escalation path. Opt-out and DNC records are carried across all campaigns, so one "stop" ends contact everywhere.
One caution: requirements vary by location, industry, and consent status, and the regulatory landscape is still moving. Engage legal counsel before launching any AI calling campaign — a structured process reduces risk, but it does not replace legal guidance specific to your situation.
Frequently Asked Questions
Is there actually a law that applies to AI voice calls?
Do I still need consent if my AI voice sounds completely human?
What happens if I make AI calls without consent?
Do different states have different rules for AI calling?
Do I have to tell people they're talking to an AI?
How do I make sure my contact list is legally safe to call?
The Legal Floor Is Rising: Make Compliance Your Dialing Strategy
AI voice calls are not in a legal gray zone—they are governed by the TCPA, and the FCC has made clear that machine-generated voices count as artificial voices. Consent must be verified before dialing, disclosure belongs in every script, and state rules like Texas's 30-second notice and Florida's AI-specific written consent add another layer. The cost of ignoring these rules is measurable: statutory damages start at $500 per call, and TCPA filings have surged 95% year-over-year. That is why compliance is not a constraint—it is a competitive advantage. Businesses that document consent, honor opt-outs, and treat disclosure as part of the caller experience can run AI campaigns that confirm appointments, qualify leads, and retain members without building a call center. My AI Call Center applies that discipline before every launch, reviewing list source and consent records and telling clients plainly if a list will not support the campaign. If you are planning an AI calling campaign, start with a free campaign review and get the full picture before you spend.