
What are the disadvantages of text messaging?
Key Facts
- One noncompliant text can cost $500 to $1,500 in statutory damages, with no cap on total liability according to Purdue Global Law School.
- Recipients need not prove actual harm — simply receiving a noncompliant text is enough to win a judgment, making bulk texts ideal for class actions per legal analysis.
- On July 21, 2025, two federal courts issued directly conflicting rulings on whether Do-Not-Call protections apply to texts legal commentators observed.
- Connecticut's mini-TCPA imposes penalties up to $20,000 per texting infraction per Purdue Global Law School.
- Florida and Oklahoma cap texts at 3 per subject per rolling 24-hour period, inside an 8 AM–8 PM window per state-law research.
- Virginia requires opted-out numbers to stay on do-not-text lists for 10 years per Purdue Global Law School.
- SMS's 160-character limit makes fitting required disclosures and opt-out language into a single text difficult according to industry research.
The Regulatory Minefield: Why Text Messaging Carries Outsized Legal Risk
One noncompliant text message can cost a business up to $1,500 — and a campaign sent to thousands of numbers multiplies that exposure with no ceiling. That is the core regulatory problem with text messaging, and it is getting worse, not better.
Under the federal Telephone Consumer Protection Act, statutory damages run $500 per violation, rising to $1,500 for willful violations, with no aggregate cap on liability. As legal analysis from Purdue Global Law School notes, a consumer doesn't need to prove actual damages — simply receiving a noncompliant text is enough to win a judgment. And because texts go out in bulk, these cases are "perfectly suited for class action certification," meaning one bad blast could mean a multimillion-dollar lawsuit.
The state layer makes it worse. The TCPA does not preempt state law, so a business can face federal and state claims simultaneously. State "mini-TCPA" laws impose rules stricter than anything at the federal level:
- Florida and Oklahoma cap frequency at 3 texts on the same subject per rolling 24-hour period, inside an 8 AM–8 PM window.
- Connecticut allows penalties up to $20,000 per infraction, with a 9 AM–8 PM calling window.
- Texas requires a $200 telemarketer registration fee plus a $10,000 bond when consent documentation is unclear, with penalties up to $5,000 per text.
- Virginia requires opted-out numbers to stay on do-not-text lists for 10 years.
Worse still, Florida, Maryland, and Oklahoma apply a rebuttable presumption that a consumer with an in-state area code is physically in that state. Proving otherwise is expensive, so companies are, in the words of one legal analysis, "economically forced" to comply with every state's strictest rules. The Supreme Court's Facebook v. Duguid ruling narrowed the federal autodialer definition — but those same states ban any automated dialing system outright, destroying that defense locally.
Then there is the post-McLaughlin chaos. After the Supreme Court's June 2025 decision stripped judicial deference to FCC interpretations, two federal courts issued directly conflicting rulings on the same day — July 21, 2025 — on whether Do-Not-Call protections even apply to texts, as legal commentators observed. The Ninth Circuit has since certified the question for appeal in Dilanyan v. Hugo Boss, staying the case — a move that Mintz's compliance team notes may open the door to similar stays. Until appellate courts or Congress act, businesses face forum shopping and heightened litigation risk with no clear rule to follow.
This is why consent documentation has become the primary defense. Auditable consent records — what compliance experts call the strongest protection available — are now the price of admission. It's also why My AI Call Center reviews list source and consent records before any campaign launches, and declines lists that can't support a defensible campaign.
Operational Burdens That Compound Compliance Exposure
Operational compliance for text messaging creates a layered burden that directly increases regulatory exposure. Businesses must register every texting number—whether A2P, 10DLC, short code, or toll-free—with wireless carriers as a prerequisite to sending messages, a step that adds administrative overhead and ongoing maintenance requirements. Beyond registration, companies are required to retain detailed consent logs for at least five years, with some industry regulations mandating even longer retention periods, turning routine messaging into a long-term record-keeping obligation. Before any message is sent, numbers must be scrubbed against both the National Do Not Call Registry and the Reassigned Number Database to avoid contacting individuals who have opted out or whose numbers have been recycled, a process that demands real-time validation tools and continuous database updates.
These operational demands are compounded by strict opt-out handling rules: businesses must automate immediate processing of STOP, END, CANCEL, UNSUBSCRIBE, and QUIT keywords, as continued texting after any of these signals is treated as a willful violation under the TCPA, carrying penalties of up to $1,500 per message. The technical constraints of SMS further complicate compliance—messages are limited to 160 characters, making it difficult to include required disclosures, opt-out instructions, and business identification within a single text, especially when state laws like California’s mandate clear advertising labels and business names. MMS support varies by carrier (typically 550 KB to 1 MB), and RCS functionality remains inconsistent due to dependencies on both carrier and device compatibility, creating fragmentation that undermines uniform compliance efforts. For organizations managing approved, permissioned lists—such as those served by My AI Call Center through structured calling campaigns—these cumulative burdens highlight why voice-based outreach on vetted lists can offer a more predictable compliance path, avoiding the character limits, registration complexity, and fragmented opt-out mechanics inherent in text messaging.
- Carrier registration is required for all A2P, 10DLC, short code, and toll-free texting numbers
- Consent logs must be retained for at least five years, with some industries requiring longer
- Numbers must be scrubbed against DNC and reassigned-number databases before every send
- STOP, END, CANCEL, UNSUBSCRIBE, and QUIT keywords require immediate automated handling
- SMS is capped at 160 characters, constraining space for required disclosures and opt-out language
State-by-State Patchwork: Building for the Strictest Standard
State-by-State Patchwork: Building for the Strictest Standard
Navigating text message compliance requires more than just meeting federal TCPA minimums; businesses face a complex patchwork of state laws that often impose stricter requirements. Florida and Oklahoma, for example, cap texts at three per subject within a rolling 24-hour period and restrict messaging to an 8 AM–8 PM window in the recipient’s time zone according to Purdue Global Law School. Connecticut narrows the allowable window further to 9 AM–8 PM and levies penalties of up to $20,000 per infraction as reported by the same source. Texas adds a $200 telemarketer registration fee, a mandatory $10,000 bond, and allows penalties up to $5,000 per text under its Deceptive Trade Practices Act per Purdue Global Law School. Virginia mandates that opted-out numbers remain on do-not-text lists for a full ten years, significantly extending data retention burdens per Purdue Global Law School. Meanwhile, California requires every commercial text to include the sender’s business name and a clear disclosure that the message is an advertisement as noted in the research.
- Florida/Oklahoma: 3 texts per 24-hour cap, 8 AM–8 PM window
- Connecticut: 9 AM–8 PM window, $20,000 per infraction
- Texas: $200 fee + $10,000 bond, up to $5,000 per text penalty
- Virginia: 10-year opted-out number retention
- California: mandatory business name and ad disclosure
Because states do not yield to federal preemption on these matters, a single noncompliant message can trigger liability under both TCPA and state law simultaneously. For organizations running national campaigns, engineering to the strictest applicable standard — whether it’s Texas’s bonding requirement, Virginia’s decade-long opt-out retention, or Florida/Oklahoma’s frequency cap — is not optional; it’s the only way to avoid multimillion-dollar exposure from statutory damages that can reach $1,500 per willful violation with no aggregate cap per Purdue Global Law School. At My AI Call Center, this principle guides our approach: we build calling and texting campaigns around the most restrictive rules in play, ensuring compliance across jurisdictions while protecting clients from avoidable legal risk. This disciplined, standards-based method turns regulatory complexity into a competitive advantage for businesses that prioritize trust and traceability in every outreach effort.
Consent Documentation as the Primary Defense
A single noncompliant text can cost $500 to $1,500 in statutory damages, and a consumer doesn't need to prove actual harm to win — receiving the noncompliant message is enough. That asymmetry is why compliance experts describe auditable consent records as the strongest defense a business can hold. If you text, your consent documentation isn't paperwork. It's your lawsuit shield.
For promotional texts, the TCPA demands prior express written consent that cannot be a condition of purchase. According to legal analysis from Purdue Global Law School, that consent is invalidated if the opt-in fails to disclose any of the following:
- The program or campaign name
- The expected message frequency
- The "message and data rates may apply" warning
- Direct links to your Terms of Service and Privacy Policy
Miss one disclosure and the consent you collected may be worth nothing. Worse, under state mini-TCPAs in Florida, Maryland, and Oklahoma, each text without a specific, signed opt-in form carries immediate statutory liability.
Many businesses assume appointment reminders, account notices, and survey requests sit outside the rules. They don't. The same Purdue Global analysis notes that non-promotional texts still require prior express consent — a lower bar than written consent, but a bar nonetheless. Sending "helpful" reminders to numbers you pulled from an old spreadsheet, without consent records, creates the same exposure as a marketing blast.
Consent belongs to a person, not a phone number. Compliance guidance is explicit that the Reassigned Number Database must be checked before sending texts to numbers that may have changed hands. A number that consented two years ago may now belong to a stranger — and that stranger can sue. Skipping this check before each send turns your oldest, "safest" list into your riskiest.
This is why a pre-launch list and consent review matters more than any tool. My AI Call Center applies the same discipline to calling campaigns: list source and consent records are checked before launch, and bought lists without clear permission records are flagged — in most cases, declined — before a client spends anything. The same logic applies to texting. Consent logs must be retained at least five years, per the federal record-keeping requirements, so build the audit trail the day consent is captured — not the day a complaint arrives.
A Lower-Uncertainty Alternative: Structured Voice Outreach on Approved Lists
The regulatory ground under text messaging keeps shifting. Two federal courts issued directly conflicting rulings on the same day in July 2025 — one holding that Do-Not-Call protections don't extend to texts, the other finding they do — and the Ninth Circuit has since certified the question for appeal, creating a landscape where forum shopping and unpredictable outcomes are the new normal.
Managed outbound calling on approved, permissioned, or reviewed lists offers a clearer footing. My AI Call Center runs structured voice campaigns only against lists that pass a pre-launch consent review, with calling windows aligned to federal and state quiet-hour rules, AI disclosure on every call, and immediate opt-out handling that feeds directly into durable DNC logs. The model sidesteps the carrier registration layer entirely — no 10DLC vetting, no short-code provisioning, no toll-free verification — and avoids the 160-character ceiling that makes required disclosures difficult to fit in a single SMS.
- Pre-launch list and consent review before any dialing begins
- Approved calling windows that respect state-specific restrictions (e.g., 8 AM–8 PM in Florida and Oklahoma, 9 AM–8 PM in Connecticut)
- AI disclosure on every call with live opt-out, transfer-to-human, and DNC capture
- Disposition-level reporting — confirmed, qualified, renewed, opted out, no answer — routed back to your CRM
- No carrier registration, no character limits, no unresolved DNC-applicability split
The research underscores the stakes: statutory damages of $500–$1,500 per violation with no aggregate cap, a federal maximum civil penalty of $53,088 per violation, and state regimes like Connecticut's $20,000 per infraction or Texas's $10,000 bond requirement. Virginia mandates 10-year retention of opted-out numbers. A single noncompliant blast to thousands of numbers can create multimillion-dollar exposure, and class certification is routine because recipients need not prove actual harm.
Campaign requirements vary by location, industry, contact type, consent status, and technology. Clients are responsible for obtaining appropriate legal guidance before launch. If you're running structured outreach — appointment reminders, renewal calls, lead qualification, win-back campaigns — on lists with documented permission, a managed voice model removes the regulatory variables that make texting a moving target. Plan a campaign at myaicallcenter.app/campaigns — calling starts at 9¢ per connected minute, quoted before launch, with a free initial review.
Frequently Asked Questions
What are the potential financial risks of sending a single noncompliant text message under the TCPA?
How do state laws create additional compliance challenges for businesses sending text messages?
Why is consent documentation considered the strongest defense against TCPA liability in text messaging?
What operational steps are required before sending a text message to remain TCPA-compliant?
Is there legal uncertainty about whether the Do-Not-Call (DNC) Registry applies to text messages?
Why might businesses consider voice-based outreach as a lower-risk alternative to text messaging for structured campaigns?
The Bottom Line on Texting Risk: Certainty Is Worth More Than Convenience
Text messaging carries a compliance burden that few channels can match: statutory damages of $500 to $1,500 per violation with no aggregate cap, a state-law patchwork that "economically forces" compliance with the strictest rules, carrier registration layers, five-year consent log retention, and a federal court split — two conflicting rulings issued the same day — over whether Do-Not-Call protections even apply to texts. None of this means outreach is off the table. It means the channel you choose should match the certainty you need. For structured campaigns on approved, permissioned, or reviewed lists — reminders, renewals, win-backs, lead qualification — managed voice outreach sidesteps the 160-character ceiling, the registration stack, and the unresolved legal questions entirely. My AI Call Center reviews list source and consent records before any campaign launches, aligns calling windows to state rules, and honors opt-outs immediately, so the compliance work is done before you spend anything. If your current texting program keeps you guessing, get a free initial campaign review at myaicallcenter.app/campaigns — calling starts at 9¢ per connected minute, quoted before launch.