CampaignsHow It WorksIndustriesResultsInsightsPlan My Campaign
TCPA And DNC Compliance

What is a TCPA violation?

Back to InsightsWhat is a TCPA violation?

What is a TCPA violation?

Key Facts

What Counts as a TCPA Violation: The Two Pillars

Most people assume a TCPA violation means calling someone on the Do Not Call Registry. In reality, that is only one slice of a much larger legal framework — and businesses get sued every day for violations they never saw coming.

At its core, the statute rests on two pillars. The first, 47 U.S.C. § 227(b), governs regulated technology and consent: using an autodialer, prerecorded voice, artificial voice, or text message without the required level of permission. Marketing contact to cell phones demands prior express written consent; informational calls like appointment reminders require prior express consent. The second pillar, § 227(c), covers Do Not Call rules — marketing to DNC-listed numbers without an established business relationship, which lasts 90 days after an inquiry and 18 months after a transaction.

Within those pillars, legal analysts identify five major violation categories:

  • Text messages sent without prior express written consent
  • DNC violations across national, state, and internal suppression lists
  • Autodialed cell phone calls without written consent — including calls to reassigned numbers
  • Prerecorded or artificial voice robocalls without written consent, ringless voicemail included
  • Failure to honor consent revocation within 10 business days

That last category is newer than most realize. Under the FCC rules effective April 11, 2025, consumers can revoke consent in any reasonable manner — replying STOP or REVOKE, leaving a voicemail, even telling a cashier in person — and a texting opt-out also revokes consent for automated voice calls. An unhandled revocation is now a violation in itself.

The AI dimension deserves special attention. The FCC's February 2024 Declaratory Ruling classified AI-generated voices as artificial voices under § 227(b), with no carve-out for technology that sounds like a live agent. A live representative may call a past customer under an established business relationship; an AI voice cannot dial that same person without separate consent.

Violations also extend well beyond DNC scrubbing. Outbound teams break the rules by contacting reassigned numbers, calling outside permitted hours, ignoring internal suppression requests, or losing the consent evidence that justified the call in the first place. Federal calling windows run 8 AM to 9 PM in the called party's local time, and states like Florida, Oklahoma, and Washington impose even tighter cutoffs.

The exposure is severe: $500 to $1,500 per violation, with no requirement to prove actual injury. A 100,000-call campaign with a systemic consent deficiency can translate into $50–150 million in potential damages.

This is why list discipline matters more than list size. At My AI Call Center, list source and consent records are reviewed before any campaign launches — and bought lists without clear permission records are flagged or declined outright. Because under the TCPA, not knowing why you called a number is the violation.

The Real Cost: Why TCPA Violations Are Strict Liability

The TCPA does not care whether you meant to break the rules. It is a strict liability statute — your business is responsible regardless of fault or intent, even for calls to reassigned numbers or wrong numbers that consumers themselves provided, according to National Law Review's TCPA overview.

Every violation carries $500 to $1,500 in statutory damages, with no requirement for the plaintiff to prove actual injury, per BCLP's analysis of the 2025 opt-out rules. Treble damages apply when conduct is willful or knowing.

Now do the math. A campaign that contacts 10,000 people in violation could produce $5–$15 million in exposure, and a 100,000-call campaign with a systemic consent deficiency could reach $50–150 million, according to ActiveProspect's breakdown of TCPA penalties. Class settlements routinely exceed $10 million, and the statute of limitations runs four years — meaning every call you place today stays on your books until at least 2029.

Many commercial general liability and umbrella policies explicitly exclude TCPA claims, treating settlements as regulatory penalties rather than covered losses, as insurance coverage analysis notes. The check, in other words, comes out of your operating budget.

Outsourcing your calling does not outsource your risk. The entity on whose behalf calls are made bears liability regardless of which downstream vendor pressed dial — a lesson QuoteWizard learned through a $19 million settlement after failing to trace consent through its vendor chain, according to Retell AI's TCPA compliance playbook. Sellers accepting warm lead transfers can even be held vicariously liable for the initial outbound call, per M&S Law Group's compliance guidance.

A large proportion of TCPA demands come from a limited pool of individuals who have turned TCPA litigation into a cottage industry, according to defense attorneys who handle these cases. These plaintiffs know the rules better than most callers do, and they document everything.

What this means in practice:

  • One bad list can generate thousands of individual violations in a single afternoon.
  • "We didn't know" is not a defense — intent is irrelevant under strict liability.
  • Your vendor's mistake is your settlement.
  • Four years of call records can be subpoenaed, so documentation is your only shield.

This is why list discipline matters more than dial volume. At My AI Call Center, list source and consent records are reviewed before any campaign launches, and bought lists without clear permission records are flagged and in most cases declined. As compliance practitioners put it, the cost of a conservative dialer setting is trivial compared to a single TCPA class action.

AI Voice Calls Are Fully Regulated: The 2024 FCC Ruling

If your outbound strategy relies on AI voice calls, one federal ruling changed everything about how you must obtain consent — and many businesses still haven't caught up.

On February 8, 2024, the FCC issued a Declaratory Ruling classifying AI-generated voices as "artificial or prerecorded voice" under § 227(b) of the TCPA. According to the voice AI compliance analysis of the ruling, the statute "does not allow for any carve out of technologies that purport to provide the equivalent of a live agent." No matter how human your AI sounds, the law treats it as an artificial voice.

The voice is what the law cares about — not the sophistication of the technology behind it.

The established business relationship trap

This is where the most dangerous misconception lives. An established business relationship (EBR) — which lasts 90 days after an inquiry and 18 months after a transaction, per the National Law Review's TCPA overview — allows a live sales rep to call a past customer even if that person is on the Do Not Call Registry.

An AI agent cannot make that same call. Because the AI voice is legally "artificial," dialing a DNC-listed past customer without separate prior express consent is a violation — even when a human employee could legally pick up the phone and dial the identical number.

Consent is tiered — and topical

The level of consent you need depends on what the call does:

  • Marketing calls to wireless numbers require prior express written consent (PEWC) — signed, naming the business and number, and stating consent is not a condition of purchase.
  • Informational calls — appointment reminders, confirmations, surveys — require only prior express consent (PEC).
  • Crossing the tiers is itself a violation. Using numbers collected under PEC for marketing outreach breaks the rules, even though you technically "have consent."
  • Consent must stay on topic. Calls must be logically and topically related to the interaction that prompted consent — an auto insurance lead permits an insurer to call, but not a mortgage lender, as TCPA defense attorneys at M&S Law Group explain.

No lead is inherently "TCPA compliant." Compliance requires an individualized inquiry comparing the lead source to the specific campaign you plan to run.

Why this matters financially

Statutory damages run $500 to $1,500 per violation with no requirement to prove actual injury, according to BCLP's analysis of the TCPA's opt-out rules. A 100,000-call AI campaign with a systemic consent deficiency carries $50–150 million in potential exposure, based on outbound compliance benchmarks.

This is precisely why My AI Call Center reviews list source and consent records before any campaign launches — and plainly declines bought lists without clear permission records. The consent tier must match the campaign's one clear goal before a single number is dialed, because in AI outbound calling, the cheapest compliance decision is the one made before launch.

The 2025 Opt-Out Rules and Unsettled Regulatory Territory

On April 11, 2025, the FCC's new revocation rules took effect — and they quietly redefined what counts as a TCPA violation. Failing to honor a consumer's opt-out is now a violation in its own right, regardless of how carefully the original consent was captured.

Under the new framework, businesses must honor revocations within 10 business days at the latest. Consumers can revoke consent in any reasonable manner — texting keywords like STOP, REVOKE, OPT-OUT, or CANCEL, pressing a key during a call, leaving a voicemail, sending an email, or even telling a cashier in person. If a business prescribes a specific method, any other reasonable method still carries a rebuttable presumption of validity.

The rules also make revocation cross-medium: a consumer who texts "STOP" has revoked consent for automated voice calls too. After revocation, a business may send exactly one clarification message, delivered within five minutes and containing no marketing content. An opt-out from an informational message applies to all future non-emergency calls and texts, while an opt-out from a marketing message applies only to marketing outreach.

Operationally, this means outbound teams need revocation handling that works in near real time, not batch processing. This is one reason managed services like My AI Call Center log and honor opt-outs immediately and carry DNC requests across all of a client's campaigns — the 10-day ceiling is a maximum, not a target.

Not everything in the 2025 landscape is settled, however, and honest compliance planning requires acknowledging the contested areas:

  • The One-to-One Consent Rule's status is genuinely unclear. One legal analysis reports it took effect January 27, 2025, while another reports the Eleventh Circuit vacated it on January 24, 2025, and a third source dates it to April 2026. Treat this as unresolved and get current legal guidance.
  • State mini-TCPAs impose stricter rules. Florida, Oklahoma, Washington, Connecticut, Maryland, and Texas each layer on tighter requirements, and campaigns must apply the most restrictive applicable rule per dialed number.
  • Calling hours shrink in some states. The federal window runs 8 AM–9 PM local time, but Florida, Oklahoma, and Washington cut off at 8 PM.
  • Frequency caps apply even with consent. Oklahoma prohibits calling a number more than three times in 24 hours, consent notwithstanding.
  • Registration requirements are widespread. Roughly 36 states require telemarketer registration, a step many outbound programs overlook entirely.

The financial exposure for getting any of this wrong is steep: statutory damages run $500 to $1,500 per violation with no requirement to prove actual injury, and state penalties add more — Connecticut alone allows up to $20,000 per violation. Because the TCPA is a strict liability statute, intent does not matter; a missed opt-out or a wrong calling window is a violation whether or not anyone meant to break the rules.

The practical takeaway: build revocation handling, calling windows, and state-level restrictions into the campaign structure itself, before the first dial. Reviewing list source, consent records, and calling windows up front — as My AI Call Center does before any campaign launches — is far cheaper than discovering a gap after the fact.

How to Run Compliant Outbound Campaigns: A Practical Checklist

Knowing what counts as a violation is one thing. Running a campaign that never produces one is where most teams stumble — so here is a practical checklist that turns the rules into daily operations.

1. Scrub against the National DNC Registry every 31 days. The registry held more than 258 million active registrations in fiscal year 2025, and operations teams must scrub calling lists at least every 31 days to stay compliant. Remember that two calls to a DNC-listed number within twelve months can constitute a violation, so a stale scrub date is a live risk, not a paperwork issue.

2. Verify list source and consent records before launch. No lead is inherently "TCPA compliant" — compliance requires an individualized inquiry comparing where the lead came from to what your campaign will do with it. As one practitioner put it, "the phrase 'warm cold list' has no legal meaning." This is why My AI Call Center reviews list source and consent records before any campaign launches, and declines bought lists that lack clear permission records — telling you plainly, before you spend anything, if the list will not support the campaign.

3. Match the consent tier to the call's purpose. Marketing calls to cell phones require signed prior express written consent, while informational calls like appointment reminders need only prior express consent. Using PEC-captured numbers for marketing is itself a violation, and consent must be "logically and topically related" to the interaction that prompted it — an insurance lead does not authorize a mortgage call.

4. Disclose AI on every call. The FCC's February 2024 ruling classifies AI-generated voices as artificial voices under the TCPA, with no carve-out for lifelike AI. A single opening disclosure also satisfies state rules like Texas's 30-second requirement.

5. Honor opt-outs immediately. Since the April 11, 2025 rules, consumers may revoke consent in any reasonable manner — keywords like STOP and REVOKE, key presses, or even telling a cashier in person — and revocation applies cross-medium. The law allows 10 business days; treat "immediately" as the standard.

6. Retain documentation for four years. The TCPA's statute of limitations runs four years, and with $500–$1,500 statutory damages per violation and no need to prove injury, your records are your defense. Keep consent proofs, scrub logs, and opt-out records the full period.

A quick pre-launch summary:

  • DNC scrub completed within the last 31 days, with the date logged
  • Consent tier verified against campaign purpose (PEC vs. PEWC)
  • AI disclosure and opt-out keywords built into the approved script
  • Calling windows set to the most restrictive applicable state rule

If documentation feels like an afterthought, treat it as the campaign's insurance policy. Every campaign My AI Call Center runs closes with opt-out and DNC logs alongside dispositioned outcomes — because when a dispute arrives four years later, the log is the only thing that answers.

Frequently Asked Questions

Is calling someone on the Do Not Call list the only way to violate the TCPA?
No — DNC violations are just one of five major categories. Under 47 U.S.C. § 227(b), using an autodialer, prerecorded or AI voice, or text without the right level of consent is also a violation, and legal analysts identify failure to honor consent revocation within 10 business days as its own violation category.
Can I get in trouble for a TCPA violation even if I didn't mean to break the rules?
Yes. The TCPA is a strict liability statute, so intent doesn't matter — you're liable even for calls to reassigned numbers or wrong numbers the consumer provided themselves. Penalties run $500 to $1,500 per violation with no requirement to prove actual injury.
Are AI voice calls exempt from the TCPA if they sound like a real person?
No. The FCC's February 2024 Declaratory Ruling classified AI-generated voices as artificial voices under § 227(b), and the statute does not allow any carve-out for technologies that sound like a live agent. Notably, a live rep can call a past customer under an established business relationship, but an AI voice cannot dial that same person without separate consent.
How much could a TCPA violation actually cost my business?
A campaign contacting 10,000 people in violation could produce $5–$15 million in exposure, and a 100,000-call campaign with a systemic consent deficiency could reach $50–150 million in potential damages. Class settlements routinely exceed $10 million, and the four-year statute of limitations means every call stays on your books that long.
If I outsource my calling to a vendor, are they responsible for TCPA violations?
No — the entity on whose behalf the calls are made bears liability regardless of which vendor pressed dial. QuoteWizard learned this the hard way with a $19 million settlement after failing to trace consent through its vendor chain. That's why My AI Call Center reviews list source and consent records before any campaign launches.
What changed with the TCPA opt-out rules in 2025?
Since April 11, 2025, failing to honor a consent revocation is a violation in itself. Consumers can revoke in any reasonable manner — texting STOP, leaving a voicemail, even telling a cashier in person — and businesses must comply within 10 business days, though a texting opt-out also revokes consent for automated voice calls, making real-time opt-out handling essential.

The Cheapest Compliance Decision Is the One Made Before Launch

A TCPA violation is rarely one dramatic mistake. It is a missing consent record, a stale DNC scrub, an opt-out honored on day eleven, or an AI voice dialing a past customer a live rep could legally call. And because the statute is strict liability, intent never enters the picture — only documentation does. With $500 to $1,500 in statutory damages per violation and a four-year lookback, one unreviewed list can outweigh an entire campaign's budget. The path forward is straightforward: verify consent tiers against campaign purpose, scrub on schedule, honor revocations immediately, and keep records for four years. That is exactly how My AI Call Center structures every engagement — list source and consent records reviewed before launch, opt-outs logged the moment they arrive, and bought lists without clear permission declined outright. If you are unsure whether your list can support the campaign you have in mind, plan a compliant campaign and get your list and consent records reviewed before you spend anything.

Get campaign planning tips