
Who must comply with TCPA?
Key Facts
- The TCPA imposes statutory damages of $500 to $1,500 per violation according to compliance guidance.
- Recent TCPA settlements have ranged from $4 million to $21 million according to lawsuit settlements.
- AI-generated voices require prior express consent under the TCPA as per AI compliance guidelines.
- The TCPA applies to all organizations making calls to U.S. consumers, including B2B according to compliance guidance.
- State laws like California's CCPA add stricter requirements than federal TCPA rules noted by telecom analysts.
- The burden of proof for compliance rests with the caller, not the consumer as per TCPA rules.
- Organizations must honor opt-outs via 'any reasonable means,' including text replies according to FCC guidelines.
Who Is Subject to the TCPA? More Organizations Than You Think
If your organization picks up a phone or sends a text to a U.S. consumer, the TCPA likely applies to you — and the law draws its net far wider than most businesses expect. The statute was written in 1991, but regulators and courts have kept pace with technology, and the list of who must comply keeps growing.
There is no categorical exemption for business-to-business calling. According to compliance guidance on AI outbound calls, any organization making calls or sending texts to U.S. consumers falls under TCPA rules, and the burden of proof rests on the caller to demonstrate compliance. That means even a small clinic confirming appointments, a franchise following up on leads, or a staffing firm screening candidates is subject to the same consent and opt-out requirements as a large telemarketing operation.
The stakes are substantial. The TCPA imposes statutory damages of $500 to $1,500 per violation, and recent settlements have ranged from $4 million to $21 million. With numbers like these, a single poorly sourced contact list can turn into a serious liability.
Perhaps the biggest shift involves AI-generated voices. A TCPA compliance guide for AI calling confirms that AI voices are regulated as "artificial voices" under the statute, which means they require prior express consent before dialing. In other words, a natural-sounding AI agent does not exempt you from the rules — it pulls you squarely into them.
Beyond the federal statute, state laws can layer on stricter requirements. California's CCPA and Florida's Mini-TCPA are two examples noted by telecom compliance analysts as imposing additional obligations on top of the TCPA. The FCC also requires callers to honor consent revocations made through "any reasonable means," so a consumer saying "stop" in a text reply counts just as much as a formal written request.
In practice, the organizations that stay out of trouble tend to do three things:
- Obtain and document prior express consent before any call or text, especially when using AI-generated voices.
- Maintain organized opt-out workflows, since compliance experts stress that clear consent practices and structured opt-out handling are the core of a sound defense.
- Audit consent processes and call scripts regularly, and screen contact lists proactively to catch risky numbers before campaigns launch.
This is why My AI Call Center reviews list source and consent records before any campaign runs, and declines bought lists that lack clear permission trails. Compliance is not a feature you add later — it is the foundation the campaign stands on. Whether you run a multi-location clinic, a recruiting firm, or a membership business, the rule is the same: if you are calling U.S. consumers, you are subject to the TCPA.
The Cost of Non-Compliance: $500 to $1,500 Per Call
One misplaced call can cost more than a customer — it can cost thousands. Under the TCPA, every non-compliant call or text carries statutory damages of $500 to $1,500 per violation, and the math compounds quickly when a campaign reaches hundreds or thousands of contacts.
According to TCPA compliance research, those statutory damages apply per violation, meaning a single poorly-scrubbed campaign can create exposure that dwarfs the campaign's entire budget. Recent TCPA lawsuit settlements have ranged from $4 million to $21 million — and those figures cover only the settlements, not the legal fees, business disruption, and reputational damage that accompany them.
The burden of proof compounds the risk. Under TCPA rules, the caller must demonstrate compliance, not the consumer, and organizations need to prove prior express consent existed, prove calls were placed within approved windows, and prove opt-outs were honored. The FCC also requires callers to honor consent revocations made through any reasonable means, so a consumer who replies STOP to a text or asks to be removed mid-call creates an immediate obligation.
For organizations using AI voices, the stakes are even higher. According to TCPA guidance for AI calling, AI-generated voices are treated as artificial voices under the TCPA, requiring prior express consent before any call is placed. Experts recommend auditing consent processes and call scripts immediately, treating AI voice as a regulated technology rather than an unregulated convenience.
Defensive layers matter because no single safeguard is enough:
- Legal awareness of TCPA, state mini-TCPA laws, and FCC rules
- Proactive data screening to catch consent gaps before dialing
- Organized opt-out workflows that honor revocations immediately
- Advanced risk detection tools that flag problematic list sources
This is why list discipline is a compliance strategy, not just a marketing preference. My AI Call Center runs campaigns only against approved, permissioned, or reviewed lists, and flags bought lists without clear permission records before a client spends anything. The goal is to make the burden of proof manageable: documented consent, honored opt-outs, and a clear record of what happened on every call.
Non-compliance is not a theoretical risk. It is a per-call financial exposure that scales with every dial, and the caller carries the burden of proving they did everything right. Organizations that treat consent documentation and list review as core infrastructure — rather than an afterthought — are the ones that avoid becoming the next settlement headline.
The Compliance Framework: Consent, Opt-Outs, and State Laws
The foundation of TCPA compliance rests on one question: did the caller obtain permission before picking up the phone? For organizations using AI-generated voices, that question carries extra weight — the TCPA treats AI voices as "artificial voices" that require prior express consent before any call is placed. There is no categorical B2B exemption, and the burden of proof sits squarely on the caller to demonstrate compliance, according to industry research.
The financial stakes make consent discipline essential. The TCPA imposes statutory damages of $500 to $1,500 per violation, and recent settlements have ranged from $4 million to $21 million, as documented in TCPA lawsuit news. That math explains why organizations cannot treat consent as a checkbox — they must be able to prove it.
Consent is only half the equation. The FCC requires callers to honor consent revocations made through "any reasonable means," meaning an opt-out via phone, email, web form, or even a spoken request during a call must be processed and respected. Compliance guidance emphasizes that organized opt-out workflows are not just defensive — they are a practical necessity for reducing litigation risk.
State-level rules add another layer. Organizations must comply with state laws such as California's CCPA and Florida's Mini-TCPA, which can impose stricter requirements than federal rules, according to telecom compliance analysis. A campaign that passes federal muster may still fail state scrutiny, so compliance teams need to map every jurisdiction where contacts reside.
Experts recommend combining multiple defensive layers to reduce exposure:
- Legal awareness of current TCPA rulings and FCC guidance
- Proactive data screening to flag lists without clear permission records
- Advanced risk detection tools that catch consent gaps before launch
- Regular audits of consent processes and call scripts
Litigation analysis confirms that combining these layers is far more effective than relying on any single safeguard. Auditing consent processes and call scripts is a recommended first step for any organization using AI voice technology, notes AI calling compliance guidance.
At My AI Call Center, this framework shapes how campaigns are built: every list is reviewed for source and consent records before launch, opt-outs are logged and honored immediately, and campaigns run only against approved, permissioned, or reviewed contacts. The goal is straightforward — run useful calls without building a bigger call center, and without inventing compliance shortcuts.
From Audit to Action: Running Compliant AI Calling Campaigns
Knowing the TCPA applies to you is one thing; proving you complied is another. The burden of proof sits with the caller, so compliance has to be built into your campaign process, not bolted on after the phones start ringing.
Start with a consent audit. Experts recommend auditing consent processes and call scripts immediately, because AI voices are treated as "artificial voices" that require prior express consent before the first dial. Review where each list came from, what each contact agreed to, and when. If a bought list has no clear permission trail, that is a problem to solve before launch, not after.
Next, screen your lists against known risk. Compliance specialists recommend combining defensive layers — legal awareness, proactive data screening, and risk detection — because a single violation carries statutory damages of $500 to $1,500, and recent settlements have ranged from $4 million to $21 million.
Opt-out handling deserves the same rigor as consent. The FCC requires callers to honor revocations made through "any reasonable means", and organized opt-out workflows are a core defense against litigation. Log every request, honor it immediately, and carry it across all future campaigns.
A practical pre-launch checklist looks like this:
- Audit consent records and confirm they cover AI-generated voices
- Review scripts for required disclosures and clear opt-out language
- Screen lists against DNC records and known litigation risk
- Document opt-outs in a log that persists across campaigns
- Confirm calling windows against state-specific quiet hours and restrictions
This is where a managed approach earns its keep. My AI Call Center reviews list source and consent records before any campaign launches, flags bought lists without clear permission records, and tells you plainly if a list will not support the campaign — before you spend anything. Every script, disclosure, and escalation path gets client approval first, and opt-outs are logged and honored immediately, with keyword opt-outs like STOP and REVOKE supported on every call.
Remember that federal rules are the floor, not the ceiling. State laws like California's CCPA and Florida's Mini-TCPA impose stricter requirements, so multi-state campaigns need location-aware rules. Campaign requirements vary by industry, contact type, and technology — obtain appropriate legal guidance before launch, and let disciplined process carry the rest.
Frequently Asked Questions
Does the TCPA really apply to small businesses like clinics, franchises, or staffing firms?
Are AI-generated voices held to the same TCPA rules as human callers?
What is the actual financial risk if we make a non-compliant call?
Is there a B2B exemption under the TCPA?
Do we have to honor opt-outs that come through text or verbally during a call?
Are federal TCPA rules the only thing we need to worry about?
The Bottom Line: If You Dial U.S. Consumers, You're on the Hook
The TCPA casts a wide net — clinics, franchises, staffing firms, membership businesses, and anyone else calling or texting U.S. consumers. There is no B2B exemption, AI voices count as artificial voices requiring prior express consent, and the burden of proof sits with the caller. With statutory damages of $500 to $1,500 per violation and settlements ranging from $4 million to $21 million, one poorly sourced list can cost far more than the campaign it powered. Your next steps are practical: audit your consent records, screen every list before launch, honor opt-outs logged through any reasonable means, and map state rules like Florida's Mini-TCPA. If you want that discipline built in from the start, My AI Call Center reviews list source and consent records before any campaign runs — and tells you plainly if a list won't support it, before you spend anything. Start with a free campaign review and bring one clear goal; we'll quote the whole campaign before a single call is placed.