The TCPA applies to AI-generated voice calls. Full stop, on February 8, 2024, the Federal Communications Commission issued a unanimous Declaratory Ruling confirming that AI-generated voices fall squarely within the statute’s “artificial or prerecorded voice” restrictions under 47 U.S.C. § 227. Any organization deploying AI voice agents for outbound calls without the required consent is already exposed to statutory damages of $500 per violation, up to $1,500 for willful violations, and the class-action dynamics that follow.


Table of Contents

What does the TCPA actually cover for automated calls?

The Telephone Consumer Protection Act, codified at 47 U.S.C. § 227, creates three independent liability tracks that compliance teams must map separately.

Liability Track Controlling Statutory Text Consent Tier Required
Automatic Telephone Dialing System (ATDS) “Using any automatic telephone dialing system” Prior express consent (wireless); no restriction on landlines for non-marketing
Artificial or prerecorded voice “Using an artificial or prerecorded voice” Prior express consent (informational); prior express written consent (telemarketing to wireless)
Do Not Call Registry Residential telephone subscribers on the national DNC list Prior express written consent for telemarketing

Each track is independent. A caller who avoids ATDS liability by using a manual dialing system still faces liability if the call uses an AI-generated voice without consent. That independence is what makes the 2024 FCC ruling so consequential.

Key historical touchpoints that frame the current rules:

  • 1991: Congress enacted the TCPA, targeting prerecorded telemarketing calls and early autodialers.
  • 2015: The FCC issued a broad ATDS interpretation, later challenged in courts.
  • 2021: The Supreme Court decided Facebook, Inc. v. Duguid, 592 U.S. 395, narrowing the ATDS definition to systems that use a random or sequential number generator — a significant win for callers on the ATDS track.
  • February 8, 2024: The FCC issued its Declaratory Ruling on AI-generated voices, closing the gap that Duguid opened by confirming the artificial voice track applies independently.

The controlling statutory text the FCC interprets reads: “It shall be unlawful for any person within the United States… to make any call (other than a call made for emergency purposes or made with the prior express consent of the called party) using any automatic telephone dialing system or an artificial or prerecorded voice.” The phrase “artificial or prerecorded voice” predates modern AI, but the FCC’s 2024 ruling makes clear it was never limited to tape recordings.


What did the FCC’s February 2024 ruling actually hold?

The FCC’s February 8, 2024 Declaratory Ruling is the controlling authority on TCPA and AI calls. The Commission acted unanimously, and the official order text leaves little interpretive room.

The FCC’s core legal reasoning turned on the ordinary meaning of “artificial.” A voice produced by a machine learning model that synthesizes human-sounding speech is not a live human voice. It is, by definition, artificially generated. The Commission rejected any argument that the statute’s drafters intended “artificial” to cover only primitive synthesizers but not modern neural text-to-speech systems. The FCC’s position: the statutory text is technology-neutral, and AI voices fit within it.

What the ruling did not do is equally important for counsel to understand. The FCC did not amend the statute. It issued a Declaratory Ruling, which is an authoritative interpretation of existing law. That means the consent obligations and damages exposure were already present in the statute; the ruling simply removes any ambiguity about whether AI voices trigger them. Callers cannot argue they were acting in a legal gray area before February 2024 if they were deploying AI voice technology without consent.

The Commission also signaled further rulemaking. The FCC indicated it was considering additional disclosure requirements, including rules that would require AI-generated voice calls to identify themselves as AI at the outset of the call. That rulemaking is ongoing, and compliance teams should monitor the FCC docket for final rules.


Consent requirements split along two axes: the purpose of the call and the type of number being called.

Call Type Number Type Consent Required
Informational (appointment reminders, account alerts) Wireless Prior express consent
Telemarketing / marketing Wireless Prior express written consent
Telemarketing / marketing Residential landline Prior express consent
Emergency calls Any No consent required

Prior express written consent for telemarketing requires a signed agreement (electronic signature qualifies) that clearly authorizes the specific caller to contact the consumer using an AI-generated voice for marketing purposes. A general terms-of-service checkbox buried in an account registration form does not meet this standard.

Damages and class-action exposure

Statutory damages include $500 per violation and higher amounts for willful violations, with no cap on the number of violations in a class action. Reuters reporting confirms that AI voice deployments have increased litigation and class-action risk for callers, with plaintiffs’ firms actively monitoring AI-generated call campaigns. A campaign that sends 100,000 unconsented AI voice calls carries a theoretical exposure of $50 million at the base rate.

Pro Tip: Document every consent transaction at the moment of capture. Courts have held that the burden of proving consent rests on the caller, not the consumer — so a missing consent record is effectively a missing defense.

ATDS analysis after Duguid

Facebook v. Duguid narrowed the ATDS definition to systems that use a random or sequential number generator. Many AI calling platforms do not meet that narrowed definition. However, practitioner analysis confirms that the artificial voice track operates independently of the ATDS track. A caller who avoids ATDS liability because their system dials from a pre-loaded list still faces full TCPA exposure under the artificial voice provision if the call uses AI-generated speech.

State law adds another layer. Several states, including Texas and Florida, have enacted mini-TCPA statutes with broader ATDS definitions, lower consent thresholds, or additional registration requirements. A campaign that is technically TCPA-compliant at the federal level may still violate state law.

Cross-agency enforcement: FTC and state AI laws

The FTC’s February 2024 proposed rule on AI impersonation signals that deceptive AI voice use can trigger FTC Act Section 5 liability independent of the TCPA. An AI voice agent that mimics a real person’s voice without disclosure creates exposure under both regimes simultaneously. State privacy statutes in California, Illinois, and Washington add biometric and voice-data obligations that intersect with AI voice cloning features.


Your compliance checklist for AI voice deployments

Before any AI voice agent goes live on an outbound campaign, work through these controls in order.

  • Classify every call flow. Label each campaign as informational or marketing before deployment. The classification determines the consent tier required and the disclosure language the AI agent must deliver.
  • Capture prior express written consent for marketing calls. Use a standalone consent form or a clearly separated checkbox, not a bundled terms-of-service agreement. The consent must name the specific caller, identify the communication method (AI-generated voice calls), and state the purpose.
  • Document consent at the point of capture. Record the timestamp, the exact disclosure language shown, the consumer’s affirmative action, the source of the phone number, and the IP address or session identifier.
  • Scrub against the National Do Not Call Registry and internal suppression lists before every campaign run, not just at initial list ingestion.
  • Enforce calling windows. Federal rules prohibit calls before 8:00 AM or after 9:00 PM local time at the called party’s location. Several states set tighter windows.
  • Require vendor contracts to address revocation. Any third-party AI voice platform you use must contractually commit to real-time revocation propagation, provenance documentation for phone numbers, and audit log retention.
  • Verify number provenance. Confirm that every number on your call list was collected with consent for the specific purpose you are calling about. Purchased lists are high-risk without independent consent verification.

Pro Tip: Design your AI agent to recognize natural-language revocation mid-call, not just DTMF keypress commands. A consumer who says “please stop calling me” has revoked consent by a reasonable method under the TCPA. If your system only processes “press 9 to opt out,” you have a compliance gap that plaintiffs’ counsel will find.

The American Bar Association advises firms to build operational systems that document consent and revocations as a first-order priority, not an afterthought. Consent is not permanent. Consumers can revoke at any time by any reasonable method, and that revocation must propagate platform-wide, not just to the specific campaign that received it.


Phrasing guidance for a standalone marketing consent form:

“By checking this box, I authorize [Company Name] to contact me at the phone number provided using automated calls or messages, including calls made using AI-generated voice technology, for marketing purposes. I understand that consent is not a condition of purchase and that I may revoke this consent at any time by [method].”

The disclosure must identify the caller by name, specify AI-generated voice as the communication method, and provide a clear revocation mechanism.

Oral disclosure for outbound AI voice agents

The AI agent should deliver this disclosure at the start of every outbound call:

“Hello, this is an automated call from [Company Name] using an AI-generated voice. [Purpose of call]. If you’d like to stop receiving calls from us, just say ‘stop’ or ‘remove me’ at any time.”

Pending FCC rulemaking may require this disclosure by rule. Implementing it now reduces litigation risk and positions the organization favorably if the rule is finalized.

  • Consumer name and phone number
  • Timestamp of consent (date, time, time zone)
  • Exact disclosure language presented at consent
  • Consent method (web form, verbal, SMS reply)
  • Source of the phone number
  • Campaign or purpose for which consent was obtained
  • IP address or session identifier (for web-based consent)
  • Revocation timestamp and method, if applicable

Four years aligns with the TCPA’s statute of limitations. Some state laws require longer retention; confirm the applicable period for each state where you operate.


How to respond when a TCPA complaint involves AI-generated calls

Speed and documentation discipline in the first 30 days determine how much exposure you can contain.

  1. Day 0: Triage and suspend. Identify the specific call flow, campaign, and AI voice agent involved. Suspend outbound activity on that flow immediately pending review. Do not delete any records.
  2. Day 0–1: Engage counsel. Notify legal counsel before communicating with the complainant or regulator. All subsequent communications should be attorney-directed.
  3. Day 1–3: Issue a litigation hold. Preserve all call recordings, transcripts, consent records, CRM import logs, vendor contracts, and system configuration snapshots. Notify IT and any third-party vendors of the hold.
  4. Day 3–7: Map consent. Pull the consent record for the specific consumer and phone number. Identify the disclosure language shown, the timestamp, and the number source. If consent is missing or deficient, document that finding immediately for counsel.
  5. Day 7–14: Audit the campaign. Determine the full scope of potentially non-compliant calls: total call count, date range, and whether the issue is systemic or isolated. This scope analysis drives the damages exposure estimate.
  6. Day 14–21: Assess vendor liability. Review vendor contracts for indemnification clauses, representations about number provenance, and revocation-handling commitments. Determine whether the vendor shares liability.
  7. Day 21–30: Evaluate remediation options. Counsel should assess whether voluntary disclosure to the FCC or FTC, a remediation offer to the complainant, or a proactive compliance upgrade reduces litigation risk. Early remediation can support a good-faith defense in damages calculations.

Document preservation checklist:

  • All call recordings and AI-generated transcripts for the relevant campaign
  • Consent records and the disclosure language version in effect at the time of each call
  • CRM import logs showing the source and date of each phone number
  • Vendor contracts and any representations about TCPA compliance
  • System configuration and code snapshots showing the AI agent’s behavior at the time of the calls
  • Internal communications about the campaign’s consent strategy

Coordinating with vendors early is critical. If the AI voice platform is a third party, its logs and configuration records may be essential to your defense, and those records are at risk of routine deletion if you do not issue a preservation notice promptly.


The compliance controls that actually move the needle

Most compliance programs for AI voice deployments fail at the same two points: consent capture quality and revocation propagation speed. Everything else, calling windows, DNC scrubbing, disclosure language, matters, but those two gaps generate the most litigation.

Here is where to focus limited resources:

  • Consent capture first. A single deficient consent form can invalidate an entire campaign’s consent records. Audit the form, the disclosure language, and the data fields being stored before any campaign launches. This is the highest-leverage control.
  • Automate revocation propagation. A consumer who revokes consent on one call must be suppressed across every campaign, every channel, and every AI agent on the platform within a very short window. Manual suppression processes are too slow and too error-prone.
  • Invest in natural-language revocation detection. DTMF-only opt-out systems are a known compliance gap. An AI agent that cannot recognize “don’t call me again” as a revocation request will generate liability on calls that a better-designed system would have prevented.
  • Require audit logs from every vendor. If a vendor cannot produce timestamped logs of consent checks, revocation events, and call metadata, that vendor is a liability, not an asset.
  • Run a quarterly consent audit. Consent obtained for one purpose does not automatically extend to a new campaign. Audit consent scope against active campaigns every quarter.

The litigation risk from AI voice deployments is real and growing. Reuters has documented the increase in class-action filings tied to AI-generated calls. The organizations that avoid that exposure are not the ones with the most sophisticated AI, they are the ones with the most disciplined consent and revocation infrastructure.

The latter are table stakes, the former are where cases are won and lost.


How 42voice supports compliant AI voice deployments

Deploying AI voice agents without the right compliance infrastructure is the fastest way to turn a cost-saving initiative into a litigation liability. 42voice is built for businesses that need AI voice automation and the operational controls to deploy it responsibly.

42voice

The platform’s CRM integration synchronizes consent records and suppression lists in real time, so a revocation captured on one call propagates across every active campaign before the next dial. AI call analytics provide timestamped call logs and transcripts that serve as audit-ready evidence. The cold calling agent is configurable to deliver required AI disclosures at call outset and to detect verbal opt-out requests mid-conversation.

For compliance officers evaluating vendor controls, 42voice’s solutions overview covers the full feature set, from consent capture hooks to multilingual agent capabilities. Request a compliance-focused demo to see how the platform maps to the controls your counsel requires.


Sources

This article provides general legal information, not legal advice. Confirm current rules and your specific compliance obligations with qualified legal counsel.


This article is general information, not a substitute for advice from a qualified lawyer. Consult a qualified legal professional about your own circumstances before acting on anything here.

FAQ

Does the TCPA apply to AI-generated voice calls?

Yes. The FCC’s February 8, 2024 Declaratory Ruling confirmed that AI-generated voices constitute an “artificial voice” under 47 U.S.C. § 227, making unconsented AI voice calls illegal under the TCPA.

Prior express written consent is required for telemarketing calls to wireless numbers using an AI-generated voice. This means a signed (including electronic) agreement that specifically authorizes the caller to contact the consumer via AI-generated voice for marketing purposes.

Can AI cold calling violate the TCPA even if no ATDS is used?

Yes. The artificial voice track and the ATDS track are independent liability theories. A system that dials from a pre-loaded list and avoids the ATDS definition under Facebook v. Duguid still triggers TCPA liability if it uses an AI-generated voice without the required consent.

What are the statutory damages for a TCPA violation involving AI calls?

Damages are $500 per violation for standard violations and $1,500 per violation for willful or knowing violations, with no statutory cap on the number of violations in a class action.

AI cold calling is legal only with the required prior express written consent from the called party. Without documented consent, outbound AI voice calls to wireless numbers for marketing purposes violate the TCPA and expose the caller to statutory damages and class-action liability.