AI Cold Calling: Prove Where Every Consent Came From

AI cold calling is lawful in the United States only where you can produce, for each number dialed, the evidence of the consent that authorized that call. The Fe

AI cold calling is lawful in the United States only where you can produce, for each number dialed, the evidence of the consent that authorized that call. The Federal Communications Commission confirmed in February 2024 that AI-generated voices are "artificial" voices under the Telephone Consumer Protection Act, so consent is required before the dialer fires, not after the prospect objects.

That is the whole governance problem in one line, and it is not the one most guides on this keyword address. Most AI cold calling compliance advice concentrates on what the machine says once the call connects. The exposure sits earlier, at the moment a number enters the calling list. Our position is that the durable control for AI cold calling is a per-number Provenance Record: a small, boring, auditable object that answers where did this number come from, who consented, to what, and when. No number without one should ever reach the dialer. We call that gate no provenance, no dial.

The reason to build the record rather than memorise the rule is that the rule is currently moving. One appellate court vacated the FCC's one-to-one consent requirement in January 2025. Another rejected the FCC's written-consent rule outright in February 2026. The FCC has waived part of its own revocation rule into 2027. Across every one of those changes, the thing a defendant has to produce stayed identical: evidence, per call, of what the called party agreed to.

A software engineer posting on Hacker News in May 2025 described the failure exactly. He took a cold call on his personal mobile on a day off, and, in his words, "demanded to know where they'd found my number." The rep said a browser plugin. He filed a subject access request, dug through the vendor's own request form, and traced the number to a contacts-backup app published by a company he had never heard of. Someone he worked with had saved his details and uploaded their address book. The consent that put him on that calling list was given by a third party, about him, to a company he had no relationship with. The caller could not have known that, because nobody in the chain kept a record worth reading (Hacker News, 26 May 2025).

The short answer: Build the consent record before you build the calling agent. An AI dialer multiplies whatever provenance defect is already in your list by the number of dials per hour, and statutory damages under the TCPA start at $500 per call with no aggregate cap.

Last updated: July 31, 2026.

Four routes a phone number takes into a calling list, and which of them leave usable consent evidence

Where a number came from determines whether you can lawfully dial it. Only two of the four common acquisition routes produce evidence you can put in front of a court.

What AI cold calling is, and the question that decides whether you can run it

AI cold calling is outbound telephone prospecting where a machine performs part or all of the call: selecting the number, placing the dial, speaking to the person who answers, or writing the outcome back to the CRM. The term covers a spectrum, and the spectrum matters legally, because the law attaches to specific mechanisms (the artificial voice, the autodialer, the calling list) rather than to the marketing category.

Vendors describe that spectrum in terms of capability: how natural the voice sounds, how fast it responds, whether it can handle an objection. That framing does not predict liability. Two systems with identical capability can sit on opposite sides of a statute depending on which numbers they dial and what the company can prove about how those numbers arrived.

So the useful first question is not "how good is the voice?" It is: for the next number this system dials, can we produce the consent that authorises the call, and where is that evidence stored? A team that cannot answer that is not running an AI cold calling programme. It is running an untested legal position at machine speed.

This article is about consent to call. A separate and equally real body of law governs consent to record once the call connects; it varies state by state and turns on different statutes. Most compliance sections fold the two together, which is how teams end up with a recording-disclosure script and no calling-list evidence at all. Treat them as two projects.

Yes, AI cold calling is legal in the United States, conditionally. The condition is consent, and for AI voices it is not optional. In a Declaratory Ruling adopted 2 February 2024 and released 8 February 2024 in CG Docket No. 23-362, the FCC confirmed that "the TCPA's restrictions on the use of 'artificial or prerecorded voice' encompass current AI technologies that resemble human voices and/or generate call content using a prerecorded voice," and stated that "callers must obtain prior express consent from the called party before making a call that utilizes artificial or prerecorded voice simulated or generated through AI technology" (FCC 24-17).

Two details in that ruling do more work than the headline. First, the Commission grounded the finding in the plain meaning of "artificial": these are artificial voice messages "because a person is not speaking them." A synthetic voice is not exempt because it sounds convincing; it is covered because it sounds at all. Second, the Commission extended the reasoning of its 2020 Soundboard Ruling, in which it held that a live agent selecting which prerecorded clip to play "does not negate the clear statutory prohibition against initiating a call using a prerecorded or artificial voice." That closes the most common workaround in AI cold calling pitches: the human-in-the-seat, machine-in-the-mouth arrangement. If the audio leaving the line is synthetic, the prohibition applies regardless of who pressed the button.

Underneath the ruling sit the operative rules, worth reading rather than summarising. Under 47 CFR 64.1200(a)(1), no person may initiate a call using an automatic telephone dialing system or an artificial or prerecorded voice to any number "assigned to a paging service, cellular telephone service, specialized mobile radio service, or other radio common carrier service, or any service for which the called party is charged for the call," without prior express consent. Paragraph (a)(2) raises the bar when the call "includes or introduces an advertisement or constitutes telemarketing": that requires prior express written consent.

The regulation defines what written consent has to contain, and the definition is stricter than most CRM consent flags. Under 64.1200(f)(9), prior express written consent means "an agreement, in writing, bearing the signature of the person called that clearly authorizes the seller to deliver or cause to be delivered to the person called advertisements or telemarketing messages using an automatic telephone dialing system or an artificial or prerecorded voice, and the telephone number to which the signatory authorizes such advertisements or telemarketing messages to be delivered." The agreement must carry a clear and conspicuous disclosure that signing authorises those calls and that the person is not required to sign as a condition of purchase. Electronic signatures count.

Read that against a typical purchased B2B list. The definition requires a signature, a named seller and the specific number; a vendor's assurance that its data is "compliant" supplies none of the three.

ProvisionWhat it prohibitsWho it protectsConsent standard on its face
47 CFR 64.1200(a)(1)ATDS or artificial/prerecorded voice callsWireless, emergency, patient-room linesPrior express consent
47 CFR 64.1200(a)(2)The same calls when they advertise or constitute telemarketingThe same linesPrior express written consent
47 CFR 64.1200(a)(3)Artificial/prerecorded voice telemarketing to residential linesResidential subscribersPrior express written consent
47 CFR 64.1200(c)(1)Telephone solicitations outside 8 a.m.–9 p.m. local timeResidential subscribersNo consent cure for the window
47 CFR 64.1200(c)(2)Solicitations to numbers on the national registryResidential subscribersSigned written agreement, or an established business relationship
47 CFR 64.1200(d)Calls to people on your own internal listResidential subscribersNone — the request governs

Then the complication. On 25 February 2026 the Fifth Circuit held that the FCC's written-consent rule does not reflect the statute. In Bradford v. Sovereign Pest Control of TX, Inc., No. 24-20379, the court wrote that "contrary to the FCC's regulation, Congress permits either written or oral consent for any auto-dialed or pre-recorded call," reasoning from the meaning of "express consent" when the TCPA was enacted: consent "directly given, either viva voce or in writing" (Fifth Circuit opinion, 25 February 2026). The panel affirmed judgment for the caller.

That holding binds the district courts of the Fifth Circuit, which covers Texas, Louisiana and Mississippi. It is not the law in the rest of the country, and it does not repeal 64.1200(a)(2), which remains on the books. What it creates is a split: the same calling programme can be defensible in Houston and actionable in Chicago. (None of this is legal advice, and the venue question is exactly the kind counsel exists for.)

A year earlier, the Eleventh Circuit had gone the other way on a different question, vacating the FCC's 2023 one-to-one consent rule, the requirement that a consumer consent to calls from only one entity at a time, on subject matter "logically and topically associated" with the interaction that produced the consent. In Insurance Marketing Coalition Limited v. FCC, No. 24-10277, decided 24 January 2025, the court found the restriction fell "outside the scope of the FCC's statutory authority" and vacated Part III.D of the 2023 Order (Eleventh Circuit opinion). We checked the current eCFR text of 64.1200(f)(9) on 31 July 2026: the one-to-one language is gone from the operative rule.

Both decisions trace to the same upstream shift. The Fifth Circuit opened its analysis by noting that it decides questions of statutory interpretation "without deference to an agency's reading," citing McLaughlin Chiropractic Associates, Inc. v. McKesson Corp., in which the Supreme Court held that the Hobbs Act "does not bind district courts in civil enforcement proceedings to an agency's interpretation of a statute" (Legal Information Institute). The practical consequence for anyone running AI cold calling: the FCC's rulebook is no longer the last word in a courtroom, and the answer to "what does consent require" is now partly a question of which circuit you are sued in.

Which is why we argue for the record over the rule. The FCC's standard wants a signed agreement naming the number. The Fifth Circuit's wants proof of a positive, direct, unequivocal grant, possibly spoken. Every reading wants you to produce something. A team holding a signed, timestamped, number-specific grant satisfies the strictest version on the board and has nothing to redo when the next opinion lands.

Here is the specific failure that an autonomous dialer scales. Consent under the TCPA runs from the called party. Data brokerage does not respect that boundary. Numbers move through address-book uploads, enrichment plugins, event registrations resold as "opted-in leads," and inference engines that guess a mobile number and then sell the guess. At every hop, the word "consent" survives in the metadata while the actual agreement, who granted what to whom, does not.

The Hacker News account quoted above is the clean illustration because the author did the archaeology most recipients never do. He traced his mobile number to a caller-ID and contacts-backup app; the "consent" in that chain had been given by a colleague uploading an address book, not by him. His email address, per the vendor's own record, came from a "guess algorithm." A calling agent handed that record has no way to distinguish it from a number typed into your own web form by the person who owns it. Both arrive as a row with a consent: true column.

An AI system does not create this problem. It changes its arithmetic. A human SDR working a bad list makes perhaps 60 dials a day and, being human, notices when three people in a row ask where their number came from. An automated dialer makes that same defective call thousands of times before anyone reads a transcript. Under 47 U.S.C. 227(b)(3), a private plaintiff may recover actual loss or "$500 in damages for each such violation, whichever is greater," and a court may award "not more than 3 times the amount available" for a wilful or knowing violation. There is no aggregate cap in the statute. Volume is the multiplier on both sides of the ledger.

The regulation also forecloses the obvious defence of outsourcing. Under 64.1200(d)(3), where do-not-call requests "are recorded or maintained by a party other than the person or entity on whose behalf the call is made, the person or entity on whose behalf the call is made will be liable for any failures to honor the do-not-call request." You can delegate the list. You cannot delegate the consequence of the list being wrong.

This gets worse as agents chain. When a marketing agent enriches a record, an SDR agent decides it is worth calling, and a voice agent places the dial, the provenance question splinters across three systems that each trust the one before it. Our earlier analysis of marketing agents and the list they inherit makes the same argument in the adjacent channel: the agent is rarely what goes wrong; the list it was handed is.

The Provenance Record: six fields the FTC already wrote down

You do not have to invent the schema. In its April 2024 amendments to the Telemarketing Sales Rule, the Federal Trade Commission wrote a definition of a complete consent record into the regulation. Under 16 CFR 310.5(a)(8), sellers and telemarketers must keep "all verifiable authorizations or records of express informed consent or express agreement," and the rule states what a complete record contains:

#Field required by 16 CFR 310.5(a)(8)What it means in a CRM
iThe name and telephone number of the person providing ConsentNot the account. The individual, and the exact number.
iiA copy of the request for Consent, in the same manner and format in which it was presentedThe rendered form or script as the person saw it, not a link to the current version.
iiiThe purpose for which Consent is requested and givenWhat you said you would call about.
ivA copy of the Consent providedThe signature, the checkbox event, the recording of the spoken grant.
vThe date Consent was givenTimestamp, with timezone.
viFor consent under the listed sections, all information specified in those sectionsThe extra elements the do-not-call and prerecorded-message provisions require.

That is the Provenance Record. Six fields, one per number, retained for five years from the date the record is produced under 310.5(a). None of it is technically hard. The reason most calling lists cannot produce it is organisational: nobody owned the field when the number was acquired, and by the time a complaint arrives the form has been redesigned twice.

The dialing side of the record is specified too. Under 310.5(a)(2), a record of each telemarketing call must include the telemarketer that placed it, the seller it was placed for, the good or service, whether the recipient was an individual or a business consumer, whether it was outbound, whether it used a prerecorded message, the calling and called numbers with date, time and duration, the script and prerecorded message used, the caller-identification number and name transmitted plus proof of authorisation to use them, and the disposition of the call including any transfer target.

Read that list next to the log an AI calling platform produces by default and the gaps are usually the same three: the script version actually used on that call, the individual-versus-business classification, and the authorisation for the caller-ID presented. Those are the fields nobody misses until they are the ones being asked for.

A caveat for the B2B reader: these TSR recordkeeping duties sit inside a rule that exempts most business-to-business telemarketing, covered below. Keep the record anyway. The reason is not that the FTC requires it of you; it is that the record is the only artefact that answers the TCPA question, which does not exempt B2B calls to wireless numbers. Borrowing a well-drafted schema you are not strictly bound by is cheaper than drafting a worse one.

A dial gate: nine sequential checks a number must pass before an AI calling agent may place the call

The dial gate. Each check either passes the number through, holds it for review, or removes it from the campaign entirely.

Prerequisites: what must exist before the first AI dial

Do not start with the voice. Start with these six. None can be retrofitted onto calls already placed.

  1. A named owner for the calling agent. A person, not a team inbox, accountable for what the agent dials and answerable when a complaint arrives. Agents that place regulated communications are the clearest case for treating non-human identity as a first-class object with an owner, a scope and an expiry date, which is the argument in our earlier analysis of non-human identity.
  2. A consent capture surface you control. A form, a call script with a recorded grant, or a signed agreement. Something that produces fields i through vi at the moment of acquisition rather than reconstructing them later.
  3. A paid national do-not-call registry subscription covering every area code you will dial, obtained no more than 31 days before any call under 64.1200(c)(2)(i)(D).
  4. An internal do-not-call list with a written policy, available on demand, per 64.1200(d)(1), plus the training obligation in (d)(2). The written policy is a document that either exists or does not; there is no partial credit.
  5. A call record store with five-year retention and a query path, because the record is worthless if producing it takes three weeks of engineering.
  6. A kill switch with a named holder. Someone who can stop the campaign inside minutes, and who is not the person whose quota depends on it running.

Two of these, the registry subscription and the written internal policy, are cheap, mandatory and routinely missing. The other four are where the engineering time goes.

The dial gate: nine checks, in order

This is the procedure. It runs per number, immediately before the dial, and the order is deliberate: the cheapest disqualifying checks come first so the expensive ones run on a smaller set.

  1. Provenance present? The number has a Provenance Record with fields i through vi populated. Missing any field: hold, do not dial. This is the no provenance, no dial rule, and it is the only check that has no exception.
  2. Number type resolved? Wireless, residential wireline, or a business line. This means a line-type lookup against carrier and number-portability data, which is a paid service and a legitimate one. It does not mean the mobile: true column that arrived attached to the list, which is an assertion by the party who sold you the record. Everything downstream depends on this classification, and it is the one teams most often infer instead of resolving.
  3. Consent scope matches the call? The purpose recorded in field iii covers what this call is about. The Eleventh Circuit removed the FCC's topical-relatedness requirement, so this is no longer a federal rule. But the scope you recorded is the scope you can prove, and the vacatur did not make an unrelated grant into a good one.
  4. National registry scrub current? The registry version used was obtained within 31 days. Log the version, the access date and the account number, which 310.5(a)(11) specifies as its own record.
  5. Internal list scrub? Your entity-specific do-not-call list, checked independently of the national registry and, in practice, more often the source of a claim, because internal requests are made directly to you and are therefore easy to prove.
  6. Local time in window? 8 a.m. to 9 p.m. at the called party's location, per 64.1200(c)(1) and 16 CFR 310.4(c). Resolve from the record's stated location where you have one, not from the area code alone.
  7. Voice mode declared? Whether this call will use a synthetic voice determines which consent standard applies. Decide it at gate time, not by whichever route the platform happens to take.
  8. Opening disclosures loaded? For artificial or prerecorded voice messages, 64.1200(b)(1) requires the identity of the responsible business at the beginning of the message, using the name it is registered under, and (b)(2) requires a callback number.
  9. Opt-out path armed? Where 64.1200(b)(3) applies, an automated interactive voice or keypress opt-out mechanism must be offered within two seconds of the identification, and invoking it must record the number to the internal list and end the call immediately.

Three of these nine, provenance and number type and local time, are the ones that fail silently. A dialer with no gate does not error when the record is thin. It just calls.

A worked example: one lead, one record, one call

Assembled artifacts beat descriptions of artifacts, so here is one complete record and the call it authorises. The company is a fictional B2B SaaS vendor; the fields are the real ones from 16 CFR 310.5.

Provenance Record — lead 84,213

FieldValue
Person providing consentDana Okoye
Telephone number consented+1 512 555 0184
Number type (carrier lookup, 2026-07-28)Wireless
Request for consent, as presentedWebinar registration form v4.2, rendered HTML archived at consent/forms/4.2/2026-06-02.html; checkbox text: "I agree that [Seller] may call or text me at the number above about its products, including using an automated or artificial voice. I am not required to agree to buy anything."
Purpose consentedProduct calls and follow-up about the seller's inventory-forecasting product
Copy of consent providedCheckbox event evt_9f31c0, IP 198.51.100.24, form version 4.2, user agent recorded
Date consent given2026-06-02T14:07:19-05:00
Signature basisElectronic, per 64.1200(f)(9)(ii)
National registry version usedData set 2026-07-19, account 41-XXXXXX
Internal list checked2026-07-28T09:02Z, not present
Local time at dial2026-07-28, 10:14 America/Chicago

Call record — dial 84,213-1

FieldValue
Telemarketer placing the callVoice agent outbound-fx-02, owner: Priya Raman, scope: product calls only, expiry 2026-12-31
SellerThe vendor named in the consent text, in full
Good or serviceInventory-forecasting product
Individual or business consumerIndividual (wireless, personal number)
OutboundYes
Prerecorded or artificial voiceYes — synthetic voice
Calling number / called number+1 512 555 0100 / +1 512 555 0184
Date, time, duration2026-07-28, 10:14:32 CDT, 02:41
Script versionscript/outbound/fx/2026-07-14 (archived)
Caller-ID name and number transmitted, with authorisationRegistered business name; authorisation contract tel-auth-2026-03 on file
DispositionConnected, opted out at 00:52 via keypress, call terminated, number written to internal list at 10:15:24 CDT

Two things to notice. Every field points at a stored artefact, not at a description of one. And the call failed commercially: the prospect opted out in under a minute, yet the record is still exactly what you want, because the opt-out is written to the internal list inside the same minute and is provable. A programme that only logs its successes has built an evidence system that works in every case except the one that reaches litigation.

If you keep one thing from this article, keep the habit of storing the rendered consent form as it appeared on the day. Field ii asks for the request "in the same manner and format in which it was presented." A link to the current form is not that, and forms get redesigned.

Two clocks and two lists: the 31-day scrub and the local-time window

The do-not-call obligation is two obligations, and teams routinely satisfy one and skip the other.

The national registry is the one everybody knows. To rely on the safe harbour in 64.1200(c)(2)(i), a caller must use "a version of the national do-not-call registry obtained from the administrator of the registry no more than 31 days prior to the date any call is made," alongside written procedures, personnel training, a maintained internal suppression list, and records documenting the process. The registry is large and active: in fiscal year 2025 it "included over 258 million active registrations" and the FTC received "over 2.6 million Do Not Call complaints" (FTC National Do Not Call Registry Data Book, FY 2025).

The internal list is the one that generates claims. Under 64.1200(d), any entity making telemarketing calls to residential subscribers must maintain a list of people who asked not to be called, with a written policy available on demand, trained personnel, and the request recorded "at the time the request is made." The request must be honoured "within a reasonable time from the date such request is made," and that period "may not exceed ten (10) business days." Requests must be kept for five years.

Ten business days, not thirty. Several guides currently ranking for this keyword say thirty days, and that number appears to be a survival from an older version of the rule. If your dialer's suppression sync runs on a monthly cadence because a blog post told you it could, it is out of compliance by roughly two weeks per cycle.

ObligationThe clockSource
National registry data freshnessObtained ≤ 31 days before the call47 CFR 64.1200(c)(2)(i)(D)
Honour an internal do-not-call request≤ 10 business days47 CFR 64.1200(d)(3)
Honour a revocation of consent≤ 10 business days47 CFR 64.1200(a)(10)
Retain an internal do-not-call request5 years47 CFR 64.1200(d)(6)
Retain TSR call and consent records5 years16 CFR 310.5(a)
Calling window (solicitations to residences)8 a.m.–9 p.m. local at the called party's location47 CFR 64.1200(c)(1); 16 CFR 310.4(c)

The calling window deserves its own paragraph because automation breaks it in a specific way. The rule keys to local time at the called party's location, not the area code. Mobile numbers keep their area code across a move; a 212 number can sit in Denver for a decade. A dialer sorting a national list by predicted answer rate will happily place a 7:20 a.m. call to somebody whose number says New York and whose body is in California. Resolve location from the record where you have it, treat area code as a weak signal, and hold anything ambiguous until mid-morning to mid-afternoon Pacific, which is inside the window in every contiguous US zone.

Revocation: ten business days, any reasonable method, and a rule still in motion

Under 64.1200(a)(10), a called party may revoke consent "by using any reasonable method to clearly express a desire not to receive further calls or text messages from the caller." The regulation names methods that are reasonable per se: an interactive voice or keypress opt-out on a call; the words "stop," "quit," "end," "revoke," "opt out," "cancel," or "unsubscribe" in reply to a text; or a website or phone number the caller designated for opt-outs. Where any of those is used, "that consent is considered definitively revoked." All revocation requests made in any reasonable manner must be honoured "within a reasonable time not to exceed ten business days from receipt," and callers "may not designate an exclusive means to request revocation of consent."

The last clause is the one that catches AI calling systems. A voice agent trained to accept only a keypress, or only the exact word "unsubscribe," has been designed around an exclusive means. Paragraph (a)(11) goes further: using some other channel, a voicemail or an email to a number or address meant to reach the caller, "creates a rebuttable presumption that the consumer has revoked consent." So the agent must recognise revocation expressed in ordinary language, and the surrounding system must catch it when it arrives by a channel the agent never sees.

One piece of this rule is not yet in force, and the honest version of that story is worth telling because it shows how fast the ground moves. The FCC's revocation rules took an announced effective date of 11 April 2025. In April 2025 the Commission waived one element, the requirement that a revocation given in response to one type of message applies to all future robocalls and robotexts from that caller on unrelated matters, until 11 April 2026. On 6 January 2026 the Consumer and Governmental Affairs Bureau extended that same narrow waiver to 31 January 2027, pending a rulemaking that may modify the requirement (FCC Order DA 26-12). The Bureau was explicit about the scope: the waiver "extends only to section 64.1200(a)(10) to the extent discussed herein and does not alter the status quo relating to any other prior Commission rules or rulings addressing revocation of consent."

Which means: the ten-business-day deadline binds now. What is waived is only the cross-subject sweep of a single opt-out. Building your system to apply revocation across all subjects anyway costs little and is where the rule appears headed.

Timeline of the compliance clocks that bind an AI cold calling programme, from the 31-day registry refresh to five-year retention

Four clocks run at once. Only one of them, the January 2027 waiver expiry, is a date rather than a duration.

B2B is not a blanket exemption

This is the most consequential misunderstanding in AI cold calling, and it comes from reading two rulebooks as if they were one.

The FTC's Telemarketing Sales Rule does contain a business-to-business exemption. Under 16 CFR 310.6(b)(7), "telephone calls between a telemarketer and any business to induce the purchase of goods or services or a charitable contribution by the business" are exempt from the rule, with two carve-outs. The exemption does not apply to the prohibitions on misrepresentation in 310.3(a)(2) and (a)(4), and it does not apply to calls inducing "the retail sale of nondurable office or cleaning supplies." So under the FTC's rule, a B2B software vendor calling a business is largely outside the TSR, including its recordkeeping and do-not-call machinery.

The FCC's TCPA rules do not have an equivalent general carve-out, and their coverage is drawn on a different axis. The do-not-call and calling-window provisions in 64.1200(c) and (d) protect residential telephone subscribers, which is why business landlines are not on the national registry. But the artificial-voice and autodialer prohibitions in 64.1200(a)(1) and (a)(2) key on the line, not on the purpose of the call. Paragraph (a)(1)(iii) covers any number assigned to cellular service or any service where the called party is charged. There is no business exception in that text.

Put the two together and the actual boundary is this:

The callTSR (FTC)TCPA artificial-voice rules (FCC)
AI voice to a company's published landlineExempt under 310.6(b)(7), except misrepresentationNot a residential line; (a)(3) does not reach it
AI voice to a decision-maker's personal mobileExempt under 310.6(b)(7), except misrepresentationCovered by (a)(1)(iii) and (a)(2) — consent required
Human voice, manually dialed, to a mobileExempt under 310.6(b)(7), except misrepresentationNot an ATDS or artificial voice; (a)(1) not triggered
AI voice to a sole trader's number that is also their home lineExempt under 310.6(b)(7), except misrepresentationCovered; may also be residential for (c) and (d)

The second row is where modern B2B prospecting actually lives. Mobile numbers are what enrichment vendors sell and what get answered, and a mobile number is exactly where the B2B exemption stops helping. A team that read "B2B is exempt" in a vendor blog and pointed a synthetic voice at a list of personal mobiles has the FTC exemption it was told about and the FCC exposure it was not.

Two further limits. The TSR exemption is federal; state telemarketing statutes, the mini-TCPAs, are separate instruments with their own scope. And calls to prospects in the EU or UK sit under a different regime built on lawful basis and data-subject rights rather than call consent. If your list crosses borders, that is a separate assessment with separate counsel.

Four ways to run outbound with AI, and what each one exposes

Most teams frame this as build versus buy. The useful frame is how much of the call is machine-produced, because that is what the statutes attach to.

Option 1 — Fully autonomous AI voice dialing. The agent selects, dials, speaks and logs.

Best for: high-volume campaigns against lists where you personally captured written, number-specific consent. Renewal outreach to your own customers, event follow-up from your own forms. What it exposes: every provision above at once. Artificial-voice consent, opening identification, the two-second opt-out mechanism, window compliance at volume, and the full recordkeeping set. Verdict: defensible only on a list you originated. Pointing it at purchased data is the single highest-risk configuration in this article.

Option 2 — AI dials, human speaks. The system builds the queue, resolves numbers, checks the gate and connects a human rep when someone answers.

Best for: teams that want dialing efficiency without taking on artificial-voice consent. What it exposes: the autodialer question rather than the voice question, plus the call abandonment rules. Under 16 CFR 310.4(b)(1)(iv) a call is abandoned if a person answers and the telemarketer does not connect them to a sales representative within two seconds of their completed greeting; the safe harbour in 310.4(b)(4) requires abandonment of no more than three percent of answered calls, measured per campaign or per 30-day period, plus 15 seconds or four rings before disconnecting an unanswered call. Verdict: the best risk-adjusted default for cold lists. You keep the gate and the logging and drop the hardest consent question.

Option 3 — AI-assisted human calling. The human dials and speaks; AI does research, note-taking, CRM writeback and follow-up drafting.

Best for: small teams, complex products, and anyone whose consent evidence is thin and honestly acknowledged as thin. What it exposes: almost none of the artificial-voice or autodialer machinery. It moves the governance question to call recording and to what the assistant is allowed to touch. A different problem, and one covered by the transcript-ownership analysis in our earlier piece on conversational platforms. Verdict: the option that gets dismissed as unambitious and is usually correct for the first two quarters.

Option 4 — Do not call; use AI on channels where consent is cleaner. Research, sequencing and personalisation for email and social, with calls reserved for people who asked to be called.

Best for: teams selling into regulated buyers, or into jurisdictions where the calling analysis is expensive. What it exposes: different rules, not no rules. Verdict: the honest answer for a meaningful minority of teams, and one no vendor guide will give you.

Choose Option 1 if you own the consent capture surface and can produce fields i through vi for every number, today, without engineering work. Choose Option 2 if your lists are mixed provenance and you want volume anyway. Choose Option 3 if you cannot yet produce the record. Choose Option 4 if the phone is not where your buyer decides anything.

What this costs before it earns

Cost sections on this keyword quote per-minute voice pricing and stop. The costs that decide whether an AI cold calling programme is worth running sit on the compliance side, and two of them are published numbers.

Access to the national registry is priced per area code. Under 16 CFR 310.8(c), the annual fee "is $82 for each area code of data accessed, up to a maximum of $22,626," with the first five area codes free and cost-sharing prohibited. Adding area codes mid-year costs $82 in the first six months and $41 in the second. National coverage therefore has a published ceiling of $22,626 a year, and a team dialing five area codes pays nothing. Registry access is not the expensive part of compliance for a focused campaign.

The expensive part is the record. Five-year retention of call audio, script versions, rendered consent forms and disposition data is a storage and retrieval commitment, and the retrieval half is what gets underbuilt. We found no published industry benchmark for that cost and will not invent one. The honest planning number is your existing cost per gigabyte-year, times five years of call volume, plus the engineering to make it queryable by phone number.

On the other side of the ledger sits the exposure. The arithmetic is simple and worth doing before the campaign, not after:

ScenarioCalls with a provenance defectStatutory floor at $500Trebled at $1,500
Small pilot500$250,000$750,000
One month, one agent5,000$2,500,000$7,500,000
One quarter, small fleet50,000$25,000,000$75,000,000

Those are not predictions, and we want to be careful here rather than dramatic. They are the multiplication that 47 U.S.C. 227(b)(3) permits a plaintiff to argue for, with no aggregate cap in the statutory text. What actually gets recovered depends on class certification, on how many of those calls a plaintiff can tie to a common defect, and on settlement dynamics we have no verified data for and will not guess at. The table exists to make one narrower point: the cost of the calling infrastructure is not the number that should drive the decision. Anything that reduces the defect rate on the list is worth more than anything that reduces the cost per minute.

What to do with the list you have already bought. Telling a team to delete a purchased list is advice nobody follows, so here is the usable version. Segment it by line type first. Business landlines fall outside the residential do-not-call and artificial-voice provisions, and calling them with a human on a manually dialed line triggers neither the ATDS nor the artificial-voice prohibition. That segment is workable today. Personal mobiles from the same file are the segment to hold, and the productive move is not to dial them but to run a consent-earning motion first: email or social outreach on its own legal footing, with a call offered rather than imposed. When someone accepts, you capture fields i through vi at that moment and the number graduates from the purchased pile into one you originated. That converts a list you cannot defend into a smaller list you can, and it is the only route we have found that does not require either deleting the asset or gambling with it.

Six mistakes in the guides currently ranking for this keyword

We read the pages ranking for this term and checked every AI cold calling compliance claim on them against the regulation. Six errors recur.

  1. "Honour opt-outs within 30 days." The rule says a reasonable time "not to exceed ten (10) business days" under 64.1200(d)(3), and the same ten-business-day limit governs revocation under (a)(10). A monthly suppression sync is not compliant.
  2. "B2B calls are exempt." True for the TSR under 310.6(b)(7). Not true for the FCC's artificial-voice and autodialer rules when the number is a mobile. See the table above.
  3. "A human presses dial, so it is not a robocall." The FCC addressed this in FCC 24-17 by extending its Soundboard Ruling: a live agent choosing which recorded audio to play "does not negate the clear statutory prohibition." If the voice is synthetic, the prohibition applies.
  4. "Written consent is required." It was, under 64.1200(a)(2), and it still is in most of the country. The Fifth Circuit held in February 2026 that the statute permits oral consent too. Both statements are now partly true depending on venue, and a guide that states either flatly is out of date in one direction or the other.
  5. "Scrub monthly." The safe harbour requires the registry version to be no more than 31 days old at the time of each call. A monthly cadence with any slippage puts calls at the end of the cycle outside it.
  6. "Disclose that it is AI and you are covered." Disclosure is a separate obligation from consent, and it does not substitute for it. Under 64.1200(b)(1) an artificial-voice message must open by identifying the responsible business under its registered name. Identifying yourself perfectly on a call you had no consent to place does not cure the call.

The pattern in all six is the same: a rule that was true at some point, repeated without a date, then repeated by the next writer. Check the operative text yourself. The eCFR is free, current, and takes about ten minutes to read for this subject.

When cold calling still wins, and when it does not

An article that only lists constraints implies the answer is always no. It is not.

Outbound calling still works where the buyer's problem is urgent and undiagnosed, where the deal is large enough to justify interrupting a day, and where the other channels are saturated. AI genuinely helps with the mechanical parts: building the queue, resolving numbers, checking the gate, writing the disposition back, drafting the follow-up. Those are the parts humans do worst and resent most.

The incumbent, a small team of humans dialing a short, self-sourced list, still wins in three situations. When the list is under a few thousand names, the fixed cost of building the gate exceeds the efficiency gained. When the product needs a diagnostic conversation rather than a qualification script, the machine books meetings that should not have been booked and the cost lands on an account executive's calendar. And when your consent evidence is thin, the human team is not more compliant, but it is slower, and slowness is a functioning circuit breaker.

The honest test: if you removed the AI entirely, would this campaign be worth running? If the answer is no, AI is being asked to make a bad list economical rather than a good motion faster. That is the case where every risk in this article compounds and none of the upside arrives.

Where LeapForce fits, and where it does not

LeapForce does not dial telephones, does not sell a voice agent, and does not maintain consent databases or do-not-call lists. Nothing in our platform will scrub a number for you.

What we build is the layer underneath: one controlled place where every AI tool, connector, model and agent runs, so that an agent placing regulated communications has an owner, a scope, an expiry, and a record of what it did. For AI cold calling that narrows to a few questions. Which agent was permitted to reach the telephony connector, under whose authority, with what scope, and what does the tamper-evident log say happened. Same argument as our earlier analysis of audit trails for agent actions: the value of an audit record is decided long before anyone asks for it.

Our rollout model for the AI Gateway is Observe first. Enforce second. Optimize third. Applied here, it means pointing the outbound stack at the gateway in observe mode before writing a single policy, so you learn what the calling agent is actually doing: which connectors it reaches, what it costs, which numbers it touched. Only then decide what to forbid. Enforcement written before observation tends to forbid the wrong things.

In the spirit of our own honesty convention: gateway endpoints, SSO and tracing are live capabilities; shadow-AI discovery and compliance-evidence packs are on the roadmap and are not shipping today. If you need an evidence pack for a TCPA claim next quarter, build it yourself against the schema in this article.

Honest limits and open questions

This is a governance argument grounded in primary regulation. Four things it deliberately does not do.

It is not legal advice, and the ground is moving. Two federal appellate courts took different paths on core TCPA consent questions inside eighteen months, and the FCC has an open rulemaking that may modify the revocation rule before its waiver expires on 31 January 2027. Nothing here substitutes for counsel who knows which circuit you sit in.

We have not run an AI cold calling campaign. LeapForce does not do outbound voice prospecting, so there is no first-hand dial log behind this piece. What we did first-hand was verify each legal claim against the operative text: 47 CFR 64.1200 and 16 CFR 310 pulled from the eCFR on 31 July 2026, FCC 24-17 and DA 26-12 read in the Commission's own documents, and both appellate opinions read in the courts' published PDFs rather than in summaries. Every correction below came from that reading.

State law is under-covered here. Several states have their own telemarketing statutes, the mini-TCPAs, with narrower windows, additional consent requirements, or private rights of action. We chose depth on federal law over a shallow state-by-state table we could not verify statute by statute in one pass. Treat the federal analysis as the floor.

We have no defensible industry data on AI cold calling outcomes. Connect rates, meeting rates and cost-per-meeting for synthetic-voice outbound circulate widely and trace, when followed, to vendor marketing without disclosed methodology. We excluded all of it rather than repeat a number we could not source. If you need those figures, generate them from your own pilot; nobody else's are checkable.

The open question we cannot resolve. If the Fifth Circuit's reading spreads and oral consent becomes broadly sufficient, the evidentiary burden shifts from "produce the signed agreement" to "prove what was said". For a programme whose calls are made by machines, may end up being easier to satisfy than the written standard, not harder. Whether that makes AI outbound safer or merely differently risky is not yet knowable, and anyone telling you it is settled is selling something.

 FAQ

Frequently asked questions

Yes, conditionally. The FCC confirmed in its February 2024 Declaratory Ruling (FCC 24-17) that AI-generated voices are "artificial" voices under the TCPA, so calls using them require the called party's prior express consent, and prior express written consent where the call is telemarketing under 47 CFR 64.1200(a)(2). AI cold calling compliance turns on whether you can produce that consent for the specific number, not on how the call sounds.

Under the FCC's rule, yes, for any call that advertises or constitutes telemarketing using an artificial voice or an autodialer. That rule is contested: in Bradford v. Sovereign Pest Control, decided 25 February 2026, the Fifth Circuit held the TCPA permits either written or oral consent. The practical answer is to capture written, number-specific, signed consent anyway. It satisfies the strictest reading on the board and needs no rework if the law shifts again.

Only half of it. The FTC's Telemarketing Sales Rule exempts most business-to-business calls under 16 CFR 310.6(b)(7), excluding misrepresentation claims and nondurable office or cleaning supplies. The FCC's rules have no equivalent general exemption, and 47 CFR 64.1200(a)(1)(iii) covers any number assigned to cellular service regardless of why you are calling. A synthetic voice dialing a decision-maker's personal mobile is covered even though the conversation is entirely about business.

To rely on the safe harbour in 47 CFR 64.1200(c)(2)(i)(D), the registry version you use must have been obtained no more than 31 days before the call is made. That is a per-call test, not a per-month process, so a monthly cadence that slips leaves the last calls of each cycle outside the safe harbour. Keep the version, access date and account number, which 16 CFR 310.5(a)(11) requires as its own record.

Ten business days. Both 47 CFR 64.1200(d)(3), for internal do-not-call requests, and 64.1200(a)(10), for revocation of consent, cap the honouring period at a reasonable time "not to exceed ten (10) business days." Several guides on this topic still say thirty days. Requests must be retained for five years, and you may not designate an exclusive method for making them.

Under 16 CFR 310.8(c), the annual fee is $82 per area code of data, capped at $22,626 for national coverage, with the first five area codes free. Additional area codes cost $82 in the first six months of the annual period and $41 in the second. Cost-sharing arrangements between sellers are prohibited by the same provision.

Not safely, and this is the highest-risk configuration described in this article. A purchased list supplies telephone numbers; the TCPA requires consent traceable to the called party, and 47 CFR 64.1200(f)(9) defines written consent as a signed agreement naming the seller and the specific number. Vendor assurances of compliance are not that record. Under 64.1200(d)(3), if a third party maintains the suppression data, the entity on whose behalf the call is made remains liable for failures.

No, not if the voice on the line is synthetic. In FCC 24-17 the Commission applied the reasoning of its 2020 Soundboard Ruling, which held that a live agent selecting which prerecorded audio to play "does not negate the clear statutory prohibition against initiating a call using a prerecorded or artificial voice." A human in the seat changes the workflow, not the legal character of the audio.

Use the schema the FTC already wrote. 16 CFR 310.5(a)(2) specifies the per-call record: who placed it, for which seller, the good or service, whether the recipient was an individual or business, whether it was outbound, whether it used a prerecorded message, calling and called numbers with date, time and duration, the script and prerecorded message used, the caller-ID name and number transmitted with proof of authorisation, and the disposition including any transfer target. Add the six consent fields from 310.5(a)(8) and retain everything five years.

Run one test: can you produce, right now and without engineering work, the six consent fields from 16 CFR 310.5(a)(8) for every number in the campaign? If yes, a full AI dialer is defensible on that list. If no, use AI for queue building, number resolution, note-taking and follow-up while a human speaks. You keep most of the efficiency and drop the hardest consent question.

Not in the part of the job that carries the risk. AI reliably handles queue construction, number resolution, gate checks, CRM writeback and follow-up drafting. What it does not do is notice that the third person this hour asked where their number came from. That is the human signal that a list has a provenance defect. Until that signal is instrumented rather than felt, the correct configuration is fewer humans doing more judgement, not no humans.

Ready to Govern Your AI?

Talk to LeapForce — one controlled layer for every AI tool, connector, model, and agent.

Thirty minutes · No pitch deck

Ready to turn AI experiments into measurable ROI?

Bring one outcome you'd like AI to move. We'll help you scope a pilot you can actually measure — and tell you honestly if it's not worth doing yet.

Comments