What are the new bot disclosure laws for AI voice calls in 2026: outbound campaigns must disclose an AI-generated voice at the start of the call, secure proper consent, and follow state statutes such as California's AB 2905. The FCC's February 2024 ruling classifies AI voices as robocalls, with TCPA violations carrying $500 to $1,500 in statutory damages per call.
What are the key regulatory changes for outbound AI voice calls in 2024 and 2025?
The key regulatory changes came from the FCC's February 2024 Declaratory Ruling and California's disclosure statutes. The FCC ruling classified AI-generated voices as 'artificial or prerecorded voice' calls under the TCPA, and California's AB 2905 added a verbal AI-disclosure requirement for automated calls effective January 1, 2025.
The Congressional Research Service, in its briefing "Combating Robocalls and Robotexts," describes the resulting regime as layered: federal TCPA rules, FCC interpretations, and state bot-disclosure laws all apply at once to the same outbound call. That layering matters operationally. A healthcare group calling patients across state lines has to satisfy federal consent rules and whatever disclosure statute applies in the patient's state, in the same call, with the same script. Kelley Drye's coverage of the FCC's rulemaking notes the agency has kept building on the 2024 ruling since, including a proposal that would force businesses to sync opt-out and suppression lists across every platform they use to dial.
What must operators do now to comply with new bot-disclosure laws?
Operators must add a spoken AI disclosure at call start, capture documented consent before dialing, and log every consent, disclosure, and opt-out event. These three controls must sit inside the call flow itself, not as after-the-fact paperwork, because TCPA compliance is evidenced through audit trails, not intent.
In practice this means a written disclosure script embedded in the call flow, not left to an agent's judgment, and a consent record tied to the specific number, purpose, and date. A structured guide to writing prompts for compliant voice AI calls covers how the disclosure language itself should be built into the model's opening turn. On the data side, mapping auditable TCPA and DNC records into a CRM is what turns a defensible consent claim into something a compliance team can actually produce on request rather than reconstruct after a complaint.
How do the FCC's February 2024 ruling and proposed rules affect outbound AI calls?
The FCC's February 2024 Declaratory Ruling brought every outbound AI voice call under existing robocall law, and pending rules would add a mandatory spoken disclosure. Under the ruling, AI-generated voices trigger the same consent, identification, and opt-out obligations that already apply to prerecorded and autodialed calls.
According to the FCC's own public notice, titled "FCC Makes AI-Generated Voices in Robocalls Illegal," the agency has been explicit that unauthorized use of AI-generated voices in robocalls violates existing law. The proposed rules go further: a required 'clear and conspicuous' disclosure at the beginning of each AI-generated call, and reliable, synced opt-out processing across every system a business uses to dial. Neither requirement is optional for an enterprise running high call volume; both need to be enforced before a number is dialed, not caught in a post-call review.
What are the state-level disclosure requirements for AI voice calls?
State disclosure requirements layer on top of federal TCPA rules, with California and Utah setting the current benchmarks. California's AB 2905 requires callers to state that a prerecorded message uses an AI-generated or significantly altered voice, backed by penalties up to $500 per violation, while Utah adds disclosure duties for regulated professions.
Because these requirements do not replace federal rules, they stack on top of them. A campaign compliant with the TCPA can still violate a state disclosure statute if the script skips the required language for that jurisdiction.
| Jurisdiction | Disclosure Requirement | Consent Standard | Penalty Exposure |
|---|---|---|---|
| Federal (TCPA / FCC) | Clear disclosure proposed at start of AI-generated call | Prior express written consent for marketing calls | $500 to $1,500 per call |
| California (AB 2905) | Verbal disclosure that voice is AI-generated, effective Jan 1, 2025 | Applies to any auto dialing-announcing device using AI voice | Up to $500 per violation |
| Utah | Disclosure required if asked, or proactively for regulated professions | Context-dependent, profession-specific | Not separately quantified |
| EU (AI Act Art. 50(1) plus ePrivacy) | Immediate disclosure at call start unless obvious | Prior opt-in consent required before calling | Not separately quantified |
What is the financial exposure for noncompliant AI outbound calls?
Financial exposure for a noncompliant AI outbound campaign scales directly with call volume under TCPA statutory damages. Ginsburg Law Group notes that TCPA violations carry statutory damages of $500 to $1,500 per call, a range that turns a single noncompliant campaign into a seven-figure liability at scale.
An analysis published by Apten.ai calculates that a campaign dialing 10,000 numbers a day could face exposure as high as $15 million under the FCC's maximum per-call penalty, purely from statutory damages before any state penalty is added. That last point is the trade-off operators tend to miss: a California AB 2905 violation at up to $500 per call does not replace federal TCPA exposure, it stacks on top of it. Treating the two as alternative risks instead of additive ones is a common and expensive misread of the compliance stack.
How should enterprises implement consent, disclosure, and opt-out controls?
Enterprises should implement consent, disclosure, and opt-out controls as hard gates inside the call flow, not manual checklists. Each outbound number must pass a real-time suppression check, each call must open with disclosure language, and every consent and opt-out event must log a timestamp, purpose, and script version before the campaign advances.
Consider an exotic car rental operator remarketing to past renters ahead of a season. Every number on that list needs to clear the current DNC and internal opt-out suppression list before the dial attempt, not just at list-build time weeks earlier. A voice AI playbook built for exotic car rentals and high-value logistics walks through how that gating fits into a lead-conversion flow without slowing down speed to lead. Agxntsix builds these gates directly into the orchestration layer of the campaigns it deploys, and as a member of the Claude Partner Network, it builds that layer on the same Claude-based agent infrastructure it uses for the rest of an enterprise's voice stack, rather than treating compliance as a separate bolt-on system.
What is the difference between marketing and non-marketing AI calls for compliance?
Marketing AI voice calls require prior express written consent from the called party, while non-marketing AI calls face a lower but still real consent bar under TCPA voice-call rules. Both call types must include disclosure and opt-out mechanisms when the voice is AI-generated, regardless of commercial intent.
A healthcare group sending an AI-voiced appointment reminder is not running a marketing call, but it is still a TCPA-regulated voice call, and if patient health information is discussed, HIPAA obligations layer on top of the consent question. A financial services firm calling to promote a new account, by contrast, sits squarely in the higher marketing-consent bracket. Sorting a call list by purpose before dialing, not after a complaint, is what keeps the two standards from getting blurred together.
How do the EU AI Act and ePrivacy rules affect outbound AI calling?
The EU AI Act and ePrivacy rules add a third compliance layer for any outbound AI calling into Europe. Article 50(1) of the AI Act requires immediate disclosure at call start unless the AI's involvement is obvious, and ePrivacy rules require prior opt-in consent before the call is placed at all.
Softcery's guidance for founders operating voice AI in the EU frames this as a compliance stack in its own right: consent to call under ePrivacy, AI disclosure under the AI Act, and a separate privacy basis for handling the caller's data. An enterprise dialing across both the U.S. and EU cannot run one script and one consent policy; it needs jurisdiction-aware routing that swaps disclosure language and consent checks based on where the call terminates.
What specific steps should enterprise teams take to build a compliant outbound AI calling stack?
Enterprise teams should build compliance into the call stack itself: consent gating before dialing, an embedded disclosure script, real-time suppression checks, and full event logging. These four layers plus vendor governance and jurisdiction-based routing turn compliance from a legal afterthought into an operating requirement enforced on every dial attempt.
- Gate every outbound list against current consent status before a campaign starts.
- Embed the disclosure script directly in the call flow's opening turn, not as an optional agent line.
- Run a real-time suppression check against DNC and internal opt-out lists immediately before each dial.
- Log consent, disclosure, and opt-out events with a timestamp, purpose, and script version for every call.
- Apply vendor governance to any third-party voice AI platform, confirming it enforces these controls rather than assuming it.
- Route calls by jurisdiction so the disclosure wording and consent standard match the state or country the number belongs to.
None of this replaces legal review. Operators building or expanding an outbound AI calling program should confirm current federal, state, and international requirements with counsel before launch, since penalty structures and disclosure wording continue to shift.
Sources
- AI Disclosure Requirements for Voice Agents
- TCPA, FCC, and State Laws Every Sales Team Must Know - Apten.ai
- The 2026 TCPA Compliance Playbook for Voice AI Outbound
- US Voice AI Regulations 2026: TCPA, BIPA, COPPA ...
- Using AI in Customer Service and Telemarketing: Top-7 ...
- Navigating State Disclosures: Operational Protocols for Dual ...
- Voice AI Compliance in India | Rootle.ai
- AI Disclosure Laws 2026: When You Must Tell Callers It's AI
