TCPA and Telemarketing Rules · October 2, 2026 · GrowthPros

Can I use AI to make cold calls?

Can AI make cold calls? Only with consent. Learn FCC TCPA rules for AI voice calls, the one-to-one consent rule, and how to run compliant AI outreach in...

Flat illustration of a smartphone with an AI voice waveform flowing into a consent shield, accented in lime green, with headline about compliant AI cold calls.

Key Facts

  • The FCC's February 2024 Declaratory Ruling confirmed AI-generated voices are "artificial or prerecorded" under the TCPA, requiring prior express consent for marketing calls per the FCC ruling.
  • TCPA violations carry $500 per call statutory damages, up to $1,500 for willful violations, with no cap on class-action size according to TCPA compliance analysis.
  • A misconfigured campaign of 10,000 non-compliant AI calls could create $5 million to $15 million in exposure per compliance risk modeling.
  • The one-to-one consent rule effective January 27, 2025 requires each consumer to explicitly authorize calls from a single, named seller for one topic per TCPA compliance guidance.
  • The National Do Not Call Registry contains over 249 million active registered numbers that must be scrubbed every 31 days according to TCPA compliance sources.
  • Contacting a lead within five minutes makes contact roughly 100x more likely than waiting thirty minutes, and about 78% of buyers choose whoever responds first per GrowthPros insights.
  • 73% of B2B buyers actively avoid suppliers that send irrelevant outreach, making cold AI dialing commercially risky per Gartner 2025 data.

The February 2024 FCC Declaratory Ruling (FCC 24-17) confirmed that AI-generated voices fall under the TCPA’s definition of "artificial or prerecorded voice," meaning unconsented AI marketing calls are illegal robocalls. This ruling settled a key legal question: AI voice technology requires the same prior express consent as traditional robocalls. For businesses, the stakes are immediate and severe — TCPA violations carry statutory damages of $500 per call, up to $1,500 for willful violations, with no cap on class-action size.

A misconfigured campaign calling just 10,000 numbers outside permitted hours or without proper consent could create $5 million to $15 million in exposure. Larger missteps scale rapidly — 100,000 non-compliant calls could result in $50 million to $150 million in damages. These figures underscore why consent isn’t a box-ticking exercise but the foundation of any lawful AI calling strategy. The FCC’s ruling explicitly ties AI voice use to the prior express consent requirement, leaving no room for ambiguity in marketing contexts.

For companies like GrowthPros, this compliance framework aligns directly with how leads are sourced and delivered. Every lead comes with a consent record that includes disclosure text, timestamp, IP address, and the named contacting party — meeting the TCPA’s requirement for prior express written consent that names the specific seller. This consent-recorded model ensures AI follow-up occurs only on opted-in relationships, never cold lists. By embedding compliance into the lead delivery process — including DNC scrubbing and immediate opt-out honoring — businesses can use AI for speed-to-lead follow-up without triggering TCPA risk.

  • Consent must name the specific seller under the one-to-one consent rule effective January 27, 2025
  • AI disclosure at call start, real-time opt-out suppression, and jurisdiction-based calling windows are baseline controls
  • Reactivation campaigns target only pre-existing, opted-in lists — never cold numbers

The path forward is clear: AI can legally enhance outreach when built on a foundation of verified consent, transparent disclosure, and rigorous list hygiene. For businesses seeking to use AI in calling, the compliant approach isn’t about avoiding the technology — it’s about deploying it within the boundaries the FCC has now explicitly defined. This means treating every AI-initiated call as subject to the same rules as a prerecorded voice message, with consent as the non-negotiable starting point.

The FCC has already answered the question of whether AI voices count as "artificial voices" — they do. But the ruling that matters most to your campaign isn't about the technology at all. It's about whether the person on the other end said yes, in writing, to your specific brand.

For marketing calls using AI voice, the legal standard is prior express written consent (PEWC) — a signed, standalone agreement, not language buried in terms of service or tied to a purchase, per TCPA compliance guidance. Informational calls need only prior express consent, but the moment your AI agent pitches a product, the written standard applies. And the stakes are steep: TCPA statutory damages run $500–$1,500 per violation with no cap on class size, meaning a misconfigured campaign of 10,000 calls could create $5M–$15M in exposure.

The one-to-one consent rule, effective January 27, 2025, tightened the screws further. Each consumer must explicitly authorize calls from a single, named seller for one topic — broad multi-seller consent collected by lead generators no longer satisfies PEWC. This is where most AI calling programs get into trouble: lead-generation forms that omit the brand name create the most common TCPA exposure. If a consumer agreed to hear from "a trusted partner" but never saw your company's name, you don't have consent — you have a lawsuit waiting for a plaintiff's lawyer.

The burden of proof compounds the problem. As one compliance analysis puts it, "a consent that cannot be retrieved per number within an hour is functionally a consent that does not exist in litigation." That's why GrowthPros attaches a consent record — disclosure text, timestamp, IP address, and named contacting party — to every lead before AI follow-up ever runs. A consent trail you can't produce is worth nothing in court.

The courtroom landscape adds another layer of uncertainty. The June 2025 McLaughlin v. McKesson decision held that FCC interpretations are not automatically binding on federal courts, creating what TCPA practitioners describe as a fragmented compliance landscape. The recommended posture is conservative policies that go beyond FCC rules and can withstand judicial scrutiny. Meanwhile, state mini-TCPAs in Arizona, Connecticut, Florida, Maryland, Oklahoma, and Washington are often stricter than federal standards:

  • A campaign compliant in one state may put you at risk in another, since state standards vary widely.
  • Texas, California, Utah, and Maine impose AI disclosure or telemarketing restrictions regardless of call direction.
  • Recent legislation — Texas in 2025, Oregon in 2026, New York in 2025 — keeps tightening calling windows, daily attempt limits, and disclosure rules.

The takeaway is simple: consent quality, not voice quality, determines whether your AI campaign is legal. A lead with documented, seller-named, timestamped consent can be called by an AI agent within minutes of opting in. A "fresh" list with no consent trail cannot be called at all — not by a human, and certainly not by a machine.

The Six-Control Compliance Stack Every AI Calling Program Needs

The FCC's February 2024 Declaratory Ruling settled the baseline: AI-generated voices are "artificial or prerecorded" under the TCPA, so every outbound AI call requires prior express consent. That single finding turns a technology decision into a consent-management problem. Six controls appear across every credible source — consent verification, AI disclosure at call start, real-time opt-out suppression, jurisdiction-based calling windows, comprehensive recordkeeping, and human escalation — and they function as an interdependent stack, not a checklist.

  • Consent verification before every dial: the one-to-one consent rule effective January 27, 2025 requires each consumer to explicitly authorize calls from a single, named seller for one topic; broad multi-seller consent no longer satisfies PEWC.
  • AI disclosure at call start: the called party must hear they are speaking with an AI system immediately, not after qualification.
  • Real-time opt-out suppression across voice, SMS, and email within 10 days, with expanded keyword recognition required starting April 11, 2025.
  • Jurisdiction-based calling windows: federal hours are 8:00 a.m.–9:00 p.m. local time, but many states end at 8:00 p.m., and a campaign compliant in one state may put you at risk in another.
  • Comprehensive recordkeeping that survives scrutiny: consent artifacts, call logs, DNC scrub timestamps, and opt-out confirmations retained longer than the longest applicable requirement — sources cite 24 months to 7 years depending on regime.
  • Human escalation for any request, dispute, or edge case the AI cannot cleanly resolve.

The operational cadence is non-negotiable. DNC lists must be scrubbed every 31 days against a registry of over 249 million active numbers, and opt-outs must be honored within 10 days across every channel. A misconfigured campaign of 10,000 calls outside permitted hours can create $5M–$15M in TCPA exposure, with statutory damages of $500–$1,500 per violation and no cap on class size. Post-McLaughlin v. McKesson, FCC interpretations are not automatically binding on federal courts, so conservative policies that exceed federal minimums are the only defensible standard. GrowthPros builds this stack into every lead product: each lead arrives with its consent record — disclosure text, timestamp, IP address, and named contacting party — already DNC-scrubbed and qualified before any AI follow-up begins.

Where AI Calling Actually Works: Follow-Up, Not Cold Dials

The real question isn't whether AI can dial a cold list — it's whether it should. Legally, an unconsented AI voice call to a consumer is just an illegal robocall: the FCC's February 2024 ruling confirmed that AI-generated voices fall squarely under TCPA restrictions and require prior express consent. And with statutory damages of $500 per violation (up to $1,500 for willful conduct) and no cap on class size, a misconfigured 10,000-call campaign can create $5M–$15M in exposure.

The compliant, effective pattern that emerges across every serious source is different: AI doesn't dial strangers — it follows up on people who already raised their hands.

That model works because consent changes everything. When a lead fills out a form that names the specific seller, the AI can call, text, and email that person within minutes without creating TCPA risk — and speed matters enormously. Contacting a lead within five minutes makes contact roughly 100x more likely than waiting thirty minutes, and about 78% of buyers choose whoever responds first.

It also works commercially. One operator describes the division of labor plainly: "We use AI to handle the first 80% of qualification so human representatives can focus on the 20% that closes deals." The AI qualifies intent, answers questions, and books the call — then hands a warm, pre-qualified contact to a human rep. That's not cold calling; that's speed-to-lead.

The foundation for all of it is the lead itself. AI voice follow-up is only safe on leads that arrive with a documented consent basis:

  • Disclosure text, timestamp, IP address, and the named contacting party attached to every lead
  • DNC scrubbing before any outbound contact — the Registry holds over 249 million active numbers
  • Immediate, permanent opt-out honoring across SMS, voice, and email
  • Reactivation limited to pre-existing, opted-in relationships — never cold lists

This is exactly how GrowthPros structures its lead delivery: every lead is consent-recorded and DNC-scrubbed before AI voice, SMS, and email follow-up begins inside a five-minute window, with the consent trail attached when the lead lands in your CRM. The AI qualifies; your team closes.

The contrast with cold dialing is stark. Beyond the legal exposure, cold AI outreach fights the market itself — 73% of B2B buyers actively avoid suppliers that send irrelevant outreach, and a "Scam Likely" label can slash answer rates by 40% or more within a week. Consented follow-up avoids both problems at once.

If you have a dormant opted-in list or buy leads by niche, the compliant path is already built: book the 15-minute qualification call and see whether consent-recorded leads with five-minute AI follow-up fit your pipeline.

Frequently Asked Questions

Can AI legally make cold calls without consent?
No, AI-generated voices are treated as artificial or prerecorded voices under the TCPA, requiring prior express consent for marketing calls. Unconsented AI calls are illegal robocalls with statutory damages of $500–$1,500 per violation and no cap on class size.
What does prior express written consent need to include to be valid for AI calls?
Prior express written consent must be a signed, standalone agreement that names the specific seller — broad or multi-seller consent from lead generators does not satisfy the one-to-one consent rule effective January 27, 2025.
What are the six essential controls for a compliant AI calling program?
The six-control compliance stack includes consent verification before every dial, AI disclosure at call start, real-time opt-out suppression, jurisdiction-based calling windows, comprehensive recordkeeping, and human escalation for unresolved cases.
Is it safer to use AI for cold lists or follow-up on opted-in leads?
AI calling is only legally safe on consent-recorded, opted-in leads — not cold lists. Using AI to follow up within five minutes of opt-in increases contact likelihood by roughly 100x compared to waiting thirty minutes.
How do state laws affect AI calling compliance compared to federal rules?
State mini-TCPAs in Arizona, Connecticut, Florida, Maryland, Oklahoma, and Washington are often stricter than federal standards, and a campaign compliant in one state may create risk in another due to varying calling windows, disclosure rules, and opt-out requirements.
What happens if I can’t prove consent for a number during litigation?
A consent record that cannot be retrieved per number within an hour is functionally invalid in court — the burden of proof falls on the caller, making timely, accessible consent documentation essential for defense.

The Verdict Is In: AI Wins on Warm Lists, Not Cold Ones

So, can AI make cold calls? Legally, yes — but only after the person on the other end has given prior express written consent naming your specific brand. The FCC's February 2024 ruling made it clear that AI-generated voices are artificial voices under the TCPA, and with statutory damages of $500–$1,500 per violation and no cap on class size, a misconfigured 10,000-call campaign can create $5M–$15M in exposure. The real opportunity isn't dialing strangers — it's speed-to-lead follow-up on consented contacts, where reaching a lead within five minutes makes contact roughly 100x more likely. That's why GrowthPros delivers every lead with its consent record attached — disclosure text, timestamp, IP address, and named seller — DNC-scrubbed before any AI voice, SMS, or email follow-up runs. If you're ready to put AI to work on the right side of the consent line, book the 15-minute qualification call and see whether consent-recorded leads with five-minute follow-up fit your pipeline.

This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.

Start

More booked calls. Not more form fills.

Tell us your niche and your goal. We will show you realistic volume, exclusivity options, and what follow-up looks like on a live call — no pressure, no 40-page deck.