
TCPA and Telemarketing Rules · October 2, 2026 · GrowthPros
Can you be sued for using AI voice?
Learn if AI voice calls can trigger TCPA lawsuits. Get compliance rules, consent requirements, and real settlement examples to avoid $500–$1,500 per-cal...

Key Facts
- AI-generated voice calls are now classified as artificial or prerecorded under the TCPA with no technological safe harbor
- AI voice calls face uncapped statutory damages of $500–$1,500 per call with no statutory limit
- A non-compliant 10,000-call AI voice campaign risks $5 million to $15 million in statutory penalties
- TCPA filings increased 95% year-over-year with aggregate verdicts exceeding $925 million
- Gen Digital settled for $9.95 million in January 2026 over prerecorded calls to non-customers
- Hy Cite Enterprises paid $4.75 million in early 2026 for TCPA violations involving AI voice calls
- Automated interactive opt-out must be delivered within two seconds of call initiation for TCPA compliance
- Internal opt-out requests must be honored within 10 business days under updated FCC guidance
- DNC registry scrubbing is required at least every 31 days for AI voice call compliance
- Phone numbers must be checked against the FCC Reassigned Numbers Database every 59 days without right-party contact
- Calling records should be retained for seven years to exceed the four-year TCPA statute of limitations
- The same audit trail that protects compliant operators can convict non-compliant ones in class actions
- Assuming an Established Business Relationship exempts AI voice calls from consent is the single most expensive misunderstanding
- Texas requires AI disclosure within 30 seconds under SB 140 effective September 2024
- California mandates AI disclosure under AB 489 and SB 1001 for outbound calls
- Fifth Circuit holds only prior express consent (oral OK) is required for marketing AI calls, creating a jurisdictional split
- Consent-recorded leads must include disclosure text, timestamp, IP address, and named contacting party
- Reactivation campaigns must target only pre-existing, opted-in relationships — never cold lists
- Every lead shipped by GrowthPros includes a consent trail with disclosure text, timestamp, IP, and contacting party
The Legal Reality: AI Voice Calls Are Now Regulated Robocalls Under TCPA
The FCC's February 2024 ruling fundamentally changed the legal landscape for AI-generated voice calls, eliminating any technological safe harbor by classifying them as artificial or prerecorded voice under the TCPA. This means businesses using AI voice for outreach now face the same regulatory exposure as traditional robocallers, with liability flowing directly to the entity benefiting from the calls—whether they dialed the number themselves or used a third-party platform. As noted in compliance guidance, "the primary responsibility of our customers to ensure that their use of our platform complies with all applicable laws and regulations, including the TCPA" cannot be outsourced.
This classification triggers uncapped statutory damages of $500–$1,500 per call, creating severe financial exposure even for modest campaigns. A non-compliant 10,000-call sequence, for example, risks $5 million to $15 million in statutory penalties before courts consider actual harm. Real-world enforcement underscores this risk: Gen Digital settled for $9.95 million in January 2026 over prerecorded calls to non-customers, while Hy Cite Enterprises paid $4.75 million early the same year. These settlements reflect a broader trend, with TCPA filings increasing 95% year-over-year and aggregate verdicts exceeding $925 million.
For companies like GrowthPros that rely on AI voice for speed-to-lead follow-up within five minutes, compliance hinges on obtaining the correct consent level—prior express written consent for marketing calls and prior express consent for informational outreach—and delivering immediate AI disclosure. Critical requirements include providing an automated, interactive opt-out mechanism within two seconds of call initiation, honoring internal opt-out requests within 10 business days, and scrubbing numbers against the DNC registry at least every 31 days. Failure to meet any of these standards creates liability, particularly because AI systems generate detailed audit trails that plaintiffs can use to prove violation patterns across entire classes.
- Maintain separate consent tracking for marketing (PEWC) and informational (PEC) calls using dual-checkbox forms
- Deploy universal AI disclosure within two seconds: "This is an AI assistant calling from [Company] on a recorded line. Is this a good time to talk?"
- Honor opt-out requests in real time for TCPA compliance and within 10 business days for internal requests
- Scrub against DNC every 31 days and the FCC Reassigned Numbers Database every 59 days without right-party contact
- Retain calling records for seven years to exceed the four-year TCPA statute of limitations
Critical Compliance Gaps: Consent, Disclosure, and Opt-Out Failures in AI Calling
Most AI-calling lawsuits don't stem from exotic legal theories — they come from three repeatable, documentable failures. And because AI platforms log everything, plaintiffs' attorneys can prove those patterns across an entire class using a company's own records.
The stakes make this worth understanding. TCPA statutory damages run $500–$1,500 per call with no cap, meaning a single non-compliant 10,000-call campaign can create $5M–$15M in exposure before a court weighs actual harm. Class-action settlements in 2025–2026 have ranged from $5M to $20M, including Gen Digital's $9.95M settlement for prerecorded calls to non-customers.
The first pattern involves AI agents that make the initial call, then hand the conversation to a seller without valid consent in place. Both parties can face liability — the AI caller and the business receiving the transfer.
This matters because liability follows the entity that benefits from the calls. In recent litigation against lead generators and vendors, courts are treating outsourced dialing as outsourced nothing: compliance risk cannot be contracted away.
There's also a related trap: assuming an Established Business Relationship exempts AI voice calls from consent. Live agents may call past customers under EBR for DNC purposes, but AI agents cannot without separate consent — a misunderstanding described as the single most expensive one in AI calling.
The second pattern is disclosure that arrives late or not at all. Automated, interactive opt-out must be delivered within two seconds of the initial message, activatable by voice command or key press. Texas requires AI disclosure within 30 seconds under SB 140, while California mandates it under AB 489 and SB 1001.
A defensive disclosure sentence — "This is an AI assistant calling from [Company] on a recorded line. Is this a good time to talk?" — satisfies Texas's 30-second rule, California's bot disclosure obligation, and the pending federal NPRM. It costs nothing to say and everything to omit.
The third pattern is campaigns that keep dialing after a STOP request. Internal opt-out requests must be honored within 10 business days under updated FCC guidance, and revocations should apply immediately and permanently across every channel and campaign — not just the one that triggered them.
This is where audit trails cut both ways. As one legal analysis puts it, the same audit trail that protects a compliant operator convicts a non-compliant one. Timestamped consent records, disclosure logs, and revocation histories either prove your process or document your violations across the whole class.
For businesses running AI follow-up — including reactivation of dormant opted-in lists — the architecture has to be built for this from day one: DNC scrubbing at least every 31 days, Reassigned Numbers Database checks every 59 days without right-party contact, and 7-year record retention to outlast the 4-year statute of limitations. At GrowthPros, every lead ships with its consent trail attached — disclosure text, timestamp, IP address, and named contacting party — because in a class action, your records are the evidence either way.
If you're buying leads or reviving a list and want the compliance architecture explained before you commit to anything, book the 15-minute qualification call — it's free and commits you to nothing.
GrowthPros-Compliant AI Follow-Up: Built-In Safeguards for TCPA-Adherent Lead Engagement
The FCC's February 2024 declaratory ruling settled the debate: AI-generated voices are "artificial or prerecorded" under the TCPA, with no carve-out for conversational realism. That classification means every outbound AI call carries the same $500–$1,500 per-call statutory exposure as a traditional robocall, and class-action settlements in 2025–2026 have already reached $5M–$20M. A non-compliant 10,000-call campaign creates $5M–$15M in potential liability before a court weighs actual harm. The audit trail that proves compliance for a disciplined operator becomes the plaintiff's best evidence against a careless one.
GrowthPros bakes compliance into the follow-up layer so clients never have to choose between speed and safety. Every lead arrives with a consent record—disclosure text, timestamp, IP address, and the named contacting party—captured at the moment of opt-in. Lists are DNC-scrubbed before any outbound touch, and opt-outs are honored immediately and permanently across voice, SMS, and email. Reactivation campaigns target only pre-existing, opted-in relationships, never cold lists, with the FCC's one-to-one consent direction built in from day one.
- Consent-recorded leads with disclosure text, timestamp, IP, and named contacting party attached
- Immediate AI disclosure on every call—within the two-second window regulators expect
- Real-time opt-out synchronization across voice, SMS, and email channels
- DNC scrubbing before every outbound batch and reassigned-number checks every 59 days
- Seven-year audit trail retention exceeding the four-year TCPA statute of limitations
The result is a follow-up engine that moves at five-minute speed without inheriting the compliance debt that sinks unprepared operators. When the audit trail is complete, the conversation starts on solid ground.
Frequently Asked Questions
Can I really get sued just for using an AI voice agent to call leads?
Yes. The FCC's February 2024 ruling classified AI-generated voices as "artificial or prerecorded voice" under the TCPA, so every outbound AI call carries the same legal exposure as a traditional robocall. Violations run $500–$1,500 per call with no cap, and class-action settlements in 2025–2026 have ranged from $5M to $20M.
If I use a third-party AI calling platform, aren't they legally responsible for compliance?
No — liability follows the entity benefiting from the calls, whether you dialed the numbers yourself or used a vendor. Courts have treated outsourced dialing as outsourced nothing: compliance risk cannot be contracted away, so platform customers bear primary responsibility for TCPA compliance.
How much could a non-compliant AI calling campaign actually cost me?
A single non-compliant 10,000-call campaign creates $5M–$15M in statutory exposure before a court even weighs actual harm. Real enforcement backs this up: Gen Digital settled for $9.95M and Hy Cite Enterprises paid $4.75M in early 2026, with TCPA filings up 95% year-over-year.
Can I call past customers with AI without getting new consent if we have an established business relationship?
No — this is described as the single most expensive misunderstanding in AI calling. Live agents may call past customers under an established business relationship for DNC purposes, but AI agents cannot without separate consent, and the first AI solicitation call without consent can itself be a violation.
What do I have to say on an AI call to stay compliant?
Disclose immediately: an automated, interactive opt-out must be offered within two seconds of the initial message, and a defensive opening like "This is an AI assistant calling from [Company] on a recorded line" satisfies Texas's 30-second rule, California's bot disclosure laws, and the pending federal NPRM. Missing or delayed disclosure is one of the three violation patterns driving current lawsuits.
Do I need written consent for every AI call, or does a verbal yes count?
In 47 states, marketing AI calls to wireless numbers require prior express written consent, though the Fifth Circuit's Bradford decision held that oral prior express consent suffices in TX, LA, and MS. For national campaigns the split doesn't eliminate risk, so separate consent tracking for marketing (written) and informational calls is the safe architecture.
The Audit Trail Doesn't Lie — Build It Right the First Time
The FCC's February 2024 ruling closed the door on ambiguity: AI-generated voice is an artificial or prerecorded voice under the TCPA, full stop. That classification carries $500–$1,500 per call in uncapped statutory damages, and class-action settlements in 2025–2026 have already reached $5M–$20M. The lawsuits driving those numbers aren't built on novel theories — they're built on three repeatable failures: consent gaps during call transfers, disclosures that arrive too late or not at all, and opt-out requests that go unhonored. The danger is that AI platforms log every timestamp, every disclosure, every revocation. That audit trail either proves your process or documents your violations across an entire class. GrowthPros bakes compliance into the follow-up layer so the leads you buy — and the dormant lists you already own — move at five-minute speed without inheriting the compliance debt that sinks unprepared operators. Every lead ships with its consent trail attached: disclosure text, timestamp, IP address, and the named contacting party. If you want to see how that architecture works before you commit to anything, the 15-minute qualification call is free and commits you to nothing.
This article is general information, not legal or financial advice. Benchmark figures are directional industry data, not guarantees of results.