TL;DR: AI outbound calls are legal — but only under specific, enforceable conditions set by the FCC's February 2024 ruling. The TCPA now explicitly covers AI-generated voices. Consent, call purpose, number type, and suppression logic determine whether your campaign is lawful. Most operators guess. The ones who build compliance into their infrastructure don't have to.
The FCC ruled in February 2024 that AI-generated voices are "artificial" under the TCPA
— every prerecorded-call restriction now applies to AI agents.TCPA violations cost $500
–$1,500 per call; FTC Telemarketing Sales Rule penalties reach $53,088 per violation.There is no categorical B2B exemption in the TCPA. The statute covers phone numbers, not employment relationships.
Consent is always required for AI voice calls
— the tier (express vs. express written) depends on call purpose.Suppression logic, consent verification, and audit trails must live in the dialing runtime, not in a spreadsheet or policy doc.
What Changed in February 2024?
On February 8, 2024, the FCC unanimously ruled that AI-generated voices are "artificial" under the TCPA. The Declaratory Ruling took effect immediately.
This was a clarification, not a new law
— and it matters for one reason: every restriction that applies to prerecorded voice calls now applies to your AI agent. The technology being conversational changes nothing legally.
AI outbound calls remain legal. They are legal under specific, enforceable conditions, and you own the burden of meeting them.
Key Point: The February 2024 FCC ruling closed the interpretive gap. If your AI agent speaks, it is legally a prerecorded voice
— full stop.
Why the Penalty Math Matters Before You Dial
TCPA violations run $500 to $1,500 per call, with no ceiling on class actions. Under the FTC's Telemarketing Sales Rule, each violation can draw a civil penalty up to $53,088, with every call and every day of missing records counting separately.
That structure is how regulators reach nine-figure judgments. When you scale to thousands of calls without consent infrastructure, exposure compounds geometrically.
I treat compliance as an architecture problem because of this. A policy document does nothing at dial time. A hard constraint in the system does.
Key Point: At scale, non-compliance doesn't produce small fines
— it produces compounding, geometric exposure. Build constraints into the system before the first call goes out.
The Decision Guide: Four Questions Before Every Campaign
1. What Is the Call's Purpose?
The TCPA defines telemarketing broadly. It covers any call that encourages the recipient to purchase, rent, or invest. In most courts' readings, that includes meeting-booking calls, demo-scheduling calls, and product-availability calls.
If your AI agent books meetings, treat it as telemarketing.
2. What Type of Number Are You Calling?
Landlines and wireless numbers carry different consent tiers. This is where B2B operators get hurt, because contact lists today are 60 to 80 percent mobile numbers. Therefore, wireless consent requirements apply to the majority of your outbound B2B contacts.
3. What Consent Do You Hold
— and Can You Prove It?
For AI voice calls, consent is always required. The only question is which level:
Informational calls: prior express consent.
Telemarketing calls: prior express written consent
— a higher bar.
If you cannot produce the consent record with a timestamp, you do not have consent in any way that survives a courtroom.
4. What Suppression Logic Runs Before the Dial?
Do Not Call registries, internal opt-outs, state calling-hour windows, and frequency caps all need enforcement at the system level.
Suppression that depends on a rep remembering a spreadsheet fails. Suppression built into the dialing runtime holds.
Key Point: These four questions are the minimum viable compliance check. If you can't answer all four with documented evidence, you're not ready to scale.
Why the B2B Exemption Assumption Fails Fast
This is the most expensive misunderstanding I see. There is no categorical B2B exemption in the TCPA. The statute applies to phone numbers
— it does not care who employs the person answering.
Most calls to a business are exempt from the federal TSR's Do Not Call provisions. That exemption resolves one rule. It does not resolve:
TCPA restrictions
Personal wireless numbers
Internal opt-outs
Recording requirements
State mini-TCPA laws in Florida, Oklahoma, Connecticut, and elsewhere
Federal compliance is the floor. States like Florida set shorter calling hours, cap call frequency, and hand consumers a private right of action. Multistate campaigns need jurisdiction-aware rules
— a single federal checklist will miss them.
Key Point: The B2B label doesn't grant TCPA immunity. Each state layer adds obligations that federal compliance alone doesn't satisfy.
Existing Customers Are Not Automatically Fair Game
An established business relationship exempts you from the National Do Not Call Registry for manual calls. It does not waive the AI consent requirement. The artificial voice itself triggers the consent obligation, regardless of relationship history.
Treating your customer database as a fair-game list for AI outbound is a common and costly error. Consent capture needs to happen at signup, renewal, or any inbound interaction. Without it, the AI agent cannot lawfully dial that customer.
Key Point: Relationship history does not equal consent for AI voice. Consent must be captured explicitly
— before the first AI call, not after.
Liability Follows the Deployment
— Including Yours
If you deploy someone else's AI voice platform, you inherit the compliance obligation directly. Platforms that ship "compliant-ready" tools without enforcement mechanisms transfer risk to you rather than eliminating it.
This shapes how I build. Execution that cannot be traced is theater, and compliance that cannot be enforced at the system level is documentation. Consent verification, suppression, and audit trails belong in the runtime
— where they run on every call whether anyone remembers them or not.
The operators who win in this category will be the ones whose systems make lawful dialing the default state. Map the four questions, build the constraints into your infrastructure, and then scale.
Key Point: Using a third-party AI voice platform doesn't transfer your liability
— it extends it. You own the compliance obligation end to end.
Frequently Asked Questions
Are AI outbound calls legal in the US?
Yes
— but only under specific conditions. The FCC's February 2024 ruling confirmed that AI-generated voices are treated as "artificial" under the TCPA, meaning all prerecorded-call restrictions apply. Consent, call purpose, and suppression compliance determine legality.
Does the TCPA apply to B2B calls?
Yes. The TCPA applies to phone numbers, not employment relationships. There is no categorical B2B exemption. The federal TSR's Do Not Call provisions have a B2B carve-out, but that resolves only one rule
— not TCPA consent requirements, wireless number restrictions, or state laws.
What consent is required for AI voice calls?
Informational calls require prior express consent. Telemarketing calls
— including meeting-booking and demo-scheduling
— require prior express written consent. Consent must be documented with a timestamp to be enforceable.
What are the penalties for TCPA violations?
$500 to $1,500 per call, with no class action ceiling. Under the FTC's Telemarketing Sales Rule, civil penalties reach up to $53,088 per violation. At scale, exposure compounds geometrically.
Does an existing customer relationship waive AI consent requirements?
No. An established business relationship exempts you from the National Do Not Call Registry for manual calls only. AI-generated voice triggers its own consent obligation regardless of prior relationship.
What suppression logic is required before dialing?
At minimum: Do Not Call registry checks, internal opt-out enforcement, state calling-hour windows, and frequency caps. All of these must be enforced at the system level
— not managed manually by reps.
What state laws add complexity beyond federal TCPA rules?
Florida, Oklahoma, and Connecticut are notable examples. These states set shorter calling hours, cap call frequency, and give consumers a private right of action. Multistate campaigns require jurisdiction-aware suppression rules.
If I use a third-party AI voice platform, am I still liable?
Yes. Deploying another company's AI voice platform does not transfer your compliance obligation. If the platform lacks enforcement mechanisms, you absorb the risk. Consent verification, suppression, and audit trails must be in the runtime
— not assumed to be someone else's problem.
Key Takeaways
The FCC's February 2024 ruling made AI-generated voices legally equivalent to prerecorded calls under the TCPA
— all the same restrictions apply.TCPA and FTC penalty structures compound at scale. Non-compliance is an architecture risk, not just a legal one.
There is no categorical B2B exemption from the TCPA. The statute covers numbers, not organizations.
Consent is always required for AI voice calls; the required tier (express vs. express written) depends on call purpose and number type.
An existing customer relationship does not waive the AI consent requirement.
Suppression logic must be enforced in the dialing runtime
— policy documents and spreadsheets fail at dial time.Third-party platform deployment doesn't eliminate your liability. You own compliance end to end.