Read this as orientation, not advice. We are describing the shape of the rules and the questions to put to your lawyer. We are not a law firm, this is not legal advice, and the specifics depend on your state, your industry and who you are calling.

Question 1 — may you contact them at all?

This is the telephone-consumer-protection question, and it is the one with real money attached: statutory damages are per call or per text, which is why plaintiff firms specialise in it.

The framework, in outline:

  • Marketing calls and texts to mobile numbers generally need prior express written consent — a specific, signed, unambiguous agreement, not a pre-ticked box.
  • Informational messages about a transaction the person already started sit at a lower bar, but the bar is not zero and the categories blur the moment you add a promotional line.
  • Calling hours are restricted — the telemarketing rules place the permitted window at 8am to 9pm in the called party's local time.
  • Revocation must work. When someone says "stop", the system has to honour it, and "reasonably promptly". An opt-out that takes a week to propagate is not a defence, it is the evidence.

The practical implication for an AI phone system: consent state is not a checkbox in your CRM, it is an input the agent checks before it dials. If your automation texts a list you bought, the automation is the violation, not the list.

Question 2 — may you record it?

Recording law is state law, and states split into two camps:

  • One-party consent — as long as one participant knows, recording is generally lawful.
  • All-party consent — everyone on the call must consent. California, Illinois, Pennsylvania and Washington are among the commonly cited all-party states, and the count sits around a dozen.

The complication is that the rule usually follows the most protective state on the call, not the state you are sitting in. A single-state operator calling into an all-party state is the classic fact pattern in these cases.

The fix is unglamorous: a disclosure at the top of every call, in the greeting, before anything is recorded. Not buried in a policy page — in the audio, where the person can hear it and object.

Question 3 — must you say it is an AI?

This is the newest layer and the one that is still moving. Recent state statutes have started to require disclosure that a caller is interacting with an artificial intelligence rather than a person, alongside related obligations such as crisis referral and record-keeping. Colorado's artificial-intelligence act, HB 26-1263, is one such example, with obligations taking effect on 1 January 2027.

We are not going to publish a state-by-state table here. Statutes in this area are being amended and litigated in real time, and a table that is right today would be wrong by the time you read it. The durable advice is simpler: disclose, always.

Disclosing costs you very little. In our own testing the overwhelming majority of callers carry on without comment, and the ones who do comment are usually relieved — they wanted to know. The alternative is discovering the requirement in a complaint.

What a governed setup looks like

Four controls, all cheap to build and all expensive to discover missing:

Consent state checked before diallingThe agent refuses to contact a number without a recorded opt-in
Disclosure in the greetingBoth that it is an AI, and that the call is recorded
Opt-out honoured immediatelyWritten to the record on the call, not batched nightly
Consent and disclosure loggedTimestamped, per contact, exportable — so a question is answered with a record

Those four are what we mean by a consent and TCPA proof trail. They are also the reason we walk through your current call flows before quoting anything — the controls are the product, and they have to match how you actually operate.