
An AI sales agent that calls or texts a prospect is doing the exact thing the Telephone Consumer Protection Act was written to regulate, and the law doesn't care whether a person or a piece of software placed the call. Recent regulatory action has made that explicit rather than leaving it as an assumption.
This guide covers what the TCPA actually requires, what changed when the FCC ruled that AI-generated voices count as "artificial" under the statute, which states have gone further than federal law, and what a compliance-first AI sales deployment needs to have in place before it makes its first call.
The TCPA restricts calls and texts placed using an autodialer or an artificial or prerecorded voice, and marketing calls or texts in that category generally need prior express written consent from the person being contacted, consent that specifically covers being contacted this way, not just a general "yes, contact me." Purely informational calls (an appointment reminder, a fraud alert) need a lower bar, prior express consent, but sales outreach almost always falls into the stricter marketing category.
The law also layers on a national Do-Not-Call registry, calling-time restrictions, and an existing-business-relationship exception that lets a company reach a current customer without the same consent bar a cold prospect would require. None of that is new, and none of it changes because AI is involved. What changed in 2024 is a specific ruling about what counts as an "artificial voice" in the first place.
On February 8, 2024, the FCC adopted a declaratory ruling, unanimously, confirming that a voice generated by AI counts as an "artificial or prerecorded voice" under the TCPA. The ruling applies to any AI technology that places an outbound call using a synthesized or cloned voice, which covers exactly the kind of voice agent a sales team might deploy to run outbound prospecting at scale.
The practical effect: an AI voice call is not a new, unregulated category of outreach. It's a robocall, legally speaking, and it needs the same prior express written consent a human-recorded robocall would need. A company that assumed AI voice calling sat in some regulatory gray area lost that argument the day this ruling came down.
One nuance worth tracking: the FCC's attempt to raise the bar further, a "one-to-one" consent standard that would have required consent for each individual seller rather than one signature covering several, was vacated by the Eleventh Circuit in January 2025, and the FCC later dropped it. The broader pre-existing consent framework is what's actually in force through 2026, not the stricter standard some vendors still reference.
Federal law is the floor, not the ceiling. At least 12 states have passed their own telemarketing statutes, commonly called mini-TCPA laws, since 2021, and several of them apply requirements the federal TCPA doesn't. Florida's Telephone Solicitation Act and Oklahoma's near-identical Telephone Solicitation Act are the two most commonly cited: both require prior express written consent for automated communications, restrict calling hours to 8am-9pm, cap the number of call attempts on the same subject in a day, and give consumers a private right to sue for $500 per violation, trebled for a willful violation. Texas updated its own telemarketing rules again in 2025, part of a broader trend of states tightening rather than loosening this area.
Rule | What it requires for AI sales outreach | Enforcement |
|---|---|---|
Federal TCPA | Prior express written consent for marketing calls/texts using an artificial or prerecorded voice; Do-Not-Call registry; calling-hour limits | Private right of action; FCC enforcement |
FCC 2024 AI-voice ruling | AI-generated voice = "artificial voice"; same consent bar as a human-recorded robocall applies | Same as TCPA above |
Florida / Oklahoma mini-TCPA | Prior express written consent; calling hours 8am-9pm; daily call-attempt caps | $500 per violation private lawsuit, trebled if willful |
5th Circuit (TX/LA/MS only) | Feb 2026 ruling: only prior express consent (not written) required for prerecorded calls to wireless numbers | Applies only within the 5th Circuit; written-consent standard still applies everywhere else |
There's no single federal statute requiring every AI-driven sales call or chat to open with "I'm an AI assistant." What does apply is Section 5 of the FTC Act, which prohibits unfair or deceptive practices, and the FTC has been explicit that hiding an AI identity can qualify as deceptive if a reasonable consumer would otherwise believe they're speaking with a person. The FTC's Telemarketing Sales Rule separately requires disclosing the seller's identity and the purpose of the call early in any telemarketing call, AI-driven or not.
A handful of states are moving faster than federal law here. Utah's AI Policy Act requires disclosure that a user is interacting with generative AI when the user asks, and more state chatbot-disclosure bills are moving through legislatures each year. The practical position: disclose upfront, by default, rather than only on request. It closes the FTC's deception exposure and gets ahead of state rules that are still being written.
Consent isn't a setup-time checkbox you clear once and forget. It's a per-contact, per-channel fact that changes over time, a prospect who consented to calls can revoke that consent through any reasonable method, and under rules that took effect in 2025, a business generally has 10 business days to honor that revocation across every channel it uses to reach that person, not just the one the revocation arrived on.
That's exactly the kind of ongoing, rules-based judgment an AI employee should carry as part of its job, not as a bolt-on integration. In Zamp's model, an AI sales agent runs against an Agent Operating Procedure, or AOP, that encodes exactly which consent scope covers which contact, which state's calling-hour and frequency rules apply, and what to do the moment a revocation comes in on any channel. A sales ops or compliance lead edits that procedure directly, in plain language, when a state law changes or a new consent form goes live, without waiting on an engineering ticket to update a script.
Just as important is what happens after the call. Every outbound attempt should leave a full decision audit trail, not just a log line saying a call was placed, but a record of what consent was checked, what it covered, and why the agent proceeded or held back. That record is what turns a TCPA inquiry from a scramble through call logs into a five-minute lookup, and it's the same governance model behind Zamp's Company Brain, the accumulated, reviewable context that carries what one AI employee learned about a contact's consent status into every other AI employee that later touches that same record.
For the operational side of running an AI sales function, our guides to AI SDRs and BDRs and the complete guide to AI sales agents cover deployment in depth, and our piece on the customer service AI agent covers the inbound side of the same relationship. For the broader picture of how an AI employee is governed across every function, not just sales, see our complete guide to AI employees.