
Can I use AI to make cold calls?
Key Facts
- The FCC's February 2024 ruling made AI cold calls legal only with prior express written consent, per compliance guidance.
- TCPA violations cost $500–$1,500 per call, so 10,000 daily AI calls risk $15 million monthly, audit findings show.
- 61% of sales teams wrongly believe B2B calls are TCPA-exempt, research reveals.
- 89% of sales teams use AI voice tools without a formal compliance strategy, audits estimate.
- Texas SB 140 requires AI disclosure within the first 30 seconds of any outbound call, legal analyses note.
- The average TCPA class action settlement now stands at $12.4 million, litigation data shows.
- 75% of customers want to know when they're talking to an AI agent, consumer research finds.
The Short Answer: Yes, But Only With Prior Written Consent
The FCC’s February 2024 ruling settled the question: AI-generated voices are legally "artificial" under the TCPA, making prior express written consent (PEWC) mandatory for every marketing call. This classification eliminates any ambiguity—outbound AI voice calls now face the same restrictions as traditional robocalls, with no regulatory loophole for the technology itself. For businesses using AI in outbound efforts, compliance isn’t optional; it’s the baseline for legal operation.
Violations carry steep financial penalties, with TCPA damages ranging from $500 per call for negligent violations to $1,500 per call for willful or knowing violations. These penalties apply per call, meaning a single non-compliant campaign can generate exposure in the millions within days. Recent settlements underscore the scale of risk, with class-action resolutions in the $5 million to $20 million range becoming increasingly common in 2025–2026. The financial stakes are compounded by the widespread lack of preparedness across sales teams.
A significant compliance gap persists in the marketplace, with 73% of sales organizations estimated to be in violation of AI cold calling regulations. Audit findings reveal that 89% of sales teams use AI voice tools without a formal compliance strategy, 61% incorrectly believe B2B calls are TCPA-exempt, and only 12% maintain written consent documentation for AI usage. This disconnect between adoption and adherence creates substantial legal vulnerability, especially for companies calling mobile numbers where TCPA applicability is absolute regardless of call context. The Pipeline Group notes that this misconception is a primary driver of avoidable litigation risk.
For CallMyLeads, which provides AI-powered lead response and appointment-setting services across the U.S., this means every outbound interaction must begin with verified consent. The service’s design—featuring immediate lead engagement, transparent AI disclosure, and seamless human escalation—aligns with compliance requirements when paired with proper consent management. By embedding PEWC checks into lead workflows and honoring opt-outs automatically, businesses can leverage AI’s speed and availability while mitigating regulatory exposure. The path forward requires treating consent not as a checkbox, but as the foundation of every AI-driven conversation.
The Consent Trap: Why B2B Callers Are Not Exempt
If your sales team believes "B2B" on the spreadsheet means "TCPA-exempt" on the phone, that belief is quietly building a seven-figure legal bill. The law does not care whether the person you're calling is a procurement manager or a homeowner — it cares what kind of number you dialed.
Here's the mechanics: the TCPA's consent requirements attach to the phone number, not the job title of the person holding it. As one compliance guide puts it plainly, calling mobile numbers — even of business decision-makers — triggers full TCPA applicability, requiring prior express written consent for marketing outreach regardless of B2B context. And since the FCC's February 2024 ruling classified AI-generated voices as "artificial or prerecorded voice" under the TCPA, every AI-assisted call to a mobile number is treated as a robocall, with no technology loophole to hide behind.
The misconception is widespread — and expensive. Audit findings show 61% of sales teams incorrectly believe B2B calls are TCPA-exempt, while 45% use purchased lists without ever validating consent. That combination is exactly how class actions get built:
- TCPA damages run $500 per call, rising to $1,500 per call if the violation is willful or knowing — with no cap on total liability.
- A team placing 10,000 AI-assisted calls daily faces potential exposure of up to $15 million per month.
- The average TCPA class action settlement now sits at $12.4 million.
The consent standard itself tightened at the start of 2025. Under the one-to-one consent rule effective January 27, 2025, multi-seller consent no longer satisfies the prior express written consent requirement — each consumer must consent to calls from one named seller, for one topic. (Note that the Eleventh Circuit vacated the FCC's rule in January 2025 and the FCC subsequently repealed it, so the precise federal posture is in flux — but several state mini-TCPAs enforce comparable or stricter standards, so treating one-to-one consent as the operating baseline remains the safer play.)
Purchased lists make all of this worse, because consent you didn't collect is consent you can't prove. When a plaintiff's attorney asks for documentation, "the vendor said it was compliant" is not a defense — and courts have proposed class coverage extending to calls made by a company's vendors, lead generators, and agents. Liability follows the entity on whose behalf the call was made, not the vendor who placed it.
This is why consent-first architecture matters. At CallMyLeads, consent is collected explicitly in the booking flow and opt-outs are honored immediately and automatically — because the cheapest TCPA defense is never making the non-compliant call in the first place. Consent is not paperwork; it's the asset that makes AI calling legal.
State-by-State Disclosure Rules That Apply Right Now
Federal rules for AI disclosure in outbound calling remain in limbo, but a patchwork of state mandates is already in effect. The FCC's proposed AI-specific rules from August 2024 have not been finalized as of September 2026, leaving businesses to navigate a shifting landscape of state requirements that vary by jurisdiction and call type. Legal experts note that while federal AI disclosure is not yet mandatory, several states have moved ahead with their own mandates, creating compliance obligations that apply the moment a call connects.
- Texas (SB 140): Requires AI disclosure within the first 30 seconds of any outbound call, effective September 2024.
- Utah: The Artificial Intelligence Policy Act mandates proactive disclosure for providers of regulated services (such as healthcare and financial services); other businesses must disclose if a consumer asks.
- California: The Bot Disclosure Law prohibits bots from misleading consumers about their artificial identity to incentivize a transaction; clear disclosure serves as a legal defense.
- Florida, Colorado, Illinois: Each has enacted or is enforcing AI disclosure requirements for automated outbound communications.
Calling-time restrictions add another layer of complexity. Federal law permits calls between 8 AM and 9 PM in the recipient's local time zone, but at least 15 states impose stricter windows — Oregon narrows it to 8 AM–8 PM with a three-contact daily cap, and Texas moved to 9 AM–9 PM Monday through Saturday. Compliance guides recommend a safe national window of 11 AM–8 PM ET, Monday through Friday to stay within every state's limits. State attorneys general in Massachusetts, California, and Oregon have signaled that existing consumer-protection statutes apply to AI-driven calls, indicating enforcement activity is likely to increase. Industry analysis shows that 73% of sales organizations are estimated to be in violation of AI cold-calling regulations, and 89% of sales teams using AI voice tools lack a formal compliance strategy. For teams running multi-state campaigns, building disclosure and timing logic into every call flow — not as an afterthought but as a default — is the only way to avoid seven-figure exposure from a single non-compliant campaign.
The Compliance System You Need Before You Dial
Before you make a single AI-powered call, you need a compliance system built into your workflow—one that doesn’t rely on memory or manual checks. The foundation starts with four non-negotiable operational pillars: scrubbing your call lists against the National Do Not Call Registry at least every 31 days, retaining consent records for 4–7 years to cover the TCPA statute of limitations and legal defense recommendations, honoring consumer opt-out requests within 10 business days, and strictly adhering to permitted calling hours (8 AM–9 PM local time, with state-specific adjustments like Oregon’s 8 AM–8 PM window). These aren’t suggestions—they’re baseline requirements reinforced by multiple compliance sources to avoid penalties that can reach $1,500 per willful violation.
Equally critical is what you say the moment the call connects. To meet evolving state AI disclosure mandates and build trust from the first second, use a clear, consistent script: “This is an AI assistant calling from [Company] on a recorded line.” This disclosure aligns with recommendations from AI voice compliance playbooks and satisfies states like Texas, which requires AI identification within 30 seconds of the call start. It also supports the 75% of customers who want to know when they’re talking to an AI agent, turning a legal obligation into a transparency advantage. For businesses using CallMyLeads, this script is baked into every outbound AI call—ensuring compliance isn’t an afterthought, but the first thing the lead hears.
Vendor Risk: Why Outsourcing AI Calls Doesn't Transfer Liability
Many businesses assume that outsourcing AI cold calling to a vendor transfers legal liability, but this is a dangerous misconception. The entity on whose behalf the calls are made remains fully responsible for compliance, including any violations committed by third-party vendors. This principle was reinforced in the Lamb v. Mortgage One Funding case, where the court proposed class coverage for calls made not only by the company but also "from any of the company's vendors, lead generators, or agents" Retell AI's TCPA Compliance Playbook explains.
This means that even if a vendor like CallMyLeads places the calls using AI technology, the hiring business bears the ultimate liability for TCPA violations, improper disclosures, or unauthorized data use. Outsourcing does not create a legal shield—it only shifts operational execution, not accountability. Companies must therefore vet vendors rigorously and ensure contractual protections are in place.
Emerging risks further complicate vendor relationships, particularly when third-party AI tools analyze call recordings for their own machine learning training. Plaintiffs' attorneys are now alleging that businesses using undisclosed third-party AI recording or analysis tools are aiding and abetting wiretapping, arguing that such vendors are no longer mere "extensions" of the business because the recordings serve the vendor's own purposes, such as improving their AI models CommLawGroup warns. This creates exposure under wiretapping statutes and biometric privacy laws in states like Illinois, Washington, and Texas, which require prior notification and express written consent for collecting voiceprints or analyzing speech.
To mitigate these risks, businesses should require specific safeguards in vendor agreements. Contracts must include explicit consent for any call recording or analysis that benefits the vendor, clear disclosure of AI vendor involvement in privacy notices, and indemnification clauses that hold the vendor liable for its own non-compliant actions. Additionally, vendors should provide audit logs, consent records, and call transcripts upon request to support the hiring business’s defense in case of litigation. Without these protections, outsourcing AI calls increases—not decreases—legal exposure.
Frequently Asked Questions
Is it actually legal to use AI for cold calls in the US?
What are the penalties if I make AI cold calls without consent?
Do B2B calls to business decision-makers get an exemption from TCPA?
Do I have to tell people they're talking to an AI on the call?
If I outsource AI calls to a vendor, does the liability transfer to them?
Can I use purchased lead lists for AI cold calling if the vendor says they're compliant?
The Bottom Line: Compliant AI Calling Isn't a Limit—It's a Competitive Edge
So, can you use AI to make cold calls? Yes—but only with prior express written consent, honest disclosure, and a compliance system built into every call flow. The FCC's 2024 ruling closed the loopholes: AI voices count as robocalls, B2B mobile numbers get no exemption, and outsourcing to a vendor transfers the work, not the liability. With penalties of $500–$1,500 per call and the average TCPA class action settlement now at $12.4 million, a single careless campaign can wipe out a year of revenue. The good news? Businesses that treat consent as the foundation—not a checkbox—are the ones still dialing while competitors face lawsuits. Your next steps: audit your consent documentation, scrub your lists against the DNC Registry, script your AI disclosure for every state you call, and vet any vendor's compliance practices before signing. If you'd rather focus on your trade than on telemarketing law, CallMyLeads handles lead response with disclosure, consent collection, and opt-outs built in—so every conversation starts on the right side of the rules. Book a free 15-minute scoping call and stop paying for leads you never get to talk to.