
Who can be sued for violations of the TCPA?
Key Facts
- 2,858 TCPA lawsuits were filed in 2025 — a 63.7% jump from 1,819 the year before, per litigation tracking data.
- TCPA statutory damages run $500 to $1,500 per call with no aggregate cap, meaning a few thousand non-compliant calls can hit eight figures.
- Class-action filings are up 95% year-over-year with aggregate verdicts exceeding $925 million, according to industry compliance analysis.
- QuoteWizard paid a $19 million settlement for failing to trace consent through its vendor chain — now the reference case for lead buyers.
- The FCC's February 2024 ruling confirmed AI-generated voices count as 'artificial or prerecorded voice' with no live-agent carve-out.
- As of April 11, 2025, businesses must process opt-outs within 10 business days — down from 30 — per analysis of the new rules.
- A confirmation text must go out within 5 minutes of an opt-out request under the FCC's new revocation rules, according to legal analysis.
It's Not Just the One Who Dialed: Why TCPA Liability Reaches Further Than You Think
Imagine getting sued for a phone call your company never made. Under the Telephone Consumer Protection Act, that scenario is not hypothetical — it is the standard plaintiffs now follow, and the numbers show how aggressively they are pursuing it.
According to litigation tracking data, 2,858 TCPA lawsuits were filed in federal and state courts in 2025, up 63.7% from 1,819 the year before. Class-action filings alone are up 95% year-over-year, with aggregate verdicts exceeding $925 million, per industry compliance analysis.
The financial exposure is staggering because of how damages work. The TCPA carries statutory damages of $500 to $1,500 per call, with no aggregate cap. A single campaign of a few thousand non-compliant calls can produce eight-figure liability before a court ever weighs intent.
Here is the part most businesses miss: the vendor who physically dialed the number is rarely the only defendant. The proposed class in Lamb v. Mortgage One Funding, filed in February 2026, reaches every consumer who received an artificial-voice call from Mortgage One "or from any of the company's vendors, lead generators, or agents." As one analysis of the case puts it, the plaintiff is making explicit what the FCC has long held implicitly: the entity on whose behalf the calls are made bears liability, regardless of which downstream vendor pressed dial.
That principle reshapes who sits in the defendant's chair:
- The business whose name, product, or service the call promotes — even if it never touched a dialer
- The vendor or AI calling service that placed the call or sent the text
- Lead generators, publishers, and agencies anywhere in the chain
- Agents and contractors acting on the business's behalf
Contracts do not save you. FTC telemarketing guidance makes clear that contractual relationships between sellers and telemarketers do not eliminate applicable obligations — both parties remain exposed no matter what the service agreement says about indemnification.
Buying leads offers no shelter either. A lead record is not the same as documented consent for every type of follow-up, and the receiving business should not assume compliance responsibility transferred to the lead source. The $19 million QuoteWizard settlement stands as the reference point for what happens when a company cannot trace consent through its vendor chain.
This is exactly why compliance architecture matters as much as speed in lead response. At CallMyLeads, consent is collected explicitly in the booking flow, opt-outs are honored immediately and automatically, and business texting is registered under A2P 10DLC carrier rules — because outsourcing the dialing never outsources the risk. Whether a business handles follow-up in-house or through a service, the liability follows the name on whose behalf the call was made.
The bottom line: if a call is made for your benefit, a plaintiff can come for you. The only real defense is a documented, traceable chain of consent behind every single contact.
The Full List of Who Can Be Sued: Callers, Sellers, Lead Generators, and Everyone in Between
Think outsourcing your calling or buying leads moves the legal risk off your plate? It doesn't. Under the TCPA, liability follows the entire chain — and every link can end up named in the lawsuit.
The clearest map of that chain comes from Lamb v. Mortgage One Funding, filed in February 2026. The proposed class covers every consumer who received an artificial-voice call from Mortgage One "or from any of the company's vendors, lead generators, or agents" — making explicit what regulators have long held: the entity on whose behalf calls are made bears liability, regardless of who pressed dial.
That means the full list of potential defendants includes:
- The seller — the business whose product or service the calls promote
- The caller or dialing vendor — the agency, call center, or AI calling service that physically places calls or sends texts
- Lead generators, publishers, and networks — the parties that sourced the consumer's information
- Agents and brokers — intermediaries acting on the seller's behalf
Contracts don't shrink this list. The FTC's telemarketing guidance specifically addresses sellers and telemarketers working together and makes clear that contractual relationships do not eliminate applicable obligations. An indemnification clause may help you recover money from a vendor later — it won't keep you out of the complaint.
Buying leads doesn't transfer consent responsibility either. Compliance experts warn that "a lead record is not the same thing as a documented right to make every type of follow-up communication," and buyers "should not assume that every compliance responsibility has been transferred to the lead source." The cautionary tale is QuoteWizard's $19 million settlement — now the reference point for what happens when a company can't trace consent through its vendor chain. Courts are also skeptical of consent language naming vague "partners" or "selected marketing affiliates" the consumer couldn't reasonably identify.
The stakes explain why plaintiffs cast such a wide net. Statutory damages run $500 to $1,500 per call with no aggregate cap, TCPA class-action filings are up 95% year-over-year, and 2,858 TCPA lawsuits were filed in 2025 alone — a 63.7% jump from the prior year. Because the statute imposes strict liability, even good-faith mistakes can trigger exposure.
AI callers sit squarely inside this framework. The FCC's February 2024 Declaratory Ruling confirmed AI-generated voices count as "artificial or prerecorded voice," with no carve-out for technology that sounds like a live agent. That's why services built on AI lead response — including CallMyLeads — treat compliance as a shared architecture: explicit consent collected in the booking flow, opt-outs honored immediately and automatically, and clear AI disclosure on every call. When both the vendor and the business on whose behalf it acts can be sued, compliance has to be designed into the system, not delegated away in a contract.
AI Voice Calls Get No Special Treatment — and Neither Do the Businesses Using Them
If your AI receptionist sounds human, the TCPA treats it like a robocall. On February 8, 2024, the FCC issued a Declaratory Ruling confirming that AI-generated voices are "artificial or prerecorded voice" under 47 U.S.C. § 227(b) — and that the statute allows no carve-out for technologies that purport to provide the equivalent of a live agent. That single ruling collapsed the biggest excuse businesses were leaning on.
The practical consequence is simple: any outbound call using an AI voice requires prior express consent, no matter how natural it sounds. Some business owners assume an existing business relationship (EBR) gives them a free pass to call. It doesn't. As one TCPA compliance analysis puts it, "EBR does not exempt the call from the AI consent requirement. The artificial voice itself triggers the consent obligation."
There's also a geographic wrinkle worth knowing. In Bradford v. Sovereign Pest (Feb. 25, 2026), the Fifth Circuit held that oral consent is sufficient for telemarketing calls in Texas, Louisiana, and Mississippi. In the other 47 states, prior express written consent is still required. If you call across state lines, your consent standard depends on where the recipient lives — not where you're dialing from.
So who gets sued when an AI call goes out without proper consent? More parties than most businesses expect:
- The entity on whose behalf the call was made — usually the business, not the vendor
- The vendor or dialing service that physically placed the call
- Lead generators and agents anywhere in the chain
- Lead buyers who can't trace consent back to its original source
The proposed class in Lamb v. Mortgage One Funding reaches calls made by the company "or from any of the company's vendors, lead generators, or agents." Hiring an AI calling service does not transfer the compliance risk to that service. FTC guidance makes clear that contractual relationships do not eliminate applicable obligations — sellers and telemarketers working together both remain on the hook, per the FTC's own telemarketing guidance.
The stakes are not theoretical. TCPA class-action filings are up 95% year-over-year, with aggregate verdicts exceeding $925 million, and statutory damages run $500 to $1,500 per call with no aggregate cap. The QuoteWizard $19M settlement is now cited as the reference point for what happens when a company cannot trace consent through its vendor chain.
This is why we treat disclosure and consent as core features at CallMyLeads, not afterthoughts — callers always know they're talking to AI, consent is captured explicitly during booking, and opt-outs are honored immediately. If you're buying AI calling from a third party and assuming the vendor owns the compliance risk, the courts have already proven you wrong. Ask any vendor hard questions about consent tracing, AI disclosure, and opt-out handling before you let them dial for you.
The Mistakes That Actually Get Companies Sued: Opt-Outs, Consent Gaps, and Missing Records
Most TCPA lawsuits don't come from shady robocall schemes. They come from small, fixable operational slips — a text sent three days after someone said "stop," a lead list that never got scrubbed, a call placed at 8:55 a.m. in the wrong time zone. Under the TCPA's strict liability standard, intent doesn't matter. The mistake itself is the violation.
The 2025 rule changes made the margin for error even thinner. As of April 11, 2025, businesses must process opt-out requests within 10 business days, down from 30, and courts now treat certain words as automatically reasonable revocation requests, according to Carlton Fields' analysis of the new opt-out rules. Those keywords include:
- "Stop" and "quit"
- "End" and "revoke"
- "Opt out" and "cancel"
- "Unsubscribe"
When a consumer sends one of those words, a clarification or confirmation text must go out within 5 minutes. That's a machine-speed deadline, not a staff-speed one — which is why manual opt-out handling has become one of the most common failure points plaintiffs exploit.
Consent gaps are the second big trap. A lead record is not the same thing as a documented right to follow up, and buyers "should not assume that every compliance responsibility has been transferred to the lead source," as Contact.io's lead follow-up compliance guidance puts it. The QuoteWizard settlement — $19 million — is now the reference point for what happens when a company can't trace consent through its vendor chain.
The settlements keep coming. Gen Digital, the company behind Norton and LifeLock, paid $9.95 million in January 2026 over prerecorded calls to non-customers, and Hy Cite Enterprises settled for $4.75 million in early 2026, with class members eligible for $600 to $1,000 each, per the 2026 TCPA compliance playbook. Neither case required proof of malice — just proof that calls went out without proper consent.
Then there are the quiet operational details. Calling lists must be checked against the National Do Not Call Registry at least every 31 days, and even good-faith errors about time zones or daylight-saving time can trigger liability, according to reporting on the 2025 litigation surge. With 2,858 TCPA lawsuits filed in 2025 — up nearly 64% from the year before — plaintiffs' attorneys are actively hunting for these gaps.
This is why automation matters. At CallMyLeads, opt-outs are honored immediately and automatically across every channel, and consent is captured at booking — because a response system that runs on its own should also keep compliance running on its own. When the rules move this fast, manual processes are the liability.
How to Protect Your Business: Shared Compliance, Consent Proof, and Instant Opt-Outs
The Lamb v. Mortgage One Funding case makes it explicit: a plaintiff class can reach "every consumer who received an artificial-voice call from Mortgage One 'or from any of the company's vendors, lead generators, or agents'" — confirming that liability travels up the vendor chain to the entity on whose behalf calls are made. Courts and the FCC have long held that the business behind the communication bears primary liability, not just the downstream vendor who pressed dial. That means buying leads or hiring an AI calling service does not transfer your compliance risk. The QuoteWizard $19M settlement became the reference point for what happens when a company cannot trace consent through its vendor chain.
Contractual indemnification does not eliminate regulatory obligations. The FTC's telemarketing guidance makes clear that sellers and telemarketers working together both retain applicable obligations regardless of contract terms. With TCPA class-action filings up 95% year-over-year and aggregate verdicts exceeding $925 million, the enforcement threat comes from private plaintiffs and state attorneys general — not the FCC. Statutory damages of $500–$1,500 per call with no aggregate cap turn even small campaigns into existential risk.
Protecting your business requires shared compliance architecture built into daily operations:
- Joint compliance agreements that define in writing who collects consent, who handles opt-outs, who manages DNC scrubbing, and who oversees vendor compliance
- End-to-end consent evidence capture — exact language presented to the consumer, version and timestamp of the consent form, method of collection (form, chat, verbal), and full vendor chain documentation — retained for seven years
- Real-time opt-out propagation across every channel (voice, SMS, email) and every integrated system (CRM, dialer, marketing platforms) so a "STOP" request is honored instantly and auditable
- AI voice-specific consent flows with explicit prior express written consent for outbound AI calls, clear AI disclosure at call start, and jurisdiction-aware consent type tracking (oral consent sufficient only in TX, LA, MS per the Fifth Circuit)
CallMyLeads builds these controls into the service layer: instant opt-out honoring across all channels, explicit consent collection at every lead intake, A2P 10DLC registration for business texting, and clear AI disclosure on every call. The system captures consent as evidence — language, timestamp, method — and synchronizes opt-out state in real time so your vendor chain stays compliant without manual work. Your leads, your data, and your calendar stay yours; the compliance infrastructure runs underneath it all. Stop paying for leads you never get to talk to — every new lead answered in seconds, 24/7/365.
Frequently Asked Questions
Can I be sued under the TCPA even if my company never made the call?
Who exactly can be named as a defendant in a TCPA lawsuit?
Does my contract with a calling vendor protect me from TCPA liability?
If I buy leads, isn't the lead generator responsible for consent?
Do AI voice calls follow different TCPA rules than regular robocalls?
How much can a TCPA violation actually cost my business?
The Call Was Made for You — So Is the Liability
The TCPA doesn't care who pressed dial. It cares whose name is on the call — and the courts have made that unambiguous. The entity on whose behalf a call is placed, the vendor who placed it, the lead generator who sourced the number, and every agent in between can all be named in the same suit. Contracts don't change that. Buying leads doesn't transfer consent. And with AI voice now explicitly classified as an artificial call, the consent requirement is stricter than most businesses realize. The 2,858 TCPA lawsuits filed in 2025 — up 63.7% from the year before — show how aggressively plaintiffs are pursuing the full chain. The only defense that holds up is a documented, traceable consent trail behind every contact. At CallMyLeads, we build that trail into the system: explicit consent captured at intake, opt-outs honored instantly across every channel, AI disclosure on every call, and A2P 10DLC registration for business texting. Your leads, your data, and your calendar stay yours — the compliance infrastructure just runs underneath it all. Stop paying for leads you never get to talk to — every new lead answered in seconds, 24/7/365.