Introducing Bland Speech v3, the most realistic voice model.

Back to blog

TCPA Autodialer Rules Explained: What Businesses Must Know

Enterprise compliance teams master TCPA Autodialer Rules with self-hosted AI calling built for regulated industries to stay fully defensible.

Ethan ClouserUpdated August 10, 202625 min read

The TCPA autodialer definition is still unsettled, and the gap between having a consent policy and proving consent call by call is where enterprise liability actually lives.

The Definition That Determines Your Liability

The TCPA autodialer definition sits at the center of every automated calling compliance decision, yet it remains one of the most misread statutes in enterprise legal practice. 47 U.S.C. § 227 determines whether your calling program faces per-call statutory damages or operates within a defensible legal boundary. Most compliance teams treat the 2021 Supreme Court ruling as a clean resolution. It wasn't. For teams deploying AI phone agents at scale, the ruling settled one narrow question while leaving the harder ones entirely open. See our voice AI for how this works in practice.

Legal gavel beside AI voice dashboard illustrating TCPA autodialer definition grey zone

The statute defines an ATDS as equipment with the capacity to store or produce telephone numbers using a random or sequential number generator, and to dial those numbers. Both elements must be present. A system that dials from a pre-loaded list without generating numbers randomly or sequentially falls outside this text, at least on its face.

The practical implication sounds reassuring: targeted-list dialers appear to be excluded. The catch is that "capacity" has been interpreted broadly by courts, and the statutory text says nothing about AI systems that generate call parameters, branching logic, or retry queues dynamically during a campaign. In *Facebook v. Duguid* (2021),

Duguid* (2021), the Supreme Court held that to qualify as an ATDS, a device must use a random or sequential number generator either to store or to produce the numbers it dials. A system that simply stores and dials a fixed list of specific numbers does not meet that definition under federal law. What the Court did not decide is equally important.

Duguid did not resolve state-law liability, FCC rulemaking authority, or how AI-driven calling systems should be classified when their internal logic generates call sequences adaptively. State legislatures moved quickly after Duguid. Florida's Telephone Solicitation Act, Washington's CEMA, and Illinois analog statutes apply definitions broader than the federal ATDS standard, meaning a targeted-list dialer cleared under Duguid can still face state-level liability.

A predictive dialer pulling from a stored list sits in relatively predictable territory post-Duguid, but an AI system that generates retry sequences and call parameters during a campaign does not.

Key takeaways#

  • The TCPA autodialer definition has never been fully settled by courts, which means the liability question isn't whether your system qualifies; it's whether you can prove it doesn't at the moment a plaintiff's attorney files.
  • Consent language in your terms of service is not a consent record. What survives discovery is a timestamped, per-call log tied to a specific number at the exact moment the call was placed.
  • A campaign that reaches 50,000 consumers without per-call documentation isn't a $500 problem; it's a $75 million problem once a plaintiff's attorney runs the math on class certification.
  • TCPA exemptions for healthcare and emergency calls carry their own compliance conditions. Assuming an exemption applies without architectural enforcement of those conditions is how exposure gets created, not avoided.
  • The policy layer collapses the moment a single operational control fails at the infrastructure level. At scale, those failures aren't rare edge cases; they're statistical certainties.
  • Generic AI wrappers sitting on top of autodialers can't enforce consent logic, call capping, or audit trails at the infrastructure level. That gap is where class actions are born.
  • Bland.ai's self-hosted architecture closes this gap by running the full voice stack on its own GPU infrastructure. Consent enforcement, call capping, and audit logging aren't add-ons bolted to a third-party platform; they're built into the layer where every call is actually placed.

TCPA Restrictions on Autodialed Calls — and Why 'Is Using an Autodialer Illegal?' Is the Wrong Question#

Demand letters have a way of clarifying what "compliance" actually means. The common assumption among enterprise buyers in regulated industries is: "If we have a consent clause in our terms and a legal sign-off on our script, we're TCPA compliant." An enterprise legal team signs off on a calling script, ops deploys the program, and thousands of calls go out.

Then a single plaintiff's attorney files, and the question shifts from "did we have a policy?" to "can you prove consent, call by call, for every number in this campaign?" That is a very different question, and most automated calling programs are not built to answer it.

Four TCPA autodialer restriction icons surrounding a cracked compliance shield, enterprise legal risk

Image: Four TCPA autodialer restriction icons surrounding a cracked compliance shield, enterprise legal risk

The stakes are especially acute for operations built to automate high-volume, high-stakes phone calls, exactly the use case where a single compliance gap can repeat across an entire campaign before anyone catches it. Platforms designed for 24/7 inbound call triage and outbound claim intake at scale must therefore treat consent documentation, call-record capture, and sentiment analysis as first-order engineering concerns, not afterthoughts.

The Four Core TCPA Restrictions That Apply to Every Autodialed Call#

The TCPA places four concrete restrictions on every autodialed call: no autodialed or prerecorded calls to cell phones without prior express consent, no calls before 8 a.m. or after 9 p.m. in the recipient's local time zone, no calls to numbers on the federal Do Not Call registry without an established consent relationship, and no prerecorded messages to residential lines without consent. These are not guidelines. Each restriction applies independently, and a call can violate more than one simultaneously.

The Per-Call Penalty Math — How $500 Becomes an Existential Number at Scale#

Consider a realistic scenario: an outbound AI claim intake campaign of 10,000 calls where 2 percent lack documented consent.

That is 200 violations. At $1,500 each, exposure reaches $300,000 before a single attorney fee is counted. Scale that to a full enrollment season and the math becomes a board-level conversation.

Wrong-number robocall claims, for instance, are among the most actively litigated TCPA theories precisely because a single stale or incorrect number in a contact list can generate an independently actionable violation on every dial.

How High-Volume Claim Intake Operations Turn a Single Compliance Gap Into a Class-Action Multiplier#

Class actions convert individual per-call violations into aggregate exposure. A single misconfigured retry rule, a stale consent record applied across a campaign, or a time-zone logic error does not produce one bad call. It produces one pattern of bad calls, and patterns certify classes.

TCPA class actions routinely sweep thousands of individual calls into a single certified class, with aggregate settlements in the tens of millions of dollars. The arithmetic is not hypothetical; it is the documented outcome when a compliance gap — a stale consent record, a misconfigured retry rule, a time-zone error — repeats across an entire campaign and plaintiffs' counsel moves to certify a class on the pattern. Wrong-number robocall lawsuits illustrate exactly this dynamic: a systematic dialing error, replicated at scale, becomes the factual predicate for class certification.

This is where the architecture of the calling platform itself becomes a compliance variable. Bland.ai's Enterprise plan is built around dedicated infrastructure with compliance documentation available under NDA, meaning the audit trail that answers "can you prove consent, call by call?" is a documented, producible record, not a reconstruction.

The Enterprise deployment framework, a structured scope, build, gray/red/green-team test, and go-live sequence delivered with a forward-deployed engineering team, is specifically designed to surface configuration risks like retry logic and time-zone handling before a single live call goes out, not after a demand letter arrives. Bland.ai's Amazon Connect integration means those compliance controls extend into existing infrastructure without requiring a platform migration, preserving the call-record continuity that TCPA defense depends on. Critically, the ability to capture and analyze customer sentiment at scale across every call is not merely an operational feature in this context; it is a compliance signal.

Sentiment analysis surfaced across a full outbound campaign can flag anomalous call patterns (unusual hang-up rates, elevated escalation signals, unexpected response distributions) before they compound into the kind of systematic record that supports class certification. Enterprise operations running continuous outbound campaigns for sales, follow-ups, reminders, and inbound intake benefit from that visibility precisely because the volume that makes AI calling economically compelling is the same volume that amplifies any single compliance gap into a class-action multiplier.

Consent forms feel like a solved problem until a plaintiff's attorney asks you to produce the timestamped, per-call consent record tied to a specific phone number at a specific moment in your claim intake workflow. That request exposes a gap most legal teams don't know exists: the difference between collecting consent and architecturally proving it, call by call, at the moment each automated outbound leg was placed. It is a gap that feels especially acute on the buyer side of outreach: legal operations teams we work with consistently find that prior express written consent requirements are harder to operationalize when building buyer or claimant lists than on straightforward seller outreach pipelines, precisely because the consent chain is longer and the reassignment risk compounds at every handoff.

The deeper problem is one that intake workflows are structurally blind to: a consent clause in your terms of service becomes legally inert the moment a phone number is reassigned, because the FCC's unsettled "prior express consent" definition means courts, not policy documents, determine whether your consent covered the actual recipient of each call, and wrong-number liability attaches on a per-call basis regardless of what your intake script says. No form, however carefully drafted, resolves that exposure at the architectural level where TCPA liability actually accrues. The FCC's own prolonged effort to amend its definition of prior consent, ultimately abandoned in the wake of the Eleventh Circuit's ruling, confirms that the regulatory ground here remains contested and that the burden of operationalizing consent falls on callers, not on future rulemaking.

Consent form, broken chain link, and secure server illustrating TCPA per-call consent proof gap

Image: Consent form, broken chain link, and secure server illustrating TCPA per-call consent proof gap

Legal operations teams report that buyer-side outreach compliance feels murkier than the seller side, suggesting that prior express written consent requirements are harder to operationalize when building buyer lists compared to seller outreach pipelines.

Under 47 C.F.R. § 64.1200(f)(9), prior express written consent is not a signature on a form. It is a four-element construct: a written agreement (including electronic), signed by the consumer, that clearly authorizes the specific seller to deliver autodialed or prerecorded calls, to a specific number, for a described purpose. Miss any one element and the consent is legally defective.

The FCC's framework also draws a hard line between "prior express consent" (sufficient for informational calls) and "prior express written consent" (required for telemarketing). That distinction matters enormously in claim intake, where a single workflow can cross both categories depending on what the agent says. Maintaining strict security and compliance standards at this level of granularity, per call, per number, per consent element, is not a documentation exercise.

It is an engineering discipline. Bland.ai's Enterprise plan is built around exactly that reality: dedicated infrastructure, compliance documentation available under NDA, and a forward-deployed engineering team that scopes, builds, and gray/red/green-team tests your first agent within a 30-day deployment framework before a single live call is placed. A 99.9% uptime SLA, concurrency and daily call volume sized to your campaign provide the throughput headroom to run compliant outbound campaigns without resorting to architectures that compress consent verification in the name of speed.

Critically, LLM inference, real-time transcription, and premium voice are all included in the per-minute rate; there are no hidden token charges that create incentives to shorten calls before consent verification logic completes.

A status-update call telling a claimant their adjuster has been assigned reads as informational. A follow-up call asking whether the claimant wants to add rental coverage reads as telemarketing. The same workflow, the same phone number, two different consent thresholds.

The FCC's regulatory framework, confirmed in Insurance Marketing Coalition, Ltd. v. FCC, 127 F.4th 303, treats call content as the classification trigger, not call origin. If your AI phone agent pivots from claim status to coverage options mid-call, the informational consent captured at intake no longer covers that leg.

The legal exposure attaches to the content delivered, not the intent documented in your intake script. This is where the architecture of the calling platform itself becomes a compliance control. Bland.ai's conversational pathways allow legal and operations teams to define and enforce the exact boundaries of what an AI phone agent may and may not say within a given call type, setting customer service quality standards at scale rather than relying on individual agent discretion.

A pathway scoped to claim-status delivery can be version-locked so that no mid-cycle content drift accidentally crosses the informational-to-telemarketing line. When Kin's customer-support team was absorbing high-volume inbound calls, policy questions, billing inquiries, and claims status checks, the operational problem was not just cost; it was the consistency risk of routing every call through a small team under pressure. The same consistency risk applies to consent-scope enforcement: a fatigued human agent improvises; a version-locked AI pathway does not.

The FCC's final rule landscape on consent makes that consistency a legal asset, not merely an operational one.

Even a perfectly constructed PEWC record has a defined scope. Consent to receive claim-status calls does not extend to upsell conversations, and it expires or becomes void the moment the consumer revokes it, which, under the FCC's framework, they may do at any time by any reasonable means. Your intake architecture must be able to honor that revocation in real time, before the next outbound leg is placed, not in the next batch sync.

For teams running continuous outbound campaigns, follow-ups, reminders, status updates, across high call volumes, the integration layer is where revocation honoring either works or fails. Bland.ai's integrations platform and Amazon Connect integration allow consent and revocation state to flow between your CRM, your contact center infrastructure, and the AI calling layer without requiring a migration or a manual reconciliation step. On the Enterprise plan, that integration is stood up by a forward-deployed engineer whose explicit mandate is to make the system production-ready, not to hand off a configuration document and leave the compliance gap open.

The FCC's abandoned consent-amendment proceeding means no regulatory relief is coming for organizations whose revocation handling depends on batch processes; the liability accrues call by call, and the architecture has to match that cadence.

TCPA Exemptions and Exceptions — and the Gaps That Create Hidden Exposure#

Legal sign-off on a TCPA-compliant script is not the same as legal protection. The gap between those two things is where class actions are born, and it is wider than most enterprise compliance teams realize, and wider still for teams deploying AI voice agents for the first time. Healthcare providers running appointment reminders and no-show follow-ups through AI-generated voice calls face a specific version of this uncertainty: operational calls that feel routine sit in a regulatory gray zone that existing TCPA guidance has not cleanly resolved for AI-specific use cases. Understanding where the hard edges actually are is the prerequisite to deploying any automated calling program responsibly.

TCPA exemption bullseye with AI voice call arrows falling into regulatory gap zones

The Four Federal Exemptions That Actually Exist and What Each One Excludes#

The TCPA recognizes four narrow federal exemptions: calls made with prior express consent, calls made for emergency purposes, calls made by or on behalf of tax-exempt nonprofit organizations, and certain calls to residential landlines that meet specific content and timing requirements. Each one carries conditions that legal teams routinely underread. The emergency exemption, for example, applies only when the call is made necessary by an imminent threat to health or safety. Routine claim status updates do not qualify, regardless of how urgently the adjuster frames them. AI-generated appointment reminders, even those handling genuinely complex, regulated call flows, fall into the same trap: the operational value of the call does not determine its regulatory classification.

The Established Business Relationship Defense Is Dead for Cell Phones#

The established business relationship (EBR) defense was eliminated for autodialed calls to cell phones by the FCC's 2012 order in the In re Rules and Regulations Implementing the TCPA proceeding. That order required prior express written consent for autodialed or prerecorded calls to wireless numbers, removing EBR as a valid shield. Insurance carriers still citing EBR to justify automated follow-up calls to policyholders' cell phones are relying on a defense that has been gone for over a decade. The same logic applies to AI voice agents conducting outbound follow-ups or inbound intake at scale; the delivery mechanism does not resurrect an extinct defense.

State Autodialer Laws That Supersede the Federal Exemption Your Counsel Approved#

The post-Duguid assumption that targeted-list AI dialers escape TCPA exposure is a compliance trap. State-law overlays like Florida's FTSA apply their own broader autodialer definitions and private rights of action independent of the federal standard, meaning a legal sign-off on a TCPA-compliant script does not constitute compliance in the jurisdictions where most mass tort claimants actually live. Florida's amended Telephone Solicitation Act (FTSA), reinforced by courts as recently as 2024 (Bradley LLP analysis, January 2024), uses a broader autodialer definition than the post-Duguid federal standard and creates its own private right of action (Florida Bar Journal).

A call that survives the federal ATDS test can still anchor an FTSA class action. Washington's Consumer Electronic Mail Act and analogous Illinois statutes apply their own definitions and private rights of action that operate independently of the federal ATDS standard. A call architecture cleared under Duguid must be re-evaluated against every state-law framework relevant to the geographic footprint of the calling campaign; federal sign-off alone does not constitute multistate compliance.

This is the compliance surface that organizations deploying AI voice at scale must map before launching. Bland.ai's Enterprise plan is built specifically for regulated teams operating at this level of complexity: compliance documentation is available under NDA, and the forward-deployed engineering team ships a first working agent within 30 days using a structured 30-day deployment framework that moves from scope through gray/red/green-team testing to go-live. For teams with existing Amazon Connect infrastructure, the platform integrates directly, adding AI voice agents into existing inbound and outbound call flows without requiring a platform migration.

Concurrency, call caps, and knowledge base access are sized to the organization's actual volume, because a 100-concurrent-call ceiling and a 5,000-call daily cap, which are the limits available on the self-serve Scale plan, are not the same as infrastructure sized to enterprise calling campaigns that must also satisfy a multistate compliance posture.

TCPA Compliance Best Practices for AI-Automated Calls — Why Architecture Is the New Policy#

Five architectural controls separate a TCPA compliance program that survives discovery from one that generates a class action. Most enterprise legal teams believe the hard work is done once consent language is approved and agents are trained. In practice, the policy layer collapses the moment a single operational control fails at the infrastructure level, and at scale, those failures aren't rare exceptions; they're statistical certainties.

One reality that organizations running high-volume AI outbound campaigns consistently encounter is that TCPA compliance for AI voice is technically complex, and standing up a defensible program requires near-expert-level technical and integration knowledge that most teams don't have in-house. That barrier is real, and it explains why so many programs that look compliant on paper carry structural exposure at the infrastructure layer. Bland.ai's Integrations Platform, including native support for Amazon Connect, which allows teams already on that stack to add AI voice without migrating to a new platform, is designed to put the enforcement controls inside the call path itself, not in a downstream system a developer still has to wire together.

Cross-divisional data fragmentation is one of the most documented proximate causes of TCPA class-action exposure. A consumer who opted out through one business unit gets called by another because the opt-out never propagated across a siloed CRM. A unified consent ledger, shared across every division placing calls to the same number pool, closes this gap.

Without it, a compliant program in one department can generate liability for the entire enterprise. Bland.ai's Enterprise plan includes unlimited knowledge bases, SSO, BAA availability, compliance documentation available under NDA, and a forward-deployed engineering team that ships the first agent within 30 days under a structured 30-day deployment framework: scope, build, gray/red/green-team test, and go live. That deployment structure exists precisely because consistent application of best-practice controls across every call, at enterprise scale, requires more than a configuration guide; it requires engineering support embedded in the rollout.

For organizations already running Amazon Connect, that framework extends to integrating AI voice agents into existing call flows without a platform migration, keeping the consent and opt-out record layer unified rather than split across two systems. The combination of these five controls forms a defensible compliance baseline.

TCPA Architectural Compliance Checklist

  • Real-Time Consent Verification
    • Consent queried synchronously at dial time
    • System queries live consent record before each call connects, no batch exports
  • Synchronous DNC Scrubbing
    • Opt-outs honored immediately
    • DNC scrub runs inside call-orchestration layer, not on a scheduled sync
  • Call-Cap Enforcement
    • Per-number frequency limits enforced pre-dial
    • Cap logic sits in dialing infrastructure, not a CRM workflow rule or spreadsheet
  • Time-Zone Validation
    • Local time resolved per number before scheduling
    • Dedicated middleware resolves current local time; area code not used as proxy
  • Unified Consent Ledger
    • Single opt-out record shared across all divisions
    • Cross-divisional opt-outs propagate in real time to every call-placing business unit
TCPA Autodialer Rules - build consent capture into

Under TCPA autodialer rules, prior express written consent must be captured before the AI places a single call, not logged retroactively. Engineering teams deploying outbound voice AI need consent verification as a hard gate in the dialing pipeline, not a CRM field filled post-hoc. The tradeoff: this adds latency to lead-activation workflows, but the alternative is per-call liability exposure that can reach $1,500 for willful violations.

2. Architect Time-Zone-Aware Call Windows as a Middleware Service#

TCPA restricts outbound calls to 8 a.m.–9 p.m. in the called party's local time zone, not the caller's. For AI-automated dialers running at scale across multiple states, this means time-zone resolution must live in a dedicated middleware layer that validates every number before queue insertion. Teams that bolt this logic onto the AI agent itself risk race conditions and clock-drift errors. The real limitation: NANP-based time-zone inference fails on VoIP numbers with ported area codes.

3. Treat Real-Time DNC Scrubbing as a Synchronous API Call, Not a Nightly Batch Job#

TCPA Autodialer Rules - treat real time dnc

The FCC's 2024 Order tightened opt-out propagation timelines, making batch-based DNC scrubbing a compliance liability for any AI outbound system processing high call volumes. Enterprises need synchronous, per-number DNC lookups wired directly into the dialer's dispatch logic. This architecture adds per-call API overhead and requires SLA agreements with list providers, but it's the only design that survives an audit when a consumer opts out at 2 p.m. and your system calls them at 3 p.m.

4. Embed AI Disclosure Logic as a Non-Skippable Call Opening Sequence#

TCPA Autodialer Rules - embed ai disclosure logic

Multiple states now mandate that AI-generated voices identify themselves as artificial at the start of a call, independent of federal TCPA autodialer rules. For voice AI developers, this means the disclosure utterance must be hardcoded into the call-opening sequence and architecturally protected from being overridden by dynamic prompt injection or A/B testing frameworks. The tradeoff is reduced flexibility in opening scripts, but non-disclosure exposes operators to both TCPA and state-level AI deception statutes simultaneously.

TCPA Autodialer Rules - federate consent opt out

Data fragmentation is the hidden compliance killer in enterprise AI calling programs: a consumer opts out through one business unit's channel, but the AI dialer in a separate division has no visibility into that revocation. A unified consent ledger, a single source of truth propagated in near-real-time across all outbound systems, is now a structural requirement, not a nice-to-have. The implementation challenge is significant for organizations with siloed CRMs, but the alternative is class-action exposure from cross-divisional consent failures.

TCPA Violations and Penalties — What the Exposure Actually Looks Like for Automated Calling Operations#

A single automated calling campaign that reaches 50,000 consumers without airtight per-call documentation isn't a $500 problem. It's a $75 million problem waiting for a plaintiff's attorney to do the math. The core synthesis here is this: the true financial risk of high-volume automated claim intake is not the headline $500–$1,500 per-call figure, it is the multiplicative effect of class certification, where enterprises without per-call audit trails cannot rebut class-wide liability on an individualized basis, converting a documentation gap into eight-figure aggregate exposure. Understanding why requires looking at how TCPA penalty math actually compounds at enterprise scale, and why the gap between a correctable violation and a certified class action almost always traces back to missing infrastructure evidence, not missing consent language.

Compliance officer at desk facing exploding penalty chart, gavel and legal binders nearby

The companies that settled in the eight-figure range almost universally had consent language somewhere in their documentation. What they lacked was per-call, per-consumer proof they could produce at discovery. Plaintiffs' attorneys don't challenge the policy; they subpoena the call logs.

When defendants can't produce per-call records at discovery, the absence of evidence becomes evidence of liability. Courts have found that an inability to demonstrate individualized consent on a call-by-call basis supports, rather than defeats, class certification, because it shows that the question of consent is common to the class rather than requiring individualized inquiry. The consent form in your terms of service is not a substitute for that record.

This is where the infrastructure layer matters as much as the legal layer. Bland.ai's Enterprise plan is built around dedicated infrastructure with compliance documentation available under NDA, precisely because organizations running at volume need records that survive a subpoena, not just policies that survive a deposition. The platform's ability to track and analyze call outcomes and sentiment on every call means each interaction generates a structured log, not a void.

For teams already operating on Amazon Connect, the Amazon Connect Integration lets AI voice agents run within existing call flows, preserving the audit continuity that compliance teams require without forcing a platform migration. Bland.ai's forward-deployed engineering team ships the first agent within 30 days under a defined scope, build, and test framework, so the documentation infrastructure is embedded from day one, not retrofitted after a complaint lands. The largest TCPA settlements were not built from a single bad call; they were built from the compounding absence of records across thousands of them.

The answer is not to call less; it is to ensure every call is documented as if a class action attorney will read it tomorrow.

Buying an AI calling platform based on its compliance page is the enterprise equivalent of inspecting a fire suppression system by reading the brochure instead of checking whether the pipes connect to the sprinklers. That gap has contributed to documented discovery failures in TCPA litigation, where defendants could not produce call-level audit logs despite having published compliance policies, a pattern that TCPA defense practitioners and litigation reviews have consistently identified as a proximate driver of class certification. The document describes what the vendor promises. The infrastructure determines what actually happens when a call goes out at scale and a plaintiff's attorney issues a legal hold the following morning.

Five infrastructure compliance checkpoints for AI calling platforms evaluated against TCPA requirements

One underappreciated complication compounds this risk: the FCC has not issued clear guidance on whether AI-generated voice calls qualify the same as prerecorded messages under TCPA exemptions, leaving operators in a legal gray area when evaluating their AI calling infrastructure. That ambiguity is not resolved by a compliance policy page; it is managed, call by call, at the infrastructure layer. Operators in healthcare feel this acutely: AI-generated voice calls for appointment reminders and patient follow-ups sit in an unresolved space under TCPA restrictions even for non-telemarketing use cases, and that gap must be addressed before legal review, not after deployment.

The FCC's 2003 TCPA rulemaking establishes that do-not-call compliance and opt-out honoring are ongoing operational obligations, meaning the platform executing each call must enforce those rules at call time, not rely on an upstream policy document to do the work.

Infrastructure Questions Every AI Calling Vendor Must Answer#

Most compliance teams know to ask for a BAA and a SOC 2 report. Fewer ask the questions that actually determine litigation exposure. Is consent logic enforced at the call-orchestration layer? Are call caps configured per number at the infrastructure level? Is there a per-call transcript with a consent timestamp, exportable on demand? Where does call data reside, and who has access? Can the platform produce a complete audit trail for a specific call within 24 hours of a legal hold?

If any answer requires a caveat, that caveat is your exposure. These questions become load-bearing at volume. The Scale plan supports up to 1,000 calls per hour and 5,000 calls per day, the throughput range where a misconfigured consent control or an unenforced call cap stops being a compliance footnote and becomes a class-action predicate.

At that scale, the compliance risk profile of AI outbound calling shifts materially, and the gap between application-layer controls and infrastructure-layer enforcement is no longer theoretical.

Application-layer consent logic is code that runs in a product interface. Infrastructure-layer consent logic is enforcement built into the call-orchestration engine itself. App-layer controls can be misconfigured, bypassed by an API call, or simply unavailable when a discovery request arrives.

When consent enforcement lives at the infrastructure layer, every outbound call is blocked or permitted based on a verified consent state before the connection is made. That is not a feature; it is an architectural property. Whether that property is present in a given deployment, and whether it is preserved when integrating with existing systems, is the question. A compliance playbook that does not specify enforcement layer is not a compliance playbook.

Amazon Connect integration, for example, allows AI agents to operate within managed inbound and outbound call flows without migrating off an existing platform. The Enterprise plan provides dedicated infrastructure, data residency controls, BAA availability, on-prem/VPC deployment, and compliance documentation available under NDA, the architectural properties that make infrastructure-layer enforcement auditable rather than assumed. Enterprise concurrency is sized to volume, and billing is contracted accordingly, rather than capped at a fixed daily ceiling.

Call Caps and Audit Trail Exportability#

Call-cap enforcement is only defensible if it is documented. A cap that exists in configuration but produces no per-call enforcement log is functionally invisible at discovery. The platform you deploy must be able to export a complete, timestamped record, showing that the cap was checked, the check passed, and the call was permitted, for every outbound leg, on demand, within the window a legal hold requires.

If that export requires a support ticket to your vendor, you do not control your own compliance evidence. Plan-level caps are explicit and graduated: Start is capped at 20 concurrent calls and 200 calls per hour; Build raises that to 50 concurrent calls and 1,000 per hour with a 2,000-call daily ceiling; Scale supports 1,000 calls per hour and a 5,000-call daily cap.

Real-time transcription is included in the per-minute rate at every tier, meaning the per-call transcript record that TCPA defense practitioners identify as the minimum evidentiary requirement is not an add-on to procure separately; it is a property of every call the platform executes. The compliance question is not whether a transcript exists; it is whether your deployment architecture ensures that transcript is captured, stored, and exportable on the timeline a legal hold demands.

Next steps#

If your automated claim intake operation is running on consent language your counsel approved but cannot produce a per-call timestamp when discovery arrives, the path forward starts with infrastructure that enforces compliance at the orchestration layer, not the policy layer. Start with our voice AI.

The finding that state-law overlays like Florida's FTSA apply broader autodialer definitions independent of the federal standard means a script cleared under federal review can still anchor a class action in the jurisdictions where most claimants live. The finding that enterprises without per-call audit trails cannot rebut class-wide liability on an individualized basis means a single documentation gap, replicated across a campaign, converts a correctable configuration error into eight-figure aggregate exposure. Together, they point to one concrete action: verify that the platform executing your calls enforces consent logic, call caps, and revocation handling at the infrastructure layer and can export a complete audit trail within 24 hours of a legal hold, before your next campaign launches.

Start with voice AI built on dedicated infrastructure where consent verification, call-cap enforcement, and per-call transcripts are properties of the call path itself. From there, a forward-deployed engineering team scopes, builds, and tests your first compliant agent within 30 days, so the audit trail your legal team needs exists from the first live call, not the first demand letter.

Frequently Asked Questions#

What did the Supreme Court actually decide in Facebook v. Duguid, and what did it leave open?#

Duguid, and what did it leave open?

In Facebook v. Duguid (2021), the Supreme Court held that to qualify as an ATDS, a device must use a random or sequential number generator either to store or to produce the numbers it dials, meaning a system that simply stores and dials a fixed list of specific numbers does not meet the federal definition. What the Court did not decide is equally important: Duguid did not resolve state-law liability, FCC rulemaking authority, or how AI-driven calling systems should be classified when their internal logic generates call sequences adaptively.

Does the FCC have ongoing authority over TCPA rules, or is the statute fixed after Duguid?#

The FCC retains rulemaking authority, and the post makes clear that Duguid left FCC authority unresolved. In fact, the FCC's own prolonged effort to amend its definition of prior express consent was ultimately abandoned in the wake of the Eleventh Circuit's ruling, confirming that the regulatory ground remains contested and that no further regulatory relief should be expected; the burden of operationalizing consent falls on callers.

What are the actual dollar penalties for a TCPA violation?#

The TCPA sets statutory damages at $500 per violation, rising to $1,500 per willful or knowing violation, with each non-compliant call treated as a separate, independently actionable violation under 47 U.S.C. § 227(b)(3). In a realistic scenario, say, 10,000 calls where 2 percent lack documented consent, that produces 200 violations and up to $300,000 in exposure before a single attorney fee is counted.

Yes. The TCPA explicitly prohibits prerecorded messages to residential lines without consent, and this restriction applies independently of the other core TCPA rules, meaning a call can violate more than one restriction simultaneously. The post also notes that the FCC draws a hard line between "prior express consent" (sufficient for informational calls) and "prior express written consent" (required for telemarketing), and that distinction applies to prerecorded message calls just as it does to autodialed ones.

If we're dialing from a targeted list rather than randomly generating numbers, are we automatically in the clear after Duguid?#

Not entirely. While Duguid means a targeted-list dialer falls outside the federal ATDS definition on its face, the post warns that courts have interpreted "capacity" broadly, and state laws in Florida, Washington, and Illinois apply definitions broader than the federal ATDS standard, so a dialer cleared under Duguid can still face state-level liability. The statutory text also says nothing about AI systems that generate call parameters, branching logic, or retry queues dynamically during a campaign, leaving that classification question open.

See Bland on your actual call volume.

10 to 15 minutes with the team that ships your first agent. We come prepared with answers, not a pitch deck.

Book a call
Written byEthan ClouserContributor