AI Cold Calling & TCPA Compliance: What SMBs Need to Know in 2026

July 2, 2026 · 12 min read · AI Calls

AI voice agents are legal — but only if you respect TCPA, DNC lists, and state-level consent rules. Here's the compliance checklist every SMB should use before scaling outbound AI calls.

AI voice agents can 10× your outbound capacity almost overnight. The catch: the FCC and FTC treat an AI-generated call the same way they treat a human dialer. That means every rule your grandfather's call center had to follow still applies — plus a growing pile of new rules specifically designed for synthetic voices. Get compliance wrong and one complaint can turn into a $500–$1,500 statutory penalty per call, plus attorney's fees under the Telephone Consumer Protection Act (TCPA).

The good news: staying compliant is not complicated. It just requires that you set up your outbound program correctly on day one, instead of retrofitting rules onto a campaign that's already going out. This guide walks through the six categories of rules that matter most in 2026, the mistakes SMBs make most often, and how Legion enforces the guardrails automatically.

Why compliance suddenly matters more in 2026

Three things changed the risk profile of AI calling this year. First, the FCC's 2024 declaratory ruling formally confirmed that AI-generated voices are "artificial or prerecorded" for TCPA purposes — so the same consent standards that apply to a robocall apply to your AI agent. Second, state-level laws in California, Florida, and Texas now require explicit disclosure that the caller is AI. Third, plaintiff's-side attorneys have industrialized TCPA litigation; a single motivated recipient can generate a class action.

The practical implication is that "we didn't know" is no longer a viable defense. Any SMB running outbound AI calls needs a documented process for consent, DNC scrubbing, opt-out handling, calling hours, caller identification, and AI disclosure.

The 6 rules that matter most

1. Prior express written consent for marketing calls to mobile numbers

Under the TCPA, any marketing call placed to a mobile number using an autodialer or artificial voice requires prior express written consent. That means a signed opt-in — typically a checkbox on a form, a "text START" reply, or a signed contract — that is specific to the phone number being called and discloses that the recipient may receive automated marketing calls.

Common mistake: assuming that a lead who filled out a form for a whitepaper has consented to marketing calls. They haven't. The consent language has to explicitly authorize marketing calls from your business via automated technology.

2. Scrub against the National DNC list before every campaign

The National Do Not Call Registry is the floor, not the ceiling. Some states maintain their own DNC lists (Pennsylvania, Wyoming, and Indiana are the most notable), and internal DNC records — people who have askedyou not to call them — must also be honored regardless of federal listing.

Best practice is to scrub the target list against federal, state, and internal DNCs at the moment the campaign fires, not the moment it was uploaded. A list that was clean on Monday can have new opt-outs by Wednesday.

3. Honor opt-outs within 10 business days — and store proof

When a recipient says "take me off your list" — verbally on a call, via SMS reply, or through a web form — you have 10 business days under FCC rules to remove them from every campaign, workspace, and dialer. Miss this window and each subsequent call is a separate TCPA violation.

Equally important: keep an auditable record of when the opt-out happened and when it was processed. In litigation, the burden is on you to prove the timeline.

4. Call only 8am–9pm in the recipient's local timezone

This is the rule most SMBs violate accidentally. If your business is in Los Angeles and you fire a campaign at 6pm your time, you're calling New York recipients at 9pm — the very edge of the window. A campaign that runs a few minutes late puts every East Coast dial into violation.

Modern dialers (including Legion) enforce this automatically by looking up the timezone of each phone number's area code and gating dials accordingly.

5. Identify the caller and business in the opening seconds

Every call must clearly state (a) who is calling, (b) on behalf of what business, and (c) how the recipient can opt out. "Hi, this is Alex calling from Legion AI — is now a good time?" checks the first two boxes. The opt-out cue can come later, but must come before the call ends.

6. Disclose AI usage where required

Several states (CA SB 1120, FL HB 919, TX HB 2879 among them) now require explicit disclosure that the voice is AI. The safest global default is to disclose on every call, regardless of jurisdiction: "This is an AI assistant calling on behalf of [Business]." Recipients almost universally accept it, and it eliminates a whole category of legal exposure.

The compliance mistakes we see most often

  • Purchased lead lists with no consent trail. The vendor promises "opt-in" but can't produce the actual capture record. That's not consent — that's a lawsuit waiting to happen.
  • Reusing a "sales" consent for "marketing" campaigns. A prospect who consented to a demo follow-up did not consent to a monthly promo blast.
  • Ignoring wireless portability. Landline numbers get ported to mobiles constantly. If your list is more than 60 days old, re-run wireless identification before dialing.
  • No revocation UX in the AI script. If the recipient says "stop calling me" and your agent doesn't detect that intent, you'll keep dialing — and each subsequent call compounds liability.

A 30-minute pre-launch checklist

  1. Confirm the consent capture language on your form(s) mentions automated marketing calls.
  2. Export a fresh copy of your internal DNC list and load it into the campaign.
  3. Run the target list through National DNC scrubbing.
  4. Set calling hours to 9am–8pm recipient local (a conservative buffer inside the legal window).
  5. Verify your AI script opens with caller identification and AI disclosure.
  6. Test the opt-out phrase library — "stop", "remove me", "don't call again", "unsubscribe".
  7. Turn on call recording with a two-party consent notice at the start.
  8. Assign a compliance owner who reviews a random 1% of calls each week.

How Legion enforces this by default

Legion's dialer auto-checks numbers against the National DNC before each dial, enforces local-time windows per area code, records and time-stamps consent, and drops any number that has previously opted out — across every workspace campaign, not just the one where the opt-out happened. Call recordings and transcripts are stored with a legal-hold audit trail so that if you're ever asked to produce consent or an opt-out record, it takes seconds instead of a legal fire drill.

None of this eliminates the need for a sensible policy — Legion is a tool, not a lawyer — but it removes the operational excuses that lead to accidental violations.

Related: AI voice agents for small business.

Want to see it live? Book a 30-min Legion AI demo.