RCS Outbound Campaigns and TCPA Compliance in 2026

RCS Outbound Campaigns and TCPA Compliance in 2026

ON THIS PAGE

Written by: Matt Beucler, CEO, Plura AI

Key Takeaways for RCS TCPA Compliance

  • RCS messages are treated as calls under the TCPA in 2026, so they require prior express written consent and quiet-hours controls.2
  • Operators must register campaigns through The Campaign Registry (TCR), avoid SHAFT content, and retain consent and message records for at least four years.2
  • Consent must come directly from consumers on a one-to-one, per-sender basis. Shared lead-generation consent does not meet that standard.
  • Quiet-hours enforcement uses the recipient’s local time zone, and opt-out confirmations must contain no promotional content.
  • Plura AI’s carrier-owned compliance engine enforces these requirements at message origination, learn how Plura AI can help secure your RCS campaigns.

How TCPA Applies to RCS in 2026

RCS sits in a gray regulatory area, but the litigation risk is very clear. The FCC’s 2019 RAY BAUM Act Order did not address RCS in relation to the TCPA’s definition of “text message”.2 Courts have since expanded how “call” is interpreted. A February 2026 Louisiana district court ruling in McGonigle v. Shopperschoice.com held that TCPA §227(c)(5) covers text messages to cell numbers, reasoning that the ordinary meaning of “call” includes any attempt to reach someone by telephone.

Texas Senate Bill 140, effective September 1, 2025, expanded the definition of telephone solicitation under the telemarketing statute to include transmissions of text or graphic messages or images and incorporated DTPA enforcement mechanisms that provide a private right of action.2 March 2026 set a record with 283 TCPA cases filed, including 220 class actions, representing a 17.6% year-over-year increase. For high-volume operators, the operationally conservative approach is to treat RCS campaigns as covered by the TCPA. Consult qualified counsel to assess your specific exposure.

The seven-row checklist below maps each compliance requirement to its 2026 rule, RCS application, documentation standard, enforcement point, retention period, and verification method.

Requirement 2026 Rule RCS Application Documentation Needed Enforcement Point Retention Verification Method
Prior express written consent One-to-one consent rule was vacated by the Eleventh Circuit Court of Appeals and removed by the FCC, affirmative opt-in, per-sender specificity Each brand must collect consent directly, shared lead-gen consent is invalid Timestamp, IP address, disclosure text, source URL, phone number Pre-send consent verification 4 years minimum (5 years per some state rules) Immutable consent ledger, audit export
Time-of-day restrictions 8 a.m. to 9 p.m. local time (federal), state variations apply Recipient’s time zone governs, sender’s time zone is not a valid defense Time-zone detection logs per message Origination-layer quiet-hours enforcement 4 years minimum Automated time-zone detection, send-log audit
Opt-out handling Any reasonable method, honor within 10 business days (FCC rule effective January 31, 2027) STOP, UNSUBSCRIBE, CANCEL, END, QUIT, OPT-OUT keywords, email, voicemail, informal language also accepted Opt-out event log with timestamp and method Real-time keyword detection, suppression list update 4 years minimum Suppression list audit, opt-out event log
Opt-out confirmation message One non-marketing confirmation only, no promotional content Single confirmation sent within five minutes of opt-out receipt Confirmation message log with timestamp Automated single-message trigger 4 years minimum Message log review, content audit
TCR campaign registration Brand and campaign registration required, unregistered traffic blocked by carriers since February 2025 RCS A2P traffic expected to follow 10DLC-equivalent registration framework TCR brand ID, campaign ID, use-case declaration, opt-in/opt-out flow documentation Carrier-level blocking of unregistered traffic Duration of campaign plus 4 years TCR dashboard, carrier provisioning confirmation
SHAFT sender identification CTIA Messaging Principles prohibit Sex, Hate, Alcohol, Firearms, Tobacco content, carrier scanning enforced Applies to RCS campaigns, Google RCS Business Messaging adds its own acceptable-use layer Campaign content samples submitted at registration, content policy acknowledgment Carrier content filtering at origination 4 years minimum Campaign sample review, carrier filtering logs
Recordkeeping 4-year minimum retention (federal) Timestamp, IP address, disclosure text, source URL, consent method, opt-out events Immutable consent and message logs, audit-ready export capability Platform-level data retention enforcement 4 years minimum, state variations apply One-click audit export, legal hold capability

See how Plura’s compliance features map to each pricing tier

Prior Express Written Consent for RCS Campaigns

The FCC’s one-to-one consent rule was vacated by the Eleventh Circuit Court of Appeals and subsequently removed by the FCC, so it never took effect. Operators should obtain explicit, individual consent from consumers for each seller, which closes the shared-consent loophole previously used by lead generators. Consent collected through lead-generation forms that list multiple brand partners does not meet that standard. Each brand must independently collect and verify consent through a direct relationship with the consumer.

Valid prior express written consent for marketing messages must satisfy several elements. Consent must be in writing, obtained via affirmative action without pre-checked boxes, specific as to the sender and message type, and not a condition of purchase. The consent record should capture the source URL, UTC timestamp, IP address, exact disclosure text shown, and consent method.

One circuit-level development affects operators in Louisiana, Mississippi, and Texas. In Bradford v. Sovereign Pest Control of Texas, Inc., the Fifth Circuit held that the TCPA requires only prior express consent, which can be oral or inferred from conduct, and rejected the FCC’s written-consent requirement for telemarketing. Outside the Fifth Circuit, the FCC’s prior express written consent requirement remains in effect. Operators running national RCS campaigns should consult counsel on how this ruling affects their consent architecture. The stakes for getting consent wrong are substantial, because TCPA violations can cost $500 to $1,500 per text or call, with class action settlements averaging $6.6 million.

Plura timestamps and stores consent records in an immutable ledger and supports one-click audit exports for legal review.

Screenshot of Plura’s fully compliant AI communications platform showing business registration and phone number provisioning workflows for AI Voice, SMS, RCS, and Webchat communication automation.
Plura’s FCC-licensed AI communications platform simplifies compliant business registration and phone number provisioning for AI Voice, SMS, RCS, and Webchat workflows.

Quiet-Hours Rules for RCS Texting

Federal TCPA rules prohibit marketing texts before 8:00 a.m. or after 9:00 p.m. in the recipient’s local time zone, as confirmed by the FCC since its 2003 order. A 2026 federal court ruling clarified that quiet-hours restrictions are determined by the recipient’s time zone, and lack of knowledge of the recipient’s time zone is not a valid defense.

Several states impose stricter windows. Florida and Massachusetts restrict marketing texts to 8:00 a.m. to 8:00 p.m. Oregon, effective January 1, 2026, added text coverage with tighter 8:00 a.m. to 8:00 p.m. hours and daily call caps. Texas, Indiana, and Colorado restrict outbound texts to 9:00 a.m. to 9:00 p.m. on the morning side. Maryland prohibits telemarketing texts before 1:00 p.m. on Sundays. The CTIA Messaging Principles recommend an 8:00 a.m. to 8:00 p.m. window for advanced messaging including RCS to reduce carrier filtering.

Prior express written consent does not waive quiet-hours restrictions. Both requirements must be satisfied independently on every outbound RCS message.

Opt-Out Handling and Confirmation for RCS

The FCC’s consent-revocation rule is effective January 31, 2027. This rule allows consumers to revoke consent in any reasonable manner, and businesses must honor that revocation within 10 business days. Accepted revocation methods include standard keywords such as STOP, STOPALL, UNSUBSCRIBE, CANCEL, END, QUIT, and OPT-OUT, along with email, voicemail, and informal language.

After receiving an opt-out, operators may send a single confirmation message that contains no promotional content. The number must then be suppressed across every campaign for that brand. Virginia, effective January 1, 2026, requires businesses to honor text opt-out requests. The broader Revocation-ALL rule, which would require honoring a single STOP request across all unrelated communication channels, was delayed from April 11, 2026, to January 31, 2027.

TCR Registration and Carrier Controls for RCS

Since February 1, 2025, U.S. wireless carriers have blocked 100% of unregistered A2P traffic sent over 10-digit long codes. Every business must register a Brand and at least one Campaign through The Campaign Registry before any traffic flows. Registration requires declaring the brand, the use case, and the opt-in, opt-out, and HELP flows.

For RCS, RCS A2P traffic is expected to require registration and compliance frameworks similar to those for A2P 10DLC, with major carriers Verizon, AT&T, and T-Mobile running beta programs as of 2026. TCR registration is separate from TCPA consent obligations, so operators must address both. Carriers also enforce real-time content filtering that compares live messages against registered campaign samples, and deviations from approved samples can be blocked.

Plura RCS messaging interface showing rich mobile communication with branded media, interactive messaging, and AI engagement tools.
Plura RCS enables rich mobile messaging with interactive media, branded customer experiences, and AI-powered conversational engagement.

Plura AI’s carrier-owned compliance engine enforces TCR registration status at origination and blocks unregistered traffic before it reaches the network. View pricing for carrier-grade compliance enforcement

SHAFT Content and Sender Identification for RCS

The CTIA Messaging Principles and Best Practices enforce SHAFT content restrictions covering Sex, Hate, Alcohol, Firearms, and Tobacco, including vape, CBD, and cannabis products, regardless of consent. Carriers scan campaigns and may reject or block content that matches SHAFT categories. These restrictions apply to RCS campaigns in addition to SMS. Google’s RCS Business Messaging layer adds its own acceptable-use policy for verified senders.

<img src="https://cdn.aigrowthmarketer.co/1779339090994-980045ddacd2.png" alt="Plura Security & Compliance dashboard highlighting SOC 2, ISO, and GDPR standards with secure trust verification management.1″ style=”max-height: 500px;” loading=”lazy” decoding=”async”>
Plura Security & Compliance supports SOC 2, ISO, and GDPR standards with trust registration, verification management, and secure AI communications.

Sender identification is a separate requirement. Marketing texts must include clear business-name identification. Adding any promotional content to a transactional message reclassifies the entire message as marketing and triggers the full prior express written consent requirement.

Recordkeeping Standards and Audit Exports

A defensible TCPA consent log must capture, for every subscriber, the source URL, UTC timestamp, IP address, exact disclosure text shown, browser user-agent, consent method, and all opt-out events. The federal minimum retention period is four years, and some state rules extend that window. Some compliance frameworks recommend a five-year minimum to account for state-level variation.

Plura stores consent records in an immutable, timestamped ledger and provides audit-ready exports in one click. This supports legal review, carrier requirements, and regulatory inquiries without manual data assembly.

Conclusion: Operational Checklist for RCS TCPA Risk

RCS outbound TCPA compliance in 2026 maps to seven operational requirements. These include prior express written consent collected on a one-to-one, per-sender basis, time-of-day restrictions enforced by the recipient’s local time zone, opt-out honored within 10 business days via any reasonable method, and a single non-marketing confirmation message. They also include TCR brand and campaign registration before any traffic flows, SHAFT content restrictions enforced at the carrier level, and a minimum four-year recordkeeping standard covering timestamp, IP address, disclosure text, URL, consent method, and opt-out events.

The litigation environment reinforces the urgency. 2,628 TCPA cases were filed in 2025, and the Q1 2026 filing surge mentioned earlier underscores the persistent litigation risk. With the statutory damages and settlement costs outlined earlier, operators running thousands of RCS interactions monthly carry material exposure on each of these seven dimensions simultaneously.

Plura AI’s carrier-owned compliance engine enforces these requirements at message origination, not as a post-send audit layer. Consent verification, time-zone-based quiet-hours enforcement, real-time DNC scrubbing, and immutable recordkeeping operate as core platform layers. Operators should consult qualified counsel to assess their specific obligations under the TCPA, applicable FCC rules, and state law before deploying RCS outbound campaigns at scale. Explore compliance-ready plans for high-volume RCS campaigns

Frequently Asked Questions

Does TCPA apply to RCS messages in 2026?

The FCC has not explicitly addressed RCS under TCPA, but courts have applied TCPA provisions to text messages broadly. Texas Senate Bill 140 expanded telemarketing definitions to include text transmissions, and 2,628 TCPA cases were filed in 2025. The prudent operational approach for high-volume U.S. operators is to treat RCS campaigns as subject to TCPA requirements and consult qualified counsel on specific legal exposure.

What does the one-to-one consent rule mean for RCS outbound campaigns?

The FCC’s one-to-one consent rule was vacated by the Eleventh Circuit Court of Appeals and subsequently removed by the FCC, so it never took effect. Operators should have each brand obtain prior express written consent directly from the consumer before sending marketing messages. Consent collected through lead-generation forms that list multiple brand partners is no longer valid for downstream use by those brands. Each sender must independently collect consent, document it with a timestamp, IP address, source URL, and exact disclosure text, and store that record for a minimum of four years. Operators purchasing third-party leads must verify that the consent form specifically named their company and that the page topic matched the product offered.

How does Plura AI support TCPA compliance for RCS outbound messaging?

Plura AI’s carrier-owned compliance engine enforces TCPA-related requirements at message origination. The platform stores consent records in an immutable, timestamped ledger, enforces time-of-day quiet-hours rules automatically through time-zone detection on the recipient’s number, performs real-time DNC scrubbing before each outbound contact, and surfaces audit-ready exports in one click. Plura supports customer compliance operations, and customers remain responsible for their own regulatory obligations, consent architecture, and the claims they make to their end users. Operators should consult qualified counsel on their specific TCPA posture.

What are the SHAFT restrictions for RCS campaigns, and how are they enforced?

SHAFT stands for Sex, Hate, Alcohol, Firearms, and Tobacco. The CTIA Messaging Principles and Best Practices prohibit messaging content in these categories regardless of whether the recipient has provided consent. Carriers scan campaigns in real time and may block or reject content that matches SHAFT categories. For RCS specifically, Google’s RCS Business Messaging layer adds its own acceptable-use policy for verified senders, which creates a second enforcement layer on top of carrier-level filtering. Operators should review both the CTIA guidelines and Google’s RCS Business Messaging policies when designing campaign content.

What recordkeeping does a defensible RCS consent log require in 2026?

A defensible consent log for RCS outbound campaigns must capture, for every subscriber, the source URL where consent was collected, the UTC timestamp of consent, the IP address of the consenting device, the exact disclosure text shown to the consumer, the consent method such as checkbox, signature, or verbal confirmation, and a complete log of all opt-out events. The federal minimum retention period is four years, and some compliance frameworks recommend five years to account for state-level variation. Records should be stored in a format that supports one-click audit export for legal review, carrier requirements, or regulatory inquiries.


1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.

2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.

This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.

This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.

See how Plura AI transforms AI voice agents