TCPA Consent Requirements for AI Voice and SMS Campaigns

TCPA Consent Requirements for AI Voice and SMS Campaigns

ON THIS PAGE

Written by: Matt Beucler, CEO, Plura AI

Key Takeaways for 2026 AI Outreach

  • Prior express written consent (PEWC) is required for AI voice and SMS marketing, with disclosures naming the sender, referencing AI, and stating the purpose.
  • Consent records should include UTC timestamps, IP addresses, source URLs, exact disclosure text, and be retained at least 4 to 5 years.
  • AI-generated voices are treated the same as traditional robocalls under the FCC’s February 2024 Declaratory Ruling, with no exceptions for conversational AI.
  • Revocation requests must be detected in real time, honored within 10 business days, and applied across all channels, with the “revoke-all” rule effective January 31, 2027.
  • Plura AI’s Compliance Engine embeds real-time DNC scrubbing, timestamped consent logging, and one-click audit exports into AI voice and SMS workflows. Learn more.

Prior Express Written Consent Requirements for AI Outreach

Under 47 C.F.R. § 64.1200(f)(9), prior express written consent (PEWC) is the standard for marketing calls and texts using an autodialer, prerecorded voice, or AI-generated voice.2 A defensible PEWC record typically includes the following elements. Consult qualified counsel to confirm how these elements apply to your specific campaigns.

  1. Written agreement with affirmative action. The consumer must take an affirmative step, such as checking an unchecked box or submitting a signed form. Pre-checked boxes do not satisfy this standard.
  2. Identification of the specific sender. The disclosure must name the exact legal or brand name of the company sending messages, not generic language such as “marketing partners.”
  3. Disclosure of automated or AI-generated technology. The consent language must reference automated text messages and phone calls, including by artificial or prerecorded voice, to cover AI voice campaigns under the FCC’s February 2024 Declaratory Ruling.
  4. Description of message purpose. The disclosure must identify the specific purpose, such as loan options, insurance quotes, or appointment scheduling.
  5. Consent is not a condition of purchase. This statement must appear explicitly in the disclosure.
  6. Message frequency and data-rate disclosure. Standard language such as “Msg & data rates may apply. Msg frequency varies” is expected.
  7. Opt-out instructions. The disclosure must include instructions such as “Reply STOP to opt out.”
  8. Electronic or physical signature. Electronic signatures are valid under the E-SIGN Act. A single form may authorize multiple sellers only when each seller is clearly identified by name.

TCPA Consent Duration and Retention Windows

TCPA consent does not carry a fixed expiration date under the statute, but recordkeeping obligations align with the federal statute of limitations and state-law claim windows. The table below summarizes retention periods operators typically maintain. Consult qualified counsel regarding the periods applicable to your jurisdiction and campaign type.

Record Type Minimum Retention Period Basis
Consent records (PEWC) 4 years (federal SOL under 28 U.S.C. § 1658) Federal TCPA statute of limitations
DNC scrub logs 4-5 years Federal SOL plus state-law buffer
Call and SMS records 4-5 years Federal SOL plus state-law buffer
Opt-out and revocation records 5 years (up to 10 years in some states) State mini-TCPA laws, for example, Virginia

Consent effectively ends when a consumer revokes it through any reasonable means. Once revoked, the record of that revocation should be retained for the applicable period.

Written Consent vs. Other TCPA Consent Standards

The FCC’s framework under 47 C.F.R. § 64.1200 requires prior express written consent for marketing calls and texts using an autodialer or artificial voice. That PEWC standard remains the operative rule in most U.S. jurisdictions.

Post-Vacatur Status of the One-to-One Consent Rule

The FCC’s December 2023 one-to-one consent rule would have required each seller to obtain its own direct consent rather than rely on shared lead-form consent.2 The U.S. Court of Appeals for the Eleventh Circuit vacated this rule in January 2025 in Insurance Marketing Coalition v. FCC. The FCC confirmed in April 2025 it would not challenge the vacatur and issued a final rule in July 2025 that reinstated the pre-2023 prior express written consent standard under 47 C.F.R. § 64.1200(f). Multi-seller lead forms remain legally valid under federal TCPA law as of July 2026, though plaintiffs’ counsel continue to use the one-to-one standard as a litigation benchmark.

In February 2026, the U.S. Court of Appeals for the Fifth Circuit held in Bradford v. Sovereign Pest Control of TX, Inc. that the TCPA’s statutory text requires only prior express consent, not necessarily prior express written consent, for prerecorded calls to wireless numbers. That ruling applies only within the Fifth Circuit’s jurisdiction covering Texas, Louisiana, and Mississippi. The FCC’s written-consent framework continues to apply in all other circuits. Operators should consult qualified counsel before adjusting consent practices based on either development.

TCPA Consent Checklist for AI Dialers

The FCC’s February 8, 2024 Declaratory Ruling confirmed that AI-generated voices qualify as artificial or prerecorded voice under 47 U.S.C. § 227(b), with no carve-out for real-time conversational AI or large-language-model agents. Operators running AI predictive dialer campaigns or AI SMS outreach can use the following checklist with qualified counsel.

  1. Confirm that consent language explicitly references “artificial or prerecorded voice” and names the specific calling entity, not umbrella partner language.
  2. Verify that consent was obtained before the first AI-generated call or text, not during or after.
  3. Ensure the consent form includes an unchecked, standalone checkbox not bundled with terms of service or email opt-ins.
  4. Confirm the disclosure identifies the specific purpose of the AI outreach, such as “insurance quotes” or “appointment scheduling.”
  5. Check that the consent record captures the UTC timestamp, IP address, user agent, source URL, and exact disclosure text shown at the time of opt-in.
  6. Validate that the AI dialer checks each number against the National DNC Registry and internal suppression lists before every dial attempt.
  7. Confirm that quiet-hours rules enforce automatically based on the called party’s time zone, not the operator’s.
  8. Verify that the system recognizes natural-language revocation signals, not only fixed keywords like STOP.

Book a live demo with Plura to see how the Compliance Engine enforces these controls at the campaign level.

Third-Party Lead Verification for AI Campaigns

When operators purchase leads from third-party generators, the consent record travels with the lead, but the operator remains responsible for verifying that the consent is valid and specific enough to cover their outreach. TCPA litigation has produced significant settlements where third-party consent was found defective, including a $75 million Capital One settlement involving autodialed calls made through third-party partners without adequate consent verification.

Operators purchasing third-party leads should review the following with qualified counsel:

  • Obtain the original consent record, including the source URL, UTC timestamp, IP address, and exact disclosure text shown to the consumer.
  • Confirm the disclosure names your specific company, not generic “partners and affiliates” language.
  • Confirm the disclosure references artificial or prerecorded voice if AI calling is planned.
  • Require vendor contracts to assign consent-validity responsibility to the lead generator and include indemnification provisions if consent is later found defective.
  • Run every purchased number against the National DNC Registry and your internal suppression list before the first contact attempt.
  • Cross-reference numbers against the FCC’s Reassigned Numbers Database (RND) to identify numbers reassigned since consent was collected.

Revocation Handling Across Voice and SMS

The FCC originally set the effective date of its TCPA consent-revocation rule for April 11, 2025, then delayed the key requirement until April 11, 2026 and extended that date to January 31, 2027. Consumers may revoke TCPA consent through any reasonable means. The following steps describe how operators can structure revocation handling across voice and SMS channels. Consult qualified counsel regarding the specific obligations applicable to your campaigns.

  1. Detect revocation intent in real time. Voice AI systems must classify natural-language revocation signals, such as “stop calling me,” “remove me from your list,” or “please cease,” not only fixed keywords. SMS systems must recognize STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, and UNSUBSCRIBE as per se reasonable revocation requests under the FCC’s rule.
  2. Write the opt-out to suppression immediately. Upon detection, the number should be added to the internal suppression list and flagged across all linked channels, including both voice and SMS, because revocation on one channel applies across all channels tied to that brand.
  3. Send a one-time, non-promotional confirmation. For SMS opt-outs, the FCC permits one brief, non-marketing confirmation message within five minutes of the opt-out request. No marketing content may appear in that message.
  4. Honor the revocation within 10 business days. The FCC’s rule requires that all further marketing contacts cease within 10 business days of the revocation request. Immediate suppression is the industry best practice.
  5. Log the revocation record. Capture the timestamp of the request, the channel through which it arrived, the transcript line or message containing the revocation, and confirmation of cross-channel suppression propagation.
  6. Prepare for the “revoke-all” rule. Effective January 31, 2027, an opt-out from one communication type will apply to all telemarketing robocalls and robotexts from the same company. Operators can begin aligning suppression infrastructure now.

Recordkeeping Obligations for TCPA Defense

A defensible TCPA audit trail connects every consent record to the corresponding call record, campaign record, CRM record, and suppression record. This level of documentation has become critical as TCPA litigation surged 60.1% in 2025 to 2,628 cases.3 In discovery, operators who cannot produce complete consent records within the discovery window often face a presumption that contacts were unauthorized.

Plura Security & Compliance dashboard highlighting SOC 2, ISO, and GDPR standards with secure trust verification management.
Plura Security & Compliance supports SOC 2, ISO, and GDPR standards with trust registration, verification management, and secure AI communications.
Metadata Field Required Detail Retention Period
Consent timestamp UTC, tied to specific opt-in event 4-5 years
IP address and user agent Device-level, captured at submission 4-5 years
Exact disclosure text Version-controlled snapshot at time of consent 4-5 years
Source URL and form ID Page where consent was collected 4-5 years
DNC scrub log Registry version, scrub date, result per number 4-5 years
Revocation record Timestamp, channel, transcript line, suppression confirmation 5+ years

Plura’s Compliance Engine supports these recordkeeping workflows through real-time DNC scrubbing, timestamped consent logging, and one-click audit exports. The platform supports TCPA compliance and DNC compliance infrastructure, with SOC 2, HIPAA, ISO certification, GDPR, and SHAKEN/STIR caller ID verification built into the platform layer.1 Operators remain responsible for their own compliance obligations and the accuracy of the consent records they collect upstream of the platform.

Screenshot of Plura’s fully compliant AI communications platform showing business registration and phone number provisioning workflows for AI Voice, SMS, RCS, and Webchat communication automation.
Plura’s FCC-licensed AI communications platform simplifies compliant business registration and phone number provisioning for AI Voice, SMS, RCS, and Webchat workflows.

Run your numbers through Plura’s calculator to model the cost difference between manual compliance overhead and an automated platform layer.

Frequently Asked Questions

How do prior express consent and prior express written consent differ?

Prior express consent is the lower standard, generally applicable to informational or transactional calls such as appointment reminders and account alerts. Prior express written consent is the higher standard, applicable to marketing calls and texts using an autodialer, prerecorded voice, or AI-generated voice. Written consent requires an affirmative consumer action, a signed agreement, and specific disclosures identifying the sender and the type of communication. The Fifth Circuit’s February 2026 ruling in Bradford v. Sovereign Pest Control narrowed the written-consent requirement within Texas, Louisiana, and Mississippi, but the written standard remains the operative framework in all other circuits. Consult qualified counsel to determine which standard applies to your campaigns.

How does the Eleventh Circuit’s vacatur affect multi-seller lead forms?

The Eleventh Circuit’s January 2025 vacatur of the FCC’s one-to-one consent rule means the rule is not currently enforced as written at the federal level. The FCC reinstated the pre-2023 prior express written consent standard in July 2025. Plaintiffs’ counsel, however, continue to use the one-to-one standard as a litigation benchmark, and courts in plaintiff-friendly circuits may scrutinize generic partner consent language closely. Treating one-to-one consent as the operating standard often provides a more defensible approach for lead-generation campaigns. Consult qualified counsel before relying on multi-seller consent forms.

How should AI voice systems handle verbal revocation of consent?

Under the FCC’s Revocation of Consent Rule, now effective January 31, 2027, verbal statements such as “stop calling me” or “remove me from your list” carry the same legal weight as a written STOP request. AI voice systems must classify revocation intent from natural language in real time, not only from fixed trigger phrases. Upon detection, the system should write the opt-out to a suppression list immediately and propagate that suppression across all linked channels, including SMS, within 10 business days. Delays in cross-channel propagation create per-violation exposure. Consult qualified counsel regarding your specific system architecture and revocation workflows.

What metadata should a TCPA consent record capture?

A defensible consent record for TCPA purposes typically includes the consumer’s phone number, the UTC timestamp of the opt-in event, the IP address and user agent of the submitting device, the source URL of the form or page where consent was collected, the exact disclosure text shown to the consumer at the time of consent, the specific affirmative action taken, and the seller name as it appeared in the disclosure. For opt-out events, the same metadata fields apply, plus the channel through which revocation arrived and confirmation of suppression propagation. Records should be stored in retrievable, version-controlled formats that remain accessible after platform migrations.

What are the financial stakes of TCPA consent issues in 2026?

Under 47 U.S.C. § 227(b)(3), statutory damages are $500 per violation, rising to $1,500 per violation for knowing or willful violations. Each individual call or text is treated as a separate violation. A campaign of 10,000 non-consensual contacts creates potential statutory exposure of $5 million to $15 million before any actual-harm consideration.3 TCPA litigation surged 60.1% in 2025 to 2,628 cases. Discovery costs alone typically run $50,000 to $150,000 before trial preparation.3 Immutable, audit-ready consent records function as a primary defense in TCPA litigation.

Bringing TCPA, AI Voice, and SMS Together

TCPA consent requirements for AI voice and SMS campaigns in 2026 center on prior express written consent with specific disclosures, timestamped and retrievable records, and prompt revocation handling across every channel. The post-vacatur landscape adds complexity: the one-to-one consent rule is not currently enforced federally, but litigation risk around generic partner consent remains significant. The Fifth Circuit’s February 2026 ruling creates a narrow regional exception to the written-consent standard, while the FCC’s framework continues to govern everywhere else. AI-generated voices remain subject to the same consent rules as traditional robocalls under the February 2024 ruling.

Plura’s Compliance Engine supports these workflows at the platform layer, with real-time DNC scrubbing, timestamped consent logging, SHAKEN/STIR caller ID verification, and one-click audit exports built into every AI voice and SMS campaign. Operators remain responsible for their own compliance obligations and should consult qualified counsel on consent language, recordkeeping periods, and revocation architecture specific to their campaigns.

Run your numbers through Plura’s calculator to model the ROI of embedding compliance infrastructure directly into your AI voice and SMS workflows.


1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.

2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.

3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.

This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.

This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.

See how Plura AI transforms AI voice agents