AI Voice Agent Disclosure Requirements: 2026 Playbook

AI Voice Agent Disclosure Requirements: 2026 Playbook

ON THIS PAGE

Written by: Matt Beucler, CEO, Plura AI

Updated September 2026

Key Takeaways

  • AI voice agents must disclose their artificial nature at the start of every call under the FCC’s TCPA framework, with prior express written consent required for outbound marketing calls.
  • State laws in California, Colorado, Texas, and Tennessee impose independent disclosure mandates with penalties ranging from $500 to $20,000 per violation.
  • Effective disclosures arrive within the first 10 to 30 seconds, include the business name and contact number, and appear in both audio and transcript records.
  • Operators must maintain audit-ready consent records, honor do-not-call requests immediately, and check state laws for every jurisdiction they call into.

When Disclosure Is Required: A Decision Tree

Disclosure obligations depend on who initiates the call and what the call is trying to accomplish. Operators typically face four primary scenarios.

  • Outbound marketing calls: 47 CFR § 64.1200(a)(2) requires prior express written consent for calls using an artificial or prerecorded voice that deliver an advertisement or constitute telemarketing to wireless numbers. Disclosure of the AI’s artificial nature is a common operational standard and, in several states, a statutory requirement.
  • Outbound informational or service calls: 47 CFR § 64.1200(a)(1) requires prior express consent for calls using an artificial voice to wireless numbers. State laws may independently require AI disclosure regardless of call purpose.
  • Inbound calls: When a customer initiates contact and an AI agent answers, the TCPA robocall consent framework applies differently because the customer placed the call. State recording-consent laws and state-level AI disclosure statutes may still apply, and many operators choose proactive disclosure as a standard practice.
  • Human-assisted calls with AI as the primary speaker: When an AI voice agent conducts the substantive portion of the call, the call is treated as an artificial-voice call for TCPA purposes, even if a human monitors or can take over.

The safest operational posture across all four scenarios is consistent disclosure at the start of every AI-led conversation, before any substantive exchange occurs. Practitioners are landing on the first 10 seconds as a common operational default, while several state statutes set a 30-second floor.

Federal Rules: FCC, TCPA, and FTC

The federal disclosure framework for AI voice agents rests on two parallel regimes: the TCPA, enforced by the FCC, and the Telemarketing Sales Rule (TSR), enforced by the FTC.

TCPA and FCC. 47 CFR § 64.1200 prohibits initiating calls using an artificial or prerecorded voice to wireless numbers without the prior express consent of the called party.2 For telemarketing calls, prior express written consent is required under 47 CFR § 64.1200(a)(2). The FCC’s February 2024 declaratory ruling confirmed that AI-generated voices fall within the “artificial or prerecorded voice” definition. This makes the full TCPA consent and disclosure framework applicable. The regulation was most recently amended effective March 25, 2026, reflecting ongoing regulatory activity in this area. TCPA penalties are $500 per violation for standard infractions and $1,500 per violation for willful or knowing violations, with each individual call counted as a separate violation.

FCC caller identity proposals. The FCC has proposed rules under CG Docket No. 02-278 that would require terminating providers to transmit verified caller name or other caller identity information for presentation on a consumer’s handset whenever a call has received an A-level STIR/SHAKEN attestation. These are proposed rules, not final requirements, as of September 2026. Consumer research cited in that proceeding found that 90% of consumers are uncomfortable answering unidentified calls and that 78% have missed an important call in the last month because they did not answer an unidentified number.3 A separate survey found that 92% of consumers assume unidentified calls are fraudulent.

FTC Telemarketing Sales Rule. The TSR, codified at 16 CFR Part 310, requires that at the start of every outbound telemarketing call, the telemarketer disclose the seller’s identity, that the purpose of the call is to sell goods or services, and the nature of those goods or services, before any sales pitch begins. The TSR and TCPA are parallel federal regimes. The TSR focuses on conduct during the call, while the TCPA focuses on the technology used. A single call can implicate both. Operators should consult qualified counsel to understand how both frameworks apply to their specific call programs.

State-by-State AI Disclosure Laws

State laws can impose disclosure requirements that are stricter than, and independent of, the federal TCPA framework. Operators must check the laws of every state into which they place calls. The table below covers key enacted laws as of September 2026.

State Law Effective Date Penalties
California AB 2905 (Pub. Util. Code § 2874) – Requires a natural, unrecorded voice announcement before an ADAD (automatic dialing-announcing device) operates, disclosing the nature of the call, business name, address, phone number, and that the message uses an artificial voice. September 2024 Up to $500 per violation (PUC enforcement)
California B.O.T. Act (Bus. & Prof. Code §§ 17940-17943) – Prohibits using a bot to communicate with a California person with intent to mislead about its artificial identity in order to incentivize a purchase or influence a vote, without clear, conspicuous disclosure. July 1, 2019 Up to $2,500 per violation (AG enforcement)
Colorado Chatbot Safety Act (HB 26-1263) – Requires operators of publicly accessible conversational AI services to clearly and conspicuously disclose that users are interacting with AI rather than a human. January 1, 2027 Up to $20,000 per violation (AG enforcement, no private right of action)
Texas SB 140 – Requires AI voice technology to be disclosed within the first 30 seconds of a call. September 1, 2025 State enforcement
Tennessee SB 1580 – Prohibits marketing AI as a qualified mental health professional; adds a private right of action. July 2026 Private right of action

California’s AB 2905 framework is particularly notable for outbound ADAD calls. A synthesized voice reading a disclosure does not satisfy the statute’s requirement for an unrecorded, natural voice announcement. Operators calling California numbers should review the specific requirements of Pub. Util. Code § 2874 with qualified counsel. Beyond California, Colorado’s Chatbot Safety Act takes effect January 1, 2027, and applies to any entity that develops or makes a publicly accessible conversational AI service available to consumers. Operators should monitor the Colorado Attorney General’s rulemaking, which was underway as of mid-2026.

Building AI Disclosure Scripts That Hold Up

An effective disclosure is clear, delivered early, and includes the business name and the purpose of the call. A strong operational disclosure spec includes four parts: trigger (when the disclosure must fire), content (exact approved language), timing (within how many seconds and before which events), and evidence (the artifact proving delivery, such as an audio segment, transcript span, and timestamp). The following scripts are starting points. Operators should review them with qualified counsel before deployment.

Outbound sales or marketing calls:

“This call is from an AI voice agent on behalf of [Company Name]. The purpose of this call is [state purpose]. This call may be recorded for quality assurance. If you are not interested, please say ‘stop’ to be added to our do-not-call list.”

Inbound customer service calls:

“Thank you for calling [Company Name]. I’m an AI assistant here to help you today. How can I assist you?”

Outbound informational or appointment reminder calls:

“This is an automated message from [Company Name] regarding your upcoming appointment. This call is from an AI voice agent. [Provide appointment details.] To speak with a team member, press 1.”

Every script should include the business name and a contact number, as required by 47 CFR § 64.1200(a)(7)(i). The disclosure should appear at the start of the call, not buried mid-conversation. Texas SB 140 sets a 30-second statutory floor, and practitioners treating the first 10 seconds as the operational default are building in additional margin. The disclosure must also appear in the call transcript, not only in the audio, to support audit-ready records.

Consent Requirements Under TCPA

For outbound marketing calls using AI voices, 47 CFR § 64.1200(f)(9) requires a written agreement bearing the consumer’s signature that clearly authorizes the seller to deliver marketing messages via autodialer or prerecorded voice, includes the authorized phone number, and states that consent is not a condition of purchasing goods or services. Electronic signatures recognized under the E-SIGN Act satisfy the signature requirement, so a properly disclosed web form checkbox can constitute valid consent.

For outbound informational calls, prior express consent is required, which can be inferred from an existing relationship context, such as a patient providing their phone number during intake. Organizations sending both informational and marketing messages must maintain separate consent records for each purpose. Consent must be revocable, and opt-out requests must be honored immediately. Operators should consult qualified counsel to design consent flows that satisfy both federal and applicable state requirements.

Coordinating AI Disclosure With Call Recording Consent

AI disclosure and call recording disclosure are distinct obligations that often need to be addressed in the same opening statement. The federal baseline for call recording is one-party consent under the Electronic Communications Privacy Act (ECPA, 18 U.S.C. § 2511), but 13 states require all-party consent for call recording: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, New Hampshire, Oregon, Pennsylvania, and Washington. In those jurisdictions, a combined disclosure covering both the AI’s artificial nature and the recording is a standard operational approach. The disclosure must be delivered before any substantive conversation begins. The first 15 seconds after connection is a defensible operational standard. Operators should check local requirements for every state into which they place calls.

International Considerations for AI Voice Programs

Under the EU AI Act, providers of AI systems that directly interact with natural persons, regardless of whether they are established in the EU or a third country such as the U.S., must inform those persons that they are interacting with AI, unless it is obvious, with these transparency obligations applying from 2 August 2026. Any deployment that reaches EU residents should be reviewed against the EU AI Act’s transparency requirements. This playbook focuses on U.S. federal and state law. Operators with international call programs should consult counsel familiar with the applicable jurisdiction.

Do I Really Need to Disclose? Common Questions

What happens if I do not disclose? The TCPA penalties discussed earlier apply on a per-call basis. State penalties under California’s B.O.T. Act reach $2,500 per violation, and Colorado’s Chatbot Safety Act carries up to $20,000 per violation with no aggregate cap.

Does disclosure hurt connect rates? An industry survey found that 55% of consumers react negatively when AI identifies itself on a call, with 22% hanging up immediately. A field experiment published in INFORMS Marketing Science found that upfront disclosure of AI involvement reduces purchase rates by up to 79.7%. The financial exposure from non-disclosure, including per-call statutory damages with no cap and class-action risk, is a material business risk that operators must weigh against conversion considerations.

Is it enough to say “This is an AI call”? A bare statement without business identification may not satisfy TCPA requirements. 47 CFR § 64.1200(a)(7)(i) requires disclosure of the business name and a contact telephone number. State laws add further requirements. Operators should review the specific disclosure elements required under each applicable statute with qualified counsel.

Compliance Checklist for AI Voice Agents

The following checklist describes the operational steps operators typically address when deploying AI voice agents, in the order they usually occur. It is a starting framework, not a substitute for legal review.

  1. Identify whether each call program is marketing or informational, and apply the appropriate consent standard.
  2. Obtain prior express written consent for outbound marketing calls before dialing.
  3. Add a clear AI disclosure at the start of every AI-led conversation, within the first 10 to 30 seconds.
  4. Include the business name and a contact telephone number in every disclosure.
  5. Honor do-not-call requests immediately and suppress opted-out numbers from all future campaigns.
  6. Check state laws for every state into which calls are placed, including recording-consent requirements.
  7. Record and store consent records with timestamps, collection method, and authorized phone number.
  8. Configure the AI to handle opt-out requests and route escalations to a human agent when required.
  9. Review FCC, FTC, and state regulatory updates on a regular schedule, as this area is evolving rapidly.

How Plura AI Supports AI Voice Compliance Operations

Once the checklist is in place, the next decision is choosing infrastructure that supports these obligations. Plura AI is an FCC-licensed carrier that owns its audio bridging infrastructure. Voice originates on Plura’s domestic carrier stack rather than a third-party CPaaS (Communications Platform as a Service). This means branded caller ID is issued at the carrier level, STIR/SHAKEN authentication runs on every outbound call, and compliance enforcement happens before the call leaves the network.

Many Twilio-based API resellers cannot issue branded caller ID under their own carrier identity or enforce real-time DNC scrubbing at the carrier level, because they do not own the carrier.4 Plura’s compliance engine is a first-class layer of the platform. Every outbound contact is checked against federal and state DNC registries in real time before dial, TCPA consent records are timestamped and immutable, and quiet-hours rules enforce automatically through time-zone detection. The platform supports SOC 2, HIPAA, ISO certification, GDPR, STIR/SHAKEN caller ID verification, TCPA compliance, and DNC compliance.1 Plura provides the infrastructure and tools to support compliance. Operators remain responsible for their own regulatory obligations and the specific consent and disclosure practices they implement.

Plura Security & Compliance dashboard highlighting SOC 2, ISO, and GDPR standards with secure trust verification management.
Plura Security & Compliance supports SOC 2, ISO, and GDPR standards with trust registration, verification management, and secure AI communications.

Plura’s AI voice agent platform includes pre-loaded TCPA, DNC, and state rule sets, immutable consent logging, and one-click audit-ready exports. The no-code workflow builder lets operators configure disclosure scripts, opt-out handling, and escalation paths without engineering resources. Every conversation is logged to a stateful database, so transcripts and consent records are available for audit review. See plans and rates or explore the AI voice demo to understand how the platform is structured.

Book a live demo with Plura to walk through how the compliance engine, disclosure scripts, and consent logging work in a live deployment.

Conclusion and Next Steps

AI voice agent disclosure requirements already shape how outbound and inbound programs operate. The FCC’s 2024 declaratory ruling brought AI-generated voices under the TCPA’s artificial-voice framework, and state laws in California, Colorado, Texas, Tennessee, and others have added independent disclosure mandates with their own penalty structures. The regulatory environment is expanding. A 2027 trend toward mandatory disclosure when a customer is interacting with AI, traceable decision logs on any AI action involving money or regulated topics, and explicit human-in-the-loop requirements for high-stakes intents is already visible in EU AI Act requirements and U.S. state-level customer-disclosure laws.5

Operators deploying AI voice agents at scale should review their current call programs against the federal and state frameworks described here, implement clear disclosure scripts that satisfy the strictest applicable state standard, establish audit-ready consent records, and consult qualified telecom counsel for guidance specific to their deployments and target states. The market for AI voice agents is growing rapidly. Grand View Research estimates the global AI voice agents market at USD 3.51 billion in 2026, projected to reach USD 35.24 billion by 2033.3 Operators who build disclosure and consent infrastructure now are better positioned as enforcement activity increases.

Ready to deploy AI voice agents that disclose properly and stay audit-ready? Book a live demo with Plura today.

Frequently Asked Questions

Does the TCPA apply to AI voice agents the same way it applies to traditional robocalls?

The FCC’s February 2024 declaratory ruling confirmed that AI-generated voices qualify as “artificial or prerecorded voices” under the TCPA, meaning the same consent and disclosure framework that applies to traditional robocalls applies to AI voice agents. The regulation focuses on the use of an artificial voice rather than the specific technology generating it, so a conversational AI that sounds natural is treated the same as a static prerecorded message for TCPA purposes. Prior express consent is required for outbound calls to wireless numbers using an AI voice, and prior express written consent is required for outbound marketing calls. Each individual call counts as a separate potential violation, so operators running high-volume outbound programs face exposure that scales with call volume. Operators should consult qualified telecom counsel to understand how the TCPA applies to their specific call programs.

What is the difference between California’s AB 2905 and the B.O.T. Act, and which applies to my AI voice agent?

California has two distinct AI disclosure frameworks that can apply to voice agent deployments. AB 2905, which amended Public Utilities Code § 2874 effective September 2024, specifically governs outbound automatic dialing-announcing device calls. It requires that before the automated message plays, a natural, unrecorded human voice must announce the nature of the call, the business name, address, and phone number, and must disclose that the message uses an artificial voice and ask for consent. A synthesized AI voice reading this disclosure does not satisfy the statute. The B.O.T. Act, codified at Business and Professions Code §§ 17940-17943 and in effect since July 2019, is broader. It prohibits using any bot to communicate with a California person with intent to mislead about its artificial identity in order to incentivize a purchase or influence a vote, without clear and conspicuous disclosure. An AI voice agent used for outbound sales calls could implicate both statutes simultaneously. Operators calling California numbers should review both frameworks with qualified counsel before deployment.

What constitutes valid prior express written consent for outbound AI voice marketing calls?

Under 47 CFR § 64.1200(f)(9), prior express written consent for outbound marketing calls using an artificial or prerecorded voice requires a written agreement bearing the consumer’s signature that clearly authorizes the seller to deliver marketing messages via autodialer or prerecorded voice to a specific phone number, and that states consent is not a condition of purchasing goods or services. Electronic signatures recognized under the E-SIGN Act satisfy the signature requirement, so a properly disclosed web form checkbox can constitute valid consent. The disclosure shown to the consumer at the time of consent must be clear and conspicuous, meaning a reasonable consumer would understand exactly what they are agreeing to. Organizations sending both informational and marketing messages must maintain separate consent records for each purpose, because the consent type required differs by call purpose. Consent must be revocable, and opt-out requests must be honored immediately. Operators should retain the exact disclosure language shown, a timestamp of consent, the collection method, and the authorized phone number, along with a version history if the disclosure text changes over time.

How does Colorado’s Chatbot Safety Act differ from the TCPA, and when does it take effect?

Colorado’s Chatbot Safety Act, signed into law on May 29, 2026, and taking effect January 1, 2027, is a standalone state statute that operates independently of the TCPA. Where the TCPA focuses on the technology used to place calls and the consent required before placing them, the Chatbot Safety Act focuses on transparency during the interaction itself. It requires operators of publicly accessible conversational AI services to clearly and conspicuously disclose that users are interacting with AI rather than a human. The law also imposes operational duties around age estimation, content controls for minors, and self-harm response protocols. Violations are enforced as deceptive trade practices under the Colorado Consumer Protection Act, with civil penalties of up to $20,000 per violation and no statutory cap on aggregate liability, because each affected consumer or transaction counts as a separate violation. There is no private right of action; enforcement is exclusively by the Colorado Attorney General. The Colorado Attorney General was conducting pre-rulemaking public comment as of mid-2026, and operators should monitor that rulemaking for specific disclosure requirements before the January 1, 2027 effective date.

What records should operators maintain to demonstrate compliance with AI voice agent disclosure requirements?

Audit-ready compliance records for AI voice agent deployments typically include several categories of documentation. For consent, operators should retain the exact disclosure language shown to the consumer at the time of consent, a timestamp of when consent was given, the collection method such as a web form or signed agreement, the authorized phone number, and a version history if the disclosure text changes over time. For each call, operators should retain a transcript or audio recording that captures the disclosure statement, the timestamp of when the disclosure was delivered relative to the start of the call, and the agent version used. For do-not-call compliance, operators should maintain records of DNC scrubbing runs, internal suppression list updates, and the date and method of each opt-out request received. For state-specific requirements, operators should document which state laws were reviewed for each call program and how the program was configured to satisfy the strictest applicable standard. Plura’s compliance engine generates timestamped, immutable consent records and supports one-click audit-ready exports, which operators can use as part of their broader compliance documentation program. Operators should consult qualified counsel to determine the specific record-retention periods and formats required under applicable federal and state law.


1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.

2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.

3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.

4 References to third-party products, services, companies, or research are made for informational and comparative purposes only. Plura AI is not affiliated with, endorsed by, or sponsored by any third party named in this article unless explicitly stated. Trademarks and product names referenced remain the property of their respective owners.

5 This article contains forward-looking statements regarding industry trends, technology adoption, and future capabilities. These statements reflect current expectations and are subject to change. Plura AI undertakes no obligation to update forward-looking statements except as required.

This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.

This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.

Read Next

See how Plura AI transforms AI voice agents