Written by: Matt Beucler, CEO, Plura AI
Key Takeaways
- S.2666, the Foreign Robocall Elimination Act, cleared the Senate Commerce Committee on June 1, 2026 and now sits on the Senate Legislative Calendar awaiting a floor vote.2
- The bill, together with the FCC NPRM in CG Docket No. 26-52, targets foreign-originated robocalls by requiring consumer-facing identification and stricter STIR/SHAKEN authentication at the carrier level.2
- Contact-center operators now face overlapping federal and state mandates that penalize foreign infrastructure and third-party CPaaS dependencies.
- Platforms built on domestic, FCC-licensed carriers with A-level STIR/SHAKEN attestations at origination address the new requirements through architecture rather than paperwork.
- Plura AI delivers a 100% U.S.-infrastructure solution that aligns with these mandates; book a live demo to see how it works.
The Problem: New Robocall Rules Hitting U.S. Contact Centers
U.S. contact-center operators now manage a stack of federal and state mandates that did not exist three years ago. S.2666 directs the FCC to establish a taskforce on unlawful robocalls that consults with the FTC and Attorney General.
On top of S.2666 sits the FCC NPRM in CG Docket No. 26-52, which proposes that voice service providers help consumers identify calls that originate outside the United States and restrict spoofing of U.S. numbers on foreign-originated calls. State-level onshoring laws in New York, New Jersey, Connecticut, Missouri, and Florida add penalties and disclosure obligations that sit alongside the federal rules.
| Date | Event |
|---|---|
| April 23, 2026 | FCC NPRM in CG Docket No. 26-52 published in Federal Register |
| June 1, 2026 | S.2666 reported out of Senate Commerce Committee with amendment; placed on Senate Legislative Calendar |
| June 2026 | H.R.6152 (House companion) remains in committee; no floor vote scheduled |
| TBD | Senate floor vote on S.2666; FCC final rule on CG Docket No. 26-52 |
Core Requirements in the Foreign Robocall Elimination Act
S.2666 directs the FCC to establish a taskforce on unlawful robocalls that consults with the FTC and Attorney General. Operators whose call traffic cannot be traced to a domestic origination point face heightened scrutiny under this framework.
Platforms built on domestic infrastructure reduce this scrutiny at the architectural level because origination, attestation, and records all sit with a U.S. carrier. Book a live demo with Plura to see how a 100% U.S.-infrastructure platform addresses these requirements by architecture.
How S.2666 Builds on the TRACED Act
The Telephone Robocall Abuse Criminal Enforcement and Deterrence (TRACED) Act, enacted in 2019, required the FCC to establish a caller ID authentication framework and directed the FCC to require voice providers to implement it. S.2666 builds on that foundation but focuses on a gap the TRACED Act did not close: foreign call origination.
| Provision | TRACED Act (Existing FCC Rules) | S.2666 (Proposed) |
|---|---|---|
| Caller ID authentication | STIR/SHAKEN required for IP-based voice networks | Extends authentication obligations and focuses on foreign-originated calls |
| Foreign call identification | Not explicitly required under TRACED Act | Requires consumer-facing identification of foreign-originated calls |
Current Status and Likely Path for S.2666
S.2666 has cleared the Senate Commerce Committee and sits on the Senate Legislative Calendar, which means it is eligible for a floor vote but has not yet been scheduled for one. The House companion bill, H.R.6152, remains in committee with no reported markup date. Bicameral passage requires both chambers to pass identical or reconciled text before the bill reaches the President’s desk.
The Senate Legislative Calendar placement represents a meaningful procedural step. Bills that reach this stage have cleared committee review and are available for floor consideration, but floor scheduling is controlled by Senate leadership and depends on competing legislative priorities. Operators should consult qualified counsel on their specific exposure and monitor Congress.gov for scheduling updates.
How S.2666 and the FCC NPRM Work Together
The FCC NPRM in CG Docket No. 26-52 and S.2666 address overlapping problems through parallel tracks. The NPRM focuses on carrier-level technical requirements so consumers can recognize foreign-originated calls and so providers restrict spoofing of U.S. numbers on those calls. S.2666 pursues the same foreign-origination problem through a task-force and enforcement framework.
The practical overlap for contact-center operators sits in the STIR/SHAKEN layer. The NPRM proposes enhancements to the existing STIR/SHAKEN framework, including requirements for terminating providers to transmit verified caller identity information when A-level attestations are indicated. This creates documentation obligations for authentication at the call level and origination at the provider level.
Operators that use foreign infrastructure or third-party carriers that cannot produce A-level STIR/SHAKEN attestations face exposure under both the NPRM and S.2666 at the same time. The domestic-handling concepts in the broader CG Docket No. 26-52 framework, which also discusses offshore customer-service call caps and sensitive-data handling, increase this exposure for any operator whose voice traffic touches foreign infrastructure at any point in the call path.
Infrastructure Approach: Meeting New Robocall Mandates
The structural response to task-force requirements starts with infrastructure, not a compliance add-on. An operator whose voice traffic originates on a domestic, FCC-licensed carrier with STIR/SHAKEN authentication at the origination point addresses the authentication layer of both the NPRM and S.2666 through architecture rather than paperwork.
Most AI voice platforms on the market today act as API resellers built on top of third-party Communications Platform as a Service (CPaaS) providers. They do not own the carrier, cannot issue A-level STIR/SHAKEN attestations at origination, and cannot produce the origination documentation S.2666 would reference because the origination record sits with the underlying carrier, not with them. When the regulatory environment tightens, those operators face a vendor-change problem on top of a compliance problem.
Plura AI operates as its own FCC-licensed audio bridging carrier. Voice originates on Plura’s domestic infrastructure. The call origination record, the STIR/SHAKEN attestation, and the related documentation all sit with the same entity that operates the platform.
Plura AI Capabilities That Map to S.2666 Exposure
Plura’s architecture addresses the S.2666 and FCC NPRM compliance surface at the carrier level, not as a bolt-on feature. The capabilities below matter for operators evaluating their risk in the current regulatory environment. Customers remain responsible for their own compliance obligations; Plura supports compliance through its infrastructure and tooling.

FCC-licensed carrier status. Plura operates its own FCC-licensed audio bridging carrier. Voice traffic originates on domestic infrastructure, which positions operators to address S.2666 domestic-handling concepts without a third-party carrier dependency.
STIR/SHAKEN caller ID verification. Every outbound voice call authenticates through STIR/SHAKEN at the carrier level. This supports A-level attestation, which is the attestation tier the FCC NPRM in CG Docket No. 26-52 proposes that terminating providers transmit.
100% U.S. infrastructure. Voice origination, model hosting, data storage, and call recording all sit on domestic infrastructure. This reduces the foreign-infrastructure exposure that S.2666’s task force and the NPRM’s foreign-call identification concepts target.
Real-time DNC scrubbing and TCPA support.1 Every outbound contact is checked against federal and state Do Not Call (DNC) registries in real time before dial. Consent records are timestamped and immutable.
Stateful Conversation Database. Every interaction across voice, SMS (Short Message Service), RCS (Rich Communication Services), and webchat is keyed to a customer token and stored in one place. This structure supports the audit-trail documentation that many frameworks reference.
Certifications and standards. Plura supports SOC 2, HIPAA, ISO certification, GDPR, SHAKEN/STIR caller ID verification, TCPA-related controls, and DNC-related controls across its platform.1

Compare plans and rates side by side at plura.ai/pricing.
Practical Compliance Checklist for Contact-Center Leaders
Start with your voice carrier and confirm it can produce A-level STIR/SHAKEN attestations at origination, not just pass-through authentication from a downstream provider. If your current AI voice or contact-center platform routes calls through a third-party CPaaS, that carrier becomes your dependency, so assess whether it can satisfy S.2666-related documentation expectations.
Once you understand your carrier chain, review your provider’s posture with respect to S.2666 and the NPRM. Assess foreign-infrastructure exposure across your full call path, including model hosting, data storage, and call recording, against the FCC NPRM CG Docket No. 26-52 domestic-handling proposals.
Coordinate with qualified counsel to review state-level onshoring obligations in New York, New Jersey, Connecticut, Missouri, and Florida. Verify that your platform maintains immutable, timestamped consent records and can produce audit-ready exports for regulatory inquiries. Continue to monitor Congress.gov for S.2666 floor scheduling and the Federal Register for the FCC’s final rule on CG Docket No. 26-52.
Frequently Asked Questions
What is the current status of the Foreign Robocall Elimination Act?
S.2666 was reported out of the Senate Commerce Committee with amendment and placed on the Senate Legislative Calendar on June 1, 2026. It has not yet received a Senate floor vote. The House companion bill, H.R.6152, remains in committee. Both chambers must pass the bill before it can be signed into law. Operators should monitor Congress.gov for scheduling updates and consult qualified counsel on their specific exposure.
How does S.2666 differ from the TRACED Act?
The TRACED Act, enacted in 2019, required the FCC to establish a caller ID authentication framework and directed the FCC to require voice providers to implement it. S.2666 focuses on foreign call origination, which the TRACED Act did not address directly. It adds a task-force structure that coordinates with the FTC and Attorney General. The two frameworks work together rather than replace each other.
What does the FCC NPRM in CG Docket No. 26-52 propose for foreign-originated calls?
The FCC NPRM proposes that voice service providers help consumers identify calls that originate outside the United States and restrict spoofing of U.S. telephone numbers on those calls. It also proposes enhancements to the STIR/SHAKEN framework, including requirements for terminating providers to transmit verified caller identity information when A-level attestations are indicated. The NPRM and S.2666 address overlapping problems through parallel regulatory tracks. Operators should consult the Federal Register and qualified counsel for the current status of the final rule.
Does using Plura make my contact center compliant with S.2666 or the FCC NPRM?
Plura supports compliance through its infrastructure, including FCC-licensed carrier status, STIR/SHAKEN authentication at origination, 100% U.S. infrastructure, real-time DNC scrubbing, immutable consent records, and support for SOC 2, HIPAA, ISO certification, GDPR, SHAKEN/STIR caller ID verification, and TCPA- and DNC-related controls across the platform. Customers remain responsible for their own compliance obligations, certifications, and the claims they make to their own end users. Plura provides the infrastructure; compliance posture downstream of that remains the customer’s responsibility. Operators should consult qualified counsel to assess their specific obligations under S.2666, the FCC NPRM, and applicable state laws.
What should contact-center operators do now, before S.2666 passes?
An infrastructure audit gives the clearest starting point. Operators should confirm whether their voice carrier can produce A-level STIR/SHAKEN attestations at origination, whether their AI voice platform routes calls through a third-party CPaaS, and whether their full call path, including model hosting and data storage, sits on domestic infrastructure. State-level onshoring obligations in New York, New Jersey, Connecticut, Missouri, and Florida already apply and do not depend on S.2666 passing. Operators should review their current vendor contracts against both the existing state laws and the proposed federal requirements with qualified counsel.
Conclusion: Preparing Your Contact Center for S.2666
The foreign robocall elimination act status as of June 2026 places S.2666 one procedural step from a Senate floor vote, with its House companion still in committee. The FCC NPRM in CG Docket No. 26-52 already sits in the rulemaking pipeline, and state onshoring laws in several states are in effect. The compliance exposure for operators using foreign infrastructure or CPaaS-dependent AI voice platforms exists today, not only in a future scenario.
Plura AI is built for this regulatory environment at the architectural level. As its own FCC-licensed audio bridging carrier running 100% U.S. infrastructure, Plura positions operators to address S.2666 task-force and domestic-handling concepts without a rushed vendor-change cycle when final rules arrive. STIR/SHAKEN authentication runs at origination. Consent records are immutable. The stateful conversation database supports the audit-trail documentation that many frameworks reference.
Operators who wait for S.2666 to pass before auditing their infrastructure may end up making vendor decisions under deadline pressure. Operators who act now can have the right architecture in place before a floor vote occurs.
Compare plans and rates side by side at plura.ai/pricing.
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.