Written by: Matt Beucler, CEO, Plura AI
Updated June 2026
Key Takeaways
- The Foreign Robocall Elimination Act creates a federal interagency taskforce and new requirements for U.S. operators handling international robocalls, including STIR/SHAKEN adoption and Robocall Mitigation Database (RMD) certification rules.2
- Providers must show established domestic operations or face additional conditions before certifying to the Robocall Mitigation Database.
- Traceback participation becomes a central compliance factor, and operators that refuse participation risk appearing on the FCC’s published non-compliant provider list.
- Plura AI’s FCC-licensed carrier, real-time DNC scrubbing, and 100% U.S. infrastructure align with the bill’s three core measures.
- Operators seeking compliant-ready voice infrastructure can get started with Plura AI today to prepare for emerging regulatory standards.
How the Foreign Robocall Elimination Act Fits into the Current Framework
The Foreign Robocall Elimination Act was introduced by Senators Ted Budd (R-N.C.) and Peter Welch (D-Vt.) to reduce unlawful robocalls originating outside the United States. As of June 2026, the Foreign Robocall Elimination Act remains unpassed, though a Senate amendment version was reported on June 1, 2026. The bill builds on the Pallone-Thune TRACED Act and establishes an interagency taskforce on unlawful robocalls.
The companion FCC rulemaking, CG Docket No. 26-52, proposes actions to encourage onshoring of call centers, improve customer service, and address illegal robocalls originating from foreign call centers. Together, the bill and the NPRM (Notice of Proposed Rulemaking) define a regulatory perimeter around foreign-originated voice traffic that U.S. operators should understand before any provisions become enforceable.
Three Core Measures That Affect U.S. Voice Operators
1. Foreign Gateway Provider Restrictions and Taskforce Reporting
The bill directs the FCC, in coordination with the FTC and the Attorney General, to establish an interagency taskforce on unlawful robocalls no later than 270 days after enactment. The taskforce must issue biennial reports to Congress. Each report must compare the volume of suspected unlawful robocalls originating inside versus outside the United States, identify the top foreign source countries, quantify financial losses and identity theft from international robocalls, and evaluate adoption of STIR/SHAKEN (Secure Telephone Identity Revisited / Signature-based Handling of Asserted information using toKENs) standards by foreign providers.
The FCC and the registered consortium are also authorized to publish a list of voice service providers that refuse traceback participation or originate or transmit substantial volumes of unlawful robocalls, and the FCC may take enforcement action based on that published list. For U.S. operators, appearing on that list creates direct enforcement exposure.
2. RMD Certification Requirements and Exemptions
S.2666 directs the FCC to issue rules requiring certain voice service providers to meet specific conditions before certifying to the Robocall Mitigation Database that they are implementing measures to mitigate unlawful robocalls. Under current law, voice service providers must provide annual certifications to the RMD. The bill adds preconditions for certain providers before those certifications can be filed.
Exemptions are available. A provider may qualify for exemption based on criteria such as FCC registration under 47 CFR 64.1195, holding a state public utility commission license, being a listed securities issuer, or otherwise demonstrating bona fide established operations. Providers that cannot demonstrate established domestic operations may face additional requirements as a precondition to RMD certification.

3. Traceback Provisions and Enforcement Exposure
The registered consortium handles receiving, sharing, and publishing traceback information on suspected fraudulent, abusive, or unlawful robocalls.
For U.S. operators, this provision matters in both directions. Registered consortium members participate when sharing traceback data, and providers that refuse to participate in traceback efforts become eligible for the FCC’s published non-compliant provider list.
How the Bill’s Requirements Translate into Infrastructure Decisions
The three measures above, foreign gateway restrictions, RMD certification rules, and traceback participation, are regulatory requirements that translate directly into infrastructure decisions operators control today. Each of the bill’s three measures maps to specific carrier, routing, and data-handling choices U.S. operators make.
Foreign gateway restrictions and STIR/SHAKEN. The FCC’s companion rulemaking in CG Docket No. 26-52 proposes actions to encourage onshoring of call centers, improve customer service, and address illegal robocalls originating from foreign call centers. Plura AI originates every outbound voice call on its own FCC-licensed audio bridging carrier with STIR/SHAKEN caller ID verification at the carrier level, not through a third-party CPaaS (Communications Platform as a Service). Voice traffic does not route through foreign infrastructure. Operators running on Twilio-based API resellers inherit that vendor’s carrier identity and attestation posture.3 Plura controls its own carrier identity and attestation.
RMD certification and established-operator exemptions. The bill’s criteria favor providers that hold FCC registration under 47 CFR 64.1195, state public utility commission licenses, or other indicia of bona fide established operations. Plura holds its own FCC carrier license, which is the registration category referenced in the bill’s exemption criteria. Operators that route voice through unregistered or foreign-infrastructure-dependent intermediaries carry a different risk profile under this provision.
Traceback participation and DNC compliance. Providers that refuse traceback participation face the enforcement exposure described above. Plura’s compliance engine runs real-time DNC scrubbing on every outbound contact, maintains immutable TCPA (Telephone Consumer Protection Act) consent records, and supports audit-ready exports. The platform supports SOC 2, HIPAA, ISO certification, GDPR, SHAKEN/STIR caller ID verification, TCPA compliance, and DNC compliance.1,2 These infrastructure layers position an operator to participate in traceback processes instead of avoiding them.

Compliant vs. Non-Compliant Infrastructure Choices in Practice
The bill’s requirements create a clear split between infrastructure choices that align with its framework and those that do not. The comparison below links each of the bill’s three core measures to the infrastructure characteristics that support or undermine that measure, so operators can see which technical decisions shape compliance posture.
Foreign gateway identification and STIR/SHAKEN adoption by providers. Non-aligned infrastructure routes voice through foreign-infrastructure CPaaS with third-party attestation. Aligned infrastructure uses a domestic FCC-licensed carrier with STIR/SHAKEN at origination. Plura capability: FCC-licensed audio bridging carrier and STIR/SHAKEN caller ID verification on every outbound call.
RMD certification requirements, with exemptions for FCC-registered providers. Non-aligned infrastructure relies on an unregistered intermediary or foreign-dependent provider, so additional requirements may apply. Aligned infrastructure uses an FCC-registered provider that may qualify for exemption under 47 CFR 64.1195. Plura capability: Holds its own FCC carrier license and operates under the FCC registration framework.
Traceback participation, with non-participants eligible for the FCC enforcement list. Non-aligned infrastructure has no audit trail, no real-time DNC scrubbing, and no immutable consent records. Aligned infrastructure has real-time DNC scrubbing, an immutable consent ledger, and audit-ready call records. Plura capability: Real-time DNC scrubbing, TCPA compliance support, immutable consent records, and one-click audit exports.
See how Plura’s compliance infrastructure maps to your operational requirements at plura.ai/pricing.
Operator Action Checklist for Infrastructure and Documentation
The steps below focus on infrastructure and documentation decisions that align with the bill’s three measures. Operators should consult qualified legal counsel regarding their specific obligations under applicable law.
- Audit your voice origination path. Identify whether your outbound voice traffic originates on a domestic FCC-licensed carrier or routes through a third-party CPaaS with foreign infrastructure dependencies. Document the answer in a central compliance file.
- Verify STIR/SHAKEN attestation level. Confirm that your carrier issues A-level STIR/SHAKEN attestation on outbound calls. Third-party resellers often inherit B- or C-level attestation from the underlying carrier, which affects how terminating providers treat your traffic.
- Check your RMD certification status. Confirm that your current Robocall Mitigation Database certification is current and that your provider qualifies for the bond exemption under FCC registration criteria. If your provider cannot confirm FCC registration under 47 CFR 64.1195, evaluate your bond exposure under the bill’s requirements.
- Confirm real-time DNC scrubbing at the platform level. DNC scrubbing that runs as a batch process before a campaign launches functions differently from real-time scrubbing before each dial. Confirm which model your platform uses and document the control.
- Establish an immutable consent record. TCPA consent records should be timestamped, tied to the specific contact, and retrievable for audit. Confirm that your platform produces audit-ready exports on demand and that your team knows how to access them.
- Assess traceback participation readiness. Confirm that your platform retains call detail records in a format compatible with traceback requests from the registered consortium. Providers that cannot respond to traceback requests face the FCC’s published non-compliant provider list.
- Review state onshoring exposure. While the Foreign Robocall Elimination Act is federal legislation, operators must also consider state-level data residency requirements. Five states, New York, New Jersey, Connecticut, Missouri, and Florida, have enacted laws that restrict offshore handling of sensitive consumer data. Confirm that your infrastructure’s data residency posture covers all five states.
- Document your infrastructure posture for legal review. Compile carrier registration documentation, STIR/SHAKEN attestation records, DNC scrubbing logs, and consent records into a single compliance file. Counsel will rely on this file when the bill’s enforcement timeline becomes active.
Frequently Asked Questions
What is the current status of the Foreign Robocall Elimination Act as of June 2026?
As of June 2026, the Foreign Robocall Elimination Act has not been enacted into law. The Senate version is S.2666 and the House companion is H.R.6152. A Senate amendment version was reported on June 1, 2026. The bill has bipartisan sponsorship from Senators Budd and Welch, and its core provisions align with the FCC’s active rulemaking in CG Docket No. 26-52. Operators tracking the bill should monitor Congress.gov for markup and floor vote scheduling. The bill’s taskforce establishment and reporting requirements are both triggered by the date of enactment, so the compliance clock does not start until the bill is signed into law.
Which voice service providers must meet RMD certification requirements?
The bill directs the FCC to issue rules determining which providers must meet certain requirements before filing RMD certification. The bill specifies exemptions for providers that hold FCC registration under 47 CFR 64.1195, hold a state public utility commission license, are listed on a national securities exchange, or otherwise demonstrate bona fide established operations. The practical effect is that providers without domestic regulatory registration or established operational history may face additional requirements. Operators should ask their voice carrier directly whether it qualifies for an exemption under the bill’s criteria and obtain that answer in writing.
What does traceback participation mean for U.S. operators?
The registered consortium shares traceback information on suspected unlawful robocalls, including call detail records and provider identifying information. For U.S. operators, this provision has two practical implications. First, the registered consortium can share information about your traffic. Second, providers that refuse to participate in traceback efforts become eligible for the FCC’s published non-compliant provider list, which the FCC may use as a basis for enforcement action. Maintaining clean call records, real-time DNC scrubbing, and immutable consent documentation positions an operator to respond to traceback requests rather than appear on that list.
How does the Foreign Robocall Elimination Act interact with the FCC NPRM in CG Docket No. 26-52?
The two operate on parallel tracks. The Foreign Robocall Elimination Act is legislation that requires Congressional passage and Presidential signature before it takes effect. CG Docket No. 26-52 is an FCC rulemaking proceeding that the Commission can advance independently under its existing statutory authority. The NPRM proposes actions to encourage onshoring of call centers, improve customer service, and address illegal robocalls originating from foreign call centers. The NPRM shares the bill’s focus on foreign-originated robocalls and call center onshoring. Operators should track both proceedings separately and consult counsel on the specific obligations each imposes once finalized.
Conclusion: Aligning Infrastructure with the Bill’s Direction
The Foreign Robocall Elimination Act establishes a federal interagency taskforce on unlawful robocalls and introduces measures for U.S. voice operators related to foreign-originated robocalls, STIR/SHAKEN adoption, RMD certification for providers that cannot demonstrate established domestic operations, and traceback participation as a condition of staying off the FCC’s published non-compliant provider list. Each requirement maps to a specific infrastructure decision, including carrier registration, STIR/SHAKEN attestation level, real-time DNC scrubbing, and immutable consent records.
Plura AI operates on its own FCC-licensed audio bridging carrier with 100% U.S. infrastructure by architecture, the compliance posture described throughout this article. The platform supports the compliance posture the bill’s measures point toward, without routing voice through foreign-infrastructure intermediaries or third-party CPaaS layers. Customers are responsible for their own regulatory obligations and should consult qualified legal counsel on their specific compliance requirements.
Explore Plura’s compliance-ready voice infrastructure at plura.ai/pricing.
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
3 References to third-party products, services, companies, or research are made for informational and comparative purposes only. Plura AI is not affiliated with, endorsed by, or sponsored by any third party named in this article unless explicitly stated. Trademarks and product names referenced remain the property of their respective owners.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.