Written by: Matt Beucler, CEO, Plura AI
Updated September 2026
Key Takeaways
- S. 2666 introduces a potential $100,000 RMD bond requirement for some voice service providers and grants traceback consortium immunity for publishing suspected unlawful robocall data.
- The bill defines covered providers broadly, including PBXs, cloud platforms, call centers, and any entity using NANP resources for voice communications.
- Gateway providers must ensure foreign-originated traffic carries proper STIR/SHAKEN attestation and remains fully traceable under evolving FCC rules.
- Refusal to cooperate with traceback requests can result in public listing and downstream blocking, which creates significant operational and enforcement exposure.
- Plura AI delivers FCC-licensed carrier infrastructure with built-in STIR/SHAKEN, real-time DNC scrubbing, and RMD filing support.1 See how it streamlines compliance in a live walkthrough.
Which Providers Are Covered by the Foreign Robocall Elimination Act
S. 2666 focuses on voice service providers, the registered traceback consortium, and a new task force that includes industry experts and a traceback consortium representative. The FCC’s July 2026 RMD rulemaking proposes a broad definition of “voice service provider” that reaches PBXs, dialing platforms, cloud service providers, over-the-top service providers, call centers, and value-added-service providers that furnish voice communications using North American Numbering Plan (NANP) resources. If your platform touches a call that uses a U.S. number, review which category applies to your operation.
- Voice Service Providers: Entities that originate or carry foreign-originated traffic. Under S. 2666, these providers may need to post an RMD bond before certifying their mitigation measures. Under existing FCC rules, providers must re-certify their RMD filings annually by March 1, and 47 CFR § 64.6301 separately imposes STIR/SHAKEN authentication obligations.
- Gateway Providers: Domestic providers that accept voice calls directly from a foreign voice service provider before transmitting the call downstream. The FCC’s July 2026 FNPRM defines a gateway provider as a domestic voice service provider that is an intermediate provider accepting calls directly from a foreign voice service provider. Gateway providers must ensure foreign traffic carries appropriate STIR/SHAKEN attestation and is traceable.
- Robocall Analytics and Call-Labeling Providers: Entities that score or label calls. The FCC’s proposed RMD rules would require providers to describe any call analytic systems they utilize, including those operated by a third-party vendor, as part of their robocall mitigation plan. Analytics vendors that share data in traceback investigations fall directly within the bill’s scope.
- Traceback Consortium Participants: Entities involved in tracing illegal calls. The Industry Traceback Group (ITG), the FCC-registered consortium that coordinates traceback requests, is central to S. 2666’s enforcement architecture. Providers in the call path must respond to ITG requests under current FCC rules.
Key terms used throughout this guide: RMD (Robocall Mitigation Database, the FCC’s public registry where providers certify their robocall mitigation measures); STIR/SHAKEN (the technical framework for authenticating caller ID on SIP calls); OCN (Operating Company Number, a unique identifier assigned to telecom providers); TRACED Act (the Pallone-Thune Telephone Robocall Abuse Criminal Enforcement and Deterrence Act, the statute under which the FCC issued orders implementing STIR/SHAKEN in IP voice networks).
Is There a Law Against Robocalls? The Provider Answer
Three federal frameworks form the current enforcement structure for robocall regulation. The Telephone Consumer Protection Act (TCPA), codified at 47 U.S.C. § 227, describes consent requirements and restrictions on autodialed and prerecorded calls.2 The TRACED Act is the statute under which the FCC issued orders implementing STIR/SHAKEN in IP voice networks. S. 2666, if enacted, adds a foreign-traffic-specific layer that includes the RMD bond, the task force, the extended traceback consortium designation, and traceback immunity and publication provisions.2 S. 2666 does not change core TCPA or Telemarketing Sales Rule (TSR) requirements. Obligations related to prior express written consent, Do-Not-Call scrubbing, and accurate caller ID remain unchanged, while the bill changes the enforcement environment around those requirements. Consult the rule text and qualified counsel for guidance on how these frameworks apply to your specific operations.
What the $100,000 RMD Bond Means for Providers
The FCC can require certain voice service providers to post a bond of up to $100,000 before certifying their mitigation measures in the RMD. Under S. 2666, the FCC would issue rules requiring a provider to post a bond of not more than $100,000, as determined by the Commission, before filing an RMD certification, if the Commission determines the bond is necessary to preserve the integrity of the database.
A bona fide provider exemption exists. S. 2666 directs the FCC to establish criteria to exempt providers from the bond requirement where the bond is not necessary to deter unlawful robocall activity. The bill identifies four factors the FCC must consider when determining exemption eligibility:
- FCC registration under 47 CFR 64.1195 and Universal Service Fund (USF) contributions under 47 U.S.C. 254(d)
- Holding a state public utility commission (PUC) certificate of authority, license, or registration
- Being a listed issuer on a national securities exchange
- Otherwise presenting indicia of being a bona fide, established communications service provider
The Congressional Budget Office estimates the number of providers affected by the bond requirement would be small and the likelihood of forfeiture would be low, because the FCC has not yet established the specific exemption conditions and bond terms. Providers that cannot demonstrate legitimate ongoing operations, regulatory oversight sufficient to ensure accountability, or the ability to pay FCC fines are the primary targets of the bond provision. Consult qualified counsel to assess your organization’s exemption eligibility under the criteria S. 2666 directs the FCC to establish.
Traceback Cooperation: What Refusal Actually Triggers
Refusing to cooperate with traceback efforts carries two direct operational consequences under S. 2666. First, the FCC, or the registered traceback consortium in consultation with the FCC, may publish a list of voice service providers that refuse to participate in private-led traceback efforts and providers found to originate or transmit substantial amounts of unlawful robocalls. Public listing functions as a signal to every downstream provider that is required to check the RMD before accepting traffic. A provider on that list faces the practical risk of being cut off from the network.
Second, the FCC may take enforcement action based on that published information. The enforcement record in 2026 illustrates what that means in practice: SK Teleco LLC was removed from the FCC’s Robocall Mitigation Database on June 12, 2026, after repeated failures to respond to traceback requests, and all downstream providers were required to block SK Teleco traffic within 30 days.
S. 2666 also extends the ITG’s designation renewal cycle. Senate Report 119-122 states that S. 2666 would extend the FCC’s designation cycle for the industry-led traceback consortium from annual renewal to once every three years. For vendors and providers that interact with the ITG, a three-year designation cycle reduces the operational uncertainty that came with annual reauthorization. It also means the ITG’s authority and immunity operate on a longer, more stable runway. The FCC’s proposed RMD rules would require providers to certify a commitment to respond within 24 hours to all traceback requests from the Commission, law enforcement, and the industry traceback consortium. That 24-hour window is the practical compliance benchmark a vendor should be able to support.
Who Sits on the S. 2666 Task Force and Why It Matters to Vendors
The S. 2666 task force includes seven private-sector representatives jointly appointed by the FCC Chairman, the FTC Chairman, and the Attorney General. Of the seven private-sector seats, three go to representatives from entities with expertise in combating unlawful robocalls, including voice service providers, analytics providers, technologists, and technology experts. One seat is reserved for a representative of the registered traceback consortium (the ITG). The remaining private-sector seats go to one representative of a marketing business that communicates with consumers by telephone, one representative of a business or nonprofit that regularly communicates with consumers by telephone for non-marketing purposes, and one representative of a customer-advocacy organization with relevant experience in combating unlawful robocalls.
The task force has 360 days after establishment to report to Congress, then sunsets 90 days after that report. The task force’s mandate covers foreign call origination points, promoting STIR/SHAKEN adoption abroad, creating a dedicated DOJ enforcement body, and potential criminal penalties. For vendors, the task force’s composition matters because it includes the provider categories most likely to face new technical and legal obligations based on the task force’s recommendations. A task force that includes analytics providers and technologists alongside telemarketing businesses and consumer advocates is structured to produce recommendations that affect the full call chain. Vendors that cannot document their STIR/SHAKEN implementation, traceback cooperation posture, and RMD filing status will be poorly positioned when those recommendations translate into FCC rulemaking.
What to Verify in a Robocall Mitigation Vendor
Vendor selection now ties directly to how your organization supports RMD filings and traceback expectations. Verify a vendor’s capabilities across six dimensions before a contract renewal or new engagement:
- Foreign-call blocking
- STIR/SHAKEN authentication
- Robocall analytics
- Call authentication and attestation decisions
- Traceback support
- RMD filing support and documentation
The FCC’s proposed RMD rules would require providers to describe any call analytic systems they use, including third-party vendors, as part of their mitigation plan. A vendor that cannot document its own RMD status, OCN registration, and STIR/SHAKEN implementation creates a gap in your mitigation plan that the FCC can scrutinize. Explore these capabilities in action with a Plura AI session.

Plura AI operates as its own FCC-licensed audio bridging carrier, which means it holds its own OCN and runs STIR/SHAKEN authentication on every outbound call. Because it controls the carrier layer, it can issue branded caller ID at the carrier level. It also enforces real-time DNC scrubbing, TCPA-litigator screening, automated quiet hours, and immutable consent logging on every outbound contact. Plura originates voice on its own carrier infrastructure rather than routing through a third-party Communications Platform as a Service (CPaaS). As a result, STIR/SHAKEN attestation decisions are made at the carrier level instead of being delegated to a reseller. That distinction matters for RMD certification accuracy: A-level attestation calls receive the best treatment from analytics providers that power “Spam Likely” labels on major carrier handsets, while C-level calls are far more likely to be labeled or blocked. Plura’s AI Predictive Dialer runs on that same carrier foundation, with branded caller ID and STIR/SHAKEN on every dial.

Twilio-based API resellers occupy a different position.3 They rent the carrier layer from a third-party CPaaS, which means caller ID is not issued under their own carrier identity and STIR/SHAKEN attestation decisions pass through the CPaaS’s infrastructure rather than the vendor’s own. For providers evaluating vendors against S. 2666 obligations, the key question is whether the vendor holds its own FCC carrier license and OCN or routes through a third party. The answer determines whether the vendor can support your RMD certification with its own documented STIR/SHAKEN implementation or whether it depends on a reseller’s filing. To compare these two models side by side, see the breakdown at plura.ai/compare.
Plura’s compliance engine supports TCPA compliance, DNC compliance, HIPAA, SOC 2, and STIR/SHAKEN caller ID verification as first-class platform layers.1 Every outbound contact is checked against federal and state DNC registries in real time before dial. Consent records are timestamped, immutable, and audit-ready. The platform’s managed workflows enforce quiet-hours rules automatically through time-zone detection. Plura’s compliance dashboard surfaces audit-ready exports in one click for legal review or carrier requirements.

Current Status and What Happens Next
S. 2666 passed the Senate by unanimous consent on August 3, 2026. As of August 10, 2026, the bill was held at the desk in the House, meaning it has been received but not yet acted upon. A companion bill, H.R. 6152, was forwarded by subcommittee to the full House committee by voice vote on September 1, 2026. The compliance timeline depends on House passage and presidential signature, followed by FCC rulemaking to establish the bond conditions, exemption criteria, and task force formation timeline. The FCC must establish the task force no later than 270 days after enactment. Providers should consult qualified counsel on their specific obligations and monitor FCC docket activity in WC Docket No. 17-97 and CG Docket No. 17-59 for implementation rules as they develop.
Conclusion: Mapping S. 2666 Obligations to a Vendor Decision
S. 2666 creates a specific, provider-type-mapped compliance structure. Voice service providers face the RMD bond and annual certification obligations. Gateway providers must ensure foreign traffic is authenticated and traceable. Analytics vendors must document their systems in mitigation plans. Every provider in the call path faces a 24-hour traceback response window with public listing and enforcement exposure for refusal. The task force’s mandate to evaluate criminal penalties and a dedicated DOJ enforcement body signals that the enforcement posture around these obligations will intensify after the report reaches Congress.
Plura AI gives providers an FCC-licensed carrier option with verifiable STIR/SHAKEN authentication, in-platform DNC scrubbing, and a documented carrier identity that supports RMD certifications. Its AI voice agent infrastructure runs on Plura’s own carrier stack, with STIR/SHAKEN on every outbound call and real-time compliance enforcement before each contact. Compare plans and rates side by side. Run your numbers through Plura’s ROI calculator to check your ROI in real time. Schedule a tailored walkthrough with Plura.
Frequently Asked Questions
Does S. 2666 Apply to My Company If We Only Use a Third-Party Dialing Platform?
The FCC’s proposed definition of “voice service provider” is broad. It covers any entity that provides voice service for a given call, including dialing platforms, cloud service providers, over-the-top service providers, and call centers that furnish voice communications using North American Numbering Plan resources. An entity does not need to provide service directly to end users to fall within the proposed definition. If your operation uses a dialing platform that originates calls on U.S. numbers, your organization may have RMD filing obligations independent of the platform vendor’s own filing. The FCC has also proposed that parents, affiliates, and subsidiaries that independently meet the definition of a voice service provider must each file a separate RMD certification. Review the proposed definition in FCC 26-49 and consult qualified counsel to determine whether your specific operation triggers a filing obligation.
What Is the Difference Between the RMD Bond in S. 2666 and Existing RMD Filing Requirements?
Under existing FCC rules, voice service providers must certify annually to the Robocall Mitigation Database that they are implementing measures to mitigate unlawful robocalls. That certification must be signed by a company officer under penalty of perjury. S. 2666 adds a bond requirement on top of that certification process. The FCC would have authority to require certain providers to post a bond before filing their RMD certification if the Commission determines the bond is necessary to preserve the integrity of the database. The bond supplements the certification as a financial assurance mechanism for providers the FCC determines cannot demonstrate legitimate ongoing operations or regulatory accountability. Providers that meet the bona fide exemption criteria, including FCC registration, USF contributions, a state PUC certificate, or listing on a national securities exchange, may be exempt from the bond requirement under criteria the FCC will establish through rulemaking after enactment.
What Happens to a Provider That Is Listed on the S. 2666 Traceback Refusal List?
S. 2666 authorizes the FCC, or the registered traceback consortium in consultation with the FCC, to publish a list of providers that refuse to participate in private-led traceback efforts or that originate or transmit substantial amounts of unlawful robocalls. The FCC may then take enforcement action based on that published information. The operational consequence of public listing is significant independent of formal enforcement. Downstream providers are required under FCC rules to check the RMD and block traffic from providers whose filings have been removed. A provider on the refusal list signals to every downstream carrier that accepting its traffic carries compliance risk. The 2026 enforcement record shows the FCC has used RMD removal and downstream blocking orders as active tools. Providers should treat the traceback response window as a hard operational requirement and verify that their vendor infrastructure can support it.
How Does STIR/SHAKEN Attestation Level Affect a Provider’s Exposure Under S. 2666?
STIR/SHAKEN assigns one of three attestation levels to each call: A-level (Full), where the provider knows the customer and that they are authorized to use the number; B-level (Partial), where the provider knows the customer but cannot verify the number belongs to them; and C-level (Gateway), where the provider only knows the call entered the network at a certain point. A-level attestation calls receive the most favorable treatment from call analytics systems that power spam labels on major carrier handsets. C-level calls are more likely to be labeled or blocked. Under S. 2666 and the FCC’s parallel KYUP and RMD rulemakings, the accuracy of attestation decisions is now a compliance obligation as well as a call-quality factor. The FCC has proposed prohibiting providers from assigning a higher attestation level than permissible under STIR/SHAKEN standards. For providers evaluating vendors, the key question is whether the vendor makes attestation-level decisions on its own carrier infrastructure or delegates those decisions to a third-party CPaaS. Consult the rule text at 47 CFR § 64.6301 and qualified counsel for guidance on your specific attestation obligations.
What Should a Provider Ask a Robocall Mitigation Vendor Before Signing a Contract?
Six questions cover the core capability gaps that S. 2666 and the FCC’s parallel rulemakings make operationally relevant. First, does the vendor hold its own FCC carrier license and OCN, or does it route through a third-party CPaaS? Second, does the vendor run STIR/SHAKEN authentication on its own infrastructure, and at what attestation level? Third, is the vendor’s own RMD filing current, and can it provide documentation? Fourth, does the vendor support timely traceback response, and does it have a documented process for responding to ITG requests? Fifth, does the vendor enforce real-time DNC scrubbing before each outbound contact, and does it maintain immutable consent records? Sixth, can the vendor describe any call analytic systems it uses, including third-party vendors, in a format suitable for inclusion in your robocall mitigation plan? A vendor that cannot answer all six questions with documented evidence creates gaps in your mitigation plan that the FCC can scrutinize during an RMD review or enforcement action. Direct these questions to any vendor under consideration, and verify the answers against the vendor’s public RMD filing before contract execution.
1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.
2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.
3 References to third-party products, services, companies, or research are made for informational and comparative purposes only. Plura AI is not affiliated with, endorsed by, or sponsored by any third party named in this article unless explicitly stated. Trademarks and product names referenced remain the property of their respective owners.
This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.
This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.