What Is TCPA Compliance? Key Rules for Calls and Texts

ON THIS PAGE

Written by: Matt Beucler, CEO, Plura AI

Key TCPA Takeaways for AI Voice and SMS

  • TCPA compliance requires prior express written consent for marketing calls or texts to wireless numbers using ATDS or artificial voice, including AI-generated voice.
  • Core requirements include consent documentation, DNC scrubbing within 31 days, time-of-day controls, opt-out handling within 10 business days, and abandonment rates below 3%.
  • AI-generated voice calls follow the same consent standards as traditional prerecorded robocalls under the FCC’s February 2024 Declaratory Ruling.
  • Violations carry statutory damages of $500 to $1,500 per call or text with no aggregate cap, which creates significant class-action exposure in 2026.3
  • Plura AI’s FCC-licensed carrier stack supports TCPA compliance at the infrastructure layer, learn more about Plura AI.

Core TCPA Requirements for High-Volume Outreach

The Telephone Consumer Protection Act (TCPA), codified at 47 U.S.C. § 227, sets the floor for outbound voice and text contact in the United States.2 The FCC implements and enforces the statute through regulations at 47 C.F.R. § 64.1200. These rules apply directly to high-volume outbound operations.

Consent tiers. Marketing or promotional calls and texts to wireless numbers using an ATDS or artificial or prerecorded voice require prior express written consent (PEWC). PEWC must be a signed or electronically signed agreement that names the specific business, describes the message types, states that message and data rates may apply, and confirms consent is not a condition of purchase. For purely informational or transactional contacts, prior express consent (PEC) may suffice, and written consent remains the more defensible standard.

One-to-one consent standard. The FCC’s December 2023 Report and Order (FCC 23-107) introduced a one-to-one consent rule requiring that written consent authorize calls from one specific seller only. The Eleventh Circuit vacated that rule in Insurance Marketing Coalition Ltd. v. FCC, 127 F.4th 303 (11th Cir. 2025). The Fifth Circuit’s February 2026 Bradford decision rejected the FCC’s prior-express-written-consent requirement under 47 C.F.R. § 64.1200(f)(9) for TCPA calls, holding that only prior express consent (oral or written) is required. Some states enforce one-to-one-style requirements independently, so operators should consult counsel on the applicable standard for their campaigns.

DNC scrubbing. Telemarketers must scrub calling lists against the National Do Not Call Registry no more than 31 days before each campaign under 47 C.F.R. § 64.1200(c)(2). Companies must also maintain an internal DNC list and honor opt-out requests within 10 business days.

Time-of-day restrictions. Telemarketing calls and texts are permitted only between 8:00 a.m. and 9:00 p.m. in the called party’s local time zone. Several states impose stricter windows: Florida and Oklahoma limit calls to 8:00 a.m. to 9:00 p.m.; Connecticut restricts calls to 9:00 a.m. to 8:00 p.m. Dialers must enforce recipient local time, not server time.

Opt-out mechanics. Under 47 C.F.R. § 64.1200(a)(10), consumers may revoke consent through any reasonable means, including replying STOP, QUIT, CANCEL, or UNSUBSCRIBE to a text, or stating verbally that they wish to stop receiving calls. The FCC’s April 2025 Consent Revocation Rule addresses revocation, with immediate suppression recommended for automated systems.

AI-generated voice. The FCC’s February 8, 2024 Declaratory Ruling established that AI-generated voices, including real-time conversational AI and voice cloning, qualify as “artificial or prerecorded voice” under the TCPA.2 No carve-out exists for technologies that sound like live agents. This ruling is directly relevant to operators evaluating AI voice platforms. The FCC is also advancing rulemaking under CG Docket No. 26-52, which proposes additional consumer protections for AI-generated communications.

Book a live demo with Plura to see how carrier-level enforcement handles consent, DNC scrubbing, and calling-window restrictions automatically before each outbound contact.

Five High-Risk TCPA Violation Categories

The following violation types generate the highest litigation volume in 2026. Each represents a distinct liability vector with per-contact damages and no aggregate cap. These five categories account for most TCPA class actions in 2025–2026, with consent failures and opt-out mishandling driving the largest settlements.

  1. Contacting without valid prior express written consent. Sending marketing texts or placing AI voice calls to wireless numbers without documented PEWC is the most common path to class-action exposure. Purchased phone lists almost never satisfy TCPA requirements because the original consent was not given to the specific sender. In Campbell v. Sirius XM Radio Inc., No. 2:22-cv-2261 (C.D. Ill.), SiriusXM agreed to a $28 million TCPA settlement fund over alleged calls to numbers on the National DNC Registry and after stop requests, with more than 427,000 claims filed by April 2026.
  2. Failing to honor opt-out requests. The single most common factual allegation in TCPA text cases is a consumer replying STOP and the platform failing to suppress the number, which results in continued texts that courts often treat as willful violations at the $1,500-per-text tier. Opt-outs must be suppressed company-wide, not just within a single campaign.
  3. Calling numbers on the National DNC Registry without a valid exception. Scrubbing lists with data older than 31 days provides no safe harbor. DNC Registry violations create potential liability of up to $51,744 per violation under the FTC’s Telemarketing Sales Rule, separate from TCPA per-call damages.
  4. Exceeding the 3% abandoned-call threshold. Predictive dialers must not exceed a 3% abandoned-call rate per campaign over any 30-day period, where an abandoned call is defined as a live answer with no agent connected within 2 seconds of the recipient’s completed greeting. Most predictive dialers on B2B mobile-heavy lists in 2026 produce 5–15% abandoned-call rates in practice, which creates systematic exposure.
  5. Contacting outside permitted calling hours. Dialing before 8:00 a.m. or after 9:00 p.m. in the recipient’s local time zone constitutes an independent violation. Reassigned-number liability compounds this: a consented contact who abandons a mobile number that is later recycled to a new subscriber can expose the caller to violations even when the original consent was valid. In Jackson v. Gen Digital Incorporated, No. 2:25-cv-00535 (D. Ariz.), Gen Digital agreed to a $9.95 million TCPA settlement in 2026 over artificial or prerecorded voice calls to non-customers.

TCPA Rules That Shape AI Dialer Deployments

The FCC’s February 2024 Declaratory Ruling clarified that AI-generated voice calls qualify as “artificial voice” calls under the TCPA. Operators running an AI predictive dialer must apply the same prior express written consent standard used for traditional prerecorded robocall campaigns. No AI-specific exemption exists.

Plura Predictive Dialer dashboard displaying AI-powered outbound call pacing, transfer analysis, and dialing performance insights.
Plura Predictive Dialer automates outbound calling with AI-powered pacing, transfer optimization, and real-time performance analytics.

Four requirements apply specifically to AI dialer deployments.

Plura’s AI Predictive Dialer runs on Plura’s own FCC-licensed carrier. Branded caller ID is issued at the carrier level, not bolted on through a third-party CPaaS (Communications Platform as a Service). Real-time DNC scrubbing, including integration with The Blacklist Alliance’s TCPA Litigation Firewall® for real-time TCPA litigator and DNC screening, operates before each dial. Calling-window restrictions enforce automatically through time-zone detection. Operators should consult counsel to confirm their specific consent documentation and campaign configuration meet applicable requirements.

The same framework applies to AI SMS platforms. The FCC treats text messages as calls under the TCPA, so automated SMS campaigns require the same PEWC, DNC scrubbing, and opt-out handling as voice campaigns. All A2P SMS campaigns using 10-digit long codes must complete 10DLC brand and campaign registration with The Campaign Registry (TCR); unregistered traffic has been blocked by carriers since February 2025.4

Plura SMS interface showing AI-powered business text messaging, automated customer conversations, and personalized engagement workflows.
Plura SMS enables personalized AI-powered text messaging with real-time customer engagement, automation, and conversational workflows.

Book a live demo with Plura to see how the AI Predictive Dialer and AI SMS platform handle consent verification, DNC scrubbing, and abandonment-rate enforcement at the carrier level.

TCPA Penalties and Recent Enforcement Trends

TCPA statutory damages range from $500 to $1,500 per text or call. Courts may award $500 per violation for negligent conduct and treble that amount to $1,500 per violation upon a finding of willful or knowing conduct under 47 U.S.C. § 227(b)(3). No aggregate cap exists on total damages in class actions.

Exposure scales quickly at volume. A campaign of 100,000 messages sent without proper consent could result in exposure exceeding $150 million in a class action.3 Class actions filed through mid-2025 were up nearly 95% year-over-year.

Recent settlements illustrate the scale of exposure:

Beyond statutory damages, The FCC proposed a $6 million fine in May 2024 against Steve Kramer for illegal robocalls using deepfake AI voice technology in the New Hampshire primary. State mini-TCPA laws add a parallel layer: Connecticut imposes penalties up to $20,000 per violation for illegal telemarketing calls or texts, and DNC Registry violations create potential liability of up to $51,744 per violation under federal or state enforcement of the TSR.

Seven-Step TCPA Compliance Checklist

The following 7-step checklist reflects the regulatory framework described above and keeps each step tied directly to what the regulation states. Because the checklist tracks regulatory language closely, it is suitable for legal review, but it does not constitute legal advice. Operators should confirm their specific implementation with qualified counsel.

  1. Document prior express written consent before first contact. PEWC must be a signed or electronically signed agreement naming the specific company, authorizing autodialed or prerecorded marketing calls or texts to a particular number, disclosing that consent is not a condition of purchase, and captured with timestamp, IP address, source URL, and exact disclosure language. Consent records must be retained for at least five years to defend against the four-year TCPA statute of limitations.
  2. Scrub against the National DNC Registry and internal DNC list no more than 31 days before each campaign. Lists must be current within 31 days under 47 C.F.R. § 64.1200(c)(2). For high-volume operations, real-time DNC scrubbing at the moment of dial is the defensible standard. Also scrub against the FCC Reassigned Numbers Database (RND) to identify recycled numbers where original consent no longer applies.
  3. Enforce calling-window restrictions by recipient local time. Enforce the federal 8:00 a.m. to 9:00 p.m. calling window described earlier, using real-time number intelligence rather than area code alone to determine local time. Apply the stricter state windows where applicable.
  4. Maintain an immutable consent ledger with audit-ready exports. Every consent record, opt-out log, scrub result, and contact attempt must be stored in a tamper-evident system. Consent records must be producible on demand in disputes. One-click audit exports reduce the operational burden of responding to regulatory inquiries or litigation discovery.
  5. Honor opt-out requests within 10 business days across all campaigns. Consumers may revoke consent through any reasonable means, including verbal statements, STOP replies, email, or web form. Suppression must apply company-wide, not campaign-by-campaign. Immediate suppression is recommended for automated systems to minimize the window of continued contact after revocation.
  6. Control abandonment rates at or below 3% per campaign over any 30-day period. Predictive dialers must not exceed a 3% abandoned-call rate. An abandoned call is defined as a live answer with no agent connected within 2 seconds of the recipient’s completed greeting. Abandoned calls must be followed by a prerecorded message identifying the business and providing an opt-out mechanism.
  7. Register A2P SMS campaigns via 10DLC before sending. A2P (application-to-person) business texting on 10-digit long codes requires brand and campaign registration with The Campaign Registry (TCR). Unregistered traffic has been blocked by carriers since February 2025. 10DLC registration operates separately from TCPA consent and must be completed before any SMS campaign launches.

How Plura Supports TCPA Controls at the Carrier Layer

Most AI voice and SMS platforms are API resellers built on top of third-party CPaaS providers. They do not own the carrier, cannot issue branded caller ID at the origination layer, and enforce compliance through bolt-on software rather than at the infrastructure level. Plura is its own FCC-licensed audio bridging carrier. Voice originates on Plura’s domestic infrastructure, which means compliance enforcement happens before a call or text leaves the platform.

Screenshot of Plura’s fully compliant AI communications platform showing business registration and phone number provisioning workflows for AI Voice, SMS, RCS, and Webchat communication automation.
Plura’s FCC-licensed AI communications platform simplifies compliant business registration and phone number provisioning for AI Voice, SMS, RCS, and Webchat workflows.

Plura’s compliance infrastructure includes the following layers, described in detail at plura.ai/products/compliance:

  • Real-time DNC scrubbing. Every outbound contact is checked against federal and state DNC registries at the moment of dial, not in a pre-campaign batch. Plura integrates with The Blacklist Alliance’s TCPA Litigation Firewall® for real-time Do Not Call scrubbing and litigation protection.4 Non-compliant numbers are blocked before the first attempt.
  • Immutable consent ledger. Consent records are timestamped and stored in a tamper-evident system. Every record captures the disclosure language, timestamp, source, and phone number. The ledger is audit-ready by default.
  • One-click audit exports. The compliance dashboard surfaces audit-ready reports on demand for legal review, carrier requirements, or regulatory inquiries. Operators do not need to reconstruct records manually under discovery pressure.
  • Automatic calling-window enforcement. Quiet-hours rules enforce through time-zone detection on the contact, applying state and federal calling-window restrictions to every campaign without manual configuration per state.
  • STIR/SHAKEN authentication. Every outbound voice call authenticates through STIR/SHAKEN at the carrier level, which destination carriers use to verify legitimate origination and reduce spam-label risk.
  • SOC 2, HIPAA, and ISO posture. Plura’s compliance framework includes SOC 2 aligned infrastructure, TCPA and STIR/SHAKEN enforcement, and real-time DNC screening.1

Plura’s AI SMS platform applies the same compliance layer to text campaigns: 10DLC-registered phone numbers, TCPA consent management, real-time DNC scrubbing, and per-state quiet-hours enforcement. The AI Predictive Dialer enforces abandonment-rate controls and time-zone restrictions automatically. All channels share a Stateful Conversation Database, so opt-out suppression applied in one channel propagates across voice, SMS, RCS, and webchat.

Plura provides the infrastructure layer that supports customer compliance. Operators remain responsible for their own consent documentation, campaign configuration, and regulatory obligations. Plura does not guarantee compliance outcomes or absolve operators of their legal duties. Consult qualified counsel to confirm your specific implementation meets applicable requirements.

Book a live demo with Plura to walk through the compliance dashboard, consent ledger, and real-time DNC scrubbing workflow with a platform specialist.

Conclusion: Applying TCPA Rules to AI Voice and SMS

Operators running high-volume outbound voice and SMS campaigns must maintain documented prior express written consent, scrub DNC lists within 31 days of each campaign, honor opt-out requests within 10 business days across all channels, restrict contacts to permitted calling windows by recipient local time, and control abandonment rates at or below 3% per campaign. Violations carry $500 to $1,500 in statutory damages per call or text with no aggregate cap, and class-action exposure in 2026 routinely reaches eight figures.

AI-generated voice calls follow the same consent requirements as traditional prerecorded robocalls under the FCC’s February 2024 Declaratory Ruling. Operators evaluating AI dialers and AI SMS platforms should confirm that the platform enforces these rules at the carrier level, not through a bolt-on compliance layer sitting on top of a third-party CPaaS.

Run your numbers through Plura’s calculator to compare the cost of non-compliance with carrier-grade infrastructure: plura.ai/calculator.

Frequently Asked Questions

What is the difference between prior express consent and prior express written consent under TCPA?

Prior express consent (PEC) is the lower standard and applies to informational or transactional contacts, such as appointment reminders or account alerts, made to wireless numbers using an ATDS. It can be oral or written. Prior express written consent (PEWC) is the higher standard and applies to marketing or promotional contacts made using an ATDS, artificial voice, or prerecorded voice. PEWC must be a signed or electronically signed agreement that names the specific company, authorizes the specific type of contact, specifies the phone number, and includes a disclosure that consent is not a condition of purchase. The FCC’s February 2024 Declaratory Ruling confirmed that AI-generated voice calls require PEWC for marketing purposes, the same as traditional prerecorded robocalls. Operators should consult qualified counsel to determine which consent tier applies to each campaign type.

Does TCPA apply to business-to-business (B2B) outbound calling and texting?

The TCPA protects “any person” and courts have held that work cell phones are covered by the statute. B2B mobile-to-mobile texting and calling requires the same prior express written consent as consumer outreach when an ATDS or artificial voice is used. Business landlines receive more limited treatment under the statute. The practical challenge for B2B operators is that contact lists are now 60–80% mobile numbers, which means the TCPA’s wireless-number consent requirements apply to the majority of outbound B2B contacts. State mini-TCPA laws in Florida, Oklahoma, Connecticut, and others may impose additional requirements on B2B campaigns. Operators should consult counsel on the specific requirements for their contact lists and campaign types.

How does the FCC’s one-to-one consent rule affect lead generation and shared consent forms?

The FCC adopted a one-to-one consent rule in December 2023 (FCC 23-107), effective January 27, 2025, which required that prior express written consent authorize calls from one specific seller only, invalidating shared-consent forms used by lead generators to bundle multiple marketers. The Eleventh Circuit vacated that rule in January 2025 in Insurance Marketing Coalition Ltd. v. FCC, 127 F.4th 303. The Fifth Circuit’s February 2026 Bradford decision rejected the FCC’s prior-express-written-consent requirement under 47 C.F.R. § 64.1200(f)(9) for TCPA calls, holding that only prior express consent (oral or written) is required. However, some states enforce one-to-one-style requirements independently, and plaintiff attorneys continue to use the one-to-one standard as a litigation benchmark even where it is not federally mandated. Operators relying on third-party lead generators should review their consent documentation with counsel to confirm it meets the applicable standard for each state where contacts will be made.

What records does an operator need to retain to defend against a TCPA claim?

A defensible TCPA record set includes the exact disclosure language presented at opt-in, the timestamp and IP address of the consent action, the source URL where consent was collected, the specific phone number authorized, the version of the consent form in use at the time, all DNC scrub results with dates, all opt-out requests and suppression confirmations with timestamps, and contact logs showing the date, time, and outcome of each outbound attempt. The TCPA’s federal statute of limitations is four years under 28 U.S.C. § 1658, so records should be retained for at least five years from the last contact to provide a buffer. Some state laws, including Virginia’s, impose 10-year opt-out record retention requirements. Operators should confirm their retention schedule with counsel based on the states where they operate.

How does carrier-level compliance enforcement differ from software-layer compliance bolt-ons?

Most AI voice and SMS platforms are built on top of third-party CPaaS providers and add compliance features as a software layer above the telecom infrastructure. In that model, DNC scrubbing, consent logging, and calling-window enforcement are handled by application code that sits between the platform and the underlying carrier. If the application layer fails, the carrier continues to route calls. Carrier-level enforcement means that compliance rules are applied at the origination point, before a call or text leaves the network. Plura operates its own FCC-licensed audio bridging carrier, which means real-time DNC scrubbing, STIR/SHAKEN authentication, and calling-window restrictions are enforced at the infrastructure layer, not as an add-on. Branded caller ID is issued directly by the carrier rather than through a third-party reseller. This architecture reduces the gap between compliance policy and compliance execution, though operators remain responsible for their own consent documentation and campaign configuration.


1 Plura AI maintains SOC 2, HIPAA, ISO, and GDPR posture as part of its platform infrastructure. References to compliance frameworks in this article describe Plura’s platform capabilities and do not constitute a guarantee that any customer using Plura will themselves be compliant with applicable laws or standards. Customers remain solely responsible for their own regulatory obligations, certifications, consent management, recordkeeping, and the claims they make to their own end users. Consult qualified legal counsel for guidance specific to your use case.

2 This article describes regulatory frameworks at a general level and does not constitute legal advice. Laws and regulations vary by jurisdiction, change over time, and apply differently depending on facts and circumstances. Readers should consult qualified legal counsel before making compliance decisions.

3 Performance figures, customer outcomes, and industry statistics referenced in this article are drawn from cited third-party sources or Plura customer case studies. Individual results vary based on implementation, use case, industry, audience, and execution. Past or aggregate performance is not a guarantee of future results.

4 References to third-party products, services, companies, or research are made for informational and comparative purposes only. Plura AI is not affiliated with, endorsed by, or sponsored by any third party named in this article unless explicitly stated. Trademarks and product names referenced remain the property of their respective owners.

This article is provided for informational purposes only and reflects Plura AI’s understanding at the time of publication. Product capabilities, integrations, and specifications are subject to change. For the most current information, visit plura.ai.

This article was produced with the assistance of AI tools and reviewed by Plura AI prior to publication.

See how Plura AI transforms AI voice agents