Back to Blog
Voice AIComplianceAI Receptionist

FCC AI Voice Call Regulations: What Australian and US Businesses Need to Know in 2026

FCC AI voice call regulations classify AI-generated voices as artificial under the TCPA, so unsolicited outbound AI robocalls need prior express consent while inbound AI receptionists answering customer calls do not. Here's what US and Australian businesses need to know about AI receptionist compliance in 2026.

Ming Xu
Ming XuCo-Founder & CIO
Updated June 23, 2026
7 min read
F

FCC AI Voice Call Regulations: What Australian and US Businesses Need to Know in 2026

As of June 2026, the FCC's February 8, 2024 Declaratory Ruling classifies AI-generated and AI-cloned voices as "artificial" voices under the Telephone Consumer Protection Act (TCPA, 47 U.S.C. Section 227), subjecting AI voice calls to the same robocall restrictions that govern prerecorded messages: they require the called party's prior express consent. The critical distinction for small businesses is direction. An inbound AI receptionist that answers a call the customer placed is in a fundamentally different regulatory posture than an outbound AI robocall that dials a consumer, because the TCPA's consent rules target calls made to people, not calls received from them. Unsolicited outbound AI calls carry real liability, while answering inbound calls customers chose to make sits in well-established legal territory. In Australia, the ACMA enforces parallel telemarketing rules through the Do Not Call Register, and the EU AI Act adds a disclosure obligation that takes effect in August 2026. This guide breaks down the inbound versus outbound distinction, the US and Australian penalty exposure, the EU disclosure rule, and a compliance checklist you can act on. Trillet includes TCPA, ACMA, GDPR, and DNCR compliance on every plan, which most competitors either charge extra for or skip entirely.

The regulatory landscape shifted fast. Within roughly a year, the US went from having no explicit stance on AI-generated voice calls to classifying them under decades-old robocall law, and multiple countries followed with their own frameworks. For any business using or considering a voice AI platform, understanding these rules is no longer optional. If you are still deciding whether an AI receptionist fits your business at all, the complete AI receptionist guide for small businesses covers setup, cost, and capabilities before you get to compliance.

Which Trillet product is right for you?

US Regulations: The FCC/TCPA Framework

The FCC's February 8, 2024 Declaratory Ruling brought AI voice calls under the TCPA by ruling that AI-generated speech qualifies as an "artificial" or "prerecorded" voice. This was not new legislation. The FCC used its existing authority to clarify that the TCPA's 1991 definitions already covered AI-generated audio, closing a loophole that had allowed AI robocalls to operate in a gray area.

Under the TCPA, businesses making AI voice calls to cell phones need prior express written consent for telemarketing purposes. A note on a rule that did not survive: the FCC's "one-to-one" consent rule, which would have required consent to be granted to a single identified seller, was scheduled to take effect January 27, 2025, but the Eleventh Circuit vacated it three days earlier in Insurance Marketing Coalition v. FCC, and the FCC announced in April 2025 it would not challenge that decision. Blanket consent obtained before a call can still satisfy the TCPA. If you read older guidance citing the one-to-one rule as active, it is out of date.

The penalty structure is tiered. Private litigants can sue for $500 per violation, trebled to $1,500 for willful or knowing violations, with a four-year statute of limitations (28 U.S.C. Section 1658). Because each call is a separate violation, damages compound fast: a campaign of a few hundred noncompliant calls runs into six figures. FCC enforcement is separate and larger. In its first AI robocall actions, the FCC reached a $1 million settlement with Lingo Telecom (the carrier that transmitted the January 2024 fake-Biden New Hampshire primary robocall) and issued a $6 million forfeiture order against the political consultant who directed it.

Informational (non-telemarketing) AI calls to cell phones require prior express consent, though not necessarily written. Calls to landlines have fewer restrictions but still cannot use artificial voices without consent if the call is telemarketing. The rules are complex enough that businesses should consult their legal team before launching any outbound AI voice campaign.

Inbound vs. Outbound: Why the Distinction Matters

Inbound AI receptionists that answer calls placed by customers are generally compliant with the TCPA because the customer initiated the call. The TCPA's consent requirements target calls made to consumers, not calls received from them. When a customer dials your business number and an AI agent picks up, no robocall provision has been triggered because no automated dialing or unsolicited calling occurred.

Outbound AI calls, where a system dials customers using AI-generated voice, fall squarely under the TCPA's restrictions. This includes appointment reminders, follow-up calls, marketing calls, and any scenario where the business initiates contact with an AI voice. These calls require proper consent documentation and compliance with do-not-call lists.

This distinction is why AI receptionists like Trillet's $49/month service operate in well-established legal territory. The customer calls your business number, the AI answers because you missed the call, and no outbound dialing occurs. The regulatory risk sits almost entirely on the outbound side. Inbound systems also do useful work that has nothing to do with telemarketing law: they apply caller ID and spam detection to filter junk calls before they ever reach you.

That said, even inbound operations should maintain good practices: inform callers they are speaking with an AI system when practical, keep call recordings in compliance with state two-party consent laws, and document your compliance posture. Consult your legal team if your AI receptionist also initiates outbound follow-up calls or texts, as those touchpoints may trigger separate consent requirements.

Australian Regulations: ACMA and the Do Not Call Register

The Australian Communications and Media Authority (ACMA) regulates telemarketing through the Do Not Call Register (DNCR) and the Spam Act 2003. As of June 2026, businesses making AI-generated voice calls to Australian numbers must comply with the same rules that apply to human telemarketers: check numbers against the DNCR before calling, honor opt-out requests, and include caller identification.

ACMA penalties are significant. Corporate breaches of the Do Not Call Register rules can reach into the millions, and ACMA enforces actively: in April 2025 the Federal Court imposed a $1.5 million penalty on telemarketer V Marketing for calls made to numbers on the register, with a further $60,000 against its director. ACMA has historically been aggressive against overseas operators targeting Australian consumers.

Australia's Privacy Act 1988 adds another layer. AI systems that collect, store, or process personal information from phone calls must comply with the Australian Privacy Principles (APPs). For a deeper look at how this affects AI answering services, see Privacy Act Compliance for AI Answering Services.

The practical upshot for Australian small businesses: using an AI receptionist to answer your incoming calls is permissible, but any outbound AI calling campaigns must comply with the DNCR and telemarketing rules. Trillet includes ACMA and DNCR compliance on every plan, handling the regulatory baseline so the business owner does not need to build compliance infrastructure from scratch.

EU AI Act: Disclosure Requirements

The EU AI Act (Article 50) requires that people interacting with an AI system be informed they are communicating with AI, "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect." This transparency obligation becomes applicable on 2 August 2026 and applies regardless of whether the call is inbound or outbound. As of June 2026 it is not yet in force, but any business with EU callers should configure disclosure now.

For businesses operating across the US, Australia, and the EU, the disclosure requirement is the safest default. Even where disclosure is not legally mandated (the TCPA does not explicitly require it), proactively telling callers they are speaking with an AI agent reduces complaint risk and aligns with the direction every major regulatory body is heading.

US State-Level AI Voice Regulations

Several US states have enacted or proposed AI-specific voice call regulations that go beyond federal TCPA requirements. California's Bolstering Online Transparency Act (BOT Act) requires bots to disclose their non-human identity in certain commercial interactions. Illinois, Texas, and Washington have biometric privacy laws that may apply to voice data collected during AI calls. New York and other states have introduced bills specifically targeting AI-generated voice in telemarketing.

The state-level landscape changes frequently. Businesses operating across multiple states should assume the strictest applicable standard and consult legal counsel for state-specific compliance. A voice AI platform with built-in compliance guardrails reduces the burden of tracking these changes manually.

What Businesses Must Do to Stay Compliant

Compliance for small businesses using AI voice technology comes down to five core obligations: obtain proper consent before any outbound AI calls, maintain documentation of that consent, check numbers against applicable do-not-call registers, disclose AI involvement when required or when prudent, and retain call records per applicable regulations.

For businesses using an inbound AI receptionist only (answering calls from customers), the compliance burden is substantially lighter. The customer initiated the call, so TCPA consent provisions for outbound calling do not apply. The primary obligations become state-level recording consent laws, data privacy requirements, and any industry-specific regulations (HIPAA for healthcare, for instance). Getting here does not require legal or technical staff: most inbound AI receptionists handle the compliance baseline out of the box, and setup without technical knowledge takes minutes rather than an IT project.

Businesses that also use outbound AI calling, whether for appointment reminders, follow-ups, or marketing, should treat every outbound AI call as subject to TCPA and ACMA requirements. Document consent, check do-not-call lists, and build opt-out mechanisms. The penalties for getting this wrong are not theoretical.

AI Receptionist Compliance Checklist

This checklist covers the minimum compliance posture for a small business using an AI receptionist. It is not legal advice. Consult your legal team for requirements specific to your jurisdiction and industry.

Inbound AI receptionist (answering missed calls):

Outbound AI calls (follow-ups, reminders, marketing):

Which Voice AI Platforms Include Compliance

Most AI receptionist platforms treat compliance as optional or charge extra for it. As of June 2026, Trillet includes TCPA, ACMA, GDPR, and DNCR compliance on every plan at no additional cost. HIPAA compliance, which some competitors charge $500 or more as an add-on, is also included. The argument for why compliance should be bundled rather than billed separately is laid out in why HIPAA compliance shouldn't be a $500 add-on, and the AI Receptionist Pricing Models Explained breakdown shows how compliance costs vary across platforms.

When evaluating any voice AI platform, ask three questions: does the platform include compliance features on every tier, does the platform own its infrastructure (wrapper platforms built on Vapi or Retell add compliance complexity because data flows through multiple third parties), and does the platform provide documentation you can show a regulator if asked. If the answer to any of these is no, you are accepting regulatory risk the platform is not managing for you.

Frequently Asked Questions

Are AI receptionist phone calls legal?

Yes, with conditions. In the US, inbound AI receptionists that answer calls from customers are generally compliant with the TCPA because the customer initiated the call. Outbound AI calls (where a business dials customers using AI-generated voice) require prior express written consent for telemarketing to cell phones. In Australia, similar rules apply under ACMA. The legality depends on direction (inbound vs. outbound), purpose (informational vs. telemarketing), and consent status. Consult your legal team for your specific use case.

Does my AI receptionist need to tell callers it is AI?

The EU AI Act (Article 50) requires disclosure unless the AI nature is obvious from context, with that obligation taking effect 2 August 2026. The US TCPA does not explicitly require disclosure, though several states have introduced or passed AI disclosure laws. Australia does not have a blanket disclosure requirement as of June 2026, but the ACCC has signaled interest in AI transparency rules. Best practice: configure your AI receptionist to identify itself as an AI assistant. It reduces complaint risk and aligns with the regulatory direction globally.

What is the penalty for making illegal AI robocalls?

In the US, TCPA violations carry $500 per call in private lawsuits and $1,500 for willful or knowing violations, with no cap on aggregate damages. FCC enforcement is separate and can run far higher: its first AI robocall actions produced a $1 million settlement with Lingo Telecom and a $6 million forfeiture against the consultant behind the January 2024 fake-Biden robocall. In Australia, ACMA telemarketing and Do Not Call Register breaches by a corporation can reach into the millions, with a $1.5 million Federal Court penalty imposed on one telemarketer in 2025. These penalties apply per call, so even a small campaign of a few hundred noncompliant calls can result in substantial liability.

Does Trillet handle compliance automatically?

Trillet includes TCPA, ACMA, GDPR, and DNCR compliance on every plan at no extra cost, including the $49/month AI Receptionist plan. This covers the platform-level compliance infrastructure: call handling that respects consent frameworks, data storage per privacy regulations, and support for industry standards like HIPAA. Platform compliance does not replace the need for legal counsel on your specific obligations, but it ensures the technology layer is not creating compliance gaps.

Which Trillet product should I choose?

If you are a small business owner needing an AI receptionist to catch missed calls, the Trillet AI Receptionist at $49/month with 150 minutes is the right fit. If you are a marketing agency wanting to resell compliant voice AI to your own clients under your own brand, Trillet White-Label starts at $99/month with $0.12/minute usage and the same compliance stack included.

Updated for June 2026: Corrected the legal record on the FCC's "one-to-one" consent rule (vacated by the Eleventh Circuit in January 2025, not in effect), replaced an unverifiable per-violation FCC penalty figure with the actual Lingo Telecom and Steve Kramer AI robocall enforcement outcomes, and clarified that the EU AI Act Article 50 disclosure obligation applies from 2 August 2026.

Related Resources

Related Articles