Playbook
Can Your AI Follow-Up Get Your Agency Sued?
The FCC says an AI voice is a robocall. Here is what that means for the texts and calls your agency automates today.
The TCPA does not care whether a human or an AI generated the voice or the text. The FCC ruled in February 2024 that AI-generated voices count as "artificial" voices under the law5, and the statute lets an individual consumer sue for $500 to $1,500 per violation2. The actual risk is not the word AI. It is whether your system initiated the contact without consent, and whether that consent is written down. Answering your phone with AI is not the exposure. Automating outbound texts and calls to your database without documented consent is.
The follow-up you just automated
You set up an AI tool to text your old leads, or to call the list of clients whose plans renew this quarter, or to follow up with anyone who filled out a quote form and went quiet. It works. Replies come in. Appointments get booked. Then you see a headline about a robocall lawsuit, or a colleague mentions a text message class action that cost an agency real money, and you wonder whether the thing you just turned on on is the same category of problem.
That worry is reasonable, and it deserves a straight answer instead of either extreme. The straight answer is not "AI is illegal" and it is not "AI is exempt." It is that the Telephone Consumer Protection Act, the federal law behind nearly every robocall lawsuit you have heard about, was written around a specific set of triggers: who initiated the contact, what technology carried it, and whether the recipient agreed to it in advance. AI changes how cheaply and how often an agency can hit those triggers. It does not change what the triggers are.
What this guide is and is not
This is a plain-language map of the federal rules and the two recent developments that actually matter for an agency automating follow-up in 2026. It is not legal advice for your specific dialer, list, or state. If a consent question is close, or your state layers its own telemarketing statute on top of the federal one, that is a conversation for your own attorney, not a blog post.
What the TCPA actually restricts
The Telephone Consumer Protection Act restricts three things at once, and most of the confusion agencies run into comes from treating them as one rule instead of three. The statute, at 47 U.S.C. 227(b)(1)(B), prohibits initiating a call to a residential line "using an artificial or prerecorded voice to deliver a message without the prior express consent of the called party," with narrow exceptions for emergencies and a few statutory carve outs1. A separate FCC rule, 47 CFR 64.1200(a), goes further for anything that is actually advertising or telemarketing sent through an autodialer or a prerecorded or artificial voice: that category needs "prior express written consent," meaning a signed agreement that clearly authorizes the calls and tells the person they are not required to consent as a condition of buying anything4.
Text messages are not a loophole. The FCC treats a text message as a call for TCPA purposes, so an automated marketing text to a mobile number sits under the same consent framework as an automated voice call1. An agency that would never dream of blasting prerecorded voicemails to a cold list but is comfortable blasting AI-drafted texts to the same list has not actually changed its legal exposure. It changed the channel, not the rule.
The autodialer piece has its own history worth knowing, because it is narrower than most agencies assume. The Supreme Court settled a long-running circuit split on April 1, 2021, in Facebook, Inc. v. Duguid, ruling unanimously that an automatic telephone dialing system, as Congress defined it, must have the capacity to store or produce phone numbers using a random or sequential number generator, not simply the capacity to dial automatically from a stored list. Because Facebook's system only texted numbers already saved in its own database rather than generating them randomly, the Court held it was not using an autodialer under the statute11. That holding is good news for an agency texting its own CRM list rather than dialing randomly generated numbers, but it is easy to overstate. The autodialer rule is only one of the three restrictions in the table below. An artificial or prerecorded AI voice calling from a stored list still needs consent under the separate artificial-voice restriction, regardless of how the numbers were selected1. Duguid narrowed one path to liability. It did not close the other two.
| Restriction | What it covers | What it requires |
|---|---|---|
| Artificial or prerecorded voice | Any call, including one voiced by AI, using a synthetic or recorded voice instead of a live person | Prior express consent, written for anything advertising or telemarketing1,4 |
| Automatic telephone dialing system | Equipment that dials numbers from a stored or generated list without a person manually placing each call | Prior express consent before dialing a wireless number1 |
| Calling hours | Any telephone solicitation to a residential number | Only between 8 a.m. and 9 p.m., local time at the called party's location3 |
Why answering the phone is not the risk
Here is the distinction that resolves most of the anxiety agencies bring to this topic. The TCPA's restrictions attach to who initiates the contact. An AI receptionist that answers when a client calls your agency after hours has not initiated anything. The client called you. The TCPA has nothing to say about that call, AI voice or not, because the statute is written around calls placed to a consumer, not calls a consumer places to a business1.
The exposure lives entirely on the other side: the moment your system places an outbound call or sends an outbound text first, to a lead, a client, or an old contact in your CRM, without consent that covers it. That is database reactivation, appointment reminders, renewal outreach, and quote follow-up, all genuinely useful work, and all squarely inside the part of the law that requires consent before you start.
AI receptionist answers your line
- The client or lead placed the call
- Nothing was initiated on your side
- No TCPA consent requirement is triggered
- Standard use case for an after-hours AI receptionist
RiskNot a TCPA question at all
AI texts or calls a lead first
- Your system placed the call or sent the text
- Artificial voice and autodialer rules apply
- Prior express consent is required before you start
- Written consent needed if it is advertising or telemarketing
RiskWhere consent and documentation matter
A quick gut check
Ask one question about any AI message you are about to automate: who placed this call or sent this text first, the customer or your system? If the answer is your system, the next question is whether you can show, in writing, that the recipient agreed to be contacted this way before you sent it. If you cannot answer that second question cleanly, that message is not ready to send yet.
What the FCC changed in 2024
The question of whether an AI-generated voice even counted as "artificial" under a decades-old statute was genuinely open until February 2024. It is not anymore. On February 8, 2024, the FCC adopted a Declaratory Ruling, by a unanimous vote, confirming that the TCPA's restrictions on an "artificial or prerecorded voice" cover current AI technologies that generate human sounding voices5. The ruling was prompted by voice-cloning robocalls impersonating a public figure during a presidential primary, but its text is not narrow. It applies the same way to a customer-service voice agent, a debt-collection bot, or an insurance follow-up caller built on the same kind of text-to-speech technology5.
Practically, that ruling closed a door some vendors and marketers had been treating as open: the idea that because a voice was generated rather than recorded from a human, it fell outside "artificial or prerecorded voice" restrictions written before consumer AI voice existed. It does not. An AI voice calling on your agency's behalf is legally the same animal as a prerecorded voicemail blast, subject to the same consent rule, the same calling-hours rule, and the same private right of action if you get it wrong5.
What a violation actually costs
The TCPA is unusual among consumer protection statutes because it hands the enforcement pen to the individual consumer, not just to a regulator. Under 47 U.S.C. 227(b)(3), a person who receives a violating call or text can sue to recover their actual monetary loss, or $500 per violation, whichever is greater, and a court can increase that award up to three times, to $1,500 per violation, if it finds the violation was willful or knowing2. Those numbers are per call or per text, not per campaign, which is the detail that turns a single bad list into a real number once a plaintiff's firm certifies a class.
$500
Minimum statutory damages per violation2
$1,500
Maximum per violation if willful or knowing2
2.6M
Do Not Call complaints the FTC logged in FY20256
Feb 2024
FCC confirmed AI voices count as "artificial"5
Put a number on it the way an agency would actually feel it. A reactivation campaign that texts 2,000 old leads without documented consent, and where even a modest fraction of those contacts are found to violate the statute, is not a $500 problem. It is a $500 to $1,500 problem multiplied by however many of those 2,000 messages a court or a settlement counts as a violation. That is the mechanism behind every large TCPA settlement you have ever read about, and it is precisely the same mechanism whether the voice on the call was a person, a recording, or a model.
The regulatory backdrop is not shrinking either. The FTC's National Do Not Call Registry Data Book for fiscal year 2025 recorded over 2.6 million Do Not Call complaints against more than 258 million active registered numbers, up from over 2 million complaints against 253 million registrations the year before6,7. More numbers on the registry and more complaints filed against it both point the same direction: a called party today is more likely, not less, to know their rights and to have somewhere to report a violation.
Put a small, honest number on it so the exposure feels concrete instead of abstract. Say an agency's reactivation campaign sends an automated text to 3,000 old contacts pulled from a CRM that never captured explicit consent for automated messaging, and a plaintiff's firm later certifies 400 of those contacts as a class. At the statutory minimum of $500 per violation, that is a $200,000 exposure before anyone even argues the violations were willful. If a court finds willfulness and applies the treble multiplier up to $1,500 per violation, the same 400-contact class is a $600,000 exposure2. This is an illustration built from the statute's stated damages range applied to a round hypothetical list size, not a prediction about any specific agency's list or a promise about how a court would rule. The point is the mechanism, not the exact figure: statutory damages are set per violation on purpose, so exposure scales with list size in a way a single bad send can outrun fast.
If you want to know whether your own follow-up setup would survive scrutiny before you find out the hard way, the free Audit includes a look at how your site and your automation handle consent-adjacent data. Run the free Audit.
Written consent, oral consent, and the split
The safest consent standard to build to is written, and that has been true since long before AI entered the picture. FCC rule 47 CFR 64.1200(a) requires "prior express written consent" for any telemarketing or advertising call or text placed with an autodialer or an artificial or prerecorded voice, meaning a signed agreement, which can be an electronic signature, that clearly authorizes the specific kind of contact and tells the signer they do not have to agree to it to buy anything4.
That standard got a real, if narrow, crack in it on February 25, 2026. A three-judge panel of the Fifth Circuit Court of Appeals ruled in Bradford v. Sovereign Pest Control of TX, Inc. that the TCPA's own statutory text requires only "prior express consent," not the heightened written form the FCC has demanded by rule since 2012, and that oral consent can satisfy the statute8. The court affirmed summary judgment for the defendant, a pest control company whose customer had verbally agreed to renewal reminder calls years earlier8.
What that ruling does not do
It does not apply nationwide. The decision binds only the Fifth Circuit, meaning Texas, Louisiana, and Mississippi, and every court outside that circuit still applies the FCC's written consent rule or its own reading of the statute8. A single agency running outbound follow-up to leads across several states cannot rely on this ruling for contacts outside those three, and even inside them, oral consent that is not carefully documented is a much weaker record to defend than a signed form.
| Where | Standard that applies | What it means for your build |
|---|---|---|
| Texas, Louisiana, Mississippi | Oral consent can satisfy the TCPA, per Bradford v. Sovereign Pest Control8 | Still document every oral yes with a timestamp and method |
| Everywhere else | FCC's written consent rule still controls4 | Capture a signed or e-signed opt-in before any autodialed or AI-voiced marketing contact |
| Your whole lead list, realistically | Mixed, since leads come from everywhere | Build to the written standard once, and every jurisdiction is covered |
What state law adds on top
The federal TCPA is not the only statute in play, and an agency that only checks its build against federal rules can still get caught by a state law layered on top. Florida is the example agencies run into most, because its Telephone Solicitation Act, codified at Fla. Stat. 501.059, created its own private right of action for unwanted marketing calls and texts, with claimants able to recover $500 per violation or actual damages, whichever is greater, separate from and in addition to whatever the TCPA allows12. Florida is not unique in having a state statute like this, and the exact consent and dialer definitions vary by state, which is exactly why a compliance approach built only around the federal statute can still miss a real exposure for a lead who happens to live in the wrong zip code.
For an agency running leads through a single state, this is one more statute to check once. For an FMO or IMO running outbound follow-up across every state its downline agents write business in, it means the safe consent standard has to be built once and applied everywhere, because checking each state's mini-TCPA individually for every campaign does not scale. This is the same reason a shared, centrally built compliance layer tends to outperform each office handling its own follow-up independently: one architecture decision, made correctly, protects every site and every state under it, instead of depending on each location remembering the rule on its own.
How to make your own follow-up compliant
None of this requires abandoning AI follow-up, and it does not require a law degree to get the basics right. Here is the actual checklist, and you can run every item on it yourself, this week, on whatever CRM or automation you already have.
Capture consent at intake
Add a clear, separate checkbox for texts and automated calls when a lead first hands you their number, not buried inside a generic terms link.
Document every yes
Store the timestamp, the exact language shown, and the method, form field, verbal, or signed, for every consent you collect.
Segment your list
Keep contacts with documented written consent separate from older contacts you cannot yet prove consent for, and treat the second group differently.
Respect the clock
Calculate the 8 a.m. to 9 p.m. window against the lead's own area code or address, not your office time zone, before any send goes out3.
Make opt-out immediate
Honor a "stop" reply or a verbal opt-out the same day, and keep a suppression list your whole stack actually checks before sending.
Know what you cannot fix with a setting
No platform toggle replaces documented consent. If the record does not exist, the message should not go out until it does.
What consent language actually looks like
A compliant checkbox is specific, not generic. Something close to "I agree to receive automated text messages and calls, including from AI voice systems, about my quote and policy options at the number provided. Consent is not required to purchase. Message and data rates may apply. Reply STOP to opt out at any time" gives you the two things a regulator or a plaintiff's attorney actually looks for: a clear description of what the contact will be, and an explicit statement that agreeing to it was optional. A generic "I agree to the terms and privacy policy" checkbox does neither, and is the version of consent capture that tends not to hold up.
You can build every piece of this yourself inside most CRMs and automation platforms, and a fair number of agencies do exactly that and never have a problem, because their list is smaller, their consent capture was already reasonably clean, and their volume never approaches the scale where a plaintiff's firm bothers to look. If that describes your agency, the DIY path is genuinely fine. Where this gets harder is at real volume, across multiple states, with leads coming in from several sources that each capture consent language differently, or with none at all.
How we build follow-up that stays inside the lines
This is the same problem we solve for the compliance side of every AI agent we build, not a separate product bolted on afterward. Our custom builds, scoped on a call rather than sold off a shelf, include the conversational AI and voice AI, the database reactivation and appointment automation, and the HIPAA safe automations that keep client data inside a system built for it9. Anything that touches real client data runs through Ambrose, which masks protected health information before any non-BAA AI model ever sees it, then re-hydrates it for you, the same PHI-gating architecture that makes the consent and documentation side of TCPA compliance a build decision instead of an afterthought9.
The distinction this guide walks through, inbound answering versus outbound initiation, is exactly how we scope these builds. An AI receptionist that answers your lines is a different compliance conversation than an AI that texts and calls back into your book with real context9, and a build done right treats them as two different systems with two different consent postures, not one feature with one on-off switch. If you would rather see how that gets scoped for your own agency than keep reading about it in the abstract, that conversation happens on a call, not through a generic form. See how we build custom.
If your agency is not ready for a custom build yet
Digital Foundation, our done-for-you website tier, includes the AI chat widget and, at the Pro tier and above, a 24/7 AI receptionist, which is the inbound side of this guide's distinction and carries none of the outbound consent questions covered above. See Digital Foundation.
| Tier | Price | What it adds |
|---|---|---|
| Starter | $247/mo | Complete, compliant site with AEO optimization, GBP management, AI chat widget10 |
| Pro | $497/mo | Plus weekly blog post, weekly location page, 24/7 AI receptionist (inbound)10 |
| Scale | $997/mo | Plus daily blog cadence, 2 new location pages weekly10 |
Custom outbound automation, the conversational follow-up and database reactivation that actually triggers the TCPA questions in this guide, is scoped on the call under our AI Expert and Enterprise tiers rather than sold as a fixed monthly line item, because the consent architecture, the list segmentation, and the volume all vary by agency9.
What compliant automation gets you
Get the consent and documentation piece right once, and the upside of AI follow-up stops being something you have to be nervous about. A database reactivation campaign that only ever contacts people who documented consent at intake is not a smaller version of a risky campaign. It is the same campaign, built so that the plaintiff's bar has nothing to find if they ever go looking. That is the actual goal here, not fewer AI messages, but AI messages you can defend the origin of if you ever need to.
It also changes how confidently you can scale the thing that is actually working. An agency that is unsure whether its reactivation list is clean tends to under-use its own best channel, because the fear of a bad list is bigger than the upside of a good one. An agency with documented, segmented consent can run that same channel at real volume, across states, without the anxiety being the thing that throttles it.
None of this is legal advice, and none of it substitutes for your own attorney's read on your specific lists, states, and platform. What it is, is the difference between guessing at where the line sits and building a system that already knows.
Scale changes the math further than most agencies expect. A single producer running a few hundred contacts through one CRM can often manage consent tracking in a spreadsheet and stay fine. An FMO or IMO with downline agents in a dozen states, each capturing leads through different landing pages and different intake forms, is managing a dozen different consent records with a dozen different failure points, and a single sloppy intake form anywhere in that chain can expose every campaign it feeds. That is precisely the shape of problem a shared, purpose-built compliance layer solves once instead of a dozen times, which is why it belongs in the same conversation as the AI voice and text automation itself, not bolted on after the fact.
Questions agencies ask
Is it illegal to use AI to text or call my leads?
No, and it never has been. What is regulated is not the word AI, it is whether the message uses an automatic telephone dialing system or an artificial or prerecorded voice, and whether you had the called party's prior express consent before you sent it. An AI voice or an AI-drafted text is treated the same as a human-recorded one under the TCPA. The tool does not create the obligation. The initiation of the contact does.
Does an AI receptionist that answers my phones create TCPA exposure?
Not for the act of answering. The TCPA restricts calls a caller initiates to a consumer, not calls a consumer initiates to you. An AI receptionist that picks up when a client calls your agency is on the inbound side of that line. The exposure shows up on the outbound side, when your system places a call or sends a text to a lead or a client first.
Do I need written consent or is a verbal yes enough?
For most of the country, get it in writing. The FCC's rule at 47 CFR 64.1200(a) requires prior express written consent before an autodialed or prerecorded marketing call, and that is still the standard nearly everywhere. A February 2026 Fifth Circuit ruling in Bradford v. Sovereign Pest Control found oral consent can satisfy the TCPA's statutory text, but that decision binds only Texas, Louisiana, and Mississippi, and even there it is one panel's reading, not a settled national rule. Build to the written standard and you are covered regardless of which circuit a lead lives in.
What actually counts as an automatic telephone dialing system?
The statutory definition and a decade of litigation over its edges is its own legal specialty, and platforms vary in how their dialers are built. What agencies get wrong less often is the dialer question and more often the consent and documentation question, which is the part this guide focuses on. If your dialing setup is in a legal gray area, that is a question for counsel, not a marketing checklist.
Does texting an old lead in my CRM to win them back count as a solicitation?
If the message is trying to sell something and the recipient has not both agreed to be contacted this way and stayed within any relationship the consent was tied to, treat it as a solicitation and get consent before you send it. Database reactivation is one of the most useful things automation does for an agency, and it is also exactly the kind of outbound, sales-intent messaging the TCPA was written to cover. The fix is not to avoid reactivation. It is to capture consent at intake so reactivation later is already covered.
What is the actual penalty if I get this wrong?
The TCPA is a private right of action, meaning an individual consumer, not just a regulator, can sue and recover $500 per violation, or up to $1,500 per violation if a court finds the violation willful or knowing, under 47 U.S.C. 227(b)(3) and (c)(5). Violations are usually counted per message or per call, not per campaign, which is why these cases are filed as class actions and why the number gets large fast against a list of any real size.
Is there a safe time of day to send automated follow-up?
Yes. 47 CFR 64.1200(c)(1) prohibits a telephone solicitation to a residential number before 8 a.m. or after 9 p.m., local time at the called party's location, not yours. An agency running one send schedule across multiple time zones needs to calculate that window against the lead's area code or address, not the office clock where the campaign was built.
Sources
- Cornell Law School, Legal Information Institute. "47 U.S.C. 227, Restrictions on Use of Telephone Equipment." law.cornell.edu.
- Cornell Law School, Legal Information Institute. "47 U.S.C. 227(b)(3) and (c)(5), private right of action and damages." law.cornell.edu.
- Cornell Law School, Legal Information Institute. "47 CFR 64.1200(c)(1), calling hours restriction." law.cornell.edu.
- Cornell Law School, Legal Information Institute. "47 CFR 64.1200(a), prior express written consent requirement." law.cornell.edu.
- Federal Communications Commission. "FCC Makes AI-Generated Voices in Robocalls Illegal," Declaratory Ruling FCC 24-17, February 8, 2024. fcc.gov.
- Federal Trade Commission. "National Do Not Call Registry Data Book, Fiscal Year 2025." ftc.gov.
- Federal Trade Commission. "National Do Not Call Registry Data Book, Fiscal Year 2024." ftc.gov.
- United States Court of Appeals for the Fifth Circuit. Bradford v. Sovereign Pest Control of TX, Inc., No. 24-20379, decided February 25, 2026; summarized in Holland & Knight, "TCPA Reset: Fifth Circuit Rejects 'Prior Express Written Consent' Rule." ca5.uscourts.gov, corroborated at hklaw.com.
- Strategic AI Architects. "AI Expert," custom AI agents and automation, verified live 2026-08-03. strategicaiarchitects.com.
- Strategic AI Architects. "Digital Foundation," pricing verified live 2026-08-03. strategicaiarchitects.com.
- Facebook, Inc. v. Duguid, 592 U.S. 395, decided April 1, 2021, holding an automatic telephone dialing system requires the capacity to store or produce numbers using a random or sequential number generator. supremecourt.gov.
- Morrison Foerster. "Uptick in Florida Telephone Solicitation Act Litigation and Ways to Mitigate Risk," summarizing Fla. Stat. 501.059's $500 per-violation private right of action. mofo.com.
Get your AI follow-up scoped the right way
Run the free Audit, a live AEO Audit plus a HIPAA tracking scan of your site, in under a minute.