Your AI SDR Is a Robocall: The Telemarketing Exposure Behind Conversational Voice Agents
AI voice agents got adopted the way most useful automation does — as a pilot that worked, then a campaign that scaled. What did not scale alongside it was the consent record. Telemarketing law regulates calls made with an artificial voice, assesses damages per call, and hands consumers a private right of action. An agent that dials two thousand numbers a day is a compliance system whether or not anyone designed it as one.
"It's Not a Robocall, It's Conversational AI"
This is the sentence that shows up in every internal debate and it does not hold. The federal restriction is written around calls placed using an artificial or prerecorded voice. A model that synthesizes speech in real time is producing an artificial voice; the fact that it is generating novel sentences rather than replaying a recording makes it more capable, not less regulated. Regulators moved on this early and explicitly, treating AI-generated voices as squarely inside the existing language rather than as a gap requiring new legislation.
The practical consequence is that the interesting legal questions are not about the technology at all. They are the same questions asked of any outbound program: what consent do you hold for this number, what did you say in the first ten seconds, is the number on a suppression list, what time is it where the consumer is, and can you prove all of it eighteen months from now. AI changes only the volume at which you answer them.
Where AI Calling Programs Actually Break
- •Purchased or enriched lists treated as consented contacts
- •A single checkbox covering an unnamed set of 'partners'
- •Consent captured for email, reused to justify a phone call
- •Number changed hands and the reassignment was never checked
- •No retrievable proof tying a specific number to a specific disclosure
- •Spoken 'stop calling me' captured in a transcript nobody parses
- •Suppression applied in the dialer but not in the CRM that reloads it
- •Revocation honored on one brand, not across affiliated entities
- •Re-import of an old list resurrects previously suppressed numbers
- •Internal do-not-call list maintained by hand, refreshed rarely
- •Agent opens with a pitch before naming the caller and the seller
- •No synthetic-voice disclosure where a state statute requires one
- •Model answers 'are you a real person?' ambiguously or falsely
- •Caller ID displaying a number that does not reach a live human
- •No callback path or opt-out mechanism stated during the call
- •Calling window computed from account timezone, not area code or address
- •Retry logic redialing no-answers far past a reasonable frequency
- •A prompt change quietly turning an informational call into a sales call
- •Campaign launched without a scrub against national and internal lists
- •No rate limit, so a bad configuration reaches thousands before anyone notices
The Classification Question That Decides Everything
Outbound calls split into two buckets with very different consent standards. Informational and transactional calls — an appointment reminder, a delivery window, a fraud alert, a response to an inbound request — sit under the lower bar. Telemarketing and advertising calls to wireless numbers require prior express written consent that names the seller and is tied to that consumer's number. The bucket is determined by the content and purpose of the call, not by the label on the campaign.
That is uniquely dangerous with generative agents, because the content is not fixed at design time. A "customer care" agent instructed to be helpful will offer the upgrade when a caller mentions a limitation. A "reactivation" agent will describe a promotion. One prompt revision by a growth team can reclassify an entire campaign into the higher consent tier without anyone filing a ticket. Treat prompt changes to outbound agents as a regulated change with a review step, the same way you treat a change to the consent form itself.
Automation Is the Aggravating Factor, Not a Defense
Most compliance regimes require a plaintiff to establish harm and then argue about how to price it. Telemarketing law works differently: fixed statutory amounts per call, elevated for willful or knowing violations, with a private right of action that makes individual and class claims economical. The count is mechanical. A misrouted campaign that dials ten thousand numbers over a weekend produces ten thousand countable events, each one documented with a timestamp, a duration, a recording and a transcript in systems you control and will have to produce.
The same logs cut the other way when the program is built properly. A defensible deployment can show, for any individual number, the consent record that authorized the call, the disclosure the agent delivered, the scrub that ran before dialing and the suppression event that followed any opt-out. Nothing about voice AI makes that harder to produce — it just has to be designed in before the campaign scales, because reconstructing consent after a demand letter arrives is not possible.
The Overlapping Regimes That Arrive Together
Telemarketing law is rarely the only statute on an AI calling program. State mini-TCPA statutes add their own consent standards, calling windows and damages, several of them stricter than the federal floor. Call-recording consent rules apply the moment you store audio for training or quality review, and in two-party states that means disclosing the recording separately from disclosing the AI. Voice cloning of a real employee or a public figure implicates right-of-publicity claims. Comprehensive state privacy laws reach the profile you built to decide who gets called, and unfair or deceptive practices authority sits behind all of it whenever the agent misrepresents what it is. Building the program narrowly and honestly satisfies most of these at once.
Defensible Deployment Checklist
Before the First Campaign Dials
- ☐Classify every campaign as marketing or transactional in writing, and hold the matching consent tier
- ☐Store proof of consent per number — the exact language, timestamp, source and seller named
- ☐Script the first ten seconds: who is calling, on whose behalf, that the voice is AI, and how to opt out
- ☐Scrub against national, state and internal suppression lists as a blocking step, not a report
- ☐Set calling windows from the consumer's location, and rate-limit the dialer so a misconfiguration cannot run away
In Ongoing Operation
- ☐Detect spoken revocation in real time and write it to the system that actually gates dialing
- ☐Propagate opt-outs across brands, channels and affiliated entities within a documented window
- ☐Gate prompt and script changes behind the same review that governs the consent form
- ☐Make honest self-identification an unoverridable rule, and test it adversarially each release
- ☐Retain consent, disclosure and suppression evidence longer than the claim window, and rehearse retrieving it
Frequently Asked Questions
Our agent only calls people who filled out a form. Are we covered?
It depends on what the form said and what the call does. Consent has to name the seller and cover calls made with an artificial voice to that number for that purpose. A demo request does not authorize a cross-sell campaign from a sister brand two years later, and an email opt-in is not phone consent. Read your own form against the campaign before assuming coverage.
Does it matter that a human takes over partway through the call?
The artificial-voice portion still happened. Warm transfer is good practice for many reasons, but the consent, disclosure and calling-window obligations attached at dial time. A human closing the call does not retroactively convert it into a manually dialed one.
We only call business numbers. Different rules?
Somewhat, but do not treat B2B as a safe harbor. Enormous numbers of business contacts are wireless, and personal cell numbers reached through enrichment data are the exact fact pattern that turns a B2B campaign into a wireless-consent problem. State statutes and internal do-not-call duties can also apply regardless of how the number is categorized in your CRM.
How fast do we have to honor an opt-out spoken to the AI?
Promptly, and the trend in both regulation and litigation is toward tight windows measured in days, not billing cycles. Build the suppression path so that a revocation detected on a call blocks the next dial attempt automatically, rather than waiting for a batch job or a human to review the transcript.
Can we use a cloned voice of our best sales rep?
Only with that person's documented, specific and revocable permission, and even then think carefully. Voice cloning adds right-of-publicity and state biometric-voiceprint questions on top of the telemarketing analysis, and the consent you need from the employee is separate from any consent you hold from the consumer being called.
What is the single highest-value control to add first?
A hard gate between your consent record and your dialer, so that no number can be called unless a retrievable consent artifact exists for it. Almost every large exposure traces back to a list that entered the calling system without one, and that gate is the only control that stops the failure at the source rather than documenting it after the fact.
Your Website Is Where Consent Is Captured
Every one of these obligations traces back to a form, a checkbox and a disclosure on a page you control. If the consent language is buried, the checkbox is pre-ticked, or the privacy notice describes a calling program you no longer run, that is the first exhibit in any complaint — and the cheapest thing on this list to fix.
See what your pages currently say. Run a free scan and review every form and disclosure that feeds your outbound program.