AI voice agents are transforming how small businesses handle phone calls. An agent that answers every inbound call within two seconds, books appointments at 2 a.m., and never puts a customer on hold is a real competitive advantage. The numbers back this up: at Le Marquier, our AI voice agent now handles 98% of inbound customer interactions with an 80% reduction in customer service costs. You can read the full Le Marquier case study here.
But here is what a lot of business owners miss when they start evaluating voice agents: phone communication in the United States is governed by a web of federal and state laws. Getting the technology right is only half the job. Getting the compliance right is the other half, and the consequences of ignoring it range from regulatory fines to class action lawsuits.
This guide breaks down the four compliance areas that matter most for SMBs deploying AI voice agents: TCPA, state recording consent laws, HIPAA (for healthcare businesses), and Do Not Call registry obligations. It is practical, not legal advice. For anything that affects real risk for your business, work with an attorney who specializes in telecommunications law.
Why AI Voice Agents Create New Legal Questions
Traditional hold music and live answering have been around long enough that the legal frameworks around them are settled. AI voice agents are different in a few ways that matter to regulators.
First, they can sound convincingly human. That creates a disclosure obligation that does not exist for obvious robots. Second, they are capable of making outbound calls at scale. That triggers TCPA consent requirements in ways that a single receptionist calling back one patient does not. Third, they log and can transcribe every call. That creates data handling responsibilities, especially in healthcare.
Regulators have been paying attention. The FCC has issued guidance on AI-generated voices in robocalls. The FTC has published rules on automated calling. Several states have passed laws specifically addressing AI impersonation of humans. The legal landscape is moving fast, and the businesses that build compliance into their voice agent deployments from the start will avoid the retrofitting cost later.
If you are still deciding whether an AI voice agent is right for your business, start with the AI readiness assessment to understand where phone automation fits in your current operation.
TCPA: The Most Important Federal Law for AI Phone Calls
The Telephone Consumer Protection Act was passed in 1991 and has been updated several times since. It restricts how businesses can use automatic telephone dialing systems (ATDS) and artificial or prerecorded voices. AI voice agents fall squarely within its scope.
Inbound vs. Outbound: The Key Distinction
TCPA compliance looks very different depending on whether your AI agent is handling inbound calls or making outbound ones.
Inbound calls are the simpler case. When a customer calls your business and your AI agent answers, TCPA is largely not an issue. The customer initiated the call, so no prior consent is required for the AI to respond. The main obligation is the disclosure requirement: your agent should identify itself as automated in the opening greeting.
Outbound calls are where TCPA gets serious. If your AI agent calls customers to confirm appointments, follow up on orders, or conduct any outreach, you are using an artificial voice to initiate communication. Under TCPA, calling a cell phone with an artificial or prerecorded voice requires prior express written consent from the recipient. This is a higher bar than implied consent or verbal consent.
What counts as prior express written consent? A signed agreement or checked box where the consumer explicitly agrees to receive automated calls from your business. This needs to be clear and not bundled inside general terms of service. The consent record needs to be kept, because you may need to produce it if challenged.
What TCPA Violations Cost
The fines for TCPA violations are not trivial. The statute allows for $500 per violation for standard violations and $1,500 per violation if the violation was willful. Because each individual call to a non-consenting number is its own violation, a campaign that reaches 500 people without proper consent can create $750,000 in potential liability. Class actions amplify this significantly.
The key protections are: consent records, a working opt-out mechanism active during every outbound call, a call time restriction (8 a.m. to 9 p.m. in the recipient's time zone), and identification of your business at the start of every call.
State Recording Consent Laws: Know Where You Call
Federal law follows a one-party consent standard for recording calls. Under federal law, one person on the call just needs to consent, and that can be you (or your AI agent operating on your behalf). But 11 states require all parties to consent before a call can be recorded.
| Consent Standard | States | What This Means for AI Voice Agents |
|---|---|---|
| All-Party Consent Required | California, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, Washington | You must announce recording at the start of every call, regardless of who initiates it |
| One-Party Consent | All other states | Recording is permitted without announcing it, though disclosure is still considered best practice |
The practical implication: if you do business with customers in California or any of the other all-party consent states, your AI voice agent's opening greeting must include a recording notice. A simple line works: "This call may be recorded for quality and training purposes." That single sentence covers you in every state.
Most AI voice agent platforms have a configurable greeting. Set the recording disclosure as a permanent part of your opening message and do not overthink it. The cost of including it is zero. The cost of omitting it and getting into a dispute with a California customer is not.
Storage and Access of Call Recordings
Recording the call is only the first compliance checkpoint. How you store and who can access recordings matters too. Recordings should be stored in an encrypted format, access should be limited to people with a legitimate business need, and retention periods should match your business policy and any applicable regulations. For most non-healthcare businesses, 12 to 24 months of retention is standard. Healthcare businesses have longer obligations under HIPAA.
HIPAA Compliance for Healthcare Voice Agents
If your business operates in healthcare, mental health, dental, pharmacy, or any field covered by HIPAA, your AI voice agent touches protected health information (PHI). That triggers a set of obligations that go beyond standard voice agent compliance.
Business Associate Agreements
The first thing to do before deploying a voice agent in a healthcare context is confirm that your platform provider will sign a Business Associate Agreement (BAA). A BAA is a contract where the vendor agrees to protect PHI according to HIPAA standards. Without a signed BAA, you cannot legally share patient data with the platform, and that means the agent cannot access scheduling systems, insurance information, or any other PHI.
Most enterprise-grade voice agent platforms offer BAAs. If a vendor you are evaluating will not sign a BAA, that is a hard blocker for healthcare use cases.
What PHI the Agent Can Access and Speak Aloud
Even with a BAA in place, you need to design your voice agent with the minimum necessary standard in mind. The agent should access and speak aloud only the PHI required to complete the task at hand. If a patient calls to reschedule an appointment, the agent needs the patient's name and appointment time. It does not need to confirm their diagnosis or insurance details unless those are directly relevant to the call purpose.
Script your agent's conversation flows carefully. Every piece of PHI spoken aloud on a call is data that could be overheard, recorded, or replayed later. Keep it tight.
Encryption and Audit Trails
Call recordings that contain PHI must be encrypted in transit and at rest. Your platform provider should handle transit encryption. For recordings at rest, confirm with your vendor what encryption standard they use (AES-256 is the industry baseline). Your agreement with them should specify this.
HIPAA also requires audit trails: logs of who accessed what PHI, when, and why. For a voice agent deployment, this means maintaining records of what data the agent accessed during each call, and who in your organization later accessed those call logs.
Patient Right to Opt Out
Patients have the right to communicate with their healthcare provider through means other than automated systems. Your voice agent should have a clear escalation path to a human for patients who request it, and your intake flow should not force patients to share sensitive health information with an AI if they decline. This is both an ethical design principle and a practical HIPAA risk management step.
Do Not Call Registry Compliance
The National Do Not Call Registry is maintained by the FTC. Consumers can register their numbers to opt out of most telemarketing calls. If your AI voice agent makes outbound calls for any commercial purpose, including appointment reminders with upsell language or promotional notifications, you have DNC obligations.
Scrubbing Your Call List
Before running any outbound AI call campaign, you must check your call list against the National DNC Registry. The FTC requires this scrub to happen within 31 days of the call. Numbers that appear on the registry cannot be called for marketing purposes. You access the registry through the FTC's website and pay a fee for data access; costs are tiered based on how many area codes you need.
Beyond the national registry, you also need to maintain an internal DNC list. Any number where someone has told you to stop calling, whether to your human team or to your AI agent, must be added to this internal list immediately and honored within 30 days.
Transactional Calls vs. Marketing Calls
There is an important distinction between transactional calls and marketing calls. A pure appointment reminder with no promotional content generally falls under the transactional exemption and is not subject to the same DNC restrictions as marketing calls. But if your reminder includes an offer ("Don't forget your appointment, and ask us about our new membership plan"), it crosses into marketing territory.
Keep reminder content factual and appointment-specific. Save promotions for opt-in channels like email or SMS where consent is explicit.
Disclosure Requirements: Telling Callers They Are Talking to AI
Several states have passed laws requiring AI voice agents to disclose their non-human nature. California's AB 302 requires that automated systems identify themselves as automated when directly asked. Other states are following. The FTC has also signaled that deceptive use of AI voices, including failing to disclose automation when a caller sincerely asks, can constitute an unfair or deceptive practice under FTC Act Section 5.
The practical standard to build around is simple: train your AI agent to acknowledge it is an automated system when asked, without hesitation. Most voice agent platforms support this behavior natively. If yours does not, build it into your fallback logic.
Opening disclosure language that covers most scenarios: "Hi, you have reached [Business Name]. This is an automated assistant. How can I help you today?" This is accurate, brief, and sets the right expectation without a clunky legal disclaimer.
Building Your Compliance Checklist Before Launch
Compliance is not a one-time box to check. It is a set of configurations, vendor agreements, and operational practices that need to be in place before you go live and maintained as your use of the agent evolves. Here is a practical pre-launch checklist.
| Compliance Area | Required Action | Who Is Responsible |
|---|---|---|
| Inbound calls | Opening greeting identifies the call as automated; recording notice included if operating in all-party consent states | You (configure greeting script) |
| Outbound calls | Prior express written consent documented for each recipient's cell phone; call times restricted to 8 a.m.-9 p.m. local time | You (maintain consent records) |
| DNC compliance | National DNC scrub within 31 days; internal DNC list maintained; opt-out honored within 30 days | You + your call list management process |
| Recording storage | Encrypted storage; limited access; defined retention period | Platform vendor + your configuration |
| HIPAA (healthcare only) | Signed BAA with platform; PHI minimization in scripts; audit trail enabled; patient opt-out available | You + platform vendor |
| AI disclosure | Agent identifies as automated in greeting and when directly asked | You (configure conversation design) |
If you are evaluating whether your business is ready to deploy an AI voice agent, including whether your data and consent infrastructure is solid enough, the AI readiness assessment will give you a structured starting point.
Choosing a Platform That Supports Compliance
Your voice agent platform is a partner in compliance, not just a technology provider. When you evaluate platforms for your AI voice agent deployment, ask these questions directly:
- Will you sign a Business Associate Agreement if we operate in healthcare?
- How is call recording encrypted in transit and at rest?
- Can we configure the opening greeting to include a recording disclosure?
- Does the platform have a built-in DNC list integration or scrubbing workflow?
- Can the agent detect opt-out language in real time and flag the number automatically?
- What audit logging is available for call data access?
A platform that cannot answer these questions concretely is a compliance risk. A platform that can answer them confidently, and has documentation to back it up, is a platform worth building on.
Use the ROI calculator to understand the financial case for AI voice agents alongside the compliance investment. In most scenarios, even with proper consent management and platform costs included, the ROI is still strong because of the volume of calls a single AI agent can handle.
For more on choosing the right platform and deployment model, read our guide on how to choose an AI voice agent and the AI voice agent implementation guide.
Frequently Asked Questions
Do AI voice agents need to disclose they are AI?
Yes. The FTC requires that automated callers identify themselves as automated systems at the start of the call. Several states, including California, have enacted laws specifically requiring AI voice agents to disclose they are not human when asked directly. Best practice is to include a brief disclosure in the opening greeting: "Hi, this is an automated assistant from [Business Name]." This protects you legally and typically has minimal impact on call completion rates.
Does TCPA apply to AI voice agent calls?
Yes. TCPA applies to any call or text made using an automatic telephone dialing system or artificial or prerecorded voice, which includes AI voice agents. For inbound calls where the customer initiates contact, TCPA is less restrictive. For outbound AI calls to cell phones, you generally need prior express written consent. TCPA violations carry fines of $500 to $1,500 per call, so the stakes are real.
Can I record AI voice agent calls without telling callers?
It depends on your state. Federal law requires only one party to consent to recording. However, 11 states require all parties to consent, including California, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Pennsylvania, and Washington. If you operate in or call into any of these states, you must announce recording at the start of every call. Most businesses add a blanket notice to cover all scenarios.
How do I make my AI voice agent HIPAA compliant?
HIPAA compliance for AI voice agents requires four things: a signed Business Associate Agreement with your voice agent platform provider, encryption of any stored call recordings that contain protected health information, strict limits on what PHI the agent can access and repeat back on a call, and an audit trail of who accessed what data. Patients should be able to opt out of AI handling for sensitive matters.
What do I need before making outbound AI calls to customers?
Before running outbound AI call campaigns, you need prior express written consent from each recipient for automated calls to cell phones, a scrubbed call list checked against the National Do Not Call Registry within the past 31 days, a working opt-out mechanism active during every call, your business name clearly stated, and a callback number available to recipients. Transactional calls have more lenient requirements than marketing calls.
Does my AI voice agent need to handle Do Not Call requests?
Yes. If a caller says "remove me from your list" or any similar phrase, your AI voice agent must recognize this as a do-not-call request and immediately honor it. The number must be added to your internal DNC list within 30 days. The agent should confirm the removal verbally during the call. Ignoring these requests is one of the most common compliance violations.
Ready to Get Started?
Book a free 30-minute discovery call. We'll identify your biggest opportunities and show you exactly what AI automation can do for your business.