Guide
Is AI Cold Calling Legal? The Honest Answer for US Businesses
The honest answer is no, not in the way most people mean it. In the US, an AI voice is treated as an artificial voice under the TCPA, and an artificial-voice marketing call to a consumer requires prior express written consent from the person you are calling. A cold list is by definition a list of people who never gave you that. So if the plan is to load ten thousand scraped numbers into an AI dialer and let it run, that plan is illegal, and the damages are priced per call rather than per campaign. What is legal is narrower and, in our experience, more profitable anyway: calling people who just raised their hand, answering your own inbound phone, and dialing business lines with your eyes open about which of them are actually cell phones. This guide walks the line between the two. It is written by a software founder, not a lawyer, and it is not legal advice โ have counsel review your specific program before you dial.
Why cold outbound is the hard case
The Telephone Consumer Protection Act restricts calls to consumers that use an automatic dialing system or an artificial or prerecorded voice. In February 2024 the FCC issued a declaratory ruling confirming that AI-generated voices count as artificial voices for TCPA purposes. That ruling did not invent a new restriction; it closed off the argument that a conversational AI is different from a recording because it improvises.
The consequence is that the consent bar for an AI sales call is the high one. Prior express written consent means a signed or clicked agreement, tied to the specific number, that discloses the person will receive autodialed or artificial-voice marketing calls, and that says consent is not a condition of buying anything. Cold calling is the practice of contacting people who have not done that. The two ideas do not overlap.
This is also the area where getting it wrong is expensive in a way that most compliance topics are not. The TCPA carries a private right of action with statutory damages of $500 per violating call, rising to $1,500 per call for willful or knowing violations, with no cap on how many calls a single suit can cover. A dialer is dangerous precisely because it can put a bad list through that meter faster than a room full of people could. Our companion guide on what the rules require walks the full obligation set in detail at getleadfriendly.com/blog/ai-voice-agents-and-tcpa-compliance.
"It's B2B, so the TCPA doesn't apply" is the most expensive mistake
This is the belief we hear most often, and it is half true in a way that makes it worse than a clean misunderstanding. The TCPA's restriction on artificial and prerecorded voice calls to residential lines is aimed at homes, and the National Do Not Call Registry is for residential and personal numbers rather than business ones. On a landline-only view of the world, B2B calling really does sit outside a lot of this.
The problem is that the separate restriction on autodialed and artificial-voice calls to wireless numbers does not care who pays the bill. A cell phone is a cell phone whether the subscriber is a consumer or a two-truck plumbing company. And for small businesses โ the exact segment most AI cold-calling pitches target โ the number on the website is very often the owner's mobile. A B2B list of small businesses is frequently, in practice, a list of cell phones.
So the useful version of the rule is not "B2B is exempt." It is: know which numbers on your list are wireless, and treat those as consumer numbers for consent purposes. That requires line-type lookup on the list before anything dials it, and it requires accepting that a meaningful share of your list will fail that check. Several states also run their own mini-TCPA statutes with their own consent requirements and their own private rights of action, and those vary in how they treat business numbers, so a federal-only analysis is not a complete one.
Four exemptions people misread
Most bad cold-calling programs are not built on defiance. They are built on an exemption that someone read too generously. These are the four we see cited most.
The pattern across all four is the same: an exemption that exists for one purpose gets stretched to cover consent for artificial-voice calls, which it does not do. If your defense of a campaign rests on one of these readings, get it in front of counsel before it dials, not after.
- Established business relationship. An EBR can exempt a telemarketing call from Do Not Call Registry rules, but it is not a substitute for the prior express written consent an artificial-voice marketing call needs. Having sold someone a furnace in 2023 does not authorize an AI sales call to them today.
- "It's informational, not marketing." Purely transactional and informational calls face a lower consent bar than marketing ones. But the test is the content and purpose of the call, not the label on your campaign. An appointment reminder that pivots into a pitch is a marketing call.
- Purchased "opt-in" leads. Buying a list does not buy you consent unless you can produce, per number, the record of what that person agreed to, when, on what page, and for whom. If the vendor cannot hand you that artifact, you have no defense to put in front of a jury.
- Partner or shared consent. A rule that would have required consent to be given to one seller at a time was struck down by a federal appeals court in early 2025, which left this area unsettled rather than settled in marketers' favor. Treat "they consented to our partner network" as contested ground and verify the current state of the law with counsel.
What is actually legal โ and works better
The reason we are relaxed about all of the above is that cold AI dialing is not where the returns are anyway. Almost every calling program we have watched perform well is built on people who just took an action, and those calls are both legal and far more likely to be answered.
The single highest-value move on that list is the first one. A form fill that gets a call back inside a minute reaches someone who is still on your website thinking about the problem. The same number called cold on a Tuesday afternoon does not. Speed on consented leads beats volume on unconsented ones by a margin that makes the legal question mostly academic.
- Calling back a lead who just submitted your form, where the form disclosed that you will call the number given. This is the workhorse and it is not cold calling.
- Answering your own inbound calls with AI. The consumer placed the call, so the outbound consent framework is largely not what you are navigating โ state call-recording consent and honesty about what the caller is talking to still are.
- Cold email, which sits under CAN-SPAM rather than the TCPA and has a genuinely lower bar: accurate headers, honest subject lines, a physical address, and a working unsubscribe you honor promptly.
- Calling verified business landlines that you have screened against your own do-not-call list, understanding that state law and the FTC's telemarketing rules can still reach these calls.
- Re-engaging your existing customer base for service and transactional purposes, on numbers where you hold a consent record you could produce on request.
Making outbound survive an audit
If you do run consented outbound, the failures that cause problems are almost never subtle legal misreadings. They are plumbing. The consent lived in one system and the dialer read from another. The scheduler used the account's time zone instead of the number's. Someone said stop on a text and the call campaign never heard about it.
The controls below are the ones worth verifying in software rather than trusting to process, because every one of them fails silently. Ask any vendor to demonstrate the enforcement rather than describe it: make them try to schedule a call outside the permitted window and show you the system refusing.
- Line-type and DNC scrubbing on every list, at import and again before each campaign โ not once, ever.
- Calling windows enforced in the called party's local time, derived from the number rather than your account settings.
- Opt-out state stored on the contact record so every channel and campaign reads the same answer, and revocation through any reasonable means is honored across the whole program.
- AI disclosure in the agent's opening, and an immediate handoff to a human whenever the caller asks for one.
- Retained consent artifacts โ the timestamp, the source page, the exact language agreed to, the call log โ kept long enough to cover a four-year statute of limitations.
How we handle this at Lead Friendly
Lead Friendly is a voice-first agentic CRM, so this question is not academic for us โ we had to decide what our own software will and will not let a customer do. The answer we landed on is that leads sourced automatically from public directories are email-only in our platform. They cannot be dialed, because we cannot produce a consent record for them, and no amount of customer demand makes that record exist. Speed-to-lead callback on your own form fills, inbound answering, and follow-up to contacts you own are what the calling layer is built for.
Around that, the guardrails run in the calling layer rather than in a policy document: calls are gated to the permitted local-time window for the number being called, do-not-call and opt-out state lives on the contact so SMS and voice cannot disagree, AI disclosure is part of the agent's opening, and 10DLC registration for SMS follow-up is walked through during onboarding. Plans start at $49/mo for Starter, with Pro at $99 and Agency at $199, and there is a 7-day free trial with 30 voice minutes that does not ask for a card โ the current breakdown is at leadfriendly.com/pricing.
What no vendor can honestly claim, us included, is that their software makes you compliant. Software can enforce timing, hold the record, and honor an opt-out consistently, which is most of the operational risk. It cannot verify that the consent you imported was real, and it cannot replace a lawyer reading your scripts and your consent language before the first call goes out. Against a statute that prices mistakes at $500 a call, that review is the cheapest thing you will buy all year.
FAQ
Is AI cold calling legal in the United States?
Not for marketing calls to consumers without prior express written consent. The FCC confirmed in February 2024 that AI-generated voices are artificial voices under the TCPA, which means an AI sales call to a consumer needs the same signed, number-specific consent a prerecorded robocall would need. A cold list, by definition, does not have it. Calling people who just submitted your form, answering inbound calls, and screened business-landline calling are the versions that can be run lawfully. This is general information, not legal advice.
Does the TCPA apply to B2B cold calls?
Partly, and the part that applies is the part that catches people. The restriction on artificial-voice calls to residential lines and the Do Not Call Registry are aimed at consumers, but the restriction on autodialed and artificial-voice calls to wireless numbers applies regardless of whether the subscriber is a business. Small business numbers are very often the owner's mobile, so a B2B list is frequently a list of cell phones. Run line-type lookup before you dial, and check state mini-TCPA laws too.
Can I use an AI voice agent to call people who filled out a form on my website?
Generally yes, and this is the highest-value legal use of the technology. If the form disclosed that you will call the number provided, you are returning contact that the person initiated rather than cold calling. Keep the consent language on the form, retain the record of what was agreed and when, and still honor opt-outs, calling windows, and AI disclosure. A callback placed within a minute of the submission also converts far better than the same number dialed cold.
What are the penalties for illegal AI calling?
The TCPA provides a private right of action with statutory damages of $500 per violating call, rising to $1,500 per call for willful or knowing violations, with no cap on the number of calls in one suit. Several states have their own statutes with additional exposure. Because damages accrue per call rather than per campaign, an automated dialer working an unconsented list can build significant liability in days, which is why list hygiene matters more than any other single control.
Lead Friendly is the agentic CRM behind this site โ its AI answers every missed call, calls new leads back in seconds, and books the appointment. See it live at leadfriendly.com โ Plans from $49/mo.