United States — Federal
FCC Rules on AI-Generated Robocalls and Voice Cloning
A cloned voice isn't a loophole in the TCPA — the FCC settled that in February 2024. Here's what the ruling actually changed, what triggered it, and the one part of the story that's still just a proposal.
On February 8, 2024, the FCC settled a question that a lot of people had assumed was still open: does a robocall made with an AI-cloned voice count as an "artificial voice" under the Telephone Consumer Protection Act, or does it slip past that definition because it sounds human instead of robotic? In a Declaratory Ruling (FCC 24-17, CG Docket No. 23-362), the Commission said it counts. Nothing about the TCPA's consent requirements changed as a result — they didn't need to. What changed is that the argument for treating AI-generated voices as something outside the statute's reach no longer has anywhere to stand.
That distinction is worth sitting with, because it's the part most coverage of "the FCC banned AI robocalls" gets loose. The FCC didn't write a new AI law. It read an old one, correctly, onto new technology.
The call that made the question urgent
The ruling didn't come out of a routine rulemaking calendar. Days before the January 23, 2024 New Hampshire presidential primary, thousands of voters got a robocall using a voice cloned to sound like President Biden, with the caller ID spoofed to look like it came from a local Democratic party official. The message told recipients not to vote in the primary — to "save your vote" for the general election in November, a statement with no basis in how New Hampshire's primary actually worked.
Political consultant Steve Kramer later admitted he directed the calls, saying he wanted to draw attention to the risks of AI in politics. The FCC and New Hampshire's attorney general didn't treat that explanation as a defense. The calls went to real voters, three days before a real election, using a real politician's cloned voice without his knowledge or consent — and they landed at a moment when the underlying legal question (does the TCPA even reach this) was genuinely unresolved enough that a bad actor could plausibly argue it didn't. The FCC moved fast specifically to close that argument before it could be tested and normalized in a presidential election year. A declaratory ruling, rather than a full notice-and-comment rulemaking, let it do that in weeks rather than the better part of a year.
What the ruling changed, precisely
The TCPA, at 47 U.S.C. § 227(b)(1), already restricted calls to residential lines made using an "artificial or prerecorded voice" — requiring prior express consent for such calls generally, and prior express written consent specifically when the call includes telemarketing content. None of that language mentions AI, because it predates AI voice synthesis by decades. The open question was whether a voice generated or cloned by an AI model falls inside "artificial voice" as written, or whether the term implicitly meant something more mechanical-sounding — a distinction a caller might exploit by arguing a sufficiently realistic AI voice isn't "artificial" in the way the statute means.
The FCC's ruling forecloses that argument directly: current AI voice-generation technologies fall within the existing TCPA definition, full stop. Practically, that means a business, campaign, or scammer using an AI voice agent for outbound calls needs exactly the same consent the TCPA already required for a traditional recorded message — no new tier, no lighter standard because the voice sounds more natural, no argument that realism buys an exemption. The ruling also matters for enforcement reach beyond the FCC itself: state attorneys general have long had authority to bring TCPA claims, and a definition that unambiguously covers AI voices gives them a clean, litigated basis to use it, rather than fighting the definitional question in every individual case.
Two defendants, two separate penalties
The aftermath of the New Hampshire calls shows something else the "FCC banned AI robocalls" framing tends to skip: liability didn't stop at the person who made the calls.
The FCC proposed a $6 million fine against Kramer directly, and he separately faced 26 felony and misdemeanor charges in New Hampshire state court for voter suppression and impersonating a candidate. But the calls didn't reach voters' phones on Kramer's own infrastructure — they moved through Lingo Telecom, a carrier that originated the traffic onto the telephone network. Lingo Telecom settled with the FCC for $1 million, roughly half of what the agency had originally sought, and agreed to future compliance obligations built around STIR/SHAKEN — the caller ID authentication framework that requires carriers to verify and attest that a call's displayed number actually belongs to the customer placing it. Lingo's exposure wasn't for making the calls; it was for the caller ID authentication gap that let spoofed, deceptive Caller ID through its network in the first place.
For any business using or reselling AI voice-calling technology, that split matters: the caller and the carrier carrying the traffic can both end up independently on the hook, for different legal theories, from the same set of calls.
The part that's still just a proposal
Here's where a lot of secondary coverage runs the two FCC actions together as if they were one ruling. They aren't. Six months after the February declaratory ruling, in August 2024, the FCC adopted a separate Notice of Proposed Rulemaking (FCC 24-84, same docket) that would go further — requiring callers to affirmatively disclose, inside the call itself, that the voice the recipient is hearing was AI-generated, and adding parallel consent-disclosure requirements for text messages that include AI-generated content. The draft would also carve out an exemption for people with speech or hearing disabilities who use AI-generated voice to communicate, as long as the call isn't an unsolicited advertisement.
That NPRM went through public comment and reply-comment periods in the fall of 2024. As of this writing, it has not been adopted as a final rule, and the FCC's current leadership has signaled a lighter regulatory posture generally, which makes near-term finalization far from certain. The practical upshot: there is currently no binding federal requirement that an AI voice call identify itself as AI. The only thing that's actually in force is the February 2024 clarification that ordinary TCPA consent rules apply — nothing about mandatory in-call disclosure.
Where a real call center runs into this today
Take a mid-size accounts-receivable firm, Castellan Recovery Partners, evaluating an AI voice-agent vendor to place outbound payment-reminder calls instead of relying on live agents for every call. Because the vendor's synthetic voice is now unambiguously an "artificial voice" under the confirmed TCPA reading, Castellan needs prior express consent before placing any such call to a residential line — typically satisfied if the original credit agreement includes a calling-consent clause, but worth re-checking against the TCPA's actual consent scope rather than assuming any old contract language covers it. If any call includes account-upsell or new-product content rather than a pure payment reminder, that call needs prior express written consent instead, a materially higher bar.
Castellan itself doesn't carry STIR/SHAKEN obligations directly — those run through whichever carrier originates its calls onto the network — but it should confirm its telephony vendor is actually compliant, given that Lingo Telecom's settlement shows a carrier's authentication gap creates its own independent exposure. And Castellan has no current legal obligation to have its AI agent announce "you're speaking with an AI" mid-call, since that requirement exists only in the still-pending NPRM. Several states have begun layering their own AI-disclosure requirements on top of federal law, so a multistate caller like Castellan should check state law separately — this article covers the federal baseline, not every state's overlay.
What this means in practice
If you're deploying AI voice technology for outbound calling, treat consent exactly as you would for any pre-recorded message: classify the call as informational or telemarketing first, and get the matching consent tier before you dial, because "it sounds like a real person" was never going to be a defense once the FCC ruled on it. If you're a carrier, understand that Caller ID authentication failures create liability that's separate from, and additional to, whatever the calling party did — the FTC's own AI enforcement record shows the same pattern of an agency reaching AI-enabled conduct through old, technology-neutral authority rather than waiting for a purpose-built AI statute, and the FCC's approach here follows the identical logic. And if you're tracking this space for compliance purposes, keep the two proceedings straight: the consent rule is binding now, and the disclosure rule is not yet anything more than a draft. For the fuller federal picture — how the FTC, EEOC, CFPB, SEC, and FDA are each applying decades-old statutes to AI conduct without a comprehensive AI law from Congress — see our overview of US federal AI regulation, which places the FCC's approach here alongside the SEC's parallel theory that overstating AI capabilities is ordinary securities fraud, not a new category of violation.
Frequently asked questions
- Did the FCC create a new law specifically banning AI voices in robocalls?
- No. The FCC's February 8, 2024 Declaratory Ruling (FCC 24-17, CG Docket No. 23-362) interpreted the existing TCPA definition of 'artificial or prerecorded voice' to include AI-generated voices — it didn't enact a new AI-specific statute or rule. The TCPA's existing consent requirements simply now unambiguously apply to AI-voice calls the same way they apply to any other artificial-voice call.
- What triggered the FCC's ruling?
- Robocalls sent to New Hampshire voters days before the January 23, 2024 presidential primary, using an AI-cloned voice of President Biden and spoofed caller ID, telling recipients not to vote in the primary and to save their vote for November. Political consultant Steve Kramer admitted directing the calls.
- What penalties actually resulted from the New Hampshire case?
- The FCC proposed a $6 million fine against Steve Kramer, who also faced New Hampshire state felony and misdemeanor charges for voter suppression and candidate impersonation. Separately, carrier Lingo Telecom, which transmitted the calls onto the network, settled with the FCC for $1 million and agreed to stricter STIR/SHAKEN caller-ID authentication practices.
- Does the law require companies to tell call recipients they're talking to an AI?
- Not yet, at the federal level. The FCC proposed such a disclosure requirement in an August 2024 Notice of Proposed Rulemaking (FCC 24-84), but as of this writing that proposal hasn't been adopted as a final rule. The only binding obligation today is the pre-existing TCPA consent requirement the February 2024 ruling confirmed covers AI-generated voices.
- Does this ruling apply to AI-generated text messages too, or only voice calls?
- The February 2024 declaratory ruling addressed voice calls specifically. The pending August 2024 NPRM proposes extending consent-disclosure requirements to autodialed text messages containing AI-generated content, but that proposal, like the voice-disclosure proposal, hasn't been finalized.
Sources & references
- Official source
- FCC — Declaratory Ruling, CG Docket No. 23-362 (FCC 24-17, released Feb. 8, 2024)
- FCC — 'FCC Makes AI-Generated Voices in Robocalls Illegal'
- FCC — Notice of Proposed Rulemaking, CG Docket No. 23-362 (FCC 24-84, adopted Aug. 7, 2024)
- FCC — Proposed $6,000,000 fine against Steve Kramer for AI-generated robocalls
- FCC — Lingo Telecom consent decree ($1 million settlement)
- NPR — 'Criminal charges and FCC fines issued for deepfake Biden robocalls' (May 23, 2024)
Suggested next reading
regulations us
US Federal AI Regulation: What Actually Exists Today
regulations us