Compliance

Is AI Cold Calling Legal? TCPA, GDPR & B2B Compliance Guide 2026

Mostly yes, for B2B, in the United States — and the word doing the work in that sentence is “mostly”. The rules that catch people out are not the ones about whether AI calling is allowed. They are the ones about consent, mobile numbers and who carries the liability when something goes wrong.

Updated September 12, 2026 · 11 min read

This is not legal advice. It is a plain-English map of the rules that apply to outbound calling, written by an operator rather than a lawyer. Telephone consumer protection law is jurisdiction-specific and changes; before you run a campaign, get advice for your industry, your states and the countries on your list.

The short answer

Using AI to make B2B cold calls is generally lawful in the United States. What makes a specific call unlawful is the circumstances around it, not the fact that a machine placed it. Calling a number on the Do Not Call Registry, using an artificial voice to reach a mobile without prior express consent, calling outside permitted hours, ignoring an opt-out, or failing to disclose where your state requires it — those are the violations.

The second thing to be clear about is who is on the hook. Liability attaches to the caller, not to the software vendor. If a platform tells you it makes you compliant, it is describing something it is not able to do.

The ruling that changed the question

In February 2024 the FCC issued a declaratory ruling that AI-generated voices count as an artificial or prerecorded voice under the TCPA. That single classification is the most important fact on this page, because the TCPA already had a well-developed set of restrictions on artificial and prerecorded voice calls — and AI calling inherited all of them at once.

The practical consequence is about mobile numbers. The artificial-voice restriction turns on prior express consent for calls to mobile numbers, and it is a separate provision from the Do Not Call Registry rules. It is not limited to residential lines. Since a large share of B2B direct-dial numbers are mobiles, “we only call businesses” does not answer the question by itself.

Is there a B2B exemption?

Not a single blanket one, and believing otherwise is the most expensive misunderstanding in outbound. There are two separate sets of rules and they have different scopes.

The Do Not Call Registry protects residential subscribers. Calls to genuine business lines generally sit outside it, which is the grain of truth the “B2B exemption” idea grew from.

The artificial and prerecorded voice restrictions are a different provision with a different scope, and they are not limited to residential numbers. A business contact reached on their mobile is not automatically fair game because the call is commercial.

Handle them as two questions rather than one. State registries add a third layer, and some are stricter than the federal baseline.

Who is responsible for what

This is the part most vendor pages leave vague, so here it is as a table. On any plan where you provide the list, you are the caller of record and the data controller. That is a contractual position, not a marketing one, and it is set out in full in our TCPA Compliance Policy.

ObligationWhose job
Scrubbing against the National DNC RegistryYou
Scrubbing against applicable state registriesYou
Obtaining consent for mobile numbersYou
Keeping consent and opt-out recordsYou
AI disclosure in the call script, where requiredYou
Lawful basis for the personal data you uploadYou
Calling-hour restrictionsDialsDone, by default
In-call opt-out detectionDialsDone, by default
Do-not-call loggingDialsDone, by default
Call recordings and transcripts for your recordsDialsDone, by default
Sourcing prospects on Pay Per MeetingDialsDone
List building and scrubbing as a paid serviceDialsDone, if you ask

Read the left column as the work and the right column as the liability. DialsDone does not scrub lists on your behalf unless you buy that as a separate service, and no plan converts your obligations into ours. If you want the sourcing side handled, that is what Pay Per Meeting is — you supply an ideal customer profile rather than contacts, and the prospecting responsibility moves with the work.

Telling people they are talking to AI

Several US states require a caller to disclose that it is not human, and the number requiring it has been growing. The requirements are not uniform — they differ on wording, on timing, and on which kinds of calls are covered — so the honest instruction is to check the states you actually call into rather than to trust any vendor’s blanket assurance, including ours.

On DialsDone the disclosure lives in the script you write, and the platform does not insert one for you. That is deliberate: the wording that satisfies a given state is a legal judgement about your campaign, not a default we can safely choose on your behalf.

Worth saying separately: even where nothing requires it, disclosing early tends to improve calls rather than end them. A prospect who works out mid-sentence that they have been talking to a machine reacts to the concealment, not to the technology.

Calling into the EU and the UK

There is no single European answer, and anyone offering one is simplifying something that is genuinely fragmented.

Under GDPR you need a lawful basis for processing the personal data on your list. Some member states accept legitimate interest for B2B outreach, subject to a balancing test you should be able to evidence. Others are markedly stricter. Several maintain corporate opt-out registers you are expected to screen against before calling, and the penalties for skipping that step are not theoretical.

In the UK, PECR sits alongside GDPR and draws a distinction between corporate subscribers and individuals — including sole traders and many partnerships, who get treated closer to individuals than the word “business” suggests. Screening against the Corporate Telephone Preference Service is part of the baseline.

If your list spans several countries, the practical approach is to segment it by jurisdiction and get advice per market, rather than to run one campaign against the loosest rule you can find.

Running a campaign that holds up

None of this is onerous once it is a routine. In order, before a single call goes out:

  • Scrub the list first — national registry, then any state registries that apply. Before upload, not after.
  • Know which numbers are mobiles and hold consent for those. This is the step most campaigns skip, and it is the one the artificial-voice rule turns on.
  • Put disclosure in the script where your states require it, at the top of the call.
  • Set calling hours to the prospect’s local time, not your own. A compliant hour in your timezone can be an unlawful one in theirs.
  • Honour opt-outs immediately and across every channel. An opt-out on a call has to suppress the contact in your email tool too, which means the suppression list cannot live inside one vendor.
  • Keep the records — consent, opt-outs, and when each was captured. Disputes turn on what you can evidence, not on what you did.

Most of the risk is decided before you dial, in the quality and provenance of the list. That is the subject of our guide to building a B2B calling list, and the compliance obligations differ by channel too — see cold email vs cold calling for how the email rules diverge from these.

Common questions

Is AI cold calling legal?

For B2B outreach under US law it is generally permitted, and TCPA restrictions are looser for business-to-business calls than for consumer calls. But the rules still apply. The FCC ruled in February 2024 that AI-generated voices count as an artificial or prerecorded voice under the TCPA, which means you must disclose AI where required, honour opt-outs, respect calling hours, and hold consent for mobile numbers. This is not legal advice, and the answer depends on your jurisdiction and who you are calling.

Is AI cold calling illegal?

Not in itself. What makes a call unlawful is the circumstances around it — calling a number on the Do Not Call Registry, using an artificial voice to reach a mobile number without prior express consent, calling outside permitted hours, ignoring an opt-out, or failing to disclose where disclosure is required. The technology is not the violation; how it is pointed at a list can be.

Is there a B2B exemption from the TCPA?

There is no single blanket B2B exemption, which is the most common and most expensive misunderstanding. The National Do Not Call Registry protects residential subscribers, so calls to genuine business lines generally sit outside it. The artificial and prerecorded voice restrictions are a separate provision and are not limited to residential numbers — so a business contact reached on their mobile is not automatically fair game just because the call is B2B. Treat the two rules separately rather than assuming one exemption covers both.

What makes an AI calling platform TCPA compliant?

Strictly speaking, a platform cannot be compliant on your behalf, because compliance attaches to the caller rather than the tool. What a platform can do is provide controls that make compliant calling possible: calling-hour restrictions, in-call opt-out detection, and do-not-call logging, which is what DialsDone provides by default. What it cannot do is obtain consent for you, scrub your list, or put a disclosure into a script you wrote. Be suspicious of any vendor claiming their product makes you compliant automatically.

Do I have to disclose that the caller is AI?

In several US states, yes, and the number of states requiring it has been growing. Even where no statute requires it, disclosing at the start of the call is widely treated as best practice and tends to make the conversation go better rather than worse. On DialsDone this belongs in the script you write: the disclosure line is your responsibility, and the platform does not insert one for you. Check what your states require, because the requirements are not uniform.

Do I need consent to call a mobile number?

For calls using an artificial or prerecorded voice — which, since the FCC's February 2024 ruling, includes AI-generated voices — prior express consent is the operative requirement for calls to mobile numbers, and it is not waived by the call being business-to-business. Since a large share of B2B direct-dial numbers are mobiles, this is usually the most important question to answer before a campaign rather than after it. Obtaining and recording that consent is the caller's responsibility.

Can I use AI cold calling into the EU or the UK?

You need a lawful basis under GDPR for the personal data you are processing, and the ePrivacy rules in each country add their own requirements for unsolicited calls. Some member states allow legitimate interest for B2B outreach; others are considerably stricter, and several maintain corporate opt-out registers you are expected to screen against. The UK's PECR draws a distinction between corporate subscribers and individuals that changes the answer depending on who you are calling. There is no single European answer, so get advice for the specific countries on your list.

What does a compliant B2B AI calling campaign look like in practice?

Scrub the list against the National Do Not Call Registry and any applicable state registries before you upload it. Know which numbers are mobiles and hold consent for those. Put a disclosure at the top of the script where your states require it. Set calling hours to the prospect's local time, not yours. Honour opt-outs immediately, permanently, and across every channel you contact people on. Keep records of consent and of opt-outs, because the ability to evidence them is what a dispute turns on.

Does DialsDone scrub my list for me?

No, and no plan where you provide the list changes that. You remain the caller of record and the data controller: scrubbing against the National Do Not Call Registry and state registries, obtaining consent where it is required, and keeping consent records are yours. DialsDone can build and scrub a list as a separate paid service if you ask for it, and on Pay Per Meeting, where we source the prospects, that sourcing is our responsibility. Otherwise the division is exactly as set out in our TCPA Compliance Policy.

Controls, not promises

DialsDone ships calling-hour restrictions, in-call opt-out detection and DNC logging by default, and publishes exactly where our responsibility ends. Read the policy before you read the pricing.

Related reading

DD

The DialsDone Team

Published by DialsDone Team · July 17, 2026 · Updated September 12, 2026

The DialsDone team builds AI phone agents and runs a human cold calling service. We publish our compliance position as policy rather than marketing, because our customers are the callers of record and need to know exactly where our responsibility ends.