Skip to main content
Governance10 min read

AI calling and outbound rules: US, Australia, UAE and India

What changes when an outbound workflow uses an AI voice — and the controls to build before it calls anyone.

A controlled operations workflow being reviewed at a desk.

The short answer

AI calling is not governed by one global rulebook. It is governed by the recipient's market, the purpose of the call, the technology used and the evidence you retain. Treat consent and preference evidence, suppression, calling-time controls, identity and recording notices, retry limits and human escalation as product requirements. In the United States, the FCC has said AI-generated voices fall within TCPA artificial-or-prerecorded-voice rules; Australia regulates telemarketing and electronic marketing through different regimes; the UAE expressly permits automated systems only within its telemarketing controls; and India combines TRAI's commercial-communications rules with a phased data-protection framework. This is an operational overview, not legal advice.

A voice agent does not turn a marketing call into a software feature. It turns it into a regulated operation with a faster failure mode: one bad list, a missing opt-out or a retry rule that ignores local time can be repeated at machine speed. The right question is not whether an AI agent is allowed to call. It is what the specific campaign is, where the recipient is, what permission or exception applies, and what the system will do when the recipient says no.

An operating guide, not a legal opinion
This article is for designing controls and preparing a proper legal review. It is not a substitute for counsel. Sector rules, state or territory rules, the exact call script, the data source and the recipient's location can all change the answer. Do not launch a new market from a blog post — including this one.

Build the control plane before the conversation

  1. 1Classify each campaign before launch: marketing, servicing, collections, research, appointment reminder or another purpose. Do not let one campaign label cover all of them.
  2. 2Record the lawful contact basis or applicable permission with the phone number, source, date, scope, channel, language and seller or brand. A lead form is not useful evidence if it does not say what the person agreed to receive.
  3. 3Screen every dial list against the relevant do-not-call, preference and internal suppression records immediately before use. A recipient's direct opt-out must take priority over any marketing workflow.
  4. 4Enforce local time windows, holiday restrictions, retry limits and answer-machine or abandonment rules in the dialler — not in a training deck.
  5. 5Start transparently: identify the company and purpose, provide any required recording notice, and make a stop request easy to understand and execute.
  6. 6Route uncertainty, distress, complaints, disputes and requests outside the approved script to a trained human. An AI agent should never improvise a legal, financial, medical or employment answer.
  7. 7Keep an auditable event trail: list version, consent or preference record, attempted and connected calls, script version, recording notice, opt-out, disposition and the human escalation outcome.

United States: an AI voice is not a TCPA loophole

The FCC's February 2024 declaratory ruling says AI-generated voices are “artificial” under the Telephone Consumer Protection Act. For telemarketing or advertising calls using an artificial or prerecorded voice, FCC materials describe a prior-express-written-consent requirement for wireless numbers and residential lines, subject to the statute, rules and applicable exceptions. The FCC's consumer guidance also says its do-not-call protections apply to telemarketing calls regardless of the technology used.

  • Treat the consent record as campaign-specific evidence: the seller, phone number, technology or voice category and marketing purpose should be clear enough for counsel to test.
  • Run both national and company-specific do-not-call suppression. The FTC says telemarketers need a process using a National Registry version downloaded no more than 31 days before a call to use the relevant safe harbour.
  • Make revocation immediate in your own system. Do not wait for a CRM export or a weekly list refresh before suppressing the number.
  • Have US counsel review state laws and sector overlays before going live. TCPA is not the only source of exposure, and the facts of each call matter.

Australia: separate voice telemarketing from SMS and email

Australia has a useful split that product teams often miss. Live or synthetic voice telemarketing sits under the Do Not Call framework and the Telecommunications (Telemarketing and Research Calls) Industry Standard 2017. The standard expressly treats the voice-call definition as including recorded or synthetic voice. Commercial SMS and email follow the Spam Act 2003 instead, with their own consent, sender-identification and unsubscribe requirements.

  • Before a telemarketing run, check the Do Not Call Register and your own suppression records. ACMA says that, after a number has been on the register for 30 days, telemarketers may call only with consent or where an exemption applies.
  • Encode the national calling-time guardrails: generally not before 9 am or after 8 pm on weekdays, 9 am to 5 pm on Saturdays, and not on Sundays or listed national public holidays. The standard also points to possible state and territory restrictions.
  • For SMS and email follow-up, do not recycle telemarketing permission without checking the Spam Act basis. The Act requires consent, accurate sender information and a functional unsubscribe facility for commercial electronic messages with an Australian link.
  • Keep the consent terms understandable: ACMA recommends express consent with clear terms explaining what the marketing is, who will use it, how long it will be used and how it can be withdrawn.

United Arab Emirates: automated systems are allowed inside strict telemarketing controls

UAE Cabinet Resolution No. 56 of 2024 applies to licensed companies, including free-zone companies, marketing products or services by telephone. It requires prior approval from the competent authority, local numbers registered under the company's commercial licence, a record of marketing calls and respect for the Do Not Call Registry. It also expressly says automated communication systems may be used for marketing only in accordance with the resolution's controls.

  • Call only from 9:00 am to 6:00 pm, identify the company and call purpose at the start, and ask whether the consumer wishes to continue before starting the marketing message.
  • Do not re-contact someone who rejects the product or service on the first call. If someone does not answer or ends a call, do not call back more than once a day or twice a week.
  • Do not call numbers on the Do Not Call Registry, and retain the records needed to demonstrate your calling operation. The resolution also requires a recording notice when a marketing call is recorded.
  • Treat financial services, insurance and securities as a separate launch path: their competent regulators may impose additional approval and conduct requirements.

India: commercial-communication controls plus personal-data design

TRAI's Telecom Commercial Communication Customer Preference Regulations (TCCCPR), 2018 are designed to prevent unsolicited commercial communication while allowing legitimate communications in line with customer preferences or opted services. TRAI's 2025 amendments strengthened its response to unregistered senders, misuse of ordinary phone numbers, robotic or auto-dialled calls and pre-recorded announcements. A production system should treat sender registration, preference and consent evidence, template or content controls, complaint handling and suppression as deploy-time controls rather than a later compliance project.

  • Before a commercial-voice launch, use the sender-registration and distributed-ledger (DLT) path required by the telecom ecosystem. TRAI's sender guidance covers principal-entity registration and the related header, content-template and consent artefacts where applicable.
  • Do not route high-volume commercial outreach through an ordinary number to avoid those controls. The 2025 amendments specifically address misuse of ordinary numbers, robotic calls, auto-diallers and pre-recorded announcements.
  • Engineer a reliable stop path and abandonment controls. A campaign that cannot honour a preference or generates silent calls is an operational failure even before it becomes a complaint.

The data layer needs its own design. India notified the Digital Personal Data Protection Rules, 2025 in November 2025 with staged commencement. As at 4 September 2026, the notification schedules the core notice, consent, processing, security and data-principal-rights rules for 18 months after publication — 13 May 2027. Build the clear notice, specific-purpose, withdrawal, retention, access and deletion pathways now; do not wait for a campaign to become the migration plan.

The smallest safe launch checklist

Evidence table for this field note
Before the first callWhat the system must be able to prove
Market and campaign classificationRecipient market, call purpose, responsible seller, applicable rules and counsel sign-off.
List approvalSource of every number, permission or exception record, list version and suppression results.
Conversation approvalApproved script, identity and recording notice, opt-out wording, escalation triggers and prohibited claims.
Dialler guardrailsLocal hours, holidays, retry cap, do-not-call checks, rate controls and a tested kill switch.
After-call governanceDisposition, opt-out propagation, recording/log access, complaint route and periodic audit owner.
What we will and will not build
We can build the consent ledger, preference checks, suppression APIs, time-zone and retry controls, approved scripts, audit trail and human handoff. We will not decide that a client has a lawful basis to call a person. That decision belongs to the client and its qualified local advisers, before the workflow is switched on.

Sources and further reading

  1. 01FCC — AI-generated voices fall within TCPA artificial-voice rules (Feb. 2024)
  2. 02FCC — consumer guide to robocalls, AI, consent and Do-Not-Call protections
  3. 03FTC — complying with the Telemarketing Sales Rule and Do Not Call process
  4. 04ACMA — Do Not Call Register
  5. 05Federal Register of Legislation — Telecommunications (Telemarketing and Research Calls) Industry Standard 2017
  6. 06Federal Register of Legislation — Spam Act 2003
  7. 07UAE Cabinet Resolution No. 56 of 2024 — Telemarketing Regulations
  8. 08UAE Ministry of Economy — telemarketing operating mechanisms and consumer protections
  9. 09TRAI — TCCCPR 2018
  10. 10TRAI — sender guidance for commercial communications
  11. 11TRAI — 2025 amendments to TCCCPR 2018
  12. 12MeitY — Digital Personal Data Protection Rules, 2025 notification
An operations lead reviewing a flagged exception in a workflow map.

From reading to doing

Bring one workflow into focus.

Take the next step with a practical scorecard, or talk through your process with the team that would help build it.