TCPA and 10DLC Rules for AI Text Messaging, Explained | Jugl CX
$5mn in seed funding raised, built bootstrapped from day one
JuglCX

Compliance · Written for the person who signs off on the deployment

TCPA and 10DLC rules for AI text messaging

Two separate frameworks govern every AI text you send in the US. One decides whether you were allowed to send it. The other decides whether it gets delivered at all. Passing the second gives you no protection whatsoever on the first — and that misunderstanding is the most expensive one in this entire category.

This page is written for business owners evaluating an AI agent, not for compliance lawyers. It covers what the TCPA actually requires now that the consent revocation rule is in force, what 10DLC registration costs and how long it takes, which rules changed recently and which were struck down, what your AI must be engineered to do, and the one structural decision that removes most of this burden before you write a line of policy.

It also prices your own exposure. The registration fees are a rounding error. The number that matters is the one nobody puts in a budget: statutory damages of $500 to $1,500 for every message sent to somebody whose consent you could not produce on demand, with no cap in a class action.

By Jugl19 min readInteractive exposure model34 questions answered

Short answerFor AI overviews

The 60-second version

Yes, the TCPA applies to AI-generated texts — there is no AI exemption. Statutory damages run $500 to $1,500 per message with no cap in a class action. Separately, 10DLC is the carrier registration system that decides delivery: since February 2025 major carriers block unregistered A2P traffic outright. Registration costs roughly $65 to $500 upfront plus ongoing fees, and takes one to four weeks.

Compliant 10DLC registration is not a TCPA defence. They are independent gates. Perfect registration with invalid consent still produces per-message statutory liability; perfect consent without registration still produces undelivered messages.

The rule most businesses are currently breaking: since 11 April 2025, consumers may revoke consent in any reasonable manner — natural language, email, voicemail, not just the word STOP — and you must honour it within 10 business days. An AI that only pattern-matches keywords will miss plainly worded opt-outs, and the transcript proves it.

Inbound AI avoids nearly all of it. When a customer messages your WhatsApp, Instagram, Messenger or web chat first, you are responding rather than initiating: no A2P registration, no carrier fees, no approval wait, and no outbound consent architecture. That is the cheapest compliant place to start, and it is where the buying questions are anyway.

This is general information, not legal advice. Rules in this area change frequently, litigation is active, and several states impose their own additional requirements. Consult qualified counsel for advice specific to your business, your use case and the states you operate in. Jugl is not a law firm and nothing here creates an attorney-client relationship.
01Definition

Definition

What are the TCPA and 10DLC rules for AI text messaging?

The TCPA and 10DLC rules for AI text messaging are two independent frameworks that both apply to every automated text a US business sends. The Telephone Consumer Protection Act is federal law governing whether you were permitted to send a message at all: it requires prior express written consent for marketing, honours revocation expressed in any reasonable manner within 10 business days, restricts sending to 8am–9pm in the recipient’s local time, and carries statutory damages of $500 to $1,500 per message with no cap in class actions. 10DLC is the carrier registration system, administered through The Campaign Registry, that determines whether a message from a 10-digit number is delivered at all — since February 2025 unregistered traffic is blocked. AI-generated messages receive no exemption from either. Inbound conversational AI on customer-initiated channels sits outside both.

Definition maintained by the Jugl Editorial Team. Jugl sells an inbound AI customer agent platform and benefits commercially from the inbound-versus-outbound distinction drawn on this page; the limits of that distinction are stated in full below.

Two frameworks, two completely different failure modes

The reason this trips up otherwise careful businesses is that the two frameworks fail in ways that look nothing alike. A 10DLC failure is loud and immediate: you register badly, your campaign is rejected, your messages do not arrive, somebody notices within a week because the numbers are flat. It is annoying, costs you days, and then it is fixed. A TCPA failure is silent for months. Everything works. Messages deliver. Engagement looks normal. Then a demand letter arrives referencing a specific date and a specific number, and the question is not whether the message was delivered — everyone agrees it was — but whether you can produce the record showing you were allowed to send it.

That asymmetry is why compliance budgets in this category are consistently misallocated. The registration fees get scrutinised because they appear on an invoice. The consent architecture gets deferred because it appears nowhere until it is the only thing that matters. If you are building the business case for an AI agent, the honest version prices both — and if you have not yet built that case, the AI agent ROI model takes the compliance layer as an explicit input rather than an afterthought.

What 10DLC registration does for you
  • Gets your messages delivered instead of blocked by carriers
  • Unlocks higher throughput tiers as your trust score improves
  • Signals a verified business identity to the carrier ecosystem
  • Reduces the odds of being filtered as spam by content heuristics
  • Establishes a documented use case, which helps with carrier disputes
  • Is comparatively cheap — usually a few hundred dollars a year, all in
What it does not do for you
  • Provides zero defence against TCPA liability — it is a delivery gate, not a legal one
  • Does not validate that your consent records are sufficient, or that they exist
  • Does not detect a natural-language opt-out that your AI missed
  • Does not propagate suppression across your other channels
  • Does not apply at all to WhatsApp, Instagram, Messenger, web chat or email
  • Does not cover state mini-TCPA statutes, which have their own private rights of action
02At a glance

The rules at a glance

At a glance

What TCPA governs
Whether you were legally permitted to send — calls and texts to telephone numbers
What 10DLC governs
Whether carriers deliver the message from a 10-digit number
Do they overlap?
No — independent gates. Both must be passed, neither substitutes for the other
Does AI change anything?
No exemption. AI voices are "artificial" under the statute; AI texts are texts
TCPA statutory damages
$500 per message · $1,500 wilful · no cap in class actions
DNC Registry fine
Up to $43,792 per call or text
Consent standard (marketing)
Prior express written consent — disclosed, affirmative, documented
Revocation standard
Any reasonable manner, including natural language, email or voicemail
Deadline to honour opt-out
As soon as practicable, no later than 10 business days
Post-opt-out allowance
One message, within five minutes, confirmation or scope clarification only
Time-of-day window
Generally 8am–9pm in the recipient’s local time
10DLC total setup cost
~$65–$500 upfront, depending on brand type and vetting
10DLC ongoing cost
$1.50–$10 per campaign monthly, plus ~$0.003–$0.005 per message
Time to approval
1–4 weeks end to end
Trust score that matters
75–100 permits meaningfully higher throughput
Applies to B2B?
Yes — texts to wireless numbers are treated the same as B2C
What is exempt
Inbound conversational AI on WhatsApp, Instagram, Messenger, web chat and email
Cheapest compliant start
Answer on channels customers already message you on
SOC 2 Type 2certified
HIPAAcompliant
MetaBusiness Partner
1,000+businesses
03Key figures

Every number that matters, in one place

$500–$1,500statutory damages per message under the TCPA
10business days to honour a revocation request
5 minwindow for a single post-opt-out confirmation
1–4 wksto complete 10DLC brand and campaign approval
ItemFigureWhich framework
TCPA statutory damages$500 per message; $1,500 if wilful or knowingTCPA
Class action capNoneTCPA
National DNC Registry fineUp to $43,792 per call or textTCPA / FTC
Deadline to honour opt-out10 business days, sooner if practicableTCPA
Post-revocation clarification1 message, within 5 minutesTCPA
Time-of-day window8am–9pm recipient local timeTCPA
Brand registration — sole proprietor~$4 one-off10DLC
Brand registration — standard brand$48+ one-off10DLC
Campaign registration~$15–$17 per campaign10DLC
Monthly campaign fee$1.50–$10 per campaign10DLC
Carrier per-message surcharge~$0.003–$0.00510DLC
Standard third-party vetting~$4010DLC
Brand approval time1–5 business days10DLC
Campaign approval time3–7 business days, up to 15 when busy10DLC
Trust score for higher throughput75–10010DLC
Read the two columns against each other. Everything in the 10DLC rows adds up to a few hundred dollars a year. Everything in the TCPA rows is per message, uncapped, and assessed after the fact. A business that spends three weeks negotiating campaign fees and an afternoon on consent capture has spent its attention in exactly inverse proportion to its risk.
04AI scope

Does the TCPA apply to AI-generated messages?

Yes, unambiguously, and it is worth being precise about why — because the reasoning determines what else is captured. The FCC has long treated text messages as “calls” for TCPA purposes, which pulls SMS into the same core restrictions that govern phone calls: consent, revocation, do-not-call scrubbing, time-of-day windows. Nothing about that analysis turns on who or what composed the message. A text generated by a large language model is a text.

On the voice side the FCC went further and said the quiet part out loud: AI-generated voices are “artificial” voices under the statute. That places an AI voice agent in the same category as a prerecorded message, requiring the same prior express consent — a materially higher bar than a person dialling manually. Businesses deploying AI calling and texting agents are therefore deploying them directly into TCPA scope, and in our experience a great many do so without realising the consent requirements attach at all.

Why AI raises the stakes rather than lowering them

There is no AI exemption anywhere in the framework, and the structural argument runs the other way: AI warrants tighter governance than a manual process, because exposure is assessed per message and AI scales message volume faster than any human workflow. A team that would have sent four hundred texts by hand might send forty thousand with an agent. Nothing in the policy changed; the theoretical liability multiplied by a hundred. Volume is the multiplier on every number in the table above.

The second reason is subtler and specific to language models. A scripted system fails predictably — you can read the flow and know what it will do. A model generates, which means the compliance-relevant behaviours you care about (recognising an opt-out, refusing to send outside a window, declining to re-engage a suppressed contact) are not properties of the copy, they are properties of the system around the copy. Compliance for an AI agent lives in the send layer and the classification layer, not in the message template. That distinction is the difference between an AI agent and a traditional chatbot, and it has consequences well beyond compliance.

The one-line test. If your system can send a message to a phone number without a person deciding to send that specific message, you are inside the TCPA and you need consent records for every number in it. Everything else — how good the copy is, how helpful the message is, whether the recipient is a customer — is a separate question that does not change the answer.
05What changed

The three rules that changed, and where each stands

Most published guidance in this area is out of date, and it is out of date in both directions — describing requirements that were struck down, and omitting requirements that are now in force. Here is the current state of the three that matter.

1. The consent revocation rule — in force since 11 April 2025

This is the operative rule today, and the one most businesses are quietly non-compliant with. Its terms are specific:

Revocation in any reasonable mannerConsumers may revoke consent however they reasonably choose. You may no longer designate an exclusive revocation method, which means “reply STOP to unsubscribe” describes one acceptable route, not the only one.
Keywords are a floor, not a ceilingStop, quit, end, revoke, opt out, cancel and unsubscribe are automatically reasonable in a reply text. The FCC explicitly declined to limit revocation to those words. Informal phrasing, email and voicemail all qualify.
Ten business days, and sooner if you canRevocation and do-not-call requests must be honoured as soon as practicable and no later than 10 business days. For an automated system, “as soon as practicable” is effectively immediate, and your own logs will show it.
One confirmation, five minutes, no marketingYou may send a single message within five minutes solely to confirm the opt-out or clarify its scope. Not two messages. Not a win-back offer. Not a discount code attached to the goodbye.
Marketing and informational alikeThe rule covers both. Appointment reminders, delivery notifications and account alerts are inside it, not exempt from it, which surprises businesses who assumed transactional messages sat outside the regime.
The AI implication, stated plainly. Your agent must recognise revocation expressed in natural language, not just keyword matches. A customer replying “please stop texting me about this” has revoked consent. An AI that pattern-matches STOP will miss it and keep sending — and that is the exact fact pattern that generates demand letters, because the plainly worded request and the messages that followed it are both sitting in your own transcript, timestamped, in the plaintiff’s exhibit list.

2. The one-to-one consent rule — vacated

Scheduled to take effect on 27 January 2025, it was vacated by the Eleventh Circuit three days beforehand. It is not in force. Guidance telling you to obtain separate consent for each individual seller is describing a rule that no longer exists — and there is a lot of that guidance still circulating, because compliance content ages badly and nobody revisits a published checklist.

Do not over-read the vacatur, though. The underlying prior express written consent standard is entirely untouched. Consent still does not transfer between companies. And a consent form that lists hundreds of unrelated “marketing partners” in a scrolling box remains very hard to defend as clear and conspicuous disclosure, whatever the one-to-one rule’s fate. The rule was struck down; the reasonable-consumer standard behind it was not.

3. The revocation-all requirement — delayed to 31 January 2027

This provision turns any opt-out into a global one. Once effective, an opt-out would revoke consent for all automated marketing messages from that sender, and — unless the consumer indicates otherwise — for informational and transactional calls and texts too, across every purpose and every channel. It had been due in April 2026; in January 2026 the FCC issued an order delaying it to 31 January 2027.

Build for it now anyway. Not out of caution, out of arithmetic. If opt-out state lives as four separate flags in your SMS platform, your email tool, your CRM and your helpdesk, unifying them later is a data migration with a deadline attached. If every channel checks one suppression service before sending, you are already compliant and the deadline is a non-event. That is a design decision available to you today at close to zero cost, and a project with a fixed date and a legal consequence if you defer it.

Also on the horizon: AI disclosure

The FCC has an open proceeding on AI-generated voice and text communications. The proposals under consideration include requiring disclosure that a message was AI-generated at the outset of an interaction, and extending revocation rights across all AI-generated channels. These are proposals, not final rules, and should not be treated as current obligations. But the direction is clear enough to design toward — and separately, several US states have enacted or proposed bot-disclosure requirements in specific contexts, and the EU AI Act imposes transparency obligations on systems that interact with people. If you operate anywhere beyond a single US state, disclosure is heading toward you from more than one direction.

Not sure which of these actually apply to you?The free conversation audit maps a real week of your conversations by channel and direction — inbound versus outbound — which is the split that decides which of these frameworks you are inside at all.
Get the free auditNo card required
0710DLC

10DLC: registration, trust scores and throughput

10DLC — 10-Digit Long Code — is the registration system US carriers use to authorise business texting from standard 10-digit numbers, administered through The Campaign Registry. If you send any automated SMS in the US, whether marketing, reminders or order updates, you need it. Since February 2025 all major carriers block unregistered application-to-person traffic, which changed this from a deliverability optimisation into a precondition for the channel existing at all.

The registration sequence, and where it goes wrong

You register a brand first — your legal business identity, EIN, address — and then one or more campaigns, each describing a specific messaging use case with sample messages and an account of how you collect opt-in. Brand registration typically clears in one to five business days. Campaign registration takes three to seven, stretching to ten or fifteen in busy periods. Budget one to four weeks end to end and assume at least one rejection.

Brand stateWhat it meansWhat you can do
UnverifiedUsually a business-name or EIN mismatch against public recordsNothing — all 10DLC messaging is blocked until it is fixed
VerifiedIdentity confirmed; the baseline stateRegister campaigns and send at standard throughput
Vetted VerifiedThird-party review completedHigher throughput tiers and better carrier treatment

Trust scores between 75 and 100 permit meaningfully higher messages per second. If your business is not on the Russell 3000, you are capped at a lower throughput tier without paying for third-party vetting — roughly $40, and usually worth it the moment volume matters. The most common causes of rejection are mundane and entirely avoidable: a legal name that does not match your EIN registration exactly, sample messages that do not correspond to the described use case, an opt-in flow a reviewer cannot find or complete on your live site, and sample messages missing the opt-out instruction.

Submit-once 10DLC checklist
  • Legal business name, EIN and address match your public registration character for character
  • One campaign per genuine use case — do not bundle marketing and two-factor codes together
  • Sample messages are real messages you will actually send, not placeholders
  • Every sample includes the opt-out instruction
  • The opt-in flow described exists on your live site and a stranger can complete it
  • Your privacy policy and messaging terms are published and reachable from the opt-in page
  • Consent language on the form states message frequency and that data rates may apply
  • Delivery verified on real handsets across all three major carriers before you scale
08The model

Price your own exposure

Eight inputs. The first seven price the visible cost of the outbound lane — registration, campaign fees, carrier surcharges. The eighth prices the invisible one. Outputs are illustrative estimates generated from your inputs, not a legal assessment, a quote or a prediction of any actual liability.

What the outbound lane actually costs you

Registration and carrier fees, approval time, and the statutory exposure nobody budgets for

Contacts you would text5,000

Everyone on the list you intend to message — customers, leads, past buyers, imported records. Count the whole list, not the segment you plan to start with.

Messages per contact a month4

Include everything: promotions, reminders, order updates, re-engagement. Informational messages are inside the revocation rule too, not only marketing.

Share with documented consent60%

Not the share who seem happy to hear from you — the share for whom you could produce a timestamp, the exact disclosure shown, and what they agreed to. You carry the burden of proof.

Campaigns to register2

Carriers register message use cases separately. Marketing, order notifications, appointment reminders and two-factor codes are typically distinct campaigns.

Monthly fee per campaign$10.00

Recurring carrier campaign fees run roughly $1.50 to $10 a month each, depending on use case and provider.

Carrier surcharge per message$0.004

Charged per message on top of whatever your provider bills. Roughly $0.003 to $0.005, and it applies to every message whether or not anybody reads it.

One-off brand registration$150

About $4 for a sole proprietor, $48 and up for a standard brand, plus roughly $40 if you need third-party vetting to unlock higher throughput.

Share customers would ask you anyway35%

The share of this volume that is answering a question — order status, availability, booking changes — rather than initiating one. That share belongs in the inbound lane, where none of this applies.

Messages a month20,0005,000 contacts × 4
Cost to run outbound$100/mo$182 to register
Sent without provable consent8,000messages a month
Statutory exposure a month$4,000,000up to $12,000,000 at $1,500 per message
Before you can send anything1–4 weeksbrand, then campaign approval
8,000 messages a month you could not defendAt 60% documented consent you are sending 8,000 messages a month to people whose consent you could not produce if asked. Statutory damages run $500 to $1,500 per message with no cap in a class action, so the theoretical exposure is $4,000,000 to $12,000,000 — every month, compounding, against a run cost of $100. Meanwhile 35% of this volume (7,000 messages, carrying $3,500,000 of that exposure) is answering questions customers would have asked you themselves. Move that share to inbound and it costs nothing, registers nothing, and waits for nobody's approval.
The input people get wrong is documented consent. Most businesses set that slider to 90% or higher on instinct, then discover during the ten-minute stress test above that the real figure — the share for whom they could produce a timestamp, the exact disclosure shown, and the affirmative action taken — is a fraction of that. The honest number is not how many people are happy to hear from you. It is how many you could prove agreed, to a stranger, in two years’ time, from records you already keep.
Or skip the lane entirelyInbound AI on WhatsApp, Instagram, Messenger, web chat and email registers nothing, waits for no approval, and carries none of the exposure above. Point one at your website and see what it handles.
Start freeNo card required
09The distinction

TCPA vs 10DLC: the distinction that catches people out

These are separate requirements that apply simultaneously, and the single most costly misunderstanding in this area is treating one as evidence of the other. Carriers do not check your consent records. Courts do not check your trust score.

DimensionTCPA10DLC
What it isFederal statuteCarrier registration system
Who enforces itFCC, FTC, and private plaintiffsMobile carriers, via The Campaign Registry
What it decidesWhether you were permitted to sendWhether the message is delivered
Penalty for failure$500–$1,500 per message, uncapped in class actionsMessages blocked; carrier fines possible
When you find outMonths later, by demand letterImmediately, by flat delivery numbers
Applies to WhatsApp / IG / web chatNo — those are not calls to phone numbersNo — those are not carrier SMS
Applies to inbound conversationsNot in the way it applies to outboundNo registration needed
Cost to complyEngineering, records and legal review~$65–$500 upfront plus ongoing fees
Does the other one help?No — registration is not a defenceNo — consent does not get you delivered
The arithmetic that makes this concrete. A perfectly registered 10DLC campaign sent to 10,000 contacts whose consent you cannot evidence is theoretical statutory exposure in the millions, from a campaign your dashboard will report as a complete success — high delivery, healthy engagement, no errors. Nothing in the carrier layer will tell you. Separately, National DNC Registry violations carry fines up to $43,792 per call or text, which is a distinct exposure on top of the statutory damages, not an alternative to them.
10The fork

Inbound vs outbound: the compliance fork

Almost the entire burden described on this page attaches to one thing: sending automated messages to people who did not message you first. Flip the direction and most of it simply does not arise — not as a loophole, but because the question the TCPA exists to answer does not come up. You are not interrupting somebody; they interrupted you.

RequirementOutbound US SMSInbound conversational AI
A2P 10DLC brand registrationRequiredNot applicable
Campaign registration and feesRequired, per use caseNot applicable
Carrier per-message surcharge~$0.003–$0.005 every messageNone
Approval wait before first send1–4 weeksNone — live the same day
Prior express written consentRequired for marketingThe customer initiated the conversation
Consent record-keeping burdenSubstantial and auditableMinimal
Time-of-day restrictions8am–9pm recipient local timeThey chose when to message you
DNC list scrubbingNational plus internalNot applicable
Statutory damages exposure$500–$1,500 per messageNot the same exposure
Where the buying intent isYou guess and interruptThey are already asking

State the conflict of interest here, because it is real. Jugl sells inbound AI agents, so a page concluding that inbound is simpler is a page concluding that you should buy what we sell. The distinction is nonetheless accurate and is the reason the row above is worth reading — but read the next paragraph too, because it is where the argument stops.

Inbound is not a compliance-free zone. General consumer protection law applies. State privacy and session-recording statutes apply, and two-party consent states have specific requirements for recorded or monitored conversations. Data protection obligations apply to whatever you store. Platform policies apply and are enforced by quality rating rather than by regulator. And the instant you capture a phone number in an inbound conversation and send an outbound text to it, you are back inside the TCPA in full, regardless of where the conversation began. The channel of capture does not determine the channel of obligation.

The commercial argument, separate from the compliance one

There is a cost advantage running alongside the compliance advantage, and it happens to point the same way. Meta bills WhatsApp per delivered template message, but replies inside the customer-initiated 24-hour service window are free, and click-to-WhatsApp ads open a 72-hour free window. An inbound-first strategy sits inside those windows by design, which makes instant response financially trivial rather than expensive. Meta has announced it will begin charging for service messages from 1 October 2026, which is worth modelling now rather than discovering later. The full channel economics are in the WhatsApp platform comparison.

The intent argument is stronger still. Outbound guesses who is interested. Inbound already knows — somebody asking whether an item is in stock at 11pm on a Sunday has told you exactly where they are in the purchase, and they are not going to wait until Monday to find out. That is not a support ticket appearing in a queue metric; it is a sale appearing in a competitor’s revenue. How agents read those signals is covered in the concierge model, and the broader shift is documented in the conversational commerce report.

11By channel

Channel by channel: what is regulated and what is not

A single “messaging compliance policy” that treats every channel identically will be wrong in both directions — over-restricting where nothing applies, and under-restricting where a great deal does. The obligations differ by channel, and so should your agent’s behaviour.

ChannelTCPA10DLCWhat actually governs it
Outbound US SMSYes, fullyYes, requiredTCPA, FCC rules, state mini-TCPA statutes, carrier policy
Outbound AI voice callsYes — AI voices are "artificial"NoTCPA prerecorded-call consent standard, state call recording law
Inbound SMS replyThe conversation is customer-initiatedNumber must still be registeredCarrier policy for the number itself
WhatsAppNoNoMeta WhatsApp Business Platform policy, template approval, quality rating
Instagram DMNoNoMeta platform policy and messaging windows
Facebook MessengerNoNoMeta platform policy and messaging windows
Website chatNoNoConsumer protection, state privacy and session-recording law, accessibility
EmailNoNoCAN-SPAM in the US; GDPR and equivalents elsewhere
RCSTreated as messaging to a phone numberRegistration generally requiredCarrier and Google platform policy, plus TCPA analysis

Channel classification is a starting point for a conversation with counsel, not a substitute for one. State law in particular varies significantly, several states have mini-TCPA statutes with independent private rights of action, and the analysis can turn on facts specific to how you capture and use a number.

The trap in the middle of that table

Look at the WhatsApp row and the outbound SMS row together. The same customer, the same question, the same AI agent, the same answer — and completely different legal machinery, depending only on which app the message travelled through. That is worth internalising before you design your channel strategy, because it means the channel decision is a compliance decision made months before anybody in legal sees a document. Businesses that pick channels on marketing grounds and discover the compliance consequences afterwards are the ones who end up retrofitting consent capture into a live system.

It is also why multi-channel AI is worth more than it looks. If your agent runs across WhatsApp, Instagram, Messenger, web chat and email with one shared customer history, the customer chooses the channel and you inherit the lightest applicable obligation. Getting that architecture right from the start is covered in the customer support agent guide, and the multilingual dimension in multilingual AI support.

12Engineering

What your AI agent must actually be able to do

Compliance for an AI messaging system is not a policy document, it is a set of behaviours in the send layer and the classification layer. These are the capabilities to require of any vendor, and to verify rather than accept on assurance.

1
Classify revocation as an intent, not a keywordEvery inbound message runs through an opt-out classifier before any response is generated. Tune it to over-trigger deliberately: a false positive costs you one subscriber, a false negative costs you a violation. Route ambiguous cases to a person the same day rather than guessing.
2
Suppress once, everywhereOne suppression service that every channel checks before sending. An opt-out expressed in a WhatsApp thread suppresses SMS, email and voice. This is the requirement arriving on 31 January 2027 and it is far cheaper to build now than to migrate to later.
3
Cap the post-opt-out message in codeExactly one confirmation, within five minutes, no marketing content. Hard-code the path rather than exposing it as an editable template, because a template is a thing somebody eventually adds a discount code to.
4
Enforce the time window at send time8am–9pm in the recipient’s local time, resolved from the best available signal and defaulting conservatively when uncertain. A hard constraint in the send layer, not a scheduling convention a campaign can override.
5
Log the decision, not just the outcomeStore the original message text, the classification, the confidence, and the action taken. Your defence is the record of what your system did and when — an audit trail you cannot reconstruct after the fact is one you do not have.
6
Escalate to a person unconditionallyAnything carrying legal, emotional, medical or safety signal routes to a human immediately, with the full transcript. This is a compliance control and a satisfaction control at once — the design detail is in the handoff guide.
7
Disclose that it is an AINot yet required federally, proposed at the FCC, required in some contexts by state law and the EU AI Act, and expected by consumers regardless. One line in the opening message removes an entire category of complaint at zero cost.
Questions worth asking a vendor, verbatim. “Show me what happens when a customer replies ‘take me off this list’ instead of STOP.” “If somebody opts out on WhatsApp, does that suppress SMS?” “Can I export the consent record and revocation log for a single phone number?” “What stops a campaign from sending at 7am in California?” If the answers are architectural, good. If they are ‘you can configure that’, the control is a setting somebody will eventually change. How to evaluate the rest of the platform is in the buyer’s guide, and the measurement guide covers what to track once it is live.
13Comparisons

The comparisons buyers ask for

AI agent versus traditional chatbot, on compliance

CapabilityScripted chatbotAI agent
Recognises "please stop texting me"No — keyword match onlyYes, as a classified intent
Handles misspelled or multilingual opt-outsNoYes, if the classifier is trained for it
Escalates ambiguous requestsFalls through to a menuRoutes to a person with context
Detects legal or safety signalNoYes — a routing rule, not a guess
Explains what it isUsually notDisclosure in the opening message
Audit trail of decisionsFlow logs onlyClassification, confidence and action logged
New requirement meansRebuild the flowUpdate the rule and the training

Outbound-first versus inbound-first, as a strategy

DimensionOutbound-firstInbound-first
Time to first message1–4 weeks of registrationSame day
Upfront cost$65–$500 plus legal reviewNone beyond the platform
Ongoing per-message costCarrier surcharge on every sendFree inside the service window
Consent infrastructureCapture, storage, proof, versioningNot required for the conversation
Statutory exposure$500–$1,500 per messageNot the same exposure
Intent qualityAssumedDemonstrated — they asked
Who it suitsEstablished lists with provable consentAlmost everyone else, as a starting point

Jugl versus a typical outbound SMS stack

What you have to doOutbound SMS platformJugl
Register a brand and campaignsYes, before anything sendsNot applicable
Wait for carrier approval1–4 weeksNone
Pay per message to carriersYes, on every sendNo
Build a consent databaseYes, with auditable proofNot for inbound conversations
Channels coveredSMS, sometimes MMSWhatsApp, Instagram, Messenger, web chat, email
Pricing modelPer message, plus platform feeFlat published tiers
Free tierTrial, then card requiredPermanent free tier, no card
Handles the compliance for youNoNo — and any vendor claiming otherwise is overselling

Stated as a disclosure rather than a finding: this is our own product, and the last row is the honest one. Choosing inbound changes which obligations attach to you. It does not delegate any obligation to us. Worked comparisons against named platforms are on the comparison hub, and Jugl vs Meta’s own business agent covers the closest adjacent option.

14Direct answers

The six questions behind every compliance review

Does any of this apply if the AI wrote the message?

Short answer

Yes. The TCPA governs the act of sending an automated message to a phone number, not the authorship of the text. The FCC has confirmed AI-generated voices are 'artificial' under the statute, and text messages have long been treated as calls. There is no AI exemption anywhere in the framework.

Example

A business that hand-sent four hundred texts a month deploys an agent and sends forty thousand. Nothing in the consent policy changed. Statutory exposure, assessed per message, is now a hundred times larger. Volume is the multiplier on every figure in this page.
Key takeawayAsk whether a message can be sent to a phone number without a person deciding to send that specific message. If yes, you are inside the TCPA and you need a defensible consent record for every number.

We are registered for 10DLC. Are we covered?

Short answer

No. 10DLC is a delivery gate operated by carriers; the TCPA is federal law enforced by regulators and private plaintiffs. Registration says nothing about whether consent was validly obtained. A fully approved campaign sent to non-consenting contacts is a fully delivered violation.

Example

Ten thousand messages, perfectly registered, high delivery rate, healthy engagement, no errors in any dashboard — and no producible consent record. That is theoretical statutory exposure in the millions from a campaign every internal system reported as a success.
Key takeawayTreat them as two independent gates. Budget attention in proportion to exposure, not in proportion to which one sends you an invoice.

Our AI handles STOP. Is that enough?

Short answer

No, and this is the most common AI-specific failure. Since 11 April 2025 consumers may revoke consent in any reasonable manner. The FCC explicitly declined to limit revocation to keywords. Natural-language requests, emails and voicemails all count, and a keyword matcher misses every one of them.

Example

“Please stop texting me about this.” “Take me off this list.” “I never signed up for these.” All three are revocations. All three pass straight through a keyword filter. All three are sitting in your transcript, timestamped, alongside every message you sent afterwards.
Key takeawayClassify opt-out as an intent and tune it to over-trigger. A false positive costs you one subscriber. A false negative costs $500 to $1,500 per message that follows it.

Does inbound AI really avoid all of this?

Short answer

It avoids the A2P registration layer and the outbound consent architecture, because you are responding to customer-initiated contact rather than initiating automated contact. It does not avoid consumer protection law, state privacy and recording rules, data protection, or platform policy — and it stops entirely the moment you send an outbound text.

Example

A customer messages your WhatsApp asking about delivery. The agent answers instantly, at no per-message cost, with nothing registered and no consent record required. If that same conversation ends with you texting them a promotion next week, the promotion is squarely inside the TCPA.
Key takeawayInbound-first is a genuine and large simplification, not a compliance-free zone. The channel where you captured a number does not determine the rules that govern messaging it.

The global opt-out rule is delayed. Can we defer the work?

Short answer

You can, and it will cost more. The requirement that an opt-out revokes consent across all purposes and channels is delayed to 31 January 2027, but the underlying build — one suppression service every channel checks — is a design decision today and a data migration later.

Example

Opt-out state living as separate flags in an SMS platform, an email tool, a CRM and a helpdesk is four sources of truth that will disagree. Unifying them under deadline pressure, with live traffic, is a materially worse project than building one service now.
Key takeawayDesign suppression as a single service that every channel consults before sending. Do it now, while it is architecture rather than remediation.

What is the cheapest compliant way to start?

Short answer

Deploy AI on the channels customers already message you on — WhatsApp, Instagram, Messenger, web chat and email. No brand registration, no campaign fees, no carrier approval wait, no consent database, and no per-message surcharge. Prove the model there, then take on outbound only if the revenue clearly justifies the layer.

Example

A retailer launches inbound AI in an afternoon and handles the availability and delivery questions arriving overnight. Six months later, with real conversation data showing which outbound messages would be worth sending, the registration project has an actual business case behind it rather than an assumption.
Key takeawaySequence matters more than scope. Inbound first is cheaper, faster, lower risk, and produces the evidence you need to decide whether outbound is worth its compliance layer at all.
15The method

How to launch AI messaging without a compliance problem

Seven steps, in this order. The order is the point — most of the pain in this area comes from doing step three before step one.

1
Decide which lane you are inSplit your intended messaging into conversations customers start and messages you initiate. Only the second triggers A2P registration and the TCPA consent architecture. Most businesses discover the first category is larger than they assumed.
2
Launch inbound firstDeploy on WhatsApp, Instagram, Messenger, web chat and email. Same day, no registration, no approval wait. This also produces the conversation data that tells you what outbound would even be for.
3
Register 10DLC before any outbound SMSBrand first, then campaigns, with real sample messages including opt-out language and an opt-in flow a reviewer can complete on your live site. Budget one to four weeks and expect one rejection.
4
Capture consent with proof attachedTimestamp, channel, the exact disclosure revision shown, the affirmative action taken, the message types agreed to. A boolean in a database is not consent; it is a claim about consent with no evidence.
5
Build natural-language opt-out detectionAn intent classifier ahead of response generation, tuned to over-trigger, tested against your own real historical messages including the messy ones, with every decision logged alongside the original text.
6
Propagate suppression across every channelOne suppression service checked before every send on every channel. Ahead of the 31 January 2027 requirement, and correct regardless of it.
7
Enforce the rest in the send layerThe 8am–9pm recipient-local window, national and internal DNC scrubbing, the single five-minute confirmation cap, and AI disclosure. Hard constraints in code, not conventions in a runbook.
Pre-launch compliance checklist for AI messaging
  • Inbound and outbound separated, with the outbound list explicitly scoped
  • 10DLC brand and every campaign registered and approved before the first outbound send
  • Consent captured with timestamp, channel, disclosure revision and affirmative action
  • Opt-out detection built as intent classification, not keyword matching
  • Suppression propagates across every channel and purpose from one service
  • Post-opt-out messaging hard-capped at one confirmation within five minutes
  • Revocation honoured well inside 10 business days, with the log to prove it
  • National DNC registry and internal do-not-call list both scrubbed before every send
  • Time-of-day window enforced in the recipient’s timezone at send time
  • AI involvement disclosed at the start of the conversation
  • Unconditional escalation path to a human, with full transcript carried across
  • Consent form version history retained, and one number spot-checked end to end
  • Counsel has reviewed your consent language and your states of operation
Start on the side where the checklist is shortInbound AI on the channels your customers already use — live the same day, nothing to register, nothing to wait for. Point it at your website and run last month's real questions through it.
Start freeNo card required
16The honest part

What none of this protects you from

A compliance page that only lists reassurances is worse than useless, because it produces confidence without protection. Here is what remains after you have done everything above.

1
State law, which this page does not coverSeveral states have their own mini-TCPA statutes with independent private rights of action, narrower time windows and additional disclosure requirements. Federal compliance is necessary and not sufficient, and the states you operate in change the analysis materially.
2
Vendor assurances are not a defenceLiability sits with the sender. A platform’s compliance features, certifications and contractual language do not transfer your obligations to them. Read what your agreement actually says about indemnity, and assume the answer is less than you hoped.
3
Historical consent you inheritedLists imported from a previous system, an acquisition or an agency carry whatever evidence came with them, which is usually none. The safest treatment of a list you cannot evidence is to re-permission it, and the second safest is not to message it.
4
Rules that are still movingThe revocation-all requirement lands on 31 January 2027. The FCC’s AI proceeding is open. State legislatures are active. Anything you build to the letter of today’s rules should be built so tomorrow’s can be added without a rewrite.
5
An AI that is confidently wrong about your policyCompliance failures are not only about sending — an agent that misstates a refund policy, a warranty term or a medical instruction creates a different kind of liability entirely. Ground it in your real documents, escalate on uncertainty, and review escalations weekly. The common failure modes are in the AI support mistakes analysis.
Three situations where you should stop reading and call a lawyer. You are texting a purchased, rented, appended or inherited list. You operate in multiple states and have not checked their mini-TCPA statutes. Or you have received a demand letter — in which case nothing on this page is a substitute for counsel, and the first thing to preserve is your logs, before anybody helpfully tidies them.
17Disclosure

Where Jugl fits — and where it does not

What it changes. Jugl’s AI agents work on inbound channels — WhatsApp, Instagram, Facebook, web chat and email — where customers reach out to you. That removes A2P 10DLC brand registration, campaign fees, carrier surcharges, the one-to-four-week approval wait and the outbound consent infrastructure from your project, because none of them attach to a conversation the customer started. As a Meta Business Partner, Jugl connects those channels natively rather than as an integration project, so the whole thing is live the same day.

What it changes commercially. Replies inside the customer-initiated 24-hour WhatsApp service window are free and click-to-WhatsApp ads open a 72-hour free window, so an inbound-first agent answers at essentially no marginal cost — while outbound template messages carry per-message pricing on top of carrier surcharges. Jugl’s own pricing is flat and published, with nothing metered per resolution, so the cost of answering more conversations does not rise as the agent succeeds. Full pricing is on the pricing page, and the wider return is modelled on the ROI page.

What it changes for your customers. The agent answers instantly in your brand voice across every channel, reads what the customer is actually asking for, and hands off to a real person the moment it matters — with the full transcript, so nobody has to explain themselves twice. Jugl is used by 1,000+ businesses. What that looks like in practice is on what is Jugl, and the handoff design specifically on the AI-to-human handoff guide.

What we cannot do for you. We are not your compliance function and we are not a law firm. If you send outbound SMS, you still need registration, consent capture, suppression, DNC scrubbing and legal review, and none of that becomes our obligation because you bought software. Choosing the inbound lane changes which rules attach to you; it does not delegate any rule to a vendor. Any platform telling you otherwise is selling you a comfort that will not survive a demand letter.

18EEAT

Methodology and disclosure

Written by

Jugl Editorial Team

Jugl Inc., Frisco, Texas — an AI customer agent platform used by 1,000+ businesses.

Reviewed by

Jugl product & customer operations

Checked against live deployment data and current vendor documentation.

Methodology & disclosure

Where the figures come from. TCPA statutory damages, the prior express written consent standard, time-of-day restrictions and the treatment of texts as calls are from the statute and FCC rules and orders. The consent revocation rule, the five-minute confirmation allowance, the 10 business day deadline and the delayed revocation-all provision are from the FCC’s published orders. The vacatur of the one-to-one consent rule is the Eleventh Circuit decision issued days before it was due to take effect. National Do Not Call Registry forfeiture figures are the published adjusted maximums. 10DLC brand, campaign, vetting and surcharge figures are from The Campaign Registry and US carrier published schedules. WhatsApp template pricing, the customer-initiated service window and the click-to-WhatsApp window are Meta’s published Business Platform pricing. Jugl pricing is our own published price list.

How the model works. Messages a month is contacts multiplied by messages per contact. Run cost is messages multiplied by the carrier surcharge, plus campaigns multiplied by the monthly campaign fee. Registration is the brand fee plus roughly $16 per campaign. Messages without provable consent is total messages multiplied by one minus your documented-consent share, and theoretical exposure is that figure multiplied by the $500 and $1,500 statutory damages. Nothing is hidden in a constant. Outputs are illustrative estimates generated from your own inputs — not a legal assessment, not a prediction of actual liability, and not a substitute for counsel.

Conflict of interest, stated plainly. Jugl sells an inbound AI customer agent platform, so a page concluding that inbound messaging carries a lighter compliance burden is a page concluding that you should buy what we sell. The distinction is real and load-bearing, and we have tried to earn the claim by stating its limits explicitly: inbound does not exempt you from consumer protection law, state privacy and recording statutes, data protection or platform policy; it ends the moment you send an outbound text; and choosing it does not transfer a single obligation from you to us. The comparison table naming our own product is labelled as a disclosure rather than a finding.

How this page is maintained and what it is not. Reviewed against current published rules, orders and carrier schedules, and revised when they change. Unlike the rest of this cluster it carries effective dates, because a compliance rule without its date is not merely stale, it is wrong. This page is general information for business owners evaluating AI messaging. It is not legal advice, it does not create an attorney-client relationship, and it does not cover state mini-TCPA statutes or non-US regimes. Consult qualified counsel for your business, your use case and your states of operation.

19FAQ

TCPA and 10DLC for AI messaging: 26 questions answered

Does the TCPA apply to AI-generated text messages?
Yes, unambiguously, and this is the single most common misunderstanding among businesses buying an AI agent. The FCC has long treated text messages as "calls" for TCPA purposes, which subjects SMS to the same core restrictions as phone calls. For AI specifically, the FCC has confirmed that AI-generated voices are "artificial" voices under the statute, requiring the same prior express consent as a prerecorded call. There is no AI exemption anywhere in the framework. If anything, AI-driven channels warrant tighter governance than manual ones, because they scale volume faster than a human process ever could, and exposure scales with volume — statutory damages are assessed per message, not per campaign. A business that would have sent 400 texts by hand and sends 40,000 with an agent has multiplied its theoretical liability by a hundred without changing a single policy document.
What is 10DLC and do I need it?
10DLC — 10-Digit Long Code — is the registration system US carriers use to authorise business texting from standard 10-digit phone numbers, administered through The Campaign Registry. You register a brand (your business identity) and then one or more campaigns (your specific messaging use cases, with sample messages and a description of how you collect opt-in). If you send any automated SMS to US mobile numbers — marketing, appointment reminders, order updates, two-factor codes — you need it. Since February 2025 all major carriers block unregistered application-to-person traffic, which means unregistered messages are not throttled or deprioritised, they are simply not delivered. You do not need 10DLC for inbound conversational channels such as WhatsApp, Instagram, Messenger, web chat or email, because those do not traverse US carrier SMS networks.
What is the difference between TCPA and 10DLC?
They are separate frameworks that apply simultaneously, and confusing them is the most expensive mistake in this area. 10DLC is carrier infrastructure: it determines whether your message gets delivered. TCPA is federal law: it determines whether you were legally permitted to send it in the first place. A perfectly registered, fully approved 10DLC campaign provides exactly zero defence against TCPA liability. You can pass every carrier check, achieve a high trust score, enjoy excellent deliverability, and still face $500 to $1,500 per message in statutory damages because the underlying consent was never validly obtained. The reverse is also true: impeccable consent records will not get an unregistered message delivered. Treat them as two independent gates, both of which must be passed for every message you send.
How much does 10DLC registration cost in total?
Roughly $65 to $500 upfront depending on brand type and whether you need vetting, plus ongoing fees. Brand registration is about $4 for a sole proprietor and $48 or more for a standard brand. Campaign registration runs roughly $15 to $17 per campaign. Standard third-party vetting, which unlocks higher throughput tiers, is around $40. Then the recurring costs: $1.50 to $10 per campaign per month, and a carrier surcharge of roughly $0.003 to $0.005 on every single message, applied on top of whatever your messaging provider charges. Budget one to four weeks before anything can send. For a business running two campaigns to a moderate list, the visible annual cost is usually a few hundred dollars — which is why it gets approved without scrutiny, and why the far larger consent-side exposure never gets priced at all.
Is the one-to-one consent rule still in effect?
No. It was scheduled to take effect on 27 January 2025 and was vacated by the Eleventh Circuit three days beforehand. It is not in force, and any guidance you find telling you to obtain separate written consent for each individual seller is describing a rule that no longer exists. This matters practically because a great deal of published compliance advice predates that decision and has never been updated, so businesses are building consent flows against a requirement that was struck down. That said, do not read the vacatur as permission to be careless with lead-generation consent. The underlying prior express written consent standard is untouched, consent still does not transfer between companies, and a consent form listing hundreds of unrelated "marketing partners" remains extremely difficult to defend on its own terms.
How long do I have to honour an opt-out request?
As soon as practicable, and no later than 10 business days from receipt. That deadline has been the operative standard since the consent revocation rule took effect on 11 April 2025, and it applies to both marketing and informational messages. Ten business days is the outer limit, not a target — in practice, suppression should be effectively immediate, because every message sent between the request and the suppression is an independent violation and the gap is trivially provable from your own logs. Two practical points. First, the clock starts when the request is received on any channel, not when it reaches the right team. Second, "as soon as practicable" is judged against what your systems are capable of, and an automated system capable of instant suppression will not be credited with needing ten days.
Can my AI send a confirmation text after someone opts out?
Yes — exactly one message, within five minutes, and only to confirm the opt-out or clarify its scope. That is the narrow allowance built into the consent revocation rule, and it exists because a customer opted out of promotions may not have intended to stop appointment reminders. The constraints are strict and worth engineering carefully. One message means one, not a confirmation plus a "we are sorry to see you go" plus a win-back offer. Five minutes means the send must be automated, because no human workflow reliably hits that window. And "confirm or clarify scope" means the message cannot contain marketing content of any kind — a discount code in a goodbye message converts a compliance step into a violation. Build this as a hard-coded path in your agent, not as a template someone can edit.
What words count as a valid opt-out?
Far more than the keyword list, and this is where AI agents fail most often. The FCC has said consumers may revoke consent "in any reasonable manner", and explicitly declined to limit revocation to specific keywords. Words that are automatically reasonable in a reply text include stop, quit, end, revoke, opt out, cancel and unsubscribe — but that is a floor, not a ceiling. Informal natural-language phrasing counts. So do emails and voicemails. A customer replying "please stop texting me about this" or "take me off this list" or "I never signed up for these" has revoked consent, and a system that pattern-matches on STOP will miss all three and keep sending. That specific failure — messages continuing after a plainly worded request — is the fact pattern that generates demand letters, because it is documented in your own transcript.
Do I need 10DLC for WhatsApp messages?
No. 10DLC governs SMS sent through US carrier networks. WhatsApp runs on Meta’s infrastructure under the WhatsApp Business Platform, with its own policies, its own quality ratings and its own per-message pricing model. There is no brand registration, no campaign registration, no carrier surcharge and no one-to-four-week approval wait. That does not make WhatsApp unregulated — Meta enforces its own commerce and messaging policies, template messages must be approved, quality ratings can restrict your sending, and other privacy and consumer protection laws still apply. But the entire A2P registration layer, and the specific TCPA consent architecture built around US carrier SMS, does not attach to a customer-initiated WhatsApp conversation. For most businesses that is the single largest compliance simplification available to them.
Does the TCPA apply to AI chatbots on my website?
No. The TCPA governs calls and texts made to telephone numbers. A web chat widget, a WhatsApp conversation, an Instagram DM and an email thread are not calls to telephone numbers, and the TCPA’s consent, revocation and do-not-call machinery does not attach to them. This is the structural reason inbound conversational AI is so much simpler to deploy than outbound SMS. Two caveats worth stating plainly. First, other law still applies — state privacy statutes, wiretapping and session-recording laws in two-party consent states, biometric and data protection rules, general consumer protection prohibitions on deceptive practices, and accessibility requirements. Second, if your web chat captures a phone number and you then text that person, the text is squarely inside the TCPA regardless of where the conversation began. The channel of capture does not determine the channel of obligation.
Does the TCPA apply to B2B text messages?
Yes, when the message goes to a wireless number, and "it is a business number" is not a defence anybody should rely on. B2B calls and texts to wireless numbers are subject to the same restrictions as B2C, and in practice the overwhelming majority of business contacts are mobile numbers. This catches a lot of sales teams by surprise, because the mental model of TCPA as consumer protection law suggests that professional outreach is different in kind. It is not. Nor does a business relationship, an exchanged business card, a LinkedIn connection or a downloaded whitepaper constitute prior express written consent for marketing texts. If your AI sales agent sends outbound texts to prospect mobile numbers, it is operating inside the same framework as a consumer marketing campaign and should be governed accordingly.
What happens if I send unregistered A2P SMS?
Carriers block it. Since February 2025 the major US carriers block unregistered application-to-person traffic rather than merely filtering or throttling it, so your messages are not delivered at all. On top of the blocking, T-Mobile imposes financial penalties for specific policy violations, and repeated violations can affect your ability to register in future. The operationally dangerous part is that blocking is often silent from your side — your platform reports messages as sent, delivery receipts are inconsistent, and a campaign can run for days looking healthy while reaching nobody. This is worth knowing before you build revenue forecasts on an SMS channel. Register first, verify delivery on real handsets across all three major carriers, and only then scale.
What are the TCPA time-of-day rules?
Generally 8am to 9pm in the recipient’s local time, not yours — and the distinction matters enormously for automated systems, which are precisely the systems capable of sending at 8:01am across four time zones simultaneously. Determining the recipient’s local time is a genuine engineering problem: area code is an unreliable proxy in an era of number portability, so businesses generally combine area code, stated address, account data and any timezone captured at signup, and default conservatively when uncertain. Some states impose narrower windows or additional restrictions, and a number of states have their own mini-TCPA statutes with independent private rights of action. Build the window into the send layer as a hard constraint rather than a scheduling convention, because a scheduling convention is a setting somebody can override at 7am on a Monday.
What is prior express written consent?
It is the standard required for marketing texts and calls, and it has specific components that a checkbox alone does not satisfy. There must be a clear and conspicuous disclosure of what the person is agreeing to receive, an affirmative action taken by that person, a statement that consent is not a condition of purchase, identification of the specific business that will be messaging, a description of the message types, and a documented, timestamped record of the whole thing. Pre-checked boxes do not count. Consent buried in terms of service does not count. Consent inferred from a transaction does not count. And critically, you carry the burden of proof — in a dispute it is your job to produce evidence of what was shown and what was clicked, not the plaintiff’s job to prove it was not. Informational messages sit under a lower prior express consent standard, but still require consent.
Does consent transfer if I buy a list or acquire a company?
No, and treating a purchased list as consented is one of the fastest routes to a class action in this area. Consent does not transfer between companies. A person who consented to receive messages from Company A has not consented to receive messages from Company B, regardless of what Company A’s form said about sharing data with partners. Selling or sharing consent with third parties does not create valid consent for those third parties. Acquisitions are more nuanced and genuinely fact-specific — a true successor in interest continuing the same business under the same brand is in a different position from a buyer acquiring a customer database as an asset — and this is exactly the kind of question to put to counsel rather than resolve from an article. What is not nuanced: a rented, purchased, scraped or appended list is not a consented list.
What is the revocation-all requirement and when does it take effect?
It is the provision that turns any opt-out into a global opt-out. Once effective, an opt-out request would revoke consent for all automated marketing messages from that sender and, unless the consumer says otherwise, for informational and transactional calls and texts too — across every purpose and every channel that sender uses. It had been due in April 2026; in January 2026 the FCC issued an order delaying it to 31 January 2027. The correct response to a delay is not to shelve the work. Suppression that propagates across channels and purposes is architectural: if opt-out state lives in your SMS platform, your email tool, your CRM and your helpdesk as four separate flags, unifying them later is a migration project, whereas building one suppression service that every channel checks before sending is a design decision you can make once, now, at almost no cost.
Does the FCC regulate AI voice calls the same way?
It regulates them at least as strictly. The FCC has confirmed that AI-generated voices are "artificial" voices under the TCPA, which means an AI voice agent placing outbound calls requires the same prior express consent as a prerecorded message — a materially higher bar than a live human dialling manually. There is also an open FCC proceeding on AI-generated voice and text communications, with proposals including a requirement to disclose at the outset that a message is AI-generated, and extension of revocation rights across all AI-generated channels. Those are proposals, not final rules, and should not be treated as current obligations. But the direction is consistent enough to design toward, and disclosure in particular costs nothing to implement voluntarily while building exactly the trust that surveyed consumers say they want.
What is a 10DLC trust score and why does it matter?
A trust score is the rating carriers assign your registered brand, and it directly determines your throughput — how many messages per second you may send, and your daily volume ceilings. Scores between 75 and 100 permit meaningfully higher rates. Your brand also lands in one of three states. Unverified usually means a business-name or EIN mismatch against public records, and it blocks all 10DLC messaging until corrected. Verified is the baseline required to register campaigns at all. Vetted Verified adds third-party review and unlocks the higher tiers. If your business is not on the Russell 3000, you are capped at a lower throughput tier without paying for third-party vetting. The practical implication: get your legal business name, EIN and address exactly consistent across registration before you submit, because a mismatch is the most common cause of rejection and re-submission adds a week.
How long does 10DLC approval take?
Budget one to four weeks end to end. Brand registration typically clears in one to five business days. Campaign registration takes three to seven business days, stretching to ten or fifteen in busy periods or when a use case description triggers manual review. Rejections are common on first submission, and each round trip costs days. The most frequent causes are a business-name or EIN mismatch, sample messages that do not match the described use case, a described opt-in flow that cannot be verified on your actual website, and missing opt-out language in the samples. The way to compress the timeline is not to escalate, it is to submit accurately: real sample messages including the opt-out instruction, a use case description that matches them, an opt-in flow that a reviewer can actually find and complete on your live site, and exact legal registration details.
What records do I need to keep to defend a TCPA claim?
Everything that proves what was shown and what was chosen, and you should assume you will need to produce it years later. At minimum: the timestamp of consent, the channel and page it was captured on, the exact disclosure language displayed at that moment (not the current version — a screenshot or an archived copy of the specific form revision), what the person affirmatively did, what message types they agreed to receive, the IP address or device identifier where available, and the complete history of every message sent to that number. Add to that a full revocation log — when the request arrived, on what channel, in what words, when suppression took effect — and a version history of your consent forms. The burden of proof is yours. A defence that consists of "our process was compliant at the time" without records that demonstrate it for the specific plaintiff is not a defence.
Is inbound AI messaging really exempt from all of this?
From the A2P registration layer and the outbound consent architecture, yes, and the reason is structural rather than a loophole. When a customer messages your WhatsApp, Instagram, Messenger or web chat first, you are responding to their contact rather than initiating automated contact with them. There is no A2P SMS traffic to register, and the consent question the TCPA is built to answer — were you permitted to interrupt this person — does not arise, because they interrupted you. What inbound does not exempt you from: general consumer protection law, state privacy and session-recording rules, data protection obligations, platform policies, and the entirety of the TCPA the moment you capture a phone number from that conversation and send an outbound text to it. Inbound-first is a genuine and large simplification. It is not a compliance-free zone, and any vendor describing it that way is overselling.
Do I need to disclose that a customer is talking to an AI?
Not yet under the TCPA, and yes under a growing patchwork of other rules — so the practical answer is to do it anyway. The FCC has proposed disclosure that a message is AI-generated at the outset of the interaction, but that is a proposal rather than a final rule. Several US states have enacted or proposed bot-disclosure requirements in specific contexts, and the EU AI Act imposes transparency obligations on systems interacting with people. Beyond regulation, disclosure is simply good practice: surveyed consumers overwhelmingly say they want clear explanation of AI decisions that affect them, and the trust cost of a customer discovering mid-conversation that they were not talking to a person is worse than the trust cost of being told at the start. A single line in the opening message and an unconditional route to a human costs nothing and removes the entire category of complaint.
How do I make my AI recognise revocation in natural language?
Treat revocation as an intent to classify, not a string to match — this is the most important engineering decision on the compliance side of an AI deployment. Concretely: run every inbound message through an opt-out intent classifier before any response is generated, tune it to be deliberately over-sensitive because a false positive costs you one subscriber while a false negative costs you a violation, and route anything ambiguous to a human within the same day rather than guessing. Log the classification decision with the original text so you can prove what you did and when. Test it against real messages from your own history, including the sarcastic, misspelled, multilingual and emotionally blunt ones, because those are the messages that actually appear. And make suppression a single service every channel checks before sending, so an opt-out expressed in a WhatsApp thread suppresses SMS too.
What does a TCPA claim actually cost a small business?
The exposure is structurally asymmetric, which is why this area produces so much litigation. Statutory damages are $500 per message, trebled to $1,500 for wilful or knowing violations, with no cap on aggregate class-action exposure. A single campaign to 10,000 non-consenting contacts is theoretical exposure in the millions, before any legal costs. Most matters do not reach that number — they begin as a demand letter and settle — but the settlement value is anchored to the theoretical maximum, and defence costs are substantial even for a claim you would ultimately win. Separately, National Do Not Call Registry violations carry fines of up to $43,792 per call or text. The asymmetry worth internalising is this: the cost of building consent capture, suppression propagation and natural-language opt-out detection properly is a few weeks of engineering. The cost of not building it is unbounded.
Does email fall under the TCPA?
No. Email is governed principally by the CAN-SPAM Act in the US, which is a different framework with meaningfully different requirements: it permits sending without prior opt-in, but requires accurate header and subject information, a valid physical postal address, clear identification of commercial content, a functioning opt-out mechanism, and honouring opt-outs within ten business days. State laws and other jurisdictions add more — GDPR, for instance, generally requires consent for marketing email to EU residents, which is a stricter standard than CAN-SPAM. The relevant point for an AI deployment is that email and SMS are not interchangeable from a compliance standpoint, and a single "messaging compliance" policy that treats them identically will be wrong in both directions. If your AI agent handles both, the rules it enforces must differ by channel.
How does Jugl handle TCPA and 10DLC compliance?
By operating in the lane where most of it does not attach, and by being explicit that this is a scope decision rather than a compliance product. Jugl’s AI agents work on inbound channels — WhatsApp, Instagram, Messenger, web chat and email — where customers reach out to you. That means no A2P brand or campaign registration, no carrier surcharges, no one-to-four-week approval wait, and none of the outbound consent infrastructure that US SMS requires. As a Meta Business Partner, Jugl connects those channels natively, and the agents answer instantly in your brand voice and hand off to a person the moment it matters. What Jugl does not do is act as your compliance function: if you send outbound SMS, you still need registration, consent capture, suppression and counsel. We are not a law firm and this page is not legal advice.
20People also ask

People also ask

Does the TCPA apply to AI-generated texts?Yes. The FCC treats text messages as calls under the TCPA, and has confirmed AI-generated voices are "artificial" under the statute. There is no AI exemption — deploying an AI texting agent deploys it directly into TCPA scope.
How much is a TCPA fine per text?Statutory damages are $500 per message, trebled to $1,500 for wilful or knowing violations, with no cap in a class action. Separate National Do Not Call Registry violations carry fines up to $43,792 per call or text.
Is 10DLC registration mandatory?Effectively yes for automated US SMS from a standard 10-digit number. Since February 2025 the major carriers block unregistered application-to-person traffic outright, so unregistered messages are not delivered rather than merely deprioritised.
Can I text customers who already bought from me?Not automatically. A purchase is not consent to receive marketing texts. Transactional messages tied to that order sit on firmer ground, but marketing requires prior express written consent captured separately and provably.
How fast must I honour a STOP request?As soon as practicable, and no later than 10 business days. You may send one confirmation message within five minutes to confirm or clarify the scope of the revocation, and nothing beyond that.
Do I need consent for appointment reminders?Yes — informational and transactional texts still need prior express consent, and the revocation rule covers them explicitly. The consent standard is lower than for marketing, but it is not zero, and opt-outs must be honoured either way.
Does 10DLC apply to Instagram or Facebook messages?No. 10DLC governs SMS sent across US carrier networks. Instagram, Messenger and WhatsApp run on Meta infrastructure under Meta platform policy, with no brand registration, no campaign fees and no carrier approval wait.
What is the cheapest compliant way to start with AI messaging?Deploy AI on the channels customers already message you on. Inbound conversational AI on your own WhatsApp, Instagram, Messenger, web chat and email is responding to customer-initiated contact, which avoids A2P registration and the outbound consent layer entirely.
NextStart free

The compliant lane is also the one where the customers already are

Everything on this page attaches to one thing: sending automated messages to people who did not message you first. Registration, consent databases, suppression architecture, carrier approval, statutory damages assessed per message. Flip the direction and most of it does not arise — and the conversations waiting on the other side are the ones where somebody is already asking you a question they want answered now.

You do not need a compliance project to find out whether this works. Point a free agent at your own website, connect the channels your customers already message you on, and watch what it handles overnight. Nothing to register. Nothing to approve. No card. If it disappoints, you have learned that in an afternoon rather than after a four-week carrier wait.

Free tier that stays free — no card, live the same dayWhatsApp, Instagram, Messenger, web chat and emailNo A2P brand or campaign registration to completeNo carrier approval wait and no per-message surchargeTrains on your website, documents and past conversationsFull-context handover to a real human, by design

The registration queue is one to four weeks. The consent database is a quarter. The inbound conversations arriving tonight are not going to wait for either of them.

SOC 2 Type 2 · HIPAA compliant · Meta Business Partner · NVIDIA Inception · 1000+ businesses

Keep reading

AI agent ROIThe full business case, with the compliance layer priced as an input.AI customer service pricingThe four pricing models decoded, with the hidden costs of each.Best AI agent for businessThe seven jobs an agent must do, and 12 weighted checks for any vendor.WhatsApp AI platforms comparedWhere Meta’s fees actually land, and which window is free.AI agent vs chatbotWhy a classifier beats a keyword match, on compliance and everything else.AI-to-human handoffThe escalation design that doubles as a compliance control.11 AI support mistakesThe failure modes that turn a good deployment into a mediocre one.Cost per contact benchmarkWhat a human contact really costs, sourced and broken down.AI customer conciergeHow agents read buying intent inside an inbound conversation.Conversational commerce reportWhere messaging-led buying is actually heading.What is a Meta Business Partner?What the status certifies, and what it does not.What is Jugl?Capabilities, fit, pricing, and who should walk away.Jugl pricingFour published flat tiers with the AI included. Free forever, no card.Free conversation auditYour real inbound volume, measured from a live week.

Sources: the Telephone Consumer Protection Act and FCC rules and orders (treatment of texts as calls, artificial and prerecorded voice standard, prior express written consent, time-of-day restrictions, the consent revocation rule effective 11 April 2025, the five-minute single-confirmation allowance, the 10 business day deadline, and the order delaying the revocation-all provision to 31 January 2027); the Eleventh Circuit decision vacating the one-to-one consent rule; published FCC and FTC forfeiture schedules for National Do Not Call Registry violations; The Campaign Registry and US carrier published schedules (brand, campaign, vetting and per-message fees, approval timelines, trust score tiers and the blocking of unregistered A2P traffic); and Meta’s published WhatsApp Business Platform pricing (template categories, the customer-initiated service window, the click-to-WhatsApp window and announced changes to service message pricing). Jugl pricing is our own published price list. This page is published by Jugl, which sells an inbound AI customer agent platform and is therefore an interested party in the inbound-versus-outbound distinction it draws; the limits of that distinction are stated in full above. This page is general information, not legal advice, and does not create an attorney-client relationship. It does not address state mini-TCPA statutes or non-US regimes. Consult qualified counsel for advice specific to your business. Meta, WhatsApp, Messenger, Instagram and Facebook are trademarks of Meta Platforms, Inc.; Jugl is a Meta Business Partner and this page is published by Jugl and is not endorsed by or affiliated with Meta Platforms, Inc. All other product names are trademarks of their respective owners.

Start free at Jugl · No card required · Permanent free tier