Compliance · Written for the person who signs off on the deployment
TCPA and 10DLC rules for AI text messaging
Two separate frameworks govern every AI text you send in the US. One decides whether you were allowed to send it. The other decides whether it gets delivered at all. Passing the second gives you no protection whatsoever on the first — and that misunderstanding is the most expensive one in this entire category.
This page is written for business owners evaluating an AI agent, not for compliance lawyers. It covers what the TCPA actually requires now that the consent revocation rule is in force, what 10DLC registration costs and how long it takes, which rules changed recently and which were struck down, what your AI must be engineered to do, and the one structural decision that removes most of this burden before you write a line of policy.
It also prices your own exposure. The registration fees are a rounding error. The number that matters is the one nobody puts in a budget: statutory damages of $500 to $1,500 for every message sent to somebody whose consent you could not produce on demand, with no cap in a class action.
By Jugl19 min readInteractive exposure model34 questions answered
The 60-second version
Yes, the TCPA applies to AI-generated texts — there is no AI exemption. Statutory damages run $500 to $1,500 per message with no cap in a class action. Separately, 10DLC is the carrier registration system that decides delivery: since February 2025 major carriers block unregistered A2P traffic outright. Registration costs roughly $65 to $500 upfront plus ongoing fees, and takes one to four weeks.
Compliant 10DLC registration is not a TCPA defence. They are independent gates. Perfect registration with invalid consent still produces per-message statutory liability; perfect consent without registration still produces undelivered messages.
The rule most businesses are currently breaking: since 11 April 2025, consumers may revoke consent in any reasonable manner — natural language, email, voicemail, not just the word STOP — and you must honour it within 10 business days. An AI that only pattern-matches keywords will miss plainly worded opt-outs, and the transcript proves it.
Inbound AI avoids nearly all of it. When a customer messages your WhatsApp, Instagram, Messenger or web chat first, you are responding rather than initiating: no A2P registration, no carrier fees, no approval wait, and no outbound consent architecture. That is the cheapest compliant place to start, and it is where the buying questions are anyway.
- What the TCPA and 10DLC actually are
- The rules at a glance
- Every number that matters
- Does the TCPA apply to AI-generated messages?
- The three rules that changed
- What valid consent actually requires
- 10DLC: registration, trust scores and throughput
- Price your own exposure
- TCPA vs 10DLC — the distinction that catches people out
- Inbound vs outbound: the compliance fork
- Channel by channel: what is regulated and what is not
- What your AI agent must be able to do
- The comparisons buyers ask for
- The six questions behind every compliance review
- How to launch without a compliance problem
- What none of this protects you from
- Where Jugl fits — and where it does not
- Methodology and disclosure
- FAQ — 26 questions answered
- People also ask
Definition
What are the TCPA and 10DLC rules for AI text messaging?
The TCPA and 10DLC rules for AI text messaging are two independent frameworks that both apply to every automated text a US business sends. The Telephone Consumer Protection Act is federal law governing whether you were permitted to send a message at all: it requires prior express written consent for marketing, honours revocation expressed in any reasonable manner within 10 business days, restricts sending to 8am–9pm in the recipient’s local time, and carries statutory damages of $500 to $1,500 per message with no cap in class actions. 10DLC is the carrier registration system, administered through The Campaign Registry, that determines whether a message from a 10-digit number is delivered at all — since February 2025 unregistered traffic is blocked. AI-generated messages receive no exemption from either. Inbound conversational AI on customer-initiated channels sits outside both.
Definition maintained by the Jugl Editorial Team. Jugl sells an inbound AI customer agent platform and benefits commercially from the inbound-versus-outbound distinction drawn on this page; the limits of that distinction are stated in full below.
Two frameworks, two completely different failure modes
The reason this trips up otherwise careful businesses is that the two frameworks fail in ways that look nothing alike. A 10DLC failure is loud and immediate: you register badly, your campaign is rejected, your messages do not arrive, somebody notices within a week because the numbers are flat. It is annoying, costs you days, and then it is fixed. A TCPA failure is silent for months. Everything works. Messages deliver. Engagement looks normal. Then a demand letter arrives referencing a specific date and a specific number, and the question is not whether the message was delivered — everyone agrees it was — but whether you can produce the record showing you were allowed to send it.
That asymmetry is why compliance budgets in this category are consistently misallocated. The registration fees get scrutinised because they appear on an invoice. The consent architecture gets deferred because it appears nowhere until it is the only thing that matters. If you are building the business case for an AI agent, the honest version prices both — and if you have not yet built that case, the AI agent ROI model takes the compliance layer as an explicit input rather than an afterthought.
- ✓Gets your messages delivered instead of blocked by carriers
- ✓Unlocks higher throughput tiers as your trust score improves
- ✓Signals a verified business identity to the carrier ecosystem
- ✓Reduces the odds of being filtered as spam by content heuristics
- ✓Establishes a documented use case, which helps with carrier disputes
- ✓Is comparatively cheap — usually a few hundred dollars a year, all in
- ×Provides zero defence against TCPA liability — it is a delivery gate, not a legal one
- ×Does not validate that your consent records are sufficient, or that they exist
- ×Does not detect a natural-language opt-out that your AI missed
- ×Does not propagate suppression across your other channels
- ×Does not apply at all to WhatsApp, Instagram, Messenger, web chat or email
- ×Does not cover state mini-TCPA statutes, which have their own private rights of action
The rules at a glance
At a glance
- What TCPA governs
- Whether you were legally permitted to send — calls and texts to telephone numbers
- What 10DLC governs
- Whether carriers deliver the message from a 10-digit number
- Do they overlap?
- No — independent gates. Both must be passed, neither substitutes for the other
- Does AI change anything?
- No exemption. AI voices are "artificial" under the statute; AI texts are texts
- TCPA statutory damages
- $500 per message · $1,500 wilful · no cap in class actions
- DNC Registry fine
- Up to $43,792 per call or text
- Consent standard (marketing)
- Prior express written consent — disclosed, affirmative, documented
- Revocation standard
- Any reasonable manner, including natural language, email or voicemail
- Deadline to honour opt-out
- As soon as practicable, no later than 10 business days
- Post-opt-out allowance
- One message, within five minutes, confirmation or scope clarification only
- Time-of-day window
- Generally 8am–9pm in the recipient’s local time
- 10DLC total setup cost
- ~$65–$500 upfront, depending on brand type and vetting
- 10DLC ongoing cost
- $1.50–$10 per campaign monthly, plus ~$0.003–$0.005 per message
- Time to approval
- 1–4 weeks end to end
- Trust score that matters
- 75–100 permits meaningfully higher throughput
- Applies to B2B?
- Yes — texts to wireless numbers are treated the same as B2C
- What is exempt
- Inbound conversational AI on WhatsApp, Instagram, Messenger, web chat and email
- Cheapest compliant start
- Answer on channels customers already message you on
Every number that matters, in one place
| Item | Figure | Which framework |
|---|---|---|
| TCPA statutory damages | $500 per message; $1,500 if wilful or knowing | TCPA |
| Class action cap | None | TCPA |
| National DNC Registry fine | Up to $43,792 per call or text | TCPA / FTC |
| Deadline to honour opt-out | 10 business days, sooner if practicable | TCPA |
| Post-revocation clarification | 1 message, within 5 minutes | TCPA |
| Time-of-day window | 8am–9pm recipient local time | TCPA |
| Brand registration — sole proprietor | ~$4 one-off | 10DLC |
| Brand registration — standard brand | $48+ one-off | 10DLC |
| Campaign registration | ~$15–$17 per campaign | 10DLC |
| Monthly campaign fee | $1.50–$10 per campaign | 10DLC |
| Carrier per-message surcharge | ~$0.003–$0.005 | 10DLC |
| Standard third-party vetting | ~$40 | 10DLC |
| Brand approval time | 1–5 business days | 10DLC |
| Campaign approval time | 3–7 business days, up to 15 when busy | 10DLC |
| Trust score for higher throughput | 75–100 | 10DLC |
Does the TCPA apply to AI-generated messages?
Yes, unambiguously, and it is worth being precise about why — because the reasoning determines what else is captured. The FCC has long treated text messages as “calls” for TCPA purposes, which pulls SMS into the same core restrictions that govern phone calls: consent, revocation, do-not-call scrubbing, time-of-day windows. Nothing about that analysis turns on who or what composed the message. A text generated by a large language model is a text.
On the voice side the FCC went further and said the quiet part out loud: AI-generated voices are “artificial” voices under the statute. That places an AI voice agent in the same category as a prerecorded message, requiring the same prior express consent — a materially higher bar than a person dialling manually. Businesses deploying AI calling and texting agents are therefore deploying them directly into TCPA scope, and in our experience a great many do so without realising the consent requirements attach at all.
Why AI raises the stakes rather than lowering them
There is no AI exemption anywhere in the framework, and the structural argument runs the other way: AI warrants tighter governance than a manual process, because exposure is assessed per message and AI scales message volume faster than any human workflow. A team that would have sent four hundred texts by hand might send forty thousand with an agent. Nothing in the policy changed; the theoretical liability multiplied by a hundred. Volume is the multiplier on every number in the table above.
The second reason is subtler and specific to language models. A scripted system fails predictably — you can read the flow and know what it will do. A model generates, which means the compliance-relevant behaviours you care about (recognising an opt-out, refusing to send outside a window, declining to re-engage a suppressed contact) are not properties of the copy, they are properties of the system around the copy. Compliance for an AI agent lives in the send layer and the classification layer, not in the message template. That distinction is the difference between an AI agent and a traditional chatbot, and it has consequences well beyond compliance.
The three rules that changed, and where each stands
Most published guidance in this area is out of date, and it is out of date in both directions — describing requirements that were struck down, and omitting requirements that are now in force. Here is the current state of the three that matter.
1. The consent revocation rule — in force since 11 April 2025
This is the operative rule today, and the one most businesses are quietly non-compliant with. Its terms are specific:
2. The one-to-one consent rule — vacated
Scheduled to take effect on 27 January 2025, it was vacated by the Eleventh Circuit three days beforehand. It is not in force. Guidance telling you to obtain separate consent for each individual seller is describing a rule that no longer exists — and there is a lot of that guidance still circulating, because compliance content ages badly and nobody revisits a published checklist.
Do not over-read the vacatur, though. The underlying prior express written consent standard is entirely untouched. Consent still does not transfer between companies. And a consent form that lists hundreds of unrelated “marketing partners” in a scrolling box remains very hard to defend as clear and conspicuous disclosure, whatever the one-to-one rule’s fate. The rule was struck down; the reasonable-consumer standard behind it was not.
3. The revocation-all requirement — delayed to 31 January 2027
This provision turns any opt-out into a global one. Once effective, an opt-out would revoke consent for all automated marketing messages from that sender, and — unless the consumer indicates otherwise — for informational and transactional calls and texts too, across every purpose and every channel. It had been due in April 2026; in January 2026 the FCC issued an order delaying it to 31 January 2027.
Build for it now anyway. Not out of caution, out of arithmetic. If opt-out state lives as four separate flags in your SMS platform, your email tool, your CRM and your helpdesk, unifying them later is a data migration with a deadline attached. If every channel checks one suppression service before sending, you are already compliant and the deadline is a non-event. That is a design decision available to you today at close to zero cost, and a project with a fixed date and a legal consequence if you defer it.
Also on the horizon: AI disclosure
The FCC has an open proceeding on AI-generated voice and text communications. The proposals under consideration include requiring disclosure that a message was AI-generated at the outset of an interaction, and extending revocation rights across all AI-generated channels. These are proposals, not final rules, and should not be treated as current obligations. But the direction is clear enough to design toward — and separately, several US states have enacted or proposed bot-disclosure requirements in specific contexts, and the EU AI Act imposes transparency obligations on systems that interact with people. If you operate anywhere beyond a single US state, disclosure is heading toward you from more than one direction.
What valid consent actually requires
Consent is where TCPA cases are won and lost, and the standard is more demanding than most businesses assume. It is not a checkbox. It is a documented record of a specific disclosure shown to a specific person at a specific moment, and the burden of producing it falls on you.
| Requirement | What it means in practice |
|---|---|
| Prior express written consent (marketing) | Clear disclosure, affirmative action, documented and timestamped |
| Not a condition of purchase | The form must state that consent is not required in order to buy |
| Identify the sender | Name the specific business that will be sending the messages |
| Describe the message types | What they will receive, at roughly what frequency |
| No pre-checked boxes | Consent cannot be the default state of a form control |
| No burial in terms | Consent cannot be inferred from a link to terms of service |
| Revocable in any reasonable way | Honoured as soon as practicable, within 10 business days |
| DNC scrubbing | National registry plus your own internal do-not-call list |
| Time-of-day restriction | Generally 8am–9pm in the recipient’s local time, not yours |
| Auditable records | You carry the burden of proof, potentially years later |
The three assumptions that cause the most damage
“They are our customers, so we can text them.” A purchase is not consent to receive marketing texts. Transactional messages directly tied to that order stand on firmer ground, but promotional messages need separately captured consent, and the boundary between the two is narrower than marketing teams like. A shipping notification with a discount code appended is not a shipping notification.
“It is a business number, so the TCPA does not apply.” B2B texts to wireless numbers are subject to the same restrictions as B2C, and most business contacts today are mobile numbers. A business card, a LinkedIn connection, a downloaded whitepaper and an existing vendor relationship are none of them prior express written consent.
“We bought the list from a reputable source.” Consent does not transfer between companies. Selling or sharing consent with third parties does not create valid consent for those third parties, regardless of what the original form said about partners. Consent also does not last forever — a record from a form filled in years ago, for a business that has since changed name and message types, is a weak record even where it technically exists.
- The timestamp of consent, to the second
- The channel and specific page or form where it was captured
- The exact disclosure language displayed at that moment — the revision, not the current version
- The affirmative action taken, and what it was labelled
- The message types and sender the person agreed to
- IP address or device identifier, where available
- The complete history of every message sent to that number
- The revocation log: when, on what channel, in what words, and when suppression took effect
- A version history of every consent form you have published
10DLC: registration, trust scores and throughput
10DLC — 10-Digit Long Code — is the registration system US carriers use to authorise business texting from standard 10-digit numbers, administered through The Campaign Registry. If you send any automated SMS in the US, whether marketing, reminders or order updates, you need it. Since February 2025 all major carriers block unregistered application-to-person traffic, which changed this from a deliverability optimisation into a precondition for the channel existing at all.
The registration sequence, and where it goes wrong
You register a brand first — your legal business identity, EIN, address — and then one or more campaigns, each describing a specific messaging use case with sample messages and an account of how you collect opt-in. Brand registration typically clears in one to five business days. Campaign registration takes three to seven, stretching to ten or fifteen in busy periods. Budget one to four weeks end to end and assume at least one rejection.
| Brand state | What it means | What you can do |
|---|---|---|
| Unverified | Usually a business-name or EIN mismatch against public records | Nothing — all 10DLC messaging is blocked until it is fixed |
| Verified | Identity confirmed; the baseline state | Register campaigns and send at standard throughput |
| Vetted Verified | Third-party review completed | Higher throughput tiers and better carrier treatment |
Trust scores between 75 and 100 permit meaningfully higher messages per second. If your business is not on the Russell 3000, you are capped at a lower throughput tier without paying for third-party vetting — roughly $40, and usually worth it the moment volume matters. The most common causes of rejection are mundane and entirely avoidable: a legal name that does not match your EIN registration exactly, sample messages that do not correspond to the described use case, an opt-in flow a reviewer cannot find or complete on your live site, and sample messages missing the opt-out instruction.
- Legal business name, EIN and address match your public registration character for character
- One campaign per genuine use case — do not bundle marketing and two-factor codes together
- Sample messages are real messages you will actually send, not placeholders
- Every sample includes the opt-out instruction
- The opt-in flow described exists on your live site and a stranger can complete it
- Your privacy policy and messaging terms are published and reachable from the opt-in page
- Consent language on the form states message frequency and that data rates may apply
- Delivery verified on real handsets across all three major carriers before you scale
Price your own exposure
Eight inputs. The first seven price the visible cost of the outbound lane — registration, campaign fees, carrier surcharges. The eighth prices the invisible one. Outputs are illustrative estimates generated from your inputs, not a legal assessment, a quote or a prediction of any actual liability.
What the outbound lane actually costs you
Registration and carrier fees, approval time, and the statutory exposure nobody budgets for
Everyone on the list you intend to message — customers, leads, past buyers, imported records. Count the whole list, not the segment you plan to start with.
Include everything: promotions, reminders, order updates, re-engagement. Informational messages are inside the revocation rule too, not only marketing.
Not the share who seem happy to hear from you — the share for whom you could produce a timestamp, the exact disclosure shown, and what they agreed to. You carry the burden of proof.
Carriers register message use cases separately. Marketing, order notifications, appointment reminders and two-factor codes are typically distinct campaigns.
Recurring carrier campaign fees run roughly $1.50 to $10 a month each, depending on use case and provider.
Charged per message on top of whatever your provider bills. Roughly $0.003 to $0.005, and it applies to every message whether or not anybody reads it.
About $4 for a sole proprietor, $48 and up for a standard brand, plus roughly $40 if you need third-party vetting to unlock higher throughput.
The share of this volume that is answering a question — order status, availability, booking changes — rather than initiating one. That share belongs in the inbound lane, where none of this applies.
TCPA vs 10DLC: the distinction that catches people out
These are separate requirements that apply simultaneously, and the single most costly misunderstanding in this area is treating one as evidence of the other. Carriers do not check your consent records. Courts do not check your trust score.
| Dimension | TCPA | 10DLC |
|---|---|---|
| What it is | Federal statute | Carrier registration system |
| Who enforces it | FCC, FTC, and private plaintiffs | Mobile carriers, via The Campaign Registry |
| What it decides | Whether you were permitted to send | Whether the message is delivered |
| Penalty for failure | $500–$1,500 per message, uncapped in class actions | Messages blocked; carrier fines possible |
| When you find out | Months later, by demand letter | Immediately, by flat delivery numbers |
| Applies to WhatsApp / IG / web chat | No — those are not calls to phone numbers | No — those are not carrier SMS |
| Applies to inbound conversations | Not in the way it applies to outbound | No registration needed |
| Cost to comply | Engineering, records and legal review | ~$65–$500 upfront plus ongoing fees |
| Does the other one help? | No — registration is not a defence | No — consent does not get you delivered |
Inbound vs outbound: the compliance fork
Almost the entire burden described on this page attaches to one thing: sending automated messages to people who did not message you first. Flip the direction and most of it simply does not arise — not as a loophole, but because the question the TCPA exists to answer does not come up. You are not interrupting somebody; they interrupted you.
| Requirement | Outbound US SMS | Inbound conversational AI |
|---|---|---|
| A2P 10DLC brand registration | Required | Not applicable |
| Campaign registration and fees | Required, per use case | Not applicable |
| Carrier per-message surcharge | ~$0.003–$0.005 every message | None |
| Approval wait before first send | 1–4 weeks | None — live the same day |
| Prior express written consent | Required for marketing | The customer initiated the conversation |
| Consent record-keeping burden | Substantial and auditable | Minimal |
| Time-of-day restrictions | 8am–9pm recipient local time | They chose when to message you |
| DNC list scrubbing | National plus internal | Not applicable |
| Statutory damages exposure | $500–$1,500 per message | Not the same exposure |
| Where the buying intent is | You guess and interrupt | They are already asking |
State the conflict of interest here, because it is real. Jugl sells inbound AI agents, so a page concluding that inbound is simpler is a page concluding that you should buy what we sell. The distinction is nonetheless accurate and is the reason the row above is worth reading — but read the next paragraph too, because it is where the argument stops.
Inbound is not a compliance-free zone. General consumer protection law applies. State privacy and session-recording statutes apply, and two-party consent states have specific requirements for recorded or monitored conversations. Data protection obligations apply to whatever you store. Platform policies apply and are enforced by quality rating rather than by regulator. And the instant you capture a phone number in an inbound conversation and send an outbound text to it, you are back inside the TCPA in full, regardless of where the conversation began. The channel of capture does not determine the channel of obligation.
The commercial argument, separate from the compliance one
There is a cost advantage running alongside the compliance advantage, and it happens to point the same way. Meta bills WhatsApp per delivered template message, but replies inside the customer-initiated 24-hour service window are free, and click-to-WhatsApp ads open a 72-hour free window. An inbound-first strategy sits inside those windows by design, which makes instant response financially trivial rather than expensive. Meta has announced it will begin charging for service messages from 1 October 2026, which is worth modelling now rather than discovering later. The full channel economics are in the WhatsApp platform comparison.
The intent argument is stronger still. Outbound guesses who is interested. Inbound already knows — somebody asking whether an item is in stock at 11pm on a Sunday has told you exactly where they are in the purchase, and they are not going to wait until Monday to find out. That is not a support ticket appearing in a queue metric; it is a sale appearing in a competitor’s revenue. How agents read those signals is covered in the concierge model, and the broader shift is documented in the conversational commerce report.
Channel by channel: what is regulated and what is not
A single “messaging compliance policy” that treats every channel identically will be wrong in both directions — over-restricting where nothing applies, and under-restricting where a great deal does. The obligations differ by channel, and so should your agent’s behaviour.
| Channel | TCPA | 10DLC | What actually governs it |
|---|---|---|---|
| Outbound US SMS | Yes, fully | Yes, required | TCPA, FCC rules, state mini-TCPA statutes, carrier policy |
| Outbound AI voice calls | Yes — AI voices are "artificial" | No | TCPA prerecorded-call consent standard, state call recording law |
| Inbound SMS reply | The conversation is customer-initiated | Number must still be registered | Carrier policy for the number itself |
| No | No | Meta WhatsApp Business Platform policy, template approval, quality rating | |
| Instagram DM | No | No | Meta platform policy and messaging windows |
| Facebook Messenger | No | No | Meta platform policy and messaging windows |
| Website chat | No | No | Consumer protection, state privacy and session-recording law, accessibility |
| No | No | CAN-SPAM in the US; GDPR and equivalents elsewhere | |
| RCS | Treated as messaging to a phone number | Registration generally required | Carrier and Google platform policy, plus TCPA analysis |
Channel classification is a starting point for a conversation with counsel, not a substitute for one. State law in particular varies significantly, several states have mini-TCPA statutes with independent private rights of action, and the analysis can turn on facts specific to how you capture and use a number.
The trap in the middle of that table
Look at the WhatsApp row and the outbound SMS row together. The same customer, the same question, the same AI agent, the same answer — and completely different legal machinery, depending only on which app the message travelled through. That is worth internalising before you design your channel strategy, because it means the channel decision is a compliance decision made months before anybody in legal sees a document. Businesses that pick channels on marketing grounds and discover the compliance consequences afterwards are the ones who end up retrofitting consent capture into a live system.
It is also why multi-channel AI is worth more than it looks. If your agent runs across WhatsApp, Instagram, Messenger, web chat and email with one shared customer history, the customer chooses the channel and you inherit the lightest applicable obligation. Getting that architecture right from the start is covered in the customer support agent guide, and the multilingual dimension in multilingual AI support.
What your AI agent must actually be able to do
Compliance for an AI messaging system is not a policy document, it is a set of behaviours in the send layer and the classification layer. These are the capabilities to require of any vendor, and to verify rather than accept on assurance.
The comparisons buyers ask for
AI agent versus traditional chatbot, on compliance
| Capability | Scripted chatbot | AI agent |
|---|---|---|
| Recognises "please stop texting me" | No — keyword match only | Yes, as a classified intent |
| Handles misspelled or multilingual opt-outs | No | Yes, if the classifier is trained for it |
| Escalates ambiguous requests | Falls through to a menu | Routes to a person with context |
| Detects legal or safety signal | No | Yes — a routing rule, not a guess |
| Explains what it is | Usually not | Disclosure in the opening message |
| Audit trail of decisions | Flow logs only | Classification, confidence and action logged |
| New requirement means | Rebuild the flow | Update the rule and the training |
Outbound-first versus inbound-first, as a strategy
| Dimension | Outbound-first | Inbound-first |
|---|---|---|
| Time to first message | 1–4 weeks of registration | Same day |
| Upfront cost | $65–$500 plus legal review | None beyond the platform |
| Ongoing per-message cost | Carrier surcharge on every send | Free inside the service window |
| Consent infrastructure | Capture, storage, proof, versioning | Not required for the conversation |
| Statutory exposure | $500–$1,500 per message | Not the same exposure |
| Intent quality | Assumed | Demonstrated — they asked |
| Who it suits | Established lists with provable consent | Almost everyone else, as a starting point |
Jugl versus a typical outbound SMS stack
| What you have to do | Outbound SMS platform | Jugl |
|---|---|---|
| Register a brand and campaigns | Yes, before anything sends | Not applicable |
| Wait for carrier approval | 1–4 weeks | None |
| Pay per message to carriers | Yes, on every send | No |
| Build a consent database | Yes, with auditable proof | Not for inbound conversations |
| Channels covered | SMS, sometimes MMS | WhatsApp, Instagram, Messenger, web chat, email |
| Pricing model | Per message, plus platform fee | Flat published tiers |
| Free tier | Trial, then card required | Permanent free tier, no card |
| Handles the compliance for you | No | No — and any vendor claiming otherwise is overselling |
Stated as a disclosure rather than a finding: this is our own product, and the last row is the honest one. Choosing inbound changes which obligations attach to you. It does not delegate any obligation to us. Worked comparisons against named platforms are on the comparison hub, and Jugl vs Meta’s own business agent covers the closest adjacent option.
The six questions behind every compliance review
Does any of this apply if the AI wrote the message?
Short answer
Yes. The TCPA governs the act of sending an automated message to a phone number, not the authorship of the text. The FCC has confirmed AI-generated voices are 'artificial' under the statute, and text messages have long been treated as calls. There is no AI exemption anywhere in the framework.
Example
We are registered for 10DLC. Are we covered?
Short answer
No. 10DLC is a delivery gate operated by carriers; the TCPA is federal law enforced by regulators and private plaintiffs. Registration says nothing about whether consent was validly obtained. A fully approved campaign sent to non-consenting contacts is a fully delivered violation.
Example
Our AI handles STOP. Is that enough?
Short answer
No, and this is the most common AI-specific failure. Since 11 April 2025 consumers may revoke consent in any reasonable manner. The FCC explicitly declined to limit revocation to keywords. Natural-language requests, emails and voicemails all count, and a keyword matcher misses every one of them.
Example
Does inbound AI really avoid all of this?
Short answer
It avoids the A2P registration layer and the outbound consent architecture, because you are responding to customer-initiated contact rather than initiating automated contact. It does not avoid consumer protection law, state privacy and recording rules, data protection, or platform policy — and it stops entirely the moment you send an outbound text.
Example
The global opt-out rule is delayed. Can we defer the work?
Short answer
You can, and it will cost more. The requirement that an opt-out revokes consent across all purposes and channels is delayed to 31 January 2027, but the underlying build — one suppression service every channel checks — is a design decision today and a data migration later.
Example
What is the cheapest compliant way to start?
Short answer
Deploy AI on the channels customers already message you on — WhatsApp, Instagram, Messenger, web chat and email. No brand registration, no campaign fees, no carrier approval wait, no consent database, and no per-message surcharge. Prove the model there, then take on outbound only if the revenue clearly justifies the layer.
Example
How to launch AI messaging without a compliance problem
Seven steps, in this order. The order is the point — most of the pain in this area comes from doing step three before step one.
- Inbound and outbound separated, with the outbound list explicitly scoped
- 10DLC brand and every campaign registered and approved before the first outbound send
- Consent captured with timestamp, channel, disclosure revision and affirmative action
- Opt-out detection built as intent classification, not keyword matching
- Suppression propagates across every channel and purpose from one service
- Post-opt-out messaging hard-capped at one confirmation within five minutes
- Revocation honoured well inside 10 business days, with the log to prove it
- National DNC registry and internal do-not-call list both scrubbed before every send
- Time-of-day window enforced in the recipient’s timezone at send time
- AI involvement disclosed at the start of the conversation
- Unconditional escalation path to a human, with full transcript carried across
- Consent form version history retained, and one number spot-checked end to end
- Counsel has reviewed your consent language and your states of operation
What none of this protects you from
A compliance page that only lists reassurances is worse than useless, because it produces confidence without protection. Here is what remains after you have done everything above.
Where Jugl fits — and where it does not
What it changes. Jugl’s AI agents work on inbound channels — WhatsApp, Instagram, Facebook, web chat and email — where customers reach out to you. That removes A2P 10DLC brand registration, campaign fees, carrier surcharges, the one-to-four-week approval wait and the outbound consent infrastructure from your project, because none of them attach to a conversation the customer started. As a Meta Business Partner, Jugl connects those channels natively rather than as an integration project, so the whole thing is live the same day.
What it changes commercially. Replies inside the customer-initiated 24-hour WhatsApp service window are free and click-to-WhatsApp ads open a 72-hour free window, so an inbound-first agent answers at essentially no marginal cost — while outbound template messages carry per-message pricing on top of carrier surcharges. Jugl’s own pricing is flat and published, with nothing metered per resolution, so the cost of answering more conversations does not rise as the agent succeeds. Full pricing is on the pricing page, and the wider return is modelled on the ROI page.
What it changes for your customers. The agent answers instantly in your brand voice across every channel, reads what the customer is actually asking for, and hands off to a real person the moment it matters — with the full transcript, so nobody has to explain themselves twice. Jugl is used by 1,000+ businesses. What that looks like in practice is on what is Jugl, and the handoff design specifically on the AI-to-human handoff guide.
What we cannot do for you. We are not your compliance function and we are not a law firm. If you send outbound SMS, you still need registration, consent capture, suppression, DNC scrubbing and legal review, and none of that becomes our obligation because you bought software. Choosing the inbound lane changes which rules attach to you; it does not delegate any rule to a vendor. Any platform telling you otherwise is selling you a comfort that will not survive a demand letter.
Methodology and disclosure
Written by
Jugl Editorial TeamJugl Inc., Frisco, Texas — an AI customer agent platform used by 1,000+ businesses.
Reviewed by
Jugl product & customer operationsChecked against live deployment data and current vendor documentation.
Methodology & disclosure
Where the figures come from. TCPA statutory damages, the prior express written consent standard, time-of-day restrictions and the treatment of texts as calls are from the statute and FCC rules and orders. The consent revocation rule, the five-minute confirmation allowance, the 10 business day deadline and the delayed revocation-all provision are from the FCC’s published orders. The vacatur of the one-to-one consent rule is the Eleventh Circuit decision issued days before it was due to take effect. National Do Not Call Registry forfeiture figures are the published adjusted maximums. 10DLC brand, campaign, vetting and surcharge figures are from The Campaign Registry and US carrier published schedules. WhatsApp template pricing, the customer-initiated service window and the click-to-WhatsApp window are Meta’s published Business Platform pricing. Jugl pricing is our own published price list.
How the model works. Messages a month is contacts multiplied by messages per contact. Run cost is messages multiplied by the carrier surcharge, plus campaigns multiplied by the monthly campaign fee. Registration is the brand fee plus roughly $16 per campaign. Messages without provable consent is total messages multiplied by one minus your documented-consent share, and theoretical exposure is that figure multiplied by the $500 and $1,500 statutory damages. Nothing is hidden in a constant. Outputs are illustrative estimates generated from your own inputs — not a legal assessment, not a prediction of actual liability, and not a substitute for counsel.
Conflict of interest, stated plainly. Jugl sells an inbound AI customer agent platform, so a page concluding that inbound messaging carries a lighter compliance burden is a page concluding that you should buy what we sell. The distinction is real and load-bearing, and we have tried to earn the claim by stating its limits explicitly: inbound does not exempt you from consumer protection law, state privacy and recording statutes, data protection or platform policy; it ends the moment you send an outbound text; and choosing it does not transfer a single obligation from you to us. The comparison table naming our own product is labelled as a disclosure rather than a finding.
How this page is maintained and what it is not. Reviewed against current published rules, orders and carrier schedules, and revised when they change. Unlike the rest of this cluster it carries effective dates, because a compliance rule without its date is not merely stale, it is wrong. This page is general information for business owners evaluating AI messaging. It is not legal advice, it does not create an attorney-client relationship, and it does not cover state mini-TCPA statutes or non-US regimes. Consult qualified counsel for your business, your use case and your states of operation.
TCPA and 10DLC for AI messaging: 26 questions answered
Does the TCPA apply to AI-generated text messages?
What is 10DLC and do I need it?
What is the difference between TCPA and 10DLC?
How much does 10DLC registration cost in total?
Is the one-to-one consent rule still in effect?
How long do I have to honour an opt-out request?
Can my AI send a confirmation text after someone opts out?
What words count as a valid opt-out?
Do I need 10DLC for WhatsApp messages?
Does the TCPA apply to AI chatbots on my website?
Does the TCPA apply to B2B text messages?
What happens if I send unregistered A2P SMS?
What are the TCPA time-of-day rules?
What is prior express written consent?
Does consent transfer if I buy a list or acquire a company?
What is the revocation-all requirement and when does it take effect?
Does the FCC regulate AI voice calls the same way?
What is a 10DLC trust score and why does it matter?
How long does 10DLC approval take?
What records do I need to keep to defend a TCPA claim?
Is inbound AI messaging really exempt from all of this?
Do I need to disclose that a customer is talking to an AI?
How do I make my AI recognise revocation in natural language?
What does a TCPA claim actually cost a small business?
Does email fall under the TCPA?
How does Jugl handle TCPA and 10DLC compliance?
People also ask
The compliant lane is also the one where the customers already are
Everything on this page attaches to one thing: sending automated messages to people who did not message you first. Registration, consent databases, suppression architecture, carrier approval, statutory damages assessed per message. Flip the direction and most of it does not arise — and the conversations waiting on the other side are the ones where somebody is already asking you a question they want answered now.
You do not need a compliance project to find out whether this works. Point a free agent at your own website, connect the channels your customers already message you on, and watch what it handles overnight. Nothing to register. Nothing to approve. No card. If it disappoints, you have learned that in an afternoon rather than after a four-week carrier wait.
The registration queue is one to four weeks. The consent database is a quarter. The inbound conversations arriving tonight are not going to wait for either of them.
SOC 2 Type 2 · HIPAA compliant · Meta Business Partner · NVIDIA Inception · 1000+ businesses
Keep reading
Sources: the Telephone Consumer Protection Act and FCC rules and orders (treatment of texts as calls, artificial and prerecorded voice standard, prior express written consent, time-of-day restrictions, the consent revocation rule effective 11 April 2025, the five-minute single-confirmation allowance, the 10 business day deadline, and the order delaying the revocation-all provision to 31 January 2027); the Eleventh Circuit decision vacating the one-to-one consent rule; published FCC and FTC forfeiture schedules for National Do Not Call Registry violations; The Campaign Registry and US carrier published schedules (brand, campaign, vetting and per-message fees, approval timelines, trust score tiers and the blocking of unregistered A2P traffic); and Meta’s published WhatsApp Business Platform pricing (template categories, the customer-initiated service window, the click-to-WhatsApp window and announced changes to service message pricing). Jugl pricing is our own published price list. This page is published by Jugl, which sells an inbound AI customer agent platform and is therefore an interested party in the inbound-versus-outbound distinction it draws; the limits of that distinction are stated in full above. This page is general information, not legal advice, and does not create an attorney-client relationship. It does not address state mini-TCPA statutes or non-US regimes. Consult qualified counsel for advice specific to your business. Meta, WhatsApp, Messenger, Instagram and Facebook are trademarks of Meta Platforms, Inc.; Jugl is a Meta Business Partner and this page is published by Jugl and is not endorsed by or affiliated with Meta Platforms, Inc. All other product names are trademarks of their respective owners.
Start free at Jugl · No card required · Permanent free tier