
"We already tick a box when they book. Isn't that permission enough?" It is the first thing an owner says when the subject of outbound AI voice comes up, and it is a fair objection. You do have a box. Someone did tick it. The call that follows sounds courteous, the AI is polite, nobody complains. And still, in most of the wordings we read, the AI voice call consent opt-in rules are not satisfied, because the box says the customer agreed to be contacted, and says nothing about being contacted by a machine that speaks.
The Call That Sounded Fine and Wasn't
Picture the before. A clinic runs a recall campaign for lapsed patients. The voice is warm, gets the name right, offers two appointment slots, books eleven people in an evening. The consent basis is a booking form checkbox reading "I agree to be contacted about my appointments and offers."
Now the after, same campaign, one changed sentence on the form: "I agree to receive calls, including automated calls made with an artificial or AI-generated voice, about my appointments and about offers from the clinic. Consent is not required to receive treatment and I can withdraw it at any time." Identical call, identical booking rate, entirely different legal position.
The difference is not politeness. The United States Federal Communications Commission settled this in a Declaratory Ruling adopted 2 February 2024, confirming that the Telephone Consumer Protection Act's restrictions on "artificial or prerecorded voice" cover current AI technologies that generate human voices, so those calls require the called party's prior express consent absent an emergency purpose or exemption. The same ruling notes that voice cloning falls inside the existing prohibition because it artificially simulates a human voice. If the call sells something, the standard rises: where AI calls introduce an advertisement or contain telemarketing, prior express written consent is required.
Naming It: The Consent Script
The Consent Script is the exact wording, at the moment of collection, that names the automated voice, names the purpose, and names the exit, in that order. Not the checkbox. Not the privacy policy the checkbox links to. The words the person reads or hears before they say yes.
Everything else operators worry about (which vendor, which voice, how natural it sounds) is downstream of this. A flawless AI voice calling on a defective Consent Script is an unlawful call delivered beautifully. A plain, slightly robotic voice calling on a sound Consent Script is a lawful call.
Three components, and each one fails independently:
- Voice disclosure. The permission must contemplate an automated or AI-generated voice, not "contact" in the abstract.
- Purpose scope. Appointment admin and marketing are different permissions. Marketing carries the written-consent bar in the US.
- Exit. Consent is voluntary, not a condition of service, and withdrawable. Published AI voice consent policies in the market state exactly that: consent is voluntary, not required for services, and can be withdrawn at any time.
Why the Script Is a Legal Mechanism, Not a Courtesy
Two instincts get operators into trouble. The first is the belief that a human somewhere in the loop cures the problem. It does not. The FCC's reasoning aligns with its earlier Soundboard Ruling, which confirmed that the presence of a live agent selecting the content of an artificial or prerecorded voice message does not take the call outside the rules. A supervisor listening in is supervision, not consent.
The second is the belief that nuisance is a matter of content. Congress's own finding when adopting the TCPA was that residential subscribers treat automated calls as a nuisance and an invasion of privacy regardless of content or initiator. Being helpful is not a defence.
What applies where
Jurisdiction matters more in voice than in messaging, because the rulebooks were written by different bodies.
| Where | Who holds the pen | What it means for outbound AI voice |
|---|---|---|
| United States | FCC (TCPA rules), FTC (Telemarketing Sales Rule) | Prior express consent for AI voice; prior express written consent where the call advertises or telemarkets; automated opt-out mechanics on prerecorded telemarketing calls |
| United Kingdom | Ofcom and the ICO under PECR | Automated marketing calls sit under the strictest end of direct-marketing consent; the operative question is whether the person consented to automated calls specifically, not to contact generally |
| UAE | TDRA, plus sector regulators | Telemarketing and automated calling are licensed, controlled activity; healthcare messaging additionally sits under DHA in Dubai and DoH in Abu Dhabi |
The UK and UAE positions are not reducible to a quoted line the way the FCC's ruling is, and no single published sentence does the job. The practical consequence is the same in all three: a permission that does not mention an automated voice is a weak permission, and in the US it is explicitly the wrong one.
What the Consent Script Predicts You Must Do Next
A named mechanism is only useful if it forecasts obligations. This one does.
If the Consent Script promises an exit, the call must contain a working one. Under the FTC's Telemarketing Sales Rule, a prerecorded telemarketing call's opt-out mechanism must automatically add the number to the seller's entity-specific Do Not Call list without human intervention, and immediately disconnect once invoked. No transfer to a retention agent. The same rule requires that the mechanism be accessible at any time throughout the campaign, including outside business hours, and that where the call could reach an answering machine, the message discloses a toll-free number at the outset connecting to the same opt-out mechanism. Both the in-call keypress or voice option and the toll-free number are required whenever you cannot be certain a person will not answer live, which in practice is always.
If the Consent Script says "AI", the call must say so too, out loud, at the top. Published policies in this category commit the system to identifying itself as automated at the beginning of each call, never misrepresenting itself as human, and offering a human on request. That last one is an operational promise, not a line of copy; it needs a real route to a real person, which is the part most deployments underbuild. We have written separately about how that handoff to a human should be mapped.
If the Consent Script separates admin from marketing, your system must honour the separation. A patient who consented to appointment reminders and not offers must be reachable by the first flow and unreachable by the second. If your CRM cannot hold two flags, it cannot hold your consent.
The artefact: a Consent Script you can use this week
Web or paper form, single checkbox, unticked by default:
"I agree that [Business] may call me, including calls placed by an automated system using an AI-generated voice, about (a) my bookings and appointments and (b) offers and services. Calls will identify themselves as automated at the start, and I can ask to speak to a person at any time. I can withdraw this consent at any time by saying 'stop AI calls' during a call, replying to any message, or emailing [address]. Consent is not a condition of receiving services."
For verbal capture, front desk or inbound call, recorded:
"Before we finish, may I have your permission for us to call you about your appointments, including calls placed by our automated AI voice system? It always says it's automated and you can ask for a person or ask us to stop at any time. Is that a yes?"
Keep the recording or the timestamped form record. Consent you cannot evidence is consent you do not have.
Six questions to put to a voice vendor
- Does the agent announce it is automated in its first spoken sentence, and can I hear a recording of it doing so?
- What exact phrases trigger an opt-out, and does the opt-out write to the suppression list without a human touching it?
- Does opt-out disconnect the call immediately, or does it route to a save attempt?
- Can the system hold separate consent flags for transactional and marketing calls, and refuse a campaign when the flag is missing?
- Do you provide a toll-free opt-out number for voicemail drops?
- Where is call audio and transcript stored, and does that placement satisfy DHA or DoH rules if I am a clinic?
Consent-Basis Territory: Where Operators Still Win
The rules bite hardest on cold outbound marketing by machine. They leave a great deal of room everywhere else, and the operators growing fastest are working that room rather than fighting the rules.
Safe and genuinely effective:
- ✅ Rebuild your intake forms and front-desk phrasing to capture the voice-disclosed permission from now on. Every new lead from today arrives usable; the backlog is the only hard part.
- ✅ Point AI voice at inbound and at calls the customer initiated or expects, where the consent question is far simpler than outbound marketing to a cold list.
- ✅ Use messaging channels for the promotional layer and keep voice for admin, which also tends to be where voice performs better. Our note on voice note disclosures covers the messaging side.
- ✅ Split your database by consent quality now and treat unclear records as marketing-ineligible until re-permissioned.
- ✅ Log the opt-out latency. If a request to stop takes a human to action it, the system is not compliant even if the wording is.
Tempting, and genuinely triggering:
- ❌ Relying on a generic "I agree to be contacted" tick for AI-voiced marketing calls in the US. The FCC's ruling is explicit that these calls need prior express consent, and telemarketing content needs it in writing; the exposure here is statutory damages per call.
- ❌ Letting the agent pass as human, or dodging the question when asked. Beyond the policy exposure, it is the single fastest way to turn a mild complaint into a regulator-facing one.
- ❌ Routing an opt-out to a retention script. The Telemarketing Sales Rule bars operator intervention after the mechanism is invoked and requires immediate disconnection.
- ❌ Placing a live agent on the line and treating that as an exemption. The Soundboard reasoning closes that door.
Borderline, and used in the field:
- ⚠️ Re-permission campaigns by human call or by message to an old list. This gains you a clean, voice-disclosed database. The risk is regulatory rather than platform: the underlying contact permission must still cover the channel you use to ask. Suits operators with a decent existing consent trail, not those starting from a purchased list.
- ⚠️ Treating AI voice appointment reminders as transactional and running them on booking-time consent alone. Widely done, defensible when the call contains no promotional content at all, and it collapses the moment someone adds "and we have an offer this month" to the script. This is legal risk, not platform risk. Suits businesses with tight script control and no marketing pressure on the reminder flow.
- ⚠️ Piloting outbound AI voice on a small warm segment while the consent wording is being rewritten. Gains real learning fast. Carries genuine legal exposure per call if the wording is later judged insufficient, so it suits operators who can cap volume and stomach that, not those with a national footprint.
The market is filling with capable products, and the last week of August 2026 alone brought new AI receptionist launches from Voiceware AI's new venture Agentrixapp and from CCS. Capability is no longer the constraint. Wording is.
Questions owners raise once the script is written
Does the AI have to say the word "AI" on the call?
The legal requirement in the US attaches to consent, not to a scripted phrase. But the published consent policies in this market commit to identifying the system as automated at the start of every call and never misrepresenting it as human, and that is the standard we build to. A single clean sentence ("this is an automated assistant calling from [Business]") costs you three seconds and removes the worst category of complaint.
We are in Dubai and only call UAE numbers. Does the FCC ruling matter?
Not directly. It matters as the clearest published statement anywhere that an AI-generated voice is treated as an artificial voice for consent purposes, and UK and UAE regulators approach automated calling from the same direction. If you call any US number, or any customer who might be roaming on a US line, it applies to those calls. Clinics have a second layer regardless: DHA or DoH expectations on patient communications sit on top of telecoms rules.
What if the person consented, then a machine reaches their voicemail?
For prerecorded telemarketing calls in the US, the message must open with a toll-free number that connects to the same automated opt-out mechanism. Practically, decide in advance whether your agent leaves a message at all. Many operators are better served by dropping to a WhatsApp or SMS follow-up, where the opt-out mechanics are simpler and the reply rate is usually higher.
Can we ask for consent during the AI call itself?
You can ask for consent to future automated calls during a call the customer initiated. You cannot use an unconsented AI outbound call to collect consent for AI outbound calls. That circle does not close.
If you want a second read on your current opt-in wording before you point a voice agent at your database, send us the exact sentence you use today and we will tell you what it covers and what it does not.
Related reading
- Do WhatsApp Voice Notes Need a Consent Disclosure?
- The Hidden Cost of Making an AI Voice Note Say 'This Is AI'



