.webp)
The Ultimate Guide to Using AI Cold Calling for Real Estate
Updated at Sep 24, 2026
10 min to read
![Is AI Calling Legal in the U.S., EU, India & Beyond_ [2025 Guide].webp](https://relinns-hrm.s3.ap-south-1.amazonaws.com/uploads/1748519991307_Is AI Calling Legal in the U.S., EU, India & Beyond_ [2025 Guide].webp)
Yes, AI cold calling can be legal, but only when it follows applicable consent, disclosure, opt-out, and telemarketing rules. In the US, AI-generated voices can fall under TCPA restrictions on artificial or prerecorded calls, while requirements differ across the EU, UK, Canada, India, and other regions.
AI cold calling is now used for sales, reminders, support, and follow-ups, but its legality depends on how the call is made and where the recipient is located. Rules can change based on the call purpose, technology, consent status, and whether artificial or prerecorded voice is used.
So, is AI cold calling legal? It can be. Businesses need to check applicable consent, caller identification, AI transparency, opt-out, do-not-call, privacy, and telecom requirements before dialing.
This 2026 guide explains the current framework across the U.S., EU, UK, Canada, and India, along with the controls businesses should consider when configuring AI voice campaigns.
Every country treats AI cold calling bots differently, and some are already enforcing compliance with real penalties.
If your bot dials across borders, you need to know exactly where it stands in each region before your next campaign goes live.
In the U.S., the FCC confirmed in February 2024 that AI-generated voices fall within the TCPA’s rules for artificial or prerecorded voice calls. That means businesses using AI voice technology must follow the same consent, identification, opt-out, and do-not-call requirements that apply to covered automated calls.
For telemarketing calls using an artificial or prerecorded voice, prior express written consent is generally required. Other informational or non-telemarketing calls may follow different consent standards or exemptions depending on the type of call and number being contacted.
Businesses should also:
2026 update: The FCC continues to revise how consent revocation works under the TCPA. In January 2026, it extended the effective date of part of its “revoke all” rule until January 31, 2027 while the agency reviews whether an opt-out for one type of communication should automatically apply to unrelated robocalls and robotexts from the same caller.

In the EU, AI cold calling can trigger several overlapping rules. GDPR applies when the call involves processing personal data, while the ePrivacy Directive requires prior consent for automated calling systems used for direct marketing. National laws implementing ePrivacy can add further requirements.
Businesses using AI voice calls should:
GDPR can also apply to businesses outside the EU when they offer goods or services to, or monitor the behaviour of, people in the EU.
Serious GDPR infringements can result in administrative fines of up to €20 million or 4% of total worldwide annual turnover from the preceding financial year, whichever is higher.
2026 update: From August 2, 2026, the EU AI Act’s Article 50 transparency rules apply to certain AI systems. Interactive AI systems must inform people when they are interacting with AI unless that fact is obvious from the circumstances, adding another transparency consideration for AI-powered voice interactions.
UK rules depend on how the AI calling system operates. Under PECR, automated marketing calls made using an automated dialling system that plays a recorded message require specific consent from the recipient. General marketing consent or consent for live calls is not enough.
For automated marketing calls, businesses should:
Live marketing calls follow different rules. In many cases, prior consent is not required, but businesses must generally screen numbers against the Telephone Preference Service (TPS), Corporate Telephone Preference Service (CTPS), and their own do-not-call lists. Where personal data is processed, UK GDPR requirements also apply.
2026 update: The Data (Use and Access) Act 2025 strengthened the ICO’s enforcement powers under PECR. From 2026, certain PECR breaches can attract fines of up to £17.5 million or 4% of worldwide annual turnover, whichever is higher.
In Canada, AI cold calling is primarily governed by the CRTC’s Unsolicited Telecommunications Rules rather than CASL. Businesses making telemarketing calls must follow the National Do Not Call List rules, general telemarketing requirements, and additional rules for automated calls.
For automated telemarketing calls using an Automatic Dialing-Announcing Device (ADAD), businesses must obtain the consumer’s express consent before the call. The consent must clearly authorize automated telemarketing calls to the specific phone number.
Businesses should also:
CASL generally applies to commercial electronic messages such as email and SMS, not live or automated telemarketing calls made to telephone numbers.
2026 update: The CRTC opened a review of Canada’s Unsolicited Telecommunications Rules in June 2026, including how the rules should address robocalls and align with newer communications practices. The existing rules remain in force while that review continues.
In India, commercial AI calling falls under TRAI’s Telecom Commercial Communications Customer Preference Regulations (TCCCPR), which govern unsolicited commercial communications, consent, customer preferences, telemarketers, and telecom resources used for outreach.
Businesses using outbound calling systems should:
2026 update: On September 18, 2026, TRAI issued the Third Amendment to the TCCCPR. It expressly defines Application-to-Person (A2P) calls to include calls initiated by software or automated platforms, including autodialling, robocalls, prerecorded voices, and artificial voice technologies. The amendment also introduces additional requirements around A2P calling, consent, and UCC enforcement, with different provisions taking effect after 30, 60, or 90 days.
TRAI has also intensified enforcement against spam. In 2025, it issued 731,120 notices to unregistered telemarketers and disconnected 184,482 telecom resources for continued non-compliance.
Whether an AI cold call is legal depends on the country, the purpose of the call, the technology used, how consent was obtained, and whether the recipient can identify and stop the communication.
Rules for outbound AI calls vary by jurisdiction, but businesses generally need to assess consent, disclosure, opt-out, caller identification, and do-not-call requirements before launching automated calling campaigns.
These call types can be treated differently depending on the jurisdiction and how the system operates. In the U.S., the FCC has confirmed that AI-generated human voices fall within the TCPA’s rules for artificial or prerecorded voice calls.
Disclosure requirements vary by jurisdiction.
In the U.S., the FCC’s 2024 ruling confirmed that AI-generated voices fall under existing TCPA rules, but the FCC’s separate proposal to require callers to disclose the use of AI-generated voice technology on each call was issued as a proposed rule, not the 2024 declaratory ruling itself.
In the EU, Article 50 of the AI Act applies from August 2, 2026 and requires certain interactive AI systems to inform people when they are interacting directly with AI. UK PECR separately requires automated marketing calls to identify the organisation responsible for the call and provide contact information.
Consent requirements are not identical across every type of AI call.
In the U.S., telemarketing calls that use artificial or prerecorded voices generally require prior express written consent. Other informational or non-telemarketing calls may be subject to different consent standards or exemptions.
In the UK and Canada, automated marketing calls also have specific consent requirements, while rules for live calls can differ. Businesses should therefore document the type of consent required for each campaign and jurisdiction rather than assuming one consent standard applies globally.
BotPenguin supports configurable disclosure prompts, consent-based call triggers, opt-out workflows, and call records that businesses can use as part of their AI calling compliance processes.
AI can be used for sales and lead generation, but the legal requirements depend on the call type, jurisdiction, number being contacted, and technology involved. Automated or AI-generated voice calls often trigger stricter consent, identification, opt-out, and do-not-call requirements than ordinary live calls.
That means businesses should evaluate each outbound campaign against the rules that apply in the recipient’s location rather than assuming one global standard.
B2B status does not automatically exempt an AI calling campaign from telemarketing rules.
In the U.S., consent requirements can depend on the type of number being called, whether the call includes telemarketing, and whether an artificial or prerecorded voice is used. Telemarketing calls using artificial or prerecorded voices to covered numbers generally require prior express written consent.
Other countries distinguish B2B calls differently. In the UK, most live B2B marketing calls can be made without prior consent if TPS, CTPS, and prior objections are respected, but automated marketing calls require specific consent. In Canada, B2B calls are exempt from the National DNCL rules, but telemarketing and automated-calling rules still apply.
The key point is that “B2B” does not by itself make an AI cold call compliant.

The purpose of the call can change which rules apply:
Adding promotional content to an otherwise informational or transactional call can change its regulatory treatment, so call scripts should match the purpose for which consent was obtained.
Industries like insurance, finance, real estate, and healthcare are more tightly regulated. Why?
Calls in regulated industries may trigger additional consent, privacy, licensing, or disclosure requirements depending on the purpose of the call and jurisdiction.
Businesses in regulated industries should check both telemarketing rules and any sector-specific privacy, licensing, or communications requirements before using AI calling.
AI calling rules are not universal. A campaign that meets the requirements in one country may need different consent, identification, opt-out, or registration procedures when calling another jurisdiction.
For example, automated direct-marketing calls generally require prior consent under the EU ePrivacy framework, while UK rules distinguish between automated and live marketing calls. Canada separately regulates automated telemarketing through its ADAD rules.
Businesses calling across borders should therefore apply the requirements of the destination jurisdiction rather than relying on the rules where the caller is based.
You can use AI for outbound sales when the campaign satisfies the rules that apply to that specific call. Before dialing, confirm that:
Non-compliant AI calling can expose businesses to regulatory action, statutory damages, telecom restrictions, complaints, and reputational harm. The consequences depend on the jurisdiction, call type, technology used, and nature of the violation.
The sections below outline some of the main risks businesses should consider before running AI-powered outbound calling campaigns.
Under the Telephone Consumer Protection Act (TCPA), a person may seek $500 in statutory damages for certain violations. If a court finds that the violation was willful or knowing, it may increase the award to as much as three times that amount, or $1,500 per violation.
These amounts are statutory damages available through TCPA actions, not a blanket FCC fine automatically imposed on every AI call.
Because the FCC has confirmed that AI-generated human voices fall within the TCPA’s artificial or prerecorded voice provisions, businesses using AI voice technology should ensure that applicable consent, identification, opt-out, and calling restrictions are satisfied before dialing.
TRAI’s UCC framework allows enforcement action against senders and telecom resources used for unsolicited commercial communication.
Depending on the violation and enforcement history, measures can include warnings, usage restrictions, suspension, disconnection of telecom resources, and other actions under the TCCCPR framework.
Businesses using AI or automated outbound calling should therefore follow customer-preference rules, use compliant telecom resources, maintain required consent records, and avoid continuing communication after valid opt-out or DND restrictions apply.

AI voice interactions can involve personal-data processing when information relating to an identified or identifiable person is collected, stored, analysed, or linked to that individual.
Businesses must identify an appropriate legal basis under GDPR and comply with relevant transparency, data minimisation, security, retention, and data-subject rights requirements. Automated direct-marketing calls may also trigger prior-consent requirements under the ePrivacy framework.
For serious GDPR infringements, supervisory authorities can impose fines of up to €20 million or 4% of worldwide annual turnover from the preceding financial year, whichever is higher.
Regulatory penalties are only one potential consequence of non-compliant calling.
Depending on the jurisdiction and circumstances, businesses may also face:
These risks can affect campaign performance even before a regulator takes formal enforcement action.
Businesses using AI calling need controls that reflect the rules applying to each campaign. Depending on the jurisdiction, this can include consent verification, caller or AI disclosure, opt-out handling, suppression lists, calling restrictions, and recordkeeping.
BotPenguin supports consent-based calling workflows, configurable disclosure prompts, opt-out handling, and call records that businesses can use within their broader compliance processes.

Making AI cold calling compliant starts with identifying the rules that apply to the campaign. Requirements can change based on the country, call purpose, number being contacted, and whether the system uses an artificial, prerecorded, or automated voice.
The steps below provide a practical compliance framework, but each campaign should be configured around the laws of the jurisdictions being called.
Determine what form of consent is required before adding a number to an AI calling campaign. For example, U.S. telemarketing calls using artificial or prerecorded voices generally require prior express written consent, while other call types and jurisdictions can follow different standards.
Your system should record:
Consent records should be specific enough to show why the business believed the call was permitted.
Disclosure requirements differ across jurisdictions. Configure call scripts so they identify the responsible business and provide any additional AI transparency notice required by the applicable rules.
For example, the EU AI Act now includes transparency requirements for certain interactive AI systems. UK automated marketing calls must identify the organisation responsible for the call and provide contact information. In the U.S., the FCC has proposed additional AI-specific disclosure requirements, while existing rules already require caller identification for covered artificial or prerecorded calls.
Where AI disclosure is required or adopted as a transparency practice, place it clearly near the beginning of the interaction rather than burying it later in the script.

AI calling workflows should make it easy to capture and honor opt-out or do-not-call requests where required.
Depending on the applicable rules, this may include voice commands, keypad options, suppression lists, or staff-managed requests. Once a valid opt-out is received, the system should update the contact’s status and prevent further calls covered by that request.
Businesses should also keep records showing when the request was received and how it was applied.
Calling hours, customer-preference rules, registration requirements, and other restrictions can vary by country and, in some cases, by state or region.
Configure campaigns using the recipient’s location so the system can apply the relevant calling windows, suppression lists, consent rules, and telecom requirements before dialing.
Do not assume that a schedule or compliance setting approved for one market can be reused unchanged in another.
Maintain enough records to demonstrate how the campaign was configured and why calls were permitted.
Useful records can include consent details, call dates, scripts or campaign versions, opt-out activity, suppression status, and routing outcomes. Retention requirements vary by jurisdiction, so businesses should align recordkeeping with the rules that apply to their campaigns.
Accurate records can also help investigate complaints and verify whether consent and opt-out controls worked as intended.
BotPenguin supports configurable consent checks, disclosure prompts, opt-out workflows, location-aware calling controls, and call records that businesses can use within their broader AI calling compliance processes.
AI voice bots can support sales, reminders, customer service, and other outbound calling workflows, but a use case is not automatically legal or illegal on its own. Compliance depends on the call purpose, technology used, consent status, recipient, and jurisdiction.
The examples below show lower-risk and higher-risk scenarios, but every campaign still needs to be checked against the rules that apply where the recipient is located.
AI calling bots can legally operate across a variety of use cases.

Appointment reminders may be treated differently from telemarketing when they relate to an existing appointment and contain no promotional content. Businesses should still verify applicable consent, privacy, identification, and sector-specific requirements before using automated or AI-generated voice.
AI voice systems can support service follow-ups, ticket updates, or satisfaction checks when the communication relates to an existing customer interaction. Adding promotional content can change how the call is regulated.
B2B calling rules vary significantly by jurisdiction. Some live business-to-business calls may be permitted without prior consent, while automated or artificial-voice calls can trigger stricter requirements. Businesses should verify the applicable B2B, telemarketing, and automated-calling rules before dialing.
For legal teams evaluating AI-powered calling and client workflows, see how AI agents for law firms can support intake, follow-ups, and other firm operations.
AI voice outreach becomes higher risk when campaigns ignore applicable consent, identification, opt-out, or do-not-call requirements.
What seems harmless in outbound marketing can lead to fines, spam blacklists, or even legal bans when applied to voice without proper controls.
Adding purchased, scraped, or third-party contacts directly to an automated AI calling campaign can create significant compliance risk when the applicable rules require prior consent.
Businesses should verify the source and scope of consent before dialing rather than assuming that possession of a phone number permits automated outreach.
Continuing to contact someone after a valid opt-out, objection, or do-not-call request can violate telemarketing rules and increase enforcement risk.
Calling systems should capture applicable withdrawal requests and apply them to the relevant suppression or do-not-call workflow.
AI voices should not be used to impersonate real people, misrepresent the identity of the caller, or deliberately mislead recipients about who is communicating with them.
Where AI-specific transparency rules apply, the required disclosure should also be included clearly in the call flow.
The same AI calling use case can be treated differently across jurisdictions. Compliance depends on how the call is configured, who receives it, what the call contains, and which consent, disclosure, opt-out, and telecom rules apply.
Treat these scenarios as a starting point for campaign review rather than a universal legal classification.
Just because AI can make a call does not mean every outreach scenario is appropriate.
Ethical AI voice outreach goes beyond minimum legal requirements. It means considering user privacy, transparency, control, and whether automation is appropriate for the conversation before the first call is placed.
AI calling systems reach people through a direct and personal communication channel. Ethical campaigns should give recipients meaningful control over that interaction.
That includes:
Even where a particular call may be legally permitted without prior consent, businesses should consider whether the outreach is expected, relevant, and respectful of the recipient’s time.
AI voices can sound increasingly natural, including variations in tone, pacing, and accent. That makes transparency especially important when a realistic synthetic voice could cause someone to believe they are speaking with a human.
Businesses should avoid using cloned or synthetic voices in ways that impersonate real people, conceal the identity of the caller, or deliberately mislead recipients.
Where AI disclosure is legally required, it should be provided clearly. Even where a specific disclosure rule does not apply, transparent communication can help reduce confusion and preserve trust.
Transparency should also extend to how AI calling campaigns are managed internally.
Good practices include:
These controls make it easier to understand how an AI calling system is operating and to correct problems when they appear.
Responsible AI calling should be transparent, controllable, and proportionate to the purpose of the outreach. Businesses should know why a contact is being called, what the system is allowed to do, and when a conversation should stop or move to a human.
Legal compliance sets the minimum requirement. Ethical implementation also considers whether the experience is fair, clear, and respectful to the person receiving the call.
Whether you build an AI voice calling system internally or use a third-party platform, compliance controls need to be part of the deployment from the start.
The exact requirements vary by campaign and jurisdiction, but the system should be able to apply consent rules, disclosures, opt-outs, calling restrictions, and recordkeeping based on where and how it is being used.
Here are the core capabilities to evaluate.
An AI calling system should support more than conversation logic. It also needs controls that allow businesses to configure campaigns around applicable consent, disclosure, opt-out, and recordkeeping requirements.
The system should be able to verify whether the contact meets the consent requirements that apply to the campaign before a call is placed.
Consent or permission data may come from CRM records, forms, previous interactions, or other approved sources. Where prior consent is required, the calling workflow should prevent contacts without valid consent from entering the campaign.
The system should also preserve enough information to show when, how, and for what purpose the relevant permission was obtained.
Call flows should support the caller-identification and AI-transparency requirements that apply in each jurisdiction.
That may include identifying the organisation responsible for the call, explaining the purpose of the interaction, or disclosing that the recipient is interacting with AI where required.
Disclosure logic should be configurable by campaign and location rather than relying on one script for every market.
The system should be able to capture and apply opt-out or do-not-call requests in accordance with the rules governing the campaign.
Depending on the call flow, this may include voice commands, keypad options, or requests handled by staff. When a valid request is received, the system should update the contact’s status and prevent further calls covered by that request.
Suppression information should also stay synchronized with the CRM or calling lists used for future outreach.
The platform should maintain records that help teams understand how each campaign operated.
Useful records can include call dates, campaign or script versions, consent status, disclosures used, opt-out activity, and call outcomes. The exact retention requirements depend on the jurisdiction and campaign.
Searchable records can help businesses investigate complaints, verify whether controls worked correctly, and provide supporting information when compliance questions arise.

If you are comparing AI voice platforms or deciding whether to build internally, compliance controls should be part of the evaluation from the start.
BotPenguin supports configurable controls that businesses can use within their AI calling compliance processes, including:
BotPenguin is GDPR, HIPAA, and CCPA compliant, ISO certified, SOC 2 attested, and VAPT-assessed by a CERT-In empanelled auditor.
For teams running outbound sales, lead verification, follow-ups, or other AI voice workflows, these controls provide a foundation for configuring campaigns around applicable consent, disclosure, opt-out, and recordkeeping requirements.
Want to see what legal AI voice software should actually look like in practice?
AI cold calling can be legal, but there is no single rule that applies to every campaign. Consent, disclosure, opt-out, do-not-call, telecom, and data-protection requirements vary by jurisdiction, call purpose, and technology.
The safest approach is to identify the rules that apply before launching a campaign, document the required permissions, configure the calling workflow accordingly, and review those controls as regulations change.
BotPenguin supports consent-based calling workflows, configurable disclosure prompts, opt-out handling, and call records that businesses can use within their broader AI calling compliance processes.
AI cold calling for lead generation can be legal, but requirements depend on the jurisdiction, call technology, recipient, and campaign purpose. Automated or artificial-voice sales calls often face stricter consent, identification, opt-out, and do-not-call requirements than ordinary live calls.
AI bot phone calls legality varies by country and sometimes by state or region. Consent, disclosure, calling-hour, opt-out, privacy, and telemarketing requirements differ, so businesses should configure campaigns according to the rules where each recipient is located.
B2B status does not automatically make AI cold calling legal. Some jurisdictions allow certain live B2B marketing calls without prior consent, while automated or artificial-voice calls may face stricter rules. Check the recipient’s location, number type, call purpose, and technology used.
Useful compliance records can include consent details, call dates, campaign or script versions, opt-out activity, suppression status, and call outcomes. These records can help demonstrate how a campaign was configured and investigate complaints, but recordkeeping requirements vary by jurisdiction.
Not necessarily. AI disclosure requirements vary by jurisdiction. However, businesses should not use human-like or cloned voices to mislead recipients or impersonate real people. Where AI-specific transparency rules apply, the required disclosure should be included clearly in the call flow.
Use a structured compliance process that checks applicable consent, disclosure, opt-out, do-not-call, calling-hour, and recordkeeping requirements before launching each campaign. Platforms such as BotPenguin can support these controls, but businesses remain responsible for configuring campaigns according to applicable laws.
Subscribe to Our Newsletter
Get the latest business insights straight into your inbox.
Checkout our related blogs you will love.
.webp)
Updated at Sep 24, 2026
10 min to read

Updated at Sep 12, 2026
9 min to read
.webp)
Updated at Aug 19, 2026
11 min to read

Updated at Jul 3, 2026
16 min to read

Updated at Jul 3, 2026
14 min to read

Updated at Jun 16, 2026
15 min to read
Table of Contents