Short answer: US consent wording still only has to authorise “an automatic telephone dialing system or an artificial or prerecorded voice”, because the FCC’s AI-generated call proposals in CG Docket 23-362 remain unfinalised as at 26 August 2026. The cheap insurance is to add an explicit AI reference to your opt-in now, and to store the exact text shown, the form version, the timestamp and the IP against every record.
This post is about wording and record-keeping, not the rules themselves. For the rules, see our posts on what NPRM 24-84 proposes, the consent chain behind purchased lists and the US state disclosure patchwork. The narrower question: what sentence goes on the form today, and what do you keep, so a rule landing in 2027 does not void a list you spent a year building? General information only, not legal advice — have your consent language reviewed by a lawyer in each market you dial.
Where the proceeding actually stands, as at 26 August 2026
Premise check first, because vendor content still calls these proposals imminent. The Federal Communications Commission adopted FCC 24-84, a Notice of Proposed Rulemaking and Notice of Inquiry in CG Docket No. 23-362, on 7 August 2024 and released it the next day; it was published as a proposed rule in the Federal Register on 10 September 2024. A Federal Register search for FCC documents citing docket 23-362 returns that proposed rule and no final rule as at 26 August 2026. Nothing in those results is a Report and Order, and no compliance date has been published. Anyone telling you an FCC AI-consent rule is in force is wrong.
The proposed definition is broader than “voice clone” — an “AI generated call” would mean “a call that uses any technology or tool to generate an artificial or prerecorded voice or a text using computational technology or other machine learning, including predictive algorithms, and large language models, to process natural language and produce voice or text content to communicate with a called party over an outbound telephone call” (FCC 24-84, para. 10). The Commission was also explicit that “[t]he TCPA’s requirements do not extend to technologies used to answer inbound calls” (para. 11).
The one sentence the FCC proposed you would have to add
Paragraph 14 of FCC 24-84 is the whole post in a sentence: “For calls that require the prior express written consent of the called party and which contain AI-generated messages, we propose that the written agreement authorizing delivery of such calls include clear and conspicuous disclosure informing the called party that they specifically authorize the caller to make calls containing AI-generated content.”
Paragraph 16 is why your existing list matters. The Commission asked: “should we grandfather existing consents to place autodialed and/or artificial or prerecorded voice calls—either indefinitely or for a limited time?” That is an open question, not a promise. Betting a year of pipeline on the answer being “yes, indefinitely” is a bet you need not take, because adding the AI reference now costs one line of form copy.
What already binds you, today
The definition you must satisfy right now is 47 CFR § 64.1200(f)(9), which requires the written agreement to include a clear and conspicuous disclosure informing the person signing that “(A) By executing the agreement, such person authorizes the seller to deliver or cause to be delivered to the signatory telemarketing calls using an automatic telephone dialing system or an artificial or prerecorded voice; and (B) The person is not required to sign the agreement (directly or indirectly), or agree to enter into such an agreement as a condition of purchasing any property, goods, or services.”
Two on-call duties sit alongside it. Section 64.1200(b)(1) requires artificial or prerecorded voice messages to “[a]t the beginning of the message, state clearly the identity of the business, individual, or other entity that is responsible for initiating the call.” Section 64.1200(b)(3) requires, for telemarketing messages to the covered lines, an “automated, interactive voice- and/or key press-activated opt-out mechanism for the called person to make a do-not-call request… within two (2) seconds of providing the identification information required in paragraph (b)(1)”.
Neither says “AI”. Identifying yourself is not disclosing that the voice is synthetic, and that gap is what the NPRM was written to close.
Revocation is the other live piece. Section 64.1200(a)(10) requires that “[a]ll requests to revoke prior express consent or prior express written consent made in any reasonable manner must be honored within a reasonable time not to exceed ten business days from receipt of such request.” Its broader “revoke-all” element — a stop request on one message type applying to unrelated future robocalls — has slipped again: in Order DA 26-12, released 6 January 2026, the Consumer and Governmental Affairs Bureau found that “good cause exists to extend the effective date for this requirement until January 31, 2027, to allow sufficient time to review the record compiled in response to a recent Further Notice of Proposed Rulemaking”.
Consent scenarios: what you have, and what it is worth
| Consent scenario | What it covers today (August 2026) | Exposure if an AI-specific rule lands | Recommended action now |
|---|---|---|---|
| Legacy autodial / prerecorded opt-in (pre-2025 form, § 64.1200(f)(9) wording only) | Autodialled and artificial-or-prerecorded telemarketing calls to the consenting number | Highest. Turns entirely on whether the FCC grandfathers existing consents — an open question in para. 16 | Re-consent at next contact, or segment and flag as AI-unreferenced |
| AI-referencing opt-in (form explicitly names AI-generated voice or text) | The same, plus the explicit authorisation the proposal asks for | Lowest. Meets the proposed para. 14 disclosure on its face | Roll out now; version the form so you can prove when wording changed |
| Purchased or brokered list | Only whatever the original capture actually said — you inherit the seller’s wording, not your own | High and compounding: you would need AI-referencing consent captured by a party you do not control | Demand the original consent text and capture record per row, or do not dial it |
| Inbound enquiry (they rang or submitted a form asking to be contacted) | Prior express consent for calls related to that enquiry; the strongest ordinary-meaning basis | Moderate. Consent likely survives, but nothing on file says AI | Add the AI line to the enquiry form itself, not only a marketing checkbox |
| Existing customer relationship | Depends on message type; a relationship is no substitute for written consent for telemarketing robocalls | Moderate. Servicing calls sit differently from marketing calls | Split servicing consent from marketing consent in your CRM now |
Wording an opt-in today
Three drafting rules do most of the work.
Name the technology, not the vendor. “Calls and texts that may use an artificial, prerecorded or AI-generated voice” survives a platform change. “Calls placed using [vendor name]” does not. Entity-level consent drafting is also unsettled ground: the Eleventh Circuit struck down the FCC’s one-to-one consent restriction in Insurance Marketing Coalition Ltd v. FCC on 24 January 2025, granting the petition and vacating “Part III.D of the 2023 Order” with a remand for further proceedings.
Keep the § 64.1200(f)(9) elements intact. The AI reference is an addition, not a replacement. You still need the authorisation to be delivered calls using an autodialer or artificial or prerecorded voice, the not-a-condition-of-purchase line, and the specific telephone number.
Put it where the signature is. The regulation defines “clear and conspicuous” as “a notice that would be apparent to the reasonable consumer, separate and distinguishable from the advertising copy or other disclosures” (47 CFR § 64.1200(f)(3)). It prescribes no placement or type-size rule, so the conservative reading is the safe one: put the sentence next to the submit button rather than behind a link. A linked terms page containing the AI sentence is a weaker artefact than a checkbox label containing it — and weaker still if the form is being completed by an automated buying agent.
What to record, per consent, forever
If a rule lands, the argument you must win is “this person saw this sentence on this date”. That is a data-model problem, not a copywriting problem. Store, immutably, against each record:
- The exact text shown — the full rendered string of the checkbox label and adjacent disclosure, not a template ID you later edit in place.
- A form version identifier and the date range it was live.
- Timestamp with timezone, source URL, and the IP address of the submission.
- Channel and capture method — web form, verbal on a recorded line, in person — plus the recording reference for verbal consent.
- The telephone number consented to, exactly as entered, and every later revocation event with a timestamp.
Australia arrives at the same place by another route, and the ACMA states the burden plainly in its guidance on avoiding sending spam: “Keep a record when a person gives express consent, including who gave the consent, when and how. Under the Spam Act, it’s up to you to prove that you have a person’s consent.” Its Statement of Expectations on consumer consent, published 1 July 2024, adds that terms and conditions “should explain what the marketing is for, who will use it, how long it will be used, and how consent can be withdrawn.”
Two caveats, without over-claiming. The Spam Act 2003 governs commercial electronic messages — email, SMS, instant messaging — not voice calls; unsolicited marketing calls fall under the Do Not Call Register Act 2006 and the associated telemarketing standard, covered in our post on the Do Not Call Register and AI voice agents. Neither instrument currently requires consent to name AI. The record-keeping discipline transfers cleanly regardless.
How re-consent works if the rule lands
Plan it as a campaign, not a migration. If the FCC adopts an AI-referencing requirement without indefinite grandfathering, the sequence is: segment records by form version; leave alone any whose captured text already names AI; for the rest, capture fresh consent at the next lawful touchpoint, through a channel the existing consent already covers. You cannot electronically message someone to ask for consent you do not have — the ACMA is explicit that a message asking for consent is itself a marketing message.
Re-consent is not a substitute for on-call disclosure either: the FCC proposal contemplates disclosure “at the beginning of each call”. For scripts that disclose without killing the conversation, see our disclosure script post.
Where this sits in an AI agent stack
Zian AI runs autonomous phone, SMS, email and WhatsApp agents, and consent state is an input to each of them rather than a compliance afterthought: which number is consented, under what wording, revoked or not. Zian integrates with HubSpot, Salesforce, HighLevel and Zapier, so the consent fields you define today are the fields an agent reads at dial time. Zian is in waitlist and partnership beta, and it is not the right answer for every team — if your outreach is entirely servicing calls to existing customers, most of this post is overhead.
FAQ
Do I have to change my consent wording right now?
No. As at 26 August 2026 there is no adopted FCC rule requiring consent to reference AI. FCC 24-84 remains a Notice of Proposed Rulemaking. The argument for changing now is risk management, not compliance.
Does adding an AI reference weaken my existing consents?
It should not, provided you keep the elements 47 CFR § 64.1200(f)(9) already requires — the authorisation to receive autodialled or artificial-or-prerecorded telemarketing calls, and the disclosure that signing is not a condition of purchase. You can read the current text at the eCFR. Adding a sentence does not remove one.
How long do I keep consent records?
Longer than you think. Under 28 U.S.C. § 1658(a), a civil action arising under an Act of Congress enacted after that section’s own enactment in December 1990 “may not be commenced later than 4 years after the cause of action accrues” — and the TCPA dates from 1991. Records should therefore outlive the campaign by years, and survive CRM migrations, which is the usual point of failure.
Does any of this apply to inbound AI receptionists?
Largely no. The FCC was explicit in FCC 24-84 that “[t]he TCPA’s requirements do not extend to technologies used to answer inbound calls” (para. 11). State disclosure laws are a separate question and several do reach inbound interactions.
Is the “revoke-all” rule in force?
Not yet. In Order DA 26-12, released 6 January 2026, the FCC’s Consumer and Governmental Affairs Bureau extended the effective date of that element of § 64.1200(a)(10) until 31 January 2027. The ten-business-day deadline for honouring revocations is already in force.
What is the Australian equivalent of an AI-referencing opt-in?
There isn’t one, yet. The Spam Act 2003 and the Do Not Call Register Act 2006 require consent but do not require it to name AI. The ACMA’s Statement of Expectations, published 1 July 2024, recommends terms that explain “what the marketing is for, who will use it, how long it will be used, and how consent can be withdrawn” — which is a reasonable place to name AI voluntarily.
Sources
- FCC, FCC 24-84 NPRM and NOI, CG Docket No. 23-362, adopted 7 August 2024.
- Federal Register, proposed rule, 10 September 2024; docket 23-362 document search.
- eCFR, 47 CFR § 64.1200, current text.
- FCC, Order DA 26-12, CG Docket No. 02-278, 6 January 2026.
- US Court of Appeals for the Eleventh Circuit, Insurance Marketing Coalition Ltd v. FCC, No. 24-10277, 24 January 2025.
- ACMA, Avoid sending spam; Consent expectations for businesses using direct marketing, 1 July 2024.
Get the consent layer right before you scale the dialling
If you are planning AI-led outreach into the US or Australia and want the consent capture, record-keeping and agent-side enforcement designed together rather than bolted on afterwards, Zian AI is taking partners during beta. Apply For Partnership.