If you are deploying autonomous agents to call, text and email prospects, AI outreach compliance — TCPA, GDPR, the Spam Act and their equivalents — is a design requirement, not a legal afterthought. The core principle is easy to miss: regulators do not care whether a human or a machine initiated the contact. The same consent, identification, calling-hour and opt-out rules apply, with a new layer of AI-specific disclosure obligations arriving on top.
Before we go further: this article is general information, not legal advice. Laws change, enforcement positions shift, and your situation has specifics we cannot see — engage qualified counsel in each market before you launch. What this guide can do is map the landscape across Australia, the United States and the EU/UK, from primary sources, so you know which controls to configure.
The stakes scale with the automation: an agent making thousands of contact attempts a day can make thousands of non-compliant ones. That is why the configuration layer — calling windows, list washing, disclosure, opt-out propagation — matters more than it ever did for a human team.
At a glance: AI outreach agents must follow the same channel laws as human teams, plus emerging AI-specific rules. In Australia, the Spam Act 2003 requires consent, sender identification and a working unsubscribe for commercial email and SMS, while the Do Not Call Register Act 2006 and a 2017 industry standard restrict calling hours. In the US, the TCPA requires prior express written consent for autodialled or prerecorded marketing calls and texts — and the FCC ruled in February 2024 that AI-generated voices count as “artificial”. In the EU and UK, GDPR requires a lawful basis, PECR governs each channel, and EU AI Act Article 50 requires disclosing AI interactions from 2 August 2026.
Australia: the Spam Act, the Do Not Call Register and the telemarketing standard
Email, SMS and instant messages: Spam Act 2003
The Spam Act 2003 covers commercial electronic messages — email, SMS and instant messages alike. As the ACMA’s guidance sets out, every message needs three things: prior consent from the recipient, accurate sender identification with correct contact details, and an easy unsubscribe. Consent can be express (a form, a ticked box, an agreement over the phone) or inferred from a provable, ongoing relationship the marketing directly relates to. Two details trip up automated systems: you cannot send an electronic message to ask for consent, because that request is itself a marketing message; and the burden of proving consent sits with the sender.
The unsubscribe requirements are specific: per the ACMA, the facility must be clearly presented, free beyond the standard cost of using the address, functional for at least 30 days after sending, and requests must be honoured within 5 working days. Buying a list does not transfer the risk — you remain responsible for consent on every address, and lists built with address-harvesting software are prohibited outright.
Voice calls: Do Not Call Register Act 2006 and the 2017 industry standard
Calls are governed by two instruments. The Do Not Call Register Act 2006 requires marketers to check calling lists against the register before dialling, and the register site’s industry guidance describes the practical safe harbour: if you washed your list within the 30 days before the call and the number was not flagged, you will not be in breach if it turns out to have been registered. In effect, a wash older than 30 days is a stale wash.
The Telecommunications (Telemarketing and Research Calls) Industry Standard 2017 then sets conduct rules for all telemarketing and research calls to Australian numbers — even numbers not on the register, and even for organisations exempt from the register itself. Per the register’s industry standards page, telemarketing calls are permitted 9:00 am – 8:00 pm weekdays and 9:00 am – 5:00 pm Saturdays, with no calls on Sundays or national public holidays unless the person has consented to being called then (research calls get slightly wider windows, including Sundays). Callers must enable calling line identification, keep the return number reachable for at least 30 days, provide the caller’s employer and the call’s purpose, and terminate immediately if asked. Each is a behaviour an AI voice agent must be configured to exhibit — we compare auditability with human teams in AI voice agents vs call centres.
United States: the TCPA, the FCC’s AI-voice ruling and CAN-SPAM
The Telephone Consumer Protection Act (TCPA) is the central US instrument for calls and texts. The FCC’s implementing rules at 47 CFR § 64.1200 prohibit initiating a telemarketing call using an automatic telephone dialing system or an artificial or prerecorded voice without the prior express written consent of the called party — a warm conversation or an old business card does not qualify. The rules also expressly note that “call” includes a text message, so autodialled marketing texts sit under the same consent framework.
The AI-specific development came on 8 February 2024, when the FCC released a unanimously adopted Declaratory Ruling recognising that calls made with AI-generated voices are “artificial” under the TCPA, effective immediately. The practical consequence: an AI-voiced outbound marketing call is a robocall in the FCC’s eyes and needs prior express written consent — and the ruling was framed explicitly around cloned voices. Several US states also run their own telemarketing statutes and AI or bot disclosure requirements, which vary widely; treat state-level review as a required step.
Email is the outlier: the CAN-SPAM Act runs on an opt-out model rather than prior consent. Per the FTC’s compliance guide, headers must be accurate, every commercial message needs an opt-out mechanism that works for at least 30 days after sending, opt-outs must be honoured within 10 business days — and there is no exception for business-to-business email.
EU and UK: GDPR lawful basis, PECR and the EU AI Act
Lawful basis: legitimate interests vs consent
Under the GDPR (and UK GDPR), processing a prospect’s personal data needs a lawful basis before any channel rule is even considered. For B2B prospecting, the usual candidates are consent and legitimate interests. The ICO’s legitimate interests guidance notes that the legislation specifically mentions direct marketing as a potential legitimate interest — but with hard conditions: it only applies where PECR does not itself require consent, the processing must pass a balancing test, and the right to object to direct marketing is absolute. If a prospect objects, you stop.
Channel rules: ePrivacy and PECR
The ePrivacy layer (implemented in the UK as PECR) then regulates each channel. For electronic mail — which the ICO confirms is defined broadly to include email, SMS, voicemail and direct messages — regulation 22 prohibits marketing to individuals without specific consent, subject to a “soft opt-in” for existing customers that does not cover prospects or bought-in lists. Corporate subscribers (companies, LLPs) can be emailed or texted, but sole traders and some partnerships count as individuals, named work emails still involve personal data, and keeping a do-not-contact list is expected practice.
For calls, the ICO’s telephone marketing guidance distinguishes live calls (regulation 21: screen against the TPS and Corporate TPS, honour objections, display your number, say who is calling) from automated calls (regulation 19: a recorded-message call requires specific prior consent to automated calls — general marketing consent is not enough). Where an AI voice agent lands between “live” and “automated” is an open classification question; the conservative reading applies the stricter automated-call standard, and that is the safe assumption to build to.
The EU AI Act: disclose the AI
The EU adds an AI-specific transparency layer. Article 50 of the AI Act (Regulation (EU) 2024/1689) requires that AI systems intended to interact directly with natural persons inform those persons they are interacting with an AI system, unless that is obvious to a reasonably well-informed person in the circumstances; it also requires synthetic audio and other generated content to be marked as artificially generated. Under Article 113, the regulation’s general application date — covering these transparency obligations — is 2 August 2026. For AI agents speaking to EU prospects, disclosure becomes law within weeks of this article’s publication.
The map: jurisdiction × channel
| Jurisdiction | Voice calls | SMS / instant messages | |
|---|---|---|---|
| Australia | Do Not Call Register Act 2006 (wash lists; 30-day wash safe harbour) + Telemarketing and Research Calls Industry Standard 2017 (weekdays 9 am–8 pm, Sat 9 am–5 pm, no Sun/public holidays; CLI; terminate on request) | Spam Act 2003 — consent, sender identification, functional unsubscribe (5 working days to action; live 30 days) | Spam Act 2003 — same consent, identification and unsubscribe duties as SMS |
| United States | TCPA / 47 CFR § 64.1200 — prior express written consent for autodialled or artificial/prerecorded marketing calls; FCC’s Feb 2024 ruling puts AI-generated voices in scope | TCPA / 47 CFR § 64.1200 — “call” includes SMS; prior express written consent for autodialled marketing texts | CAN-SPAM Act — opt-out model: accurate headers, working unsubscribe for 30 days, opt-outs honoured within 10 business days; no B2B exception |
| EU + UK | ePrivacy/PECR — reg 21 live calls (TPS/CTPS screening) and reg 19 automated calls (specific consent); GDPR lawful basis; EU AI Act Art 50 disclosure from 2 Aug 2026 | ePrivacy/PECR reg 22 (“electronic mail” includes SMS and DMs) — consent or soft opt-in for individuals; GDPR lawful basis | ePrivacy/PECR reg 22 — consent/soft opt-in for individuals; corporate subscribers reachable but GDPR still applies to named contacts |
Consent architecture: one framework across channels
Notice the pattern: “consent” is not one thing. The same person might be lawfully emailable under CAN-SPAM’s opt-out model, textable in Australia only with express or inferred consent, and callable by an AI voice in the US only with prior express written consent. A multi-channel AI agent therefore needs consent recorded per channel and per jurisdiction, not as a single boolean on the contact record.
Three architectural rules follow. First, capture provenance — who consented, when, how, to what — because the ACMA puts the burden of proof on the sender, and the TCPA’s written-consent standard is only useful if you can produce the writing. Second, propagate opt-outs instantly across channels: a prospect who replies STOP to an SMS and gets an AI call the next morning is a complaint waiting to happen; statutory deadlines are ceilings, not targets. Third, log everything: full conversation records are both your compliance evidence and your quality-control corpus.
If you want to see what disciplined, consent-aware sequencing looks like in practice, Join Waitlist and watch how pacing rules shape a live cadence.
What to check and configure in an AI agent platform
None of the above is satisfied by a vendor logo or badge. Whatever platform you deploy — and this applies to Zian as much as anyone — compliance is a property of your configuration and your legal review, not of the software. The useful question is whether the platform gives you the controls:
- Calling-hour windows per jurisdiction, evaluated in the recipient’s local time — Australia’s weekday/Saturday windows are the template, but every market needs its own. Zian’s SmartReach AI™ orchestrates channel and timing by country, so jurisdiction-aware pacing is native rather than bolted on — which matters when automation lifts volume the way a 926% increase in follow-ups implies.
- DNC and preference-list washing — Australia’s Do Not Call Register on a sub-30-day cycle, TPS/CTPS in the UK, plus your own suppression lists, checked before every dialling batch.
- AI disclosure — a configurable, up-front statement that the caller is an AI system, ahead of the EU AI Act’s Article 50 deadline. This matters doubly with voice cloning: the FCC’s ruling was aimed squarely at cloned voices.
- Instant opt-out propagation — STOP, “unsubscribe” and a spoken “take me off your list” should suppress the contact across every channel immediately.
- Human escalation — a live path from AI to human for objections, complaints and consent questions. Zian’s human-in-the-loop escalation supports this pattern.
- Full conversation logs — recorded, transcribed, exportable. Auditable logs are the difference between asserting compliance and demonstrating it, and Zian’s guardrail configuration is built around exactly that kind of record. Teams with data-residency needs can also run private model deployments on their own infrastructure.
Run this checklist against any vendor on your shortlist — our rundown of the best AI voice agents for outbound calls in 2026 is a starting universe, and our guide to AI cold calling software with automatic follow-up digs into the pacing mechanics that keep high-volume cadences on the right side of these rules.
Frequently asked questions
Is it legal for an AI agent to make sales calls in the United States?
It can be, with the right consent. The FCC’s February 2024 Declaratory Ruling confirmed that AI-generated voices are “artificial” under the TCPA, so AI-voiced telemarketing calls require prior express written consent under FCC rules — the same standard as any prerecorded marketing call. State telemarketing and disclosure laws add further requirements, so review each state you call into. This is general information, not legal advice.
Does an AI agent have to tell people it is an AI in the EU?
Yes, in most direct-interaction scenarios. Article 50 of the EU AI Act (Regulation (EU) 2024/1689) requires that people interacting directly with an AI system are informed of that fact unless it is obvious from the circumstances, and the regulation’s general application date under Article 113 is 2 August 2026. A convincing AI sales voice is a textbook case where it would not be “obvious” — so configure the disclosure.
Can I email B2B prospects in the UK without consent?
Sometimes — PECR distinguishes recipient types. Per the ICO’s guidance on electronic mail marketing, you can email corporate bodies, but individuals — including sole traders and some partnerships — require specific consent or the soft opt-in, which does not cover bought-in lists or new prospects. Emailing a named employee still involves personal data, so you also need a UK GDPR lawful basis, and any objection must be honoured.
What hours can an AI agent make telemarketing calls in Australia?
Under the Telecommunications (Telemarketing and Research Calls) Industry Standard 2017, published on the Do Not Call Register’s industry standards page, telemarketing calls are allowed 9:00 am – 8:00 pm weekdays and 9:00 am – 5:00 pm Saturdays, with no calls on Sundays or national public holidays unless the person has consented. Lists must also be washed against the Do Not Call Register, with a wash within the prior 30 days operating as the practical safe harbour.
How quickly must opt-out requests be honoured?
It varies by regime: Australia’s Spam Act requires unsubscribe requests to be actioned within 5 working days per the ACMA, the US CAN-SPAM Act allows 10 business days for email per the FTC, and the UK GDPR right to object to direct marketing is absolute. The engineering answer is simpler: suppress the contact immediately, across all channels, and every deadline takes care of itself.
Is this article legal advice?
No. It is general information drawn from regulator and legislative sources current at the time of writing. Rules change — the ICO, for example, notes its PECR guidance is under review following the UK’s Data (Use and Access) Act — and their application depends on your facts. Engage qualified counsel in each jurisdiction before deploying an AI agent.
Build outreach that scales without cutting corners. Zian’s autonomous sales agents pair multi-channel reach with the guardrail configuration described here — jurisdiction-aware pacing, auditable logs, human-in-the-loop escalation. Join Waitlist.