A caller in San Diego dials a Los Angeles law firm at 2:47 p.m. The firm's AI voice agent answers, runs through a 90-second intake, and ends the call. The agent's recording disclosure was: "this call may be recorded for quality and training purposes." The disclosure played at second 3 of the call. The caller heard it, said nothing, and continued the conversation.
That call is probably compliant under California Penal Code Section 632. It is also probably non-compliant under the same statute if the AI is configured slightly differently. The boundary depends on details that most AI voice intake vendors do not script for.
This post is the practical reference. The 12 US states that require all-party consent for recorded calls, what consent actually looks like in those states, what happens when a call crosses state lines, and the disclosure script pattern that works in every jurisdiction without breaking call flow.
TCPA does not cover call recording
Worth stating up front because most vendors confuse this point: the federal Telephone Consumer Protection Act (TCPA) does not regulate call recording. TCPA regulates outbound calling, autodialers, pre-recorded voice, and consent for telemarketing. Recording consent comes from a different patchwork: state wiretap statutes, layered on top of the federal Electronic Communications Privacy Act (ECPA) and the Wiretap Act (18 U.S.C. § 2511).
Federal law and 38 US states require only one-party consent for recording phone calls. As long as one party to the conversation consents (and in most cases, the party doing the recording counts as that one), the recording is legal. Twelve states require all-party consent: every party on the call must consent.
For AI voice intake, the relevant question is whether the AI's recording disclosure constitutes effective consent capture for every party on the call.
For the inbound-call rules under TCPA itself, see TCPA and AI voice intake.
The 12 all-party consent states, as of 2026
| State | Primary statute | Civil exposure | Criminal classification |
|---|---|---|---|
| California | Cal. Penal Code §§ 631, 632 | $5,000 per violation or treble damages | Misdemeanor |
| Connecticut | Conn. Gen. Stat. § 52-570d | Civil cause of action with statutory damages | Class D felony for unauthorized eavesdropping |
| Delaware | 11 Del. C. § 1335 | Civil cause of action | Class A misdemeanor |
| Florida | Fla. Stat. § 934.03 | Statutory damages | Third-degree felony |
| Illinois | 720 ILCS 5/14-2 (2014 revision) | Civil cause of action | Class 4 felony for surreptitious recording |
| Maryland | Md. Cts. & Jud. Proc. § 10-402 | Civil cause of action | Felony |
| Massachusetts | Mass. Gen. Laws ch. 272 § 99 | Civil cause of action | Felony |
| Montana | Mont. Code Ann. § 45-8-213 | Civil action available | Misdemeanor |
| Nevada | Nev. Rev. Stat. § 200.620 | Civil cause of action | Class D felony |
| New Hampshire | N.H. Rev. Stat. Ann. § 570-A:2 | Civil cause of action | Class B felony |
| Pennsylvania | 18 Pa. C.S. § 5703 | Civil cause of action | Third-degree felony |
| Washington | Wash. Rev. Code § 9.73.030 | Liquidated or actual damages | Class C felony |
A few state-by-state notes that vendors miss:
- Florida is sometimes confused with one-party-consent states because the statute has a specific exception for journalists gathering news. The default rule for AI voice intake is all-party consent.
- Illinois had its eavesdropping statute partially struck down by the state supreme court in 2014 (People v. Clark, People v. Melongo) and revised the same year. The current statute requires consent for recording "private conversations" with a clear definition.
- Pennsylvania is the most-litigated of the 12 states for AI voice contexts, partly because of the Wiretap Act's broad civil-action provision and partly because PA companies frequently call into other states (and vice versa).
- Connecticut has an additional electronic-disclosure requirement codified by regulation on top of the statute. Most AI voice agents do not produce a discrete signaling tone.
What "consent" actually looks like in practice
The legal standard in all-party consent states is generally: each party must be made aware that the call is being recorded and must continue the conversation, with that continuation treated as implied consent.
Three patterns that satisfy this in most states:
- Spoken disclosure followed by caller continuation. "Thank you for calling. This call is being recorded for quality and training purposes." Caller continues talking. Implied consent attaches.
- Spoken disclosure followed by explicit verbal consent. "Thank you for calling. This call is being recorded. May I continue?" Caller says yes. Explicit consent attaches. Stronger evidentiary posture.
- Disclosure plus opt-out path. "Thank you for calling. This call is being recorded. If you would prefer not to be recorded, please let me know." Caller says nothing. Continued participation is consent. The opt-out option strengthens the consent posture for litigation defense.
Two patterns that do NOT satisfy the requirement:
- Disclosure played AFTER substantive conversation begins. The first 30 seconds of recording happened before consent. Civil exposure attaches to that pre-disclosure period.
- Disclosure played in a recording the caller has to navigate past in an IVR, where the language is ambiguous about whether THIS call is being recorded versus whether calls in general may be recorded.
The cleanest configuration for AI voice intake is the disclosure as the literal first sentence of the call, before the agent identifies the firm and before any substantive question is asked. The few hundred milliseconds it costs in call-flow polish is well under the cost of one wiretap claim.
Cross-state calls: which state's law applies
This is the question vendors get wrong most often.
When a caller in California dials a New York firm, both California's all-party consent rule and New York's one-party consent rule are potentially in play. The general rule applied across most circuits: the law of the more restrictive jurisdiction governs. If either party is in a two-party-consent state, the AI voice agent should script for two-party consent.
The implication for AI voice intake configuration:
- Firms with intake lines that take calls from anywhere should default to two-party consent disclosure on every call. The one-party-consent jurisdictions do not penalize the extra disclosure.
- Vendors that "vary the script by caller area code" are using the wrong mental model. Caller location is unreliable. Cell phones move. VoIP numbers are jurisdictionally indeterminate. Default to the strict standard.
The default-to-two-party-consent pattern is also the simplest to operationalize. One script. One audit trail. One consent-capture pattern. No state-aware logic required at the call-routing layer.
The disclosure script that works everywhere
After a fair amount of vendor-evaluation work, the script pattern that satisfies the legal requirement in every US state and does not break the call flow is:
"Thank you for calling [Firm Name]. This call is being recorded for quality and training purposes. How can I help you today?"
Three things this pattern gets right:
- The disclosure is the first substantive utterance after the firm identification. Every word recorded after that point is post-disclosure.
- The "how can I help you" prompt at the end transitions immediately to substantive intake. The caller's response constitutes implied consent under the prevailing standard.
- The phrasing matches the dominant pattern in commercial customer-service recordings, which is the body of case law most heavily relied on by courts evaluating consent.
Variations that do not work as well:
- "May be recorded" instead of "is being recorded." The may-be formulation is weaker for consent purposes. Some statutes require disclosure of actual recording, not contingent recording.
- Long disclosures with multiple clauses. Callers stop listening after the first 5 to 7 seconds. A 20-second compliance script is functionally equivalent to no disclosure.
- Music or hold-message disclosures. Pre-call recordings do not satisfy in-call consent capture in most jurisdictions.
The audit trail nobody asks about until they need it
If a wiretap claim is brought, the firm wants timestamped evidence that:
- The disclosure was played at second 0 to 3 of the call.
- The caller continued the call after the disclosure.
- The caller's continued participation was logged as consent.
- The recording itself starts after the disclosure.
Most AI voice vendors capture some of this. Few capture all of it cleanly. The audit-trail data points worth requiring from a vendor:
- Timestamp of disclosure playback, down to the millisecond if possible.
- Speech-to-text confirmation that the disclosure was actually rendered, not just attempted.
- Voice-activity-detection timestamp showing when the caller started speaking after disclosure.
- Audit log entry tagging the call as "consent captured: implied" with the timestamp.
This is the kind of thing nobody asks about during procurement and everybody wants on day 1 of a litigation hold. Vendors who can produce this audit trail in CSV form on request have done the work. Vendors who say "we have audit logs" without showing what the logs contain have not.
Three diligence questions for vendor evaluation
The diligence pass for state-law compliance takes 15 minutes. The three questions:
- What is your default recording disclosure script, and is it the same in every state? The right answer is yes, the default script is two-party-consent compliant, no state-aware variation required. State-aware variation is a feature in some products and a complexity tax in others.
- At what point in the call does the disclosure play, and when does recording start? Disclosure must come before recording. Vendor demos that show "disclosure plays in the first 5 seconds" without showing the recording start timestamp are unverifiable.
- What does your per-call audit trail look like? Ask for a sample CSV export with disclosure-timestamp, recording-start-timestamp, and consent-capture flag fields. If the vendor cannot produce one in a business day, the audit trail does not exist as advertised.
If a vendor cannot answer all three in writing, they have not done the work for two-party-consent state operation. This is the diligence pass that separates vendors with legitimate compliance work from vendors who learned the law during sales calls.
For the federal-layer companion piece, see TCPA and AI voice intake. For the prospective-client confidentiality framework, see ABA Model Rule 1.18 and AI voice intake. To see how recording disclosure and audit-trail capture work in a live demo, book a call.
