All posts

Legal

TCPA and AI voice intake: what law firms actually need to know

NeuraVoice··8 min read

The most-asked question we get when a law firm evaluates an AI voice intake vendor is some version of "is this TCPA-compliant?" Almost every confident answer to that question, from vendors and from Google searches, is incomplete or wrong.

This post is not legal advice. It is a working overview of how the Telephone Consumer Protection Act actually applies to AI voice intake, written for managing partners and intake managers evaluating vendors. We have tried to be specific about what is settled, what is contested, and what your firm has to decide for itself.

What TCPA actually covers

The Telephone Consumer Protection Act of 1991, as amended, is a federal statute that regulates certain types of phone-based communications. The parts that matter for AI voice intake are:

  1. Outbound calls placed using an "automatic telephone dialing system" (ATDS) or pre-recorded voice to mobile phone numbers. These require prior express consent from the called party. Telemarketing or solicitation calls require prior express written consent.
  2. Outbound calls to residential lines with pre-recorded messages for telemarketing. Similar consent rules apply.
  3. Calls to numbers on the federal Do Not Call (DNC) registry for telemarketing. Federal DNC checking is mandatory before solicitation calls. Many states layer their own DNC rules on top.
  4. Revocation of consent. A consumer can revoke previously-given consent through any reasonable means. The vendor or your firm must honor it.

What TCPA does not cover, in the context of AI voice intake:

  • Inbound calls. When the consumer calls you, TCPA does not apply to that call. The consumer initiated the contact.
  • Calls placed manually, without an autodialer.
  • Calls to business lines (with some limited exceptions).
  • B2B calls in many configurations, though state law can layer here.

The inbound vs outbound distinction is the wedge

The single most useful thing to understand about TCPA for legal intake is that it primarily covers outbound. AI voice intake at most law firms is a defensive use case, not an offensive one. Callers dial the firm. The firm answers.

If your firm uses an AI voice agent for inbound intake, your TCPA exposure is small. The agent answers when the consumer calls. There is no "called party" in the TCPA sense; the consumer originated the call.

The exceptions worth flagging:

  • Outbound callbacks, even within a single intake conversation, may trigger TCPA scrutiny if they are automated. If your AI agent calls a prospective client back later that day to confirm a consult, that callback is outbound.
  • Outbound campaigns for matter intake (mass tort, class action solicitation) are squarely TCPA-covered. Express written consent from the consumer is required.
  • Outbound reactivation of stale leads sitting in your CRM can be TCPA-covered if the contact list contains mobile numbers and you are using automated dialing.

Most general-practice and personal-injury firms running AI voice intake never touch the outbound side. The exposure is incidental.

The call-recording layer

TCPA itself does not require call-recording consent. That comes from a different patchwork: state wiretap statutes. As of 2025, twelve US states require all-party consent for recording phone calls: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington. The other thirty-eight states (and federal law) only require one-party consent.

If your firm operates in or takes calls from any of the twelve all-party-consent states, the AI voice agent's opening line should include a recording disclosure. The standard pattern is "this call may be recorded for quality and training purposes," or a more specific firm-tailored variant. Caller acknowledgment (verbal "okay" or simply continuing the call) is typically treated as consent.

Two things firms often miss here:

  1. The recording disclosure has to come before the recording starts, or in the very first seconds of the call. A vendor that records the entire opener and only discloses afterward has a problem.
  2. The audit trail matters. If a wiretap claim is ever brought, your firm wants timestamped evidence that the disclosure was played, the caller continued, and consent was logged. Ask any vendor for their per-call audit trail.

AI-specific wrinkles

The case law that shapes TCPA for AI voice agents is evolving. A few things worth knowing:

Facebook v. Duguid (2021). The Supreme Court narrowed what counts as an "automatic telephone dialing system" under TCPA. The court held that an ATDS must use a random or sequential number generator. This narrowed TCPA exposure for many predictive-dialer use cases, but the consent and DNC requirements still apply to outbound autodialed calls and pre-recorded messages.

Pre-recorded vs synthetic voice. TCPA explicitly covers "artificial or pre-recorded voice." The plain-language reading covers AI-synthesized voice when used in outbound calls. The FCC has reinforced this in 2024 guidance treating AI-generated voice the same as pre-recorded voice for TCPA purposes. The AI voice agent itself is regulated. Consent rules apply.

Revocation handling. A consumer can revoke consent through any reasonable means: verbal statement on a call, text reply with "STOP," email, written letter. Your AI voice agent must recognize revocation and immediately end the call, log the do-not-contact flag, and not retry. A vendor without a clean revocation flow is a TCPA liability waiting to happen.

Four things firms underweight

After a fair amount of vendor-evaluation conversations, these are the four questions that come up too late.

1. How does the agent handle revocation mid-call?

If a caller says "take me off your list" or "do not call me again," the AI voice agent should immediately confirm, log the request as a permanent do-not-contact flag, and end the call gracefully. It should not pivot to a different value proposition or attempt one more qualifying question. The right behavior is a clean exit and a logged DNC flag that flows to your CRM. Test this in a vendor demo.

2. How is the recording disclosure scripted?

In all-party-consent states, the disclosure must come at the start of the call, before the substantive intake conversation. Ask the vendor for the exact opener used in those states. If it is the same opener as in one-party-consent states, that is a problem. State-aware scripting is a reasonable expectation for any vendor handling intake at scale.

3. Is your call data being used to train any model?

This is not strictly a TCPA question, but it is adjacent. Some AI voice vendors retain rights to use customer call data for training their underlying models. For legal intake, that is privilege-disclosure exposure dressed as a routine vendor practice. Ask in writing whether your call audio or transcripts ever leave your tenant for training purposes. The honest answer is "never." Anything else is a different conversation.

4. What is the state-law layer?

Some states have layered TCPA-style restrictions on top of federal law. Florida's mini-TCPA (the Florida Telephone Solicitation Act) is the most active in 2024 and 2025 litigation. California has its own consumer privacy and recording rules. Washington and Oregon have specific call-recording statutes. If your firm operates in or takes calls from those states, the vendor should be able to tell you how their script handles each. If the vendor's answer is "we follow federal TCPA," they do not know the answer.

Evaluating vendors

The right TCPA conversation with an AI voice intake vendor takes about twenty minutes. The questions are:

  1. Show me the recording disclosure your script uses for inbound calls in California, Florida, and Illinois.
  2. Show me a recording of your agent handling a "take me off your list" mid-call.
  3. Send me your DNC checking model for outbound. (For most legal-intake firms, the answer is "we do not do outbound and you do not need this.")
  4. Send me your data-use policy. Do you train any model on customer call data?
  5. What is your audit trail per call? Where do I read it during a procurement diligence pass?

If a vendor can answer all five in writing within a business day, they have thought about TCPA. If they cannot, they are going to learn TCPA in your firm's first complaint.

The actual TCPA exposure for inbound legal intake is small

Most general-practice law firms running AI voice intake on inbound calls have a TCPA risk profile that is roughly equivalent to running an outsourced answering service. The agent answers when the consumer calls. The recording disclosure is scripted. Revocation flows to a do-not-contact flag.

The vendor-evaluation work is bigger than the law. The actual law, applied to inbound intake, is mostly about getting the recording disclosure right and being able to honor revocation. Both are solved problems for vendors that have done the work.

The harder questions for legal buyers are a layer up: privilege, conflict checks, and what happens when the agent does not know the answer. We will cover those in the next post.

Keep reading

Try it on your own calls

Spin up an agent in 5 minutes. Cancel anytime.

14-day free trial, 60 free minutes, cancel anytime. Bring your own intake script or start from a template. Wire it up to your CRM when you're ready.

Start free trial

Want a guided walkthrough first? Talk to the team.