Last updated: July 2026. Before a deployment goes live, the question owners ask us most often isn't about price or voice quality. It's "am I actually allowed to do this?" The short answer is yes. No US federal law bans an AI receptionist, and the FCC has stated plainly that the Telephone Consumer Protection Act's requirements "do not extend to technologies used to answer inbound calls." What does apply is narrower than most of the internet claims, but it isn't nothing. This guide maps the real rules, state by state, with the statute text behind each one.
This article is general information, not legal advice. AI rules are moving quickly, and how they apply depends on your state, your industry, and how your calls are handled. Run your setup past your own attorney before relying on it.
Key takeaways
- No federal law bans AI receptionists. The TCPA governs calls you place. In its 2024 proposed rule on AI calls, the FCC wrote that "the TCPA's requirements do not extend to technologies used to answer inbound calls" (FCC 24-84, ¶ 11).
- The "$500 per call" number does not apply to inbound answering. TCPA damages attach to calls a business makes. A customer dialing your number isn't one of them.
- Maine is the law that squarely reaches a voice AI. Since September 24, 2025, 10 M.R.S. §1500-DD covers chatbots that communicate through "aural" means, voice included. One sentence of disclosure satisfies it.
- The FTC has no AI-disclosure rule. Operation AI Comply (September 25, 2024) targeted how five companies marketed or enabled AI products, not businesses that quietly used AI.
- Call-recording consent is the real exposure, and it predates AI entirely. Roughly a dozen states require all-party consent for recorded calls.
- Ignore any page telling you the Colorado AI Act lands June 30, 2026. It was repealed and reenacted in May 2026; the new framework starts January 1, 2027.
Is it legal to use an AI receptionist in 2026?
Yes. No US federal statute prohibits a business from using an AI voice agent to answer its own phone. The laws people worry about fall into three buckets, and only two of them touch an inbound receptionist at all.
The first bucket is robocall law: the TCPA and the FCC rules under it. That regime is built around calls a business initiates to consumers. The second is the new wave of state AI-transparency laws, which are about telling people when they're talking to a machine. Only a handful reach a business receptionist, and the duty they impose is usually one line of script. The third is call-recording consent, which has nothing to do with AI and everything to do with wiretap statutes written decades ago.
The practical upshot: the legal work of deploying an AI receptionist is mostly a greeting decision and a recording decision. It is not a licensing problem, and there is no federal permission slip to obtain.
Does the TCPA apply to an AI receptionist answering inbound calls?
Almost certainly not, and this is where most content in this space goes wrong. The TCPA's restrictions live in 47 U.S.C. § 227(b)(1), and the operative verbs are narrow. The statute makes it unlawful "to make any call … using any automatic telephone dialing system or an artificial or prerecorded voice," and "to initiate any telephone call to any residential telephone line using an artificial or prerecorded voice."
Make. Initiate. A business answering a call its customer dialed does neither. The limitation is on the face of the statute, not a lawyer's interpretation of it.
In February 2024, the FCC confirmed that AI-generated voices count as "artificial" under the TCPA (FCC 24-17, released February 8, 2024). That ruling got wide coverage and is the source of most of the fear. But read what it actually covers: AI technology that initiates outbound calls to consumers. It says nothing about answering.
The FCC then made the point explicit. When it proposed new AI calling rules in August 2024, it explained why its definition was drawn the way it was:
"[T]he TCPA's prohibition on using an artificial or prerecorded voice message extends only to outbound calls that are 'made' or 'initiated' by the caller. … The TCPA's requirements do not extend to technologies used to answer inbound calls."
Source: Federal Communications Commission, Notice of Proposed Rulemaking, FCC 24-84, ¶ 11 (August 2024)
The FCC's proposed definition of an "AI-generated call" ends with the words "over an outbound telephone call" (¶ 10). The agency said it drafted the definition that way to avoid "unintentionally encumbering … widely used existing customer service technologies on inbound calls." That NPRM is still a proposal, and as of July 2026 no final rule has been adopted. But it tells you how the regulator reads its own statute.
One honest caveat: if you use the same platform for outbound calling (follow-up campaigns, lead re-engagement, appointment reminders to people who didn't ask for them), you are squarely back inside TCPA territory, and consent rules apply. The inbound/outbound line is the whole ballgame. Know which side of it each call sits on.
Do you have to tell callers they're talking to an AI?
In most states, not as a matter of law. But the trend is running toward disclosure, and one state already requires it for voice.
Maine is the clearest case. Since September 24, 2025, 10 M.R.S. §1500-DD has prohibited using "an artificial intelligence chatbot or any other computer technology to engage in trade and commerce with a consumer in a manner that may mislead or deceive a reasonable consumer into believing that the consumer is engaging with a human being unless the consumer is notified in a clear and conspicuous manner that the consumer is not engaging with a human being." Maine defines a chatbot as software that simulates human conversation "through textual or aural communications." Aural means voice. A phone receptionist is in scope.
Read the trigger carefully, though. The duty bites only where a reasonable consumer may be misled into thinking they're talking to a person. Disclosing at the top of the call discharges it completely. Violations run through the Maine Unfair Trade Practices Act; the section itself doesn't state a dollar figure, and we'd treat any specific penalty number you see quoted online as unverified.
Utah takes a lighter approach than its early reputation suggests. The Utah AI Policy Act (SB 149) originally required proactive disclosure, but 2025 amendments (SB 226 and SB 332, effective May 7, 2025) scaled it back sharply. For ordinary consumer interactions, you must disclose only when someone makes "a clear and unambiguous request" to know whether they're talking to a human or a machine. In other words: when the caller asks, answer honestly. Utah's Division of Consumer Protection can impose administrative fines of $2,500 per violation, per Davis Polk's analysis of the amendments. Any page still telling you Utah demands upfront disclosure for every consumer is quoting the pre-2025 rule.
Which state AI laws actually reach a business AI receptionist?
Fewer than the headlines imply. Most of the laws that get cited in this conversation were written for a different problem: outbound robocalls, online sales bots, companion chatbots, or algorithmic decisions about housing and employment. Here's what each one really covers.
| Law | In force | Reaches an inbound AI receptionist? | What it actually covers |
| TCPA + FCC Declaratory Ruling (FCC 24-17) | Feb 8, 2024 | No | Outbound calls you place using an artificial or prerecorded voice |
| FCC AI NPRM (FCC 24-84) | Proposed Aug 2024, not law | No | Would require disclosure on outbound AI calls; expressly carves out inbound |
| Maine: 10 M.R.S. §1500-DD | Sept 24, 2025 | Yes | Any chatbot including "aural"; disclose if a consumer could be misled |
| Utah AI Policy Act (SB 149, am. SB 226 / SB 332) | May 7, 2025 | Partly | Disclose on a "clear and unambiguous request"; proactive only for high-risk regulated-occupation interactions |
| California AB 2905 (Pub. Util. Code §2874) | Jan 1, 2025 | No | Outbound autodialed calls using an AI-generated voice |
| California B.O.T. Act (SB 1001) | Jul 1, 2019 | No | Online bots only; needs intent to mislead plus a sales or voting purpose |
| California SB 243 | Jan 1, 2026 | No | Companion chatbots; expressly excludes customer-service and business-operations bots |
| Texas TRAIGA (HB 149) | Jan 1, 2026 | Maybe (health care) | Government agencies, plus AI used in relation to a health care service or treatment. Untested for front-desk scheduling |
| Colorado SB 24-205, repealed & reenacted by SB 26-189 | Jan 1, 2027 | Unlikely | Automated decisions in "consequential" areas; booking an appointment isn't one |
Two of these deserve a flag because they're the most commonly misreported. California SB 243 is a companion-chatbot law; its text expressly excludes bots "used only for customer service" and business operational purposes (SB 243 text). And the Colorado AI Act is the one nearly every competing article still gets wrong: it never took effect in its original form. Governor Polis signed SB 26-189 on May 14, 2026, which "repeals and reenacts those provisions" with a narrower automated-decision framework starting January 1, 2027 (see Holland & Knight's summary). If a page tells you to prepare for June 30, 2026, it hasn't been updated since spring.
Does the FTC require you to disclose AI in customer service?
No. There is no FTC rule requiring businesses to announce AI in customer service, and you should be skeptical of any page that says otherwise. This is the single most repeated error in the AI receptionist niche.
What the FTC has is Section 5 of the FTC Act, its general authority over unfair and deceptive practices, and a willingness to use it. In September 2024 the agency announced Operation AI Comply, a five-case enforcement sweep: DoNotPay, Rytr, Ascend Ecom, Ecommerce Empire Builders, and FBA Machine.
Four of the five were about false claims made about an AI product: a "robot lawyer" that couldn't lawyer, business opportunities that overpromised returns. The fifth, Rytr, was different. The FTC alleged its writing tool furnished users the means to generate fake reviews, a theory two commissioners publicly dissented from. But here's the part that matters for you: not one of the five involved a company failing to tell customers they were talking to a machine.
"Using AI tools to trick, mislead, or defraud people is illegal. The FTC's enforcement actions make clear that there is no AI exemption from the laws on the books."
Source: Lina M. Khan, then-Chair, US Federal Trade Commission, announcing Operation AI Comply, September 25, 2024
That framing is the one to internalize. The FTC isn't policing whether you use AI. It's policing deception, and as Rytr shows, that extends to helping someone else deceive. An AI receptionist that answers honestly when asked, and doesn't impersonate a specific named human, sits outside the theory entirely.
Do you need consent to record calls your AI receptionist answers?
This is the exposure that actually deserves your attention, and it has nothing to do with AI. Recording a phone call is governed by wiretap statutes that long predate voice agents. But AI receptionists record and transcribe by default, which quietly moves a lot of businesses into scope for the first time.
Federal law sets a one-party-consent floor (18 U.S.C. §§ 2510–2511): if you're a party to the call, you can record it. Many states go further and require all parties to consent. Working through the state-by-state entries in the Reporters Committee for Freedom of the Press's Reporter's Recording Guide, we count twelve: California, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, and Washington. Two more split the difference: Oregon applies all-party rules to in-person conversations but not phone calls, while Connecticut's criminal wiretap law requires one-party consent even though its civil statute requires all parties'.
Treat that list as a starting point, not gospel. A few states are genuinely contested. Delaware has conflicting statutes on the books, and Michigan's status turns on case law, so the count you'll see quoted varies by source. If you take calls across state lines, and if you advertise online you do, the safe default is to give recording notice on every call regardless of where you're based. That's one clause in your greeting, and it costs you nothing.
What should your AI receptionist actually say?
One sentence, at the top of the call, before anything substantive happens: "Thanks for calling [Business]. You're speaking with our AI assistant, and this call may be recorded. How can I help?"
That line does four jobs at once. It satisfies Maine's notification standard. It pre-answers Utah's "are you a robot?" request before anyone has to ask. It handles recording notice. And it sets an expectation the caller can work with. In our deployments the disclosure question resolves faster than owners expect, because the compliant version and the version that converts turn out to be the same sentence.
The fear owners bring to this is that disclosure kills the call, that people hang up the moment they hear "AI." What we see is that callers care far more about whether the thing on the other end can actually help them. Someone with a burst pipe at 11pm wants the appointment booked. The failure mode isn't disclosure; it's an agent that discloses and then can't do anything useful.
The one thing worth avoiding is a fake human persona. Giving your agent a name is fine and normal. Insisting it's a person when a caller directly asks is where you cross from a script decision into a deception problem. And per Khan's framing above, that's the theory regulators already have.
A five-step compliance checklist
If you want the whole thing as a to-do list, this is it:
- Disclose in the greeting. One sentence, before anything substantive. Covers Maine, pre-empts Utah.
- Add recording notice to the same sentence if calls are recorded or transcribed, which with any AI agent they are.
- Tell the truth when asked. Script the agent to confirm it's an AI if a caller asks directly. Never claim to be a named human.
- Separate your outbound. Follow-ups, reminders, and re-engagement campaigns are TCPA territory and need consent. Inbound answering is not. Know which is which.
- Check your industry overlay. Licensed providers in Texas, and law firms everywhere, have duties the general statutes don't create. That's a conversation with your counsel or your bar, not a blog post.
What does this mean for dental, legal, and home-services businesses?
Your industry changes the nuance more than the answer. The baseline holds everywhere: disclose in the greeting, handle recording consent.
Dental and medical practices carry a few extra questions. Utah attaches heightened duties to "regulated occupations," but the proactive-disclosure trigger requires a high-risk interaction: collecting sensitive personal information and giving personalized advice someone would rely on for a significant decision. That test is conjunctive: both prongs, or no duty. Booking a cleaning involves no reliance-grade advice, so it fails the test regardless of what the call collects.
Texas deserves more caution than most articles give it. TRAIGA's healthcare disclosure duty (Tex. Bus. & Com. Code § 552.051) is tied to AI used in relation to a health care service or treatment, which is broader than diagnosis alone, and broader than the "diagnosis or treatment" shorthand you'll see repeated around the web. Whether front-desk scheduling at a licensed practice falls inside "in relation to" is untested. If you're a licensed provider in Texas, treat that as an open question for your counsel, not a settled exemption; Norton Rose Fulbright's analysis of TRAIGA walks through the scope.
Texas also passed SB 1188 (effective September 1, 2025), a broader medical-records law whose AI provisions attach to diagnostic use. Where a practitioner uses AI for diagnosis, they must stay within their license scope, review AI-generated records consistent with Texas Medical Board standards, and disclose the AI use to patients. Note the two laws pull in different directions: TRAIGA is broader than diagnosis, SB 1188's duty is diagnosis-tied. Don't let anyone blur them for you.
The other question every practice asks is HIPAA, a separate regime from the disclosure laws above. In short: AIEmply is HIPAA-ready for healthcare clients, we sign a business associate agreement, and no vendor is "HIPAA certified," because HHS certifies no one. For what a healthcare practice should verify before buying, including the BAA, the business-associate test, and the 2026 penalty tiers, see our full guide to whether an AI receptionist is HIPAA compliant.
Law firms have a duty the statutes don't create: professional responsibility. Client confidentiality and competence obligations apply to any tool touching prospective-client intake, and several state bars have issued their own AI guidance. The statutory analysis above doesn't change, but your bar's rules are a separate check. See AI receptionists for law firms for how intake calls are triaged.
HVAC, plumbing, and contractors have the simplest position of the group: no regulated-occupation overlay, no health data. The live issue is emergency triage. An after-hours call about a gas smell needs to reach a human fast, and that's a routing decision, not a legal one. Our HVAC and plumbing AI receptionist page walks through the escalation path.
How AIEmply handles this in practice
We build the disclosure line into the greeting during setup, because it's the default that ages well. Regulators are moving one direction on transparency, and a script written to be honest today doesn't need rewriting when the next state passes something.
On the data side, the claims we make are narrow and specific. AIEmply, a product of Veltro Systems LLC, is GDPR- and CCPA-compliant, uses enterprise-grade encryption, and never shares your conversation data with third parties. You own it. What we won't tell you is that we make you compliant. No vendor can, because compliance depends on your state, your industry, your recording posture, and your outbound practices. Any vendor promising blanket legal cover is selling something we wouldn't buy.
None of which is the point, though. The compliance question is a sentence of script. The question underneath it is whether the phone gets answered at all, and that's where the money is. A 100% answer rate against roughly 60% handled manually is the difference between the two, and it's the only number in this article that shows up on your P&L. It's more than a phone bot. It's a trained virtual employee customized to your business, answering in under 3 seconds, 24/7/365, and handing off to a human the moment a call needs one. Most businesses are ready to test in 1–2 weeks.
The bottom line
No state we've found bans an AI receptionist outright. The TCPA, the law that generates most of the anxiety, governs calls you place, and the FCC has said in its own proposed rule that its requirements don't reach technologies used to answer inbound calls. Maine requires disclosure for voice AI in commerce. Utah requires an honest answer when a caller asks. The FTC has no disclosure rule, only a deception theory that punishes lying. And recording consent, the oldest rule in the stack, is the one most likely to catch you out.
Handle it in one sentence at the top of the call, get your recording posture right, and the legal question is closed. Then you can go back to the question that actually moves money: whether the calls are getting answered at all.
100% Answer Rate • Ready in 1–2 Weeks • Performance Guarantee
If you want to hear how a disclosed greeting actually sounds on a live call, try a live demo or see how it works. When you're ready to price it out, plans start at $149/month, no credit card required. The guarantee is exactly this: "Billing starts only after your AI Employee is live. If the first month delivers no measurable result, the next month is free."
Book a 15-minute consultation and we'll map your call flow, your disclosure line, and your integrations in one sitting.
Related reading: How does an AI receptionist work? · AI receptionist vs answering service · Best AI receptionist for small business
Frequently asked questions
Is it legal to use an AI receptionist in the United States?
Yes. No US federal law bans a business from using an AI voice agent to answer its own phone, and we're not aware of any state that bans it outright. The rules that exist govern two things: disclosing that a caller is talking to AI, and getting consent to record the call. Both are handled in the greeting.
Does the TCPA apply to an AI receptionist?
Generally no. The TCPA restricts calls a business "makes" or "initiates" to consumers using an artificial or prerecorded voice. Answering a call your customer dialed is neither. In its 2024 proposed rule on AI calls (FCC 24-84, ¶ 11), the FCC stated that "the TCPA's requirements do not extend to technologies used to answer inbound calls." Outbound AI calling is a different matter and does require consent.
Do I have to tell callers they are speaking to an AI?
In Maine, yes. 10 M.R.S. §1500-DD covers voice chatbots and requires clear notification where a consumer might otherwise believe they're talking to a human. In Utah, you must answer honestly when a caller makes a clear and unambiguous request. Most other states have no such duty for inbound customer service, but disclosure is the safer default as more states legislate.
Does the FTC require businesses to disclose AI use?
No. The FTC has no rule requiring AI disclosure in customer service. It enforces Section 5 of the FTC Act against deception, and its September 2024 Operation AI Comply sweep targeted five companies over how they marketed or enabled AI products. Not one of the five involved a business failing to tell customers they were talking to a machine. Claims that "the FTC requires disclosure" are inaccurate.
Do I need consent to record calls my AI receptionist answers?
Often, yes, and this rule predates AI. Federal law requires one-party consent, but roughly a dozen states require all-party consent, including California, Florida, Illinois, and Washington. Because calls cross state lines, the safe practice is to give recording notice on every call, which the standard greeting already does.
What should my AI receptionist say at the start of a call?
A single sentence covers it: "Thanks for calling [Business]. You're speaking with our AI assistant, and this call may be recorded. How can I help?" That satisfies Maine's notification standard, pre-answers Utah's request rule, and handles recording notice before any substantive conversation begins.
Does the Colorado AI Act affect my AI receptionist?
Not in its original form. That version never took effect. Colorado SB 26-189, signed May 14, 2026, repealed and reenacted the AI Act with a narrower automated-decision framework beginning January 1, 2027. It targets automated decisions in consequential areas like employment, housing, and lending. Booking an appointment is not a consequential decision.
Is an AI receptionist allowed in California?
Yes. California's B.O.T. Act (SB 1001) applies to online bots, not phone calls, and requires intent to mislead plus a sales or voting purpose. AB 2905 covers outbound autodialed calls using an AI voice. SB 243 covers companion chatbots and expressly excludes customer-service bots. California does require all-party consent to record calls.
Sources
- Federal Communications Commission, "Implications of Artificial Intelligence Technologies on Protecting Consumers from Unwanted Robocalls and Robotexts," Notice of Proposed Rulemaking (FCC 24-84), August 2024, retrieved July 2026.
- Federal Communications Commission, Declaratory Ruling on AI-generated voices under the TCPA (FCC 24-17), February 8, 2024, retrieved July 2026.
- Cornell Legal Information Institute, 47 U.S.C. § 227: Restrictions on use of telephone equipment, retrieved July 2026.
- Maine Legislature, 10 M.R.S. §1500-DD: Use of artificial intelligence chatbots in trade or commerce, effective September 24, 2025, retrieved July 2026.
- Davis Polk, "Utah scales back reach of generative AI consumer protection law", 2025, retrieved July 2026.
- California Legislature, Public Utilities Code § 2874 (as amended by AB 2905), retrieved July 2026.
- California Legislature, SB 243: Companion chatbots, retrieved July 2026.
- Colorado General Assembly, SB 26-189: Automated Decision-Making Technology, signed May 14, 2026, retrieved July 2026.
- Holland & Knight, "Colorado Governor Signs SB 189", May 2026, retrieved July 2026.
- Norton Rose Fulbright, "The Texas Responsible AI Governance Act", retrieved July 2026.
- Holland & Knight, "Texas Enacts Comprehensive AI Governance Laws with Sector-Specific Healthcare Provisions" (covering SB 1188 and HB 149), June 2025, retrieved July 2026.
- Federal Trade Commission, "FTC Announces Crackdown on Deceptive AI Claims and Schemes", September 25, 2024, retrieved July 2026.
- Reporters Committee for Freedom of the Press, Reporter's Recording Guide, retrieved July 2026.
- Kelley Drye, "FCC Proposes New TCPA Rules for AI Calls and Texts", retrieved July 2026.