Blog

Turned On AI Texting? The Compliance Questions You Haven't Asked Yet

The rules didn't change because a machine is doing the texting. What changed is how fast a sloppy setup gets you caught.

If you've flipped on AI texting and your speed to lead finally looks the way it should, good. Before you celebrate, here are the five things I'd have someone on your team check this week, before a carrier or a regulator checks them for you:

  • Confirm every number is 10DLC registered, yours and your vendor's. Unregistered traffic doesn't get slowed down anymore. It gets blocked.

  • Pull one consent record at random. Not just whether you have it, but whether someone could stand up in a deposition and authenticate it. If you can't produce the timestamp and the source, it isn't consent you can defend.

  • Write down how you handle opt-outs. The FCC is about to let you designate one exclusive method, but only if you disclose it clearly in your messages. If you haven't done that work, you're still honoring anything that reads like a stop request.

  • Check that texts physically cannot fire outside legal sending windows, even at 9:45 at night when someone's chasing a number.

  • Know your 90-day line. If your last good consent is older than that, you may need fresh consent before you re-engage.

What's actually changed

The rules held steady for years. This month they moved twice.

Start with the litigation picture, because it's doing something more interesting than most coverage suggests. Filings ran up hard through 2024 and 2025 and peaked this spring. Then July 2026 came in at 108 TCPA class actions against 198 in July 2025, a 45% drop, and Eric J. Troutman is openly asking whether we've finally seen the top. But read the year-to-date number before you relax: 1,371 filings through July 31 against 1,250 a year ago, still up 9.7%.

So the monthly trend is cooling and the annual volume is still higher than last year. If you're waiting for a signal that this stopped being a problem, that isn't it.

The foundation hasn't moved. Get consent before you text, honor opt-outs, identify yourself (47 U.S.C. ยง 227).

In February 2024, the FCC confirmed that AI-generated messages fall under the same TCPA restrictions as human ones. No carve-out, no grace period. If your system sends a text, consent rules apply exactly as if a producer picked up the phone.

The opt-out rules just flipped

This is the one to pay attention to. The FCC has revealed revisions to its revocation rules that go the opposite direction from what everyone was bracing for. The "nuclear" version, where one stop request killed every message you send, is dead.

Three pieces to it.

  • An opt-out from an informational message now applies only to that category of message, not to everything you send.

  • An opt-out from a marketing message still ends all future marketing from you. Worth sitting with, because most agency lead outreach is marketing. That's the bucket you're in.

  • And the big one. You can designate an exclusive way to opt out, a keyword, a keypress, or a number or website you provide, and you don't have to process revocation requests made any other way.

That third piece only protects you if you clearly and conspicuously disclose the designated method in the message. No disclosure, no protection. This is an option you have to actually set up, not something that arrives on its own.

It also isn't law yet. It's set to be adopted at the September open meeting and takes effect 30 days after Federal Register publication, and it reads as prospective. Nothing you already sent gets cleaned up by it. The full ruling is here if you want to hand it to your counsel.

The carrier side is a separate system

This is the part agencies get wrong. 10DLC isn't the FCC. It's the carriers, using CTIA's messaging standards, with The Campaign Registry as the gate. Since February 2025 they've blocked unregistered traffic outright. Which means you can be fully TCPA-compliant and still have your messages die on the way out, and you can pass carrier filtering and still lose a suit on consent documentation. Two systems, both of which have to be satisfied. The carrier one bites faster because it's automated.

One piece of good news that still holds. The Eleventh Circuit vacated the FCC's one-to-one consent rule in early 2025 (Insurance Marketing Coalition v. FCC), so the way most agencies collect consent through lead vendors, where one opt-in can cover multiple sellers, still works under the general read. That one matters for how lead flow operates in this industry.

Your compliance counsel confirms the specifics for your setup. I'm telling you what I keep seeing on the ground, not handing you a legal opinion.

The call I keep getting

Every few weeks I get the same call. An owner turned on AI texting, the contact rates are climbing, and someone finally asks the question nobody raised during setup: are we actually compliant if the AI is the one sending the texts?

Fair question. The honest answer is that the rules don't change just because a machine is doing the work. The only thing that matters is whether your setup clears the same bar every time, on message 1 and on message 10,000.

When I walk through it with them, the same blind spots show up.

10DLC registration, because a lot of folks still haven't done it and didn't realize the vendor's numbers count too.

Consent documentation, and this one just got a lesson attached to it. A court recently threw out a Jornaya record as hearsay because the defense couldn't authenticate it, and the defendant lost its summary judgment bid over it. Having the record in a system somewhere is not the same as being able to prove it's real. That's a distinction most agencies have never been asked to make. Notice that none of this month's opt-out changes touch it.

The 90-day gap, because you buy a lead in January, they don't bind, you want them back in May, and your consent may have gone stale. I see that one missed constantly.

State rules, where Florida, Washington, and Oklahoma have moved past federal TCPA and California has addressed AI disclosure. That's exactly where your own counsel earns their fee.

The thing that catches most agencies is finding out after the fact which pieces their vendor actually covered and which ones quietly landed on them. That discovery has a way of arriving at the worst possible time.

What counts as "stop"

Until the new rule lands, the case law is still the case law, and it has been all over the place.

Palm Beach Tan is paying $2.5 million to settle a suit over texts sent after stop requests, and the settlement came with a list of the phrasings that counted. A Florida court held in August that "Stop" sent to a text may revoke consent for your calls too. Meanwhile a New York court found a free-form request insufficient to stop further texts, though on unusually clean facts for the defense.

Troutman expects the new rule to crush the free-form opt-out litigation going forward. I'd believe it. But "going forward" is carrying real weight in that sentence, and none of it helps on messages you already sent.

So here's how I'd play it. If you want the designated-method protection, go get it deliberately. Pick your keyword, disclose it clearly in every message, document that you did it. If you're not going to do that work, keep honoring anything that reads like a stop request, the way you do now. What hurts agencies is assuming they have protection they never actually set up.

One aside. Stopping a channel and declining a product aren't the same thing, and if you've done the work to designate an exclusive opt-out method, you have room to confirm by another channel whether they still want a quote. If you haven't done that work, you don't have that room yet, and this is exactly the fact pattern the cases above turned on.

And the federal rule doesn't override your state. Pennsylvania's new telemarketing law codifies its own opt-out keyword list starting in October, and it keys quiet hours to where the consumer is, not where your office is.

There's also a live fight over whether a text is a "telephone call" for do-not-call purposes. A Missouri court just joined what Troutman calls the new majority holding it isn't, while a New Jersey court went the other way days earlier. I'd watch it rather than plan around it.

A machine doesn't have bad days

Here's the part I find encouraging. Once you treat compliance as a process question, the machine starts working in your favor.

A rep running 100 dials a day forgets the opt-out language, texts someone at 9:45 because they're trying to hit a number, loses track of who opted out last week. A system built right doesn't have those days. It checks consent before every message, catches an opt-out the moment it lands, holds the sending window on its own, and keeps a full record of every conversation, timestamps, consent events, opt-outs, all of it.

It also means that when a rule changes the way it just did, you change one setting instead of retraining a floor and hoping it took.

That last part about the record is the one agencies undervalue until they need it. An audit trail generated as the conversation happens is a different asset than three people digging through a CRM six months later trying to rebuild what happened. The Jornaya ruling is what that difference costs.

Mav clears this bar, and it's a fair thing to make any AI vendor show you in detail. A system that makes non-compliance structurally hard is a different animal than a person trying to remember training on every single interaction.

Before you go

I want to know where the worry actually sits for you. Of the four gaps that trip agencies up most, 10DLC registration, consent documentation, the 90-day re-engagement window, and state-level rules, which one is the thorn in your side right now? We'll dig into that next time I write about compliance.

Greg Spano

Greg Spano

© 2026 Mav Automation Ventures Inc. All rights reserved.