Outbound calls · safety & consent
Outbound AI Call Safety and Consent
Inbound is easy: someone called you. Outbound is where an AI agent can get a business in trouble, because the agent decides who gets a phone call. This page points to the federal rules that apply, links each one to its primary source, and turns them into checks you can put in front of make_call.
This is not legal advice. It summarizes federal sources so you know what to read and what to ask counsel. State laws add their own requirements, and which rules apply depends on what the call is for and who receives it. Read the linked text, not just this page.
The FCC ruling on AI voices
In February 2024 the FCC released a Declaratory Ruling, FCC 24-17 (CG Docket No. 23-362), on AI and robocalls. Its operative sentence, from paragraph 2: the TCPA's restrictions on the use of "artificial or prerecorded voice" encompass current AI technologies that generate human voices, so calls that use them "require the prior express consent of the called party to initiate such calls absent an emergency purpose or exemption."
For a builder, the practical reading is simple. An agent that speaks with a synthesized voice is placing an artificial-voice call. Whether you have consent, and what kind, is a question to answer before the call, not after it.
The FCC delivery rules: 47 CFR 64.1200
The FCC's implementing rules live in 47 CFR § 64.1200. Several paragraphs map directly onto agent design:
| § 64.1200(b)(1)–(2) | Artificial or prerecorded voice messages must identify the business responsible at the beginning of the message and state a telephone number for it. |
| § 64.1200(b)(3) | For telemarketing and certain exempted calls to residential lines: an automated voice or key-press opt-out mechanism, offered within two seconds of the identification, that records the number to the do-not-call list and ends the call. |
| § 64.1200(c)(1) | No telephone solicitation to a residential subscriber before 8 a.m. or after 9 p.m., local time at the called party's location. |
| § 64.1200(c)(2) | No telephone solicitation to a residential subscriber on the national do-not-call registry, subject to the safe-harbor conditions in the rule. |
| § 64.1200(d) | Callers covered by the rule must keep their own do-not-call list with written procedures, and honor a request within a reasonable time, not more than ten business days. |
These paragraphs have conditions and exceptions this table leaves out. Which ones apply depends on whether the call is telemarketing, informational, or exempt, and on whether it reaches a residential line or a wireless number.
The FTC side: the Telemarketing Sales Rule
The FTC enforces the Telemarketing Sales Rule, 16 CFR Part 310. For outbound sales calls it covers, among other things, calling-time limits (§ 310.4(c): between 8 a.m. and 9 p.m. at the called person's location, without prior consent), required oral disclosures at the start of a sales call (§ 310.4(d): the seller's identity, that the purpose is to sell, and what is being sold), and access to the National Do Not Call Registry (§ 310.8). Sellers and telemarketers get registry data through the FTC's telemarketer registry site, not the consumer sign-up page.
Turning the rules into agent checks
make_call executes on a valid calls:write key. It carries destructiveHint: true, so clients that honor annotations will ask a human first, but there is no server-side approval step in front of it today. That makes the checks below your agent's job:
- Know why you are calling. Classify each call before dialing: a reply to someone who asked to be called, an informational call, or a sales call. The rules above differ by category, so the classification belongs in your data, not just the prompt.
- Store consent where the agent can check it. Keep the consent record (what, when, how captured) on the lead. Have the agent refuse to call a number without one, and log the refusal.
- Identify the business in the first words. Put the business name and a callback number in
first_messageor the agent's greeting. - Check local time at the recipient's location. Not your server's time zone.
- Scrub against the national registry yourself. CallMCP does not look numbers up in the National Do Not Call Registry before dialing. It enforces its own suppression list, built from in-call opt-outs and manual entries.
- Make retries safe. Pass an
idempotency_keyon everymake_callso a retry returns the original call instead of dialing twice. - Keep a human in the loop for volume. Run outbound tools in a client that asks before destructive calls, or put your own approval step in front of them, especially for anything that looks like a campaign.
// sketch of a pre-dial gate in your agent code, before tools/call make_call
if (!lead.consent?.voice) return refuse('no consent on file');
if (lead.do_not_call) return refuse('on suppression list');
if (!withinLocalHours(lead.timezone)) return defer('outside calling hours');
if (call.purpose === 'sales' && !registryScrubbedRecently(lead.phone))
return refuse('registry scrub missing');
return callTool('make_call', { agent_id, to: lead.phone, idempotency_key });What CallMCP does on its side
Some protections run server-side regardless of what your agent does: a state-aware AI and recording disclosure prepended to the greeting, opt-out phrases detected in caller transcripts that suppress the number for both voice and SMS, calling-hours checks on scheduled callbacks and outbound SMS, and approval gates on number purchases and config changes. The safety and compliance page documents each one, with the gaps named, so you can see exactly where your own checks need to cover.
Next: if you are still deciding how your agent should reach the phone at all, read how to give an AI agent a phone number and MCP vs REST for voice agents.