FDCPA and Reg F for Automated Collection Calls


FDCPA compliance is the set of obligations a third-party debt collector carries on every consumer contact: what must be disclosed, how often you can call, when, and what you must do when a consumer disputes the debt or asks you to stop.
None of the FDCPA obligations change when an AI voice agent places the call instead of a person. That statute regulates the communication, not the caller. A second statute, the TCPA, does turn on the caller, and that is the part most collections teams miss.
What does change is where the risk sits. A human collector varies from the script and a voice agent does not, which makes the configuration the compliance surface. This post covers what that means in practice.
TL;DR
Yes, in full, wherever it would apply to a human collector making the same call.
The FDCPA regulates communications in connection with the collection of a debt by a debt collector. It does not distinguish between a collector speaking, a collector using a dialer, a prerecorded message, or a conversational AI agent.
So the analysis does not start with the technology. It starts with the same two questions as always: is this entity a debt collector for this debt, and is this communication in connection with collecting it. If both are yes, every obligation attaches.
The corollary matters just as much. There is no rule prohibiting automated collection calls, and treating AI as categorically off-limits reads a restriction into the FDCPA that is not there. What is there, in a different statute, is a consent regime. The FCC has ruled that an AI-generated voice is an artificial voice under the TCPA, so the technology does change the consent analysis even though it changes nothing in the FDCPA one. Both are covered below.
Regulation F is the CFPB rule implementing the FDCPA, effective since November 30, 2021. Six obligations shape any calling program.
| Requirement | What it means on a call |
|---|---|
| Call frequency | A presumption of compliance at or below seven calls about a particular debt within seven consecutive days with no call within seven days of a telephone conversation about that debt, and a presumption of violation above either. The CFPB is explicit that the rule sets no hard cap |
| Time and place | No calls before 8 a.m. or after 9 p.m. in the consumer's local time, and none at a time or place known to be inconvenient |
| Identification and purpose | The collector identifies itself and discloses that the communication is an attempt to collect a debt |
| Validation notice | Required debt information delivered in or within five days of the initial communication, with a dispute window that follows |
| Third-party disclosure | The debt may not be revealed to anyone other than the consumer, which governs voicemails and wrong-person answers |
| Conduct | No harassment, no false or misleading representations, no unfair practices |
Two details of the frequency rule are routinely misread and both matter for how a system is built. The presumptions are rebuttable rather than hard caps, so exceeding them creates a presumption of violation that a collector may rebut with evidence, and they are counted per debt rather than per consumer, so a consumer with three accounts is analyzed three times. The CFPB's Debt Collection Rule FAQs are the primary source and are worth reading directly rather than through a vendor summary.
One more detail that changes system design: the consent that takes a call outside the frequency count covers a period no longer than seven consecutive days, even if the consumer agrees to a longer one. It also ends early if the consumer revokes it, or as soon as you have a telephone conversation about that debt. An agent that records consent has to expire it on all three conditions, not just the clock.
The script stops being guidance and becomes configuration, which cuts both ways.
On a human floor, compliance risk is variance. Collectors improvise, skip disclosures under time pressure, talk over a dispute, or answer a question they should not. Monitoring catches a sample of it after the fact.
With a voice agent, variance collapses. The disclosure lands identically on call one and call ten thousand, the calling window is enforced by the dialing logic rather than remembered, and every call produces a transcript of what was actually said rather than an outcome code.
The flip side is that an error is systematic. A human collector who mishandles a dispute creates one incident. A misconfigured agent that mishandles disputes creates every incident in the campaign, at machine speed, before anyone reviews a call.
That asymmetry is the whole compliance argument, and it points in one direction: test hard before launch, monitor continuously afterwards, and treat any prompt change touching disclosure language as a compliance change rather than a copy edit.
Each one is a configuration decision, not a script sentence.
On the platform side the relevant pieces are the transfer behavior, the per-call record from post-call analysis, and scoring every call against your own criteria with AI quality assurance, which is how a compliance team reviews a whole campaign instead of a sample of twelve calls.
It does not make a program compliant, and any vendor implying otherwise is selling something that does not exist.
A voice agent executes the policy you configure. It has no view on whether your disclosure language is adequate, whether your state licensing is current, whether a particular account is time-barred, or whether a client contract imposes stricter rules than the statute.
Three specific limits worth stating to anyone evaluating this.
The security and vendor-diligence side is separate again. Any vendor touching consumer account data should publish its posture, as Retell does in its Trust Center, and that is an input to your assessment rather than a substitute for it.
They are different statutes, and collections teams conflate them constantly.
The FDCPA governs what a debt collector may say and how often. The TCPA governs consent for calls and texts, reaches first-party creditors as well as third-party collectors, and carries statutory damages per call. It is also the statute that turns on the technology, which is the part collections teams miss.
State law adds to this. California's AB 2905, effective January 1, 2025, requires a call that uses an AI-generated voice to say so.
A calling program can be immaculate under Regulation F and still be a TCPA problem if the consent position is wrong. Treat them as two separate reviews with two separate owners, and keep the consent record auditable at the account level.
Scripted demos prove nothing. Test the failure modes.
Then keep testing after launch, because agents drift as prompts get edited. Reviewing calls at volume rather than by sample is what makes that practical, and it is a large part of why collections teams run this on a platform they control. See how that fits an existing collections operation on the debt collection industry page.
None of this is legal advice. Your compliance counsel sets the parameters, and this post is a map of what they will need to decide.
There is no prohibition on the technology. The same FDCPA and Regulation F obligations apply as for a human collector, along with the TCPA consent rules and state law, so FDCPA legality depends on how the calls are configured. What does turn on who is speaking is the TCPA: an AI-generated voice is an artificial voice, so it needs prior express consent to a wireless number, is limited to three calls in any 30 days on a residential line, and carries an opt-out and identification requirement a live collector does not.
Regulation F presumes a violation where a collector places more than seven calls about a particular debt within seven consecutive days, or calls within seven days of having had a telephone conversation about that debt. Both presumptions are rebuttable and both count per debt rather than per consumer. Some states are stricter.
Yes. The requirement to identify the collector and state that the communication is an attempt to collect a debt attaches to the communication, so an automated call carries it exactly as a human call does.
Yes, using the limited-content message format: the consumer's name, a request to call back, the name of a person to contact, and a phone number. It must not indicate that the call concerns a debt, which is why the format exists.
The agent may seek location information only and must not reveal that the call concerns a debt. Configure and test this path explicitly, because it is the most common way an automated program creates a third-party disclosure problem.
It changes the shape of the risk. Variance falls, since every call carries the same approved language, and systematic risk rises, since a misconfiguration repeats on every call. The mitigation is testing before launch and reviewing calls at volume afterwards.
Run the calls your compliance team approved.
Retell is a Customer Experience AI Platform for Autonomous Customer Relations. It delivers the disclosures your compliance team approved on every call, records what was said, and transfers to a collector the moment a call needs one. Unlike managed AI vendors and BPOs, a change does not become a ticket, a queue, or another SOW, which is what makes continuous testing realistic: Canon replaced days of change requests and meetings with direct adjustments its own team makes in Retell. Across the platform, 80% of production minutes run through agents customers build and manage themselves.
Prove it on your own calls before you sign anything. Run a pilot on your own call volume.
This article is for general information only and is not legal advice. Debt collection and calling rules vary by state and change over time, so have qualified counsel review any script, disclosure, or calling program before you use it.
See how much your business could save by switching to AI-powered voice agents.
Total Human Agent Cost
AI Agent Cost
Estimated Savings
A Demo Phone Number From Retell Clinic Office

Start building smarter conversations today.


