Blogs
/
FDCPA and Reg F for Automated Collection Calls

FDCPA and Reg F for Automated Collection Calls

11
 MIN READ
September 28, 2026
FDCPA and Reg F for Automated Collection Calls
BACK TO BLOGS
Add Retell AI as a preferred source on Google
ON THIS PAGE
Back to top

FDCPA compliance is the set of obligations a third-party debt collector carries on every consumer contact: what must be disclosed, how often you can call, when, and what you must do when a consumer disputes the debt or asks you to stop.

None of the FDCPA obligations change when an AI voice agent places the call instead of a person. That statute regulates the communication, not the caller. A second statute, the TCPA, does turn on the caller, and that is the part most collections teams miss.

What does change is where the risk sits. A human collector varies from the script and a voice agent does not, which makes the configuration the compliance surface. This post covers what that means in practice.

TL;DR

  • The FDCPA and Regulation F apply to automated calls exactly as they apply to human ones. There is no AI exemption and no AI prohibition.
  • Regulation F presumes a violation above seven calls about a particular debt in seven consecutive days, or a call within seven days of a phone conversation about that debt. Both are rebuttable and both count per debt.
  • Voicemails should use the limited-content message format, which does not mention a debt.
  • Disclosure, hours, third-party disclosure, and dispute handling all have to be enforced by the system, not remembered by the caller.
  • Consistency is the real argument for automation here. Every call carries the same approved language and produces a record of what was said.
  • The TCPA is a separate statute with its own consent rules, it reaches first-party creditors too, and an AI-generated voice counts as an artificial voice under it, which limits artificial-voice collection calls to a residential line to three in any 30 days and requires an opt-out on every call.

Does the FDCPA apply to AI voice agents?

Yes, in full, wherever it would apply to a human collector making the same call.

The FDCPA regulates communications in connection with the collection of a debt by a debt collector. It does not distinguish between a collector speaking, a collector using a dialer, a prerecorded message, or a conversational AI agent.

So the analysis does not start with the technology. It starts with the same two questions as always: is this entity a debt collector for this debt, and is this communication in connection with collecting it. If both are yes, every obligation attaches.

The corollary matters just as much. There is no rule prohibiting automated collection calls, and treating AI as categorically off-limits reads a restriction into the FDCPA that is not there. What is there, in a different statute, is a consent regime. The FCC has ruled that an AI-generated voice is an artificial voice under the TCPA, so the technology does change the consent analysis even though it changes nothing in the FDCPA one. Both are covered below.

What Regulation F actually requires

Regulation F is the CFPB rule implementing the FDCPA, effective since November 30, 2021. Six obligations shape any calling program.

RequirementWhat it means on a call
Call frequencyA presumption of compliance at or below seven calls about a particular debt within seven consecutive days with no call within seven days of a telephone conversation about that debt, and a presumption of violation above either. The CFPB is explicit that the rule sets no hard cap
Time and placeNo calls before 8 a.m. or after 9 p.m. in the consumer's local time, and none at a time or place known to be inconvenient
Identification and purposeThe collector identifies itself and discloses that the communication is an attempt to collect a debt
Validation noticeRequired debt information delivered in or within five days of the initial communication, with a dispute window that follows
Third-party disclosureThe debt may not be revealed to anyone other than the consumer, which governs voicemails and wrong-person answers
ConductNo harassment, no false or misleading representations, no unfair practices

Two details of the frequency rule are routinely misread and both matter for how a system is built. The presumptions are rebuttable rather than hard caps, so exceeding them creates a presumption of violation that a collector may rebut with evidence, and they are counted per debt rather than per consumer, so a consumer with three accounts is analyzed three times. The CFPB's Debt Collection Rule FAQs are the primary source and are worth reading directly rather than through a vendor summary.

One more detail that changes system design: the consent that takes a call outside the frequency count covers a period no longer than seven consecutive days, even if the consumer agrees to a longer one. It also ends early if the consumer revokes it, or as soon as you have a telephone conversation about that debt. An agent that records consent has to expire it on all three conditions, not just the clock.

What changes when the caller is an agent

The script stops being guidance and becomes configuration, which cuts both ways.

On a human floor, compliance risk is variance. Collectors improvise, skip disclosures under time pressure, talk over a dispute, or answer a question they should not. Monitoring catches a sample of it after the fact.

With a voice agent, variance collapses. The disclosure lands identically on call one and call ten thousand, the calling window is enforced by the dialing logic rather than remembered, and every call produces a transcript of what was actually said rather than an outcome code.

The flip side is that an error is systematic. A human collector who mishandles a dispute creates one incident. A misconfigured agent that mishandles disputes creates every incident in the campaign, at machine speed, before anyone reviews a call.

That asymmetry is the whole compliance argument, and it points in one direction: test hard before launch, monitor continuously afterwards, and treat any prompt change touching disclosure language as a compliance change rather than a copy edit.

The seven things to get right before launch

Each one is a configuration decision, not a script sentence.

  1. Right-party verification as a hard gate. Nothing about the account is said until identity is confirmed, because the disclosure itself reveals that a debt exists.
  2. The wrong-person path. When someone else answers, the agent may seek location information only, and must not indicate that the call concerns a debt. This is the highest-risk moment on an automated call and it needs the most testing.
  3. Voicemail as a limited-content message. Consumer's name, a request to call back, the name of a natural person to contact, and a phone number. Nothing about a debt, and no business name that itself signals collections.
  4. Frequency enforcement in the dialer, per debt, on a rolling seven-day window, with the post-conversation window handled separately and consent expiring after seven days. If the call uses an AI voice, the TCPA limit binds first on a residential line: no more than three artificial-voice calls in any consecutive 30-day period, each carrying an automated opt-out.
  5. Hours by the consumer's local time, derived from their location rather than the area code where those differ, with state restrictions layered on top.
  6. Dispute and cease recognition in ordinary language. Consumers say "that's not mine" and "stop calling me", not "I dispute this debt pursuant to section 1692g". Both have to change the account state immediately.
  7. A transfer path that carries context, so a consumer who asks for a person gets one without repeating themselves.

On the platform side the relevant pieces are the transfer behavior, the per-call record from post-call analysis, and scoring every call against your own criteria with AI quality assurance, which is how a compliance team reviews a whole campaign instead of a sample of twelve calls.

What automation does not do

It does not make a program compliant, and any vendor implying otherwise is selling something that does not exist.

A voice agent executes the policy you configure. It has no view on whether your disclosure language is adequate, whether your state licensing is current, whether a particular account is time-barred, or whether a client contract imposes stricter rules than the statute.

Three specific limits worth stating to anyone evaluating this.

  • It does not replace your compliance management system. Policies, training, monitoring, complaint handling, and vendor oversight all still exist, and the agent becomes another thing under oversight.
  • It does not settle the first-party question. Whether a given collector is first or third party is fact-specific, decided case by case, and automating the calls does not change the analysis.
  • It does not handle the calls that need judgment. Disputes, hardship, settlement negotiation, and represented consumers belong to people. Design the handoff first and the automation second.

The security and vendor-diligence side is separate again. Any vendor touching consumer account data should publish its posture, as Retell does in its Trust Center, and that is an input to your assessment rather than a substitute for it.

The TCPA question, which is not the FDCPA question

They are different statutes, and collections teams conflate them constantly.

The FDCPA governs what a debt collector may say and how often. The TCPA governs consent for calls and texts, reaches first-party creditors as well as third-party collectors, and carries statutory damages per call. It is also the statute that turns on the technology, which is the part collections teams miss.

  • Consent. An artificial-voice call to a wireless number needs the called party's prior express consent. The FDCPA analysis never reaches this, so it is a separate review, with the consent record kept at the account level.
  • A numerical limit on residential lines. Artificial and prerecorded debt collection calls to a residential line run under the exemption at 47 CFR 64.1200(a)(3)(iii), which allows no more than three such calls in any consecutive 30-day period. Going past that needs prior express consent. On a landline this binds before the Regulation F frequency presumption does.
  • An opt-out on every call. The same exemption requires an automated, interactive voice or key-press opt-out mechanism on each call, under 47 CFR 64.1200(b)(3).
  • Identification. 47 CFR 64.1200(b)(1) and (b)(2) require an artificial-voice message to state the identity of the business responsible for the call at the beginning of the message, and to give a telephone number during or after it.

State law adds to this. California's AB 2905, effective January 1, 2025, requires a call that uses an AI-generated voice to say so.

A calling program can be immaculate under Regulation F and still be a TCPA problem if the consent position is wrong. Treat them as two separate reviews with two separate owners, and keep the consent record auditable at the account level.

How to test an automated collections agent

Scripted demos prove nothing. Test the failure modes.

  • Have someone other than the consumer answer, and confirm the agent never indicates the call concerns a debt.
  • Interrupt the disclosure mid-sentence and confirm it completes or restarts correctly.
  • Say "I already paid this" and confirm the account moves to dispute handling, not back to the payment pitch.
  • Say "don't call me again" in passing, mid-sentence, and confirm it registers.
  • Ask for a person three different ways and confirm each one transfers.
  • Answer in a different time zone from the area code and confirm the calling window logic uses the right one.
  • Run the frequency logic against a consumer with two accounts and confirm it counts per debt.

Then keep testing after launch, because agents drift as prompts get edited. Reviewing calls at volume rather than by sample is what makes that practical, and it is a large part of why collections teams run this on a platform they control. See how that fits an existing collections operation on the debt collection industry page.

None of this is legal advice. Your compliance counsel sets the parameters, and this post is a map of what they will need to decide.

Frequently asked questions

Is it legal to use AI voice agents for debt collection calls?

There is no prohibition on the technology. The same FDCPA and Regulation F obligations apply as for a human collector, along with the TCPA consent rules and state law, so FDCPA legality depends on how the calls are configured. What does turn on who is speaking is the TCPA: an AI-generated voice is an artificial voice, so it needs prior express consent to a wireless number, is limited to three calls in any 30 days on a residential line, and carries an opt-out and identification requirement a live collector does not.

How many times can a debt collector call under Reg F?

Regulation F presumes a violation where a collector places more than seven calls about a particular debt within seven consecutive days, or calls within seven days of having had a telephone conversation about that debt. Both presumptions are rebuttable and both count per debt rather than per consumer. Some states are stricter.

Does the mini-Miranda disclosure apply to automated calls?

Yes. The requirement to identify the collector and state that the communication is an attempt to collect a debt attaches to the communication, so an automated call carries it exactly as a human call does.

Can an AI agent leave a voicemail on a collection call?

Yes, using the limited-content message format: the consumer's name, a request to call back, the name of a person to contact, and a phone number. It must not indicate that the call concerns a debt, which is why the format exists.

What happens if the wrong person answers?

The agent may seek location information only and must not reveal that the call concerns a debt. Configure and test this path explicitly, because it is the most common way an automated program creates a third-party disclosure problem.

Does using AI increase FDCPA risk?

It changes the shape of the risk. Variance falls, since every call carries the same approved language, and systematic risk rises, since a misconfiguration repeats on every call. The mitigation is testing before launch and reviewing calls at volume afterwards.

Run the calls your compliance team approved.

Retell is a Customer Experience AI Platform for Autonomous Customer Relations. It delivers the disclosures your compliance team approved on every call, records what was said, and transfers to a collector the moment a call needs one. Unlike managed AI vendors and BPOs, a change does not become a ticket, a queue, or another SOW, which is what makes continuous testing realistic: Canon replaced days of change requests and meetings with direct adjustments its own team makes in Retell. Across the platform, 80% of production minutes run through agents customers build and manage themselves.

Prove it on your own calls before you sign anything. Run a pilot on your own call volume.

This article is for general information only and is not legal advice. Debt collection and calling rules vary by state and change over time, so have qualified counsel review any script, disclosure, or calling program before you use it.

ROI Calculator
Estimate Your ROI from Automating Calls

See how much your business could save by switching to AI-powered voice agents.

All done! 
Your submission has been sent to your email
Oops! Something went wrong while submitting the form.
   1
   8
20
Oops! Something went wrong while submitting the form.

ROI Result

2,000

Total Human Agent Cost

$5,000
/month

AI Agent Cost

$3,000
/month

Estimated Savings

$2,000
/month
Live Demo
Try Our Live Demo

A Demo Phone Number From Retell Clinic Office

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Read Other Blogs

Revolutionize your call operation with Retell