What Is Automated Debt Collection Calling Under the FDCPA? The 2026 Definition

Ubicloud Postgres - why I'm paying attention to this (deep dive)

10 min read

See what counts as automated debt collection calling under the FDCPA and TCPA, the consent rules that apply, and tools that keep AI dialers compliant.

Picture a compliance officer opening Monday's audit report to find the bank's new AI dialer placed forty thousand calls to numbers where consent had already been revoked. One configuration error, forty thousand potential lawsuits.

That's the reality of automated debt collection in 2026. The Supreme Court narrowed what counts as an "autodialer," the FCC pulled AI voice clones into decades-old call restrictions, and the CFPB wrote hard numerical caps into Regulation F.

This guide breaks down what actually makes a call "automated" under the FDCPA, TCPA, and Regulation F, where the real gray zones sit, and what a compliant calling operation looks like right now. If you're already comparing vendors, the roundup of AI calling tools built specifically for FDCPA-compliant debt collection is a useful next stop.

Key Takeaways

  • An automated debt collection call uses an ATDS or an artificial/prerecorded voice, including an AI-generated voice, to collect a consumer debt.

  • Facebook v. Duguid (2021) narrowed the ATDS definition to systems using a random or sequential number generator; Trim v. Reward Zone (2023) kept that narrow reading intact rather than reopening it.

  • Regulation F's 7-in-7 rule and the FTC's 3% abandonment cap are hard limits, not guidelines. A single violation triggers $500 to $1,500 in statutory damages, with no aggregate cap.

  • Real-time consent checks, DNC scrubbing, and immutable audit trails are what separate a compliant platform from one that finds out about its violations after a regulator does.

What Is an Automated Debt Collection Call Under the FDCPA and TCPA?

An automated debt collection call is any call placed with an Automatic Telephone Dialing System (ATDS) or an artificial or prerecorded voice, made for the purpose of collecting a consumer debt covered by the Fair Debt Collection Practices Act. The FDCPA sets who counts as a debt collector and what conduct is off-limits. The TCPA sets which technology triggers extra rules. Here is how the two statutes fit together.

  • FDCPA scope. A debt collector is anyone whose main business is collecting debts, or who regularly collects debts owed to someone else. The law only covers consumer debt taken on for personal, family, or household reasons, not business or agricultural debt.

  • TCPA trigger. The TCPA restricts calls made with an ATDS or an artificial/prerecorded voice, without consent. Under a 2024 FCC ruling, an AI-generated voice counts as an "artificial" voice under the statute, the same as a recorded human voice would.

  • Artificial and prerecorded voice calls. Any message delivered through voice cloning, text-to-speech, or a prerecorded playback falls under this rule, whether or not the dialing system itself is an ATDS. Consent for these calls is judged separately from ATDS consent.

  • Where AI voice agents sit. A modern voice agent can trip both wires at once: the system dialing the number and the voice delivering the message. A platform built for collections has to satisfy both requirements on every single call.

How Did Facebook v. Duguid Redefine the Autodialer?

Facebook v. Duguid narrowed the autodialer definition to systems that use a random or sequential number generator to store or produce the numbers they call, cutting most curated-list dialers out of ATDS status entirely. Before 2021, almost any system that could dial automatically risked being called an ATDS. Here's how that narrower reading has held up since:

  • Trim v. Reward Zone USA LLC (9th Cir., 2023): the court had a chance to reopen that door and didn't. Following its own 2022 decision in Borden v. eFinancial, it held that a system isn't an ATDS unless the generator produces the phone numbers themselves, not just stores numbers pulled from elsewhere. The plaintiff's ATDS claim failed on that basis.

  • Supreme Court review denied (January 2024): the plaintiff asked the Court to resolve the conflict with other circuits' readings. The Court declined, leaving the narrow reading intact in the Ninth Circuit.

  • The picture isn't uniform everywhere: other circuits, including the Third Circuit in a related case, have hinted at a broader reading where storing numbers (not just producing them) via a random or sequential process could still trigger ATDS status.

That live split is why a cautious compliance program treats any automated dialer as a potential ATDS for consent purposes, rather than betting the operation on the friendliest circuit's reading holding up everywhere it operates.

When Is an Automated Debt Collection Call Legally Permitted?

An automated call is legally permitted only when the collector holds prior express consent, and in some cases prior express written consent, for that specific number and call type. What counts as consent depends on the technology and the number being dialed:

  • Standard prior express consent: required for any call to a cell phone made with an ATDS or an artificial/prerecorded voice. If a lender collected the number during the original application for servicing purposes, courts often treat that as sufficient consent for non-marketing collection calls.

  • Prior express written consent: needed when a call mixes in an advertisement or telemarketing message alongside the collection attempt. This requires a signed agreement with specific disclosures about automated calling.

  • What doesn't count: generic "we may call you" language buried in a privacy policy.

  • Revocation is absolute: a consumer can revoke consent at any time, through any reasonable method (verbally, by text, or through a web portal). Once revoked, the dialing system has to stop calling that number immediately. A system that accepts a revocation at 10:05 a.m. but dials the same number at 10:07 a.m. has already failed.

  • The DNC Registry's reach is narrower than it looks: it technically governs telemarketing and sales calls, not routine debt collection, so it doesn't automatically block collectors from calling. More than 258 million numbers were on the Registry as of September 30, 2025, and most well-run collections operations still screen against it alongside their own internal do-not-call and cease-and-desist lists, since a single number can carry both a servicing relationship and an unrelated sales flag.

The same real-time discipline has to carry across every channel, not just voice, which is why compliant automation across voice, email, and SMS is usually evaluated as one connected system rather than three separate tools.

What Does Regulation F Require From Automated Debt Collection Calls?

The CFPB's Regulation F turns the FDCPA's broad prohibitions into specific numbers.

  • The 7-in-7 rule: Section 1006.14(b) creates a rebuttable presumption that calling a consumer more than seven times in seven days about one debt counts as harassment. Every automated dialing system needs to enforce this cap per consumer and block extra attempts once it's hit.

  • Limited-content messages: A voicemail that meets Section 1006.2(j)'s content rules isn't treated as a full "communication" requiring extra disclosures, but it still counts as a contact attempt and still gets tallied against the 7-in-7 limit.

  • Record retention: Under 12 C.F.R. § 1006.100, debt collectors must keep records showing compliance, including call recordings, for three years after their last collection activity on the debt.

AI voice agents raise the stakes here because TCPA liability is strict. There's no "we didn't mean to" defense. A campaign that dials the wrong time zone, an agent that skips the required debt-collector disclosure, or a model that hallucinates a settlement offer all trigger statutory damages per call.

A platform built for 2026 needs to enforce, at minimum:

  1. Real-time consent verification: Before every dial, the system checks a live consent record for that number and call type.

  2. Automated time-of-day scrubbing: No call connects outside the consumer's permitted local calling window.

  3. Call abandonment rate enforcement: Under the FTC's Telemarketing Sales Rule and matching FCC rules, no more than 3% of calls answered by a live person can go unconnected to an agent within two seconds, measured per campaign over a rolling 30-day period. This is a hard regulatory ceiling, not a target to approach.

Catching a problem in the moment usually comes down to watching the conversation itself, which is where real-time behavior analysis during a collection call earns its keep alongside the dialer-level controls above.

What Happens When a Single Automated Call Breaks the Rules?

A single automated call that breaks the TCPA triggers $500 to $1,500 in statutory damages on its own, with no cap on total exposure, and class actions turn one configuration error into a portfolio-wide liability event.

Here's how that exposure actually stacks up:

  • Class actions scale it fast: one plaintiff who proves consent was revoked but the dialer wasn't updated can certify a class covering every consumer who got the same call over months or years. Because the penalty is set by statute, total liability comes down to arithmetic, not a judge's discretion.

  • Regulators aren't sitting this out: in a case resolved in September 2025, Citizens Disability, LLC and its subsidiary agreed to pay a $1 million penalty to resolve FTC allegations tied to more than 109 million telemarketing calls, over 25 million of them to numbers on the Do Not Call Registry, under the Telemarketing Sales Rule and the FTC Act. It's a telemarketing case rather than a debt collection case specifically, but the same enforcement math applies to a debt collector running comparable call volume.

  • The evidence trail is the only real defense: a platform running automated collection calls needs an immutable, per-call audit trail capturing consent status at the moment of dial, the disclosures delivered, the call's outcome, and any revocation raised mid-call. Without it, there's no defense once a regulator or plaintiff's attorney comes asking.

What Makes a Debt Collection Platform Compliant by Design?

A platform is compliant by design when it enforces four things at the moment of action rather than reviewing them afterward: real-time consent checks, automated DNC and time-of-day scrubbing, abandonment-rate limits, and immutable audit trails. Auditing calls after they happen is a 2019 approach, and a platform that only catches violations after the fact has already lost the argument.

Here's what each control does and which rule it maps to:

Feature

Regulatory Basis

What It Actually Does

Real-time consent verification

TCPA prior express consent; 2024 FCC ruling on AI voices

Checks a live consent ledger before every dial and blocks the call if consent is missing or revoked

Automated time-of-day and DNC scrubbing

FDCPA harassment rules; internal and federal DNC lists

Enforces permitted calling windows and screens against suppression lists automatically, per number

Call abandonment rate enforcement

FTC Telemarketing Sales Rule; 47 C.F.R. § 64.1200(a)(7)

Tracks connected vs. placed calls per campaign in real time and halts dialing before the 3% threshold is crossed

Immutable audit trails

Regulation F recordkeeping, § 1006.100

Captures consent status, disclosures, disposition, and any revocation for every call, retained for the required period

The goal is to make compliance the default outcome rather than something a team has to remember to check. That means a voice agent that stays on script, escalates when it should, and has been stress-tested against FDCPA and TCPA boundaries before it ever speaks to a real consumer.

5 Tools That Help Businesses Run Compliant Automated Debt Collection Calls

Buying the right platform comes down to four things that actually predict whether a vendor keeps you out of trouble: how it handles consent in real time, how many channels it covers, what it's actually certified against, and how it gets deployed.

Here's how five options compare on those points before you dig into their differentiators.

Tool

Real-Time Consent Tracking

Channel Coverage

Compliance Certification

Deployment Model

Domu

Yes, tracked at the interaction level

Voice, SMS, email

SOC 2 Type II, CFPB, TCPA, PCI, HIPAA

Cloud SaaS

Skit.ai

Yes, compliance-first architecture

Voice (primary), SMS, email, web chat

Reg F, FDCPA, HIPAA, TCPA, PCI-DSS

Cloud SaaS

Prodigal

Partial, via agent-assist scoring

Voice, email, SMS (via proAgent suite)

TCPA/FDCPA/UDAAP monitoring, not full autonomous compliance

Cloud SaaS

TrueAccord

Yes, on digital channels

Email, SMS, voicemail drops, self-service portal

Code-based FDCPA compliance; limited live voice automation

Cloud SaaS

Convoso

No native consent ledger; manual/compliance-mode dialing only

Voice only

TCPA-focused dialer controls (DNC scrubbing, STIR/SHAKEN); not collections-specific

Cloud SaaS

1. Domu

Screenshot 2026-09-21 091647.png

Source

Domu is a compliance-first platform built specifically for regulated servicing, coordinating voice, SMS, and email through a single AI agent that carries context across every channel. Instead of treating compliance as a report generated after the fact, Domu checks and enforces it at the moment each interaction happens.

  • Automates FDCPA disclosure delivery on every call and tracks TCPA consent in real time at the interaction level, not through a nightly batch job.

  • Certifies conversation scripts against federal and state boundaries before an agent ever goes live, then audits every completed call against those same rules.

  • Holds SOC 2 Type II certification and is built around CFPB, TCPA, PCI, and HIPAA requirements, with an exam-ready evidence trail for every call.

Best for: banks, lenders, and insurers that need one system covering voice, text, and email with compliance enforced at the point of every interaction, not reconstructed after the fact.

2. Skit.ai

Screenshot 2026-09-21 091741.png

Source

Skit.ai runs a voice-first Digital Collection Agent built to handle the entire collections conversation, from early reminders through late-stage payment negotiation, across voice and several digital channels.

  • Built specifically around Reg F, FDCPA, HIPAA, TCPA, and PCI-DSS requirements, with compliance updates pushed as regulations change.

  • Can go live in under 48 hours with minimal configuration, which suits teams that need a fast, narrowly-scoped voice deployment.

  • Prices on a performance basis in some engagements, tying cost to results rather than a flat license fee.

Best for: collection agencies and lenders that want a proven, high-volume voice-first deployment without building an omnichannel program from scratch.

3. Prodigal

Screenshot 2026-09-21 091933.png

Source

Prodigal positions itself as an intelligence layer over your existing collections operation rather than a pure calling agent, combining a natural-language AI agent (proAgent) with scoring and analytics tools trained on hundreds of millions of consumer finance conversations.

  • Blends fully autonomous outreach with agent-assist modes, so live collectors get real-time coaching and compliance flags during the call itself.

  • Surfaces FDCPA, TCPA, and UDAAP non-compliance risk across a portfolio in aggregate, which helps compliance teams spot patterns rather than only single-call issues.

  • Covers voice, email, and SMS from one intelligence layer, but leans more on scoring and monitoring than on being the primary autonomous dialer.

Best for: teams that already run live agents and want an intelligence and coaching layer on top, rather than replacing the calling operation outright.

4. TrueAccord

Screenshot 2026-09-21 092035.png

Source

TrueAccord is a digital-first collections platform that leans heavily on email, SMS, and voicemail drops rather than live conversational voice AI, built around a machine-learning engine that personalizes the outreach sequence for each consumer.

  • Uses a patented model (HeartBeat) to tailor message timing and channel to each consumer's past response behavior.

  • Builds FDCPA compliance into the code path itself, rather than layering rules on top of a general messaging platform.

  • Covers self-service payment options for consumers across digital channels, which reduces the volume of live or automated calls needed in the first place.

Best for: lenders and fintechs whose delinquency population responds better to digital-first outreach than to phone calls, with voice as a secondary channel.

5. Convoso

Screenshot 2026-09-21 092143.png

Source

Convoso is a contact-center dialer platform built for outbound sales and lead generation, with compliance controls (DNC scrubbing, STIR/SHAKEN attestation, manual and compliance-mode dialing) layered on top of general-purpose dialer infrastructure rather than a collections-specific rules engine.

  • Offers a Click-to-Comply manual dialing mode that requires an agent to initiate every call, which sidesteps ATDS classification entirely for higher-risk lead types.

  • Runs real-time DNC scrubbing against federal, state, and internal suppression lists before every dial attempt.

  • Signs outbound calls under STIR/SHAKEN to improve caller ID trust and answer rates, though this addresses call authentication rather than FDCPA-specific disclosure requirements.

Best for: collections operations that already have a compliance and script framework built in-house and need dialer infrastructure to run it on, rather than a fully managed compliance layer.

Conclusion

The platforms compared above solve the technology half of the problem. The harder half is that compliance obligations under the FDCPA and TCPA sit with the collector or creditor initiating the call, not with whichever vendor built the dialer.

No platform, however well certified, transfers that liability off your books. Treat vendor compliance claims as a starting point for your own due diligence, not a substitute for it, and revisit that due diligence every time a regulator issues a new ruling, because the rules here have changed at least three times in the past five years and show no sign of settling down.

If your current program is already compliant on paper but still underperforming, the gap is often operational rather than legal. It's worth reading up on why some debt collection calls see such low engagement before assuming the fix is a new vendor, and comparing notes against how voice AI performs for regulated lenders specifically, since the compliance bar and the results bar are two different problems that happen to share a dialer.

Frequently Asked Questions

What makes a debt collection call 'automated' under the FDCPA and TCPA?

A call is automated under the combined framework if it uses an Automatic Telephone Dialing System (ATDS) that employs a random or sequential number generator to store or produce numbers, or if it delivers an artificial or prerecorded voice message. AI voice clones are artificial voices under the TCPA.

Does the Supreme Court's Facebook v. Duguid ruling mean my predictive dialer is safe from TCPA lawsuits?

Not definitively. Duguid requires the dialer to use a random or sequential number generator to qualify as an ATDS. Many list-based predictive dialers fall outside this definition, but the Ninth Circuit's Trim v. Reward Zone decision left open the question of whether the generator must produce the numbers itself, keeping list-based systems in a litigation gray zone.

What consent do I need before making an AI voice debt collection call to a cell phone?

Prior express consent is required at minimum, and generic 'we may call you' language is insufficient. If the call contains advertising or telemarketing, prior express written consent is required. Consent can be revoked at any time through any reasonable means, and the platform must honor that revocation in real time.

What is the 7-in-7 rule under the CFPB's Regulation F?

Section 1006.14(b) of Regulation F creates a rebuttable presumption that calling a consumer more than seven times in a seven-day period about a specific debt constitutes harassment. Automated dialing systems must enforce this per-consumer cap directly and count limited-content messages against the total.

What damages can a single unlawful automated collection call trigger?

TCPA statutory damages are $500 per negligent violation and up to $1,500 per willful violation. There is no aggregate cap, so a single misconfigured campaign can generate class-action exposure in the hundreds of millions of dollars for a systemic error like dialing consumers who have revoked consent.

What platform features are mandatory for compliant automated collection calling in 2026?

Real-time consent verification against a central ledger, automated DNC and time-of-day scrubbing, programmatic call abandonment rate enforcement, and immutable per-call audit trails that capture disclosures and call disposition are all key. Post-call auditing cannot catch a violation before it triggers liability.

Sources

  1. FDCPA - Interagency Consumer Laws & Regulations - files.consumerfinance.gov

  2. Do Not Call | Federal Trade Commission - search.ftc.gov

  3. VII-3 Fair Debt Collection Practices Act | FDIC.gov - www.fdic.gov

  4. Interagency Consumer Laws and Regulations FDCPA - www.federalreserve.gov

  5. All versions of 12 CFR Part 1026 (Regulation Z) | Consumer Financial Protection Bureau - www.cfpb.gov

  6. Federal Communications Commission FCC 24-17 Before the Federal Communications Commission Washington, D.C. 20554 In the Matter of ) ) Implications - docs.fcc.gov

Related Articles

Silhouette map of Europe in white on a black background.
Silhouette map of Europe in white on a black background.
Silhouette map of Europe in white on a black background.
Silhouette map of Europe in white on a black background.

We’re building the next generation of engagement technology: intelligent, automated and compliant. Our mission is to empower financial institutions to orchestrate every stage of the servicing lifecycle with dignity and unprecedented efficiency.

Copyright © 2026 Domu Technology, Inc. All rights reserved.