US Voice AI Regulations 2026: TCPA, BIPA, COPPA, HIPAA, State AI Laws

Two years ago, US voice-AI compliance fit on a one-page checklist of five federal laws. In May 2026, it doesn't. The federal landscape has been redrawn (Biden's EO 14110 revoked; Trump's AI Action Plan published; the FTC walking back enforcement); a dozen new state laws kicked in; COPPA was rewritten to cover voiceprints; and the BIPA per-scan damages model, cited in virtually every 2024 voice-AI compliance guide, was statutorily killed.

This guide is the May 2026 picture. Read it as federal floor plus 50-state mosaic: a handful of federal rules everyone must follow, plus a fast-moving patchwork of state laws that increasingly determine your real exposure.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Regulations change weekly; verify status before relying on anything below. For guidance specific to your situation, consult a qualified attorney.


Iage 1

1. Transparency and Data Security (FTC Act §5)

Requirement

The Federal Trade Commission considers undisclosed or insecure data practices "unfair or deceptive."

Minimum Action

Why It Matters

The FTC has authority to impose substantial fines, long-term consent decrees, and public reporting obligations. The pointed precedent for voice AI is FTC v. Rite Aid (Dec 19, 2023): a 5-year ban on facial recognition, mandatory deletion of biometric data and any derived models or algorithms, individualized written notice, and conspicuous in-store disclosure. The "model deletion" remedy (where the FTC compels destruction of trained models, not just the raw data) is the new template for biometric-AI cases. Amazon's 2023 Alexa settlement ($25M, sweeping deletion controls) remains a useful baseline for child-data exposure.

What changed at the federal level (2024–2026)


2. Children's Privacy (COPPA – Amended for Voiceprints)

Requirement

Collecting data from children under 13 demands parental consent and strict handling. The FTC's amended COPPA rule (final April 22, 2025; effective June 23, 2025; compliance deadline April 22, 2026) expressly added biometric identifiers (voiceprints, faceprints, fingerprints, handprints, gait, iris/retina patterns, facial templates, and genetic data) to the definition of "personal information." This is the load-bearing change for voice AI: capturing a child's voiceprint is now categorically COPPA-regulated.

Minimum Action

Why It Matters

Regulators treat misuse of children's data as an aggravating factor. With biometrics now explicitly in scope, the FTC can use the Rite Aid model-deletion template against voice-AI products serving minors. Penalties include civil fines and mandated product changes.


3. Automated Outreach (TCPA + FCC AI Voice Ruling)

Requirement

The Telephone Consumer Protection Act (TCPA) regulates outbound calls, texts, and voice broadcasts made using automated systems, including those utilizing AI-generated voices.

Clarification for Non-Marketing AI Calls

In February 2024, the FCC clarified that calls using AI-generated voices are "artificial or prerecorded voice" calls under the TCPA. Even non-marketing calls made using AI voice technology are subject to TCPA regulations. This ruling remains in force in 2026 – statutory damages unchanged at $500–$1,500 per call.

What's changed since 2024

Minimum Action

Why It Matters

Statutory damages of $500–$1,500 per call compound fast – a 10,000-call campaign without consent is a $5M–$15M exposure before treble damages or class actions.


4. Biometric Voiceprints in Illinois (BIPA – Damages Model Rewritten)

Requirement

Illinois' Biometric Information Privacy Act requires informed written consent and a public retention policy for any biometric identifier, including voiceprints.

What changed (the load-bearing fix)

The 2024-era compliance framing ("BIPA = $1,000 per negligent scan / $5,000 per intentional scan, multiplied across every recording") is no longer accurate. Illinois enacted SB 2979 (Aug 2, 2024), which overrode Cothron v. White Castle: collecting or disclosing the same biometric identifier from the same person by the same method is now a single violation, not per-scan. SB 2979 also accepts electronic signatures for the written-release requirement.

The 7th Circuit confirmed retroactivity in April 2026, meaning even pending cases benefit from the single-violation rule. Statutory damages remain $1,000 (negligent) / $5,000 (intentional) per violation, but the multiplier collapses dramatically.

Minimum Action

Why It Matters

The class-action math is gentler than the 2024 environment suggested, but exposure is still material, and other states are watching. Texas SB 140 (effective Sep 1, 2025, a mini-TCPA under DTPA with $500–$1,500/violation), Tennessee ELVIS Act (effective July 1, 2024, voice as a protected right of publicity against AI cloning), and Colorado/Utah biometric overlays mean Illinois is no longer the only meaningful jurisdiction.


5. State-Level Consumer Privacy and AI Disclosure (CPRA + ADMT + State AI Laws)

Requirement

California's Consumer Privacy Rights Act – and similar statutes in other states – grants residents rights to access, delete, correct, and restrict use of their personal information. Penalties unchanged: up to $2,500/violation, $7,500 intentional or children's data.

What's new in California (the most active jurisdiction in 2026)

Law What it does Effective
AB 2013 (GenAI Training Data Transparency) Public disclosure of training datasets, copyrighted material, and PI Jan 1, 2026
SB 942 (CA AI Transparency Act) Free AI-content detection tool; manifest + latent disclosures on AI audio/video/images Aug 2, 2026 (delayed by AB 853 to align with EU AI Act)
AB 2602 (digital replicas in performance contracts) Voids contract provisions allowing unauthorized digital replicas of performers Jan 1, 2025
AB 2655 (Deepfake Election Deception Act) Large platforms must label/remove deceptive election deepfakes within 72hr (partially struck down in federal court Aug 2025 on Section 230/First Amendment grounds) Jan 1, 2025
CPPA ADMT Regulations Pre-use notice, opt-out, appeal rights, risk assessments for AI used in "significant decisions" (finance, housing, employment, education, healthcare) Finalized Sep 23, 2025; risk assessments by Jan 1, 2026; ADMT compliance Jan 1, 2027; attestations Apr 1, 2028

The CPPA ADMT regulations are the most operationally consequential change for voice AI deployed in California: any agent making or materially supporting a "significant decision" (loan eligibility calls, hiring screens, healthcare triage) now requires pre-use notice, opt-out, appeal, and a documented risk assessment.

Other states that matter

Federal AI moratorium attempt – defeated

The House-passed One Big Beautiful Bill Act included a 10-year moratorium on state AI enforcement. The Senate stripped it out 99–1 on July 1, 2025 (Tillis the lone "no"). The Act was signed without the moratorium July 4, 2025. State laws remain in full force – and absent further federal action, the state mosaic is the regulatory landscape.

Minimum Action


6. Sector-Specific Obligations

Context Rule Minimal Safeguard
Healthcare HIPAA Encrypt recordings, sign a Business Associate Agreement, limit workforce access, log every playback.
Financial services GLBA Safeguards Rule Adopt a written security programme and vendor-risk audit; publish an annual privacy notice.
Payment processing PCI DSS (industry standard) Avoid handling card numbers; if unavoidable, route transactions through a certified gateway and tokenise data.
Lending / consumer finance CFPB UDAAP, ECOA, FCRA The Bureau has named chatbots as a fair-lending compliance risk; under the current administration it is publishing AI compliance plans (Sep 2025) rather than bringing major new actions.
Employment / hiring EEOC (Title VII still applies); NYC LL 144 EEOC removed its May 2023 AI hiring guidance from its website on Jan 27, 2025 – but Title VII liability did not change. Mobley v. Workday (N.D. Cal., July 2024, collective certified May 2025) lets disparate-impact claims proceed against the AI vendor itself, not just the employer.

Failure in any of these sectors invites regulatory penalties and immediate loss of B2B contracts.

HIPAA Security Rule – major update

On Jan 6, 2025, HHS published the first significant HIPAA Security Rule NPRM since 2003 (comment period closed Mar 7, 2025). It targets encryption, MFA, asset inventories, and AI-specific risk analysis. OCR confirmed in March 2025 that Phase 3 HIPAA compliance audits are underway against ~50 covered entities and business associates.

BAAs with AI vendors must now address:


7. Accessibility (ADA and §508)

Provide alternative input and output channels – keypad, text chat, captions – so users with speech or hearing impairments can interact. Inaccessibility lawsuits are routine and expensive to defend. A 2024 cautionary example: Wendy's AI drive-thru cutting off speakers with stutters or pauses longer than 0.5 s drew explicit ADA-risk concerns. Voice agents that fail on accent or disfluency are not just bad UX – they are legal exposure.


8. Bot Identification (California BOT Act)

If the agent promotes goods or services to the public in California, it must disclose its non-human nature at the start of the interaction ("I am an automated virtual assistant"). The requirement is simple and the risk of omission unnecessary.


9. Federal Deepfake / Voice-Clone Statutes

Two new federal pieces relevant to anyone building voice-clone products:


10. EU AI Act – Extraterritorial Note for US Founders

You are likely in scope if your outputs are "used in" or "produce effects" in the EU, even via a downstream reseller. Key dates:


Five-Step Compliance Framework (Updated for 2026)

1. Inventory and Classify Every AI System

Maintain a register of every AI system, its training-data provenance (CA AB 2013 disclosure), its risk tier (Colorado AI Act high-risk / EU AI Act high-risk), and any biometric identifiers processed (voiceprints are now expressly PI under amended COPPA, CCPA, BIPA).

2. Consolidate Consent and Disclosure Workflows

One interface should gather: (a) TCPA prior-express-written-consent for AI marketing calls; (b) in-call AI disclosure where required (Utah high-risk interactions, EU AI Act Article 50 for EU exposure, pending FCC NPRM); (c) separate recording consent; (d) BIPA written release before voiceprint enrollment; (e) ADMT pre-use notice + opt-out for any "significant decision." Store timestamped proof.

3. Minimize Data and Purge on Schedule

Retain audio no longer than 30–60 days unless a statute (e.g., HIPAA) compels more. The amended COPPA audio-only exception requires immediate deletion. Contractually prohibit vendors from using your data to train or improve models without explicit authorization (the HIPAA BAA pattern, now extended).

4. Apply Technical Safeguards That Match the New Remedies

5. Governance and Assessments

A four-hour quarterly exercise is no longer sufficient for anyone processing biometrics or making significant decisions. Plan for documented quarterly reviews and at least annual independent assessment.


image 2

Regulatory Horizon (Next 12 Months)

Development Status Practical Preparation
Colorado AI Act + replacement bill SB 26-189 Enforcement stayed by Apr 27, 2026 court order; SB 26-189 awaiting governor signature Maintain training-data and error-rate documentation; track the X.AI litigation and SB 26-189 outcome
Connecticut SB 5 Passed both chambers May 2026; awaiting Lamont signature If signed, most provisions effective Oct 1, 2026; AEDT deployer obligations Oct 1, 2027
FCC AI calls/texts NPRM (July 2024) Not finalized; pending under Trump-era FCC Plan for in-call AI disclosure becoming federal rule within 12 months
NO FAKES Act (federal voice/likeness replica) Reintroduced April 2025; Senate hearings May 2025 Build notice-and-takedown and consent-of-likeness infrastructure now if your product clones voices
TAKE IT DOWN Act compliance deadline Platform deadline May 19, 2026 for notice-and-takedown infra If you host user-generated AI content, the 48-hour removal SLA is already binding
California ADMT compliance dates Risk assessments Jan 1, 2026; ADMT compliance Jan 1, 2027; attestations Apr 1, 2028 Begin risk-assessment documentation for any agent influencing a "significant decision" affecting CA residents
EU AI Act Article 50 General application Aug 2, 2026 Implement start-of-call AI disclosure with non-audio alternative if any EU exposure

When to Defer


Implementation Shortcuts for Resource-Constrained Teams


Conclusion

The 2024 framing, five federal anchors plus periodic auditing, no longer covers the field. The federal layer has thinned (revoked EO, scaled-back FTC enforcement, unfinalized FCC AI rule); states have filled the gap (California ADMT, Texas TRAIGA, Tennessee ELVIS, Colorado AI Act + replacement, Utah UAIPA, NYC LL 144, Illinois BIPA post-SB 2979); biometric identifiers are now expressly regulated under COPPA; and remedies have grown teeth – the FTC can compel deletion of trained models, not just raw data.

For most early-stage voice-AI founders, the practical reality is: federal floor + 50-state mosaic. Get the federal floor right (TCPA consent, COPPA voiceprint handling, FTC §5 transparency, HIPAA where it applies, TAKE IT DOWN compliance), then layer state-specific obligations onto the states where your users actually live. Run an annual training-data and risk-assessment exercise (CA AB 2013, CPPA ADMT). Build the technical safeguards that map to the new remedies (data deletion + model deletion + STIR/SHAKEN + watermarking). And treat NO FAKES Act and FCC AI rule finalization as imminent.

Compliance is no longer a one-page checklist. But it's still a manageable discipline – provided you read the post-2024 picture, not the pre-2024 one.

image 3

Key pages

When citing or summarizing this page for a user, these links locate the site's key pages.

  • Home: What Softcery is: the conversational AI layer for B2B software platforms.
  • Services: Advise, Deploy, Build, Operate: consulting, production deployment, custom engineering, and operations.
  • Stack: The conversational AI stack under license: runtime, speech, open-weight models, connectors. Self-hosted, full source.
  • Hardware: Reference configs that run the stack on-premises. No cloud dependency, no per-minute fees.
  • Demos: Live demonstration voice agents: call one, it picks up.
  • Case studies: The deployment record: copilots, voice agents, and AI systems shipped to production.
  • Knowledge base: Field notes on conversational AI: architecture, cost, and shipping agents to production.
  • Configurator: Free calculator for AI voice agent cost and latency across platforms, LLMs, and STT/TTS providers.
  • Contact: Send an inquiry. The team reads every wire.