The FCC: TCPA, STIR/SHAKEN & the RMD
The only body in the A2P stack that makes binding law. The FCC enforces the TCPA, mandates STIR/SHAKEN caller-ID authentication, and runs the Robocall Mitigation Database — and it has been the busiest it's ever been in 2024–2026.
The Federal Communications Commission is the only government regulator in the A2P stack — the one body whose rules carry the force of federal law, applied nationally and (often) effective the moment they’re published. Everything else on this site is a registry, a trade-group “best practice,” or a private carrier filter. The FCC plays three distinct roles, and 2024–2026 has been the most active stretch of FCC rulemaking and enforcement in the history of US messaging and calling.
Role 1 — Enforcing the TCPA
The FCC administers the TCPA (Telephone Consumer Protection Act, 47 U.S.C. 227), implemented through its rules at 47 CFR 64.1200. This is the federal law that governs whether an automated call or text is legal to send — consent requirements, the do-not-call regime, quiet hours, and consent revocation all live here.
Two things make TCPA enforcement different from ordinary agency rulemaking:
- The statute carries a private right of action, so most actual enforcement happens in court, brought by recipients (often as class actions) — not by the FCC. Statutory damages run $500–$1,500 per message, uncapped in aggregate, with no proof of harm required.
- FCC agency enforcement tends to land on providers, not end-businesses — through the RMD (below) and forfeitures against carriers that pass illegal traffic.
For the full law, damages, and consent standards see /regulations/tcpa/. For the texting-specific application, see TCPA basics.
The AI-voice ruling (Feb 8, 2024)
On February 8, 2024 the FCC issued a Declaratory Ruling that calls using AI-generated voices are “artificial” within the meaning of the TCPA — making them illegal in robocalls absent prior express consent. It was effective immediately. The practical effect: voice-cloning and synthetic-voice outbound campaigns sit under the same consent requirements (and the same $500–$1,500-per-call exposure) as any prerecorded robocall.
The one-to-one consent rule saga
The FCC’s 2024 one-to-one consent rule — aimed at lead-generation, requiring per-seller, topically-related consent — is the clearest example of the courts overriding the agency:
| Event | Date | Status |
|---|---|---|
| Rule vacated by the 11th Circuit (Insurance Marketing Coalition v. FCC) | Jan 24, 2025 | One business day before its Jan 27, 2025 effective date |
| Rule formally repealed by FCC final rule | Sept 2025 | Dead |
There is no federal one-to-one consent mandate today. As covered on the TCPA page, TCR and carrier rules still independently prohibit sharing/selling SMS opt-in data and buying leads for texting, so the practical bar for lead-gen SMS remains high.
Role 2 — Mandating STIR/SHAKEN
The FCC mandates STIR/SHAKEN caller-ID authentication on IP voice networks. Originating providers must cryptographically sign their calls so terminating carriers can verify the number wasn’t spoofed. The rollout was phased by provider type:
| Provider type | STIR/SHAKEN deadline |
|---|---|
| Large voice providers | June 30, 2021 |
| Non-facilities-based small voice providers | June 30, 2022 |
| Facilities-based small voice providers | June 30, 2023 |
| Gateway providers (foreign-originated traffic) | Required to authenticate |
| Non-IP / TDM portions | Continuing extension while a non-IP equivalent is developed |
New third-party caller-ID authentication obligations took effect September 18, 2025, expanding who can sign on a provider’s behalf. The brand-facing consequence of all this: you cannot sign your own calls, and the only way to earn A-level attestation is to originate from a number your provider authenticated — see STIR/SHAKEN & attestation and get A-attestation.
Role 3 — Running the Robocall Mitigation Database
The FCC operates the RMD (Robocall Mitigation Database), where every voice, intermediate, and gateway provider must file a certification of its STIR/SHAKEN status (or a robocall-mitigation plan if it hasn’t fully implemented). The RMD is the FCC’s primary enforcement lever on the voice side: a provider removed from the database forces every downstream provider to block all of its traffic.
RMD recertification (Mar 1, 2026)
The RMD now requires annual recertification, and the next deadline applies to all voice, intermediate, and gateway providers — explicitly including MVNOs:
This is a provider-side obligation, not something most brands file directly — but if you operate your own voice infrastructure, or want to confirm your carrier is covered, the robocall mitigation (RMD) page walks through it.
What’s still open
The FCC isn’t finished. Two items to watch (tracked with dates on the change tracker):
- Quiet-hours petition — the Ecommerce Innovation Alliance petitioned the FCC (March 2025) arguing that prior express written consent forecloses quiet-hours liability. Comments closed April 10, 2025; still pending as of mid-2026. See quiet hours.
- Call-branding FNPRM (Oct 28–29, 2025) — proposes tying verified caller identity and branding to A-level attestation. Proposed, not yet in force.
Next
- TCPA — the law the FCC enforces, in full.
- Robocall Mitigation (RMD) — the provider-side filing the FCC runs.
- Change tracker — every dated FCC action since 2024.