Reference

The FCC: TCPA, STIR/SHAKEN & the RMD

The only body in the A2P stack that makes binding law. The FCC enforces the TCPA, mandates STIR/SHAKEN caller-ID authentication, and runs the Robocall Mitigation Database — and it has been the busiest it's ever been in 2024–2026.

reference Last verified mid-2026 5 min read

The Federal Communications Commission is the only government regulator in the A2P stack — the one body whose rules carry the force of federal law, applied nationally and (often) effective the moment they’re published. Everything else on this site is a registry, a trade-group “best practice,” or a private carrier filter. The FCC plays three distinct roles, and 2024–2026 has been the most active stretch of FCC rulemaking and enforcement in the history of US messaging and calling.

Role 1 — Enforcing the TCPA

The FCC administers the TCPA (Telephone Consumer Protection Act, 47 U.S.C. 227), implemented through its rules at 47 CFR 64.1200. This is the federal law that governs whether an automated call or text is legal to send — consent requirements, the do-not-call regime, quiet hours, and consent revocation all live here.

Two things make TCPA enforcement different from ordinary agency rulemaking:

  • The statute carries a private right of action, so most actual enforcement happens in court, brought by recipients (often as class actions) — not by the FCC. Statutory damages run $500–$1,500 per message, uncapped in aggregate, with no proof of harm required.
  • FCC agency enforcement tends to land on providers, not end-businesses — through the RMD (below) and forfeitures against carriers that pass illegal traffic.

For the full law, damages, and consent standards see /regulations/tcpa/. For the texting-specific application, see TCPA basics.

The AI-voice ruling (Feb 8, 2024)

On February 8, 2024 the FCC issued a Declaratory Ruling that calls using AI-generated voices are “artificial” within the meaning of the TCPA — making them illegal in robocalls absent prior express consent. It was effective immediately. The practical effect: voice-cloning and synthetic-voice outbound campaigns sit under the same consent requirements (and the same $500–$1,500-per-call exposure) as any prerecorded robocall.

The FCC’s 2024 one-to-one consent rule — aimed at lead-generation, requiring per-seller, topically-related consent — is the clearest example of the courts overriding the agency:

EventDateStatus
Rule vacated by the 11th Circuit (Insurance Marketing Coalition v. FCC)Jan 24, 2025One business day before its Jan 27, 2025 effective date
Rule formally repealed by FCC final ruleSept 2025Dead

There is no federal one-to-one consent mandate today. As covered on the TCPA page, TCR and carrier rules still independently prohibit sharing/selling SMS opt-in data and buying leads for texting, so the practical bar for lead-gen SMS remains high.

Role 2 — Mandating STIR/SHAKEN

The FCC mandates STIR/SHAKEN caller-ID authentication on IP voice networks. Originating providers must cryptographically sign their calls so terminating carriers can verify the number wasn’t spoofed. The rollout was phased by provider type:

Provider typeSTIR/SHAKEN deadline
Large voice providersJune 30, 2021
Non-facilities-based small voice providersJune 30, 2022
Facilities-based small voice providersJune 30, 2023
Gateway providers (foreign-originated traffic)Required to authenticate
Non-IP / TDM portionsContinuing extension while a non-IP equivalent is developed

New third-party caller-ID authentication obligations took effect September 18, 2025, expanding who can sign on a provider’s behalf. The brand-facing consequence of all this: you cannot sign your own calls, and the only way to earn A-level attestation is to originate from a number your provider authenticated — see STIR/SHAKEN & attestation and get A-attestation.

Role 3 — Running the Robocall Mitigation Database

The FCC operates the RMD (Robocall Mitigation Database), where every voice, intermediate, and gateway provider must file a certification of its STIR/SHAKEN status (or a robocall-mitigation plan if it hasn’t fully implemented). The RMD is the FCC’s primary enforcement lever on the voice side: a provider removed from the database forces every downstream provider to block all of its traffic.

The RMD has teeth — and the FCC is using them
In August 2025 the FCC revoked RMD certifications for roughly 1,400 providers (185 first, then 1,200+ more) — the most aggressive cleanup to date. False or inaccurate submissions carry forfeitures around $10,000 base. Removal isn’t a slap on the wrist: it severs the provider’s traffic from the network.

RMD recertification (Mar 1, 2026)

The RMD now requires annual recertification, and the next deadline applies to all voice, intermediate, and gateway providers — explicitly including MVNOs:

Deadline · 2026-03-01
RMD annual recertification — The filing window opened Feb 1, 2026. Recertify (or file) or risk removal from the RMD — which forces downstream providers to block all of your traffic.

This is a provider-side obligation, not something most brands file directly — but if you operate your own voice infrastructure, or want to confirm your carrier is covered, the robocall mitigation (RMD) page walks through it.

What’s still open

The FCC isn’t finished. Two items to watch (tracked with dates on the change tracker):

  • Quiet-hours petition — the Ecommerce Innovation Alliance petitioned the FCC (March 2025) arguing that prior express written consent forecloses quiet-hours liability. Comments closed April 10, 2025; still pending as of mid-2026. See quiet hours.
  • Call-branding FNPRM (Oct 28–29, 2025) — proposes tying verified caller identity and branding to A-level attestation. Proposed, not yet in force.

Next

Sources