Compliance & Automation
AI Call Recording Laws in 2026: Consent Rules for AI Receptionists (and Why AI Vendors Are Getting Sued)
Short answer: Federal law lets one party consent to recording a call, but California, Florida, Washington and several other states want every party's consent, so an AI receptionist should announce recording in its first line, before it collects anything. That's the old problem. The new one is the AI vendor itself. Since 2025, federal judges have let wiretap claims proceed against AI phone and transcription companies (Google, ConverseNow, Otter, and now Pegasystems) on the theory that a vendor able to use your callers' words for its own purposes is a third-party eavesdropper. Your greeting, your storage settings and your vendor's terms all have to line up.
We build AI voice receptionists at Wrk Less, mostly on Retell with n8n handling everything after the call. We're in Orlando, an all-party consent state, so recording consent shapes every agent we build from the first line of the script. Here's what changed this fall and how we configure for it.
This is not legal advice. Have your attorney approve your recording notice and vendor contracts.
Do you need consent to record calls answered by an AI receptionist?
Yes. The real question is whose consent you need.
The federal Wiretap Act allows recording when "one of the parties to the communication has given prior consent," unless the call is intercepted for a criminal or tortious purpose (18 U.S.C. § 2511(2)(d)). Your business is a party to its own calls, so federal law is the easy part.
States are stricter. Florida makes interception lawful when "all of the parties to the communication have given prior consent" (Fla. Stat. § 934.03). Washington requires the consent of all participants but treats a recorded announcement as consent (RCW 9.73.030). By one statute-by-statute count, nine states require every party's consent for at least some recording: California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania and Washington, with several more split or contested.
Your callers don't stay inside your state lines. A Florida HVAC company gets calls from snowbirds with Pennsylvania cell numbers. So we build to the strictest rule by default.
Why are AI vendors suddenly getting sued for wiretapping?
Because of one California statute and one legal test.
California's Invasion of Privacy Act (CIPA) § 631 covers anyone who learns the contents of a communication in transit without everyone's consent. Section 637.2 lets plaintiffs seek $5,000 per violation with no proof of harm (Bosin's breakdown of CIPA). A business can't eavesdrop on its own call. The fight is over the software company sitting in the middle.
Courts in the Northern District of California increasingly apply the capability test: if the vendor could use call data for its own purposes, it may be a third party. It doesn't have to be proven that it actually did. That test keeps surviving motions to dismiss:
- Ambriz v. Google (Feb. 10, 2025). Google's Contact Center AI was plausibly a third party because its terms let it use call data to improve its AI models with customer permission.
- Taylor v. ConverseNow (Aug. 11, 2025). This is the closest case to an AI receptionist. ConverseNow's voice assistant answered restaurant calls, and the court agreed with the capability approach partly because the company's own website and privacy policy said call data improved its products.
- In re Otter.AI (Aug. 13, 2026). Wiretap, CIPA and BIPA claims survived because Otter allegedly kept conversation data to train its models.
- Juarez v. Pegasystems (filed Oct. 2, 2026). A new class action in Massachusetts federal court claims Pega's Voice AI streamed U.S. Bank calls to Pega's cloud for live transcription without callers' consent. It pleads CIPA plus the Massachusetts and Pennsylvania wiretap laws, seeking $5,000 per violation in California and at least $1,000 per violation in the other two states.
None of these are liability findings. Each one is a pleading-stage ruling or a fresh complaint. But they show the plaintiffs' playbook, and the deploying business can end up named alongside the vendor.
Does live AI transcription count as "recording" if nothing is saved?
Don't count on that defense. Section 631 is about learning a call's contents in transit, and an AI receptionist has to do exactly that to work. It transcribes the caller in real time so the model can answer. The Pegasystems complaint targets live transcription and analysis, not an archive of stored files.
So a "don't store recordings" toggle is good hygiene, not a consent strategy. Callers still need to hear, up front, that the call is recorded and processed by AI.
Can a voice AI system create a biometric "voiceprint"?
It can, and that's a separate risk. Illinois' Biometric Information Privacy Act treats voiceprints as biometric identifiers that need written notice and a written release. In August, plaintiffs accused Walmart of building caller voiceprints through its AI customer-service line, and in late September Lowe's faced a similar proposed class action. Both are allegations only.
The line that matters is between diarization, which separates "speaker 1" from "speaker 2" within one call, and speaker recognition, which builds a persistent profile that identifies a person across calls. The second is where BIPA exposure lives. Our small-business receptionists identify callers by phone number and CRM lookup, not by voice. We don't turn on voice authentication unless a client's attorney has signed off on BIPA consent.
Didn't California just fix CIPA?
No, not for phone calls. Governor Newsom signed SB 690 on September 30, 2026, effective January 1, 2027. It removes private lawsuits under the pen-register section, § 638.51, only for website and app tracking. Sections 631, 632 and 632.7, the ones used against AI call recording, are untouched. The governor did ask the Legislature to revisit the rest of CIPA next year, so watch the 2027 session.
The three layers at a glance
| Layer | Rule | What it means for your AI receptionist |
|---|---|---|
| Federal | Wiretap Act, one-party consent | Your business can consent, unless the purpose is criminal or tortious |
| State | All-party states such as CA, FL, WA, PA, MA | Announce recording before collecting anything; offer a path for callers who decline |
| Vendor | CIPA § 631 capability test | Vendor terms that allow its own use of call data become evidence |
| Biometric | Illinois BIPA | No voiceprints or voice authentication without written consent |
How does Wrk Less set up recording on a voice agent?
This is the checklist we work through on every Retell build before an agent takes a live call:
- Disclosure in the first utterance. Retell has no dedicated recording-announcement setting. Its docs say to put the disclaimer in the agent's Begin Message, or in an opening conversation node with Skip Response and Block Interruptions turned on, so callers can't talk over it. Our line names the business, says "I'm an AI assistant," and says the call is recorded and transcribed. That pairs with the AI-identity rules in our disclosure laws post.
- A real path for "no." If a caller objects, the agent offers a transfer to a person or a scheduled human callback. It doesn't keep collecting details. In all-party states a caller's objection means a live AI conversation is the wrong tool, even with storage turned off.
- Storage set on purpose. Retell lets you choose, per agent, between Everything, Everything except PII and Basic Attributes Only. PII scrubbing can strip card numbers, dates of birth and account numbers. We push what the client needs into the CRM through the post-call webhook, then set a retention period. Retell's default is to keep data forever.
- Vendor terms read, not skimmed. Retell's Terms of Service, last updated June 1, 2026, say that if you don't opt out of recording, you permit Retell to use call data for "the development, training, and improvement of artificial intelligence and machine learning models that are included in the Service," after de-identification and aggregation (Section 11). Retell staff have separately said in its community forum that it does not train on customer call data. Under the capability test, that gap matters. We get the no-training position into the DPA, and we run the same check on every vendor in the stack.
- No voice biometrics unless counsel approves BIPA-grade consent.
- Proof of what callers heard. The webhook writes the greeting version and the caller's response to the CRM next to the transcript.
- Test calls before launch. We place calls that say "Don't record me" and "Who else is listening?" The agent has to respond honestly and route correctly every time.
Does recording consent cover AI callbacks and texts?
No. Recording consent and calling consent come from different laws. A caller who agrees to be recorded hasn't agreed to an AI callback. Outbound AI voice calls fall under the TCPA's artificial-voice rules, and texting follows the FCC's revised opt-out framework. We covered both in the FCC opt-out rules post. For after-hours call answering, our default is still the one from the real-estate seller-call build: the AI answers and a human makes the callback.
Bottom line
"This call may be recorded" was enough when the only listener was a tape recorder in your office. Now there's a software company in the middle of every AI call, and courts want to know what it can do with what it hears. Announce early, give callers a real way to say no, keep only what you need, and make sure your vendor contract says what your greeting implies.
Want us to audit your call recording setup?
We'll review your AI receptionist's greeting, storage and retention settings, vendor terms and CRM logging, then fix what's off. See how we handle Retell voice agent setup, or go straight to booking your AI systems assessment.
Questions people ask
Is it legal for an AI receptionist to record my customers' calls?
Generally yes, if the caller is told and consents where state law requires it. Federal law allows recording with one party's consent, but states such as California, Florida, Washington, Pennsylvania and Massachusetts require every party's consent for at least some recordings. Because callers can be anywhere, the safest design announces recording in the agent's opening line and gives callers who object a route to a person.
Which states require all-party consent to record a phone call?
By one reading of statute text from September 2026, nine states require every party's consent for at least some call recording: California, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania and Washington. Some only prohibit secret recording, and several other states are split or contested, so confirm the current rules with counsel for the states your callers come from.
Can my AI phone vendor be sued for listening to my calls?
Yes, and it is happening. Under California's CIPA, several federal courts have used a 'capability test': a software vendor that is able to use call contents for its own purposes, such as training its models, may be treated as a third-party eavesdropper. Claims against Google, ConverseNow and Otter.ai survived motions to dismiss, and a new suit against Pegasystems was filed on October 2, 2026. These are allegations, not findings of liability.
Does turning off call recording storage make an AI receptionist compliant?
Not by itself. An AI voice agent must transcribe speech in real time to respond, and California's wiretap provision focuses on learning a call's contents while it is in transit. Limiting storage and setting a short retention period reduces risk, but callers should still hear an up-front notice that the call is recorded and handled by AI.
Did California's SB 690 change the rules for recording phone calls?
No. SB 690, signed September 30, 2026 and effective January 1, 2027, only removes private lawsuits under CIPA's pen-register section for website and app tracking. The sections used in AI call recording cases, 631, 632 and 632.7, are unchanged, though the governor asked lawmakers to revisit broader CIPA reform in 2027.