On 28 July 2026, all 50 state and territory attorneys general signed the same letter to the FCC. The ask is short, and it lands squarely on anyone running auto dialer software: originating carriers should have to understand their customers’ business before putting that traffic on the network, not just confirm the company exists.

Identity checks already exist. Everyone agrees they are not working. The letter cites more than 29.6 billion scam robocalls and texts in the preceding year and close to $2 billion in consumer losses, which is a reasonable way of saying that knowing a customer’s legal name has bought nobody very much.

If you run legitimate outbound campaigns, none of this is aimed at you. You are still the one who has to answer it.

What the attorneys general actually asked for

Three things, and the second one is the interesting one.

First, carriers should look past identity verification into business practices, reputation, history, intended use of the service, and compliance with state and federal law. That is a different exercise from checking a tax ID. It means somebody at your carrier forms a view about whether your campaigns are the kind of thing they want carried on their network.

Second, the standard should apply to every originating provider regardless of size. The letter is explicit that illegal calls are often facilitated by smaller voice service providers. Plenty of outbound teams sit on exactly those smaller carriers, usually because they are cheaper and easier to deal with. That cost advantage is about to come with a paperwork cost attached.

Third, carriers should collect extra information on high-risk customers buying high-volume services, and then keep monitoring them. Note the phrasing. High volume is a risk category on its own. If you dial serious numbers, you are in that bucket whether or not you have ever generated a complaint.

Comparison of current carrier identity checks against the broader Know Your Customer standard requested for auto dialer software customers
The question changes from whether you are a real company to whether your traffic belongs on the network.

Why your carrier will take this seriously

Because the enforcement has already started, and it has worked.

Operation Robocall Roundup launched in August 2025 as a multistate effort. Phase one was not litigation. It was warning letters to 37 smaller voice providers, and the results came fast: 13 of those companies were removed from the FCC’s Robocall Mitigation Database, 19 dropped out of traceback results, and at least four terminated high-risk customer accounts.

That last number is the one to sit with. Four providers looked at their own customer lists and cut people loose. Not because a court told them to. Because a letter arrived and they decided some accounts were not worth the exposure.

Removal from the Robocall Mitigation Database is the part people underestimate. It is not a fine. It means no US provider may lawfully accept your traffic, which for a carrier is closer to a death sentence than a penalty. Separately, in August 2025 the FCC ordered more than 1,200 voice service providers out of that database for deficient filings alone.

Phase two arrived in December 2025 and moved up the food chain, opening investigations into Bandwidth, Inteliquent, Lumen Technologies and Peerless Network over high-volume traffic tied to suspicious campaigns. When the task force is willing to name carriers of that size, the smaller ones underneath them start reviewing customers much more carefully.

Pressure applied to carriers does not stay at the carrier. It gets pushed down to the accounts generating the traffic, and it usually gets pushed down without much ceremony.

You have quietly become the subject of due diligence

For years the relationship with a carrier was procurement. You bought minutes, you negotiated a rate, you argued about a bill occasionally. The vetting ran one way and it ran on your credit.

What is forming now looks more like underwriting. Your carrier is being asked to form and defend an opinion about your operation, and to keep that opinion current while you remain a customer. Anyone who has been through a payment processor’s risk review will recognise the shape of it.

The practical risk here is not a regulatory fine. Most outbound teams are nowhere near that. The risk is an account review you did not know was happening, concluding on a Tuesday afternoon, with your traffic stopped while somebody asks you for records you cannot produce quickly. Your campaigns are down either way. Being right does not restore dial tone.

I would treat this as an operational problem rather than a legal one. The legal position of a well-run outbound team is usually fine. The documentation is what tends to be missing.

The evidence file your auto dialer software should produce on demand

Five questions cover most of what a carrier review will ask. The test is not whether you could eventually answer them. It is whether you can answer them the same day, in a format somebody else can read.

Table of five carrier vetting questions matched to the records that answer each one
Five questions, five artefacts. The gap is almost always in the last two rows.

Who are you calling and why. A written brief per campaign, not a description of your company. Which list, sourced when and from where, what the call is offering, expected volume and duration. This sounds bureaucratic until the day somebody asks, and then it is the difference between a phone call and an incident.

Where consent came from. This is the one that fails, and it fails in a specific way. Teams have consent. What they do not have is a per-number record showing the timestamp, the form or page the person used, and the exact wording they agreed to. A spreadsheet column marked “opted in” is not evidence of anything. We went through what the current rules expect in more detail in our piece on 2026 TCPA rules for auto dialers.

How people get off the list. Consumers can revoke consent by any reasonable method now, including replying STOP to a text, and revocation has to carry across the channels you run rather than just the one it arrived on. Your scrub log should show the request, the timestamp and the propagation. Our write-up on building opt-out logic for the full rule covers the traps.

What attestation your calls carry. Know your signing level per route and know whether you can demonstrate ownership of the numbers you display. If your calls go out with B or C level attestation, expect that to be the follow-up question rather than the end of the conversation. That problem is common on smaller carriers and we looked at it closely in the STIR/SHAKEN attestation gap.

What your complaint rate is. Almost nobody tracks this until somebody else tells them the number, which is the worst possible way to find out. Pull your own traceback notices and complaint volumes, trend them monthly and break them down by campaign. Walking into a review with your own figures changes the tone of it completely.

What is worth doing this week

Pick one campaign, ideally your largest, and try to produce the full file for it in an afternoon. Not a plan to produce it. The actual documents. Most teams discover the gap is consent records and complaint data, in that order.

Then ask your carrier two questions directly: what attestation level are my calls getting, and what would trigger a review of my account. The answers are useful on their own, and how readily they come tells you something about how prepared that carrier is for what the attorneys general are asking of them.

The last piece is architectural, and it is where self-hosted platforms have a real advantage. Your consent records, scrub logs and call detail records need to be yours, exportable, and retained longer than you think you need. If those records live inside a vendor’s platform and you can only see them through a dashboard, you are one support ticket away from missing a deadline that somebody else set. ICTDialer keeps that data on infrastructure you control for exactly this reason, and it is worth comparing how other open source auto dialer options handle record retention before you commit.

None of this makes your campaigns compliant. Compliance is the underlying practice. What it does is let you prove the practice exists on a day when somebody has decided to ask, which is a much narrower and much more solvable problem.

Frequently asked questions

What did the attorneys general actually ask the FCC to do?

In a letter dated 28 July 2026, all 50 state and territory attorneys general asked the FCC to require originating voice providers to understand their customers’ business practices, reputation, history, intended use of the service and legal compliance, rather than only verifying identity. They also asked that the standard apply to providers of every size and that high-volume, high-risk customers be monitored over time.

Does this apply to my business or only to carriers?

The obligations fall on the carriers. The consequences land on their customers, because the only way a carrier can meet a standard like this is to ask its customers for evidence. If you buy origination and dial at volume, expect to be asked.

What is the Robocall Mitigation Database and why does removal matter?

It is the FCC register that voice providers must be listed in for their traffic to be accepted by other US providers. Removal effectively disconnects a provider from the network. Thirteen companies were removed following the first phase of Operation Robocall Roundup, and more than 1,200 were removed in August 2025 over deficient filings.

I run fully consented campaigns. Am I still affected?

Probably yes, because high volume is treated as a risk factor by itself. The letter specifically asks carriers to collect additional information on customers buying high-volume services. Consented traffic is much easier to defend, but only if the consent records can be produced quickly.

What is the single most common gap?

Per-number consent records with a timestamp, a source and the exact wording the person agreed to. Most teams have consent in some form and cannot export proof of it per number. Complaint rate tracking is a close second.

How long should I keep these records?

Longer than the limitation period you expect to face, and longer than your platform’s default. Storage is cheap and the records are worthless the moment they age out. If your dialer purges call detail records on a fixed short window, change it before you need it.

Related resources

Details of the attorneys general letter are drawn from the National Association of Attorneys General release of 28 July 2026, with Operation Robocall Roundup figures from the participating state attorney general offices.