โ†
AI for Skilled Trades & Home Services
Strategic ยท M12 ยท lesson 12 of 22 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
TCPA, Two-Party Consent, and AI Voice Calls
๐Ÿ“–
now learning

TCPA, Two-Party Consent, and AI Voice Calls

15 min

An owner running a 6-truck HVAC shop with Avoca on the front line, Hatch nurturing stale leads, and ServiceTitan call recording in the dispatch row is, statutorily, an outbound telemarketing operator, a recorded-call processor, and a voice-biometric collector under three of the most-litigated consumer-protection regimes in the country. TCPA exposure on AI-initiated calls and texts runs $500-$1,500 per event with treble on willful and class-action settlements at $5M-$50M in adjacent industries. Two-party-consent wiretap exposure runs $1,000-$10,000 per call across twelve jurisdictions where AI-listening tools without compliant disclosure create felony events on every recording. The 2026 plaintiff bar moved from auto, retail, and lending into home services โ€” deployment volume crossed the threshold, the demographic fits, and PE-backed roll-up balance sheets are visible. This lesson is the owner's compliance map: state-by-state consent geography, disclosure scripts that convert notification into legally-defensible consent, post-AI-booked text discipline, configuration audit each major vendor requires, the 2026 settlement environment, and the documented operating cadence that survives a state-AG inquiry, a class-action discovery demand, a Wrench Group QBR, and a one-star review on the Tuesday after a Hatch sequence misfires.

Why This Lesson Matters to the Owner

The CSR does not write the TCPA check. The Comfort Advisor does not pay the wiretap settlement. The marketing manager who configured Hatch at 200 texts a week with a one-percent bad-recipient rate does not get the state-AG letter โ€” the owner does. Every regulatory exposure AI creates against TCPA, two-party consent, and the 2026 voice-disclosure rules attaches to the operator, the licensed individual qualifying the shop, or the corporate entity that signed the AI vendor's MSA. Vendors disclaim via SaaS limitation-of-liability clauses typically capped at 12 months of fees ($12K-$36K); the shop's exposure on a single multi-statute event runs $50K-$500K plus license suspension risk. The vendor gestures at the disclaimer and exits. The shop pays.

2026 is the year this stops being theoretical for trades. Avoca's trajectory โ€” Series A led by Kleiner Perkins, April 2026 Series B of $125M led by Meritech and General Catalyst at a ~$1B valuation โ€” confirms voice-AI deployment is mainstreaming. Rilla's 18% close-rate lift across 30-40 virtual ride-alongs/day per manager produces the kitchen-table recording surface plaintiff firms will target. Hatch's 30-45% stale-lead reactivation lift produces the text-volume surface TCPA class certifications require. ServiceTitan Voice, Jobber AI Receptionist, Housecall Pro AI Agents, Podium AI Employee, and Birdeye AI Employee are all in market with per-state configuration. CallRail Conversation Intelligence's 2026 expansion to per-call sentiment, missed-opportunity flagging, and lead-source attribution multiplies the secondary-processing consent scope. The owner's compliance discipline prevents the convergence from becoming the lawsuit.

Twelve U.S. jurisdictions require all-party consent. Get the twelve right and contain the bulk of the exposure.

California โ€” Penal Code ยง 632. Prohibits recording of confidential communications without all-party consent; "confidential" interpreted broadly. Statutory damages: $5,000 per violation or three times actual. Strict liability. The state where every plaintiff firm files first.

Pennsylvania โ€” Wiretap and Electronic Surveillance Control Act. All-party; third-degree felony plus civil damages of $100/day or $1,000 plus punitive plus attorney fees. A CallRail or Avoca recording in PA without compliant disclosure is a felony event in the recording itself.

Florida โ€” ยง 934.03. Single-party for surveillance, all-party for communications under the residential-phone-call interpretation Florida courts have applied. Configure as two-party for any phone recording; $1,000 per violation or actual damages.

Illinois โ€” 720 ILCS 5/14. All-party for private electronic communications. Class 4 felony first offense; Class 3 second. BIPA voiceprint stacking layers $1,000-$5,000 per consumer.

Massachusetts โ€” MGL c. 272 ยง 99. Among the strictest. SJC interpreted aggressively. Civil damages plus criminal exposure up to 5 years imprisonment.

Maryland, Connecticut, Delaware, Montana, Washington, New Hampshire, DC. All all-party. Washington's RCW ยง 9.73.030 has anchored multiple class-action filings; Montana's ยง 45-8-213 and New Hampshire's RSA ยง 570-A round out the twelve.

Two operational notes. States move โ€” Massachusetts has discussed reform; Nevada has been judicially reinterpreted toward stricter consent. Quarterly governance review includes a state-law refresh. Cross-state calls default to the stricter jurisdiction. A CSR in Dallas answering an inbound from San Diego is governed by California. Vendor configuration applies the stricter rule to cross-border calls; the conservative posture treats every recording as all-party.

TCPA โ€” The 2026 Settlement Environment and the AI Voice Surface

The Telephone Consumer Protection Act governs automated calls and texts. Hatch nurture, Avoca outbound recovery, Jobber AI Receptionist follow-up, Housecall Pro AI Agents outbound, and Podium AI Employee SMS all operate within TCPA's reach. Three things changed in 2026.

First, the FCC's 2023-2024 rulings tightened consent revocation. A single "STOP," "no," or "remove" across any channel revokes consent shop-wide, immediately. AI tools maintaining local consent caches lagging the CRM by even 24 hours produce per-violation events on every text sent during the lag. CRM-sourced consent at send time is the only TCPA-defensible architecture in 2026; consent log is the source of truth, AI tools read at send time, opt-out is a hard gate not a configurable checkbox the marketing manager can override.

Second, AI-initiated calls fall under the strictest TCPA categories. The 2024 FCC declaratory ruling treats AI-generated voice (synthetic or AI-cloned) as artificial or prerecorded voice under ยง 227(b), requiring prior express written consent for marketing calls regardless of established business relationship. Avoca outbound on a missed call to a homeowner who never affirmatively opted into AI-voice contact is a per-call $500-$1,500 event at minimum, treble on willful. Restrict outbound AI voice to consumers with prior express written consent โ€” a one-time inbound interaction with explicit consent capture, an online form opt-in with AI-voice language, or a contractual relationship with documented AI-contact authorization. Avoca's compliance configuration ships with this gate; the operator confirms at pilot and audits quarterly.

Third, the class-action environment escalated. Auto warranty, retail loyalty, healthcare outreach, and lending have absorbed $5M-$50M+ TCPA settlements. Three factors put trades next. Deployment volume crossed the threshold โ€” Hatch at 200 texts/week ร— shop footprint ร— bad-list rates produces six-figure exposure on the math. Customer demographic skews homeowner with established credit and active dispute behavior โ€” class-favorable. PE roll-up consolidation under Wrench Group, Authority Brands, Apex Service Partners, Sila Services, Path Light Pro, Redwood Services, and ARS-Rescue Rooter produces deep-pocket defendants. Owner cadence: monthly TCPA audit reviewing flagged opt-outs, confirming suppression worked, documenting the audit pass.

"This call may be recorded for quality assurance" is notification. It is not consent. The 2026 compliant pattern captures affirmative consent via continued participation โ€” the consumer's choice to remain on the line after disclosure is the consent moment, captured in the recording.

The compliant inbound disclosure for AI-listening (CallRail / ServiceTitan / Avoca):

"By remaining on the line, you consent to recording of this call and to AI processing of the recording for quality, training, and service improvement purposes. If you do not consent, please advise the agent and we will continue without recording. You may request deletion of any recording at [shop phone]."

Four elements make it defensible. One: captures consent via continued participation, a behavior the consumer can opt out of. Two: discloses AI processing, not just recording โ€” the secondary-processing surface CallRail Conversation Intelligence, Rilla, Avoca analytics, and ServiceTitan Conversational AI all touch. Without explicit AI-processing language, consent scope is partial and exposure is full. Three: offers an opt-out path the agent honors. Four: includes a deletion-request mechanism several state privacy regimes increasingly require.

The AI-voice-agent inbound disclosure (Avoca, Jobber AI Receptionist, Housecall Pro AI Agents, ServiceTitan Voice):

"You've reached [shop]. I'm an AI assistant. This call is recorded and processed by AI for booking, quality, and training. To continue, please stay on the line. To speak with a human, say 'human' or press zero. To opt out of recording, say 'no recording' and I'll route you to a live agent."

The AI's identity is disclosed at call open โ€” the 2024 FCC ruling treats undisclosed AI-voice contact as a ยง 227(b) violation. Recording-and-AI-processing language captures both surfaces. Human-routing and opt-out paths give the consumer documented control mechanisms the compliance audit can verify.

The AI-booked-call follow-up text:

"Hi [first name], this is [shop]. We've booked your [service type] for [time]. Reply YES to confirm, RESCHEDULE to move it, or STOP to opt out. Text rates apply."

The text after an AI-booked call is the second-most-litigated surface in the TCPA chain. The first-text rule: every AI-booked or AI-recovered call generates exactly one confirmation text containing standard STOP language, message-rate disclosure, and shop identity. Subsequent texts require explicit opt-in captured during the AI call ("Would you like text reminders? Reply YES.") or fall under EBR with shop-side STOP honored. Marketing texts (review nudges, NiceJob, Hatch nurture) require separate documented opt-in distinct from the transactional confirmation.

Texting After AI-Booked Calls โ€” Where the Litigation Actually Hits

The under-watched 2026 exposure surface is the text sequence after an AI-booked call. Avoca books the no-heat call at 6:47 a.m.; ServiceTitan fires appointment confirmation at 6:48; Hatch sends "your tech is on the way" at dispatch, a review nudge two hours later, a NiceJob review-card text 24 hours later, and a marketing follow-up 30 days out. Five texts after one AI-booked call. Each is a TCPA-governed event. Three of the five typically rely on opt-in capture that never happened.

Rule one: tier the texts by purpose. Transactional (appointment confirmation, on-my-way, job-complete) under EBR with shop-side STOP honored. Service (NiceJob review request after job close) under explicit consent captured during AI booking or at job-close on the tech's tablet. Marketing (Hatch nurture, replacement campaign, seasonal tune-up) requires separate documented opt-in distinct from any transactional consent. The CRM tags each text by tier; the AI tool reads tag and consent state at send time; mismatched tags block.

Rule two: AI bookings capture opt-in explicitly. Avoca, Jobber AI Receptionist, Housecall Pro AI Agents, and ServiceTitan Voice ship per-state configuration for opt-in during booking. System prompt asks: "Would you like text confirmations and reminders for this appointment?" Affirmative answer captured in recording, logged in CRM consent table, propagated to downstream tools at send time. Absent explicit opt-in, the post-call sequence is restricted to the single transactional confirmation under EBR.

Rule three: STOP propagates to every tool, every channel, immediately. The 2024 FCC standard treats a single STOP across any channel as a shop-wide opt-out. CRM consent table is the source of truth; ServiceTitan, Hatch, NiceJob, Podium AI Employee, Birdeye AI Employee read from it at send time. Local caches that lag produce per-violation events on every text sent during the lag.

Rule four: monthly TCPA audit. Pull prior-month opt-outs from the CRM consent table. Cross-reference texts sent from each tool during the post-opt-out window. Confirm zero post-opt-out events. Log the audit pass. Any flagged event triggers vendor configuration review and the failure log entry. 30 minutes monthly for a 6-truck shop; the documented audit pass is the artifact the state-AG examiner credits.

What Gets You Sued โ€” The Three 2026 Patterns

Three patterns produce most of the 2026 trades-shop TCPA, wiretap, and AI-voice-disclosure claims. Each has a defined operating fix; each compounds when the fix is absent.

Pattern one: the stale-list Hatch sequence. Marketing manager imports an aged customer list into Hatch, configures a "we miss you" nurture sequence at 200 texts a week, and the list contains 2-4% bad numbers (reassigned, opted-out elsewhere, on the National Do Not Call Registry, or wrong-numbered). Per-violation math: 200 texts ร— 4 weeks ร— 3% bad ร— $500-$1,500 = $36K-$108K monthly. Class math: cohort ร— certification ร— settlement pressure = $1M-$5M+. Fix: list-hygiene audit before any sequence enters Hatch; CRM-sourced consent at send time; DNC scrub before import; monthly TCPA audit.

Pattern two: the California Avoca recording without two-party disclosure. Shop in a one-party state (Texas, Florida despite the surveillance carve-out, or Arizona) deploys Avoca with default greeting; Avoca answers an inbound from a California homeowner; recording captured without California-compliant disclosure. Per-call exposure: $5,000 under ยง 632 strict liability. Across a 30-call/day California-inbound footprint, monthly strict-liability math is $4.5M; settlement floor is six figures. Fix: configure Avoca for all-party-consent disclosure default across every state, audit disclosure plays in the first 8-12 seconds of every recording, quarterly sample review per state.

Pattern three: the kitchen-table Rilla recording without spouse re-disclosure. Comfort Advisor delivers Rilla disclosure at the door; homeowner consents. Twenty minutes in, the spouse walks in and joins the discussion. Rilla continues recording; the spouse never heard the disclosure. In an all-party state, this is a wiretap event regardless of the original homeowner's consent โ€” the spouse is a party who has not consented. Fix: advisor training drills the re-disclosure on spouse, adult child, or third-party entry, captured verbally. "Quick note โ€” I'm recording our conversation for follow-up and coaching; by continuing, you consent. If you'd rather I not record, I'll pause." Rilla's 2026 dashboard tracks disclosure-completion per advisor; declining rate triggers coaching or program removal.

Vendor Configuration โ€” Each Tool, Each State, Each Quarter

Every AI-voice and AI-listening vendor ships per-state configuration. The vendor carries the technical capability; the shop carries deployment-confirmation responsibility. Owner's quarterly cadence walks the vendor matrix once every 90 days.

Avoca AI. Per-state system prompt configures disclosure as first utterance after greeting. Confirm during 30-day pilot the disclosure plays in each state served. Verify AI-identity disclosure ("I'm an AI assistant") is live โ€” the 2024 FCC ruling makes it mandatory. Confirm human-routing and opt-out paths function. The HL Bowman case study's 100% answer rate only counts as a compliant win when the disclosure plays correctly. Quarterly: sample 5 calls per state, confirm disclosure in first 8-12 seconds, confirm AI-identity disclosure, confirm human-routing path.

CallRail Conversation Intelligence. Per-state configuration at the tracking-number level. The 2026 expansion added AI-processing disclosure as a configurable field; enable it. Sentiment analysis, missed-opportunity flagging, and lead-source attribution all derive from the audio; the disclosure must cover all three. Quarterly: pull a sample per state, listen to first 15 seconds, confirm disclosure presence and state match.

ServiceTitan Call Recording and ServiceTitan Voice. Per-territory configuration within the phone integration. Disclosure plays at call answer; for outbound CSR calls, agent reads within the first 10 seconds. Titan Intelligence layers AI processing on top โ€” the same disclosure governs both. Custom phone-number assignments drift; the quarterly audit catches drift. ServiceTitan Voice's AI-identity disclosure is configurable and required.

Rilla. Per-state configuration plus advisor verbal-disclosure training including spouse/third-party re-disclosure. Rilla's 2026 dashboard tracks per-advisor disclosure-completion rate; declining rates trigger coaching or program removal.

Jobber AI Receptionist, Housecall Pro AI Agents, Podium AI Employee, Birdeye AI Employee, Hatch. Same pattern. Each ships per-state configuration with disclosure as configurable strings; each requires AI-processing language for 2026 secondary-processing; each gets the same quarterly audit. Hatch additionally requires CRM-sourced consent integration; vendor audit confirms send-time CRM read.

The 2026 Settlement Environment and the Owner-Defensible Posture

Three observable 2026 signals. Adjacent industries continue settling at $5M-$50M+ bands; the plaintiff bar has the playbooks and the discovery templates. The FCC's 2024 rulings on AI-generated voice and consent revocation are operational and state AGs are adopting them under UDAP analogs. Three trades-adjacent plaintiff-firm filings landed in late 2025 and early 2026 โ€” home services is on the calendar.

The owner-defensible posture has four components by Q3 2026. One: counsel-reviewed disclosure language for each of the twelve two-party states plus the AI-voice disclosure. Refreshed annually or on state-law change. Two: vendor configuration matrix โ€” every recording and AI-voice vendor (CallRail, ServiceTitan Voice, Avoca, Rilla, Jobber AI Receptionist, Housecall Pro AI Agents, Podium AI Employee, Birdeye AI Employee, Hatch) crossed against every state in the shop's footprint, with pilot-confirmation date, last quarterly audit date, observation note. Three: failure log โ€” date, location, vendor, failure pattern, remediation, customer-recovery action, cost avoided. Four: monthly TCPA audit plus quarterly two-party-consent audit, both producing documented audit-pass artifacts.

The four components compose the operating system the PE-backed platform CEO walks into the quarterly board review with; the Authority Brands or Wrench Group regional president audits in their portfolio QBR. The architecture is asymmetric โ€” high exposure ($500-$10,000 per violation, $5M-$50M+ class action, license suspension risk), cheap fix (30 minutes monthly TCPA audit, 30 minutes quarterly two-party audit, ~$2K-$5K annual counsel review). Build the cheap fix in week one of any AI-voice or AI-listening deployment, or find out what statutory damages without proof of harm feel like in front of an Illinois plaintiff firm with three trades-shop class-action filings already on the docket.

Key Takeaways

  • Twelve jurisdictions require two-party consent โ€” California ($5K strict liability), Pennsylvania (third-degree felony), Florida (treat as two-party for residential), Illinois (Class 4 felony plus BIPA stacking), Massachusetts (up to 5 years imprisonment), Maryland, Connecticut, Delaware, Montana, Washington, New Hampshire, DC. Cross-border calls default to stricter; conservative posture treats every recording as all-party.
  • TCPA on AI voice and text โ€” $500-$1,500 per call or text, treble on willful, class settlements $5M-$50M+ in adjacent industries. The 2024 FCC ruling treats AI-generated voice as artificial under ยง 227(b), requiring prior express written consent regardless of EBR.
  • The compliant inbound disclosure has four elements โ€” consent via continued participation, AI-processing disclosure (not just recording), opt-out path the agent honors, deletion-request mechanism. "May be recorded for quality assurance" is notification, not consent.
  • The AI-voice disclosure identifies the AI as AI at call open โ€” the 2024 FCC ruling makes AI-identity disclosure mandatory; undisclosed AI-voice contact is a ยง 227(b) violation regardless of other language quality.
  • Texts after an AI-booked call tier by purpose โ€” transactional (EBR, STOP honored), service (explicit consent at AI booking), marketing (separate documented opt-in distinct from transactional). CRM tags each text; the AI tool reads at send time; mismatched tags block.
  • STOP propagates shop-wide immediately, every channel, every tool โ€” CRM consent table is the source of truth; ServiceTitan, Hatch, NiceJob, Podium AI Employee, Birdeye AI Employee read at send time. Local caches that lag produce per-violation events on every text sent during the lag.
  • Three failure patterns produce most 2026 claims โ€” stale-list Hatch ($36K-$108K monthly per-violation, $1M-$5M class), California Avoca without two-party disclosure ($5K per call strict liability), kitchen-table Rilla without spouse re-disclosure (per-call exposure regardless of original consent).
  • Vendor configuration matrix audited quarterly โ€” Avoca, CallRail, ServiceTitan Voice, ServiceTitan Call Recording, Rilla, Jobber AI Receptionist, Housecall Pro AI Agents, Podium AI Employee, Birdeye AI Employee, Hatch โ€” every vendor crossed against every state, with pilot date, last audit date, observation note.
  • Monthly TCPA audit โ€” pull prior-month opt-outs, cross-reference texts sent during the post-opt-out window, confirm zero events, log the audit pass. 30 minutes monthly for a 6-truck shop; the artifact the state-AG examiner credits.
  • Owner-defensible posture has four artifacts โ€” counsel-reviewed disclosure language by state, vendor configuration matrix, failure log, monthly TCPA plus quarterly two-party audit. Owner-signed; produced under audit on 24-hour notice; survives state-AG inquiry, class-action discovery, FTC look, PE-portfolio QBR.
  • Asymmetric architecture โ€” exposure $500-$10,000 per violation plus class action plus license suspension risk; fix ~$2K-$5K annual counsel plus 1-2 hours monthly audit. Build the cheap fix in week one.