Quick answerDefault to no outbound calling for anything that is not either explicitly scheduled by the customer or legally required, such as a callback the customer requested at a specific time. Phone is the most interruptive channel a company has, arriving into whatever the customer happens to be doing at that exact moment with no way to defer it the way a text message or email can be deferred. Reserve outbound AI-agent calls for cases with prior, specific consent to be called, not general marketing consent, and never for cold outreach.
Phone is not just another channel on the outbound list
The general governance process for letting an AI agent reach out first covers outbound contact across channels broadly: email, SMS, in-app notification, and phone all get evaluated by roughly the same framework of consent and purpose. Phone deserves its own, stricter policy layer on top of that framework, because it is fundamentally more interruptive than every other channel on the list. A text message waits in an inbox until the customer is ready. A phone call interrupts whatever the customer is doing the instant it rings.
That interruption cost is exactly what phone-specific consent regimes like the TCPA in the United States are built around, and it is why a company's own internal policy should be stricter than the legal minimum, not just compliant with it.
The default policy
No outbound AI-agent-initiated calls except in two cases: the customer scheduled the call themselves, at a specific time they chose, or the company has specific, informed consent to place calls for a defined purpose, not a blanket marketing opt-in buried in terms of service. Everything else defaults to a less interruptive channel first, with phone reserved as an escalation the customer can request, not a default the agent reaches for.
Why "the customer opted into marketing communications" is not enough
Broad marketing consent covers email and sometimes SMS in most jurisdictions, it does not automatically extend to phone calls, and even where it legally does, treating it as sufficient ignores the interruption asymmetry described above. Require a distinct, phone-specific consent step, separate from general marketing opt-in, before any AI agent is authorized to place an outbound call for a purpose the customer did not themselves initiate.
What genuinely legitimate outbound AI-agent calling looks like
A customer requests a callback at 3pm, the agent calling at 3pm is continuing something the customer started, not initiating unprompted contact, and is fine under this policy. A customer has an active, urgent account issue, fraud on their account, for example, and has previously consented to be reached by phone for exactly this kind of issue: also fine, because the consent is specific and the purpose is urgent enough to justify the interruption. General retention outreach, satisfaction check-ins, or feature announcements placed as unprompted outbound calls are not fine under this default, regardless of how the AI agent frames the conversation once the customer picks up.
Cross-border complications are a separate layer
Phone consent rules vary significantly by jurisdiction, and what changes legally when an AI agent initiates contact across borders covers that variance in depth for outbound contact generally. This post's phone-specific interruption-cost framework should be applied on top of whatever the cross-border legal analysis requires for a given customer's jurisdiction, not instead of it. The legal minimum and the trust-preserving default are two different bars, and phone calling should generally clear the higher of the two.
FAQ
Can the agent leave a voicemail if the customer does not answer an authorized outbound call? Yes, if the underlying call itself was authorized under this policy, a voicemail summarizing the same purpose is a reasonable continuation, not a new outbound action requiring separate consent.
Does an existing support relationship count as implied consent for outbound calls? No. An active support relationship justifies inbound call handling and scheduled callbacks the customer requested, it does not by itself authorize the agent to initiate new outbound calls the customer did not ask for.
Should the policy differ for B2B accounts versus individual consumers? The interruption-cost reasoning still applies to B2B, but consent can often be captured once at the account level through a designated contact rather than per individual employee, as long as that consent is specific to phone contact and not inferred from a general business relationship.

