If you are considering an AI agent to answer your phone, there is a question that comes before which vendor: does it record, and are you allowed to?

It almost certainly records. Voice agents work by turning speech into text, and most keep that transcript — it is how the summary in your CRM gets written. Whether or not anyone calls it a recording, that is what it is.

One-party and all-party states

Federal law sets a floor: one party to the conversation has to consent. That floor is the Wiretap Act, and the exception is worth reading in its own words — 18 U.S.C. § 2511(2)(d) permits interception by someone who "is a party to the communication" or who has one party's prior consent. If you are on the call, that is you, and no announcement is needed.

A number of states set a higher bar and require every party to consent: California (Penal Code § 632), Florida (§ 934.03), Illinois (720 ILCS 5/14-2), Pennsylvania (18 Pa.C.S. § 5704), Washington (RCW 9.73.030) and Maryland (Courts and Judicial Proceedings § 10-402) among them.

Read the statute rather than a list, for two reasons. The roster moves. And several of these turn on whether the conversation was private or confidential — Illinois and Washington both say so on their face, California says "confidential communication" — which makes it partly a question about the call rather than only about the state.

Maryland is where we operate, and it is one of the stricter ones. § 10-402(b) makes an unlawful interception a felony: up to five years, or a $10,000 fine, or both. That is not a regulatory slap, and it means the constraint is not academic for us or for anyone taking calls from this region.

The complication that catches people is that your state is not the only one that matters. A call has two ends. If your customer is in an all-party state and you are not, the safe assumption is that the stricter rule applies. For a local trade with a tight service area that is manageable. For anyone taking calls across state lines it means defaulting to the stricter standard, because you cannot know where the caller is standing when they dial.

Why an AI agent makes this sharper

Three reasons this bites harder than ordinary call recording.

The recording starts immediately. A human who answers can judge when to say "this call is being recorded". An AI is transcribing from the first syllable, so the disclosure has to come first or it comes too late.

There is no human party on the line. The comfortable reading of one-party consent is that the employee on the call is the consenting party. When nobody is on the call, that argument is thinner — and notice how the exceptions above are drafted. Both the federal one and Maryland's are written around a party to the communication. Whether a business is a party to a call that only its software attended is not a settled question, and it is not somewhere to be clever.

The transcript persists and travels. It goes into a CRM, gets summarised, and may pass through a vendor's systems. A recording nobody keeps is a different risk from a transcript stored indefinitely and processed by a third party — and courts have started treating that third party as its own problem. In Ambriz v. Google (Northern District of California, February 2025) a wiretapping claim against the vendor behind a contact-centre AI survived a motion to dismiss, on the reasoning that a provider capable of using what it transcribes is not merely a tool the business is holding. Scope that properly: it is one district court declining to throw a case out, not a finding of liability. It is the direction of travel, not the destination.

What this means for the greeting

The disclosure has to be built into the first thing the agent says, on every call, before it collects anything.

That is a design constraint, and it is worth stating plainly because it is usually treated as a settings checkbox. It is not — it is a sentence at the top of the script, and it competes for the caller's patience with everything else you want in the opening.

The version that works is short, plain and up front:

"Hi, you've reached [business]. I'm an automated assistant and this call is recorded. How can I help?"

Three things are doing work there. It says who they reached. It says the assistant is automated, which people increasingly expect and resent being hidden. And it says the call is recorded, before anything is collected.

You also need a path for someone who objects. If a caller says they do not want to be recorded, there has to be somewhere for that to go — a transfer, a callback, something. In practice this is rare. In principle, an agent with no answer to it is a bad design.

A point that gets missed: consent has to run in both directions of the relationship, not just from the caller.

If you are recording calls for quality or training, your own staff are on those calls too. In an all-party state their consent matters as much as the customer's, and it is normally handled in an employment agreement. Worth confirming rather than assuming.

Conversely, and more importantly: a contract does not authorise recording someone who never signed it. Whatever your terms of service say, the person calling your number at 8am has not read them. The consent that matters for a phone call is the one obtained on the phone call.

Nor does consent to be recorded carry forward into anything else. The agent has just captured a phone number, and what you may send to it afterwards is a separate question with a separate standard — we worked through that one in do you need consent to text a lead who called you?.

A workable default

  1. Assume you must disclose, regardless of your state. It costs one sentence and removes the question.
  2. Put the disclosure in the agent's first utterance, before any data collection.
  3. Say the assistant is automated in the same breath. Cheap trust, and increasingly expected.
  4. Give an objecting caller somewhere to go.
  5. Know where your transcripts are stored, how long for, and who else's systems they pass through.
  6. Check your own state and the states you take calls from. Do not work from a list you half-remember.

None of this is a reason to avoid AI on the phone. We build these and they work — see where AI actually fails in lead intake for the operational failure modes, which are more likely to cost you money than this is, and AI receptionist, answering service, or missed-call text-back? if you have not yet settled that a voice agent is the right answer at all. But the compliance question is the one that attaches at the instant the call connects, before the clever part starts, and it is the cheapest thing on the list to get right.

Is a transcript legally a recording?

Treat it as one. The wording of the statutes varies and the safe assumption is that capturing the content of a call counts, whether the audio is kept or not. This is squarely a question for a lawyer in your state.

What if the AI only records part of the call?

The obligation attaches when capture starts. Recording part of a conversation is still recording a conversation.

Does an outbound AI caller change things?

It generally raises the bar, because outbound calls bring telemarketing rules into play on top of recording rules — calling hours (47 CFR § 64.1200(c)(1) puts solicitations between 8 a.m. and 9 p.m. in the called party's local time, not yours), do-not-call obligations, and disclosure requirements. Outbound is a bigger commitment than inbound and worth treating as a separate decision.

Our vendor says they handle compliance. Is that enough?

It is worth reading closely. Vendors typically provide the mechanism — a configurable disclosure — while the obligation to use it correctly stays with you. The liability generally follows the business whose phone it is. And as Ambriz above suggests, a vendor may carry exposure of its own for what it does with the transcript; that is in addition to yours, not instead of it.

More in AI operations.