The Telephone Consumer Protection Act lets a single unsolicited text cost you up to $500 — and up to $1,500 if a court finds the violation was knowing or willful (TCPA, 47 U.S.C. § 227, via Texty Pro, 2026). Before you point an AI agent at customer texting, the rule you cannot skip is consent: marketing texts need prior express written consent, you must honor opt-outs by any reasonable means within 10 business days, and you can only send between 8 a.m. and 9 p.m. local time. This guide walks through what that means in plain English, why WhatsApp and web chat sit largely outside the TCPA, and the specific things you must never do.
What is the TCPA and does it apply to my small business?
The TCPA applies to your business the moment you send an automated or marketing text message to a customer's phone number — regardless of how small you are. There is no employee-count or revenue floor like you see in some privacy laws. If you text leads or customers in the United States using a system that stores and dials numbers automatically, you are in scope.
The law dates to 1991 and is enforced by the Federal Communications Commission (FCC), but the real teeth come from private lawsuits. Statutory damages run $500 per unsolicited text and up to $1,500 per knowing or willful violation (TCPA, 47 U.S.C. § 227, via Texty Pro, 2026). Because every individual message can count as a separate violation, a sloppy campaign to a few hundred people can turn into six-figure exposure fast.
That is the honest reason this topic matters more in the US than almost anywhere else. The TCPA is one of the most litigated consumer-protection statutes in the country, and plaintiffs' lawyers actively look for businesses that text without proper consent. An AI agent does not change the rules — it just sends messages faster, which means it can break the rules faster too.
It also helps to be clear about what the TCPA is not. It is not a privacy law in the data-handling sense, and it does not care how big your company is. A two-person plumbing outfit and a national franchise face the same per-message exposure. So the right mental model is simple: every automated text you send is a small legal event, and your job is to make sure each one is consented, well-timed, and easy to stop. Get that framework right once and you can scale your messaging without scaling your risk.
Do I need consent to text my customers, and what kind?
Yes — and the kind of consent depends entirely on what the text says. The TCPA recognizes two tiers, and confusing them is the most common way small businesses get into trouble.
For marketing or promotional texts — a sale, a "we miss you" message, a new-service announcement — you need prior express written consent. That means documented agreement where the customer knowingly opts in, sees what kind of messages they'll get, and isn't forced to consent as a condition of buying something (Bloomreach, 2026). For transactional or informational texts — an appointment confirmation, a "your technician is on the way" update — you need prior express consent, which can be oral and is a lower bar (Bloomreach, 2026).
Here is the part people miss: having someone's phone number is not consent to market to them. A customer giving you their number to book a repair has not agreed to receive your promotions. If your AI agent collects numbers during a chat and you later blast those numbers with offers, you have a problem. Capture the consent explicitly, log it with a timestamp, and keep that record — because in a TCPA suit, the burden is on you to prove consent existed.
The practical upshot for written consent is that "written" does not require a wet signature. A checked box on a web form, a confirmed opt-in keyword reply, or a documented agreement during a chat can all qualify, provided the customer clearly saw what they were signing up for. The disclosure should name your business, describe the type of messages (marketing), and make clear that consent is not a condition of purchase (Bloomreach, 2026). What kills you in court is not the format — it is the absence of a record. If you cannot reproduce exactly what the customer agreed to and when, you effectively have no consent at all.
Does the TCPA apply to WhatsApp and web chat?
Generally, no — and that is a real, defensible advantage of using those channels over SMS. The TCPA targets calls and texts sent to a telephone number over the carrier network. Messages sent and received inside WhatsApp or a web-chat widget travel over the internet, not as SMS to a phone number, so they fall largely outside the TCPA today (legal commentary via TCPAWorld, 2025).
This matters for how you design your messaging mix. A web-chat widget on your site and an opt-in WhatsApp thread carry meaningfully less TCPA litigation risk than cold SMS blasts. This is one reason a channel strategy is also a compliance strategy. Omago, an AI agent platform that helps SMEs automate customer conversations across WhatsApp, Telegram, and web chat, leans on exactly these IP-based channels rather than carrier SMS.
But do not treat this as a loophole, and be honest with yourself about three caveats. First, courts could read the TCPA more broadly, and at least one has applied it to app messages that were ultimately delivered via SMS. Second, a pending bill (Rep. Pallone) would expand the TCPA's "text message" definition to cover app-based messaging — flag this as pending and not yet law. Third, WhatsApp Business is governed by Meta's Business Policy, which requires opt-in consent, pre-approved message templates, and a quality-rating system that can ban accounts for spam. Standard 10-digit SMS in the US also requires 10DLC registration (Conversive, 2025). The honest takeaway: WhatsApp and web chat reduce messaging-consent risk; they do not eliminate the obligation to get consent and behave well.
What are the SMS quiet hours and opt-out rules I have to follow?
You can only send marketing texts between 8 a.m. and 9 p.m. in the recipient's local time, and you must let customers opt out by any reasonable means — not just the word "STOP." These two operational rules trip up more automated systems than anything else, because they are easy to get technically wrong at scale.
On opt-outs, the FCC's rule that took effect April 11, 2025 says consumers may revoke consent by any reasonable means (FCC Order DA-25-312, via Nixon Peabody, 2025). The per se valid keywords are stop, quit, end, revoke, opt out, cancel, and unsubscribe — but plain language like "please stop texting me" also counts. You must honor an opt-out within 10 business days, and you may send one confirmation text within 5 minutes as long as it contains no promotional content. For an AI agent this is decisive: simple keyword-only "STOP" detection is legally insufficient. Your agent has to understand intent, not just match a word.
On quiet hours, the 8 a.m.–9 p.m. window comes from 47 C.F.R. § 64.1200(c), and several states are stricter — Florida and Oklahoma effectively run 8 a.m.–8 p.m., and Texas SB 140 sets 9 a.m.–9 p.m. on weekdays with tighter Sunday limits (Postscript, 2025; Privacy World, 2025). A wave of "quiet hours" class-action lawsuits began in 2025, some targeting messages sent only a few minutes outside the window even where consent existed (Privacy World, 2025). Treat this as a live, active litigation risk: your automation must time-zone-stamp recipients and refuse to fire outside the window.
Here is the short version of what good messaging hygiene looks like in practice:
- Collect and log explicit consent before any marketing text, with a timestamp and the language the customer saw.
- Use the recipient's local time zone to enforce the 8 a.m.–9 p.m. window — and tighten it where a state demands.
- Detect opt-out intent, not just the keyword "STOP," and stop within 10 business days (sooner is safer).
- Identify your business by name in every message.
- Never buy, rent, or share phone-number lists — consent belongs to the person, not the number.
What changed for the TCPA in 2025, and what do I do about it?
Three big things shifted in 2025, and the practical answer is the same for all of them: take the conservative posture and follow the strictest reasonable interpretation. The legal ground moved, but the safe operating rules for a small business did not get looser.
First, the FCC's "one-to-one consent" rule is dead. It was vacated by the Eleventh Circuit in Insurance Marketing Coalition v. FCC on January 24, 2025, which held the FCC had exceeded its authority (via Wiley, 2025). If you've read older articles saying you need separate, seller-specific consent for each business — that rule never took effect. The long-standing prior-express-written-consent requirement for marketing still applies.
Second, the Supreme Court's McLaughlin v. McKesson decision (June 20, 2025) held 6–3 that courts are not bound by the FCC's interpretation of the TCPA and must interpret the statute themselves (McLaughlin Chiropractic Associates, Inc. v. McKesson Corp., No. 23-1226, via Troutman Pepper Locke, 2025). In plain terms: FCC orders are now persuasive, not binding, in court. That increases uncertainty and invites fresh challenges from both sides. For an SME, the lesson is to never assume an FCC carve-out is bulletproof — design for the strict reading.
Third, the cross-channel "revoke-all" portion of the opt-out rule — where opting out on one channel kills consent on all of them — was delayed, then further extended to January 31, 2027 while the FCC reviews comments (Consumer Financial Services Law Monitor, January 2026). Flag that as pending and contested. None of this changes the smart move: get written consent, honor opt-outs broadly and fast, respect quiet hours, and keep records. (This is a current-as-of-2026 snapshot and is not legal advice — talk to counsel about your specific setup.)
TCPA do's and don'ts for an AI agent on messaging
The fastest way to keep an automated messaging program out of trouble is to bake these rules into the agent's behavior, not into a policy document nobody reads. Configure the agent so the compliant path is the only path.
| DO | DON'T |
|---|---|
| Get prior express written consent before marketing texts | Don't text marketing without documented, timestamped consent |
| Honor any reasonable opt-out within 10 business days | Don't rely only on "STOP" keyword detection — read intent |
| Send marketing texts only 8 a.m.–9 p.m. recipient local time | Don't ignore stricter state windows (FL/OK 8a–8p; TX 9a–9p) |
| Identify your business by name in every message | Don't buy, rent, or share phone-number lists |
| Treat WhatsApp/web chat as lower-risk but still get consent | Don't assume any FCC carve-out is litigation-proof post-McLaughlin |
A few state "mini-TCPA" laws deserve their own mention because they go beyond the federal floor. Connecticut bans marketing outreach without written consent and allows penalties up to $20,000 per violation; Oklahoma caps you at three calls in 24 hours. If you operate across state lines — and most messaging programs do — your safest design is to comply with the strictest state where your customers actually live.
This is also where the human-versus-automation line matters. An AI agent is excellent at the mechanical compliance work: stamping time zones, logging consent, recognizing an opt-out phrased a dozen different ways, and refusing to send outside the window. What it should not do is make a judgment call about whether an ambiguous message counts as consent. When in doubt, the agent should escalate to a person rather than guess — because guessing wrong is what generates lawsuits.
It is worth being blunt about what automation can and cannot solve here. Software can enforce a quiet-hours window perfectly and never forget to honor an opt-out — that is a genuine win over a human team juggling a hundred conversations. But software cannot give you consent you never collected, and it cannot fix a sloppy intake form that buried the marketing opt-in. Compliance is upstream of automation. If your consent capture and recordkeeping are clean, an AI agent makes the program safer and more consistent. If they are not, automation just sends non-compliant messages at higher volume. Fix the inputs first, then let the agent handle the execution.
How does messaging compliance connect to my broader AI and data setup?
Messaging consent is one piece of a larger compliance picture, and the smart move is to treat them together rather than bolting compliance on after launch. The same chat logs that prove you obtained consent are also personal information under state privacy laws, so your retention and deletion practices touch both worlds.
If you're choosing channels, weigh the consent-risk profile alongside reach. For US small businesses, SMS, iMessage, and Messenger often carry more day-to-day traffic than WhatsApp, so position a web widget plus WhatsApp where it fits your audience rather than assuming any single channel dominates. The right answer is the channel mix your customers actually use, configured with consent baked in from day one. For more on that decision, see how to choose the right messaging channel for your AI agent.
Compliance is also one of the most common reasons AI customer-service projects stall or get yanked after launch — the rules feel murky, so owners either freeze or wing it. Neither is necessary if you set guardrails up front. For the broader view of where these projects go wrong, see why AI customer service projects fail for SMEs. Get consent, opt-outs, quiet hours, and recordkeeping right, and the messaging layer becomes the boring, dependable part of your stack — which is exactly what you want it to be.
Frequently Asked Questions
Do I need consent to text my customers?
For marketing or promotional texts, yes — you need prior express written consent that is documented and specific. For purely transactional messages like an appointment confirmation, a lower standard (prior express consent, which can be oral) applies (Bloomreach, 2026). Simply having someone's phone number is never enough to send them marketing.
Can I text customers after 9 p.m.?
No. The TCPA prohibits marketing texts before 8 a.m. or after 9 p.m. in the recipient's local time (47 C.F.R. § 64.1200(c)), and some states are stricter — Florida and Oklahoma effectively cut off at 8 p.m., and Texas runs 9 a.m.–9 p.m. on weekdays (Postscript, 2025; Privacy World, 2025). A wave of class-action suits in 2025 targeted messages sent just minutes outside the window.
What happens if I text someone who replied STOP?
You must stop sending marketing messages and honor the opt-out within 10 business days (FCC Order DA-25-312, via Nixon Peabody, 2025). Continuing to text after a valid opt-out is a clear violation that can cost $500–$1,500 per message (Texty Pro, 2026). Note that since April 11, 2025, customers can opt out by any reasonable means, not just the word "STOP."
Does the TCPA apply to WhatsApp?
Generally not today. The TCPA targets texts sent to a phone number over the carrier network, and WhatsApp messages travel over the internet, so they fall largely outside its scope (TCPAWorld, 2025). That said, WhatsApp Business is governed by Meta's own Business Policy, which still requires opt-in consent and pre-approved templates — and a pending bill could expand the TCPA to cover app-based messaging.
Is the FCC one-to-one consent rule still in effect?
No. The Eleventh Circuit vacated the FCC's one-to-one consent rule on January 24, 2025 (Insurance Marketing Coalition v. FCC, via Wiley, 2025). The older prior-express-written-consent requirement for marketing texts remains in force. If you've read that you need separate consent for each individual seller, that rule never took effect.
Sources: TCPA / 47 U.S.C. § 227 via Texty Pro (2026); Bloomreach (2026); FCC Order DA-25-312 via Nixon Peabody (2025); Insurance Marketing Coalition v. FCC via Wiley (2025); McLaughlin Chiropractic Associates, Inc. v. McKesson Corp. via Troutman Pepper Locke (2025); Consumer Financial Services Law Monitor (January 2026); 47 C.F.R. § 64.1200(c); Postscript (2025); Privacy World (2025); TCPAWorld (2025); Conversive (2025).
