Are AI Voice Scam Calls Illegal? Federal and State Law (2026)
Independently fact-checked against primary sources (last audited September 24, 2026). · 27 primary sources cited on this page. How we verify our legal content

As of September 2026, using an AI-cloned or AI-generated voice to call someone and trick them out of money is illegal under federal law in several separate ways. The Federal Communications Commission ruled in February 2024 that the Telephone Consumer Protection Act's limits on calls using an "artificial or prerecorded voice" cover AI-generated voices, so those calls need the called party's prior express consent. The scam itself can be charged as federal wire fraud under 18 U.S.C. § 1343, and some states, including Arizona and New Hampshire, have added criminal statutes that name computer-generated voices or deepfakes.
This article covers the federal rules (the TCPA, the FCC's ruling, the FTC Impersonation Rule and the federal fraud and identity theft statutes) and a sample of state statutes. It does not re-explain general TCPA consent rules, which are covered in the TCPA overview, or voice ownership and right-of-publicity law, which is covered in AI voice cloning laws and the ELVIS Act.
Are AI Voice Scam Calls Illegal?
Yes. As of September 2026, a scam call that uses an AI-generated or cloned voice falls under at least two separate federal laws, and they do different jobs.

The first is the Telephone Consumer Protection Act (TCPA), 47 U.S.C. § 227, a law about calling practices. Section 227(b)(1)(B) makes it unlawful "to initiate any telephone call to any residential telephone line using an artificial or prerecorded voice to deliver a message without the prior express consent of the called party," unless an emergency purpose, a federal debt-collection purpose or an FCC exemption applies. Section 227(b)(1)(A) sets a parallel rule for calls to cell phones and certain other lines. The FCC's February 2024 ruling, discussed below, treats an AI-generated voice as an "artificial" voice for these rules.
The second is the law against the theft itself. The federal wire fraud statute, 18 U.S.C. § 1343, reaches anyone who, with a scheme to defraud or to obtain money by false pretenses, "transmits or causes to be transmitted by means of wire, radio, or television communication in interstate or foreign commerce, any writings, signs, signals, pictures, or sounds for the purpose of executing such scheme." A phone call that crosses state or national lines is a wire communication in interstate or foreign commerce, and wire fraud applies whether or not an AI voice was involved.
Cloning a voice is not, by itself, what these federal laws prohibit. Voice synthesis has lawful uses, such as dubbing and accessibility tools. What they target is using a synthetic voice to place unconsented calls, or using it to deceive someone out of money or property.
What the FCC's February 2024 Ruling Held
The FCC adopted its Declaratory Ruling in CG Docket No. 23-362 (FCC 24-17) on February 2, 2024, released it on February 8, 2024, and made it effective on release. The central holding, from paragraph 2:
"In this Declaratory Ruling, we confirm that the TCPA's restrictions on the use of 'artificial or prerecorded voice' encompass current AI technologies that generate human voices."
The ruling continues that "calls that use such technologies fall under the TCPA and the Commission's implementing rules, and therefore require the prior express consent of the called party to initiate such calls absent an emergency purpose or exemption." In paragraph 5 the FCC added that "AI technologies such as 'voice cloning' fall within the TCPA's existing prohibition on artificial or prerecorded voice messages because this technology artificially simulates a human voice."
The ruling interprets existing law. It did not create a new prohibition. It also points out that the FCC's rules at 47 CFR § 64.1200(b) already require every artificial or prerecorded voice message to identify, at the beginning of the message, the business, individual or other entity responsible for the call. For how consent works under these rules, see the TCPA overview.
The FCC connected the ruling to the harm scam calls cause. It said voice cloning "can convince a called party that a trusted person, or someone they care about such as a family member, wants or needs them to take some action that they would not otherwise take." The ruling applies to AI technologies that "either wholly simulate an artificial voice or resemble the voice of a real person taken from an audio clip to make it appear as though that person is speaking on the call."
How much weight courts give the ruling
An FCC declaratory ruling is the agency's reading of the statute, and it does not bind every court. In McLaughlin Chiropractic Associates, Inc. v. McKesson Corp., 606 U.S. 146 (2025), a TCPA case, the Supreme Court held that the Hobbs Act does not bind district courts in civil enforcement proceedings to an agency's interpretation of a statute. The Court said the district court "is not bound by the FCC's interpretation of the TCPA" and should interpret the statute "under ordinary principles of statutory interpretation, affording appropriate respect to the agency's interpretation."
In practice, a court hearing a private TCPA suit over an AI voice call decides for itself whether the call used an "artificial" voice. Before the ruling, the Ninth Circuit had described the term in passing in Trim v. Reward Zone USA LLC, 76 F.4th 1157 (9th Cir. 2023), a text-message case, saying that "an artificial voice is a sound resembling a human voice that is originated by artificial intelligence." The same decision held that text messages without an audible component did not use a prerecorded voice, so a text-only AI scam does not fit this part of the TCPA the way a spoken call does.
Can You Sue Over an AI Voice Scam Call?
For the person who received the call, the TCPA is the federal law that provides a private claim for money. Under 47 U.S.C. § 227(b)(3), a person may bring "an action to recover for actual monetary loss from such a violation, or to receive $500 in damages for each such violation, whichever is greater," or an action to stop the violation, or both. If the court finds the defendant "willfully or knowingly" violated the law, it "may, in its discretion, increase the amount of the award to an amount equal to not more than 3 times the amount available." That makes the range $500 to $1,500 per violation when the base is $500. Trebling is up to the court, not automatic.
The TCPA's separate do-not-call action, § 227(c)(5), has different terms (up to $500 per violation and a reasonable-procedures defense) and is aimed at repeated telemarketing calls from the same entity; it is explained in TCPA damages and lawsuits. A TCPA claim generally must be filed within four years under 28 U.S.C. § 1658(a), which sets that period for civil actions under federal statutes enacted after December 1, 1990 unless the statute provides otherwise.
The practical limit is finding someone to sue. Scam callers often hide behind spoofed numbers and may be outside the United States, and a claim is worth only what can be collected. Damages counting, class actions and recent settlements are covered in TCPA damages and lawsuits.
The Enforcement Trail: Kramer and Lingo Telecom
The best-documented AI voice robocall case began on January 21, 2024, two days before New Hampshire's Democratic presidential primary, when potential voters received calls carrying an AI-generated message in a voice made to sound like President Biden. Two FCC actions followed, and neither rests on the TCPA's artificial-voice provision.
Steve Kramer: $6,000,000 forfeiture under the Truth in Caller ID Act. In Forfeiture Order FCC 24-104, adopted September 26, 2024 and released September 30, 2024, the FCC imposed "a penalty of $6,000,000 against Steve Kramer" for the robocall campaign "in violation of the Truth in Caller ID Act of 2009, which is codified at section 227(e) of the Communications Act," and the FCC's rule at 47 CFR § 64.1604. That law makes it unlawful to cause a caller ID service "to knowingly transmit misleading or inaccurate caller identification information with the intent to defraud, cause harm, or wrongfully obtain anything of value." According to the order, 9,581 calls were placed displaying the number of a New Hampshire political operative who had not consented, and the Enforcement Bureau reviewed a sample of 3,000 of them. Kramer did not respond to the earlier Notice of Apparent Liability. The order directs payment within 30 days of release; it does not show whether the penalty has been paid.
The order notes that a Truth in Caller ID violation "is not dependent on the content of the call," but that AI voice-cloned messages combined with misleading caller ID "may further demonstrate a caller's intent to defraud, cause harm, or wrongfully obtain something of value."
Lingo Telecom: $1,000,000 civil penalty and a compliance plan. Lingo Telecom, a voice service provider, completed 3,978 of the New Hampshire calls and signed them with A-level caller ID attestations under the STIR/SHAKEN framework, which is meant to show consumers that caller ID information is accurate. The FCC Enforcement Bureau resolved its investigation of apparent violations of 47 CFR § 64.6301(a), the rule requiring voice service providers to implement the STIR/SHAKEN framework, in connection with those attestations, through Consent Decree DA 24-790, adopted August 21, 2024. Lingo agreed to pay "a civil penalty to the United States Treasury in the amount of one million dollars ($1,000,000)". The decree also provides that Lingo "may only apply an A-level attestation to a call if Lingo Telecom itself has provided the Caller Identity to the calling party," and requires a compliance plan.
The FTC Impersonation Rule: What It Covers Now
The Federal Trade Commission's Rule on Impersonation of Government and Businesses, 16 CFR Part 461, took effect on April 1, 2024. It makes it an unfair or deceptive practice to falsely pose as a government agency or a business, so an AI voice call that pretends to come from a bank, a utility or a government agency can fall under it.

The rule does not reach a scammer who impersonates a private individual, such as a grandchild. A ban on impersonating individuals (proposed § 461.4) is still only a proposal as of September 2026, and in December 2024 the FTC dropped the part of its proposal that would have reached providers of tools used in impersonation schemes. The rule's text and the status of the proposal are covered in deepfake fraud and impersonation laws.
Criminal Charges: Wire Fraud and Identity Theft
Wire fraud. Section 1343 carries a fine, up to 20 years in prison, or both. If the violation affects a financial institution or involves benefits connected with a presidentially declared major disaster or emergency, the maximum rises to a fine of up to $1,000,000, up to 30 years, or both. A voice scam call made to get money wired, sent in cryptocurrency or paid in gift cards fits the statute's description of a scheme carried out over wire communications. Wire fraud is a criminal charge brought by federal prosecutors, not a claim a victim files.
Identity theft. Two federal statutes are relevant, and how far they reach a cloned voice is not fully settled. The identity fraud statute, 18 U.S.C. § 1028, defines a "means of identification" as "any name or number that may be used, alone or in conjunction with any other information, to identify a specific individual," including "unique biometric data, such as fingerprint, voice print, retina or iris image, or other unique physical representation." Aggravated identity theft, 18 U.S.C. § 1028A(a)(1), adds a mandatory 2-year prison term for anyone who, during and in relation to certain listed felonies (wire fraud among them), "knowingly transfers, possesses, or uses, without lawful authority, a means of identification of another person."
A scam that uses a real person's name to impersonate them fits the definition's reference to a name. Whether a synthetic imitation of someone's voice is itself a "voice print" or "other unique physical representation" under the statute is an open question that the text does not answer. The Supreme Court has also limited § 1028A. In Dubin v. United States, 599 U.S. 110 (2023), it held that the statute is violated when the misuse of another person's means of identification "is at the crux of what makes the underlying offense criminal, rather than merely an ancillary feature of a billing method." In an impersonation scam, the impersonation is usually the core of the deception, but how courts apply that test to a cloned voice remains to be seen.
The State Layer: A Sample, Not a Survey
State coverage of AI voice fraud is uneven, and what follows is a sample of statutes that address computer-generated voices, deepfakes or AI directly. It is not a 50-state census, and a state missing from this list is not a state without a relevant law. Every state has general fraud, theft and impersonation laws that can apply to a scam call no matter how the voice was produced. For state-by-state deepfake statutes, see the deepfake laws by state hub.
| State | Statute | What it covers | Penalty or remedy |
|---|---|---|---|
| Arizona | A.R.S. § 13-2006(A)(4) | Using a computer-generated voice recording, image or video of another person with intent to defraud other persons | Class 5 felony |
| New Hampshire | RSA 638:26-a | Knowingly creating, distributing or presenting a deepfake of an identifiable individual to harm that person | Class B felony (up to 7 years) |
| New Hampshire | RSA 507:8-j | Civil action by the person whose likeness was used in such a deepfake | Damages resulting from the use |
| Utah | Utah Code § 76-2-107 | An offense committed with the aid of generative AI | The underlying offense's penalty |
Arizona. Laws 2025, chapter 184 (SB 1295) added paragraph 4 to Arizona's criminal impersonation statute. It covers "Using a computer-generated voice recording, image or video of another person with the intent to defraud other persons," and defines "defraud" as making "a false representation or material omission to deceive another person to gain a benefit." Comedy, parody, artistic expression, criticism and cases where "it is clear to a reasonable listener or viewer" that the recording was digitally manipulated are not fraudulent. The AI paragraph is a class 5 felony, one class higher than the class 6 felony for the statute's other forms of impersonation. Because the victim is the person deceived, this statute fits a family-emergency voice scam directly. More on Arizona is in Arizona deepfake laws.
New Hampshire. Effective January 1, 2025, RSA 638:26-a makes it a class B felony to knowingly create, distribute or present a deepfake of an identifiable individual "for the purpose of embarrassing, harassing, entrapping, defaming, extorting, or otherwise causing any financial or reputational harm to the identifiable person." The statute defines a deepfake to include audio in which a person's voice "has been digitally altered." Under RSA 651:2, the maximum prison term for a class B felony is 7 years. The companion civil statute, RSA 507:8-j, lets the person whose likeness was used sue for damages.
Both New Hampshire statutes are written around harm to the person who was faked, not the person who was fooled. A grandparent who wires money after hearing a cloned grandchild is the fraud victim, but the statutes' purpose element points to harm to the grandchild. That case fits these statutes less cleanly than Arizona's, and ordinary theft and fraud charges remain available. More on New Hampshire is in New Hampshire deepfake laws.
Utah. Utah Code § 76-2-107, effective May 1, 2024, provides that "An actor may be found guilty of an offense if: (a) the actor commits the offense with the aid of a generative artificial intelligence; or (b) the actor intentionally prompts or otherwise causes a generative artificial intelligence to commit the offense." It creates no new crime. It makes clear that using AI to commit an existing crime, such as fraud or theft, does not take the conduct outside that crime.
What to Do If You Get an AI Voice Scam Call
The FTC's consumer guidance on these calls is short: "Don't trust the voice." If a caller sounds like a family member in trouble and asks for money, hang up and call that person back on a number you know is theirs. If you cannot reach them, contact another family member or a friend. The FTC also warns that requests to wire money, send cryptocurrency, or buy gift cards and read out the card numbers and PINs are signs of a scam.
Write down the date, time and caller ID number, keep any voicemail, and save payment records if money was sent. If you sent money, contact your bank, wire service or gift card company right away. If you want to record a suspicious call, recording rules differ by state; see recording laws by state and the federal Wiretap Act. Then report the call. Each agency handles a different part of it:
- FTC at reportfraud.ftc.gov, for the scam itself, including impersonation of a business or government agency.
- FCC at consumercomplaints.fcc.gov, for the robocall, spoofed caller ID or an unwanted AI-voice call.
- FBI Internet Crime Complaint Center (IC3) at ic3.gov, which describes itself as "the central hub for reporting cyber-enabled crime." IC3 also lists elder fraud as a category.
- Your state consumer protection office, found through the official directory at usa.gov/state-consumer. Your state attorney general is listed at usa.gov/state-attorney-general.
If someone cloned your voice to scam other people, a report to these agencies is still the first step. A civil remedy for the person whose voice was copied depends on state law and is often limited: New Hampshire's RSA 507:8-j, for example, applies when the deepfake was meant to harm that person. Right-of-publicity rules are covered in right-of-publicity rules covered in AI voice cloning laws. A proposed federal voice-and-likeness right is discussed in our coverage of the NO FAKES Act, a pending bill.
Disclaimer: This article provides general legal information about federal law and selected Arizona, New Hampshire and Utah statutes on AI voice scam calls, current as of September 2026. It does not cover every state's law and is not legal advice. For advice about your situation, consult a licensed attorney in your state.
Frequently Asked Questions
Is it illegal to use an AI voice to scam someone?
Yes. As of September 2026, an AI voice scam call can violate the TCPA's rules on calls using an artificial or prerecorded voice, which the FCC applied to AI-generated voices in Declaratory Ruling FCC 24-17, and the scam itself can be charged as federal wire fraud under 18 U.S.C. § 1343. Some states, including Arizona, have added statutes aimed at computer-generated voices used to defraud.
Is AI voice cloning illegal by itself?
Not under the federal laws discussed here, which target how a synthetic voice is used rather than creating one; voice synthesis has lawful uses. The legal problems arise from how it is used: calling people with an artificial voice without their prior express consent, deceiving someone to get money or property, or using another person's voice or likeness without permission under state law.
Can you go to jail for an AI voice scam?
Yes. Federal wire fraud under 18 U.S.C. § 1343 carries up to 20 years in prison, or up to 30 years if it affects a financial institution or involves disaster-related benefits. Aggravated identity theft under 18 U.S.C. § 1028A can add a mandatory 2 years when a means of identification of another person is used in the fraud, although how that statute applies to a cloned voice is not settled. State charges, such as Arizona's class 5 felony for using a computer-generated voice to defraud, may also apply.
Can I sue someone who called me with an AI voice?
The TCPA allows a private lawsuit under 47 U.S.C. § 227(b)(3) for actual loss or $500 per violation, whichever is greater, and a court may, in its discretion, increase the award up to three times that amount for willful or knowing violations. The practical obstacle is identifying and collecting from the caller, since scam calls often use spoofed numbers and may come from outside the United States. A TCPA claim generally must be filed within four years (28 U.S.C. § 1658(a)).
Does the FTC Impersonation Rule cover a scammer pretending to be my grandchild?
Not as of September 2026. The rule in effect since April 1, 2024 covers impersonation of government agencies and businesses. A ban on impersonating individuals (proposed § 461.4) is still only a proposal, and the FTC dropped its separate proposal to extend liability to providers of tools used in impersonation schemes in December 2024.
Was anyone fined for the AI Biden robocalls in New Hampshire?
Yes. The FCC imposed a $6,000,000 forfeiture on Steve Kramer in Forfeiture Order FCC 24-104 under the Truth in Caller ID Act, which bars misleading caller ID sent with intent to defraud, cause harm or wrongfully obtain anything of value. Lingo Telecom, the carrier that transmitted calls in the campaign, agreed to a $1,000,000 civil penalty and a compliance plan in Consent Decree DA 24-790.
How can I tell if a call uses a cloned voice?
Often you cannot tell by listening. The FTC's advice is not to trust the voice: hang up and call the person back on a number you know is theirs, or reach them through another family member. Pressure to pay by wire transfer, cryptocurrency or gift cards is a warning sign.
Can I record a call I think is an AI scam?
Under federal law, 18 U.S.C. § 2511(2)(d) allows a person who is a party to a call to record it unless the recording is made to commit a criminal or tortious act. Some states require every party to consent, so the rule depends on where you and the caller are.
Updates
Independently fact-checked against the cited primary sources
Sources and References
- 47 U.S.C. § 227 (Telephone Consumer Protection Act, including § 227(b)(1), (b)(3), (c)(5) and (e))(govinfo.gov).gov
- FCC Declaratory Ruling, Implications of Artificial Intelligence Technologies on Protecting Consumers from Unwanted Robocalls and Robotexts, FCC 24-17, CG Docket No. 23-362 (released Feb. 8, 2024)(docs.fcc.gov).gov
- 47 CFR § 64.1200 (FCC delivery restrictions and identification rules for artificial or prerecorded voice calls)(ecfr.gov).gov
- McLaughlin Chiropractic Associates, Inc. v. McKesson Corp., 606 U.S. 146 (2025)(courtlistener.com)
- Trim v. Reward Zone USA LLC, 76 F.4th 1157 (9th Cir. 2023)(courtlistener.com)
- FCC Forfeiture Order, In the Matter of Steve Kramer, FCC 24-104 (released Sept. 30, 2024)(docs.fcc.gov).gov
- FCC Enforcement Bureau Order and Consent Decree, In the Matter of Lingo Telecom, LLC, DA 24-790 (Aug. 21, 2024)(docs.fcc.gov).gov
- 16 CFR Part 461, Rule on Impersonation of Government and Businesses(ecfr.gov).gov
- FTC final rule, Trade Regulation Rule on Impersonation of Government and Businesses, 89 FR 15017 (Mar. 1, 2024)(federalregister.gov).gov
- FTC supplemental notice of proposed rulemaking on impersonation of individuals, 89 FR 15072 (Mar. 1, 2024)(federalregister.gov).gov
- FTC informal hearing notice dropping the proposed means and instrumentalities provision, 89 FR 104905 (Dec. 26, 2024)(federalregister.gov).gov
- Unified Agenda, FTC Trade Regulation Rule on Impersonation of Government and Businesses, RIN 3084-AB71(reginfo.gov).gov
- 18 U.S.C. § 1343 (wire fraud)(govinfo.gov).gov
- 18 U.S.C. § 1028 (fraud in connection with identification documents; definition of means of identification)(govinfo.gov).gov
- 18 U.S.C. § 1028A (aggravated identity theft)(govinfo.gov).gov
- Dubin v. United States, 599 U.S. 110 (2023)(courtlistener.com)
- Ariz. Rev. Stat. § 13-2006 (criminal impersonation)(azleg.gov).gov
- Arizona Laws 2025, Chapter 184 (SB 1295)(azleg.gov).gov
- N.H. RSA 638:26-a (Fraudulent Use of Deepfakes)(gc.nh.gov).gov
- N.H. RSA 507:8-j (Civil Actions for Fraudulent Use of Deepfakes)(gc.nh.gov).gov
- N.H. RSA 651:2 (sentences and limitations)(gc.nh.gov).gov
- Utah Code § 76-2-107 (commission of offense with aid of generative artificial intelligence)(le.utah.gov).gov
- 18 U.S.C. § 2511 (interception of communications; party consent)(govinfo.gov).gov
- FTC Consumer Alert: Scammers use AI to enhance their family emergency schemes(consumer.ftc.gov).gov
- FTC ReportFraud(reportfraud.ftc.gov).gov
- FCC Consumer Complaint Center(consumercomplaints.fcc.gov).gov
- FBI Internet Crime Complaint Center (IC3)(ic3.gov).gov
- USA.gov: State consumer protection offices(usa.gov).gov
- USA.gov: State attorneys general(usa.gov).gov
- 28 U.S.C. § 1658 (Time limitations on the commencement of civil actions arising under Acts of Congress)(govinfo.gov).gov