Skip to content
Compliance

FCC One-to-One Consent Rule Is Dead: Insurance Leads Now

The FCC's one-to-one consent rule is vacated and repealed. Here is what changed, what didn't, and how to vet an insurance lead vendor's consent in 2026.

Mike Moore 19 min read
Mike Moore at a desk reviewing a lead vendor consent audit checklist on a monitor next to a glowing emerald voice waveform, representing TCPA prior express written consent compliance for insurance lead buyers

The FCC’s one-to-one consent rule, the regulation that would have made it functionally illegal for a comparison-shopping site to sell one consumer’s information to more than one insurance buyer, is dead. Not delayed, not paused, dead: vacated by the Eleventh Circuit on January 24, 2025, left unappealed by the FCC, and formally stripped out of the agency’s own rulebook on August 29, 2025. If you buy shared or aggregated insurance leads and you have spent the last two years bracing for a rule that would force every lead vendor to rebuild its consent flow, that rule is not coming. What replaced it is not “anything goes.” It is the same “prior express written consent” standard that has governed telemarketing robocalls since 2012, and most agencies buying leads today have never actually checked whether their vendors meet it.

This matters because the coalition that killed the rule was, literally, an insurance industry group. Insurance Marketing Coalition Limited describes itself in its own court filing as a consortium of more than twenty entities representing insurance lead generators, the merchants who buy from them, and the consumers who use comparison tools, and it took the FCC to the Eleventh Circuit specifically because the rule would have broken the shared-lead model a large part of ACA, Medicare, life, and final expense lead generation runs on. That is the industry you are buying from. Understanding what this case actually decided, and what it left completely untouched, is the difference between reading a regulatory headline and knowing what your own lead vendor contracts should say.

The short version

  • The FCC's 2023 "one-to-one consent" rule, which would have barred a consumer from authorizing more than one seller at a time and required calls to be "logically and topically associated" with whatever prompted the consent, was vacated by the Eleventh Circuit on January 24, 2025, in Insurance Marketing Coalition Ltd. v. FCC.
  • The court's mandate made the vacatur effective April 30, 2025. The FCC did not appeal, and on August 29, 2025 it published a Federal Register notice formally removing the rule from its own regulations.
  • The pre-2023 standard governs again: written, signed, disclosed "prior express written consent" under 47 CFR § 64.1200(f)(9), with no cap on how many sellers one form can authorize and no requirement that the subject matter be narrowly related to the page the consent was captured on.
  • None of this means a bought lead is automatically safe to call. It still needs a real, documented consent record, and the agency that dials, not the lead vendor, is the party exposed to the TCPA's $500-to-$1,500-per-violation statutory damages if that record does not hold up.
  • TCPA litigation is not a rare event: 2,810 TCPA suits were filed in 2025 alone. Using an AI caller does not transfer any of this liability away from the licensed agent.

Start with the phrase everything in this story turns on: “prior express written consent.” The Telephone Consumer Protection Act says you need the called party’s “prior express consent” before dialing or texting them with an autodialer or an artificial or prerecorded voice, but Congress never defined what that consent has to look like. The FCC filled that gap in 2012, ruling that for telemarketing and advertising robocalls specifically, “prior express consent” means “prior express written consent”: a signed agreement, in writing, that clearly authorizes the seller to deliver telemarketing messages using an autodialer or prerecorded voice, names the phone number, and carries a clear and conspicuous disclosure that the person is agreeing to get those calls. That 2012 standard is not new, it is not controversial, and it is not what this article is about. It is also the standard that governs today, because everything the FCC tried to bolt onto it in 2023 has since been torn back off.

In 2023, the FCC adopted a Second Report and Order that added two new restrictions on top of the 2012 written-consent rule, both aimed squarely at lead generation and comparison-shopping websites. The first, which the Eleventh Circuit’s opinion calls the “one-to-one-consent restriction,” said a consumer could authorize no more than one identified seller at a time. Checking one box that said “I consent to calls from Bank A and Bank B” would not count as valid consent for either bank; the consumer would have to check two separate boxes, one per seller, naming each one individually. The second, the “logically-and-topically-related restriction,” said that whatever calls the consumer consented to had to be logically and topically associated with the interaction that prompted the consent. The FCC’s own example: a consumer giving consent on a car-loan comparison site does not consent to get calls about loan consolidation, even if the same consent form clearly and separately authorized exactly that.

Why this specifically targeted insurance lead generation

Comparison-shopping sites for insurance work by collecting one consumer's information once, then selling access to that lead to several licensed agents or agencies who compete for the business. The 2023 rule's one-to-one restriction would have required a separate, individually named authorization for every buyer who might ever call, which the Eleventh Circuit's opinion notes is exactly the business model Insurance Marketing Coalition Limited's members, lead generators, buying merchants, and the comparison-shopping consumers themselves, told the court the rule would break.

Both restrictions applied only to telemarketing and advertising robocalls and robotexts, and both applied categorically, regardless of any other facts showing the consumer had, in plain terms, actually agreed to be called. That last part is what sank the rule in court.

Why the Eleventh Circuit vacated it

Insurance Marketing Coalition Limited challenged the 2023 rule on three grounds: that the FCC exceeded its statutory authority, that the rule violated the First Amendment, and that it was arbitrary and capricious under the Administrative Procedure Act. The court, in a January 24, 2025 opinion written by Judge Branch and joined by Judges Luck and Lagoa, ruled entirely on the first ground and did not need to reach the other two.

The court’s reasoning is worth understanding on its own terms, because it explains why this outcome is durable rather than a fluke. The TCPA requires “prior express consent,” full stop; it does not say “prior express consent, plus a one-seller limit,” and it does not say “prior express consent, plus a topical-relevance test.” The FCC’s authority under the statute is to “prescribe regulations to implement” the TCPA, and the court held that “implement” means to carry a law into effect, not to add new substantive conditions the statute itself never imposed. The court leaned on its own prior precedent, particularly Gorss Motels, Inc. v. Safemark Systems, LP, which had already held that a consumer can give one clear, unmistakable “prior express consent” that covers multiple, even loosely defined, entities at once, such as a hotel and its unnamed “affiliates.” One-to-one consent had never been part of what the TCPA, or the court’s own case law interpreting it, required.

"Agencies have only those powers given to them by Congress, and enabling legislation is generally not an open book to which the agency may add pages and change the plot line." But changing the plot line is exactly what the FCC tried to do here.

— Insurance Marketing Coalition Ltd. v. FCC, quoting West Virginia v. EPA, 597 U.S. 697 (2022)

Even the FCC’s own courtroom arguments undercut the rule. At oral argument, the FCC’s counsel was asked about a consumer who checks boxes consenting to calls from three separate mortgage companies, then checks a fourth box consenting to calls from a home-repair business. Counsel agreed the logically-and-topically-related restriction would have invalidated that fourth consent, then, separately, agreed that without the 2023 rule, the TCPA itself would allow it. That concession is a big part of why the court found the restrictions unlawful rather than merely debatable: the agency’s own lawyers admitted real, voluntary, clearly-stated consent was being invalidated by a test the statute never asked for.

The court granted the petition, vacated Part III.D of the 2023 order, and remanded to the FCC. It did not rule on the First Amendment or arbitrary-and-capricious arguments, because it did not need to once the statutory-authority argument succeeded.

The full timeline, start to finish

Timeline infographic showing five dated milestones for the FCC's one-to-one consent rule: 2023, FCC adopts the rule in its Second Report and Order; January 27, 2025, the rule's scheduled effective date per FCC Consumer and Governmental Affairs Bureau public notice; January 24, 2025, the Eleventh Circuit vacates the rule in Insurance Marketing Coalition Ltd v FCC, three days before it was due to take effect; April 30, 2025, the court's mandate makes the vacatur effective; August 29, 2025, the FCC publishes a Federal Register notice formally removing the vacated language from its own rules. Sourced to the Eleventh Circuit opinion and the Federal Register.
The one-to-one consent rule, adoption to repeal
Date Event
2023 FCC adopts Part III.D of its Second Report and Order, adding the one-to-one-consent and logically-and-topically-related restrictions to the 2012 "prior express written consent" definition
January 27, 2025 The rule's scheduled effective date, per the FCC Consumer and Governmental Affairs Bureau's public notice setting the compliance deadline
January 24, 2025 The Eleventh Circuit issues its opinion in Insurance Marketing Coalition Ltd. v. FCC, granting the petition for review and vacating Part III.D, three days before the rule was due to take effect
February–March 2025 Consumer advocacy groups move to intervene and seek rehearing en banc; the FCC itself declines to seek further review
April 22, 2025 The Eleventh Circuit denies the intervention motions as untimely under Federal Rule of Appellate Procedure 15(d)'s 30-day window
April 30, 2025 The court's mandate issues, making the vacatur of Part III.D formally effective
August 29, 2025 The FCC publishes 90 FR 42137, a Federal Register notice conforming its own codified rules to remove the vacated language; effective the same day

Read that sequence closely and one detail stands out: the rule was three days from taking effect when the court killed it. Agencies and lead vendors that had spent the prior year rebuilding consent-capture flows to comply were, in the space of a single week, told to stop.

With the 2023 restrictions gone, the standard that governs telemarketing and advertising robocalls and robotexts is the one the FCC adopted in 2012 and the Eleventh Circuit’s own precedent has interpreted consistently since: the consumer has to “clearly and unmistakably” state, before the call happens, that they are willing to receive it, in a signed writing (an electronic signature and a checked box both count) that names the phone number and discloses that checking the box means agreeing to autodialed or prerecorded telemarketing calls.

Two things that standard does not require, now that the 2023 additions are gone:

  • A one-seller limit. A consumer can lawfully check one box authorizing calls from multiple named sellers, or check a box that clearly identifies several sellers or affiliates, in a single form. What matters is that the authorization is clear and specific about who is being authorized, not that only one party is named.
  • A topical-relevance test. Consent captured on an auto-insurance quote page can lawfully cover a call about home insurance, life insurance, or any other product, provided the consent language actually and clearly said so. There is no requirement that the subject matter match the page the consumer was on.

What did not change: consent still has to be real

Nothing in this ruling relaxed the underlying requirement that consent exist and be documented. A pre-checked box, a consent disclosure buried where no reasonable person would read it, a form that never mentions telemarketing calls at all, or a lead sold from a site the consumer never actually visited, were illegal under the 2012 standard before the 2023 rule existed, and they are illegal under that same standard now. The one-to-one and topically-related restrictions were extra conditions layered on top of real consent. Killing them did not touch the floor underneath.

That distinction is the whole point of this article. Lead vendors and comparison-shopping sites are no longer required to rebuild their consent flows around a one-seller model, and most will not. But “the rule that would have forced stricter documentation is gone” is very different from “documentation no longer matters,” and a lot of agencies are going to read headlines like “one-to-one consent rule is dead” and hear the second thing when the first thing is what actually happened.

The TCPA is not the only federal rule in play

The FCC's vacated rule lived inside the TCPA. It is not the only federal seller-specific consent requirement on the books. The FTC's Telemarketing Sales Rule, at 16 CFR § 310.4(b)(1)(v)(A), has long required that written consent to receive a prerecorded-message telemarketing call evidence willingness to be called "by or on behalf of a specific seller." That provision predates the FCC's 2023 order, was not part of this case, and was untouched by the Eleventh Circuit's ruling. Whether it reaches a given insurance telemarketing call depends on a McCarran-Ferguson analysis of how much your state already regulates that specific activity, which is exactly the kind of question worth putting to counsel rather than guessing at. It is a narrower rule than the one this article is about, since it applies specifically to prerecorded-voice calls, not autodialed calls generally, but it is a reason not to treat "the FCC's rule is dead" as the end of the research.

Why this is your problem, not just your lead vendor’s

Here is the scenario worth sitting with. Your agency buys 200 shared ACA or Medicare leads a month from an aggregator. The aggregator’s landing page has a consent checkbox, a privacy policy link, and a list of “marketing partners” somewhere in a scroll box. You have never read that scroll box. You have never asked the vendor for a copy of the actual consent record tied to a specific lead. You call the lead, using an autodialer or a prerecorded or AI-generated voice, because that is how outbound calling works at any real volume.

If that consent turns out to be defective, forged, expired, or never actually disclosed telemarketing calls in the first place, the person who gets sued is not usually the aggregator sitting three steps upstream. It is the business that placed the call the consumer actually received. Vicarious liability under the TCPA has been applied to the party that benefits from a call even when a third party technically dialed it, and “our lead vendor told us their leads were compliant” is a claim you can raise against your vendor in a separate contract dispute, not a defense that makes a consumer’s TCPA claim against you go away.

What one non-compliant call actually costs, against what a call costs to place

Illustrative, built from this article's sourced figures: TheAffordableAI's published Single Account per-minute rate against the federal statutory damages range for one violation.

One 3-minute follow-up call, Single Account rate $0.60
TCPA statutory floor, one violation $500
TCPA willful-violation ceiling, one violation $1,500

Per-minute rate from TheAffordableAI's published pricing. Statutory damages per 47 U.S.C. § 227(b)(3). This is not legal advice and does not estimate your own exposure, which depends on your own consent and vendor documentation.

That gap, sixty cents to place a call against $500 to $1,500 in statutory exposure if the consent behind it does not hold up, is not a rounding error. It is per violation, meaning per call or per text, not per lawsuit, and a court can push it to the top of that range if it finds the conduct was willful or knowing. None of this depends on whether the call led to a sale.

Jan 24, 2025

Date the Eleventh Circuit vacated the one-to-one consent rule

Source: Ins. Mktg. Coal. Ltd. v. FCC, No. 24-10277

$500-$1,500

TCPA statutory damages, per violation

Source: 47 U.S.C. § 227(b)(3)

2,810

TCPA lawsuits filed in full-year 2025

Source: WebRecon LLC, Dec. 2025 year in review

20+

Member entities in the coalition that brought the case

Source: 11th Cir. opinion, describing IMC's own petition

Stat card showing four figures about the FCC one-to-one consent rule and TCPA risk: January 24, 2025 as the date the Eleventh Circuit vacated the rule in Insurance Marketing Coalition Ltd v FCC; 500 to 1,500 dollars in TCPA statutory damages per violation under 47 U.S.C. 227(b)(3); 2,810 TCPA lawsuits filed in 2025 per WebRecon LLC's year in review; and August 29, 2025 as the date the FCC formally removed the rule from its own regulations per the Federal Register.

TCPA litigation was not some rare event even before this case. WebRecon LLC, which tracks consumer-protection litigation filings, recorded 2,810 TCPA lawsuits filed in 2025, essentially flat against 2024. That volume did not depend on the one-to-one rule existing or not; it reflects ordinary TCPA enforcement against calls and texts that never had valid consent in the first place, which is exactly the exposure a sloppy lead vendor relationship creates regardless of what the FCC’s rulebook says about seller counts.

None of this requires hiring counsel to review every lead source, though counsel is worth involving if your agency runs meaningful bought-lead volume. You can run every step below yourself, this week, with the vendor relationships you already have.

  1. Ask for the actual consent language, not a summary of it. A reputable vendor can show you the exact checkbox text and disclosure the consumer saw at the moment they submitted their information. If a vendor cannot produce that, or resists sharing it, that is your answer.
  2. Check whether the disclosure actually says “telemarketing” or “autodialed calls.” Consent to “receive information” or “get a quote” is not the same as consent to receive autodialed or prerecorded telemarketing calls. The FCC’s 2012 standard requires the written agreement to include a clear and conspicuous disclosure of exactly what the consumer is agreeing to.
  3. Confirm whether the box was pre-checked. A pre-checked consent box has never satisfied “clearly and unmistakably stated” consent under the FCC’s or the courts’ reading of the TCPA, one-to-one rule or not. This is worth asking about directly, because it is a common shortcut on older or lower-quality lead-gen sites.
  4. Find out how long the vendor retains the consent record, and whether you can get a copy per lead. If a lead you called eighteen months ago becomes the subject of a demand letter, “the vendor probably still has it” is not a plan. Ask what the retention window is before you buy, not after a dispute starts.
  5. Read your lead-purchase agreement’s indemnification clause with a skeptical eye. Many vendor contracts include language that sounds like it shifts TCPA liability to the vendor. It may reduce your practical recovery odds in a dispute, but it does not change who a consumer can sue in the first place; that is determined by who placed the call, not by your private contract.
  6. Treat multi-buyer, comparison-shopping leads differently from single-buyer, exclusive leads. A lead sold to several agencies at once is the exact model this whole legal fight was about protecting. That is not a reason to avoid it, the court just confirmed it is lawful, but it is a reason to be more, not less, careful about the consent record behind it, since more parties are relying on the same consent to make the same calls.

You can build all six of these into a one-page vendor checklist yourself, and plenty of agencies already do exactly that before they ever wire a payment to a new lead source. If part of your list is an older, previously-purchased database rather than fresh buys, the aged insurance leads guide on this site covers the separate question of what is legal to call again months or years later.

Before and after: the same agency, two ways of buying leads

Unverified lead buying

How most agencies buy shared leads today

  • Leads purchased from an aggregator based on price and volume, not documented consent quality
  • Nobody at the agency has read the actual checkbox language on the vendor's landing page
  • No process to request a per-lead consent record if a call is ever challenged
  • Indemnification clause in the vendor contract assumed to cover TCPA exposure, never actually tested

UnverifiedWhether the consent behind a purchased lead would hold up

Vendor-vetted lead buying

The same agency, with a one-page vendor consent checklist

  • Vendor consent language, disclosure text, and pre-check status confirmed before the first purchase
  • A documented retention window and a known process to request a per-lead consent record
  • Indemnification language read and understood as a contract remedy, not a liability transfer
  • Every outbound call logged with a disposition and transcript, ready if a consent dispute ever surfaces

DocumentedA defensible answer if a purchased lead's consent is ever challenged

Could a version of this rule come back?

Treat this as a live question, not a settled one, even though nothing currently pending would revive it. No party petitioned the Supreme Court for review of the Eleventh Circuit’s decision. The FCC itself chose not to seek further review of its own loss. A coalition of consumer advocacy groups, including the National Consumers League, tried to intervene after the fact to pursue rehearing en banc, and the court denied that motion in April 2025 because it came more than 30 days after the original petition for review, missing the deadline set by the Federal Rules of Appellate Procedure. And rather than leaving the vacated language sitting in limbo, the FCC affirmatively conformed its own codified rules in August 2025 to remove it, which is a stronger signal than silence would have been.

This is a separate question from whether a lead you already have permission to call can later have that permission withdrawn; the TCPA revoke-all rule guide on this site covers the current and upcoming rules on honoring a revocation once one arrives. None of that forecloses a future FCC writing a narrower rule aimed at the same underlying concern, lead-generation consent chains that obscure who is actually going to call a consumer, in a way built to survive the same statutory-authority challenge that sank this one. That would be a new rulemaking with its own notice-and-comment process, not a revival of the vacated 2023 order, and there is nothing on the FCC’s public docket right now suggesting one is imminent. The practical takeaway is not “this will never change again.” It is that the standard governing your lead purchases today is the 2012 written-consent rule, plainly, and building your vendor-vetting process around that rule is not wasted effort even if a future rule eventually adds new conditions on top of it.

Where TheAffordableAI fits

Vetting a lead vendor’s consent language is a procurement and legal-review decision, and no calling platform, including ours, makes that decision for you. What a managed AI caller can do is make what happens after you buy a lead more defensible. Every call TheAffordableAI places gets logged against the lead’s record automatically, including disposition and any language spoken on the call, and that log syncs natively with HighLevel instead of sitting in a separate system someone has to reconcile after the fact. If a consumer or their attorney ever challenges a call, having a complete, timestamped record of exactly what was said and when is a materially better position than a gap in your CRM. The full list of what is included on every plan is on the features page.

Native HighLevel CRM sync

Every call, disposition, and transcript lands in the CRM automatically, ready to produce if a purchased lead's consent is ever disputed.

Multi-calendar intent routing

Route ACA, Medicare, life, and P&C leads to the right calendar and the right licensed agent instead of one undifferentiated queue.

Warm transfers and auto-booking

A lead that clears your own vendor-vetting process gets connected to a licensed agent live, or booked against real calendar availability.

Number warmup and spam defense

Calling a purchased list at volume without your caller ID getting flagged is its own problem; warmup and spam defense run as a standing routine on every plan.

Hear what a compliant follow-up call sounds like

There is a live demo call on the homepage. Listen to it, then decide whether your current lead-buying process actually documents the consent behind the leads you are dialing.

Pricing is published, not quoted privately: a Single Account runs $200 a month plus a $500 one-time setup fee, at $0.20 a minute, down to $0.15 a minute at bulk volume. An Agency plan, which routes to 20-plus agents at once, runs $500 a month plus a $1,000 one-time setup fee, at $0.18 a minute, down to $0.16 a minute at bulk. Both are month to month with no long-term contract, so testing whether better call documentation is worth it to your agency costs, at most, one month either way. You can also build a version of this yourself with a spreadsheet and a disciplined process, and plenty of agencies do exactly that rather than change how they operate over it. It is worth pricing both.

When this article is not enough, and when AI calling is the wrong tool

Be honest about the limits of what any of this solves. If your agency’s actual problem is that a specific lead vendor has a track record of selling low-quality or improperly consented leads, the fix is finding a better vendor or building your own lead generation, not layering more call-logging on top of a bad source. And if you are buying leads at a scale where a serious consent-compliance review makes sense, that review belongs with an attorney who has actually read your specific vendor agreements, not a blog post, however well sourced. No AI caller and no CRM feature substitutes for that judgment call, and spending money on new calling infrastructure to paper over a vendor relationship you should not be in is not a good trade.

Using AI does not transfer liability

The one-to-one consent rule's death changes what a lead vendor is legally required to build. It does not change who is responsible for verifying that real, documented consent exists before a call goes out. Prior express written consent, Do Not Call compliance, and TCPA liability stay the responsibility of the licensed agent and agency, whether a human or an AI places the call. Medicare campaigns carry CMS's own rules on top of all of this, including the TPMO disclaimer and call-recording requirements. An automated caller does not carry any of that responsibility away from you.

The rule that would have forced every insurance lead vendor to rebuild its consent flow around a one-seller model is not coming back on any timeline anyone can currently point to. That is genuinely good news for the shared-lead economy a lot of agencies depend on. It is not a reason to stop asking your vendors the questions their own consent records should already answer. The standard has not gotten stricter since this case, but it has not gotten looser either: it is the same written, disclosed, specific consent requirement that has applied since 2012, and it is worth knowing whether the leads you are buying this month would actually survive someone asking to see it.

Frequently asked

What was the FCC's one-to-one consent rule?

It was Part III.D of the FCC's 2023 Second Report and Order under the TCPA, which would have redefined 'prior express written consent' to add two new restrictions on top of the existing 2012 written-consent requirement: a consumer could authorize only one seller at a time to call or text them, and any calls had to be on a subject 'logically and topically associated' with whatever interaction prompted the consent. In practice, it targeted the comparison-shopping and lead-aggregator model where one consumer form generates leads sold to many buyers.

Is the one-to-one consent rule in effect in 2026?

No. The Eleventh Circuit Court of Appeals vacated Part III.D of the rule on January 24, 2025, in Insurance Marketing Coalition Ltd. v. FCC, and the court's mandate made that vacatur effective April 30, 2025. The FCC chose not to appeal, and on August 29, 2025 it published a Federal Register notice formally conforming its own regulations to remove the vacated language. The rule does not exist in any form as of this writing.

What does 'prior express written consent' require right now, without the one-to-one rule?

The standard that has applied since 2012 and still applies today: a signed, written agreement (electronic signatures count) that clearly authorizes the specific seller or sellers to call or text using an autodialer or a prerecorded or AI-generated voice, names the phone number the consent covers, and includes a clear and conspicuous disclosure that the box-check or signature means agreeing to receive telemarketing calls. A consumer can lawfully authorize multiple sellers in one form, and the subject matter does not have to be narrowly related to the page they were on.

Who was Insurance Marketing Coalition Limited, and why did an insurance group bring this case?

IMC describes itself, in its own petition, as a consortium of more than twenty entities representing a cross-section of insurance industry stakeholders, including lead generators, the merchants who buy leads from them, and consumers who use comparison-shopping tools. The 2023 rule would have made the multi-buyer comparison-shopping model that a large share of insurance lead generation runs on functionally unworkable, which is why an insurance trade coalition, not a telecom company, was the one that took the FCC to court.

If the rule is dead, does that mean bought insurance leads are automatically safe to call?

No. Killing the one-to-one and topically-related restrictions did not touch the underlying requirement that real consent exist in the first place. A lead with no genuine consent record, a forged checkbox, a pre-checked box, or a consent form that never disclosed telemarketing calls was illegal before this rule and is illegal after it. What changed is narrower than it sounds: a lead vendor can legally sell one consumer's information to multiple buyers again, but the vendor still has to be able to produce a real, disclosed, written consent record if a call is ever challenged.

Who is liable if a lead vendor's consent turns out to be defective?

The party that places the call, which in most fact patterns is the insurance agent or agency, not the lead vendor. Vicarious liability under the TCPA has repeatedly been extended to the business that benefits from the call, and 'the lead vendor told us it was compliant' is a contract dispute with your vendor, not a defense to a consumer's TCPA claim. That is exactly why 47 U.S.C. § 227(b)(3)'s $500-to-$1,500-per-violation statutory damages exposure runs to the agency that dialed, and it is worth reading your lead vendor agreement's indemnification language with that in mind.

Could a one-to-one consent rule come back?

It is not guaranteed to stay gone forever, but nothing currently pending would bring it back. No party sought Supreme Court review of the Eleventh Circuit's decision, the FCC's own attempt to intervene in support of rehearing was denied as untimely, and the FCC's August 2025 Federal Register notice affirmatively removed the rule from its own regulations rather than leaving it in limbo. A future FCC could try to write a narrower version that survives the same statutory-authority challenge, but that would be a new rulemaking, with its own comment period and its own timeline, not a revival of this one.

Does using an AI voice agent change any of this?

No. Consent, vendor vetting, and TCPA liability stay the responsibility of the licensed agent and agency placing the call, whether the caller is a human or an AI. An AI caller does not transfer that liability away from you. What a well-built AI calling setup can do is log a full disposition and transcript against every lead automatically, which is useful documentation if a consent dispute ever surfaces, but it does not replace the vendor-vetting work this article walks through.

Sources

  1. United States Court of Appeals for the Eleventh Circuit — Insurance Marketing Coalition Ltd. v. FCC, No. 24-10277 (opinion filed January 24, 2025)
  2. United States Court of Appeals for the Eleventh Circuit — Order denying motions to intervene, No. 24-10277 (filed April 22, 2025)
  3. Federal Register — Federal Communications Commission, 90 FR 42137, "Delete, Delete, Delete..." (published August 29, 2025)
  4. Federal Communications Commission — Consumer and Governmental Affairs Bureau, "One-to-One Consent Rule for TCPA Prior Express Written Consent: Frequently Asked Questions" (posted December 23, 2024)
  5. Cornell Law School Legal Information Institute — 47 U.S.C. § 227, Telephone Consumer Protection Act
  6. Cornell Law School Legal Information Institute — 16 CFR § 310.4, FTC Telemarketing Sales Rule, prerecorded-message consent requirement
  7. WebRecon LLC — December 2025 Stats & Year in Review (full-year 2025 TCPA litigation filings)
  8. TheAffordableAI — Pricing

Put this on your own phone line

See the AI dial, qualify, and warm-transfer a live call in under a minute. No contract, no dev work.

← All articles