Industry Insights10 min read

India's Voice AI Compliance Playbook 2026: What Enterprises Need to Know Before Deploying AI Voice Calls

N

Naveen Kumar R

2026

India's Voice AI Compliance Playbook 2026: What Enterprises Need to Know Before Deploying AI Voice Calls

This article is for educational and informational purposes only and does not constitute legal or regulatory advice. Requirements vary by enterprise, industry, calling purpose, data flows and technology architecture. Talk to your own legal and compliance advisors before finalising a deployment.

"Is AI voice calling legal in India?" That question comes up in almost every vendor call, board deck, and legal review before a company puts an AI voice agent on live customer calls. The honest answer is: it depends , not on some special "AI calling law," because no such law exists in India, but on the same things that have always governed a phone call here. Who you're calling. Why you're calling them. What you record. Where that data goes afterward. And which regulator already oversees your industry.

That's actually useful news. TRAI's telecom rules, the Digital Personal Data Protection (DPDP) Act, and RBI's and IRDAI's sector rules weren't written with AI voice agents in mind, but they apply anyway. Deploying voice AI means mapping a deployment against rules that predate it, adding the few things that are genuinely new (like what happens to a transcript once it reaches a language model), and being honest about what's settled law, what's regulatory expectation, and what's still catching up.

This is a working reference for exactly that mapping, built for the legal, compliance and procurement teams who have to sign off before a single outbound AI call goes out.

Yes. There is no statute or TRAI regulation that prohibits using AI to place or receive phone calls in India. What's regulated isn't the "AI" part of the call , it's the same things that were already regulated when a human agent made it: the telecom channel used to place it, the personal data collected during and after it, and, in regulated sectors, the conduct rules that already apply to customer communication.

Bottom line: an AI voice deployment is legal in India when it follows the same telecom registration, consent and data-handling rules that any calling program has to follow, plus the additional data-processing questions that come from routing a conversation through speech-to-text, a language model, and text-to-speech. There's no separate "AI calling licence," and Indian telecom law doesn't currently single out AI-generated speech for different treatment than a human voice on the same call.

The India Voice AI Compliance Stack

Before diving into each regulator, it helps to see the whole stack at once , because most compliance failures happen when a team optimises for one layer (usually TRAI/DLT) and misses the others.

Compliance layerRelevant authority / frameworkWhat it affectsVoice AI implication
Telecom commercial communicationTRAI , Telecom Commercial Communications Customer Preference Regulations (TCCCPR), 2018, as amended, plus the Distributed Ledger Technology (DLT) ecosystemSender registration, consent, Do Not Disturb, promotional vs. service classificationEvery outbound campaign needs a registered Principal Entity, sender header and content template , regardless of whether a human or an AI agent delivers the script
Numbering for regulated sectorsTRAI / DoT , 1600-series (BFSI & Government) and 1601-series (other sectors, from Aug 2026) directionsWhich number range different sectors must use for service and transactional callsBFSI and insurers stay on 1600; utilities, courier and logistics firms are now migrating to 1601, and TRAI has signalled the model will keep expanding to more sectors
Personal dataDigital Personal Data Protection Act, 2023 + DPDP Rules, 2025Notice, consent, purpose limitation, retention, breach reporting, data principal rightsCall recordings, transcripts and phone numbers are personal data; how they're processed, stored and eventually deleted falls under this Act as its provisions phase in through 2027
Banking & NBFC conductRBI , Fair Practices Code, outsourcing directions, Digital Lending Guidelines, and the (advisory) FREE-AI reportCalling hours, agent conduct, vendor accountability, AI governance expectationsA bank or NBFC is responsible for what its AI vendor does on a collections or verification call, exactly as it already is for a human calling agent
Insurance conductIRDAI , Protection of Policyholders' Interests, Operations and Allied Matters of Insurers Regulations, 2024, and the related Master CircularDisclosure, grievance handling, outsourcing oversight, solicitation conductInsurers and their agency partners stay accountable for what an AI pitch says, even when a vendor like Goodbox built the flow
Synthetic / AI-generated contentMeitY , IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026Labelling and provenance requirements for AI-generated audio/video published on intermediary platformsDoesn't apply to a live phone call itself, but matters the moment AI-generated voice content is published or shared on a platform

TRAI and Telecom Rules: What Enterprises Need to Check

TRAI doesn't have a category called "AI calling." It regulates commercial communication over telecom networks, and an AI voice agent is just another way of delivering that communication. The core mechanics haven't changed:

Registration. Any business sending promotional commercial communications , calls or messages , needs to register as a Principal Entity on the DLT platform, register its telemarketers, and register the sender header and content template for that campaign. This applies whether the script is read by a human agent or generated by an AI voice agent; the DLT ecosystem doesn't distinguish between the two. Worth being precise here: this duty attaches to the promotional/commercial category specifically. Genuine service and transactional calls , the ones covered by the 1600/1601-series numbering rules below , sit outside this apparatus, in a different, narrower compliance lane. Getting that classification right, covered in the Promotional vs. Service table further down, determines which of these two paths a given campaign actually needs.

Consent and DND. Promotional calls to numbers on the National Customer Preference Register (India's Do Not Disturb list) remain restricted unless the recipient has given explicit, documented consent for that specific category of communication. TRAI's Second Amendment to the TCCCPR (February 2025) tightened enforcement considerably , it lowered the complaint threshold that triggers action against a sender, gave TRAI the power to act directly against a non-compliant sender rather than only through the telecom operator, and narrowed how long a customer's explicit consent for a commercial transaction stays valid. A further Third Amendment, released for public consultation in March 2026, proposes tightening this further and is, as of this writing, still working its way through TRAI's review process rather than being final law , worth rechecking at publish time.

Promotional vs. service. This distinction matters more for AI voice than almost anything else in the stack, because it decides which registration path and which number series a call needs. We cover this in detail in the table below.

The 1600-series , and now 1601-series , requirement. In late 2025, TRAI directed entities regulated by RBI, SEBI and PFRDA , and, separately, by IRDAI , to move their genuine service and transactional calls onto the 1600 numbering series rather than standard 10-digit numbers. The IRDAI deadline was 15 February 2026, and it has already passed. If your BFSI or insurance client is using Goodbox (or any vendor) for service calls , payment confirmations, renewal reminders, fraud alerts , those calls should already be routed through a 1600-series number, not a generic outbound line.

This part of the framework moved again in 2026: on 10 August 2026, TRAI directed telecom operators to begin onboarding entities in sectors other than BFSI and government onto a new 1601 series for the same category of service and transactional calls, starting with utilities (electricity, water, gas, LPG distribution) and courier/logistics firms in Phase I, with a 90-day onboarding window for telecom operators. 1600 stays reserved for BFSI and government; 1601 is the new lane for everyone else, and it can't be used for promotional calls either. Only utilities and logistics are covered so far , TRAI hasn't named the next sectors , but the direction of travel is clear: the "trusted numbering" model is expanding well beyond BFSI, and enterprises in recruitment, real estate, BPO or e-commerce should expect their own sector to eventually be pulled into some version of this framework rather than assume it stops at banking and insurance.

Network-side AI detection. Since early 2026, TRAI has directed telecom operators themselves to run AI/ML systems that flag suspicious calling patterns , high volume, unusual velocity, inconsistent caller-ID use , and share that intelligence across networks within hours. This obligation sits with the telecom operators, not with enterprises or voice AI vendors directly. But it means a poorly configured AI campaign (rapid-fire dialling, rotating numbers, no registered header) can now get throttled or flagged by the network itself, before a single customer complaint is filed.

DPDP and Voice Data: What Happens to Recordings and Transcripts?

A voice call generates more personal data than most teams initially account for: the phone number, the voice recording itself, the transcript, whatever the caller says (which can include health, financial, or other sensitive details depending on the use case), and any metadata your CRM attaches afterward. Under the DPDP Act, all of this is personal data, and the enterprise initiating the call is typically the data fiduciary , the party that decides why and how the data is processed , while a voice AI platform processing that data on the enterprise's behalf is typically a data processor.

Here's where it gets specific to voice AI: the moment a call is transcribed and sent to a large language model for understanding or response generation, that LLM provider becomes part of the processing chain too, often as a sub-processor. If that model is hosted by a third party, your data-processing agreement with your voice AI vendor needs to say what happens to that transcript once it leaves your vendor's systems , is it used to improve someone else's model, retained by the model provider, or discarded after the response is generated? This is one of the most commonly overlooked questions in voice AI procurement, and it's worth asking explicitly (see the vendor checklist below) rather than assuming.

A practical example: an NBFC runs an outbound EMI reminder campaign through an AI voice agent. The call itself is a service communication, so it's exempt from some of the promotional-consent machinery under TRAI's rules. But DPDP still applies to everything that happens with the data generated by that call , the recording, the transcript noting whether the customer promised to pay, and the phone number itself. The NBFC needs a clear, documented purpose for retaining that data, a defined retention period, and a way to delete it once that purpose is served , separate from, and in addition to, its telecom obligations.

It's worth being precise about timing here, because the Act didn't commence in one move. The government's commencement notification (G.S.R. 843(E), 13 November 2025) staggers it across three tiers, and the DPDP Rules, 2025 follow the same structure:

Commencement tierWhat it coversStatus as of September 2026
Immediate (13 Nov 2025)Definitions; constitution and powers of the Data Protection Board; the penalty, appeals and enforcement framework; Rules 1, 2 and 17–21 of the DPDP RulesIn force
+1 year (13 Nov 2026)Consent-withdrawal mechanics (Section 6(9)); one specific grievance-redressal duty (Section 27(1)(d)); Consent Manager registration (Rule 4)Not yet in force , a couple of months out as of this writing
+18 months (13 May 2027)Notice and consent standards, core data-fiduciary obligations, security safeguards, breach notification, retention and erasure, most data-principal rights, cross-border transfer rules (Sections 3–17, 27–37 and Rules 3, 5–16, 22–23)Not yet in force

In practice: the Data Protection Board and its penalty powers already exist, but the detailed notice-and-consent machinery most teams picture when they think "DPDP compliance" doesn't formally bind data fiduciaries until May 2027. That's a reason to build the right architecture now, while there's still runway , not a reason to wait until the deadline forces it.

Call Recording, Transcription and LLM Processing

It helps to think of an AI voice call as a pipeline, because each stage carries a different compliance question:

Call → Recording → Transcript → AI processing → CRM → Analytics

  • Call: Is this number on a DND list, and if so, does this specific communication qualify for an exemption (service/transactional) or does it need documented consent?
  • Recording: Is the customer aware the call may be recorded, consistent with standard telecalling practice, and is that awareness itself logged somewhere retrievable?
  • Transcript: Once speech becomes text, it becomes far easier to search, copy, and repurpose , which is exactly why purpose limitation matters here specifically.
  • AI processing: Which model processed this transcript, where is that model hosted, and does the contract with that provider say the data isn't retained or used for training beyond the specific request?
  • CRM: Once the outcome lands in a CRM record, who inside the organisation can see it, and for how long?
  • Analytics: Aggregated or anonymised analytics carry a different (lighter) compliance burden than raw transcripts , but only if the anonymisation is real, not just a stripped name field with the phone number still attached.

Most compliance gaps in voice AI deployments don't happen at the "call" stage, where everyone is already paying attention to TRAI and consent. They happen two or three steps downstream, where the data has already changed form and nobody re-asked the compliance question.

What Changes for Banks, NBFCs and BFSI?

Short version: not as much as some vendor marketing suggests, and not as little as some deployment teams assume.

RBI has not issued a dedicated set of "AI calling rules." What it has done, in August 2025, is publish the FREE-AI Committee Report , a set of seven guiding principles and 26 recommendations on how AI should be governed across RBI-regulated entities. This is currently advisory, not a binding Master Direction, though RBI has signalled it may convert parts of it into supervisory expectations or formal directions over time. Treat it as a strong signal of direction, not as an enforceable rulebook today.

What is already binding, and applies to AI voice exactly as it applies to a human calling agent, is RBI's existing Fair Practices Code and outsourcing framework:

  • Recovery and collections calls cannot be made before 8:00 am or after 7:00 pm.
  • Agents (human or automated) cannot harass, intimidate, or publicly shame a borrower, or contact their employer or family to pressure repayment.
  • The regulated entity , the bank or NBFC , remains fully responsible for what its outsourced vendor does on a call made in its name. Deploying an AI voice platform doesn't transfer that liability.
  • RBI's Digital Lending Guidelines separately restrict lenders (and their apps) from accessing a borrower's contact list or photos for recovery purposes, and prohibit shaming tactics , relevant context for any AI-driven collections workflow.

Add the 1600-series requirement covered above, and standard expectations around auditability (every call following approved scripting, being fully recorded, and being available for review) and grievance handling, and you have the actual, current BFSI compliance surface for voice AI , most of which predates AI entirely and simply needs to be re-checked against an automated calling program instead of a human one.

What Changes for Insurance Companies?

IRDAI's core framework here is the Protection of Policyholders' Interests, Operations and Allied Matters of Insurers Regulations, 2024, and its accompanying Master Circular from September 2024, which consolidated roughly thirty older circulars into one document. It covers disclosure requirements, claims turnaround times, grievance redressal, and , relevant here , the conditions under which insurers can outsource activities to third parties, including a requirement for board-approved outsourcing policies and ongoing oversight of vendors.

What's an existing, settled requirement: insurers and their agents/intermediaries are expected to comply with TRAI's telemarketing and DND rules, avoid unregistered telemarketers, and route genuine service and transactional calls through the 1600-series numbers TRAI mandated (deadline: 15 February 2026, already passed). Grievance handling and outsourcing oversight obligations under the 2024 regulations apply in full to any AI-driven calling program run on an insurer's behalf.

What's an open operational question rather than settled law: exactly how AI-generated pitches should be scripted to stay within IRDAI's disclosure expectations, how "genuine interest" captured by an AI agent should be documented for audit purposes, and what level of human sign-off a regulated product pitch needs before an AI agent can deliver it. IRDAI has not issued AI-specific calling regulations, and be cautious of content claiming otherwise , several vendor blogs currently in circulation cite a specific "AI-focused IRDAI master circular" with granular scripting requirements that we could not verify against IRDAI's actual published circulars.

What's genuinely evolving: expect IRDAI's general regulatory posture on outsourcing and conduct to tighten as AI-driven sales calling becomes more common in the market, following the same direction RBI has signalled through FREE-AI for the banking side.

Promotional Calls vs. Service Calls

This classification decides almost everything downstream , which number series to use, whether DND scrubbing applies, and what kind of consent record you need. It is also the single most common thing enterprises get wrong when they move a calling program from a human team to an AI one, because a script that felt "informational" often reads as promotional under TRAI's framework.

The numbering side of this got clearer in mid-2026. TRAI's 10 July 2026 clarification confirmed that the 140-series is the number range meant for promotional calls specifically , distinct from, and not to be confused with, the 1600/1601-series reserved for service and transactional calls covered earlier. A promotional campaign that's fully DLT-registered but still dialling out from a standard 10-digit number is missing this piece; the classification in the table below determines not just the consent path but which numbering series the call should ride on.

ExamplePurposeCompliance questions to evaluate
EMI reminderService / transactionalIs this purely a payment reminder, or does the script also cross-sell? Is it going out on a 1600-series number if the lender is RBI-regulated?
Sales outreach (cold or warm)PromotionalIs the Principal Entity, header and template registered on DLT? Is the call originating from a registered 140-series number? Is the number DND-scrubbed? Is there documented, purpose-specific consent?
Insurance renewal reminderService / transactionalIs this strictly a renewal notice, or does it introduce a new product? The moment it upsells, it likely needs promotional treatment
Insurance upsell / cross-sellPromotionalSame DLT, 140-series numbering and consent requirements as any sales call , being an existing customer does not automatically create standing consent for a new product pitch
Candidate screening callNeither , falls outside TCCCPR's commercial-communication scopeConsent to be contacted about a specific job application, clarity on how the recording will be used in the hiring decision
Support callback (customer-initiated)ServiceGenerally lower-friction, but the recording and any data captured during the call are still subject to DPDP

When in doubt, the safer default is to treat a call as promotional and register it accordingly , the cost of over-registering is negligible; the cost of a misclassified sales call reaching a DND number is not.

15 Questions to Ask Your Voice AI Vendor Before Deployment

Copy this into your procurement checklist.

  1. Is our Principal Entity, sender header, and call script template registered on the DLT platform for this specific use case?
  2. Which number series will this campaign use, and is it appropriate for our regulatory category (service vs. promotional)?
  3. How is consent captured, stored, and made retrievable if a customer disputes having agreed to be contacted?
  4. Which speech-to-text, language model, and text-to-speech providers process our call data, and where are they hosted?
  5. Is our call data used to train any model , yours, or a third-party provider's , and if so, can that be turned off?
  6. What is the default retention period for call recordings and transcripts, and can we set our own?
  7. Where is our data stored at rest , specifically, is it kept within India?
  8. Who has access to raw call recordings and transcripts inside your organisation, and is that access logged?
  9. What sub-processors are involved in this pipeline, and do our contracts flow down our data-protection obligations to them?
  10. What happens to our data if we terminate the contract , deletion timeline, and proof of deletion?
  11. What independent security testing has been performed on the platform, and can a summary be shared under NDA?
  12. What is your incident-response process if a data breach involves our customers' call data, and what are your notification timelines?
  13. Can every call be reconstructed for audit , script version, recording, transcript, consent record, and outcome , on request?
  14. Under what conditions does the AI hand off to a human agent, and how much context does that human receive?
  15. What documentation can we hand to our own compliance and legal teams to support our regulatory filings?

Build Your Voice AI Compliance Matrix

A simple, living document , not a one-time audit , tends to work better than a static policy PDF. A minimal version looks like this:

ControlOwnerEvidenceStatus
Use-case definition (what is this campaign for)Business ownerWritten use-case brief
Communication classification (promotional / service / transactional)ComplianceClassification memo
Telecom mapping (DLT registration, number series)Telecom/ITDLT registration certificate
Data mapping (what's collected, where it flows)Data protection officerData flow diagram
Consent / notice mechanismCompliance + vendorConsent capture logs
Recording policyComplianceRecording disclosure script
Retention scheduleData protection officerRetention policy document
Vendor and sub-processor listProcurementSigned DPA + sub-processor register
Security postureInfoSecCertifications, pen-test summaries
Human escalation pathOperationsEscalation SOP
Audit trailComplianceSample call reconstruction
Incident response planInfoSec + LegalIR runbook

Common Voice AI Compliance Mistakes

Treating a sales pitch as a service call. The easiest way to end up on the wrong side of TRAI's rules is to write a "renewal reminder" script that quietly introduces a new product, then run it as a service communication. If the script sells anything, register it as promotional.

Assuming the vendor's compliance covers you. A voice AI platform's own certifications and data practices matter, but they don't substitute for the enterprise's own obligations as the data fiduciary. Ask for documentation; don't assume it exists.

No documented consent trail. Verbal consent captured mid-call is fine in principle, but if it isn't stored as a retrievable artifact , timestamped, tied to the specific call , it's very hard to demonstrate later if a customer disputes it.

Retention by default, not by design. The most common gap we see isn't over-retention out of malice; it's simply never having decided a retention period at all, so recordings and transcripts accumulate indefinitely. Set a number, document why, and stick to it.

No human off-ramp for regulated conversations. An AI agent that keeps pushing forward on a collections dispute or an insurance complaint, instead of routing it to a human, creates both a compliance and a customer-experience problem at the same time. Build the handoff trigger before launch, not after the first complaint.

What Enterprises Should Monitor Through the Rest of 2026

Clear and already applicable today:

  • TRAI's TCCCPR framework, DLT registration, and DND rules
  • The 1600-series requirement for RBI-, SEBI-, PFRDA- and IRDAI-regulated entities (deadlines already passed)
  • The 1601-series direction issued 10 August 2026 for non-BFSI, non-government sectors (Phase I onboarding underway)
  • TRAI's 10 July 2026 clarification that the 140-series is reserved for promotional calls, distinct from the 1600/1601-series for service and transactional calls
  • RBI's Fair Practices Code calling-hour and conduct restrictions
  • IRDAI's Protection of Policyholders' Interests Regulations and Master Circular
  • The DPDP Act's Data Protection Board, penalty framework and appeals structure

Evolving , worth monitoring closely:

  • TRAI's Third Amendment to the TCCCPR, still in draft as of mid-2026 and expected to finalise soon
  • Which sectors TRAI adds to the 1601-series framework after Phase I (utilities, courier and logistics)
  • The DPDP Act's consent-withdrawal mechanics and Consent Manager framework, due to commence 13 November 2026
  • The DPDP Act's core notice, consent and data-fiduciary obligations, due to fully commence 13 May 2027
  • Whether RBI converts any FREE-AI recommendations into binding Master Directions or circulars
  • Whether IRDAI or SEBI issue AI-specific guidance of their own, following RBI's lead

None of the items in the second list are law yet. Don't build a compliance narrative , internal or public-facing , that treats them as if they already are.

How Goodbox Approaches Enterprise Voice AI

Compliance in a voice AI deployment is a shared responsibility between the enterprise, the voice AI platform, the underlying telecom ecosystem, and any third-party AI providers involved in the pipeline. No single party owns all of it, and no vendor's platform makes an enterprise's DPDP or TRAI obligations disappear.

Goodbox's role in that chain is the calling and conversation layer: routing calls, handling the conversation, recording it, and syncing outcomes back into a customer's CRM or CCaaS stack. On the BFSI and insurance and loan sales side specifically, Goodbox's platform is built around the reality that these are regulated conversations , every call follows approved scripting, is fully recorded, and is designed to be auditable, with the AI explicitly scoped to pitch, qualify and inform rather than provide regulated financial advice or make binding commitments; that stays with licensed human agents. Customer call and transcript data is stored within India, and Goodbox's platform is ISO 27001 certified.

What we'd rather not do is claim more than that in a single blog post. If you're evaluating Goodbox for a regulated use case, the honest next step is a conversation with our team about your specific compliance requirements , data residency, retention, consent handling, and audit needs , rather than taking marketing copy as a substitute for your own due diligence.

Talk about deploying Voice AI for your enterprise

Frequently Asked Questions

Is AI voice calling legal in India?

Yes. There is no law prohibiting the use of AI to make or receive phone calls. The same telecom, data protection, and sector-specific rules that apply to any calling program apply to an AI-driven one.

Does TRAI regulate AI voice calls specifically?

No , TRAI regulates commercial communication over telecom networks generally, through the TCCCPR and the DLT ecosystem. It doesn't have a distinct legal category for AI-generated calls; the existing registration, consent, and DND rules apply regardless of who or what is speaking.

Do AI voice agents need consent to call someone?

It depends on the classification of the call. Promotional calls to a number on the Do Not Disturb registry require documented, purpose-specific consent. Genuine service or transactional calls have more limited consent requirements under telecom rules, though DPDP's data-processing obligations still apply to whatever personal data the call generates.

Does the DPDP Act apply to voice recordings and transcripts?

Yes , recordings, transcripts and phone numbers are all personal data under the Act. The Board and penalty framework are already in force; the rest phases in through 2027 (see the commencement-tier table earlier in this article for exact dates). Handle the data responsibly now regardless , the deadline is a floor, not a starting point.

Can companies legally record AI voice calls?

Yes, consistent with standard telecalling compliance practice , disclosure to the customer, a documented basis for recording, and a defined retention and deletion policy for the recording afterward.

Are AI-made calls treated differently from human-made calls under Indian law?

Not currently, in any dedicated statute. The obligations attach to the calling entity and the nature of the communication, not to whether a human or an AI system delivered it.

Can banks and NBFCs use AI voice agents for collections?

Yes, but the same Fair Practices Code restrictions that apply to human recovery agents apply in full , no calls before 8 am or after 7 pm, no harassment or intimidation, and the regulated entity remains liable for the AI vendor's conduct on its behalf.

Can insurers use AI voice agents for sales and renewals?

Yes, subject to the same TRAI telemarketing/DND rules and IRDAI's general outsourcing and conduct oversight requirements that apply to any third-party calling arrangement. There is no separate IRDAI approval process specific to AI.

Is DLT registration required for AI voice calling campaigns?

For promotional/commercial campaigns, yes , Principal Entity, sender header and content template all need DLT registration, and (per TRAI's July 2026 clarification) the call should originate from a registered 140-series number, regardless of whether a human or an AI voice agent delivers it. Genuine service and transactional calls sit under a different framework (the 1600/1601-series numbering rules) rather than DLT's promotional-consent apparatus.

Can a voice AI vendor send call data to an LLM provider?

Typically yes, since that's how the AI understands and responds to the conversation , which is exactly why it's important to know which provider, where it's hosted, and whether your data is used for model training. Ask directly; don't assume.

Where should AI call recordings and transcripts be stored?

That depends on your sector and risk tolerance, but for regulated BFSI and insurance use cases, storing this data within India substantially simplifies your compliance posture and is increasingly the practical default enterprises look for.

How long should voice recordings and transcripts be retained?

There's no single mandated number across the board; it depends on sector-specific record-keeping requirements and your own DPDP purpose-limitation analysis. What matters is that a specific period is chosen deliberately, documented, and followed , not left undefined.

Should an AI voice agent tell customers it's AI?

There is no general Indian legal requirement mandating this today, unlike some other jurisdictions. Many enterprises choose to disclose it anyway as a matter of transparency and trust; that's a policy decision worth making deliberately rather than defaulting into.

What should enterprises ask a voice AI vendor before signing?

See the 15-question checklist above , it covers telecom registration, consent handling, data flow, model providers, retention, security, and audit readiness.

When should an AI voice agent hand off to a human?

At minimum: when a conversation turns into a dispute, a complaint, or a request that requires regulated advice (financial or insurance) that only a licensed human can provide. Build this trigger into the workflow before launch.


This article reflects the regulatory position as understood on September 2, 2026. Several of the frameworks discussed here , particularly TRAI's Third Amendment to the TCCCPR and the DPDP Act's phased timeline , are actively evolving. Confirm current status before relying on this article for a specific compliance decision, and consult qualified legal counsel for your organisation's particular circumstances.

Primary Regulatory Sources

Data protection (MeitY / Data Protection Board)

  • Digital Personal Data Protection Act, 2023 and Digital Personal Data Protection Rules, 2025 , PIB press release, Nov 14, 2025
  • Commencement notification G.S.R. 843(E) (Act) and DPDP Rules, 2025, Rule 1 (Rules) , staggered commencement schedule , full text via dpdpa.com
  • IT (Intermediary Guidelines and Digital Media Ethics Code) Amendment Rules, 2026 , notified via Gazette Notification G.S.R. 120(E) on 10 February 2026, effective 20 February 2026 , MeitY FAQ document

Telecom (TRAI / DoT)

RBI

  • Framework for Responsible and Ethical Enablement of Artificial Intelligence (FREE-AI) Report , RBI Press Release, Aug 13, 2025
  • RBI Fair Practices Code and outsourcing/recovery-agent conduct directions (various circulars, including the August 2022 outsourcing circular)

IRDAI

  • Protection of Policyholders' Interests, Operations and Allied Matters of Insurers Regulations, 2024
  • Master Circular on Protection of Policyholders' Interests, 2024 (IRDAI/PP&GR/CIR/MISC/117/9/2024) , IRDAI document repository
AI Voice Calling Compliance in India: 2026 Guide | Goodbox AI | Goodbox AI