appliedbits
DISPATCH  ·  Regulatory Watch PUBLISHED
PUBLISHED 2026-07-11

Week ending July 3, 2026

Two threads ran through the short holiday week, and they point in opposite directions. On June 29 the industry filed its reply comments against the Commission’s call-center onshoring NPRM and told the FCC, more or less in unison, that it has no authority to say where a call center sits. Two days later the Commission circulated a draft asserting exactly the kind of gatekeeping power the onshoring filers are resisting — an overhaul of the Robocall Mitigation Database built to decide which providers get to be in the voice network at all. The interesting part is what surfaced in between: the argument that a U.S.-hosted AI agent should count as “onshore,” which quietly turns a labor-and-data proceeding into a question about who, or what, is answering the phone.

Industry closes ranks against the onshoring NPRM — and slips an AI agent through the door

The proceeding is Improving Customer Service and Protecting Consumers through Onshoring (CG Docket No. 26-52, FCC 26-16, released March 26), which proposes, in CTIA’s paraphrase, “sweeping changes to regulate the use of foreign call centers for customer service communications” with the stated goal of “encourag[ing] and facilitat[ing] the onshoring of call centers.” The reply record that closed June 29 is close to a shutout. CTIA called the proposals “not needed, not helpful, and not within the Commission’s authority.” The Consumer Technology Association argued the record confirms “market dynamics already discipline poor customer service performance more effectively than prescriptive regulation could.” EchoStar put it plainly: “the offshore call center market is already working.”

The heaviest fire is on authority. The U.S. Chamber of Commerce went straight at the FCC’s national-security framing, arguing that “abstract concerns about national security cannot and do not give the Commission authority it otherwise lacks,” and that the sprawl of the proposal trips the major-questions doctrine — a “decision of such magnitude and consequence” belongs to Congress. Edison Electric Institute added the critical-infrastructure objection, warning that the rules “exceed the Commission’s statutory authority, lack evidentiary support, and would improperly sweep in electric utilities and other critical infrastructure, imposing significant operational risks for outage communications, emergency response, and customer service reliability” — and that neither the TCPA nor Section 251(e) reaches “call center location, staffing, or operations.” That last point matters beyond the utilities: it’s the same jurisdictional hook the Commission would need for any number-anchored identity mandate, and the record is now full of parties telling it that numbering authority under 251(e) does not stretch to end-user business practices.

For an identity reader the buried question is data, not labor. The onshoring case rests on the premise that sensitive customer information — the CPNI and account data a service rep touches to authenticate a caller — is less safe offshore. USTelecom, represented by Kellogg Hansen, conceded the goal and rejected the mechanism: “Commenters overwhelmingly agree with the Commission’s aims of protecting customer data and promoting national security, but they also overwhelmingly agree that mandatory onshoring is not the right mechanism to achieve those aims,” because providers “already employ robust security practices at their call centers — including those located abroad — to protect customer data.” The section heading is the thesis in six words: the proposed rules “Will Not Promote Data Privacy Or National Security.” Whether the Commission accepts that the data-security problem is a controls problem rather than a geography problem is the whole ballgame, and it’s the version of this fight that touches the authentication stack directly.

Then the twist. Puerto Rico Telephone Company d/b/a Claro warned that onshoring mandates “will unintentionally drive companies to AI” — that squeezing offshore human agents “may accelerate a transition away from human agents and toward artificial intelligence.” Televox, an AI-agent vendor, took that dynamic and asked the Commission to bless it: “secure, U.S.-hosted AI-enabled customer engagement tools can and should be made a part of the domestic customer-service solution,” and the Commission “should clarify that AI agents may be counted toward any domestic call-volume requirement” where the system is hosted in the United States. “In that model,” Televox wrote, “AI adoption and onshoring are not in tension. AI makes onshoring more feasible, more secure, and less costly.” Its proposed division of labor is the tell — route the routine volume to U.S.-hosted AI and reserve “U.S.-based human capacity for sensitive, complex, empathetic, or escalated interactions,” with a specific carve-out that sensitive transactions “should be routed to U.S.-based workflows, especially where sensitive personal information is involved.” Read against the rest of the section’s work on synthetic voice, this is the same convergence from the customer-service side: a rule aimed at putting humans back on U.S. soil ends up licensing an American-hosted machine to handle the call, and the line that’s supposed to protect the sensitive-data interaction is a hosting-location rule, not an identity one. If a U.S.-hosted AI agent satisfies an onshoring mandate, “who is on the call” has quietly become “where is the server.”

The Commission circulates a Robocall Mitigation Database overhaul for July 22

On July 1 the Commission circulated a draft Further NoticeImproving the Effectiveness of the Robocall Mitigation Database (WC Docket Nos. 24-213 and 17-97; CG Docket No. 17-59) — teed up for the July 22 Open Meeting. This is the affirmative counterpart to the onshoring fight: where the onshoring filers say the Commission cannot police who sits in the network, the RMD notice is about policing who gets into it. The FNPRM “advances measures aimed at improving the reliability, integrity, and effectiveness of the Robocall Mitigation Database (RMD) as a central tool for preventing and stopping illegal calls” — the list that every provider must file into and that downstream providers rely on to decide whose traffic to accept.

The proposed moves are the ones the enforcement side has wanted for a while: “confirm the scope of entities that must file,” tighten the accuracy of “certifications, robocall mitigation information, business identifying information, provider type and service information,” add “enhanced screening measures to prevent bad actor providers from entering the RMD in the first instance,” build “strengthened processes for removing” the ones already in, and stand up “audit requirements and resources for administering the RMD.” The framing — a database that ensures “only legitimate, transparent, and accountable providers gain or maintain access,” in service of “rebuilding trust in voice communications” — is doing the work that KYC-at-origination and number right-to-use have been doing in the comment records all spring. The RMD is where the STIR/SHAKEN gate becomes an enforceable membership list, and the Commission is proposing to turn the membership criteria from a self-attestation into something screened and auditable. Comments will be set once it’s adopted; the vote is the milestone.

An unusual alliance forms around consent revocation

The consent-revocation rules drew the week’s most interesting signature block. The American Bankers Association, ACA International, and the National Consumer Law Center — banks, the debt-collection bar, and the leading consumer-advocacy group, three parties who are almost never on the same filing — wrote jointly to Chairman Carr and Commissioners Gomez and Trusty to say they “share a common goal to ensure that consumers’ revocations of consent to receive autodialed or prerecorded voice calls and text messages under the Telephone Consumer Protection Act are accurately and efficiently processed,” and to flag shared concern about “aspects of the Report and Order.” When the industry that wants to keep calling and the advocates who want the calls to stop both tell the Commission its revocation plumbing is broken, that’s a rare piece of consensus worth watching.

From the other direction, the Alarm Industry Communications Committee filed an ex parte “to address the impact of the Commission’s consent revocation rules on alarm company communications” and to “urge the Commission to provide explicit protection for life-safety alarm communications, with particular emphasis on alarm verification calls.” The alarm-verification call is the textbook hard case for a blanket revoke-all rule: it’s the call you want to go through even after you’ve told the company to stop calling you, because the alternative is a missed break-in or fire. And the Stop Scams Alliance, through counsel Rosemary Harold, dropped a fresh evidentiary brick into the 17-59/17-97/02-278 record — a new Gallup national survey, The United States of Scams: The Financial and Emotional Fallout — to keep the harm numbers in front of the Commission as it reworks the rules.

Honorable mentions

The numbering docket had its own reply round. In Combatting Illegal Robocalls Through FCC Numbering Policies (WC 26-49, consolidated with 20-67, 13-97, and 07-243), the National Consumer Law Center and allied consumer groups backed extending numbering-resource certification and disclosure to resellers, urged a broader definition of “reseller,” and pressed the Commission to “specify consequences for knowingly furnishing numbers for illegal robocalling” — including a presumption that a provider or reseller that keeps no records of the numbers it assigns “should be presumed to be the maker of illegal calls.” 10x People pushed back from the small-provider side, arguing the “single-level resale proposal would harm competition without meaningfully improving enforcement.” This is the numbering-KYC question — WC 20-67 is literally about “knowledge of customers by entities with access to numbering resources” — reaching the same origination-side logic as the robocall dockets, one layer down at the number itself. Separately, the FTC opened a comment window on a draft policy statement addressing AI accuracy on July 1, and the Commission adopted an Emergency Alert System cybersecurity order (FCC-26-38) aimed at ensuring alert messages “originate from authorized and verifiable sources” — message authentication for the alerting layer, adjacent to the caller-authentication work.

Looking ahead

July 22 is the date: the RMD Further Notice goes to a vote, and the draft’s screening-and-removal machinery is the thing to read closely, because it’s where the Commission decides how much identity proof it will demand before a provider can sit inside the trusted call path. On onshoring, the reply record is closed and the ball is with the Commission — watch whether it engages the wall of authority objections (Chamber, EEI, CTIA all built the same 251(e)/major-questions argument) or presses ahead on a national-security theory the Chamber just called a pretext, and whether the “U.S.-hosted AI counts as onshore” framing from Televox and Claro shows up anywhere in the Commission’s thinking. The consent-revocation FNPRM now has both an industry-plus-consumer letter saying the processing is broken and an alarm-industry ask for a life-safety carve-out, so a revised order is the plausible next step. And the numbering-KYC reply round in WC 26-49 is worth a second look once the Commission signals whether it will adopt NCLC’s “presumed maker” default for providers that can’t account for their own numbers.