appliedbits
DISPATCH  ·  Regulatory Watch PUBLISHED
PUBLISHED 2026-07-25

Week ending July 24, 2026

The robocall-mitigation trilogy got its third leg this week. On Wednesday the Commission released a Further Notice aimed squarely at the Robocall Mitigation Database, and it landed on the same day the reply-comment window closed on the Know-Your-Customer FNPRM from the spring. So the record filled up at both ends at once: the agency proposing to bolt the front door of the RMD shut while industry told it, in reply after reply, that the KYC half of the project is aimed at the wrong target. Meanwhile the all-IP transition kept building its own head of steam, with AT&T and Harold Furchtgott-Roth both pressing the Commission to name a date and mean it.

The RMD gets its own rulemaking, and it’s built for re-entry, not entry

FCC 26-49, adopted July 22 and released the 23rd in WC Docket No. 24-213 (with 17-97 and 17-59 along for the ride), is the Robocall Mitigation Database growing up. The framing is explicitly a whack-a-mole problem: as the RMD has become the thing downstream providers check before they accept traffic, “the Commission’s RMD rules and existing functionality must stay ahead of bad actors’ ability to enter (or re-enter) the RMD and then transmit illegal calls on the U.S. voice network.” The center of gravity in the notice isn’t the initial filing — it’s everything the agency now wants to do to keep a removed provider from simply re-papering itself back in under a new name. There are proposed rules on parents, affiliates, subsidiaries and principals; on third-party submitters who file on a provider’s behalf; and a whole section titled “Keeping Removed Bad Actor Providers Out.”

The identity-of-the-carrier problem runs straight through it. The Commission is candid that its foreign-provider worry is a signaling worry: bad actor foreign providers, it writes, “are attempting to avoid their calls being viewed as foreign originated, which would invite less scrutiny when the call uses a U.S. NANP number and could allow the call to receive a different STIR/SHAKEN attestation.” That is the whole game in one sentence — number, provenance and attestation level are the levers, and the RMD is where the Commission proposes to pin them down. The notice also gently opens the door to automated tooling, directing the Bureau to make sure any technical validation solution “complies with all relevant federal data and privacy statutes, along with any other relevant government guidance, such as those addressing use of artificial intelligence.” Chairman Carr and Commissioner Trusty each issued separate statements. Comments run 30 days after Federal Register publication, replies 60.

The same spoofing problem is getting a very different answer in the UK. Ofcom finalized an update to its Calling Line Identification guidance (revised July 15, in force from July 2027) that leans on network-level obligations under General Condition C6 to make providers block international calls that “falsely display UK numbers” — spoofing that, in Ofcom’s words, “misleads the recipient of a call about who is calling them.” Where the FCC’s instinct is to authenticate the call and pin down the caller’s provenance, Ofcom’s is to block the bad number at the border: same harm, opposite lever.

Read it against the KYUP FNPRM from May and the shape is clear: KYC (customer), KYUP (upstream provider), and now RMD (the ledger that ties the two together). The Commission is trying to make the database the connective tissue — the place a KYUP diligence check gets cross-referenced, the place a removed originator can’t quietly resurface.

Industry to the KYC docket: you’re about to tax the small guys and miss the fraud

The reply round on the April KYC FNPRM (FCC 26-27) closed Thursday, and the through-line from the serious filers is consistent: documentary identity-gating scales badly, and the providers it will actually bite aren’t the fraudsters. The Consumer Access & Choice Coalition, through Jonathan Marashlian at The CommLaw Group, pushed a tiered framework keyed to volume and risk rather than a universal mandate, and put the market-structure argument bluntly: “A rule that raises the cost of entry or continued service for small, innovative, and low-ARPU providers will not stop sophisticated fraud. It will reduce affordable communications options for the consumers least able to bear additional costs.” The coalition leans on TextNow, Pinger, WISPA and ACA Connects to argue that account, device, behavioral, STIR/SHAKEN and traceback controls already do the work that “universal documentary identity gating” would only duplicate.

Citizens Against Government Waste, signed by Tom Schatz, hit the privacy and cybersecurity flank, warning that mandatory collection and annual re-verification would sweep up sensitive customer data — and citing WISPA’s point that requiring “unnecessary customer information may increase cybersecurity and privacy risks without materially improving robocall prevention,” alongside the Gramm-Leach-Bliley wrinkle for bank-adjacent callers. The arithmetic CAGW quotes is the kind that lands: a provider with 5,000 customers and fewer than ten employees running 5,000 re-verifications a year is not a fraud-prevention program, it’s an attrition program. Whether the Commission calibrates the final KYC rule to that record — a genuine tiered, risk-based structure with red-flag triggers instead of a flat documentary floor — is the question the RMD notice now inherits, because the two dockets are converging on the same providers.

Worth flagging alongside it: a July 23 ex parte from the American Bankers Association, the National Consumer Law Center and ACA International — an unusual creditor-and-consumer-advocate joint front — met with the Consumer and Governmental Affairs Bureau on the TCPA revocation-of-consent rules from the February 2024 Order. Their proposed fix would let a caller read a revocation request as reaching “only to the category of messages to which the revocation was directed,” provided the caller discloses that construction and offers a means to revoke everything. It’s a narrower question than KYC, but it’s the same coalition dynamic: banks and consumer advocates converging on workable mechanics.

The all-IP transition stops being a “looking ahead” item

The July 15–16 workshop clearly lit a fire, because the ex parte traffic in the IP-transition cluster (WC 25-304, 25-311, 25-208, with 17-97 stapled on for authentication) is now where the forward motion is. AT&T, through Brian Benison, laid out the most concrete ask of the week: adopt the USTelecom-developed ALIII model for non-negotiated, over-the-internet interconnection as “the default framework for IP interconnection for voice traffic,” and — the part that gives it teeth — “first adopt its proposed December 31, 2028, sunset date for TDM interconnection obligations.” AT&T wants an interim, conditional pathway to retire legacy TDM tandems before ALIII is fully standardized, plus forbearance from the section 251(c)(2) interconnection obligations “on a LATA-by-LATA basis where specified criteria are met,” moving voice exchange toward internet-style peering and bill-and-keep. This is the transition’s endgame stated plainly: a firm sunset, an internet-model default, and a glide path that rewards carriers who move early.

Harold Furchtgott-Roth refiled his economic paper across the same dockets (correcting a signature block on the June 25 original), and it supplies the cost-benefit spine the Commission asked for in each NPRM. His core finding is the one the record will lean on: “each year that TDM remains in place costs the American economy billions of dollars in inefficient redundant interconnection,” and a single voice-service provider clinging to TDM can impose those costs on everyone it exchanges traffic with — the classic holdout problem that argues for a hard date rather than a voluntary drift. The paper also picks winners among the pending proposals, reserving particular benefits for the Inteliquent model; expect the carriers whose proposals it grades less generously to answer.

For this beat the interesting seam is 17-97’s presence on both filings. The transition isn’t a separate silo from authentication — STIR/SHAKEN has to ride the new interconnection architecture, and the question of who signs, who attests, and how provenance survives an internet-model handoff is exactly the identity problem the RMD docket is chewing on from the other direction. WTA’s framing that these proceedings are interrelated keeps proving out.

Honorable mentions

Cin-Q Automobiles filed a reply supporting its petition for reconsideration in the long-running TCPA junk-fax fight (02-278, 05-338, 25-307) — a reminder that the Commission’s petition-dismissal housekeeping in 25-307 still has live parties attached. On the high-cost side, the ACAM Broadband Coalition pressed an ex parte for an E-ACAM extension as the Bureau worked through routine 10-90 traffic including a new public notice — the legacy-service-retirement and universal-service reform threads that sit under the same transition umbrella. And on the FTC side, the only in-window item that touches this beat was a July 21 action permanently banning a student-loan-forgiveness operator from the debt-relief industry and from telemarketing — enforcement, not rulemaking, but a data point on how hard the telemarketing perimeter is being policed.

Looking ahead

The KYC reply record is now closed, so watch for the Commission to move toward an order — and watch whether it adopts the tiered, risk-based structure the record is begging for or holds to a flat documentary floor. The RMD FNPRM’s comment clock starts on Federal Register publication; expect the same small-provider and identity-vendor voices to show up quickly, since re-entry controls are where the compliance-tooling market lives. In the IP cluster, AT&T’s forbearance ask in 25-311 invites replies from the rural carriers who interconnect at those tandems, so look for NTCA/WTA and the transit-dependent CLECs to respond to the December 2028 date. And keep an eye on whether anyone answers Furchtgott-Roth’s grading of the competing interconnection proposals on the merits. In Canada, the CRTC’s review of its Unsolicited Telecommunications Rules (Notice 2026-132) closes to interventions July 27 — worth watching whether filers there push to fold synthetic-voice disclosure into the auto-dialer definition, a question the FCC will face next.