Been mapping how AI voice agents hold up against TCPA enforcement. Three gaps keep coming up in enforcement actions, lawsuits, and deployment discussions: **1. Consent with no paper trail** Most teams HAVE consent — a checkbox, a form, a verbal “yes”. But they can’t PROVE it: no timestamp, no source, no copy of what the person actually agreed to. In a dispute, unprovable consent = no consent. Fix: log every consent event with timestamp, source, and the exact language agreed to. Keep consent records at least 4 years (5 to be safe). **2. Opt-outs that don’t actually work** “Reply STOP to opt out” is table stakes for SMS, but voice deployments often have no equivalent: no “press 9 to be removed”, no suppression-list update after the call, and the DNC list never gets scrubbed against the dialer. The FCC’s Sept 30, 2026 order updated the revocation rules: a sender can now designate one exclusive opt-out channel (e.g., an IVR keypress) if it’s clearly disclosed — otherwise “any reasonable means” still applies, including telling the AI “stop calling me” mid-call. If your agent can’t handle that and you haven’t designated an exclusive channel, you have a gap. **3. Nobody knows who owns compliance in the contract** Agency deploys the agent, client owns the numbers, vendor provides the infra. When a $500–$1,500-per-call problem shows up, everyone points at each other. Few service agreements assign TCPA responsibility explicitly. One paragraph fixes it — check whether yours has it. Not a lawyer — operational notes from research, not legal advice. Curious: which of these have you actually run into in production?