What compliance risks arise from AI outbound calling?
The main risk in AI outbound calling is often that the call itself lacks a valid basis, not that the model says one wrong sentence. Cold marketing to purchased or scraped numbers should not be the default. Requested callbacks and expected service calls for orders, appointments, or after-sales work still need an authorized telecom route, traceable number purpose, clear company and AI identity, opt-out or human handoff, and evidence retention appropriate to the service.
AI calls combine telecommunications, personal information, advertising, and content responsibility. Buying numbers does not grant marketing rights, and hiring a cloud-communications supplier does not transfer every duty. A company calling its own customers, a licensed call centre acting for another party, and a software provider have different roles; the communications authority and counsel should confirm the applicable licence and responsibility.
When translating compliance duties into evidence and controls, also compare What should a team do when a Chinese public-security app filing is rejected? and What compliance support can a software development provider deliver?; the linked guidance adds context that should be considered in the same decision.
| Scenario | User expectation | Main risk | Recommendation |
|---|---|---|---|
| User-requested callback | Explicit request with time and purpose | Repeated calls or calls after cancellation | Limit to the request and support cancellation |
| Order, delivery, repair | Directly connected to a live service | Marketing hidden in service notice, wrong recipient | Communicate only necessary facts; route exceptions to staff |
| Satisfaction follow-up | Existing relationship but automation may be unexpected | Frequency, recording, secondary marketing | Offer a choice and suppress immediately after refusal |
| Renewal reminder | Depends on contract and settings | Reminder expands into promotion | Separate service reminder from marketing |
| Bought or scraped marketing list | No direct relationship or valid permission | Harassment, privacy, route suspension, enforcement | Do not implement |
| Financial or medical script | Sector controls apply even with contact authority | Misleading output and significant rights | Specialist review and human-first handling |
Audit the number source before the model script. For each number retain origin, collection notice, permitted purpose, validity, and refusal status. Keep service permission, marketing permission, do-not-call, and complaint states separate in CRM. Synchronize refusal across campaigns and suppliers. Check purpose before importing a list; approve and log exports; the technology provider must not reuse the list for training or another client.
MIIT's Notice on Strengthening Call Centre Business Management addresses call-centre forms, user consent for specified outbound service, commercial marketing restrictions, compliant routes, number display, personal information, and records. Whether a particular operator falls within it depends on the role, but it is strong evidence that a purchased line does not make mass AI marketing acceptable.
Constrain AI with a stoppable conversation state machine. State the actual organization, purpose, and automated nature at the opening. End or transfer when the person refuses, opts out, is distressed, complains, or enters contracts, compensation, health, or another sensitive matter. The model uses approved knowledge and actions and cannot invent price, eligibility, efficacy, or return. Do not reveal an order or address before identity is sufficiently confirmed.
Approve script, model, settings, knowledge, and tools as versions. Validate and repeat back critical amounts, dates, and addresses. Defend against prompt injection that exposes instructions or client data or triggers unauthorized actions. Link call task, recording, transcription, and disposition with one stable ID. Determine current synthetic-voice and content-label duties for the actual service.
Recordings need a lawful basis, notice, purpose, roles, encryption, and retention. The MIIT notice contains a minimum recording period for certain covered call-centre callbacks and information calls, but that is not a universal six-month rule for every business. Freeze a disputed record when lawfully required, and delete on schedule otherwise.
Pilot only a small service list with a documented basis. Monitor wrong number, missing identity disclosure, repeat call after refusal, false promise, failed handoff, complaint, do-not-call hit, and leakage alongside completion. Define stop thresholds before launch.
Wavesteam can build task, consent, script, handoff, suppression, evidence, and quality-review systems and connect a provider approved by the client. The client owns number source, purpose, sector script, and operating entity. Wavesteam will not implement unauthorized cold marketing, SIM pools, caller-ID manipulation, or complaint-control evasion. China's Personal Information Protection Law provides the general privacy basis.