Inbound vs Outbound AI Calling: Which to Build First

Inbound and outbound AI calling share a voice and nothing else. One needs no consent from the caller and is judged on latency. The other needs documented consent for every number and carries $500 to $1,500 per call in US penalties. What separates them, the 5 rung ladder of outbound risk, and where our own deployments sit.

Cover reading Answer the call, or make it, beside an outbound shift confirmation run showing consent and calling window checked before dialling, the agent calling a guard, confirmations logged, no answers escalated, and 8 people reduced to 1
On this page

Build inbound first. An AI agent that answers calls needs no consent from the caller, carries low legal exposure and recovers revenue you are already losing. An AI agent that makes calls needs documented consent for every number it dials, and in the US carries statutory damages of $500 to $1,500 per call with no cap.

Both are worth building and we have built both. But they are different products with different risks, and the order matters more than most businesses realize. This covers what actually separates them, the 5 rung ladder of outbound risk, and where each of our own deployments sits.

On this page

  1. What is the difference between inbound and outbound AI calling?
  2. Why build inbound first?
  3. Outbound: removing work you already do
  4. The outbound risk ladder
  5. What do the rules actually say?
  6. How Canada differs
  7. What we built, and which side each sits on
  8. Which should you build first?
  9. How these figures were arrived at
  10. Frequently asked questions

What is the difference between inbound and outbound AI calling?

Inbound means the customer rings you and an AI agent answers. Outbound means your system decides to dial and a person's phone rings. Same voice technology, and almost nothing else in common.

A comparison of inbound and outbound AI calling across who initiates the call, consent required, legal exposure, what each is worth, the hardest engineering, the failure mode and when to build each first
The consent row is the one that changes everything else in the table.

The row that changes everything is consent. When somebody calls you, they have chosen to start the conversation, and US consent obligations under the Telephone Consumer Protection Act apply primarily to outbound calls. When you call them, you need permission before the phone rings, and the standard depends on why you are calling.

Why should you build inbound first?

The inbound case is simple arithmetic. Calls arrive when nobody can answer: after hours, during the morning rush, when three people ring at once. Every one that rings out is revenue you had already earned the right to.

The engineering that matters here is latency, because the caller is on the line hearing every pause. Under 800 milliseconds from the end of their sentence to the first audio back reads as a natural pause. Past 1,500 they start talking over the agent. Our guide to how voice agents work covers that in depth, and the automotive version works through the numbers for a repair shop specifically.

Legally it is the quiet side. You still need to disclose that the caller is speaking to an AI, and call recording consent rules vary by state and province, but you are not asking permission to have the conversation because the caller started it.

Outbound: removing work you already do

Outbound is not primarily a sales tool, whatever the marketing suggests. Its best use in most businesses is removing a repetitive calling job somebody is doing by hand: confirmations, reminders, scheduling, chasing.

The engineering that matters here is not latency. It is the dial time gate, which is the check that runs before every single call: do we have consent for this number, is it on a do not call list, are we inside the permitted calling window, and how many times have we already tried. Get that wrong at volume and you have manufactured a legal problem rather than a saving.

The outbound risk ladder

A 5 rung ladder of outbound AI calling risk from calling your own workforce at the bottom through transactional customer calls, service follow up and marketing to cold outreach at the top, with the consent standard and exposure level for each
Rung 1 is where our only measured outbound deployment sits, and that is not a coincidence.

The important thing about that ladder is that the rungs are separated by relationship and purpose, not by technology. The same AI voice agent placing the same call is low risk when it confirms a shift with your own employee and high risk when it pitches a promotion to a stranger.

What do the rules actually say?

General information rather than legal advice, and this area moves quickly.

The foundation is the FCC's declaratory ruling of 8 February 2024, which recognized that calls made with AI generated voices are artificial under the TCPA. There is no exemption for sounding human. The FCC explicitly rejected the idea that technology providing the equivalent of a live agent falls outside the rules.

Consent comes in 2 tiers. Informational or transactional calls require prior express consent, which can be given orally. Marketing calls require prior express written consent, which must be signed, name the specific business, and authorize automated or AI calls to that number. Compliance guidance for voice AI operators sets out both tiers and the September 2024 FCC proposal to mandate AI disclosure at the start of every AI generated call.

Penalties are per call and uncapped: $500 per violation, rising to $1,500 for willful or knowing violations. Engineering guidance for outbound stacks notes that a consent scrubbing bug affecting a few thousand calls in a month can produce seven figure exposure, and that class action risk scales with campaign volume.

One recent wrinkle worth knowing. A February 2026 appellate decision held that the TCPA's text requires only prior express consent rather than prior express written consent for artificial voice calls, applying the Supreme Court's Loper Bright framework. A 2026 compliance playbook for voice AI notes that the decision changes nothing in the other 47 states, where courts continue to apply the written consent rule. Build to the stricter standard unless your counsel tells you otherwise.

How Canada differs

Canadian outbound runs through the CRTC's Unsolicited Telecommunications Rules and the National Do Not Call List rather than the FCC. Consent can be express or implied, calling curfews apply, and registration and DNCL scrubbing are required. Record retention differs too: 4 years in the US against 3 years plus 14 days in Canada. CASL governs any email travelling alongside a calling campaign.

Neither regulator currently mandates that every AI call opens by announcing it is AI, though the FCC has proposed it. We build it in anyway. Callers mind being deceived considerably more than they mind a machine.

What we built, and which side each sits on

From our work. Our automotive agent is inbound. It answers calls to a mechanic shop, qualifies the job and books against the real diary, with one deployment serving several shops and routing by the number the caller dialled. The engineering challenge was entirely latency: it started at 1.5 seconds of response lag and we brought it to 0.5, almost none of which came from the model. It was voice activity detection thresholds and the round trip to the booking system. It is a demo still under test.

Ziltrix is outbound, and it sits on rung 1. A security workforce platform had 8 staff ringing guards every day to confirm shifts those guards had already accepted. The AI agent took that to 1 person handling exceptions, moved coverage from 12 hours to 24/7, raised capacity from 100 calls a day to more than 5,000, and recovered $42,000 a year in salary. Live in 4 weeks.

Notice what the Ziltrix agent never does. It does not sell anything, it does not call anyone who has not already agreed to a shift, and it does not contact a single consumer who did not opt into a relationship. That is not a limitation we worked around. It is why the deployment was straightforward to put live.

Which should you build first?

  1. Count your missed inbound calls first. Pull last month's log and split it by hour. If calls are ringing out, inbound is the cheaper and faster win, and it carries almost no legal exposure.
  2. Then find your rung 1. Look for a repetitive calling job somebody does by hand to people you already have a relationship with: shift confirmations, appointment reminders, delivery windows, document chasing.
  3. Build the dial time gate before the conversation. Consent, do not call status, calling window and retry limits are the first thing to build in an outbound agent, not the last.
  4. Log consent per number, with a timestamp and source. If you cannot show where consent came from, you do not have it.
  5. Take counsel before rung 3 and above. Everything from service follow up upward deserves a conversation with someone who does telecom law for a living.

Where Codeatic fits in

We build both. Inbound agents for service businesses that are losing calls, and outbound agents for the operational calling that eats a person's week. Our guide to AI call agents by industry covers which call to hand over in 6 sectors, and the customer service piece covers where a voice agent makes service worse rather than better.

If you are not sure which side your opportunity is on, run the free AI audit or get in touch. If your answer is a cold calling campaign, we will tell you to talk to a lawyer before you talk to us.

When not to build outbound at all

When you cannot produce, for every number you intend to dial, a record of when and how consent was given. When the calling list came from anywhere other than your own customer or staff records. And when the purpose is to sell rather than to confirm, unless you have written consent and the appetite to defend it.

The short version

Inbound and outbound AI calling share a voice and nothing else. Inbound needs no consent from the caller, is judged on latency, and recovers revenue you are already losing, so build it first. Outbound needs documented consent per number, is judged on the gate that runs before each dial, and carries $500 to $1,500 per call in US statutory damages. Start outbound on rung 1, your own workforce or transactional confirmations with existing customers, which is exactly where our only measured outbound deployment sits.

How these figures were arrived at

The comparison table and the 5 rung ladder describe how we scope voice deployments and are not a published framework. Consent standards and penalty ranges summarize US federal rules under the TCPA following the FCC's declaratory ruling of 8 February 2024, with the ruling linked directly and the practical guidance attributed to the specialist sources cited inline. Canadian rules are summarized from published 2026 guidance on CRTC and DNCL requirements. All of it is general information rather than legal advice, it varies by state and province, and it changes: take telecom counsel before running any outbound program. Our automotive latency figures come from a demo still under test, measured from the end of caller speech to the first audio out. The Ziltrix outcomes are published on our case study page and measured against the manual process the client recorded beforehand.

Reviewed 25 September 2026 by Usama Tariq, Co-Founder and CTO. If you find an error in this post, email info@codeatic.com and we will publish a correction on the page rather than editing it quietly.

Frequently asked questions

What is the difference between inbound and outbound AI calling?

Inbound means a customer calls you and an AI agent answers. Outbound means your system dials out. Inbound generally needs no consent from the caller because they started the conversation. Outbound needs documented consent for every number before the phone rings.

Is outbound AI calling legal?

Yes, with consent. The FCC ruled in February 2024 that AI generated voices are artificial voices under the TCPA, so the existing consent rules apply. Informational and transactional calls need prior express consent, marketing calls need prior express written consent, and penalties run $500 to $1,500 per call with no cap.

Do I need consent for an AI agent that answers inbound calls?

Not to answer the call, since the caller initiated it. You do need to disclose that they are speaking to an AI, and call recording and transcription consent rules vary by state and province, so check the rules where you operate.

What is the safest outbound AI calling use case?

Calling your own staff or contractors about something operational they already agreed to, such as confirming a shift. It has high volume and predictable structure without the consumer protection exposure that comes with selling to people who did not ask.

Which should I build first, inbound or outbound?

Inbound, in almost every case. It is faster to deploy, carries far less legal exposure, and recovers revenue you are already losing. Build outbound second, starting with your own workforce or transactional confirmations with existing customers.

Does an AI agent have to say it is AI on an outbound call?

Neither the FCC nor the CRTC currently mandates it on every call, though the FCC has proposed exactly that and several states have their own disclosure rules. Do it anyway. Callers object to being deceived far more than to talking to a machine.

How do the rules differ in Canada?

Canadian outbound runs through the CRTC's Unsolicited Telecommunications Rules and the National Do Not Call List rather than the FCC, with registration, DNCL scrubbing and calling curfews. Record retention is 3 years plus 14 days in Canada against 4 years in the US.

What happens if consent is wrong on an outbound campaign?

Each call can count as a separate violation at $500, tripled to $1,500 for willful violations, with no cap. A consent scrubbing error across a few thousand calls in a month can reach seven figure exposure, and class action risk scales with volume.


Abdul Wahab, Co-Founder and CEO, Codeatic

Abdul has spent 5 years building software, across web stacks and mobile in React Native, Flutter and native Android, before moving into product, architecture and AI work. He holds an MS in Computer Science from PUCIT and leads Codeatic, an AI automation agency working with SMBs and startups across the US, Canada, the UK and Saudi Arabia. Connect on LinkedIn.

Technically reviewed by Usama Tariq, Co-Founder and CTO, Codeatic. Usama is an AI and computer vision engineer who builds production systems from unstructured video, image and speech data. He built the REVOX engine at Veedback, developed LLM and computer vision systems at Coeus Solutions GmbH, and led AI model development at OMNO AI. He is an OpenCV OAK-D finalist and a contributor to Workhub, and holds a BS in Computer Science from COMSATS University Islamabad. Connect on LinkedIn.