State attorneys general are urging the FCC to tighten voice-provider KYC rules, shifting anti-robocall enforcement upstream with stronger identity checks, ongoing monitoring, and risk-based oversight.
A bipartisan coalition of 50 state and territorial attorneys general has urged the Federal Communications Commission (FCC) to strengthen “Know Your Customer” requirements for originating voice service providers—the providers that give callers access to the U.S. voice network. Their central message is straightforward: the most effective robocall-control measure is to prevent unlawful traffic from entering the network in the first place.
The comments from the National Association of Attorneys General were filed on July 27th 2026 in response to the FCC’s proposal to expand and sharpen provider duties involving customer identification, verification, and monitoring. Rather than treating KYC as a one-time onboarding exercise, the coalition advocates a risk-based, continuing obligation to understand who is using voice services and whether that use poses an illegal-traffic risk.
Illegal robocalls, scam calls, caller-ID spoofing, and telephone-enabled fraud often depend on access to legitimate voice-network infrastructure. Originating providers are therefore uniquely positioned to identify problematic customers before high-volume or unlawful traffic is launched, preserve usable records, and terminate or refuse service when warning signs emerge.
The AG coalition’s position reflects a familiar enforcement problem: by the time a call reaches a terminating carrier, analytics provider, or consumer, the unlawful traffic has already entered the network and may have caused harm. Stronger onboarding and monitoring obligations would move compliance upstream, where providers retain the greatest practical leverage over the customer generating the calls.
The joint comments support the FCC’s effort to require originating providers to collect a more robust body of information from business customers before granting them network access. The attorneys general also recommend three important additions to the Commission’s KYC framework.
The coalition’s rejection of a small-provider exemption is consequential. A size-based safe harbor may create regulatory arbitrage: problematic callers can gravitate toward the provider with the least demanding customer-vetting process, thereby undermining the purpose of a network-wide anti-robocall regime.
For originating providers, this does not necessarily mean identical operational processes for every business model. It means the compliance baseline should apply universally, while the depth of investigation, documentation, and continued monitoring should increase with the customer’s risk profile, calling volume, business purpose, and compliance history.
The comments point toward a layered compliance framework rather than a “check-the-box” verification protocol. In practice, that model could distinguish an established local business making modest appointment-reminder calls from a newly formed entity seeking large volumes of dialable numbers, short-duration calling capacity, or rapid access to high-volume outbound service. This is an illustrative compliance implication of the coalition’s call for business-understanding and high-risk monitoring requirements.
The existing FCC anti-robocall framework has already recognized KYC-type obligations in other contexts, including gateway-provider requirements. The AG coalition’s submission seeks a more rigorous version of that preventive approach for domestic originating voice providers.
For voice service providers, the expected direction of travel is toward documented, defensible customer acceptance and retention controls. A provider that can show it assessed customer identity, business reality, contemplated traffic, legal-compliance risk, and subsequent warning signs will be in a stronger position to demonstrate reasonable mitigation practices than one relying solely on basic account-registration data.
Operationally, providers should consider whether their current programs address:
Businesses that rely on outbound calling—particularly lead generators, telemarketers, debt collectors, affiliates, and high-volume platforms—should expect greater scrutiny of their operational legitimacy and legal-compliance controls before obtaining voice capacity. The practical result may be more extensive onboarding questionnaires, requests for proof of consent and campaign controls, verification of lead sources, and ongoing reviews when calling patterns change.
For compliant callers, reliable documentation will become more commercially important: evidence of lawful consent, DNC suppression, seller–telemarketer relationships, campaign purpose, caller-ID practices, and complaint-management processes can help satisfy provider diligence and avoid service disruptions. This follows directly from the states’ recommendation that providers understand customers’ practices, reputation, historical conduct, intended use, and legal compliance.

The joint filing signals unusually broad state-level support for converting voice-provider KYC from basic customer identification into a substantive, risk-sensitive gatekeeping obligation. If the FCC adopts the coalition’s recommendations, originating providers may face stronger universal onboarding standards, enhanced monitoring of high-risk customers, and greater pressure to deny or discontinue service before suspicious traffic becomes a consumer-facing robocall problem.