Voice phishing simulations in the United States
The United States is the one country in this portal where your team rents the number itself with no approval in front of it, and the one where the hard question is not procurement at all. A voice phishing simulation is lawful here, and how far the federal telephone statute reaches it depends on the line you dial: a desk phone, a home line and a mobile get three different answers under the same section.
Phone numbers
Supplied by Callstrike
Local numbers in the United States.
Running a simulation
Permitted, and it turns on the line
One statute, three answers. The mobile is the line most of your staff will answer.
Consent
The statute's own mechanism
The telephone rules are built on prior express consent, and on a mobile that is the open question.
Getting a phone number in the United States
No approval step, and nothing to wait for.
Direct provisioning
Your team provisions numbers here directly from available inventory, with no approval step in front of it.
Nothing is filed and nothing is waited on. Your team searches the inventory in the console and rents an American number the same day, and there is no clearance form because there is no American regulator asking you for one. The reason is structural rather than lucky: the numbering rules are addressed to carriers and to authorised interconnected providers, and a business renting numbers from a provider is not an applicant under them. What the console offers you at the moment you look is the authority on what you can take, because the inventory is live rather than a published list.
Be ready for the things that look like American paperwork and are not regulatory clearance. Carrier onboarding checks, campaign registration, toll free verification, branded calling enrolment and caller name registration are all real, and they are processes run by carriers and industry registries rather than requirements imposed by the Federal Communications Commission. Knowing which is which is worth something specific: it tells you who you are negotiating with when somebody says a rule requires what in fact only their process does.
- 01Search the inventory and rent your numberYour team, in the Callstrike console.
- 02Build and launch the campaignYour team
No regulatory documentation is required to hold a number here, and there is no clearance step in front of it either. Your team rents the number from the inventory in the console and starts building the campaign.
Is it lawful to run a simulation in the United States?
The position in short, before your counsel reads the detail below.
Yes, and the American answer is not one answer, which is where almost every page on this subject goes wrong. The Commission ruled in February 2024 that the Telephone Consumer Protection Act's restrictions on an artificial or prerecorded voice reach current technologies that resemble human voices, so an AI voice is an artificial voice and you are inside that regime. What the regime does next depends on the line. An ordinary office wireline is in neither prong of the prohibition on the face of the statute. A home line is inside it with an exemption available for a commercial call that carries no advertisement and is not telemarketing. A mobile is inside it with no applicable exemption at all, and that is the line most of your staff will pick up.
On the mobile line the question is whether the employment relationship supplies prior express consent, and no ruling has decided it. Do not let anyone tell you that the Commission shut the door on consent, because it did not: what it refused was a request to write an exception for technology that purports to provide the equivalent of a live agent, which is a point about the technology and not about the mechanism. The statute underneath is a consent statute, and consent is precisely the American route. It is one to build deliberately with your own counsel rather than to assume, and the reason to be careful is the arithmetic: a private plaintiff can claim five hundred dollars a call, which across a workforce is the exposure that matters rather than any regulator.
One further rule shapes the call itself rather than its lawfulness, and it surprises people. Every artificial or prerecorded voice message must state at its beginning, clearly, the identity of the business responsible for initiating the call, under the registered name, and there is no security testing exception to it. A call that opens by naming your company is not a simulation. That is why the American design conversation is about which delivery you use rather than about which document you write, and it is the single most operationally important sentence on this page.
Recording is the other thing to settle before the first call, and the state that governs is usually where your employee is standing rather than where your head office is. Federal law needs one party, so a participant is covered, with a proviso worth reading: the exception is lost where the interception is made for the purpose of a criminal or tortious act. Several states then want every party to agree, and their compliant route is announcing the recording at the start, which ends a test in its first sentence. In those states, log what happened and when rather than the audio. There is no works council here and nobody to consult, so the American file is short: your standing employee privacy notice, your recording map, and in California a documented risk assessment that workforce testing triggers by name.
What your company needs to do
6 items, in the order you will need them.
- Decide which lines are in scope, and write down whyUnited States-specificThis is the American decision and it cannot be deferred, because the statute gives a different answer for a desk phone, a home line and a mobile. If mobiles are in scope, take the prior express consent question to your counsel before the campaign rather than after it, and record what you were advised.
- Map your recording rule to where your people areUnited States-specificOne party is the federal floor and several states want everybody. Work from the list of states your employees are actually in, treat Delaware as an all party state until your counsel says otherwise, and where a state wants everybody, capture the outcome and the timestamp instead of the conversation.
- Write the California risk assessment if you employ people thereUnited States-specificThe privacy regulator's rules took effect on 1 January 2026 and workforce testing is an express trigger: automated processing that infers an employee's reliability or performance from systematic observation. The first assessments are due by the end of 2027, so this is live rather than forthcoming. The old employment exemption in the state privacy act expired at the start of 2023, whatever the consolidated text still appears to say.
- Put security testing in the standing employee privacy noticeCalifornia wants notice at or before the point of collection, and a standing notice that says exercises of this kind happen satisfies it. Telling somebody about a particular test does not, and would end the test anyway. Get this into the notice your workforce already receives rather than issuing a new one for the programme.
- Present a number your own organisation holdsThe caller identification offence needs misleading information plus an intent to defraud, cause harm or wrongfully obtain something of value, and an authorised internal test carries none of them. State that as an argument about the intent element and never as a general permission. The practical reason is separate: a number your provider can vouch for earns a full attestation, and an improvised display value gets labelled or blocked on the wire before anyone picks up.
- Check whether your own regulator already asks for thisNew York's financial services rules require annual awareness training that includes social engineering, which a programme like this satisfies without being mandated by it. Federal banking examiners list social engineering among the penetration tests management should consider. Nobody should tell you that either rule requires a simulated call, and the distinction is worth keeping straight when the programme is being justified internally.
The controls that do the work
How Callstrike is configured, and which provision in the United States each choice answers.
Auto-hangup before disclosure
The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.
This page is not going to overstate what this control does in the United States. The provisions that decide an American campaign bite on placing the call, not on what the call obtains, so ending the call early answers neither the artificial voice prohibition nor the opening identification requirement. What it does answer is the data side, and that is not nothing: the credential an employee starts to give is never spoken into the system, so it is not in the audio, not in the report and not inside the scope of the California assessment. It also keeps the federal recording exception clean, because that exception is lost where the purpose is a criminal or tortious act and a call built to stop before it takes anything is the opposite of that.
In-call debrief and follow-up
A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.
The federal one party rule turns on the purpose of the interception rather than on who agreed to it, so what the recording exists for is a live question rather than a formality. A call whose last minute is vishing training delivered by a second voice that breaks character on the spot, followed by an email that repeats it in writing, is evidence that the exercise was an awareness one. A caught employee, no explanation, and a report circulating three weeks later is the version that is hard to characterise that way.
Consent Management
Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.
Two jobs here and they are different. It produces the dated evidence that the standing notice reached a person before the campaign ran, which is what California asks for at or before the point of collection. And where you are building the argument that the employment relationship supplied prior express consent for calls to mobiles, the signed and timestamped record of what your staff were told is the evidence that argument stands on. It does not answer the requirement to identify the business at the start of an artificial voice message, and this page does not pretend otherwise.
SCORM module
An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.
The two rules that shape an American call are addressed to telephone calls: the prohibition on an artificial voice to certain lines, and the duty to name the business at the beginning of the message. A web call the learner starts in their own browser after working through the module is not a telephone call, so neither reaches it, and Callstrike's vishing simulator delivers the same deepfake voice through it. Be precise about the limit of that: the recording analysis does not change, because a state statute about recording a conversation does not care which network carried it.
Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.