Callstrike
Compliance

Voice phishing simulations in the United States

Phone numbers in the United StatesDirect provisioning

The United States is the one country in this portal where your team rents the number itself with no approval in front of it, and the one where the hard question is not procurement at all. A voice phishing simulation is lawful here, and how far the federal telephone statute reaches it depends on the line you dial: a desk phone, a home line and a mobile get three different answers under the same section.

Phone numbers

Supplied by Callstrike

Local numbers in the United States.

Running a simulation

Permitted, and it turns on the line

One statute, three answers. The mobile is the line most of your staff will answer.

Consent

The statute's own mechanism

The telephone rules are built on prior express consent, and on a mobile that is the open question.

Getting a phone number in the United States

No approval step, and nothing to wait for.

Direct provisioning

Your team provisions numbers here directly from available inventory, with no approval step in front of it.

Nothing is filed and nothing is waited on. Your team searches the inventory in the console and rents an American number the same day, and there is no clearance form because there is no American regulator asking you for one. The reason is structural rather than lucky: the numbering rules are addressed to carriers and to authorised interconnected providers, and a business renting numbers from a provider is not an applicant under them. What the console offers you at the moment you look is the authority on what you can take, because the inventory is live rather than a published list.

Be ready for the things that look like American paperwork and are not regulatory clearance. Carrier onboarding checks, campaign registration, toll free verification, branded calling enrolment and caller name registration are all real, and they are processes run by carriers and industry registries rather than requirements imposed by the Federal Communications Commission. Knowing which is which is worth something specific: it tells you who you are negotiating with when somebody says a rule requires what in fact only their process does.

  1. 01Search the inventory and rent your numberYour team, in the Callstrike console.
  2. 02Build and launch the campaignYour team

No regulatory documentation is required to hold a number here, and there is no clearance step in front of it either. Your team rents the number from the inventory in the console and starts building the campaign.

Is it lawful to run a simulation in the United States?

The position in short, before your counsel reads the detail below.

Yes, and the American answer is not one answer, which is where almost every page on this subject goes wrong. The Commission ruled in February 2024 that the Telephone Consumer Protection Act's restrictions on an artificial or prerecorded voice reach current technologies that resemble human voices, so an AI voice is an artificial voice and you are inside that regime. What the regime does next depends on the line. An ordinary office wireline is in neither prong of the prohibition on the face of the statute. A home line is inside it with an exemption available for a commercial call that carries no advertisement and is not telemarketing. A mobile is inside it with no applicable exemption at all, and that is the line most of your staff will pick up.

On the mobile line the question is whether the employment relationship supplies prior express consent, and no ruling has decided it. Do not let anyone tell you that the Commission shut the door on consent, because it did not: what it refused was a request to write an exception for technology that purports to provide the equivalent of a live agent, which is a point about the technology and not about the mechanism. The statute underneath is a consent statute, and consent is precisely the American route. It is one to build deliberately with your own counsel rather than to assume, and the reason to be careful is the arithmetic: a private plaintiff can claim five hundred dollars a call, which across a workforce is the exposure that matters rather than any regulator.

One further rule shapes the call itself rather than its lawfulness, and it surprises people. Every artificial or prerecorded voice message must state at its beginning, clearly, the identity of the business responsible for initiating the call, under the registered name, and there is no security testing exception to it. A call that opens by naming your company is not a simulation. That is why the American design conversation is about which delivery you use rather than about which document you write, and it is the single most operationally important sentence on this page.

Recording is the other thing to settle before the first call, and the state that governs is usually where your employee is standing rather than where your head office is. Federal law needs one party, so a participant is covered, with a proviso worth reading: the exception is lost where the interception is made for the purpose of a criminal or tortious act. Several states then want every party to agree, and their compliant route is announcing the recording at the start, which ends a test in its first sentence. In those states, log what happened and when rather than the audio. There is no works council here and nobody to consult, so the American file is short: your standing employee privacy notice, your recording map, and in California a documented risk assessment that workforce testing triggers by name.

What your company needs to do

6 items, in the order you will need them.

  • Decide which lines are in scope, and write down whyUnited States-specificThis is the American decision and it cannot be deferred, because the statute gives a different answer for a desk phone, a home line and a mobile. If mobiles are in scope, take the prior express consent question to your counsel before the campaign rather than after it, and record what you were advised.
  • Map your recording rule to where your people areUnited States-specificOne party is the federal floor and several states want everybody. Work from the list of states your employees are actually in, treat Delaware as an all party state until your counsel says otherwise, and where a state wants everybody, capture the outcome and the timestamp instead of the conversation.
  • Write the California risk assessment if you employ people thereUnited States-specificThe privacy regulator's rules took effect on 1 January 2026 and workforce testing is an express trigger: automated processing that infers an employee's reliability or performance from systematic observation. The first assessments are due by the end of 2027, so this is live rather than forthcoming. The old employment exemption in the state privacy act expired at the start of 2023, whatever the consolidated text still appears to say.
  • Put security testing in the standing employee privacy noticeCalifornia wants notice at or before the point of collection, and a standing notice that says exercises of this kind happen satisfies it. Telling somebody about a particular test does not, and would end the test anyway. Get this into the notice your workforce already receives rather than issuing a new one for the programme.
  • Present a number your own organisation holdsThe caller identification offence needs misleading information plus an intent to defraud, cause harm or wrongfully obtain something of value, and an authorised internal test carries none of them. State that as an argument about the intent element and never as a general permission. The practical reason is separate: a number your provider can vouch for earns a full attestation, and an improvised display value gets labelled or blocked on the wire before anyone picks up.
  • Check whether your own regulator already asks for thisNew York's financial services rules require annual awareness training that includes social engineering, which a programme like this satisfies without being mandated by it. Federal banking examiners list social engineering among the penetration tests management should consider. Nobody should tell you that either rule requires a simulated call, and the distinction is worth keeping straight when the programme is being justified internally.

The controls that do the work

How Callstrike is configured, and which provision in the United States each choice answers.

Auto-hangup before disclosure

The bot ends the call at the moment an employee starts to give up a credential or a piece of personal data, so the thing the pretext asked for is never spoken into the system and never stored.

This page is not going to overstate what this control does in the United States. The provisions that decide an American campaign bite on placing the call, not on what the call obtains, so ending the call early answers neither the artificial voice prohibition nor the opening identification requirement. What it does answer is the data side, and that is not nothing: the credential an employee starts to give is never spoken into the system, so it is not in the audio, not in the report and not inside the scope of the California assessment. It also keeps the federal recording exception clean, because that exception is lost where the purpose is a criminal or tortious act and a call built to stop before it takes anything is the opposite of that.

In-call debrief and follow-up

A second voice breaks character as soon as the call ends, explains what just happened and why it worked, and a follow-up email repeats it in writing while the moment is still sharp.

The federal one party rule turns on the purpose of the interception rather than on who agreed to it, so what the recording exists for is a live question rather than a formality. A call whose last minute is vishing training delivered by a second voice that breaks character on the spot, followed by an email that repeats it in writing, is evidence that the exercise was an awareness one. A caught employee, no explanation, and a report circulating three weeks later is the version that is hard to characterise that way.

Consent Management

Two modes: collect consent now, over email, Slack or Teams with a full audit trail per employee; or record that your organisation already has this covered, by uploading the policy, handbook clause or agreement and confirming the scope it applies to. The document is hashed, the attestation is signed and timestamped, and an audit email is issued. Included on every plan.

Two jobs here and they are different. It produces the dated evidence that the standing notice reached a person before the campaign ran, which is what California asks for at or before the point of collection. And where you are building the argument that the employment relationship supplied prior express consent for calls to mobiles, the signed and timestamped record of what your staff were told is the evidence that argument stands on. It does not answer the requirement to identify the business at the start of an artificial voice message, and this page does not pretend otherwise.

SCORM module

An interactive web presentation on voice-phishing risk, delivered through your own LMS, which then invites the learner to opt into a web call with the bot. A call the person starts themselves in a browser is not a telephone call, so telephony rules do not reach it.

The two rules that shape an American call are addressed to telephone calls: the prohibition on an artificial voice to certain lines, and the duty to name the business at the beginning of the message. A web call the learner starts in their own browser after working through the module is not a telephone call, so neither reaches it, and Callstrike's vishing simulator delivers the same deepfake voice through it. Be precise about the limit of that: the recording analysis does not change, because a state statute about recording a conversation does not care which network carried it.

Consent Management is included on every plan. See AI voice phishing simulation and human-in-the-loop voice phishing for how each is delivered.

For your legal team

The sourced position

Everything above, with the instruments behind it. Every claim cites the statute or the regulator it comes from, so your counsel can verify it rather than rely on our summary.

What you have to document, and what you do not

There is no federal equivalent of the European lawful basis test, so there is no American document called a legitimate interest assessment and nothing to point to when someone asks which basis you are relying on. That is an absence rather than a gap in this page. The federal obligations that do exist, in the Safeguards Rule, the HIPAA Security Rule and the securities disclosure rules, are security programme duties, and none of them contains a basis test.

California is the exception, and it became one because an exemption expired rather than because anything was enacted. Section 1798.145(m) of the Civil Code still appears in the consolidated text and still reads as though employee data is outside the CCPA. Read to the end of the subdivision: paragraph (4) says it became inoperative on 1 January 2023, and the Legislative Counsel's own credit line at the foot of the section says the same. The words are still on the page and the rule is dead. If you check only the first paragraph you will reach the opposite of the truth.

So a California employer owes its own workforce the notice at collection in section 1798.100(a), which has to be given at or before the point of collection. That is satisfiable by a standing employee privacy notice that says security testing happens; it is not satisfiable by telling somebody about a particular test, which would end the test anyway.

California also now has the closest American thing to a data protection impact assessment, and workforce testing is an express trigger for it. The Privacy Protection Agency's regulations require a documented risk assessment before processing that uses automated processing to infer an employee's reliability or performance at work from systematic observation. A programme that scores who failed, and repeats across a workforce, is doing exactly that. The regulations took effect on 1 January 2026, and the first assessments are due to be completed by the end of 2027, so this is a live obligation rather than a forthcoming one.

On consultation there is genuinely nothing to consult. The United States has no works council, no co-determination body and no request-triggered consultation duty over workplace monitoring. The only statutory channel is collective bargaining under the National Labor Relations Act, and only where the workforce is already represented by a union. For a non-union employer there is no consultation instrument at all. A reader arriving from our German or Italian page should not go looking for the American equivalent, because there is not one.

Recording, and why the answer is your employee's state

The federal floor is one party. Section 2511(2)(d) of the Wiretap Act makes it lawful for someone who is a party to the communication, or who has one party's prior consent, to intercept it. There is a proviso worth reading rather than skipping: the exception is lost where the interception is for the purpose of committing a criminal or tortious act. The design point that follows is that the recording exists to evidence a security test, not to build a case against an individual.

Several states then require every party to agree, and in those states the compliant route collides with the exercise. Washington and Connecticut both offer a path that consists of announcing at the start of the call that it is being recorded, and Washington requires the announcement itself to be recorded. An announcement like that ends a simulation in its first sentence. Which leaves two honest options in an all party state: do not capture the audio at all, and log only what happened and when, or obtain genuine advance agreement from everyone, which telegraphs the test. There is no third route the statutes support.

The states below were each read in their own legislature's text. California is worth singling out because it has two provisions and the second is the one that catches a simulation: Penal Code section 632 turns on whether the conversation was confidential, but section 632.7 carries no such qualifier and reaches calls to and from mobile phones directly. Massachusetts is keyed on secrecy rather than on consent, so the prohibited thing there is the secret recording. Montana and Washington both accept a warning given by one party. Maryland makes a breach a felony carrying up to five years.

Delaware contradicts itself on its face and we are not going to resolve it for you. Title 11 section 1335 makes it a misdemeanour to intercept a private conversation without the agreement of all parties, while section 2402 of the wiretapping chapter says one party is enough. Both are current. Treat Delaware as an all party state or take it to your own counsel.

One thing this page will not do is hand you a complete map. The nine states we name are verified examples and not an exhaustive list of the states that require every party to agree. Six further candidates could not be read from their own legislatures during this research and are deliberately absent rather than described from memory, so their absence here means nothing at all about them. Check your own state before you record, and remember the state that governs is usually the one where the employee is standing when the phone rings, not the one your headquarters is in.

The TCPA, an AI voice, and which line you are dialling

In February 2024 the Federal Communications Commission ruled that the Telephone Consumer Protection Act's restrictions on an artificial or prerecorded voice reach current AI technologies that resemble human voices. In the same ruling it refused, in terms, to allow any carve out of technologies that purport to provide the equivalent of a live agent. That refusal is the reason this page cannot offer you the comfortable answer, and it is why you should be careful with any supplier who tells you a human on the line makes the rules go away.

Here is the part that almost every page on this subject gets wrong. The TCPA does not give one answer. Section 227(b)(1) has two prongs and they reach different lines. An employee's ordinary office wireline is in neither of them: the first prong lists emergency lines, patient rooms and wireless or charged-per-call numbers, and the second prong reaches residential lines. So on the face of the statute an artificial voice test call to a desk phone is outside the prohibition.

A call to an employee's home line is inside the second prong, but the Commission's rules exempt a call that is made for a commercial purpose but does not include or introduce an advertisement or constitute telemarketing, capped at three calls in any thirty day period and subject to an opt out. A security test fits that description, so on a residential line there is a route through.

A call to an employee's mobile is the hard one, and it is the line most people actually answer. It sits inside the first prong, which carries no marketing limitation at all, and the exemptions the Commission has made for wireless numbers are a closed list covering package deliveries, inmate collect calls, bank fraud alerts and healthcare messages. None of them covers workforce testing, and the Commission cannot simply add one: its general exemption power is written to reach only the residential prong. So lawfulness on a mobile turns entirely on whether the employment relationship supplies prior express consent, and that question is unsettled. No FCC ruling has decided it. The 2024 ruling does not address employer to employee calls at all. Take it to your own counsel and note that the statute gives a private plaintiff 500 dollars per call, which across a workforce sized campaign is the exposure that matters rather than regulatory enforcement.

There is a further rule that surprises people, and it is the practical one. Every artificial or prerecorded voice message must, at the beginning of the message, state clearly the identity of the business responsible for initiating the call, under the registered name. There is no security testing exception to it. A call that opens by naming your company is not a simulation, and any honest reading of the rules has to put that squarely in front of you rather than at the bottom of a page.

A live operator, speaking in real time on a manually placed call, is neither an automatic dialling system nor an artificial voice, so section 227(b)(1) does not attach to that call. It reduces exposure and it changes nothing else: the recording rules above, the caller identification rules below, and every sectoral duty apply unchanged. The moment any part of the audio is machine generated, the Commission's refusal quoted at the top of this section forecloses the argument that the operator's presence makes it a live call.

Presenting a number, and whether the call survives the network

Presenting a number that is not the one you are calling from is not by itself unlawful in the United States, and the reason is an element rather than an exception. The Truth in Caller ID provision makes it unlawful to transmit misleading or inaccurate caller identification information with the intent to defraud, cause harm, or wrongfully obtain anything of value. The FCC's rule uses the same words. Both are conjunctive: inaccurate information and one of those three intents. An authorised, contracted test run for the employer's own defensive purposes does not carry any of them.

State that as an argument about the intent element and never as a general permission. The two exceptions the rule does spell out are for law enforcement activity and for conduct under a court order that specifically authorises caller identification manipulation. An employer has neither and must not claim either.

The constraint that will actually decide whether your call connects is technical. Carriers authenticate the calls they originate and attach an attestation saying how much they can vouch for. A number your own provider has assigned to you can carry a full attestation. A number belonging to somebody else cannot, and the weaker signal makes it more likely the call is labelled or blocked before anyone picks up. The originating provider makes that decision, not you. This is the practical reason to run a simulation from a number your organisation actually holds, quite apart from the identification duty in the previous section.

What the country matrix holds for the United States

Number types:
Local, Toll free
Restricted for automated outbound:
None recorded

Generated from the same country matrix the platform enforces at dispatch, so it cannot drift from what you can actually buy.

Why there is no American clearance to wait for

There is no regulatory submission to prepare here, and that is a real finding rather than an omission. The FCC's numbering rules govern who may draw numbers from the North American Numbering Plan, and that means carriers and authorised interconnected voice providers. An applicant under those rules has to supply an operating company number, which is a carrier identifier. A business renting numbers from a provider is not an applicant and has nothing to file.

We looked for an end user obligation and there is none to cite. No rule requires a company using American telephone numbers to hold a local address, to be registered in the United States, or to identify in advance the people it intends to call.

Be careful with what you will nonetheless be asked for. Carrier onboarding checks, campaign registration, toll free verification, branded calling enrolment and caller name registration are real, and you may well have to complete several of them before a single call goes out. They are commercial and industry body processes operated by carriers and registries. They are not FCC requirements, and we are not going to describe them as regulatory clearance when they are not. Knowing which is which matters when somebody tells you a rule requires something that in fact only their process does.

Where your regulator asks for this by name

New York's financial services rules are the most direct in the country. Part 500 requires every covered entity to provide periodic, and at minimum annual, cybersecurity awareness training that includes social engineering, updated to reflect the risks the entity identified in its own risk assessment. Read the words precisely, because the difference matters commercially: it mandates training that includes social engineering. It does not in terms mandate simulated attacks, and anyone telling you New York requires vishing simulation is selling rather than advising.

The federal banking regulators go one step further in their examination handbook, which describes a penetration test as targeting systems and users, and lists social engineering among the types of penetration test management should consider when deciding on coverage. That is examiner guidance rather than a rule, but it is the guidance your examiner works from.

For the much wider set of businesses the Federal Trade Commission treats as financial institutions, the Safeguards Rule requires security awareness training for personnel and, absent effective continuous monitoring, annual penetration testing based on the risk assessment. Healthcare organisations have a mandatory security awareness and training standard under the HIPAA Security Rule, though its implementation specifications are addressable and none of them names phishing or voice testing, so do not let anyone tell you HIPAA requires this.

Public companies face a disclosure duty rather than a testing duty. The securities rules require a description of the processes for assessing, identifying and managing material cybersecurity risks, including whether third parties are engaged in those processes, and a description of board oversight. A company that runs social engineering testing has something to describe. The rule does not require the testing itself, and the distinction is worth keeping straight when the programme is being justified internally.

Take this further

Research prompt for your own AI assistant

Paste into Claude, Harvey or your firm's tool to pressure-test the position above.

You are advising on an authorised internal security exercise in the UNITED STATES. Our own employees receive a simulated voice-phishing call, placed by our vendor on our instruction, to measure susceptibility. No credential is captured or stored. The workforce is informed in advance through a standing security testing policy.

Verify or correct each proposition below against primary United States sources, and tell me what we must document before the first call:

1. 47 U.S.C. 227(b)(1) reaches an ordinary office wireline in neither prong, reaches a residential line through (b)(1)(B), and reaches a mobile through (b)(1)(A)(iii) with no marketing limitation.
2. 47 CFR 64.1200(a)(3)(iii) exempts a commercial, non-advertising, non-telemarketing call to a residential line, and 227(b)(2)(B) limits the Commission's exemption power to paragraph (1)(B), so that exemption cannot be extended to mobiles.
3. Whether the employment relationship supplies prior express consent for a call to an employee's mobile. Identify any FCC ruling, court decision or petition on the point, and advise how consent should be obtained and evidenced if it is the route.
4. FCC 24-17 places AI-generated voices inside the artificial voice regime and refused an exception for technology purporting to provide the equivalent of a live agent. Confirm it says nothing about employer to employee calls.
5. 47 CFR 64.1200(b)(1) requires an artificial or prerecorded voice message to identify the responsible business at the beginning, with no security testing exception.
6. 18 U.S.C. 2511(2)(d) supplies a one-party rule with a criminal or tortious purpose proviso, and identify every state where our employees sit that requires all parties.
7. The CPPA risk assessment regulations (11 CCR 7150 to 7157) are triggered by automated processing inferring employee reliability or performance, effective 1 January 2026 with first assessments due by the end of 2027.
8. No FCC numbering rule imposes an end user filing; campaign registration and caller name registration are industry processes rather than regulatory clearance.

Flag anything that has changed since September 2026, and name any state statute or sectoral rule this analysis omits.

Common questions

Does the TCPA stop us running an AI voice simulation on our own staff?
It depends on the line. A desk phone is outside the prohibition on the face of the statute. A home line has a commercial non-advertising exemption. A mobile sits inside with no exemption available, and whether employment supplies prior express consent is unsettled, so that one belongs with your counsel.
Is it legal to present a different caller ID for a simulation?
The offence requires misleading caller identification plus an intent to defraud, cause harm or wrongfully obtain something of value. An authorised internal test carries none of those. That is an argument about the intent element, not a general permission, and the written exceptions cover only law enforcement and court orders.
Can we record the simulated calls?
Federal law needs one party, so as a participant you are covered. Several states require everyone, and their compliant route is announcing the recording, which ends the test. In those states, capture outcomes rather than audio. The state that governs is usually where your employee is, not where you are.
Do we need a works council or a union to agree first?
There is no American works council and no co-determination body, so for most employers there is nobody to consult. Where a union already represents the workforce, the duty to bargain over terms and conditions of employment is the only statutory channel, and whether this programme falls inside it is Board case law we have not verified.

Elsewhere in the Americas

The rules differ by country even inside one region. These are the nearest guides to this one, each showing how phone numbers are obtained there.