India has significantly strengthened its regulation of spam calls and unwanted commercial communications.
On September 18, 2026, the Telecom Regulatory Authority of India, or TRAI, amended the Telecom Commercial Communications Customer Preference Regulations, 2018, known as TCCCPR 2018. The goal is to strengthen the regulatory framework for curbing unsolicited commercial communications, or UCC, protecting consumers from spam and preventing the misuse of telecom resources.
The core of the amendment is that spam will no longer be handled only after consumers complain.
In the past, spam response largely followed a complaint-based model. A consumer reported unwanted communication, a telecom operator verified the complaint, and action followed if certain thresholds were crossed. But spam calls, robocalls and automated commercial communications now spread faster and at larger scale. This is no longer an era in which people manually dial numbers one by one. Software and automated platforms can use large pools of numbers to make calls and send messages at scale.
Regulation therefore has to change as well.
In the new amendment, TRAI explicitly incorporates AI/ML-based detection of suspected UCC into regulatory enforcement. Major telecom service providers have already deployed AI/ML systems to detect suspected spam communications and alert users. TRAI also issued a direction on February 27, 2026, requiring telecom service providers to share AI/ML-based intelligence on suspected UCC with one another and conduct further investigation of suspected senders. The amendment now brings that direction into the regulatory framework.
In other words, India is treating spam enforcement as a telecom-network data problem.
Which numbers repeatedly make commercial calls?
Which calling-line identifications, or CLIs, are flagged as suspicious across multiple operators?
Do senders that AI systems classify as likely UCC also appear in consumer complaints?
Are multiple numbers connected to the same sender over a short period?
The idea is to have telecom operators share these signals, conduct earlier investigations and apply graded enforcement.
Under the amendment, when five or more CLIs associated with a sender are flagged within a period of ten days, access providers must initiate further investigation and graded action. These actions may include KYC re-verification, physical verification, barring of outgoing services and, in cases of repeated violations and misuse of telecom resources, disconnection of telecom resources.
This is designed to respond to the way spam senders avoid enforcement by rotating numbers.
The spam industry does not operate through only one number. It rotates numbers, changes sender information and uses large-scale telecom resources. Blocking one number is therefore not enough. If several CLIs connected to the same sender generate suspicious signals, enforcement must move from the number level to the sender level.
That is also why AI/ML detection matters.
Humans cannot verify every spam call. If enforcement waits for complaints, many consumers may already have received the calls. But if telecom-network data and AI-based detection are combined, suspicious patterns can be identified earlier. Of course, false positives are a risk. For that reason, TRAI has said that designated numbering series used for legitimate commercial and government communications, including 140xx, 1600xx and 1601xx numbers, should not be displayed to recipients as suspected spam.
This point matters.
Stopping spam cannot mean blocking all commercial communication. Authentication calls from banks, government notifications, delivery updates, reservations and payment-related service calls can be necessary for consumers. The challenge is distinguishing necessary communication from unwanted spam. TRAI is trying to balance that distinction through designated numbering series and a regulated framework.
The second core element is regulation of A2P calls.
A2P stands for application-to-person. It refers to calls made to people not through direct human dialing, but by applications, software systems or automated platforms. TRAI sees A2P calls as increasingly used for large-scale commercial communication, with automation and mass-calling capability creating the risk of misuse for spam calls.
The amendment clearly defines A2P calls. They include voice calls initiated by an application, software system or automated platform without direct human dialing and delivered to individual telecom subscribers, including autodialing, robocalls and pre-recorded or artificial-voice technologies.
All entities using A2P calls must declare such use and the CLIs they will use to telecom service providers in advance. Any A2P call made without prior declaration will be treated as UCC.
This provision is especially meaningful in the age of AI voice.
In the past, robocalls mostly played pre-recorded voices at scale. Now, generative AI and voice-synthesis technologies can enable automated calls that sound increasingly human. If financial scams, insurance or loan marketing, political campaigns, false notifications and phishing calls are combined with AI-generated voices, the scale of harm can increase.
TRAI is bringing this risk into a prior-declaration framework through the category of A2P calls.
That is a sound direction. As communication becomes more automated, regulation must identify the point where automation begins. Regulators must be able to know whether a call was made manually or by software, which number was used and which operator allowed the communication.
To create a deterrent effect for A2P calls, TRAI allows terminating access providers to charge originating access providers a termination charge of up to 0.05 rupees per minute. However, calls from regulated commercial numbering series or calls approved by authorities are exempted.
This creates an economic signal.
Spam grows because it is cheap. When the cost of automated mass calling is low, senders can profit even if the success rate is very small. Termination charges can change the cost structure of large-scale A2P calls and discourage indiscriminate automation.
The third change narrows the scope of commercial communication based on consumer inquiry.
When a consumer inquires about a product or service, a sender may contact the consumer on the basis of that inquiry. But TRAI has limited this permission to seven days from the date of the inquiry. It also requires that the inquiry be made in written or digital form and kept by the sender in a verifiable manner to prevent misuse.
This is a practical exception for e-commerce and digital-service platforms.
If a consumer asks for a car-insurance quote, real-estate information or an online service consultation, a business may need to respond for a limited period. But if that inquiry is treated as permanent marketing consent, the consumer may continue receiving unwanted calls and messages.
The seven-day limit draws that boundary.
Responding to an inquiry is allowed.
Turning an inquiry into a long-term sales right is not.
And the fact of inquiry must be preserved in a verifiable form.
The fourth change is a consumer appeals mechanism.
TRAI has introduced an appeal process for consumers who are dissatisfied with the resolution of UCC complaints. Consumers may file an appeal within 15 days of complaint resolution, using the same existing complaint channels: the TRAI DND app, telecom service-provider apps or portals, or the 1909 voice-call or SMS route.
This strengthens consumer protection.
Spam victims often do not know whether their complaints were properly handled. Even when a telecom provider says action was taken, the sender may continue calling. A structure that allows consumers to appeal unsatisfactory complaint outcomes is necessary for trust in the regulatory system.
The fifth change is earlier complaint-based action.
Under the earlier framework, action against a UCC sender was triggered when five or more unique complaints were received within ten days. The new amendment combines AI-system suspicion with consumer complaint data. If a sender’s CLI has been flagged as suspected UCC by an AI/ML system and three or more unique complaints are received within ten days, action can begin.
This is an important design.
TRAI is not relying only on AI.
It is not simply waiting for consumer complaints either.
It combines AI detection with complaint data.
This approach tries to reduce both false positives and delay. If AI detects a suspicious signal but there are no consumer complaints, enforcement can be cautious. If complaints are relatively few but AI signals exist as well, enforcement can move faster. The combination of data sources becomes central to regulatory action.
The sixth change expands the scope of explicit consent.
TRAI has broadened the definition of consent so that legacy consents already held by entities may be recognized under certain conditions. But such consent must have been obtained in a verifiable manner and must subsequently be registered on a digital platform of the telecom service provider to be considered valid.
This provision adjusts the conflict between regulatory change and business reality.
Companies already hold large volumes of customer consents. If a shift to a digital consent system invalidates all existing consent, industry disruption could be severe. But if all legacy consent is recognized without safeguards, it could become a channel for spam.
TRAI chose a compromise based on verifiability and digital registration.
Past consent may be recognized, but it must be provable.
And it must be registered within the telecom-network platform.
Consent must become regulated data, not merely an internal corporate record.
The seventh change addresses misuse of headers and content templates.
In India’s commercial messaging framework, sender headers and content templates play an important role. Businesses must send messages using registered headers and approved templates. But if headers or templates are misused, spam or fraud can appear to come from legitimate senders.
The new amendment requires the originating access provider to suspend a misused header or content template within six hours of becoming aware of misuse, and to inform the concerned sender. The sender must take corrective action to prevent further misuse and report the matter to law-enforcement agencies. If the misuse is attributable to a telemarketer, all telecom resources of that telemarketer may be disconnected across all telecom service providers and the telemarketer may be blacklisted for one year.
This is a strong sanction.
The problem of spam and phishing is not merely annoyance. It can lead to financial fraud, identity theft and malicious-link distribution. If trusted business headers or sender information resembling banks or government agencies are misused, consumers can be deceived easily. Header and template misuse therefore requires rapid blocking.
The eighth change strengthens contract conditions among access providers, senders and telemarketers.
TRAI noted that although the regulatory framework requires telecom providers to impose contractual obligations on senders and telemarketers to comply with the rules, competitive pressures often discourage providers from including strict conditions. The amendment empowers TRAI to prescribe mandatory clauses that must be included in agreements between access providers and senders or telemarketers.
This shows the reality of telecom regulation.
To stop spam, telecom providers must act actively. But senders and telemarketers are also customers of telecom providers. If competition is intense, a provider that imposes strict conditions may lose customers. As a result, everyone may become too lenient.
TRAI is trying to solve this by allowing the regulator to set standard contractual conditions.
The ninth change is sender classification.
Not all senders are the same. Banks, hospitals, government agencies, e-commerce platforms, small marketing firms and large telemarketers differ in service importance, economic impact, scale of telecom-resource use and consumer impact if service is interrupted. TRAI now allows senders to be classified into categories and differential enforcement actions to be applied in case of violation.
This is a more refined approach.
If regulation is too blunt, it creates side effects. Immediately cutting off telecom resources for an important service sender can harm consumers. On the other hand, weak action against malicious telemarketers allows spam to continue. Enforcement should vary according to sender type, risk and social importance.
The tenth change concerns call-management apps.
TRAI has prohibited call-management applications from blocking, filtering or tagging as spam, in bulk, calls from designated numbering series such as 1600xx and 1601xx service or transactional calls and 140xx regulated promotional calls, or other series designated by authorities or the central government. The concern is that such tagging can incorrectly mark genuine commercial or government communications as spam. Individual users retain the freedom to block or filter calls on their own devices.
This provision is interesting.
In Korea, spam-blocking apps are generally viewed as consumer-protection tools. But TRAI is wary of private apps treating public or regulated commercial numbering series as spam by default. Since these numbering series already operate under a regulatory framework, indiscriminate tagging by private apps could block necessary communications.
TRAI also requires that if a call-management app allows users to report unsolicited commercial communication under any label such as spam or junk, those reports must be sent to the distributed ledger technology, or DLT, platform operated by the access provider.
This is about data integration.
If spam reports remain trapped inside private apps, they are difficult to use for regulatory enforcement. If complaint data flows into the DLT platform, telecom operators and regulators can use it to sanction senders. TRAI is trying to bring private-app consumer touchpoints into the formal regulatory data system.
The eleventh change strengthens DLT platform access for VNOs.
Virtual network operators, or VNOs, are also considered access providers under the regulatory framework and must comply with obligations. To enable that compliance, network service operators must give VNOs access to DLT platforms and necessary systems through digital interfaces with real-time capabilities. This is intended to solve operational difficulties VNOs face in accessing DLT platforms.
The overall direction of the amendment is clear.
Spam is not being treated merely as individual inconvenience.
It is being treated as misuse of telecom resources.
AI/ML detection and consumer complaints are being combined.
Automated A2P voice calls are being brought into the regulatory system.
Consent, senders, templates, headers, call-management apps and VNOs are being connected into one ecosystem.
TRAI said the amendment aims to strengthen consumer confidence in the commercial communications ecosystem, increase accountability across stakeholders and enable more effective and faster action against misuse of telecom resources by spammers.
This matters because of the scale of India’s telecom market.
India is one of the world’s largest mobile user markets. Phone numbers are connected to finance, e-commerce, public services, authentication, delivery, healthcare and education. In such a market, spam and robocalls are not merely inconveniences. They weaken trust in the digital economy as a whole.
If spam calls become too frequent, consumers stop answering unknown numbers.
Then legitimate calls from banks, hospitals, delivery services and government agencies also suffer lower reach.
If scam calls increase, trust in digital services weakens.
Companies face higher customer-contact costs.
Telecom networks become polluted with low-cost bulk traffic.
Spam enforcement is therefore telecom-quality policy and digital-economy policy.
The problem becomes even larger as AI voice and automated calls spread. In the past, spam calling required human agents. Now, voice synthesis, automated dialing and generative scripts can enable more natural mass calling at far lower cost. Consumers may find it harder to distinguish whether they are speaking to a human or to AI.
TRAI’s explicit definition of A2P calls, robocalls, pre-recorded calls and artificial-voice technologies reflects this shift.
Spam in the AI era is no longer just a few lines of text.
It is an automated call that sounds human.
It is personalized phishing.
It is fraud at scale.
It is automation that blurs the boundary between commercial marketing and financial crime.
That is why regulators must connect sender identity, numbers, consent, complaints, AI detection and platforms into a single system.
The implications for Korea are significant.
Korea also faces serious problems with spam text messages, voice phishing, robocalls, illegal telemarketing and loan or investment solicitation calls. If AI voice synthesis and automation tools become widespread, existing voice-phishing response systems may come under greater pressure. Criminals will be able to approach more people, faster and more naturally.
There are four points Korea can study.
First, a system for sharing telecom operators’ AI detection data across providers.
Spam does not remain inside one telecom network. If numbers and senders move across networks, signal sharing among operators becomes necessary.
Second, prior declaration for A2P calls.
If companies use automated mass voice calls, they may need to declare in advance which numbers will be used, for what purpose and through which systems.
Third, combining AI detection with consumer complaints.
Trusting only AI creates false-positive concerns. Waiting only for complaints is too slow. Combining both signals enables enforcement that is faster and better grounded.
Fourth, linking private spam-blocking app data to public regulatory platforms.
If user reports do not remain trapped inside apps but flow into an official regulatory system, enforcement becomes stronger.
There are also points that require caution.
AI-based spam detection can create problems of false positives, discrimination and transparency. If legitimate calls from small businesses, hospitals, delivery companies or public agencies are incorrectly blocked, harm can occur. Indiscriminate spam tagging by private apps can also unfairly restrict expression and legitimate business activity. Regulation must therefore be strong, but it must also include appeal, numbering-series management, sender classification and verifiable consent.
TRAI’s inclusion of consumer appeals, sender classification and protection for designated numbering series suggests awareness of this balance.
Use AI to detect spam, but do not trust AI alone.
Accept complaints, but do not wait only for complaints.
Protect legitimate communication, but act quickly against misuse.
Give consumers blocking tools, but also build a public complaint-data system.
That is the policy meaning of this amendment.
Telecom regulation in the AI era is no longer only about managing phone numbers. Sender identity, consent data, automated systems, AI detection, consumer complaints, private apps, digital platforms, telecom contracts and law-enforcement reporting are all connected. Spam has evolved technologically, and regulation must evolve technologically as well.
India’s TRAI amendment shows that direction.
It uses AI to catch spam, and regulates spam made more powerful by AI.
It is a structure in which the intelligence of the telecom network responds to the automation of the spam industry.
Ultimately, the essence of this measure is not only consumer protection, but restoration of trust in communications.
If phone calls can no longer be trusted, the digital economy is shaken.
Authentication calls, bank notices, delivery contacts, public alerts and medical consultations all become suspect.
When spam pollutes the telecom network, legitimate communication is harmed as well.
India is therefore asking:
Who is making the call?
Which number is being used?
Was it declared in advance?
Did the consumer consent?
Did AI detect suspicious signals?
Do consumer complaints match those signals?
If misuse is confirmed, how quickly should the connection be cut?
These questions are likely to become central to telecom regulation in many countries.
The age of spam is not over.
It is becoming stronger through AI and automation.
Regulation must therefore become smarter too.

