Telecom operators in India can now take action against suspected spam callers identified by their AI and machine-learning systems even when consumers have not filed a complaint. The change comes under the Telecom Commercial Communications Customer Preference (Third Amendment) Regulations, 2026, which brings network-level AI detection into the regulatory enforcement framework.
TRAI notified the Third Amendment on September 18, but details of how the AI-led enforcement mechanism works are now drawing attention. The framework allows operators to identify suspected Unsolicited Commercial Communication (UCC), share information across networks, re-check KYC details and impose progressively stronger action against repeat offenders.
AI Detection Can Trigger Action Without a Consumer Complaint
The biggest change is that telecom operators no longer have to rely exclusively on consumer complaints to identify potential spam senders.
Under Regulation 21A, operators must use AI/ML-based UCC detection systems to identify Calling Line Identifications (CLIs) that have a high probability of being used for UCC and share relevant information between operators. TRAI had already directed operators in February 2026 to use AI/ML-based UCC detection and inter-operator sharing; the Third Amendment incorporates that framework into the regulations.
When an operator’s system flags an incoming call as suspected spam, the information must be shared with the originating access provider through the telecom industry’s Distributed Ledger Technology platform within two hours.
The originating operator must then identify the sender using its KYC records within one business day and share the relevant information with other operators. Those operators must also check whether the same sender is associated with other connections on their networks.
Five AI-Flagged CLIs Within 10 Days Trigger Graded Action
Importantly, the new system does not mean that every AI flag immediately results in a disconnection.
The regulatory trigger is linked to the number of CLIs associated with the same sender. If five or more CLIs belonging to a sender are identified as suspected UCC within 10 days, the access providers must initiate action against that sender.
The subsequent enforcement is graded.
Operators can be required to carry out KYC re-verification and, in repeated cases, physical verification. Depending on the findings and the history of violations, outgoing services can be barred and telecom resources can ultimately be disconnected.
For the first violation triggered through the AI-based mechanism, outgoing services associated with the sender’s telecom resources can be barred across operators for 15 days. This applies to the sender’s telecom resources even when an individual resource was not itself used to make the suspected spam communication.
Repeat Spammers Can Face a One-Year Industry-Wide Ban
The consequences become considerably stronger when the activity is repeated.
For subsequent violations, the framework provides for disconnection of the sender’s telecom resources, including SIMs and PRI/SIP resources, across access providers for one year. The sender can also be placed on a blacklist, with operators barred from providing new telecom resources during that period.
This is significant for businesses or operations that rely on large numbers of telecom resources. Changing a SIM or moving activity between operators is less useful if the sender’s identity and associated telecom resources are being mapped across networks.
The Complaint System Still Matters
The new AI mechanism does not eliminate the consumer complaint system.
In fact, TRAI has separately strengthened the complaint-based route. The earlier framework used a threshold of five or more unique complaints within 10 days. Under the amended rules, action can be triggered with three or more unique complaints within 10 days when the sender’s CLI is also flagged by the operator’s AI/ML system as suspected UCC.
This creates two complementary detection routes: network-level AI can identify suspicious behaviour independently, while consumer complaints can strengthen the case when they are corroborated by the AI system.
That is different from saying that complaints are no longer relevant.
What Network-Level AI Is Looking For
The purpose of the AI/ML system is to identify behavioural patterns associated with suspected UCC rather than relying solely on an individual user’s report.
The framework refers to AI/ML-based systems operated by access providers for identifying suspected UCC. In practice, the detection process can examine communication behaviour and identify CLIs that show a high probability of being used for unsolicited commercial communication. TRAI’s earlier AI/ML direction established the basis for sharing these suspected UCC signals between operators.
This network-level approach is particularly relevant to senders operating multiple numbers, because information about related CLIs can be connected through KYC identifiers and checked across operators.
Legitimate Businesses Could Still Be Affected by False Flags
The move also raises an important implementation question: how accurately can AI systems distinguish genuine commercial communication from unwanted spam?
A legitimate business may generate high outbound call volumes, automated calls or repeated calls to customers. Such behaviour can resemble spam patterns even when the communication is permitted or expected.
TRAI’s framework therefore does not describe an AI flag as the final determination of wrongdoing. The five-CLI threshold leads to further investigation and graded measures, including KYC and physical verification. The framework also provides mechanisms for representation and appeals in relevant parts of the UCC enforcement process.
That distinction matters because an automated detection system can identify a suspicious pattern, but enforcement still has to account for the identity of the sender, the nature of the communication and the applicable regulatory requirements.
A2P Calls Also Come Under the New Framework
The Third Amendment also addresses Application-to-Person (A2P) voice calls, including calls initiated through applications, software or automated systems.
Such calling activity has to follow the regulatory framework, including applicable declaration requirements. Undeclared A2P calls can be treated as UCC, giving operators another mechanism to act against automated commercial calling that does not comply with the rules.
The changes therefore go beyond simply identifying individual spam numbers. They are intended to make telecom networks more capable of detecting and tracing the sources of unwanted commercial communications.
What Changes for Indian Mobile Users
For consumers, the most important change is that reporting a spam call is no longer the only path through which a suspicious sender can come under regulatory scrutiny.
If an operator’s AI system detects a high-probability UCC pattern, the number can enter the inter-operator detection and verification process without waiting for an individual complaint. If multiple CLIs associated with the same sender are flagged within the prescribed period, graded enforcement can follow.
The system is therefore moving toward a combination of AI detection, cross-network intelligence, KYC verification and consumer complaints, rather than depending on any one of these mechanisms alone.
For India’s telecom operators, that represents a significant change in how spam enforcement can be performed at the network level. For users, the intended benefit is faster identification of persistent spam sources without requiring every unwanted call to first generate a formal complaint.
