TRAI’s new anti-spam framework is moving from customer warnings towards network-level enforcement, with AI-based detection, inter-operator sharing and tougher action against repeat violators. The phased rollout will also bring automated A2P calls under tighter controls, while repeat violations can result in a one-year disconnection and blacklist across telecom operators.
AI detection becomes part of TRAI’s enforcement framework
The Telecom Regulatory Authority of India notified the Telecom Commercial Communications Customer Preference (Third Amendment) Regulations, 2026 on September 18. The amendment formally brings AI and machine-learning-based suspected spam detection into the regulatory framework.
Under the new Regulation 21A, telecom service providers have to identify Customer Line Identifications, or CLIs, that have a high probability of being used for unsolicited commercial communications. Relevant information is then shared between telecom operators so that suspected spam activity can be investigated beyond the originating network.
This builds on a TRAI direction issued in February 2026 requiring operators to use AI/ML-based UCC intelligence for inter-operator sharing and further investigation.
Three complaints can now trigger action with AI corroboration
The revised framework lowers the complaint threshold from the earlier five-complaint trigger to three or more unique complaints within 10 days when the sender is also corroborated by the operator’s AI/ML detection system.
The framework also looks at multiple CLIs associated with the same sender. Five or more such CLIs flagged within a 10-day period can lead to investigation and graded enforcement measures, including KYC re-verification, physical verification, outgoing-service barring and, for repeated violations, disconnection.
This is important because the system is not designed around complaints alone. A complaint threshold and network intelligence are being combined before stronger action is taken.
Repeat offenders can lose telecom resources for one year
The amended framework provides significantly tougher consequences for subsequent violations.
For a repeat violation, the sender’s telecom resources can be disconnected by all access providers for one year. This can cover resources such as SIMs and PRI/SIP trunks, while the sender can also be placed in the blacklist category for the same period. New telecom resources cannot be provided by access providers to the blacklisted sender during that period.
The cross-operator element is particularly significant for businesses using multiple telecom providers. Enforcement is no longer limited to the individual number or network through which the offending communication was detected.
The rules also provide mechanisms for a sender to represent against enforcement action and appeal a decision, so disconnection is not simply an automatic consequence of an isolated customer complaint.
Automated and robocalls face new A2P requirements
Another major change concerns Application-to-Person, or A2P, voice calls.
Entities using A2P calling must pre-declare their use of automated calling and the relevant CLIs to their access provider. The framework covers automated calling systems, including autodialling and robocall-type operations. Undeclared A2P calls can be treated as unsolicited commercial communications.
TRAI has also introduced a termination charge of up to Rs 0.05 per minute for A2P calls. The charge is intended to create an economic deterrent against high-volume automated commercial calling, while specified commercial numbering series and authorised calls are treated separately under the framework.
For legitimate enterprises, this makes pre-declaration and accurate classification increasingly important, particularly where customer-service platforms, sales systems or automated voice applications generate large volumes of calls.
What happens to a suspected spam sender?
The enforcement process can broadly be understood as a sequence rather than a single AI decision.
First, the operator’s AI/ML system identifies CLIs with a high probability of being used for UCC. The information can then be shared with other access providers.
Where the prescribed complaint and network-detection conditions are met, the access provider can investigate the sender. Depending on the findings and the stage of violation, enforcement can progress through KYC or physical verification, outgoing-service barring and eventually disconnection.
For subsequent violations, the framework provides for all telecom resources of the sender to be disconnected across access providers for one year, accompanied by blacklisting and a restriction on obtaining new resources.
That distinction matters: AI detection identifies suspected activity, but the regulation does not simply say that an AI flag by itself permanently disconnects a business.
The 30, 60 and 90-day rollout
The new framework is being implemented in stages rather than requiring every provision to become operational on the same day. Reporting on the implementation schedule describes a 30-day stage for core AI-detection, A2P declaration and related mechanisms, followed by a 60-day stage for A2P termination charges and a 90-day stage for the lower complaint threshold.
The exact distinction between the notified regulation and its phased operational implementation is important for businesses because different compliance requirements can therefore arrive on different dates.
The regulation itself was formally notified on September 18, 2026, and TRAI’s regulations database lists the Third Amendment under its Quality of Service division.
What this means for consumers
For mobile users, the most visible change should be stronger action against persistent spam rather than another change to the DND registration process.
TRAI already allows consumers to report unsolicited commercial communications through 1909, the DND app and service-provider channels. The new framework connects those complaints with network-level intelligence and inter-operator enforcement.
The framework also introduces a consumer appeal mechanism for UCC complaint resolution, giving consumers a route to challenge how a complaint was handled.
For businesses, however, the compliance burden is becoming more significant. Companies using bulk voice, automated calling, SIP/PRI resources or multiple telecom providers will need clearer records of consent, calling purpose, numbering resources and A2P usage.
The broader shift is clear: TRAI is moving India’s anti-spam regime from a system that primarily identifies and warns subscribers about suspected spam towards one where operator-side AI intelligence can feed directly into regulatory enforcement and cross-network action.
