May 23, 2026
AI Cold Calling Compliance in Australia
Automated outbound is powerful, and in Australia it's also regulated. The good news is that the rules are clear, well-documented, and entirely compatible with running an agentic SDR — provided you build compliance in from the start rather than bolting it on later. This is a practical guide, not legal advice: confirm specifics with a qualified adviser and the regulator's own materials.
The two laws you must know
Australian outbound sits primarily under two regimes, both overseen by the Australian Communications and Media Authority (ACMA):
The Do Not Call Register Act 2006 governs telemarketing calls. Numbers on the Do Not Call Register generally may not be called for marketing purposes, and businesses must "wash" their calling lists against the Register.
The Spam Act 2003 governs commercial electronic messages — email, SMS, instant messaging. It requires consent, identification of the sender, and a functional unsubscribe in every commercial message.
Both apply regardless of whether a human or an AI agent places the call or sends the message. Automation is not a loophole.
Rule 1: Wash against the Do Not Call Register
Before an AI agent dials a marketing call, the number must be checked against the Do Not Call Register. Practically, this means your list-loading process integrates a Register wash and suppresses matched numbers. There are exemptions (for example, some existing-customer and public-interest categories), but treat them narrowly and document your basis.
For an AI system, the advantage is consistency: a properly configured agent always respects the suppression list, where a human dialler can slip. Wiring this into your data flow is part of a sound AI CRM integration — the suppression check is a tool the agent calls before every marketing dial.
Rule 2: Get consent right for messages
Under the Spam Act, commercial SMS and email need consent. Consent can be express (someone opted in) or, in narrower cases, inferred from an existing relationship — but inferred consent is easy to over-claim, so lean on express consent where you can. Keep records of how and when consent was obtained.
This shapes how you run SMS outreach and cold email: your agent should only message contacts with a lawful basis, and every message needs sender identification and a working unsubscribe.
Rule 3: Disclose appropriately
Transparency builds trust and increasingly reflects regulatory expectations. Being upfront that a caller is an AI assistant, and identifying the business on whose behalf it's calling, is good practice. The specifics of when and how to disclose an AI caller are evolving — we track them in telephone AI disclosure rules in Australia. Our own view is simple: disclose clearly and early. Prospects respond well to honesty, and it removes an entire category of risk.
Rule 4: Respect calling hours and frequency
Telemarketing rules include restrictions on permitted calling hours and standards around call conduct and frequency. An AI agent should be configured to call only within permitted windows for the recipient's location and to avoid harassing repeat-dialling. This matters especially for after-hours lead capture: responding to an inbound enquiry at 9pm is different from cold marketing at 9pm — know which one you're doing and set the guardrails accordingly.
Rule 5: Handle opt-outs instantly and permanently
When someone says "stop," the system must honour it immediately and permanently, across every channel. An agent that hears "take me off your list" on a call should suppress that contact from future calls and messages. Because the agent writes to your CRM in real time, opt-outs propagate instantly — a genuine advantage over paper-based or batch processes.
Why AI can be more compliant, not less
There's a lingering assumption that automation increases compliance risk. Done properly, the opposite is true:
- Consistency. Guardrails apply to every single interaction — no rep forgets the disclosure or the Register wash.
- Auditability. Every call and message is logged with a transcript, so you can prove what was said. This ties directly into agentic AI security and compliance.
- Human escalation. When a call raises anything sensitive — a complaint, a legal question, a vulnerable person — the agent escalates rather than improvising, per human-in-the-loop AI sales.
A practical compliance checklist
Before you switch on automated outbound:
- Wash every marketing list against the Do Not Call Register.
- Verify consent for every SMS/email contact and record its basis.
- Configure disclosure — identify the AI and the business up front.
- Set calling hours and frequency caps per recipient location.
- Wire opt-out handling to suppress instantly across all channels.
- Log everything for auditability.
- Define escalation triggers for anything sensitive.
Start from the ACMA telemarketing and spam guidance as your source of truth, and treat the Office of the Australian Information Commissioner's privacy materials as the companion reference for handling personal data.
The bottom line
Compliant AI cold calling in Australia is entirely achievable — the framework is clear and an agent that's configured well is often more consistent than a human team. The winning approach is to bake in Register washing, consent, disclosure, calling hours and instant opt-outs from day one. Get that foundation right and you can run fast, effective outbound with confidence.
For the broader picture of what a compliant agent does end to end, see what is an agentic SDR, and for the disclosure specifics, read telephone AI disclosure rules in Australia. This article is general information only and not legal advice.
