← Back to articles

Collections AI Compliance Guide 2026: FDCPA, TCPA & FHA

Property managers: Your 2026 glossary to Collections AI Compliance—FDCPA, TCPA, Reg F, and Fair Housing. See penalties, guardrails, and consent rules.

Collections

TL;DR

Collections AI compliance refers to the body of federal and state regulations governing the use of artificial intelligence tools for rent and debt collection. Property managers face unique risks because they may be classified as third-party debt collectors under the FDCPA, and AI-generated voices are now treated as robocalls under FCC rules. Fair Housing Act obligations add another layer that most compliance guides ignore entirely. This glossary breaks down every regulation, term, and penalty that matters when using AI to collect rent.

Why Property Managers Need a Collections AI Compliance Glossary Now

AI-powered rent collection is no longer theoretical. YC-backed startups like Altur have already collected over $6 million using only AI agents in their first six months of operation. CollectWise claims its platform doubles recovery rates while cutting collection costs by 75%. The technology works, and it’s scaling fast.

But the regulatory environment is scaling just as fast. TCPA class actions hit 507 in Q1 2025 alone, more than double the same period the prior year. FDCPA lawsuits reached 396 filings in January 2026 by itself. And the FCC has explicitly classified AI-generated voices as robocalls, meaning every AI call your system makes carries consent requirements that didn’t exist two years ago.

The problem: every existing compliance guide targets general debt collectors. None address property management specifically. That leaves property managers asking a basic question with no clear answer: “If I use AI to collect rent, what laws apply to me?”

This glossary answers that question. Every term is defined through the property management lens, covering the regulations, penalties, and AI-specific concepts that matter for rent collection.

Haven’s AI property management platform is building Collections AI with compliance baked in from the start. Here’s the regulatory framework it’s designed around.

Which Laws Apply Based on Your Role?

This is one of the biggest missing pieces.

Readers constantly wonder:

"Does this law even apply to me?"

Create this table.

Your Situation

FDCPA

TCPA

FHA

UDAAP

Landlord collecting own rent

Usually No

Yes

Yes

Possibly

Property manager collecting for owner

Often Yes

Yes

Yes

Yes

Collection agency

Yes

Yes

No

Yes

Law firm collecting rent

Usually Yes

Yes

No

Yes

Core Federal Laws Governing Collections AI

FDCPA (Fair Debt Collection Practices Act)

The FDCPA is the foundational federal law protecting consumers from abusive debt collection tactics. Congress enacted it to prohibit debt collectors from using unfair, deceptive, or abusive practices when collecting consumer debts.

Why property managers should care: The FDCPA generally applies only to third-party debt collectors, not original creditors. This creates a critical distinction. A landlord collecting their own past-due rent is typically exempt. But a property management company collecting rent on behalf of a property owner? That’s where things get complicated.

Anyone who attempts to collect rent on behalf of a property owner or landlord qualifies as a “debt collector” under the FDCPA and must follow its rules. Case law is mixed on whether third-party management companies can avoid this classification, which means compliance is essential regardless of how you interpret your status.

Penalties bite hard. Consumers can seek actual damages or statutory damages of up to $1,000 per violation, plus attorney fees. Class actions cap total statutory damages at the lesser of $500,000 or 1% of the collector’s net worth. And because FDCPA violations also constitute unfair practices under the FTC Act, the FTC can pursue civil fines exceeding $50,000 per violation.

For a deeper look at how AI intersects with housing regulations, see this Fair Housing compliance guide.

Regulation F: The 7-in-7 Rule and Beyond

Regulation F is the CFPB’s implementing rule for the FDCPA, and it introduced the now-famous “7-in-7” rule: no more than seven call attempts per particular debt in a rolling seven-day period. Third-party debt collection agencies must also provide written notice within five days of initial contact.

The critical mistake practitioners make is treating 7-in-7 as a quota rather than a ceiling. Seven calls is the maximum tolerable exposure, not a target. State laws often impose stricter limits.

Regulation F also governs digital communications, including email and text messaging, with opt-out requirements and timing restrictions. For AI systems that communicate across multiple channels (phone, SMS, email), the regulation’s contact-frequency rules apply to each channel, and the cumulative effect matters.

TCPA (Telephone Consumer Protection Act)

This is arguably the single biggest compliance risk for any property manager considering AI voice tools for collections.

Under the TCPA and the FCC’s 2024 declaratory ruling, AI-generated or “synthetic” voices are treated the same as prerecorded messages or robocalls. It doesn’t matter if your AI sounds human. It doesn’t matter if it’s interactive. If the voice is AI-generated, the same restrictions apply.

The practical consequence: you cannot use AI phone agents to call or text a consumer unless you already have prior express consent. Practitioners on Retell AI’s TCPA compliance blog highlight a commonly misunderstood point: an Established Business Relationship (EBR) exempts you from Do-Not-Call rules for manual calls, but it does NOT exempt AI voice calls from consent requirements. The AI voice itself triggers the consent obligation, regardless of your existing relationship with the consumer.

Penalties range from $500 to $1,500 per call, with no aggregate cap. For a property manager with hundreds of units, a single flawed AI calling campaign could generate six or seven figures in liability within days.

Understanding how AI calls are routed and managed is a prerequisite for TCPA compliance.

UDAAP (Unfair, Deceptive, or Abusive Acts or Practices)

UDAAP is the catch-all. The CFPB has explicitly stated that its policy on abusive conduct covers abusive uses of AI technologies. The agency examines for discrimination across all consumer finance markets, including collections.

What makes UDAAP particularly dangerous for AI collections: a communication sequence can comply with every Regulation F timing and disclosure requirement and still create exposure. Regulators assess the cumulative consumer experience, not isolated steps. If your AI sends a text, follows up with a voicemail, then sends another text, and each individual message is technically compliant, the overall pattern can still be deemed unfair or abusive.

This means collections AI compliance isn’t just about checking boxes. The total contact pattern, tone, timing, and frequency across all channels must be defensible as a whole.

Fair Housing Act (FHA)

This is the regulation every other collections AI compliance guide ignores. It shouldn’t be ignored.

The Fair Housing Act prohibits discrimination based on race, color, national origin, religion, sex (including gender and sexual orientation), disability, and familial status. The FHA doesn’t ask whether you meant to discriminate. It asks whether the outcome was discriminatory. When an algorithm produces that outcome, the complaint sticks to you, not the software vendor.

HUD has issued guidance noting that while AI use in housing is generally well-intentioned, automated algorithms can unintentionally reinforce existing biases. If an AI collections system disproportionately escalates against tenants in protected classes (through timing patterns, communication frequency, tone, or escalation thresholds), it could trigger a disparate impact claim.

For property managers, this isn’t abstract. If your AI sends more aggressive collection messages to tenants in certain zip codes, or escalates to legal threats faster for tenants with certain names, you have a Fair Housing problem regardless of whether you programmed that behavior intentionally.

How Multiple Regulations Overlap

Most readers don't understand that multiple laws apply simultaneously.

Create this.

AI Action

Laws Triggered

AI phone call

TCPA + Regulation F + FDCPA

AI text

TCPA + Regulation F

AI email

Regulation F

AI escalation

FDCPA + FHA + UDAAP

AI payment reminder

TCPA (depending on method)

AI lawsuit threat

FDCPA + UDAAP

AI-Specific Compliance Terms

Compliance by Design vs. Compliance by Audit

Compliance by design means building regulatory constraints directly into the AI system’s architecture so that violations cannot reach the consumer. Compliance by audit means reviewing interactions after the fact and catching problems retroactively.

The difference is substantial. As one industry analysis puts it: if your platform allows a violation to reach a debtor, the architecture failed, not the agent. For collections teams managing regulated portfolios, real-time intervention is the safer approach.

A compliance-by-design system won’t let the AI make an eighth call in seven days. It won’t let the AI call outside permitted hours. It won’t let the AI skip required disclosures. The rules are enforced at the system level, not the agent level.

Some vendors making calls on behalf of lenders don’t offer any visibility into their bots’ workflows or per-call activity. As one practitioner quoted in National Mortgage News warned: “That is dangerous, because when the auditor comes you do not have anything to show.”

For examples of how guardrails work in practice, see this guide on AI assistant script guardrails.

Compliance-as-Code

Compliance-as-code takes the compliance-by-design concept and makes it literal: FDCPA, TCPA, and Regulation F rules are embedded directly in system logic. Contact frequency limits, disclosure requirements, calling-hour restrictions, and consent checks all execute automatically. All interactions are logged with timestamps, creating an audit trail without manual effort.

This approach reduces the surface area for human error, which is where most collections AI compliance failures originate.

Human Escalation Protocols

Under FDCPA Section 809, when a debtor disputes a debt using phrases like “I dispute this debt” or “This isn’t mine,” the system must immediately escalate to a licensed human collector. An AI agent that continues attempting collection after a dispute is a violation, full stop.

Escalation protocols should also trigger for emotional distress signals, threats of self-harm, requests for legal representation, and any situation where the AI cannot confidently determine the appropriate response. The concept mirrors escalation rules in maintenance AI, where emergencies require immediate human handoff.

AI Disclosure

The FCC’s August 2024 Notice of Proposed Rulemaking formally defines “AI-generated call” and proposes mandatory in-call disclosure plus consent language that specifically references AI use. Maine’s Chatbot Disclosure Act already requires clear notice when consumers interact with AI systems.

The trend is unmistakable: regulators want consumers to know when they’re talking to a machine. Any collections AI system should disclose its nature at the start of every interaction, regardless of whether current law requires it in your state. The requirement is coming everywhere.

Required Disclosures During AI Collections

Situation

Disclosure Needed

AI voice call

AI disclosure (where required)

Debt collection communication

Mini-Miranda

Initial communication

Validation notice

Consent collection

Consent language

Call recording

State recording notice (where applicable)

Audit Trail

An audit trail in AI collections means immutable, timestamped logs of every interaction: messages, call recordings, disposition notes, consent records, and escalation events. The word “immutable” matters. Regulators expect that records cannot be altered after the fact.

For property managers already using AI for other operations, the concept is familiar. The recording and QA practices that apply to maintenance and leasing calls apply with even greater urgency to collections.

Records You Should Retain

Record

Recommended Reason

Consent records

TCPA defense

AI call recordings

Complaint investigation

Text messages

Regulatory review

Emails

Audit trail

Escalation logs

FDCPA compliance

Rule engine versions

Demonstrate compliance

Human overrides

Audit evidence

Consent Management

Consent management covers how the system obtains, stores, tracks, and honors consent for AI-powered communications. This includes pass-through consent (where consent given to the original creditor transfers to a third-party collector), opt-out tracking, and revocation handling.

The FCC’s “Revoke All” enforcement rule (effective April 2026) applies consent revocation across all lines of business, which means fragmented consent systems are a liability. If a tenant revokes consent for marketing calls, that revocation may extend to collections calls depending on how consent was originally obtained.

Mini-Miranda Warning

The Mini-Miranda is the required disclosure in collection communications stating that the communication is from a debt collector and any information obtained will be used to collect the debt. Under the FDCPA, this disclosure must appear in every communication, including those generated by AI.

An AI system that forgets the Mini-Miranda on even one call or message creates a per-violation penalty exposure. This is a compliance-as-code problem: the disclosure should be hardcoded, not optional.

Property Management-Specific Terms

First-Party Collection

First-party collection occurs when a business collects a debt owed directly to itself. A landlord calling a tenant about late rent is first-party collection. This generally falls outside FDCPA jurisdiction.

However, “outside FDCPA” does not mean “unregulated.” First-party collectors are still subject to TCPA consent requirements for AI calls, UDAAP standards, Fair Housing obligations, and state consumer protection laws. The FDCPA exemption is narrower than most property managers assume.

First-party collection calls are also generally exempt from TCPA marketing consent frameworks because they’re informational. But again, if the call uses an AI-generated voice, the FCC’s 2024 ruling kicks in and consent requirements apply regardless.

Third-Party Collection

Third-party collection occurs when someone collects a debt on behalf of another party. This is where property managers face their greatest collections AI compliance risk.

A property management company collecting rent for an owner it manages is potentially a third-party debt collector under FDCPA. The statute covers anyone who “regularly collects or attempts to collect debts owed or due another.” A management company that routinely pursues past-due rent for multiple owners fits that description.

Case law varies by jurisdiction, and some courts have carved out exceptions for property managers acting as agents of the owner. But the safest approach, particularly when deploying AI tools, is to assume FDCPA obligations apply and build compliance accordingly.

Rent Recovery vs. Debt Collection

When does past-due rent become a “debt” under federal law? The answer depends on timing and context.

Current-month rent that’s a few days late is generally treated as a billing matter. But once a tenant has vacated (or been evicted) and owes a balance, that balance is almost certainly a “debt” under the FDCPA. The transition point is fuzzy, which is exactly why AI systems need conservative guardrails.

A good rule of thumb: if you’re sending the communication because the tenant failed to pay, and the purpose of the communication is to get them to pay, treat it as a collection communication and apply full compliance protocols.

Post-Resident Recovery

Post-resident recovery, collecting money from former tenants for unpaid rent, damages, or lease-break fees, is almost always third-party collection territory. The tenant’s relationship with the property is over, the amounts are disputed more often, and the dynamics mirror traditional debt collection closely.

AI systems used for post-resident recovery should operate under full FDCPA, TCPA, and UDAAP compliance. This is also the area where AI for lease renewals intersects with collections, since proactive renewal outreach can reduce the volume of post-resident balances in the first place.

Emerging Regulations to Watch

Colorado AI Act (SB 189)

On May 14, 2026, Colorado Governor Polis signed SB 189, which revises Colorado’s original AI law and delays its effective date from June 30, 2026, to January 1, 2027. The revised law scales back some requirements from the original version but still imposes obligations on “high-risk” AI systems, which would include collections tools that make decisions affecting consumers’ financial status.

Property managers operating in Colorado should track this closely. The law will require impact assessments and transparency measures for qualifying AI systems.

Maine Chatbot Disclosure Act

Maine now requires clear notice when consumers interact with AI systems. While the law is narrow, it signals the direction of state-level AI regulation: transparency first, with broader obligations likely to follow.

FCC “Revoke All” Consent Enforcement

Effective April 2026, the FCC’s rule applies consent revocation across all lines of business. If a consumer revokes consent for one type of communication, that revocation carries across the entire organization. Property managers with separate leasing, maintenance, and collections communication streams need unified consent tracking or risk violations.

State Mini-TCPAs

Multiple states have enacted their own versions of the TCPA, often with stricter requirements. Florida, Washington, and Oklahoma impose additional consent requirements or calling restrictions that go beyond federal law. AI collections systems operating across state lines need state-specific rule engines.

CFPB Enforcement Trends

Reduced federal oversight in 2026 may shift enforcement responsibility to state attorneys general. This doesn’t mean less enforcement. It means less predictable enforcement, with 50 different regulators potentially interpreting the same rules differently. Self-regulated compliance becomes more important, not less, in this environment.

Penalties Quick-Reference Table

Regulation

Penalty per Violation

Aggregate Cap

Notes

FDCPA

$1,000 statutory + actual damages + attorney fees

$500,000 or 1% net worth (class actions)

396 cases filed in January 2026 alone

TCPA

$500 to $1,500 per call

No aggregate cap

507 class actions in Q1 2025

FTC Act

$50,000+ per violation

No aggregate cap

FDCPA violations auto-trigger FTC Act exposure

Fair Housing Act

Compensatory + punitive damages

No statutory cap

DOJ/HUD enforcement; injunctive relief available

State laws

Varies widely

Varies

Texas TRAIGA: up to $200,000 per violation

The absence of aggregate caps for TCPA and FTC Act violations is what makes AI collections uniquely risky. An AI agent that makes 1,000 non-compliant calls in a week creates $500,000 to $1.5 million in TCPA exposure alone. Automated systems can generate violations at a speed and scale that manual processes never could.

Building a Compliance-First Collections AI Strategy

Collections AI compliance isn’t a one-time certification. Regulations are changing quarterly. The Colorado AI Act was revised in May 2026. The FCC’s “Revoke All” rule took effect in April 2026. State attorneys general are filling federal enforcement gaps with their own interpretations.

The property managers who will use AI collections successfully are the ones who treat compliance as architecture, not afterthought. That means selecting tools with real-time guardrails, maintaining immutable audit trails, training staff on escalation triggers, and updating rule engines as regulations change.

Haven is building its Collections AI with exactly this approach: compliance-first architecture, PMS integration, and human escalation built into the system. If you’re evaluating AI collections tools, understanding the terms in this glossary isn’t optional. It’s the foundation for every vendor conversation you’ll have.

Book a demo to see how Haven approaches compliant AI for property management.

Common Compliance Mistakes

This section is missing entirely.

Use something like:

Assuming first-party collections are exempt from every law

FDCPA may not apply, but TCPA, FHA, UDAAP, and state laws still can.

Treating AI calls like manual calls

AI-generated voices generally trigger robocall rules even when a human agent could have made the same call.

Forgetting consent revocation

Consent withdrawals must be tracked and honored across communication channels where required.

Ignoring Fair Housing risk

Bias in AI escalation logic can create disparate impact even without discriminatory intent.

Relying on post-call audits

Preventive guardrails are generally more effective than finding violations after consumer contact.

Frequently Asked Questions

Does the FDCPA apply to property managers collecting rent?

It depends on the collection structure. If you’re a landlord collecting your own rent, FDCPA generally doesn’t apply. But if you’re a property management company collecting rent on behalf of an owner, you may be classified as a third-party debt collector. Case law is mixed, so the safest approach is to comply with FDCPA regardless.

Can I use an AI voice agent to call tenants about past-due rent?

You can, but the FCC’s 2024 declaratory ruling classifies AI-generated voices as robocalls. This means you need prior express consent before the AI dials, even if you have an existing business relationship with the tenant. Violations carry $500 to $1,500 in penalties per call.

What is the 7-in-7 rule in Regulation F?

Regulation F limits call attempts to seven per particular debt in a rolling seven-day period. This is a ceiling, not a recommended frequency. Many states impose stricter limits, and UDAAP standards may still flag seven calls as excessive depending on the circumstances.

How does the Fair Housing Act affect AI collections?

If your AI system disproportionately targets, escalates, or communicates more aggressively with tenants in protected classes (even unintentionally), it could trigger a disparate impact claim. The FHA looks at outcomes, not intent. Algorithmic bias in contact patterns, escalation thresholds, or tone can create liability.

What is compliance-as-code in collections AI?

Compliance-as-code means embedding regulatory rules (calling hours, frequency limits, disclosure requirements, consent checks) directly into the AI system’s logic so they execute automatically. This prevents violations from reaching consumers rather than catching them in post-hoc audits.

Do I need to tell tenants they’re talking to an AI?

Several jurisdictions already require it (Maine’s Chatbot Disclosure Act, for example), and the FCC has proposed mandatory in-call AI disclosure at the federal level. Even where not yet required, disclosing AI use is the safest practice and will likely become mandatory nationwide.

What happens if a tenant disputes a debt during an AI call?

Under FDCPA Section 809, the system must immediately escalate to a licensed human collector. The AI cannot continue collection activity after a dispute. This is a non-negotiable compliance requirement that should be hardcoded into any collections AI system.

How do state AI laws affect rent collection?

States are moving faster than the federal government on AI regulation. Colorado’s AI Act (effective January 2027) will require impact assessments for high-risk AI systems. The FCC’s “Revoke All” rule applies consent revocation across all business lines. Property managers operating in multiple states need state-specific compliance configurations.