What TRAI’s new UCC rules say about using AI to detect spam

What TRAI’s new UCC rules say about using AI to detect spam


Telecom operators must now use AI/ML systems to identify suspected spammers and initiate investigations against them. Under the third TCCCPR amendment, TRAI has introduced a framework that links AI-based spam detection with enforcement against unsolicited commercial communications (UCC). 

Previously, operators largely used these systems to warn recipients about suspected spam. The amended regulations require operators to share information about suspected spammers, conduct KYC checks, and investigate potential violations. They also allow operators to combine AI-generated intelligence with customer complaints to initiate action at a lower complaint threshold.

How will AI systems identify suspected spammers? Under the newly introduced Regulation 21A, every Terminating Access Provider (TAP) must use its AI/ML-based UCC_Detect system to identify suspected spammers. These systems analyse calling and messaging behaviour to identify numbers with a high probability of sending UCC.

Operators must classify such numbers as “Suspected high probability UCC CLI“, based on behavioural parameters. TRAI may specify these parameters from time to time. Importantly, operators can continue using their existing algorithms to warn customers about suspected spam. However, they can only share numbers classified as high-probability UCC senders for further investigation and enforcement.

Once an operator identifies such a number, it must share the information with the concerned Originating Access Provider (OAP) via the Distributed Ledger Technology (DLT) platform. It must do so immediately, and no later than two hours after identification.

How will operators investigate AI-flagged numbers? Once the OAP receives information about a suspected spammer, it must immediately notify the sender through SMS, email, or both. The notification must explain that the operator identified the number based on its communication behaviour.

The OAP must then identify the sender’s unique KYC identifiers within one business day and share them with other operators through DLT. These operators must identify all telecom resources allotted to the same sender. They must also check whether their AI systems flagged any other numbers associated with that sender in the preceding ten days. If operators identify five or more numbers belonging to the same sender as high-probability UCC numbers within ten days, they must initiate further action.

What action can operators take against suspected spammers? The amendment introduces a graduated enforcement mechanism when five or more numbers belonging to the same sender meet the AI-flagging threshold.

  • First instance: The OAP must re-verify the sender’s KYC within three business days. Failed verification triggers action under existing KYC guidelines. If re-verification succeeds, the case still counts as the first violation, and any later one is treated as a repeat.
  • Second instance: The OAP must conduct physical KYC within five business days and investigate whether the sender misused its telecom resources.If an operator finds that the KYC details don’t match the physical verification, or that the sender misused telecom resources for UCC, all operators must bar outgoing services on all of the sender’s telecom resources (including PRI/SIP trunks and SIMs) for 15 days, whether or not the sender used those resources to send UCC. If the details match, the case still counts as the second instance.
  • Subsequent instances: The OAP must investigate potential misuse within five business days and can take actions including blocklisting, disconnection of the sender’s telecom resources for a year, and blocking of the devices used for UCC.

If the second investigation establishes misuse, operators can impose a 15-day restriction on outgoing services across the sender’s telecom resources. However, TRAI has clarified that AI-generated intelligence alone cannot establish a regulatory violation. Operators must investigate suspected spammers before taking enforcement action.

Complaints provide a second enforcement trigger: The amendment changes regulation 25—the earlier framework required “5 or more complaints” from unique recipients within ten days. With AI corroboration, action can begin with “3 or more complaints” from unique recipients within ten days. This applies when any CLI was identified as a “Suspected high probability UCC CLI” during that period.

Once the threshold is met, the OAP must immediately suspend outgoing services on the telecom resources used to send UCC and simultaneously start an investigation. In April 2026, AI systems flagged 771 crore calls and 48 crore SMS as suspected spam to alert customers. Operators received 2,66,105 complaints; 17,401 met the earlier threshold. TRAI said this gap supported combining complaint data with AI/ML outputs.

Designated series are protected from blanket spam tagging by call-management applications. Recipients cannot flag CLIs from 140xx, 1600xx and 1601xx as “Suspected UCC spam.” Schedule IV requires operators to tell detected Senders that the system has identified them, with high probability, as suspected UCC Senders and that they “must refrain from sending UCC.”

What safeguards will prevent incorrect AI flagging? TRAI’s explanatory memorandum says AI-generated intelligence “by itself, may not constitute conclusive evidence”. It notes that false positives cannot be entirely ruled out. Therefore, “AI-based flagging” is not a “self-sufficient basis” for regulatory action. Instead, TRAI says the flag triggers “further investigation”. The Authority also rejected mandatory human review. It said it will not take deterrent action solely on AI intelligence.

The framework also requires operators to provide flagged senders with a mechanism to challenge their classification and submit supporting justification. Operators must remove the spam flag if they find the justification satisfactory.

Also read:



Content Curated Originally From Here