What Is the Foreign Robocall Elimination Act?
As of August 2026, the Foreign Robocall Elimination Act (S. 2666) is a bipartisan bill that passed the U.S. Senate by unanimous consent on August 3, 2026, and is now awaiting House action. The law would create a federal interagency task force combining FCC, FTC, and Department of Justice officials with private-sector experts to combat unlawful robocalls originating from outside the United States. It also strengthens the Industry Traceback Group and authorizes the FCC to require certain voice service providers to post bonds of up to $100,000 before entering the Robocall Mitigation Database.
Who it affects: Every business that relies on a VoIP or cloud-based phone system, because the law targets the providers that route your calls and tightens the standards those providers must meet.
What it does for callers: Legitimate businesses should see fewer scam calls reaching their lines, stronger caller ID verification through STIR/SHAKEN, and more accountability from providers handling international call traffic.
When it takes effect: The bill still requires House passage and the President’s signature. If enacted, the FCC would have 270 days to establish the task force, and the task force would have 360 days to report to Congress.
What Changed on August 3, 2026
On August 3, 2026, the U.S. Senate passed the Foreign Robocall Elimination Act (S. 2666) by unanimous consent. The bill, introduced by Senators Peter Welch (D-Vt.) and Ted Budd (R-N.C.), represents the first robocall-related legislation to advance in the Senate since the TRACED Act in 2019. The bill was sent to the House of Representatives on August 10, 2026, according to Congress.gov.
The legislation does three concrete things. First, it directs the FCC, in coordination with the FTC and the U.S. Attorney General, to establish a time-limited interagency task force focused exclusively on foreign-origin robocalls. The task force would include seven private-sector members drawn from voice service analytics, telecommunications technology, marketing, and consumer advocacy. Second, it strengthens the Industry Traceback Group by granting legal immunity for receiving, sharing, and publishing information about suspected unlawful calls, and by authorizing the group to publicly name providers that refuse to cooperate with tracebacks or that originate high volumes of illegal call traffic. Third, it gives the FCC authority to require certain providers to post a surety bond of up to $100,000 before they can certify in the Robocall Mitigation Database, with exemptions for established, compliant providers.
We have been watching this bill closely because it directly affects the provider ecosystem that routes calls for businesses like ours and like yours. If your VoIP provider is already compliant with STIR/SHAKEN and maintains a clean Robocall Mitigation Database filing, these changes work in your favor. If your provider is not, this law raises the stakes considerably.
Does the Foreign Robocall Elimination Act Apply to Small Businesses?
The Foreign Robocall Elimination Act targets voice service providers, gateway providers, and the infrastructure that routes calls into U.S. networks from abroad. It does not impose new compliance requirements directly on end-user businesses. If you run a medical practice, a contracting company, or a small office and you use a VoIP phone system to take inbound calls, you are not filing anything new because of this bill.
That said, the law affects you indirectly in two ways. First, it raises the compliance bar for VoIP providers. Providers that cannot maintain clean Robocall Mitigation Database filings or refuse to participate in call tracebacks face public naming and potential bonding requirements. That means your provider’s compliance status now has a more visible paper trail, and switching away from a flagged provider before enforcement action hits is far less disruptive than dealing with service interruptions after the fact.
Second, the bill signals where federal enforcement is heading. The task force is specifically directed to evaluate criminal penalties for foreign robocall operators and to recommend new DOJ enforcement structures. Businesses that make legitimate outbound calls, such as appointment reminders, payment confirmations, or service follow-ups, benefit when the enforcement ecosystem can distinguish between lawful business calling and illegal robocall traffic. Better traceback cooperation and provider vetting make that distinction clearer. If your provider supports STIR/SHAKEN caller ID authentication, your outbound calls are already being verified and are less likely to be flagged or blocked by downstream carriers.
Why Congress Is Acting on Foreign Robocalls Now
The timing of S. 2666 is not accidental. According to Senator Welch’s office, Vermonters alone received 27 million robocalls in the first half of 2026. Nationally, the problem has been worsening despite the STIR/SHAKEN framework, because a significant share of illegal calls originate from outside U.S. networks where the FCC’s domestic enforcement tools do not reach.
The TNS 2026 Robocall Investigation Report found that while 85 percent of call traffic between Tier-1 carriers was signed and verified with STIR/SHAKEN in 2025, only 17.5 percent of traffic between smaller carriers was signed. That gap is where bad actors operate. Foreign-origin calls entering through non-compliant gateway providers bypass the authentication framework entirely, which is exactly the entry point this legislation targets.
The Senate vote also came alongside a parallel push from state attorneys general. A coalition of nearly all 50 state AGs has been pressing the FCC for tougher Know Your Customer rules for phone providers, and the FCC itself initiated a Further Notice of Proposed Rulemaking on July 23, 2026, to expand the scope of providers required to file in the Robocall Mitigation Database. The federal and state pressure is converging on the same goal: making it harder for illegitimate providers to access U.S. phone networks.
If you are not sure whether your current business phone provider meets STIR/SHAKEN compliance standards, our team can walk you through what to check and what to ask. In our experience setting up VoIP systems for small businesses, the providers that invest in compliance infrastructure are the same ones that deliver cleaner call quality and fewer service disruptions.
How Will This Law Affect Business Phone Users in Practice?
For most small business owners, the practical effect of the Foreign Robocall Elimination Act will show up in three areas: fewer spam calls reaching your desk phone, better caller ID accuracy on inbound calls, and a clearer picture of whether your VoIP provider is operating above board.
Before S. 2666 vs. After S. 2666: What Changes for Business Phone Users
| Area | Before S. 2666 | After S. 2666 (if enacted) |
|---|---|---|
| Foreign robocall enforcement | FCC, FTC, and DOJ act independently with no dedicated foreign-call focus | Dedicated interagency task force with private-sector experts focused on foreign-origin calls |
| Provider accountability | Providers file in the RMD voluntarily; non-compliant providers face removal but no financial barrier to re-entry | FCC can require surety bonds up to $100,000 for certain providers before RMD certification |
| Traceback cooperation | Industry Traceback Group operates with limited legal protections; non-cooperating providers face few consequences | Traceback Group gains legal immunity and authority to publicly name non-cooperating providers |
| Criminal penalties | Criminal prosecution of foreign robocall operators is rare and uncoordinated | Task force to recommend dedicated DOJ enforcement body and evaluate new criminal penalties |
One pattern we see regularly when setting up business phone systems is that owners assume all VoIP providers handle call authentication the same way. They do not. Providers that have fully implemented STIR/SHAKEN across their IP networks can attest to the legitimacy of every call they originate, which means your business number shows up as verified on the recipient’s phone. Providers that have not fully implemented it may only partially sign calls, or rely on mitigation plans that fall short of full authentication. Under the tightening enforcement environment, the difference between these two provider types is becoming operationally significant.
How to Verify Your Business Phone Provider Is Compliant
The best time to verify your VoIP provider’s compliance status is before an enforcement action forces the issue. Here are the steps we recommend to every business owner using a cloud phone system in 2026.
- Check the Robocall Mitigation Database. Visit the FCC’s Robocall Mitigation Database and search for your provider by name. Confirm that their certification is current and has not been flagged or removed. If you cannot find your provider in the database, that is a red flag.
- Ask your provider about STIR/SHAKEN implementation. Request written confirmation that your provider has fully implemented STIR/SHAKEN on all IP-based portions of their network, not just a partial rollout. Full implementation means every call originating from your business number carries an A-level attestation.
- Confirm traceback cooperation. Ask whether your provider participates in Industry Traceback Group requests within 24 hours. Providers that refuse or delay traceback cooperation are exactly the type that the new legislation targets for public naming.
- Review your caller ID settings. Verify that your outbound caller ID displays your actual registered business number. Mismatched or unregistered caller IDs can trigger call blocking by downstream carriers, and enforcement is only getting stricter.
- Document your provider’s compliance status. Keep a record of your provider’s RMD filing date, STIR/SHAKEN attestation level, and any compliance confirmations they provide. If you ever need to switch providers due to an enforcement action, this documentation speeds the transition.
- Test your inbound call experience. Call your own business number from a mobile phone and check whether the caller ID displays correctly, whether the call connects without unusual delays, and whether any spam-warning labels appear. These are the same signals your customers see.
Common Misconceptions About Robocall Laws
The most common mistake we hear from business owners is assuming that robocall legislation only affects telemarketing companies or large call centers. The Foreign Robocall Elimination Act targets the provider infrastructure, not the businesses using it. But if your provider gets removed from the Robocall Mitigation Database, your calls stop connecting to other networks. That is not a theoretical risk. In August 2025, the FCC removed over 1,200 providers from the RMD in a single enforcement action, according to the FCC Enforcement Bureau.
Another misconception is that STIR/SHAKEN is optional for small providers. The own-certificate requirement took effect in 2025, and the FCC has signaled through its July 2026 FNPRM that it plans to expand the definition of “voice service provider” to include cloud service providers, PBXs, and dialing platforms. The direction is toward more coverage, not less.
A third misconception involves the bill’s current status. S. 2666 has passed the Senate but not yet the House. It is not law. However, the enforcement environment it reflects is already active. The FCC’s parallel rulemakings on Know Your Customer requirements, the Robocall Mitigation Database expansion, and number reseller oversight are all moving forward independently. Even if S. 2666 stalls in the House, the regulatory pressure on non-compliant providers is intensifying through existing FCC authority. Businesses should not wait for a final signature to verify their provider’s compliance status. If you have concerns about how AI-powered phone scams are targeting businesses, understanding your provider’s authentication capabilities is the first line of defense.
Provider-Level Protection vs. DIY Call Blocking
Some businesses try to handle robocall protection at the handset level with call-blocking apps or manual blocklists. That approach catches individual numbers after they have already rung your phone, but it does nothing about the underlying problem: illegitimate traffic entering your provider’s network in the first place.
Provider-level protection works upstream. A VoIP provider with full STIR/SHAKEN implementation and a compliant RMD filing authenticates calls at the network level before they reach your desk phone. Calls that fail authentication or originate from flagged providers are blocked or flagged before they ring. That is the difference between swatting flies and installing a screen door.
In our experience building phone systems for small businesses, the providers that invest in compliance infrastructure also tend to deliver better call quality, more reliable uptime, and faster number porting. Compliance and service quality are not separate issues. They reflect the same operational discipline. If your current provider cannot clearly explain their STIR/SHAKEN attestation level or their RMD filing status when you ask, that tells you something about how they run the rest of their network. For more context on the regulatory landscape affecting VoIP text messaging, we covered the TCPA ruling earlier this year.
Frequently Asked Questions
What is the Foreign Robocall Elimination Act?
The Foreign Robocall Elimination Act (S. 2666) is a bipartisan bill passed by the U.S. Senate on August 3, 2026, that creates a federal interagency task force to combat unlawful robocalls originating from outside the United States. It also strengthens the Industry Traceback Group and authorizes the FCC to require surety bonds from certain voice service providers.
Has the Foreign Robocall Elimination Act been signed into law?
As of August 2026, no. The bill passed the Senate by unanimous consent and was sent to the House of Representatives on August 10, 2026. It still requires House passage and the President’s signature to become law.
Does this law change TCPA requirements for businesses?
No. S. 2666 does not modify the Telephone Consumer Protection Act or the Telemarketing Sales Rule. Existing requirements around prior express written consent, Do Not Call scrubbing, and accurate caller ID remain unchanged. The bill changes the enforcement environment around those requirements, not the requirements themselves.
How do I know if my VoIP provider is compliant with STIR/SHAKEN?
Ask your provider for written confirmation of full STIR/SHAKEN implementation across all IP-based portions of their network. You can also search the FCC’s Robocall Mitigation Database to verify that your provider has a current, valid certification on file.
What happens if my VoIP provider gets removed from the Robocall Mitigation Database?
Other voice service providers and intermediate carriers are required to stop accepting call traffic from any provider removed from the RMD. In practice, this means your outbound calls may not connect, and your inbound calls may be disrupted. The FCC removed over 1,200 providers in a single enforcement action in August 2025.
What is the surety bond requirement in S. 2666?
The bill authorizes the FCC to require certain voice service providers to post a bond of up to $100,000 before they can certify in the Robocall Mitigation Database. Established, compliant providers would be exempt. The bond is designed to prevent bad actors from cycling through the database by creating a financial barrier to entry.
Next Steps
If you want to verify your current VoIP provider’s compliance status, start with the FCC’s Robocall Mitigation Database. For a deeper look at how FCC robocall mitigation rules affect VoIP providers, we covered the compliance landscape in detail. If you are evaluating a new business phone system and want to ensure your provider meets the standards that are now being enforced, our team can help you compare options and get set up in as little as one business day.
Your business phone system should protect you from robocall disruptions, not expose you to them. Talk to our team about switching to a VoIP provider built on full STIR/SHAKEN compliance, 99.9% uptime, and plans starting at $18.99 per user per month.