
In the battle against robocalls, the FCC (News - Alert) has escalated from warning shots to a full assault on non-compliant voice providers. Its latest action includes removing more than 1,200 non-compliant voice service providers from the Robocall Mitigation Database, effectively disconnecting them from the U.S. phone network until they obtain explicit approval to re-file.
Earlier this month – the warning shot – the FCC removed an initial group of 185 providers following final warnings to them. These actions really trace back to December of last year, when 2,411 providers were ordered to cure deficient filings or face removal – which now has happened for more than half of them.
The message is clear: If voice providers are unwilling or unable to implement caller-ID authentication and a credible mitigation plan, you do not get access to American consumers.
This moment is significant because it converts policy into practical consequence. Listing in the RMD is not just paperwork and a meaningless stamp. Rather, it’s a key that unlocks U.S. networks for network traffic and, with the loss of approved status, downstream carriers are required to block traffic from those carriers. In other words, their customers – including illegal robocallers – are unable to connect calls.
At the same time, a bipartisan coalition of 51 state attorneys general has launched Operation Robocall Roundup, warning dozens of providers that failure to support traceback, maintain accurate certifications, and implement effective mitigation will bring further action. It seems that federal and state powers are pushing robocall mitigation efforts together, which should increase pressure on those carriers who have, thus far, failed to comply.
But, if STIR/SHAKEN caller-ID authentication is the technical backbone of the fight, why hasn’t it already crushed the problem? After all, it was supposed to be a silver bullet – at least that’s how it was originally positioned.
First, there’s a coverage issue. STIR/SHAKEN operates on IP networks. When calls traverse non-IP (TDM) segments – still very common at interconnects and in legacy environments – authentication often falls off. So, until the industry either closes the non-IP gap with approved alternatives or accelerates all-IP interconnection, signatures will disappear in transit and spoofers will continue to find seams in the fabric.
Second, there's integrity. High-trust A-level attestation has at times been granted too liberally, especially where vetting standards are weak or signing is outsourced. Regulators are tightening rules so providers must use their own certificates and make their own attestation decisions, but enforcement and commercial incentives have to reinforce this shift.
Completeness is also a challenge. Too many calls still fail to arrive at termination with authentication intact. As long as end-to-end signed-call ratios remain low, the deterrence is limited.
The issue is not a theoretical one. Robocalls are a persistent on-ramp to fraud and bad actors continue to use imposter, investment, and tech support scams, among others, to siphon billions from households each year. To make matters worse, AI has lowered the cost of highly convincing social-engineering campaigns, giving criminals new ways to impersonate family members, banks, or government agencies.
For enterprises, the impact runs beyond fraud losses; it erodes brand trust, reduces answer rates for legitimate outbound contact, and drives up the operational costs of customer service.
What will it take to convert the current enforcement surge into durable consumer protection?
It starts with designing for end-to-end trust, rather than treating STIR/SHAKEN as a silver bullet. That includes transparency from carriers on their non-IP footprints and metrics related to authenticated vs. non-authenticated traffic.
Attestation should be clear and it must be earned, not assumed. The State of New York is taking a step in that direction with its Robocall Identification and Notification for Guarding consumers (RING) Act.
In addition, traceback should move from and after-the-fact action to a real-time control mechanism. Providers that respond to traceback requests within hours and feed those signals into automated traffic shaping, quarantine, or temporary blocking mechanisms could cut off bad campaigns before they scale and have a significant impact. This could be driven by a coalition of federal and state partners intensify expectations around traceback support, fast responders will become the ecosystem’s most trusted interconnects.
AI and behavioral analytics can also play a role here. A signed call is not necessarily a safe call, because originators can acquire signatures and then behave badly. AI-driven analytics can examine velocity, call windows, destination entropy, ANI churn, and historical reputation to flag likely abuse with low false positives. Blending authentication with analytics can improve both security and answer rates. For legitimate high-volume callers, branded calling and rich call data can restore confidence by giving consumers context while preserving rigorous screening for fraud.
Enterprises also can help by ensuring their outbound numbers are consistently registered, authenticated, and monitored, and that agents follow callback flows that reduce the chance of customers being diverted to fraudulent numbers.
Of course, customer education matters, too. Publishing official numbers, using secure callback procedures, and reminding users what their agents will and will not do in terms of identity, account verification, and payments, can go a long way towards reducing fraud.
While STIR/SHAKEN was thought to be the easy solution, that’s not how it’s played out. Reducing robocalls in a meaningful way will require collaboration between federal and state entities, carriers, enterprises, technology providers, and even consumers. This is an all-hands-on-deck situation and, ultimately, numbers alone aren’t going to be the measuring stick for success. Rather, customer perception will be the real metric.
If more than eighty percent of legitimate traffic arrives with authentication intact, if attestation is reliably tethered to strong identity vetting, and if traceback-to-mitigation loops run in hours rather than days, the entire ecosystem will see wins.
While the FCC’s decision to disconnect chronic carriers for non-compliance may seem extreme to some, it’s a necessary step towards resolving what has become a major obstacle to legitimate communication. The next step is following up with engineering, operations, and governance from the telecom industry.
Edited by
Erik Linask