The FCC has issued a Further Notice of Proposed Rulemaking to significantly expand the Robocall Mitigation Database, proposing stricter ownership disclosures, enhanced KYC/KYUP procedures, and more rigorous mitigation plans. These rules would apply to a broad range of voice service providers, including VoIP resellers and cloud providers, with potential enforcement actions including removal from the database and loss of access to US voice networks.
The proposed expansion shifts the regulatory burden from traditional carriers to the broader infrastructure layer, including cloud providers and call centers that facilitate streaming-adjacent voice services. By mandating machine-readable mitigation plans and US-registered agents, the Commission is creating a more aggressive enforcement framework that can instantly de-platform non-compliant entities. This move signals a transition toward a zero-trust environment for voice traffic, forcing infrastructure providers to vet their upstream partners with the same rigor as their direct customers. Industry stakeholders should monitor the Federal Register for the 30-day comment window to assess how these ownership disclosures will affect international service providers.
The FCC's Robocall Mitigation Database has undergone significant expansion since its initial launch under the TRACED Act of 2019. In March 2025, the Commission adopted rules requiring all voice service providers to file updated robocall mitigation plans in the database, with enforcement actions including removal from the database for non-compliant filers. The database now serves as the central gatekeeper determining which providers can legally originate or terminate calls on U.S. networks, and the September 2026 Further Notice of Proposed Rulemaking represents the most aggressive expansion of its scope since inception.
The proposed expansion arrives amid heightened congressional and state-level pressure on robocall enforcement. In July 2026, the FCC announced enforcement actions against multiple voice providers for failing to maintain accurate database filings, signaling that the Commission is already using the existing framework as a punitive tool before the new rules take effect. The ownership disclosure requirements in the FNPRM echo similar know-your-customer mandates that the FCC imposed on intermediate providers in 2024, extending the compliance chain further upstream to cloud platforms and resellers that may not have previously considered themselves subject to robocall regulations.
For cloud communications providers, the proposed rules create a compliance architecture similar to what streaming platforms face under DMCA safe harbor provisions. The requirement for machine-readable mitigation plans and U.S.-registered agents mirrors the FCC's 2024 order mandating that gateway providers implement STIR/SHAKEN authentication and file detailed robocall mitigation plans, which established the technical and procedural baseline that the new FNPRM now extends to a broader class of entities. Voice infrastructure providers serving streaming and OTT platforms with integrated calling features will need to assess whether their services fall within the expanded definition of voice service provider subject to these requirements.
The FCC has proposed a major expansion of its Robocall Mitigation Database to include VoIP resellers, MVNOs, and cloud-based platforms. This shift forces infrastructure providers to implement stricter know-your-customer procedures and ownership disclosures. It matters because it creates a zero-trust environment, allowing the FCC to de-platform non-compliant entities from U.S. networks.
The expansion targets a broader range of voice service providers, specifically including VoIP resellers, MVNOs, and cloud-based dialing platforms that facilitate voice traffic.
Non-compliant entities face removal from the Robocall Mitigation Database, which effectively bars them from legally originating or terminating traffic on U.S. voice networks.
Providers must implement affirmative, effective mitigation measures, provide detailed ownership disclosures, and potentially offer financial assurances like letters of credit to deter bad actors.
Cloud providers must now adopt more rigorous vetting of upstream partners and comply with machine-readable mitigation plan requirements, similar to existing mandates for gateway providers.
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source