Guide
AI Tools Security and Privacy Checklist for Local Service Businesses: Customer Data, Call Recording and Text Consent
What an owner-operator should check before an AI receptionist, chatbot, call recorder or texting tool touches customer data, with the US consent rules, costs and penalty figures that apply.
Owners of independent local service businesses in the United States (home services, trades, clinics, salons and similar) who use or are considering AI receptionists, chatbots, call recording, AI note-takers or business texting.

- Key facts
- 9
- Steps
- 13
- Pitfalls covered
- 8
- Research captured
- 2026-10-01
An AI phone agent, a website chatbot or a texting tool does more than save time. It listens to your customers, stores what they say, and often sends it to a third-party vendor. That makes you responsible for three things at once: how the vendor handles the data, whether callers and texters agreed to be recorded or contacted, and whether you can prove it later.
Most published checklists are written for call centers or enterprise IT teams. This guide is written for an owner who has a phone, a Google Business Profile, maybe Google Ads or Local Services Ads, and a handful of software subscriptions. It covers the rules that matter most in practice: call-recording consent by state, text-message consent under the TCPA, the 10DLC registration that business texting requires, the data-use clause in your AI vendor's contract, and the call recording that Google Ads can switch on for you by default.
Two cautions apply throughout. First, this is a practical checklist, not legal advice. Several figures below come from law-firm and trade summaries rather than the statute or court text, and each place where that matters is flagged. Second, where published counts disagree (for example, the number of all-party-consent states), the disagreement is stated rather than smoothed over. Information is current as of October 1, 2026.
At a glance
The facts that matter
Ransomware in small-business breaches: 88%
Verizon's 2025 Data Breach Investigations Report (published April 23, 2025) found ransomware in 44% of all breaches but in 88% of breaches involving small and medium businesses. The 88% figure comes from Verizon's press release summary.
Third-party involvement in breaches: 30%, doubled
Verizon's 2025 report says third-party involvement in breaches doubled to 30%. Every AI vendor you connect to customer data is a third party.
FBI IC3 reported losses, 2025: $20.877B
The FBI's Internet Crime Complaint Center received 1,008,597 complaints, up 26% in losses on 2024. It also began tracking 'AI-related' complaints: 22,000+ complaints and nearly $900M in losses. Figures come from secondary summaries of the report released April 7, 2026.
TCPA private damages: $500 to $1,500 per violation
$500 per violation, up to $1,500 if willful or knowing. Texts count as calls. About 80% of TCPA suits are class actions.
Text opt-out deadline: 10 business days
Since April 11, 2025, a business must honor a revocation of text or call consent within a reasonable time not to exceed 10 business days. The broader 'revoke-all' provision was delayed to January 31, 2027.
Google Ads call recording: On by default
Google Ads call recording is enabled by default to allow AI-powered lead qualification, except for accounts that previously disabled it and healthcare and financial-services advertisers. Recordings are available for 30 days.
A practical path
What to do
- 01
Take inventory. List every tool that hears, reads or stores customer information: AI receptionist, chatbot, call recorder, note-taker, texting platform, ad platform recording. The FTC's data framework starts with 'take stock', then 'scale down', 'lock it', 'pitch it' and 'plan ahead'.
- 02
Check which account type you are on. Several guides say consumer ChatGPT plans (Free, Plus, Pro) may use conversations for training by default while business plans do not. Confirm each vendor's current terms yourself; OpenAI's own pages could not be verified.
- 03
Read the vendor's data-use clause. The legal theories in Ambriz v. Google and In re Otter.AI turn on a vendor retaining and using conversations for its own purposes, such as model training. Ask whether the vendor can, and does, use your customers' calls for anything but serving you.
- 04
Put security terms in the contract and limit access. The FTC advises security provisions in vendor contracts, giving vendors access only to the data points they need, and confirming that vendors follow your rules rather than taking their word for it.
Watch for these
Common mistakes
Assuming federal one-party consent covers every call
Federal law is one-party consent, but California and other all-party states apply their own rules. California law applies to calls to or from California regardless of where the caller is. If either party is in an all-party state, the safest approach is to get everyone's permission.
Trusting a vendor's marketing instead of its data-use clause
The wiretap cases against Google's call-center AI and Otter.AI turn on whether a vendor has the capability to use conversations for its own purposes, such as model training. The FTC advises you to confirm that vendors follow your rules and not just take their word for it.
Leaving Google Ads call recording on without reviewing it
Google enables call recording by default for AI-powered lead qualification and plays callers a message that calls are recorded 'for quality purposes.' Search Engine Journal advises advertisers to check whether that message satisfies their own legal obligations.
Using a personal or consumer AI account for customer information
Several guides say consumer ChatGPT plans may use conversations for training by default and business plans do not. Verify each vendor's current terms before pasting customer details into any tool.
Treating a text opt-in as permanent or undocumented
You must stop texting within 10 business days of a revocation, and marketing texts need prior express written consent backed by a record of the date and time, method and exact wording shown. A broader revoke-all rule takes effect January 31, 2027.
Choose with context
A decision guide
| What the rule requires | Key date or caveat | |
|---|---|---|
| Recording a phone call | Federal law is one-party consent. All-party states require everyone's permission, and the safest approach is to get it whenever either party may be in one. | Published counts of all-party states range from 11 to 13. California law applies to calls to or from California. |
| Placing a call with an AI-generated voice | Prior express consent under the TCPA (FCC declaratory ruling). | Ruling dated February 8, 2024. |
| Sending marketing texts | Prior express written consent, with a record of date and time, method and exact wording shown. | Texts count as calls under the TCPA. |
| Honoring STOP or other opt-outs | Stop within a reasonable time not to exceed 10 business days. STOP, QUIT, END, REVOKE, OPT OUT, CANCEL and UNSUBSCRIBE are per se reasonable; other reasonable methods also count. | In effect since April 11, 2025. The revoke-all provision moved to January 31, 2027. |
| Texting or calling residences for solicitation |
Takeaway
For a local service business, the highest-value checks are few and concrete: read each AI vendor's data-use clause, record only with consent that satisfies the strictest state involved, review the Google Ads call-recording setting, and keep dated records of text consent while honoring opt-outs within 10 business days. Everything else in this guide supports those four habits.
Before connecting an AI receptionist or note-taker
Read the vendor's data-use clause
The Ambriz v. Google and In re Otter.AI claims turn on a vendor's capability to use conversations for its own purposes, and the FTC advises confirming that vendors follow your rules rather than taking their word for it.
Before you record any call
Announce recording on every call
Federal law is one-party consent, but if either party is in an all-party state the safest approach is to get everyone's permission, and published counts of those states range from 11 to 13.
If you run Google Ads or Local Services Ads
Check your call-recording setting
Google Ads recording is on by default for most accounts, and Local Services Ads communications may be retained up to 180 days, with you responsible for data on your own systems.
Before texting customers
Document consent and honor STOP within 10 business days
TCPA damages run $500 to $1,500 per violation, and a revoke-all rule takes effect January 31, 2027.
Why local service businesses should care
Breach and fraud statistics are mostly gathered across organizations of all sizes, but several point directly at small firms.
Verizon's 2025 Data Breach Investigations Report, published April 23, 2025, analyzed more than 22,000 security incidents, of which 12,195 were confirmed breaches. Third-party involvement in breaches doubled to 30%. Ransomware appeared in 44% of breaches overall and in 88% of breaches involving small and medium businesses. The median ransom paid was $115,000, and 64% of victims did not pay. For initial access, credential abuse accounted for 22% of breaches and vulnerability exploitation for 20%. The 88% figure comes from Verizon's press release; the report PDF itself was not parsed, though Security Magazine repeats the same numbers.
IBM and Ponemon's Cost of a Data Breach report is the other widely quoted source. IBM's 2026 report landing page shows a global average of $4.99M, a 12% increase over the prior year and a record high, a 56% rise in AI-driven attacks, and $1.93M saved by extensive use of security AI and automation. Secondary coverage of the 2026 report puts the US average at $11.5M (Security Boulevard, August 2026) and says 92% of organizations with AI-related incidents lacked adequate AI access controls (eSecurity Planet). Those two figures were not on IBM's page as retrieved. For the 2025 report, secondary sources say high levels of shadow AI added $670K to average breach cost and that 97% of organizations with AI-related incidents lacked AI access controls. One page carrying these figures also carries a 2026 date, so check which report year a figure belongs to before you repeat it. IBM's figures describe organizations in general; the page does not break out small businesses, and no primary-source average breach cost for a local service business under 50 employees has been found.
The FBI's Internet Crime Complaint Center (IC3) 2025 report, released April 7, 2026, counted 1,008,597 complaints and $20.877B in reported losses, up 26% on 2024. Business email compromise accounted for about $3.05B. The report introduced 'AI-related' as a formal descriptor, with more than 22,000 complaints and nearly $900M in losses. These figures come from secondary summaries (SpyCloud and Hoodline) of the primary report PDF at ic3.gov.
Litigation over calls and texts is also rising. Using WebRecon data reported by TCPAWorld, Q1 2025 TCPA class action filings were 507, up 112% from 239 in Q1 2024, and September 2025 class action filings spiked 283%. About 80% of TCPA suits are class actions. These are blog-level tallies, not court data.
Questions
Frequently asked
Keep reading