Skip to main content

 

What do email authentication and caller identity have to do with Canada’s telecom policy? More than you might think. 

On July 24, 2026, M3AAWG filed a formal intervention with the Canadian Radio-television and Telecommunications Commission (CRTC) as part of its review of the Unsolicited Telecommunications Rules (UTRs). This article explains what we said, why we said it, and why the issue deserves attention beyond the experts working directly with DMARC and STIR/SHAKEN. The full set of comments is available here.

These are the rules that govern robocalls, telemarketing, and automated dialing in Canada. The CRTC opened this review under Notice of Consultation 2026-132, and we want to start by saying thank you. Rulemaking reviews like this take real institutional effort, and the questions the Commission posed were thoughtful and specific. M3AAWG is grateful for the opportunity to provide technical recommendations focused on preventing avenues for abuse.

Why this review matters right now

The current Canadian UTR framework hasn't had a substantive update since 2014. Think about what a robocall looked like in 2014. It usually meant a piece of physical dialing hardware that played back a pre-recorded message and dialed through phone numbers in a predictable pattern. The methods for robocalling were limited by the technical limitations of that time.

That picture is gone. Today, someone can spin up thousands of AI-generated voice calls using nothing more than a cloud subscription, a language model, and a list of phone numbers. There's no hardware, no physical dialer, no "equipment" in the sense the old rules imagined. That gap between what the rules describe and what actually happens on the network today is exactly the kind of gap that sophisticated bad actors find and exploit.

So when the CRTC opened this review, it gave us a real chance to advocate to close that gap before it gets abused further, rather than after.

The core idea behind everything we recommended

If there's one sentence that sums up our whole submission, it's this: 

“Rules should be built around outcomes, not mechanisms.”

In plain terms, that means the question shouldn't be "did this call come from a machine with a particular kind of hardware?" It should be "did this person receive an unwanted automated call without meaningful consent, without disclosure, and without anyone accountable for it?" 

A rule built around that second question stays relevant as technology changes. A rule built around a specific technical mechanism has to be rewritten every time the technology evolves, and it always moves faster than the rulemaking process.

What we actually recommended

Here's the plain language version of our main recommendations.

Update the definition of an automated calling system so it covers AI, not just old-school hardware. The current definition talks about equipment that stores or produces a pre-recorded message. We asked the CRTC to replace that with a definition based on what the system does: does it initiate or conduct a call to someone without a real person meaningfully involved in that specific call, regardless of whether the voice is a recording, a synthetic AI voice, or something else entirely? We also asked the Commission to make clear that someone can't dodge the rules just because a third-party platform is doing the automating, or because a human clicks "approve" on a batch of a thousand AI-generated calls.

Require callers to say up front when you're talking to a machine. If an AI system is making the call, the person on the other end should be told that clearly, at the very start of the call, before any sales pitch and without having to press a button to find out. This one is straightforward. People deserve to know who, or what, they're talking to, especially now that AI voices can be used to impersonate government officials, banks, or even family members.

Don't let "personal use" become a loophole. People using an AI assistant to book a haircut or call a restaurant shouldn't get tangled up in telemarketing rules built for mass campaigns. But we asked the Commission to be careful here, because a broadly written personal use exemption is exactly the kind of thing a bad actor will hide behind to claim their mass calling operation is just "personal." We suggested clear factors the Commission can use to tell the difference, like volume, whether numbers were purchased or harvested, and whether there's a financial benefit involved.

Retire the old "sequential versus random dialing" distinction. This rule dates back to when auto dialers worked through phone prefixes in numerical order. Nobody dials that way anymore. Modern operations use predictive models and purchased data instead, and the old distinction has become a technicality bad actors can point to to claim they're compliant. We recommended replacing it with standards based on call volume and whether valid consent exists.

Make sure both the calling company and the client behind the call can be identified. Abusive campaigns often hide behind a chain of intermediaries and resellers. We asked the CRTC to require that both the platform making the call and the business that hired them be identifiable, similar in spirit to "know your customer" practices used elsewhere.

Recognize that an authenticated call isn't automatically a trustworthy call. STIR/SHAKEN, the caller ID authentication system, verifies where a call came from. It doesn't verify whether the call is honest or wanted. We asked the Commission to preserve carriers' ability to keep using spam labels, reputation systems, and analytics alongside authentication, not instead of it.

Treat consent as belonging to a person, not a phone number. Phone numbers get reassigned to new people all the time. We recommended that Canada consider something like the reassigned numbers database the US FCC already runs, so that consent someone gave years ago doesn't follow their old number to a stranger.

Build in privacy protections for AI voice technology specifically. This includes limits on how long voice recordings and voice biometric data can be kept, a rule that consent given through one channel, say a chat form, can't automatically be stretched to cover phone calls, and clear recognition that AI voice cloning used to impersonate real people is a serious harm the rules should address directly.

We also weighed in on record-keeping timelines, how the review should coordinate with the incoming privacy legislation such as C-36 currently before Parliament, and how disclosures should be written so they're genuinely understandable to older adults, people with disabilities, and people communicating in a language other than their first one.

Why M3AAWG is the one saying this

M3AAWG's more than 200 member organizations collectively handle the majority of the world's email, messaging, and voice traffic. Our members are the carriers, service providers, and infrastructure operators who see this abuse happening in real time and who are also the ones expected to authenticate calls, filter spam, and respond to traceback requests. We're a founding participant in the STIR/SHAKEN ecosystem, and a lot of this submission is really about making sure UTR modernization doesn't accidentally work against that authentication infrastructure, but strengthens it instead.

What happens next

We've asked the CRTC for party status so we can participate in the reply phase of this proceeding, and we've offered to provide additional technical detail if it would help the Commission's work. Rules like these move slowly by design, and that's appropriate given how much depends on getting them right. But the direction matters, and we think a modernized UTR framework built around outcomes rather than mechanisms is one that will actually hold up as AI calling technology keeps evolving.

Thank you again to the CRTC for the opportunity to be part of this process. We'll keep members posted as the proceeding moves forward. 

Feeling Inspired?

  • Use the subscribe option at the top of this blog to stay up to date on what’s happening at M3AAWG. 
  • Read through additional M3AAWG Public Policy Publications
  • Visit our Join Us page to learn more about becoming a M3AAWG member.