By
July 27, 2026
9 min read
What Regulation F and the CFPB Mean for Your AI Debt Collection Software Decision



Why collections teams are suddenly buying AI
Because the math changed twice at once: delinquencies are climbing back toward pre-pandemic levels while the labor pool willing to do outbound collections work keeps shrinking, and the AI tooling to run that outreach got cheap enough to matter. A wave of AI-native vendors, InDebted, Skit.ai, Prodigal, HighRadius, C&R Software, has moved into the space in the last two years, each selling predictive scoring, automated dunning sequences, and voice or chat agents that promise to do the work of a collections floor at a fraction of the headcount cost.
None of those vendor pages will tell you the part that actually matters for a finance or compliance leader signing the contract: the risk in AI-driven collections isn't the AI. It's what happens to your consumer data once it leaves your walls, and whether the system you bought can produce a specific, defensible reason for every adverse action it takes. That's the decision this post is built to help you make.
Is AI debt collection software actually compliant with Regulation F?
An AI system can be built to comply with Regulation F, but "AI-powered" and "Reg F compliant" are not the same claim, and most vendor marketing pages blur the two on purpose. Compliance depends entirely on how the system handles communication frequency, consent, and content, not on whether a model is involved.
What Regulation F actually requires
Regulation F, the CFPB's debt collection rule that took effect November 30, 2021, sets a bright-line "call cap" (no more than seven calls per consumer per debt per week), requires specific content and format for validation notices, and lays out consent rules for reaching consumers by email or text. The full text is worth reading directly rather than trusting a vendor's paraphrase, since the CFPB's Regulation F final rule is specific about what counts as an electronic communication and how opt-outs must be honored. An AI agent sending automated texts or emails at scale needs to track this per-consumer, per-debt state correctly, not approximately. That's a data architecture problem before it's a language model problem.
The CFPB's line on algorithmic decisions
This is the part almost no vendor page engages with honestly. In May 2022 the CFPB issued Circular 2022-03, stating plainly that creditors using complex algorithms or AI to make credit and collections decisions still have to give consumers specific, accurate reasons for adverse actions. "The model flagged this account" is not a compliant explanation. If your AI system prioritizes, scores, or routes accounts in a way that affects the consumer's outcome, and most collections AI does exactly that, you need an audit trail that can produce a real reason on demand, not a confidence score. The NIST AI Risk Management Framework is a decent starting point for what that documentation should look like, even though it's not collections-specific.
Any AI collections system also has to sit on top of the baseline federal law the industry has operated under for decades: the Fair Debt Collection Practices Act. Reg F is an implementation of the FDCPA, not a replacement for it. A vendor that talks about Reg F but never mentions the FDCPA's validation and dispute-handling requirements hasn't fully thought through what they're selling you.
What breaks when you bolt AI onto an existing collections program
The failure mode we see most often isn't a rogue chatbot saying something wrong on a call. It's an AI layer added on top of a collections workflow that was never designed to expose per-account communication history, consent status, and state licensing rules to the system making outreach decisions. A few specific breakage points show up repeatedly:
State ARM licensing. Collection agency licensing is state-by-state, and an AI system that decides when and how to contact a consumer needs to know which state's rules apply to that account, not just the federal floor.
TCPA calling and texting restrictions. Autodialed calls and automated texts trigger consent requirements separate from Reg F. A voice AI agent that "sounds human" doesn't change its legal classification as an automated system.
Validation notice timing. If the AI layer accelerates outreach faster than the validation notice can legally go out, you've created a violation the system caused, not solved.
Explainability gaps. When an AI model deprioritizes or escalates an account and a consumer disputes the treatment, "the model said so" is not an answer a regulator or a plaintiff's attorney will accept.
There's also a behavioral wrinkle worth knowing before you deploy voice AI at scale. Research out of Yale School of Management found that consumers are more willing to break repayment promises made to an AI collector than to a human one, per Yale Insights. That's not a compliance risk, it's a collections-performance risk, and it means the efficiency gains from AI outreach can get eaten by lower promise-to-pay follow-through if the deployment isn't designed with escalation to a human at the right moments.
Build vs. buy: the real trade-off for regulated creditors
When you subscribe to a third-party AI collections platform, you're not just buying software, you're handing a vendor your consumers' names, balances, payment history, and often their financial hardship details. The question that matters is what that vendor does with the data afterward. Does it stay in a single-tenant environment scoped to your portfolio, or does it flow into a shared model trained across multiple creditors' accounts? Most vendor pages don't answer this clearly because the honest answer, for a lot of them, is the latter: your data helps train a model other clients benefit from too.
That's not automatically disqualifying, but it changes your risk posture. If your legal or compliance team ever needs to explain to a regulator exactly what data went where and why a specific decision was made about a specific consumer, "our vendor's proprietary model" is a much harder position to defend than an architecture you own and can inspect line by line.
This is the same trade-off we've written about for accounts receivable generally in why AR software stops working once billing gets complex, but third-party collections raises the stakes further: it's not your own money you're managing, it's a regulated relationship with someone else's consumer debt. The build case gets stronger, not weaker, the more regulated your data is.
What to ask before you sign with an AI debt collection vendor
Most vendor sales calls will not surface these on their own. Ask directly, in writing, before you sign:
Is our data used to train or fine-tune a model shared across other clients, and can we get that in the contract, not just verbally?
Where does the data live physically, and does the vendor retain it after contract termination?
Can the system produce a specific, human-readable reason for any adverse action or account-treatment decision, on demand, within a timeframe that satisfies a CFPB inquiry?
What states is the platform actually licensed and configured to operate correctly in, and how does it handle a state whose rules differ from the federal floor?
What's the human-in-the-loop path when the AI is uncertain, and who reviews escalations before they become a compliance incident instead of after?
If a vendor can't answer question one clearly, assume the answer is unfavorable to you.
What a compliant, owned collections AI setup actually looks like
The pattern that holds up under audit isn't a single AI model deciding everything. It's a system where deterministic rules (communication caps, state licensing gates, consent status) sit in a hard layer the AI cannot override, and the AI itself is scoped to narrower jobs: drafting outreach language within pre-approved templates, triaging which accounts need human attention, summarizing a consumer's history for an agent before a call. The model never gets to be the final word on whether a communication goes out; the rules engine is.
For regulated clients specifically, we run this kind of system self-hosted on the client's own infrastructure with zero data retention on the model side, which removes the "did our data train someone else's model" question entirely. We've built exception-based automation on this same principle for a medical-legal operations firm, Preferred Med Network, where document intake and case assignment run on autopilot and the system only raises a flag to a human when confidence is low or data is missing, saving roughly $300,000 a year without removing a human from decisions that need one. The public writeup is at the Preferred Med Network case study. A collections program built the same way looks less like a chatbot replacing agents and more like agents who spend their day only on the accounts that actually need a human decision.
What this actually costs and what it should return
Vendor collections platforms typically price on a per-account-worked or per-seat basis, often landing somewhere between $0.75 and $2 per active account per month depending on volume and features, plus setup fees. For a portfolio of 50,000 active accounts, that's roughly $450,000 to $1.2 million a year in subscription cost alone, recurring, with your data flowing through someone else's infrastructure the entire time.
A custom-built system costs more up front, usually a multi-week engagement scoped around a paid diagnosis of where the actual leakage or labor cost sits before anything gets built, but the client owns the resulting IP outright with no subscription tail. We saw a comparable shape on the billing side with C&G Energy Services, where a revenue-leaking utility billing process that was losing over $1 million a year got broken into discrete automation projects and recovered roughly $800,000 a year, with the honest caveat that most of the fix was process automation and integration work, not exotic AI. The C&G Energy Services case study and our related piece on how AI agents stop revenue leakage in utility billing both make the same point: the ROI in these systems usually comes from fixing a broken process end to end, not from bolting a model onto the part that was already visible.
If you're weighing this decision against a broader state and federal compliance patchwork, our piece on what Colorado's new AI Act actually requires is a useful companion, and if your board or insurer is asking what a defensible AI architecture needs to document, AI liability insurance: what your architecture means to an underwriter covers the audit-trail expectations in more depth.
If you're working through this decision, this is exactly what our Discovery phase maps out before anything gets built, and we're happy to compare notes.
Frequently asked questions
How do you automate debt collection without breaking Regulation F?
Start by making communication frequency, consent status, and state licensing rules deterministic gates the AI system cannot override, not something the model infers. Automate drafting and triage, not the final decision to contact a consumer. Log every decision with a specific, human-readable reason so you can answer a CFPB or consumer inquiry without relying on a confidence score.
Is AI debt collection software legal and CFPB-compliant?
It can be, but compliance depends on the implementation, not the AI label. The CFPB's 2022 circular makes clear that algorithmic decisions still require specific, accurate reasons for adverse actions. A vendor calling itself compliant without addressing explainability and data handling hasn't actually made that case.
Does the CFPB allow AI or algorithms to make collections decisions?
Yes, but with a condition: whoever deploys the algorithm remains responsible for giving consumers specific reasons behind any adverse action, per Circular 2022-03. "The model decided" doesn't satisfy that requirement. The decision-making logic needs to be auditable back to a real, statable reason.
Can debt collectors text, email, or use chatbots under Regulation F?
Yes, with consent and content rules attached. Regulation F permits electronic communication but requires clear consent tracking, opt-out honoring, and specific disclosures, detailed in the CFPB's final rule. A chatbot or texting agent has to enforce these rules per consumer, per debt, not apply a blanket policy across the portfolio.
What's the difference between AI debt collection software and a custom-built collections agent?
Off-the-shelf software is faster to deploy but usually means your consumer data and decision logic sit inside someone else's shared platform, sometimes training a model used across other clients' portfolios too. A custom-built agent costs more up front but stays on your infrastructure, under your audit control, with no subscription tail and no ambiguity about where the data goes.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
By
July 27, 2026
9 min read
What Regulation F and the CFPB Mean for Your AI Debt Collection Software Decision



Why collections teams are suddenly buying AI
Because the math changed twice at once: delinquencies are climbing back toward pre-pandemic levels while the labor pool willing to do outbound collections work keeps shrinking, and the AI tooling to run that outreach got cheap enough to matter. A wave of AI-native vendors, InDebted, Skit.ai, Prodigal, HighRadius, C&R Software, has moved into the space in the last two years, each selling predictive scoring, automated dunning sequences, and voice or chat agents that promise to do the work of a collections floor at a fraction of the headcount cost.
None of those vendor pages will tell you the part that actually matters for a finance or compliance leader signing the contract: the risk in AI-driven collections isn't the AI. It's what happens to your consumer data once it leaves your walls, and whether the system you bought can produce a specific, defensible reason for every adverse action it takes. That's the decision this post is built to help you make.
Is AI debt collection software actually compliant with Regulation F?
An AI system can be built to comply with Regulation F, but "AI-powered" and "Reg F compliant" are not the same claim, and most vendor marketing pages blur the two on purpose. Compliance depends entirely on how the system handles communication frequency, consent, and content, not on whether a model is involved.
What Regulation F actually requires
Regulation F, the CFPB's debt collection rule that took effect November 30, 2021, sets a bright-line "call cap" (no more than seven calls per consumer per debt per week), requires specific content and format for validation notices, and lays out consent rules for reaching consumers by email or text. The full text is worth reading directly rather than trusting a vendor's paraphrase, since the CFPB's Regulation F final rule is specific about what counts as an electronic communication and how opt-outs must be honored. An AI agent sending automated texts or emails at scale needs to track this per-consumer, per-debt state correctly, not approximately. That's a data architecture problem before it's a language model problem.
The CFPB's line on algorithmic decisions
This is the part almost no vendor page engages with honestly. In May 2022 the CFPB issued Circular 2022-03, stating plainly that creditors using complex algorithms or AI to make credit and collections decisions still have to give consumers specific, accurate reasons for adverse actions. "The model flagged this account" is not a compliant explanation. If your AI system prioritizes, scores, or routes accounts in a way that affects the consumer's outcome, and most collections AI does exactly that, you need an audit trail that can produce a real reason on demand, not a confidence score. The NIST AI Risk Management Framework is a decent starting point for what that documentation should look like, even though it's not collections-specific.
Any AI collections system also has to sit on top of the baseline federal law the industry has operated under for decades: the Fair Debt Collection Practices Act. Reg F is an implementation of the FDCPA, not a replacement for it. A vendor that talks about Reg F but never mentions the FDCPA's validation and dispute-handling requirements hasn't fully thought through what they're selling you.
What breaks when you bolt AI onto an existing collections program
The failure mode we see most often isn't a rogue chatbot saying something wrong on a call. It's an AI layer added on top of a collections workflow that was never designed to expose per-account communication history, consent status, and state licensing rules to the system making outreach decisions. A few specific breakage points show up repeatedly:
State ARM licensing. Collection agency licensing is state-by-state, and an AI system that decides when and how to contact a consumer needs to know which state's rules apply to that account, not just the federal floor.
TCPA calling and texting restrictions. Autodialed calls and automated texts trigger consent requirements separate from Reg F. A voice AI agent that "sounds human" doesn't change its legal classification as an automated system.
Validation notice timing. If the AI layer accelerates outreach faster than the validation notice can legally go out, you've created a violation the system caused, not solved.
Explainability gaps. When an AI model deprioritizes or escalates an account and a consumer disputes the treatment, "the model said so" is not an answer a regulator or a plaintiff's attorney will accept.
There's also a behavioral wrinkle worth knowing before you deploy voice AI at scale. Research out of Yale School of Management found that consumers are more willing to break repayment promises made to an AI collector than to a human one, per Yale Insights. That's not a compliance risk, it's a collections-performance risk, and it means the efficiency gains from AI outreach can get eaten by lower promise-to-pay follow-through if the deployment isn't designed with escalation to a human at the right moments.
Build vs. buy: the real trade-off for regulated creditors
When you subscribe to a third-party AI collections platform, you're not just buying software, you're handing a vendor your consumers' names, balances, payment history, and often their financial hardship details. The question that matters is what that vendor does with the data afterward. Does it stay in a single-tenant environment scoped to your portfolio, or does it flow into a shared model trained across multiple creditors' accounts? Most vendor pages don't answer this clearly because the honest answer, for a lot of them, is the latter: your data helps train a model other clients benefit from too.
That's not automatically disqualifying, but it changes your risk posture. If your legal or compliance team ever needs to explain to a regulator exactly what data went where and why a specific decision was made about a specific consumer, "our vendor's proprietary model" is a much harder position to defend than an architecture you own and can inspect line by line.
This is the same trade-off we've written about for accounts receivable generally in why AR software stops working once billing gets complex, but third-party collections raises the stakes further: it's not your own money you're managing, it's a regulated relationship with someone else's consumer debt. The build case gets stronger, not weaker, the more regulated your data is.
What to ask before you sign with an AI debt collection vendor
Most vendor sales calls will not surface these on their own. Ask directly, in writing, before you sign:
Is our data used to train or fine-tune a model shared across other clients, and can we get that in the contract, not just verbally?
Where does the data live physically, and does the vendor retain it after contract termination?
Can the system produce a specific, human-readable reason for any adverse action or account-treatment decision, on demand, within a timeframe that satisfies a CFPB inquiry?
What states is the platform actually licensed and configured to operate correctly in, and how does it handle a state whose rules differ from the federal floor?
What's the human-in-the-loop path when the AI is uncertain, and who reviews escalations before they become a compliance incident instead of after?
If a vendor can't answer question one clearly, assume the answer is unfavorable to you.
What a compliant, owned collections AI setup actually looks like
The pattern that holds up under audit isn't a single AI model deciding everything. It's a system where deterministic rules (communication caps, state licensing gates, consent status) sit in a hard layer the AI cannot override, and the AI itself is scoped to narrower jobs: drafting outreach language within pre-approved templates, triaging which accounts need human attention, summarizing a consumer's history for an agent before a call. The model never gets to be the final word on whether a communication goes out; the rules engine is.
For regulated clients specifically, we run this kind of system self-hosted on the client's own infrastructure with zero data retention on the model side, which removes the "did our data train someone else's model" question entirely. We've built exception-based automation on this same principle for a medical-legal operations firm, Preferred Med Network, where document intake and case assignment run on autopilot and the system only raises a flag to a human when confidence is low or data is missing, saving roughly $300,000 a year without removing a human from decisions that need one. The public writeup is at the Preferred Med Network case study. A collections program built the same way looks less like a chatbot replacing agents and more like agents who spend their day only on the accounts that actually need a human decision.
What this actually costs and what it should return
Vendor collections platforms typically price on a per-account-worked or per-seat basis, often landing somewhere between $0.75 and $2 per active account per month depending on volume and features, plus setup fees. For a portfolio of 50,000 active accounts, that's roughly $450,000 to $1.2 million a year in subscription cost alone, recurring, with your data flowing through someone else's infrastructure the entire time.
A custom-built system costs more up front, usually a multi-week engagement scoped around a paid diagnosis of where the actual leakage or labor cost sits before anything gets built, but the client owns the resulting IP outright with no subscription tail. We saw a comparable shape on the billing side with C&G Energy Services, where a revenue-leaking utility billing process that was losing over $1 million a year got broken into discrete automation projects and recovered roughly $800,000 a year, with the honest caveat that most of the fix was process automation and integration work, not exotic AI. The C&G Energy Services case study and our related piece on how AI agents stop revenue leakage in utility billing both make the same point: the ROI in these systems usually comes from fixing a broken process end to end, not from bolting a model onto the part that was already visible.
If you're weighing this decision against a broader state and federal compliance patchwork, our piece on what Colorado's new AI Act actually requires is a useful companion, and if your board or insurer is asking what a defensible AI architecture needs to document, AI liability insurance: what your architecture means to an underwriter covers the audit-trail expectations in more depth.
If you're working through this decision, this is exactly what our Discovery phase maps out before anything gets built, and we're happy to compare notes.
Frequently asked questions
How do you automate debt collection without breaking Regulation F?
Start by making communication frequency, consent status, and state licensing rules deterministic gates the AI system cannot override, not something the model infers. Automate drafting and triage, not the final decision to contact a consumer. Log every decision with a specific, human-readable reason so you can answer a CFPB or consumer inquiry without relying on a confidence score.
Is AI debt collection software legal and CFPB-compliant?
It can be, but compliance depends on the implementation, not the AI label. The CFPB's 2022 circular makes clear that algorithmic decisions still require specific, accurate reasons for adverse actions. A vendor calling itself compliant without addressing explainability and data handling hasn't actually made that case.
Does the CFPB allow AI or algorithms to make collections decisions?
Yes, but with a condition: whoever deploys the algorithm remains responsible for giving consumers specific reasons behind any adverse action, per Circular 2022-03. "The model decided" doesn't satisfy that requirement. The decision-making logic needs to be auditable back to a real, statable reason.
Can debt collectors text, email, or use chatbots under Regulation F?
Yes, with consent and content rules attached. Regulation F permits electronic communication but requires clear consent tracking, opt-out honoring, and specific disclosures, detailed in the CFPB's final rule. A chatbot or texting agent has to enforce these rules per consumer, per debt, not apply a blanket policy across the portfolio.
What's the difference between AI debt collection software and a custom-built collections agent?
Off-the-shelf software is faster to deploy but usually means your consumer data and decision logic sit inside someone else's shared platform, sometimes training a model used across other clients' portfolios too. A custom-built agent costs more up front but stays on your infrastructure, under your audit control, with no subscription tail and no ambiguity about where the data goes.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
By
July 27, 2026
9 min read
What Regulation F and the CFPB Mean for Your AI Debt Collection Software Decision



Why collections teams are suddenly buying AI
Because the math changed twice at once: delinquencies are climbing back toward pre-pandemic levels while the labor pool willing to do outbound collections work keeps shrinking, and the AI tooling to run that outreach got cheap enough to matter. A wave of AI-native vendors, InDebted, Skit.ai, Prodigal, HighRadius, C&R Software, has moved into the space in the last two years, each selling predictive scoring, automated dunning sequences, and voice or chat agents that promise to do the work of a collections floor at a fraction of the headcount cost.
None of those vendor pages will tell you the part that actually matters for a finance or compliance leader signing the contract: the risk in AI-driven collections isn't the AI. It's what happens to your consumer data once it leaves your walls, and whether the system you bought can produce a specific, defensible reason for every adverse action it takes. That's the decision this post is built to help you make.
Is AI debt collection software actually compliant with Regulation F?
An AI system can be built to comply with Regulation F, but "AI-powered" and "Reg F compliant" are not the same claim, and most vendor marketing pages blur the two on purpose. Compliance depends entirely on how the system handles communication frequency, consent, and content, not on whether a model is involved.
What Regulation F actually requires
Regulation F, the CFPB's debt collection rule that took effect November 30, 2021, sets a bright-line "call cap" (no more than seven calls per consumer per debt per week), requires specific content and format for validation notices, and lays out consent rules for reaching consumers by email or text. The full text is worth reading directly rather than trusting a vendor's paraphrase, since the CFPB's Regulation F final rule is specific about what counts as an electronic communication and how opt-outs must be honored. An AI agent sending automated texts or emails at scale needs to track this per-consumer, per-debt state correctly, not approximately. That's a data architecture problem before it's a language model problem.
The CFPB's line on algorithmic decisions
This is the part almost no vendor page engages with honestly. In May 2022 the CFPB issued Circular 2022-03, stating plainly that creditors using complex algorithms or AI to make credit and collections decisions still have to give consumers specific, accurate reasons for adverse actions. "The model flagged this account" is not a compliant explanation. If your AI system prioritizes, scores, or routes accounts in a way that affects the consumer's outcome, and most collections AI does exactly that, you need an audit trail that can produce a real reason on demand, not a confidence score. The NIST AI Risk Management Framework is a decent starting point for what that documentation should look like, even though it's not collections-specific.
Any AI collections system also has to sit on top of the baseline federal law the industry has operated under for decades: the Fair Debt Collection Practices Act. Reg F is an implementation of the FDCPA, not a replacement for it. A vendor that talks about Reg F but never mentions the FDCPA's validation and dispute-handling requirements hasn't fully thought through what they're selling you.
What breaks when you bolt AI onto an existing collections program
The failure mode we see most often isn't a rogue chatbot saying something wrong on a call. It's an AI layer added on top of a collections workflow that was never designed to expose per-account communication history, consent status, and state licensing rules to the system making outreach decisions. A few specific breakage points show up repeatedly:
State ARM licensing. Collection agency licensing is state-by-state, and an AI system that decides when and how to contact a consumer needs to know which state's rules apply to that account, not just the federal floor.
TCPA calling and texting restrictions. Autodialed calls and automated texts trigger consent requirements separate from Reg F. A voice AI agent that "sounds human" doesn't change its legal classification as an automated system.
Validation notice timing. If the AI layer accelerates outreach faster than the validation notice can legally go out, you've created a violation the system caused, not solved.
Explainability gaps. When an AI model deprioritizes or escalates an account and a consumer disputes the treatment, "the model said so" is not an answer a regulator or a plaintiff's attorney will accept.
There's also a behavioral wrinkle worth knowing before you deploy voice AI at scale. Research out of Yale School of Management found that consumers are more willing to break repayment promises made to an AI collector than to a human one, per Yale Insights. That's not a compliance risk, it's a collections-performance risk, and it means the efficiency gains from AI outreach can get eaten by lower promise-to-pay follow-through if the deployment isn't designed with escalation to a human at the right moments.
Build vs. buy: the real trade-off for regulated creditors
When you subscribe to a third-party AI collections platform, you're not just buying software, you're handing a vendor your consumers' names, balances, payment history, and often their financial hardship details. The question that matters is what that vendor does with the data afterward. Does it stay in a single-tenant environment scoped to your portfolio, or does it flow into a shared model trained across multiple creditors' accounts? Most vendor pages don't answer this clearly because the honest answer, for a lot of them, is the latter: your data helps train a model other clients benefit from too.
That's not automatically disqualifying, but it changes your risk posture. If your legal or compliance team ever needs to explain to a regulator exactly what data went where and why a specific decision was made about a specific consumer, "our vendor's proprietary model" is a much harder position to defend than an architecture you own and can inspect line by line.
This is the same trade-off we've written about for accounts receivable generally in why AR software stops working once billing gets complex, but third-party collections raises the stakes further: it's not your own money you're managing, it's a regulated relationship with someone else's consumer debt. The build case gets stronger, not weaker, the more regulated your data is.
What to ask before you sign with an AI debt collection vendor
Most vendor sales calls will not surface these on their own. Ask directly, in writing, before you sign:
Is our data used to train or fine-tune a model shared across other clients, and can we get that in the contract, not just verbally?
Where does the data live physically, and does the vendor retain it after contract termination?
Can the system produce a specific, human-readable reason for any adverse action or account-treatment decision, on demand, within a timeframe that satisfies a CFPB inquiry?
What states is the platform actually licensed and configured to operate correctly in, and how does it handle a state whose rules differ from the federal floor?
What's the human-in-the-loop path when the AI is uncertain, and who reviews escalations before they become a compliance incident instead of after?
If a vendor can't answer question one clearly, assume the answer is unfavorable to you.
What a compliant, owned collections AI setup actually looks like
The pattern that holds up under audit isn't a single AI model deciding everything. It's a system where deterministic rules (communication caps, state licensing gates, consent status) sit in a hard layer the AI cannot override, and the AI itself is scoped to narrower jobs: drafting outreach language within pre-approved templates, triaging which accounts need human attention, summarizing a consumer's history for an agent before a call. The model never gets to be the final word on whether a communication goes out; the rules engine is.
For regulated clients specifically, we run this kind of system self-hosted on the client's own infrastructure with zero data retention on the model side, which removes the "did our data train someone else's model" question entirely. We've built exception-based automation on this same principle for a medical-legal operations firm, Preferred Med Network, where document intake and case assignment run on autopilot and the system only raises a flag to a human when confidence is low or data is missing, saving roughly $300,000 a year without removing a human from decisions that need one. The public writeup is at the Preferred Med Network case study. A collections program built the same way looks less like a chatbot replacing agents and more like agents who spend their day only on the accounts that actually need a human decision.
What this actually costs and what it should return
Vendor collections platforms typically price on a per-account-worked or per-seat basis, often landing somewhere between $0.75 and $2 per active account per month depending on volume and features, plus setup fees. For a portfolio of 50,000 active accounts, that's roughly $450,000 to $1.2 million a year in subscription cost alone, recurring, with your data flowing through someone else's infrastructure the entire time.
A custom-built system costs more up front, usually a multi-week engagement scoped around a paid diagnosis of where the actual leakage or labor cost sits before anything gets built, but the client owns the resulting IP outright with no subscription tail. We saw a comparable shape on the billing side with C&G Energy Services, where a revenue-leaking utility billing process that was losing over $1 million a year got broken into discrete automation projects and recovered roughly $800,000 a year, with the honest caveat that most of the fix was process automation and integration work, not exotic AI. The C&G Energy Services case study and our related piece on how AI agents stop revenue leakage in utility billing both make the same point: the ROI in these systems usually comes from fixing a broken process end to end, not from bolting a model onto the part that was already visible.
If you're weighing this decision against a broader state and federal compliance patchwork, our piece on what Colorado's new AI Act actually requires is a useful companion, and if your board or insurer is asking what a defensible AI architecture needs to document, AI liability insurance: what your architecture means to an underwriter covers the audit-trail expectations in more depth.
If you're working through this decision, this is exactly what our Discovery phase maps out before anything gets built, and we're happy to compare notes.
Frequently asked questions
How do you automate debt collection without breaking Regulation F?
Start by making communication frequency, consent status, and state licensing rules deterministic gates the AI system cannot override, not something the model infers. Automate drafting and triage, not the final decision to contact a consumer. Log every decision with a specific, human-readable reason so you can answer a CFPB or consumer inquiry without relying on a confidence score.
Is AI debt collection software legal and CFPB-compliant?
It can be, but compliance depends on the implementation, not the AI label. The CFPB's 2022 circular makes clear that algorithmic decisions still require specific, accurate reasons for adverse actions. A vendor calling itself compliant without addressing explainability and data handling hasn't actually made that case.
Does the CFPB allow AI or algorithms to make collections decisions?
Yes, but with a condition: whoever deploys the algorithm remains responsible for giving consumers specific reasons behind any adverse action, per Circular 2022-03. "The model decided" doesn't satisfy that requirement. The decision-making logic needs to be auditable back to a real, statable reason.
Can debt collectors text, email, or use chatbots under Regulation F?
Yes, with consent and content rules attached. Regulation F permits electronic communication but requires clear consent tracking, opt-out honoring, and specific disclosures, detailed in the CFPB's final rule. A chatbot or texting agent has to enforce these rules per consumer, per debt, not apply a blanket policy across the portfolio.
What's the difference between AI debt collection software and a custom-built collections agent?
Off-the-shelf software is faster to deploy but usually means your consumer data and decision logic sit inside someone else's shared platform, sometimes training a model used across other clients' portfolios too. A custom-built agent costs more up front but stays on your infrastructure, under your audit control, with no subscription tail and no ambiguity about where the data goes.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.
Tell us where the manual work hurts
We’ll tell you straight whether AI can fix it, what it costs, and what it should return. Whatever we build, you own.