Back to Articles
    Fundraising & Compliance

    Text Message Fundraising and TCPA: Consent Rules AI Will Not Remember for You

    Nearly every conversation about nonprofit texting is about the message: how to write it, when to send it, how to make the ask land. Almost none of it is about the question a plaintiff's attorney will ask first, which is who said you could text this person, when did they say it, and what exactly did the screen say when they said it. That record is the entire compliance posture of an SMS program, it is the part AI cannot invent for you, and most organizations running text campaigns today could not produce it.

    Published: September 22, 2026•17 min read•Fundraising & Compliance
    A nonprofit fundraiser reviewing consent records and opt-in disclosures for a text message program

    Mobile messaging has stopped being an experiment for nonprofits. According to the M+R Benchmarks 2026 mobile messaging findings, nonprofits sent 40 percent more mobile messages in 2025 than in 2024, mobile revenue grew 48 percent while overall online revenue grew 15 percent, and subscriber lists grew 5 percent year over year. Those numbers describe a channel that is scaling quickly inside organizations that have not correspondingly scaled the record-keeping underneath it. Volume growth without consent growth is exactly the shape of an enforcement problem.

    This article is not about how conversational giving over SMS works. We covered the mechanics of that separately in our piece on text-to-give and conversational SMS, and this one deliberately stays off that ground. What follows is about the unglamorous layer beneath the channel: the Telephone Consumer Protection Act, what it actually requires before a fundraising text goes out, what a compliant opt-in disclosure has to say, what a consent record has to contain, and how the whole apparatus has to behave when someone texts back the word STOP.

    The reason this matters more than most compliance topics is arithmetic. The TCPA carries statutory damages of up to 500 dollars per violation and up to 1,500 dollars per violation where the conduct is willful or knowing, and the violation unit is the message, not the campaign and not the person. An organization that texts four thousand supporters on a list it cannot document, twice a month, is not looking at one problem. It is looking at a number that scales with the size of the list and the cadence of the program, which is to say it scales with exactly the things a successful fundraising team is trying to increase.

    We will also be specific about AI, because this is a topic where the temptation to delegate is strong and the consequences of delegating the wrong part are severe. AI is genuinely useful here. It can draft compliant disclosure language, audit a subscriber list against your own consent schema and tell you which records are incomplete, classify inbound replies so opt-out intent does not sit unread in a queue, and review outbound drafts against your written policy before anyone hits send. What it must never do is decide whether a particular number may legally be texted, manufacture a consent record that does not reflect something a human being actually did, or state a legal conclusion you then rely on.

    One necessary caveat before the detail. This is a US-focused overview written for nonprofit staff, not legal advice, and the TCPA is a statute where small facts change answers. Federal rules have shifted repeatedly in the last two years, state statutes vary meaningfully, and appellate courts have recently split on questions as basic as whether a text message is a call. Use this to arrive at a conversation with counsel already knowing what to ask. That is a much shorter and cheaper conversation than the one that starts with a blank page.

    What the TCPA Reaches, and Which of Your Texts Are Actually Marketing

    The Telephone Consumer Protection Act and the FCC rules implementing it at 47 CFR 64.1200 restrict calls and texts made to wireless numbers using an automatic telephone dialing system or an artificial or prerecorded voice. Text messages sent through a mass messaging platform are treated as within that scope for practical purposes, and every credible nonprofit messaging vendor operates on that assumption. The important distinction for a fundraising team is not whether the TCPA applies at all. It is which consent standard applies to each message you send.

    The rules draw a line between messages that advertise or promote, which sit in the telemarketing bucket and require the higher standard of prior express written consent, and informational or transactional messages, which sit in a lower bucket requiring prior express consent that can be established more simply. A donation receipt, an event reminder for an event the person registered for, a volunteer shift confirmation, and a delivery notice for something the person requested are the clear informational cases. A solicitation for a gift, a year-end appeal, a matching gift push, and a membership renewal ask are the clear marketing cases.

    The problem is that real nonprofit messages do not respect the line. Consider the message most development teams would consider harmless: "Thanks for volunteering on Saturday. We served 240 meals. Chip in 25 dollars to keep the kitchen stocked." That is a transactional opener with a solicitation attached, and the attachment is what governs. Once a message contains an ask, the whole message is treated as marketing, and the consent you needed was the higher standard, not the lower one. Teams get into trouble here constantly because the dual-purpose message feels like good stewardship rather than a legal event.

    The practical response is to classify message types in writing before the program scales, and to enforce the classification at the template level rather than in a sender's head. Build a template library where every template is tagged with the consent standard it requires, and where the sending system refuses to release a marketing-tagged template to a segment that only has informational consent on file. This is a systems control, and it is far more reliable than training people to remember a distinction they will encounter twice a month under deadline. If your organization is already building automated donor communications, this classification belongs in that architecture from the start rather than being retrofitted later.

    One more category deserves attention because it hides in plain sight. Advocacy messages asking a supporter to contact a legislator are not fundraising, but they are also frequently not purely informational, and organizations that run both fundraising and advocacy programs often maintain them in separate systems with separate lists and separate vendors. That structural split is where consent records and opt-out signals go to die, and we return to it below.

    Classifying your message types

    The tag that determines which consent standard applies

    • Clearly transactional: gift receipts, shift confirmations, event reminders for registered attendees
    • Clearly marketing: appeals, renewal asks, matching gift pushes, event ticket sales
    • Dual purpose: a thank-you with an ask attached, which is governed as marketing
    • Advocacy: its own category, its own list, and frequently its own vendor and its own gap
    • Enforcement point: the tag lives on the template, and the platform blocks the mismatch

    Prior Express Written Consent: What the Disclosure Actually Has to Say

    Prior express written consent is a defined term, not a description of a general feeling that someone agreed. Under the FCC's rules it means a written agreement, bearing the signature of the person being contacted, that clearly authorizes the sender to deliver advertisements or telemarketing messages to a specific telephone number using an automatic telephone dialing system or an artificial or prerecorded voice. An electronic signature that satisfies the federal E-SIGN Act counts, which is what makes a web form checkbox workable. The word doing the most work in that definition is "clearly," and it is where most nonprofit opt-in flows fail.

    A compliant disclosure needs to tell the person, in language they will actually read, several specific things. It needs to name the organization that will be texting them. It needs to say that the messages may be sent using automated technology. It needs to make clear that agreeing is not a condition of making a donation or receiving any service, which is the requirement most donation forms quietly violate by bundling the checkbox into the transaction flow. It needs to describe the kind of messages and give some sense of frequency. And it needs to say that message and data rates may apply and how to stop, which is where the standard HELP and STOP language belongs.

    The mechanics around the checkbox matter as much as the words next to it. The box must be unchecked by default, because a pre-checked box is not an affirmative act by the person and reads as the organization consenting on their behalf. The disclosure must sit immediately adjacent to the box rather than behind a link to a terms page, because a reasonable person has to have seen it at the moment they acted. And the consent must be separable from everything else on the form, so that someone can give a gift, join a mailing list, or register for an event without being forced to also accept text messages.

    This is the point where the single most common nonprofit misconception needs stating directly. A checkbox on a donation form that says "Yes, keep me updated" is not consent for future fundraising texts. It may not even be consent for texts at all, since it does not name the channel, does not mention automated technology, and does not make the not-a-condition disclosure. Neither is a phone number typed into a donation form's contact field. Supplying a number so a receipt can be sent, or so staff can call about a gift, is not authorization for an automated appeal three months later. Organizations that treat "we have their number" as equivalent to "we may text them" are building a list that cannot be defended.

    The same logic applies to every other channel through which numbers arrive. Event registration lists, petition signatures, raffle entries, volunteer applications, purchased or exchanged lists, and numbers appended by a data vendor all carry the same question: at the moment this number entered our file, did a person read a disclosure meeting the standard above and take an affirmative action in response? If the answer is no, or if the answer is unknown, the number is not textable for marketing regardless of how warm the relationship feels. A pragmatic path for those numbers is an email or a call asking them to opt in properly, which builds a smaller list you can actually use.

    Elements of a defensible opt-in disclosure

    What has to appear next to the unchecked box

    • The name of the organization that will send the messages
    • A statement that messages may be sent using automated technology
    • An explicit statement that consent is not a condition of donating or receiving services
    • The type of messages and an honest indication of frequency
    • Message and data rates language, HELP for help, STOP to cancel, and links to terms and privacy

    The Consent Record Is the Deliverable

    Here is the operational heart of the whole topic. In a TCPA dispute, the burden of establishing consent sits with the sender. The person who received the text does not have to prove they never agreed. Your organization has to produce evidence that they did, for that specific number, at a specific moment, under a disclosure whose exact wording you can reproduce. A screenshot of your current donation page is not that evidence, because your current page is not necessarily the page that existed eighteen months ago when the number came in.

    A usable consent record captures, at minimum, the phone number in a normalized format, a timestamp with a time zone, the source of the consent identified specifically enough to reconstruct it, the exact disclosure text that was displayed at that moment stored as a snapshot rather than as a pointer to a live page, the IP address and user agent for a web opt-in, the method by which consent was given, and a version identifier for the disclosure language. If consent arrived by the person texting a keyword to your short code, the record should hold the inbound message content and the timestamp of that message. If consent arrived on paper at an event, the record should reference a scanned image of the signed card.

    The disclosure snapshot is the field organizations skip and the one that matters most. Storing "consented via donation form" tells you nothing defensible, because nobody can say what the form said at the time. Versioning the disclosure language and stamping each consent record with the version identifier solves this cleanly and costs almost nothing to implement. When you change the wording, you mint a new version, and every record carries the version that was live when it was created. That single design decision converts an unprovable assertion into a reproducible fact.

    Retention needs deliberate thought too. The federal TCPA carries a four year statute of limitations, and several state statutes have their own periods, so a retention schedule that purges contact history after two years can leave you unable to defend a claim that is still live. At the same time, consent records contain personal data you are obliged to protect, so the answer is a defined retention period with restricted access rather than either indefinite accumulation or premature deletion. Fold this into your organization's broader records retention schedule rather than letting the messaging vendor's defaults decide it for you.

    Finally, ask a question most nonprofits have never asked their SMS vendor: can we export the full consent record, including disclosure snapshots, in a format we can read without your platform? Many organizations discover at the worst possible moment that their evidence lives inside a system they no longer subscribe to, or that the export contains a timestamp and nothing else. Make the exportable consent record a contractual requirement during procurement, alongside the other questions you would ask during vendor onboarding for any system holding sensitive supporter data. The evidence has to be yours.

    Fields every consent record should hold

    What you must be able to produce, per number

    • Number and timestamp: normalized number, date, time, and time zone
    • Source: the specific form, keyword, event, or paper card, identified precisely
    • Disclosure snapshot: the exact language shown, stored by version, not a link to a live page
    • Technical evidence: IP address and user agent for web opt-ins, inbound message body for keyword opt-ins
    • Lifecycle: scope of consent, any revocation with its timestamp and channel, and retention date

    The Rule That Came and Went: One-to-One Consent and the Lesson It Leaves

    In December 2023 the FCC adopted an order that would have required consent to be given to one identified seller at a time, and would have required the resulting messages to be logically and topically related to the interaction that produced the consent. It was aimed squarely at lead generation, where a single checkbox on a comparison website could be treated as consent for dozens of unrelated companies to call. The rule was scheduled to take effect on January 27, 2025.

    It never did. On January 24, 2025, three days before the effective date, the Eleventh Circuit decided Insurance Marketing Coalition v. FCC and vacated the rule, holding that the agency had exceeded its statutory authority because the requirement conflicted with the ordinary meaning of prior express consent in the statute itself. The FCC declined to challenge the decision, and in September 2025 it issued a final rule formally removing the vacated language and restoring the prior definition of prior express written consent at 47 CFR 64.1200(f). As of 2026, one-to-one consent is not a federal requirement.

    For nonprofits, the substantive relief is modest, because most charities were never running lead generation arrangements in the first place. The place it bites is partnership and coalition messaging, where several organizations share an opt-in form or a joint campaign. The federal rule that would have made that clearly unlawful is gone. That is not the same as the practice being safe. A supporter who checked a box at a coalition event and then received appeals from six organizations they cannot remember agreeing to is a supporter who will complain, will report the message as spam, and may consult a lawyer under a state statute the federal vacatur did not touch.

    The broader lesson is about rule churn, and it is the practical reason this article exists. In under two years the sector saw a major consent rule adopted, vacated by a court of appeals, and formally repealed by the agency. Over the same window the Supreme Court's 2025 decision in McLaughlin Chiropractic Associates v. McKesson reduced the deference district courts owe to FCC interpretations of the TCPA, which means more of these questions now get answered court by court rather than settled nationally by the agency. A compliance program designed around the most permissive available reading of a rule is a program that breaks every time the reading changes.

    Design instead for the standard you can defend under any plausible reading. Name your organization specifically in the disclosure rather than referring to partners generally. Get separate consent for each organization that will actually send messages, even where a shared form is technically permitted. Keep the consent topically connected to what the person was doing when they gave it. None of that is required federally today, all of it survives the next rule change intact, and the incremental cost is a slightly longer form. This is the same durability principle that applies across the shifting regulatory landscape nonprofits are navigating more generally.

    Building for rule churn

    Choices that survive the next change in the law

    • Name the sending organization in the disclosure, never "our partners" or "affiliated groups"
    • Take a separate opt-in per organization on any shared or coalition form
    • Keep the messages you send related to what the person signed up for
    • Version and date your disclosure language so you can show what applied when
    • Review the program annually with counsel rather than after a demand letter arrives

    STOP Has to Work Immediately, and It Has to Work Everywhere

    Revocation is the area where the FCC has been most active and where nonprofit programs most reliably fail, because failure here is structural rather than intentional. The FCC's consent revocation rules, most of which took effect on April 11, 2025, establish that a person may revoke consent through any reasonable means, that senders must honor the request within a defined window, and that senders may not impose a specific method as the only acceptable one. The Commission has indicated that replying with words including STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, or UNSUBSCRIBE constitutes a reasonable revocation.

    Read that list carefully, because it is where automated opt-out handling breaks. Many messaging platforms process the literal keyword STOP automatically at the carrier level and pass everything else through as an ordinary inbound reply. A supporter who texts back "please stop texting me" or "take me off this list" or "unsubscribe me" has revoked consent, and in most systems that message lands in an inbox nobody reads, while the next appeal goes out on schedule. That is the single most common real-world TCPA exposure in nonprofit texting, and it is entirely a workflow problem rather than a legal one.

    The second structural failure is propagation across systems. A supporter texts STOP to the fundraising platform, the fundraising platform suppresses them correctly, and six weeks later the advocacy team sends an action alert from a different vendor with a different list, to the same person, who has now revoked consent twice and been texted anyway. Add a peer-to-peer texting tool a volunteer team uses during a campaign, and a third list exists that nobody reconciles. The FCC has separately been working toward a requirement that a revocation sent to one part of an organization applies across that organization's messaging, and the effective date for that revoke-all obligation has been extended more than once, most recently into 2027. Waiting for the deadline is the wrong posture. Design the propagation now, because the supporter already expects it to work that way and a plaintiff's attorney will frame it as one organization regardless of your vendor map.

    Build a single authoritative suppression list that every sending system reads before a send, rather than each platform keeping its own. Make writing to that list the only way an opt-out is recorded, so there is no path by which one system knows something the others do not. Instrument it: log every suppression with its source, its timestamp, and the message that triggered it, so you can demonstrate the request was honored and when. And test it on a real cadence by sending a test opt-out through each channel you accept and confirming the suppression appears everywhere within minutes. This is the same discipline that makes a clean, reconciled CRM possible, and the two projects are usually worth doing together.

    A note on the confirmation message. Sending one message confirming that the opt-out was processed is standard practice and generally accepted, provided it does nothing but confirm. Organizations sometimes use that final message to make one more ask, or to offer a reduced frequency option in a way that reads as a retention attempt. Do not. A person who has just revoked consent and receives an appeal in response has received exactly the message the rule exists to prevent, and it is the kind of detail that turns an ordinary complaint into a willfulness argument.

    An opt-out process that actually holds

    Beyond the literal STOP keyword

    • Accept revocation by any reasonable means, including plain-language replies and email or phone requests
    • One authoritative suppression list that every sending system reads before every send
    • Propagation across fundraising, advocacy, and peer-to-peer tools without manual reconciliation
    • A logged record of each suppression with source, timestamp, and triggering message
    • A confirmation message that confirms and nothing else, with no ask and no retention pitch

    10DLC Registration and Carrier Vetting: The Layer That Is Not the Law

    Running a text program in the United States means satisfying two separate authorities that are easy to confuse. The first is the law, which is the TCPA, the FCC rules, and state statutes. The second is the carriers, who decide whether your messages reach handsets at all. Carrier requirements are contractual and industry-driven rather than statutory, they derive largely from the CTIA Messaging Principles and Best Practices, and they are enforced by filtering rather than by lawsuits. Passing one does not satisfy the other, and an organization can be fully registered and still legally exposed, or legally clean and still blocked.

    If you send application-to-person messages from a ten digit local number, you must register through The Campaign Registry, which is the ecosystem carriers use for 10DLC. Registration has two parts. The brand registration establishes the organization: legal name, EIN, address, website, and contact. For a nonprofit this is where your 501(c)(3) status is verified against public records, and where mismatches between your registered legal name and the name on your IRS determination letter cause delays that feel inexplicable until you look at the exact string you submitted. The campaign registration then describes each use case: the message types, sample messages, the opt-in method described in words, and the URLs of your terms of service and privacy policy.

    The opt-in description in that campaign registration deserves more care than most organizations give it, because it is a statement to the carriers about how you collect consent, and it should match what your donation page actually does. Registering a campaign that describes a web form opt-in and then sending to a list built from event sign-in sheets is a misrepresentation to the carrier ecosystem on top of whatever the legal analysis says. Vetting partners cross-reference submitted data against public records, state registries, and IRS databases, and inconsistencies get flagged. Submit what is true, and if what is true is not defensible, fix the collection before you register the campaign.

    Carriers also require certain things in the messages themselves that overlap with, but are not identical to, the legal requirements. Your sender identity should be clear in the message. HELP must return useful information including the organization name and support contact. STOP must work. Registration also determines throughput and filtering tolerance, which is why organizations with an unregistered or poorly registered campaign see mysterious delivery failures during year-end appeals, at the exact moment delivery matters most. Sort the registration out in the quiet months, not in the last week of December when your year-end send schedule is already locked.

    The final point is the one to write into your policy: carrier approval is not a legal defense. A registered campaign that delivers reliably to a list you cannot document is still a list you cannot document. Treat 10DLC as the delivery layer and the TCPA as the permission layer, keep them as separate items in your compliance checklist, and never let the smooth operation of one be taken as evidence about the other.

    Registration essentials for a nonprofit sender

    What carriers verify, and where nonprofits stumble

    • Legal name and EIN matching your IRS records exactly, character for character
    • An opt-in description that truthfully matches how you actually collect numbers
    • Live, reachable terms of service and privacy policy URLs that mention the messaging program
    • Working HELP and STOP handling, with clear sender identification in messages
    • Separate campaigns for genuinely different use cases, registered well before peak season

    State Mini-TCPA Laws, Quiet Hours, and Why Federal Compliance Is Not Enough

    A growing number of states have enacted their own telephone solicitation statutes, commonly called mini-TCPA laws, that reach text messages and impose requirements stricter than federal law. Your obligations are determined by where the recipient is, not where your organization sits, which means a national donor file subjects you to the strictest rule that applies to any segment of it. Federal compliance is the floor. It is not the standard.

    Florida's Telephone Solicitation Act is the one that reshaped the litigation landscape. It creates a private right of action for Florida residents receiving nonconsensual commercial texts, provides for enhanced damages in willful cases, narrows the permitted calling window to 8 a.m. through 8 p.m. in the recipient's local time, and has been read to require that the consent language specifically reference telephonic sales calls rather than merely describing texts generally. Oklahoma's Telephone Solicitation Act follows the Florida model closely and adds an emphasis on being able to produce consent records in a form a court will accept. Washington reaches commercial text messages through its own statutes with its own damages framework and an 8 a.m. to 8 p.m. window. Maryland's Stop the Spam Calls Act, effective in 2024, requires prior express written consent for automated calls and texts and closes the evening window earlier than the federal rule.

    Quiet hours deserve separate attention because they are the easiest rule to break by accident and one of the most actively litigated. The federal restriction bars telemarketing calls and texts before 8 a.m. and after 9 p.m. in the recipient's local time, and several states compress that further. The accident happens because most scheduling tools send by the organization's time zone rather than the recipient's. A 7:30 p.m. Pacific send from a California nonprofit lands at 10:30 p.m. for donors in New York, which is outside the federal window for every one of them. If your file spans time zones, your sending system needs to schedule per recipient, and if it cannot, your send windows need to be narrowed until the earliest and latest recipients are both inside the tightest applicable limit.

    The state layer got more consequential in 2026 rather than less. In July 2026 the Seventh Circuit held in Steidinger v. Blackstone Medical Services that text messages are not telephone calls for the purposes of the TCPA's do-not-call private right of action, closing one avenue for federal text claims in that circuit and creating a split with other courts that have read the statute differently. The practical effect is not that texting became safer. It is that plaintiffs' firms have more reason to bring claims under state statutes, which are unaffected by a federal appellate reading, frequently carry their own damages, and in Florida's case have already generated substantial litigation volume. Tracking the state patchwork is now the higher-value activity, which is the same conclusion nonprofits have reached about state privacy laws more broadly.

    Practically, keep a short internal matrix of the states where you have meaningful donor concentration, with the consent standard, the permitted hours, and any state-specific disclosure language each requires. Store state alongside the phone number in your data model so you can segment by it, which sounds obvious and is frequently impossible in files where the address and the mobile number were collected at different times. Separately, remember that state charitable solicitation registration is a different obligation that also follows the donor's location, and a text asking for money is a solicitation for those purposes too. Our overview of charitable solicitation compliance covers that side of the map.

    What to hold in your state matrix

    The strictest applicable rule governs each recipient

    • The consent standard each state applies, including any required wording
    • Permitted sending hours in the recipient's local time, not your office's
    • Whether a private right of action and enhanced damages exist, and the limitations period
    • Any frequency caps, registration requirements, or record production obligations
    • Whether the state carves out charitable organizations, and how narrowly

    The Nonprofit Exemption, and Why Building a Program On It Is a Bad Idea

    Somewhere in almost every nonprofit there is a person who believes the organization is exempt from the TCPA. That belief has a real basis and a badly overstated scope, and the gap between the two is where avoidable liability lives. What is true is that tax-exempt nonprofit organizations receive favorable treatment in specific places: calls made by or on behalf of a tax-exempt nonprofit for a charitable purpose are generally not subject to the national Do Not Call registry restrictions in the same way commercial telemarketing is, and certain live, manually dialed calls sit outside the rules that govern automated ones.

    What is not true is that nonprofit status removes the consent requirement for automated texts to wireless numbers. The FCC has been clear that there is no blanket exemption of that kind. The restriction on autodialed and prerecorded messages to mobile phones is written around the technology and the recipient's device, not around the tax status of the sender, and a mass messaging platform sending to a supporter list is squarely within it. An organization that texts four thousand people on the theory that charities are exempt has not found a loophole. It has made four thousand decisions it cannot defend.

    Three further conditions narrow the exemption to the point where relying on it is impractical. First, it turns on the purpose being solely charitable, and the dual-purpose message problem discussed earlier reappears here with more force. A message that mixes mission content with anything resembling a commercial offer, a ticketed event with a retail feel, a sponsor acknowledgment, or a merchandise link may fall outside the charitable characterization entirely. Second, the analysis can change when a professional fundraiser or commercial vendor sends on your behalf, because the calling party is not simply your organization anymore. Third, and most decisively, state mini-TCPA laws do not uniformly carve out charities, and a federal exemption is no help at all against a Florida or Maryland claim.

    There is also a strategic argument that has nothing to do with law. Even where an exemption would hold, texting people who never asked to be texted is a poor way to build a supporter relationship. Mobile is the most intimate channel a nonprofit has access to, unsolicited messages there generate irritation out of proportion to their content, and the reputational cost of being the organization that texts people who did not opt in outlasts any short-term revenue it produces. The organizations with the healthiest mobile programs have smaller, fully documented lists that respond better, which is a more durable asset than a large list that cannot be defended and does not engage.

    The right operating posture is therefore simple: collect and document prior express written consent for every number you text with an ask, regardless of what an exemption might permit. Treat the exemption as a narrowing of liability theories if something goes wrong, never as a permission slip in advance. Write that posture into your policy in exactly those terms, so that a new development director two years from now does not rediscover the exemption and reach a different conclusion. This is the same reasoning behind keeping firm guardrails around donor outreach even where the letter of a rule leaves room.

    Why the exemption is thinner than it sounds

    Conditions that undercut it in practice

    • No blanket exemption exists for autodialed calls or texts to wireless numbers
    • The purpose must be solely charitable, which mixed or commercial content defeats
    • A professional fundraiser sending on your behalf changes the analysis
    • State mini-TCPA statutes do not reliably carve out charitable organizations
    • Damages accrue per message, so a single bad list assumption multiplies quickly

    Where AI Helps, and the Line It Must Not Cross

    Everything above is work, and most of it is the kind of structured, repetitive, documentation-heavy work that small development teams never get to. This is where AI earns its place in a compliance program: not by knowing the law, which it does unreliably and with unnerving confidence, but by doing the drafting, the sorting, the cross-checking, and the monitoring that turn a policy into a practice.

    Drafting compliant disclosure language. The opt-in disclosure is a short piece of writing with a fixed list of required elements and a hard constraint that it must read like human language on a phone screen. Give a model the element list from this article, your organization's name, your actual message types and frequency, and your terms and privacy URLs, and ask for three versions at different lengths for the donation form, the event kiosk, and the paper card. What comes back is a genuine first draft with the elements accounted for. It then goes to counsel, because the version that satisfies Florida's specific wording expectations is not something you want a model to have guessed at.

    Auditing your list for records of consent. This is the highest-value application and the one almost nobody runs. Define your consent record schema, export your subscriber list with whatever consent fields exist, and have a model classify each record against the schema: complete, incomplete and repairable, or undocumented. What emerges is a map of where your list came from and where the evidence is missing, usually grouped by source in a way that immediately identifies the two or three intake paths responsible for most of the gaps. The model is doing data classification against your rules, not making a legal call about any individual number, and that distinction is what keeps the use safe.

    Classifying inbound replies for opt-out intent. Recall that revocation can be expressed in ordinary language, and that platform keyword matching catches only the literal keywords. A classifier reading inbound messages and flagging anything that plausibly expresses opt-out intent, including misspellings, mixed-language replies, and phrasings like "wrong number" or "this is my kid's phone," closes the largest practical gap in most programs. Configure it to be aggressively over-inclusive. A false positive costs you one subscriber who can opt back in. A false negative is a violation per subsequent message, and the asymmetry is not close.

    Reviewing message drafts against your own policy. Before a send, a model can check a draft against your written rules: is this template tagged marketing or informational, does the tagging match the content, does the segment have the matching consent standard on file, does the message identify the sender, is the send window inside the tightest applicable state limit for this segment, and does it contain anything that would defeat a charitable-purpose characterization. This is a checklist run consistently rather than a judgment, which is precisely what automation is for. Logging each check also builds the kind of audit trail that demonstrates a program operating as designed.

    Monitoring for change, and preparing the human conversation. A model can summarize developments in a narrow area you define, produce a monthly brief on TCPA and state telemarketing developments affecting your states, and turn that into a list of questions for counsel. Treat the output as a research brief and a question list, never as a compliance determination. Used that way it converts a week of reading into an afternoon of verification, and it means your annual legal review starts from a current picture rather than a two year old memory.

    And now the line, which is not negotiable. AI must not decide whether a given number may legally be texted. That decision rests on evidence in your records and on law that applies to your facts, and a model asked to adjudicate it will produce a confident answer with no basis, which is worse than no answer because it will be relied on. AI must not generate, infer, backfill, or reconstruct a consent record. A consent record documents something a human being actually did at a specific moment, and a synthesized record is not weak evidence, it is fabricated evidence, and producing it in a dispute is a far more serious problem than the original gap. And AI must not be the source of a legal conclusion your program depends on. Models get regulatory detail wrong routinely, this area has changed three times in two years, and the confident tone with which an incorrect answer arrives is exactly what makes it dangerous.

    The rule to write into your policy is short. AI prepares, drafts, classifies, flags, and monitors. A named person reviews the flags, owns the list, and answers the question of whether a number may be texted. Counsel reviews the disclosure language, the policy, and the program annually. Nobody, at any point, lets a model fill in a consent record. Organizations already thinking carefully about informed consent in their programs will recognize the underlying principle: consent is a thing a person gives, and no system can give it on their behalf.

    Hand to AI

    Drafting, classification, and monitoring

    • Draft opt-in disclosure language in several lengths for counsel to review
    • Audit the subscriber list against your consent schema and group gaps by source
    • Classify inbound replies for opt-out intent, tuned to be over-inclusive
    • Check outbound drafts against your written policy before every send
    • Produce a monthly change brief and a question list for your annual legal review

    Never delegate

    Decisions and records that require a person

    • Deciding whether a particular number may legally be texted
    • Generating, inferring, or backfilling a consent record that no person created
    • Asserting a legal conclusion your program then relies on without counsel
    • Overriding or clearing a flagged opt-out without a named human reviewing it
    • Approving the final disclosure wording that goes live on your forms

    A Realistic Path From Where You Probably Are

    Most organizations reading this are running a text program with partial documentation, a list assembled over several years from several sources, and an opt-out process that works for the literal keyword and nothing else. The distance from that to a defensible program is a few weeks of focused work, and the sequence matters because the first step tells you how much of the rest you need.

    Start with the inventory. List every path by which a phone number has ever entered your file, and for each one write down what the person saw and what they did. Donation form, event registration, keyword campaign, paper pledge card, petition, volunteer application, appended by a vendor, imported from a merged organization. Then run the AI-assisted list audit described above and classify every record against your schema. Organizations that do this honestly usually find that a majority of their textable list traces to two or three intake paths, one of which turns out to be undocumented, and knowing that turns an overwhelming problem into a specific one.

    Then fix the intake before you fix the history, because a leaking pipe keeps leaking while you mop. Rewrite the disclosure, version it, make the checkbox unchecked and separable, and make sure the system captures the full consent record including the disclosure snapshot. Confirm the 10DLC campaign registration describes the new reality. Only then decide what to do about the historic records that cannot be documented, which is a conversation with counsel about risk tolerance rather than a decision a fundraiser should make alone. The common landing place is a re-permission campaign through a channel you can defend, accepting that the list will get smaller and the engagement rate will go up.

    Finish by operationalizing. Build the single suppression list and wire every sending system to it. Put the reply classifier in front of the inbound queue. Add the pre-send policy check. Store state alongside the number and set sending windows per recipient time zone. Name an owner for the program and put an annual review on the calendar with counsel, covering the disclosure language, the state matrix, and a sample of consent records pulled at random to confirm they contain what they should. That last audit is uncomfortable and is the most useful of the three, for the same reason a random file review is more informative than a policy document: it tells you what is actually happening.

    The sequence, in order

    Inventory, then intake, then history, then operations

    • Inventory every intake path and audit the list against your consent schema
    • Rewrite, version, and deploy the disclosure, and capture the full record going forward
    • Bring counsel in on the undocumented history and decide on a re-permission approach
    • Build the single suppression list, the reply classifier, and the pre-send check
    • Name an owner, set the annual review, and sample real consent records each year

    Conclusion

    Text message fundraising works, and the sector's own benchmark data shows organizations leaning into it hard. The channel's advantage is also its hazard: a message on a phone is immediate and personal, which is why it converts and why the law treats it more carefully than email. The organizations that will still be running healthy mobile programs in five years are the ones treating consent as infrastructure rather than as a checkbox, with records they can produce, opt-outs that propagate, and disclosure language they wrote on purpose.

    The practical shape of that infrastructure is clear enough by now. Classify your message types and enforce the classification at the template level. Collect prior express written consent with a disclosure that names you, mentions automated technology, says consent is not a condition of anything, and describes frequency. Store the record with a timestamp, a source, a snapshot of the exact language shown, and the technical evidence that surrounds it. Honor revocation expressed any reasonable way, immediately, across every system you send from. Register your 10DLC campaign truthfully and remember it is not a legal defense. Track the states where your donors actually live, and send inside the tightest window that applies to any of them.

    Two things are worth holding onto about the law itself. It changes, as the one-to-one consent rule's short life demonstrated, so build for the standard you can defend under any plausible reading rather than the most permissive one currently available. And the nonprofit exemption is real but narrow, it does not cover automated texts to mobile phones, and it offers nothing at all against the state statutes where an increasing share of the litigation now lives. None of this is legal advice, and a program of any size should have counsel review the disclosure language, the policy, and the state map at least once a year.

    AI genuinely changes what a small team can accomplish here. It drafts the disclosure, audits the list and shows you which intake path is the problem, catches the opt-out phrased as a sentence instead of a keyword, checks every draft against your own rules before it sends, and keeps you current on a legal landscape that moves faster than any development director can track. That is real capacity, and it is the difference between a compliance program you intend to build and one you have. What it cannot do is give consent on a supporter's behalf, decide whether a number is safe to text, or tell you what the law is. Those stay with people, with records made at the moment a human being said yes, and with a lawyer who has read your actual forms.

    Can You Produce the Consent Record for Every Number You Text?

    We help nonprofits audit their SMS lists, design consent records that hold up, and put AI to work on the drafting, classification, and monitoring, so your counsel reviews a real program instead of a blank page.