TRAI mandates AI for spam detection in India
India's telecom regulator TRAI has updated regulations requiring telecom operators to use AI and machine learning to identify and investigate suspected spammers.
The Telecom Regulatory Authority of India (TRAI) has amended its regulations, mandating telecom operators to employ Artificial Intelligence (AI) and Machine Learning (ML) systems for the identification and investigation of suspected spammers. The updated Telecom Commercial Communications Customer Preference Regulations (TCCCPR) framework links AI-based spam detection with enforcement against unsolicited commercial communications (UCC). Previously, these systems were largely used to warn recipients about potential spam.
The amended rules require operators to share information on suspected spammers, conduct Know Your Customer (KYC) checks, and investigate potential violations. AI/ML systems will analyze calling and messaging behavior to identify numbers with a high probability of sending UCC. These numbers are to be classified as "Suspected high probability UCC CLI" based on behavioral parameters. Operators can continue using existing algorithms for customer warnings but can only share high-probability numbers for investigation and enforcement.
Upon identification, operators must immediately share information about suspected spammers with the concerned Originating Access Provider (OAP) via the Distributed Ledger Technology (DLT) platform, no later than two hours after identification. The OAP must then notify the sender via SMS or email, explaining that the number was flagged based on its communication behavior. The OAP is required to identify the sender's unique KYC identifiers within one business day and share them with other operators.
If five or more numbers belonging to the same sender are identified as high-probability UCC numbers within a ten-day period, operators must initiate further action. This can include re-verification of KYC, physical verification, investigation into misuse of telecom resources, and potentially blocking services or devices. TRAI clarifies that AI-generated intelligence alone is insufficient evidence for regulatory action and will trigger an investigation.
The updates also allow for action to be initiated with a lower threshold of complaints when corroborated by AI detection. Previously, five complaints from unique recipients within ten days were required; the new policy allows action with three complaints if the number was identified as a "Suspected high probability UCC CLI." This aims to expedite measures against spam and reduce consumer harassment.