Quick note before we start. This is a plain-English explainer, not legal advice. The CTIA guidelines are voluntary and they change over time, and carriers add their own enforcement rules on top. Have a lawyer review your flows before you launch. Below is the practical version: what the guidelines ask of you, translated into decisions you make when building an SMS chatbot.

What the CTIA guidelines are, and why a chatbot builder should care
CTIA is the trade association for the US wireless industry. Its Messaging Principles and Best Practices are the industry’s shared rulebook for business texting. They are not a law like the TCPA, and CTIA itself does not hand out fines. But carriers enforce these principles, and if your chatbot breaks them, your messages can get filtered or blocked. The version at the time of writing is the May 2023 final document, and CTIA states plainly that its guidelines are voluntary best practices, not legal obligations.
Consent: the foundation everything else stands on
The core rule is simple. Non-Consumers are expected to obtain a consumer’s consent before sending messages, and marketing messages specifically call for express written consent. Consumers must be able to revoke that consent.
Your chatbot should never message a phone number just because you have it. A number from a CRM, a form that did not mention SMS, or a bought list does not count. The guidelines are explicit: do not use opt-in lists that have been rented, sold, or shared. Build your own list and vet it yourself.
The guidelines recognize different consent tiers that matter for chatbots. If the user texts first and your bot just answers, that is conversational and consent is implied. If the user asked to be contacted about something specific, like appointment reminders, that is informational and needs express consent for that purpose. The moment the message contains a sales promotion, it is promotional and needs express written consent with full disclosures. A support bot that ends a conversation with “and check out our sale this weekend” just crossed tiers. Keep each message inside the tier it was collected under.
How consent maps to chatbot flows
The guidelines recognize several opt-in mechanisms, and chatbots typically use one of them:
- A phone number entered through a website form or a button tapped on a mobile page. Your “text me updates” button counts, but only if the consent language next to it is clear.
- A keyword texted from the user’s own phone, like “Text PIZZA to 12345.”
- A consumer-initiated conversation, where the user texts first and the bot replies with responsive information.
- Sign-ups at a point of sale or over the phone with IVR.
Each opt-in has to pair with a clear call-to-action covering five things: what the program is, which number or short code messages will come from, the specific identity of the organization behind the first message, clear language about opting in and any fees, and the other terms (how to opt out, care contact info, the privacy policy). Opt-in details should not be buried in fine print, and nothing should be deceptive.
Document every opt-in
The guidelines recommend keeping consent records with specifics: the timestamp, the medium (web form, keyword, POS sign-up), the experience the user saw, the campaign it applied to, the phone number, and the identity of the person who consented. For a chatbot builder, this is a database design decision. Store it the moment the user opts in. If you ever need to prove consent, “trust me, they clicked the button” will not carry the day.
The opt-in confirmation message
If your chatbot sends recurring messages, the guidelines say to send an opt-in confirmation message before any other messaging goes out. It must include:
- The program name or product description
- Customer care contact information (a toll-free number, a 10-digit number, or HELP instructions)
- How to opt out
- A statement that messages are recurring and how frequent they are
- Clear language about any fees or charges and how they are billed
A classic example: “Welcome to Joe’s Pizza Deals. Get up to 4 msgs/mo with coupons and new menu items. Reply HELP for help, STOP to cancel. Msg and data rates may apply.” It sets every expectation up front.
Consent is also campaign-specific. An opt-in for one campaign is not transferable to another, and it does not carry over to a different brand. If your chatbot runs separate programs, like order updates and marketing promos, treat them as separate consents. And “message and data rates may apply” is one of those disclosure phrases carriers look for at opt-in, so include it.
Identification: say who you are in every message
The guidelines require the specific identity of the organization behind the initial message to be represented clearly. The recipient sees a phone number on their screen, not your logo. A message that opens with “Hi, this is Bright Dental with your appointment reminder” satisfies this instantly. A message that opens with “Your appointment is tomorrow at 2” and never names the sender does not.
This also applies to links. Embedded links should not conceal who is sending the message. If you use a URL shortener, use one dedicated to your exclusive use, and any site it leads to should unambiguously identify its owner. For chatbots, the practical takeaway is to use your own branded short domain instead of a public shortener, a classic spam signal that gets filtered.
Opt-out handling: where chatbots earn or lose trust
The guidelines say message senders should let consumers opt out at any time, support multiple opt-out mechanisms (phone call, email, or text), and send exactly one final confirmation message per campaign acknowledging the opt-out, then send nothing further.
The keyword rules deserve attention. Use standardized STOP wording in your opt-out instructions, but your bot must also honor plain-language variants: end, unsubscribe, cancel, quit, and phrases like “please opt me out.” Capitalization, punctuation, and letter case do not invalidate a request. “STOP.” with a period still counts. And wire up HELP to return real support contact information from day one, not as an afterthought.
For a chatbot builder, this translates into concrete engineering requirements. Your natural language handling should catch every reasonable phrasing of “I want out,” not just the exact keyword. The moment an opt-out is recognized, the bot must stop that campaign’s messaging immediately, log it, and send the single confirmation. No “are you sure?” flows, no re-engagement attempts, no quiet follow-ups.
Content rules: what your chatbot is allowed to say
The guidelines require senders to take reasonable steps to prevent unlawful, deceptive, or abusive content. The prohibited list in ยง5.3.1 covers content that is unlawful, harmful, abusive, malicious, misleading, harassing, excessively violent, obscene, illicit, or defamatory, plus phishing, privacy invasions, safety threats, intimidation, and malware. Marketing content also has to comply with the FTC’s truth-in-advertising rules.
For chatbot builders, the deceptive-content rule has teeth in a specific way. Your bot should never mislead about who is sending or imply things the brand cannot deliver. A bot that says “I’m Sarah from Bright Dental” when there is no Sarah is the kind of identity deception the guidelines are aimed at.
The SHAFT rules
On top of the primary guidelines, carriers enforce content restrictions around the categories known by the industry shorthand SHAFT:
- Sex and adult content and hate speech are effectively prohibited.
- Firearms content is treated as prohibited on carrier networks regardless of age gating.
- Tobacco (including vaping products) is prohibited or heavily restricted.
- Alcohol can be allowed, but only with robust age verification at opt-in and explicit carrier approval.
Cannabis and CBD messaging is prohibited on US carrier networks even where state law allows it, and gambling, sweepstakes, and high-risk financial offers face their own extra restrictions. Enforcement looks at both the message text and the underlying business type. A chatbot for a vape shop can have perfectly compliant opt-out handling and still get blocked because of what the business sells. If your bot touches any SHAFT-adjacent category, confirm with your messaging provider before launch.
Sending behavior: the patterns that look like spam
A few more guidelines affect how your chatbot behaves at scale. Do not spread similar messages across many sending numbers to dodge volume limits (snowshoeing). Do not send through unauthorized paths (grey routes). Do not spoof an originating number that is not assigned to you.
Respect quiet hours. The CTIA handbook itself does not set specific hours, but TCPA rules and carrier practice point to 8 AM to 9 PM in the recipient’s local time zone, with some states differing. See our quiet hours by state guide and run your send windows through the quiet hours checker before scheduling bot broadcasts.
For chatbots specifically, the conversational pattern is your friend. A bot that replies to user-initiated messages looks like ordinary conversation. A bot that blasts one-way promotions from a 10-digit number looks like bulk traffic and gets judged by the stricter rules.
Putting it together: a launch checklist for your bot
Before your SMS chatbot goes live, confirm these:
- Every opt-in path shows clear consent language with program description, frequency, fees, opt-out instructions, and a privacy policy link.
- Opt-ins are logged with timestamp, medium, wording shown, and the campaign they apply to.
- A confirmation message goes out before any other recurring messaging.
- The first message names the brand.
- STOP and its plain-language variants are understood and honored, with one confirmation message and then silence.
- HELP returns real contact information.
- Links use your own domain, not a public shortener.
- Content avoids deceptive claims and stays clear of SHAFT-restricted categories.
- Messages stay within the consent tier they were collected under.
- Quiet hours are respected in the recipient’s time zone.
Want this set up for you?
I build SMS chatbots and API integrations for businesses. If you would like what this guide describes, done for you, get in touch.
Frequently asked questions
Are CTIA guidelines legally required?
No. They are voluntary industry best practices. But carriers enforce them alongside laws like the TCPA, and violating them can get your messages filtered or your account suspended.
Do the CTIA guidelines apply to AI chatbots specifically?
The guidelines do not mention AI chatbots by name, but they apply to any Non-Consumer messaging, which includes messages sent by a business or its agents. An automated bot texting on behalf of a brand is a Non-Consumer sender, so the consent, identification, opt-out, and content rules all apply.
What opt-out keywords must an SMS chatbot support?
The guidelines call for standardized STOP wording, but your bot must also honor plain-language variants: end, unsubscribe, cancel, quit, and phrases like “please opt me out.” Minor differences in capitalization or punctuation do not invalidate a request.
Does my chatbot need to identify itself as a bot?
The guidelines require the initial message to name the organization behind it. That is the hard requirement. Being transparent that the sender is automated is the safer reading, and it avoids the deceptive-content rules around misrepresenting who is sending.
What happens if my chatbot’s messages get flagged?
Carriers can filter or block traffic that looks like unwanted messaging, often with no detailed explanation. Prevention is the whole strategy: clean consent, clear identification, working opt-outs, honest content, and registered campaigns.
Conclusion
The CTIA guidelines look intimidating in full, but for a chatbot builder they reduce to a short list. Get clear consent and keep proof. Say who you are. Send the confirmation message. Honor every opt-out quickly and completely. Keep your content honest and clear of restricted categories. Build these into the flow itself, and the guidelines become a design pattern rather than a risk.
This article is for general information only and is not legal advice. CTIA updates its guidance over time, and carriers enforce their own policies on top of it. Review the current CTIA guidance and consult qualified counsel before launching a chatbot that texts consumers.
