~/krishnamallam/opinions/eu-checks-the-number.md
./home./opinionsonline · rome
krishna@medialogic:~$ cat eu-checks-the-number.md
29 Aug 2026·8 min read·
#india#eu#regulation#voice-ai

The EU checks the number. India registers the caller.

Four EU regulators now drop calls wearing a number they are not entitled to. Italy alone rejects 7.5 million a day, and in one window 56% of mobile-origin traffic was fake. India took the opposite route and registers every sender. For anyone building voice agents across both, the rules run opposite to what most teams assume.

I run engineering in Rome and in Hyderabad, so I get to watch two regulatory systems attack the same problem with opposite instruments. Unwanted phone calls are a plague in both places.

The comparison matters commercially. If you are building voice agents for both markets you are probably assuming India is the permissive one and the EU is the strict one. On consent that is true. On enforcement mechanism it is the other way round, and on AI disclosure the gap is now enormous.

India registers the caller

Register the principal entity, the telemarketer, the headers and the content templates on the DLT platform. Use the 140 series for promotional calls and the 1600 series for transactional ones. Scrub against DND. Break the rules and your telecom resources get suspended, then blacklisted: over 800 entities blacklisted and more than 1.8 million numbers disconnected.

It is a coherent system with a structural weakness. The grey channel does not spoof anything. It dials from ordinary ten-digit SIMs bought like anyone else's, which is exactly why SIM-based dialers advertise around 2.3 times the connect rate of compliant telephony. At the network layer those calls look like your cousin ringing you, because technically that is what they are. So every enforcement action needs a company or a person identified, acted against, and identified again next week when the operation reappears with new SIMs.

The EU checks the number

EU regulators went after the number itself. Four of them have now built variations of the same control:

WhereMechanismLive since
Spain, CNMCInternational calls presenting Spanish numbers blocked; SMS on invalidly assigned Spanish numbering blocked7 Mar 2025
Italy, AGCOMOperators block calls from abroad presenting Italian caller IDs they are not entitled to use19 Aug 2025 fixed, 19 Nov 2025 mobile
France, ARCEPMAN, a STIR/SHAKEN-based authentication scheme; unauthenticated French mobile numbers from abroad are masked1 Jan 2026 for mobile
Ireland, ComRegFixed and mobile CLI blocking on the same designrolling out

The design is identical: if a call arrives from outside the country wearing a domestic number it is not entitled to, drop it. No investigation, no entity to find, no blacklist to maintain. Worth knowing that each of these is a national decision rather than a single EU instrument, so there is no one rule to look up for caller ID.

The volumes are the argument. Italy blocked over 43 million calls in the first month, then around 7.5 million a day once mobile came into scope. In the eleven days after 19 November the filter stopped 49.3 million calls, which AGCOM put at roughly 56 percent of all traffic from mobile networks presenting Italian numbers.

Read that again. More than half of that traffic was fraudulent, and it disappeared the moment somebody checked whether the caller ID was real. France is furthest along conceptually: rather than filtering foreign-origin fakes it authenticates calls cryptographically, and by the end of 2025 more than 80 percent of roaming calls from French subscribers carried authentication.

Be fair about the registries

The EU has not abandoned registration. Spain's CNMC opens an SMS alias registry requiring every business to register its sender ID from 7 June 2026, which is essentially India's DLT header scheme. Bloctel in France, the Registro delle Opposizioni in Italy and the Robinson lists in Spain and Germany are opt-out registers serving the same purpose as DND.

So the difference is not registry versus filter. It is that these countries put an authentication layer for voice underneath the registry layer, and India has not. India's rules assume the number in the CLI field means something because the sender was registered. The EU stopped assuming and started checking.

The mechanism lesson is the part I would take to any regulator: anything requiring attribution scales with the enforcer's budget, and anything that filters scales with traffic. India's will is not in doubt, this is a regulator that disconnected 1.8 million numbers, but its mechanism needs a name attached to every action and filtering needs none.

There is a second-order effect that is underrated. In India, compliance costs you the connect rate, because the compliant number is visibly a telemarketing number and the grey channel's is not. In these EU markets, enforcement raised the value of the compliant channel: when half the junk stops arriving, people answer the phone again, and the business that stayed inside the rules is the one that benefits. Enforcement that improves the economics of compliance rather than taxing them is rare, and worth copying.

What the labelling layer does to a voice agent

India is not doing nothing about the calls the registry cannot catch. It labels them. Airtel built network-level AI spam detection in-house and now identifies something like 100 million suspected spam calls a day, has alerted around 252 million customers, and reported a roughly 12 percent drop in people answering flagged calls within two and a half months of launch. Truecaller labels most of what still arrives.

That is real engineering doing real work, and it is not the same thing as blocking. The call still rings. The systems are voluntary. And the verdict attaches to a number.

Which is where it stops being an abstraction for anyone deploying agents.

An agent does not dial from a SIM. It dials from a DID rented from a cloud telephony provider, over SIP: Exotel, Ozonetel, MyOperator and the rest, in four flavours, ten-digit mobile, landline, 140 promotional and 1600 transactional. That number takes minutes to provision.

So when a few hundred recipients mark your collections agent on Truecaller, the number is finished. Your EMI reminders stop being answered, including the entirely legitimate ones, and the cheapest fix is to rotate to another DID from the pool. Minutes on an API. "Indian numbers that won't get spam-tagged" now shows up as a selection criterion in telephony-stack buying guides, which tells you how normal the churn has become.

Look at what that means structurally. The registry regime assumes a stable registered identity. The labelling layer that compensates for the registry's blind spot makes stable identity expensive to keep, and disposable identity cheap to obtain. India built one system that rewards keeping your number and another that punishes it.

Labelling punishes the number. Authentication protects it.

That distinction decides your unit economics, because answer rate is the whole business case for a voice agent. In India your caller ID is a consumable. In the EU, where the fraudulent traffic is dropped before it rings and a national number has to be genuinely yours, it is an asset that accrues value.

Two things worth auditing on any Indian deployment, incidentally. Which series the agent actually dials from, because promotional calls placed on a ten-digit virtual number are not compliant however normal it has become. And whether anyone is tracking flag rate per number as an operational metric, because at the moment it is usually discovered as a mysterious collapse in connect rate.

On AI, the two have swapped positions

IndiaEU
AI must announce itself on a callDraft. TRAI's Third Amendment, consulted 13 Mar 2026, not notifiedIn force. AI Act Article 50, applicable 2 Aug 2026
PenaltyGraded, largely landing on the operatorsUp to €15M or 3% of worldwide turnover
Synthetic voiceLabelled with provenance, IT Rules, since 20 Feb 2026Disclosure of artificially generated audio under Article 50
Criminal exposureNone specific to AI voiceItaly, Law 132/2025: 1 to 5 years for AI-altered voice that misleads and causes unjust harm
Consent to dialService and transactional calls sit outside DNDePrivacy Article 13: automated calling systems need prior consent

That last row catches Indian teams. In India a delivery confirmation or an EMI reminder sits outside DND because it is transactional or service traffic. In the EU, a system that dials autonomously is an automated calling system, and for direct marketing that means prior opt-in. Member states transposed ePrivacy differently, some allow a business-to-business exemption, Germany is stricter than most, and there is no pan-EU equivalent of India's transactional carve-out.

The rule of thumb is therefore the opposite of what most teams assume: build to the EU specification and degrade for India, never the reverse. Consent before the dial, disclosure at hello, provenance on synthesised audio, retention and erasure that actually run, and per-call evidence of all of it. Each is either already required in the EU or draft in India, which makes the EU configuration a strict superset for the AI layer. A stack built for India needs new plumbing to enter the EU. A stack built for the EU needs a config change to enter India.

What happens next

India's draft Third Amendment puts mandatory AI and machine-learning detection at the access-provider layer, doing pattern analysis on call volumes, durations and answer rates. Strip the vocabulary away and that is India moving from caller enforcement toward network enforcement, reaching the EU insight by a different route, because pattern detection does not require identifying anyone either. It only requires the traffic to look wrong.

Which brings it back to agents. A human on an unregistered SIM produces traffic that looks human, because it is. An agent produces thousands of conversations with machine-regular pacing and duration curves. Whichever layer a regulator picks, cryptographic authentication or statistical detection, agent-scale calling is the easiest thing on a network to see.

If the plan depends on not being seen, it is on the wrong side of both systems at once.


Sources: AGCOM figures via Il Sole 24 Ore and LaPresse; MEF on the AGCOM regulation; ARCEP on numbering and MAN; ComReg on CLI call blocking; Bird & Bird on the Spanish anti-fraud regulation; Norton Rose Fulbright on Italy's Law 132/2025; ePrivacy Directive Article 13; AI Act Article 50, applicable 2 August 2026; Airtel's network AI spam detection and who decides a call is spam; telephony stacks for Indian voice agents via Awaaz. Indian enforcement figures as cited in my earlier piece.

krishna@medialogic:~$ cd ../ · all opinions →