India’s Telecom Regulatory Authority (TRAI) has significantly broadened its anti-spam framework, enacting new regulations that compel caller-identification and call-management applications to share user-reported spam data with telecom operators. This move, aimed at bolstering the nation’s fight against unsolicited commercial communications, has ignited controversy, with leading spam-blocking app maker Truecaller vehemently protesting the mandate, labeling it as "anti-competitive" and a "one-way exchange" of valuable user data.
The pivotal amendment, officially notified on Friday, mandates that any application facilitating caller identification and call management, particularly those allowing users to flag calls as spam or junk, must now transmit these reports to a blockchain-based platform. This platform is meticulously maintained by telecom operators and serves as the central nervous system for tracking commercial communications and enforcing anti-spam directives across the country. TRAI’s rationale behind this crucial adjustment is to vastly expand the collective intelligence pool of spam reports, thereby enabling more robust and targeted enforcement actions against persistent spammers. By integrating the granular data gathered by third-party apps with the telecom industry’s existing enforcement infrastructure, India seeks to create a more formidable and unified front against unsolicited calls.
However, the implications of this directive are far-reaching and have been met with significant apprehension from the very entities TRAI seeks to leverage. Truecaller, a dominant player in India’s burgeoning digital communication landscape, has voiced strong objections. The Stockholm-based company, whose Indian user base exceeds a staggering 350 million out of its global tally of over 500 million monthly active users, argues that the new rules create an uneven playing field. They contend that forcing apps to share their meticulously collected user-generated spam data with telecom operators, who are their direct competitors in offering communication services, constitutes an anti-competitive practice. This, Truecaller asserts, effectively transfers commercially sensitive and proprietary data – the very foundation of their service’s efficacy – to entities that could potentially leverage it for their own commercial gain, without offering reciprocal data sharing or compensation.
India’s decision to intensify its anti-spam measures is underscored by the sheer scale of the problem it confronts. The nation has been battling an overwhelming surge of spam and fraudulent calls, posing a significant nuisance and threat to its digitally connected population. A comprehensive report released by Truecaller in February painted a stark picture, revealing that its users in India encountered approximately 42 billion spam calls in 2025 alone. This staggering figure encompasses calls that were ultimately blocked, identified as spam, or simply ignored by users. The company further highlighted its own efficacy by stating that it successfully blocked nearly 12 billion such calls within the same year, underscoring the magnitude of the challenge.
This is not the first instance of friction between Truecaller and the Indian regulatory body regarding the handling of unsolicited communications. In the past, the Swedish company had openly objected to previous TRAI restrictions that prevented call-management apps from automatically flagging calls originating from certain government-designated number ranges as spam. Truecaller’s concern was that such exemptions could inadvertently create loopholes, allowing unwanted promotional and fraudulent calls to bypass their sophisticated filtering mechanisms. While the recent amendments do retain this restriction, barring call-management apps from indiscriminately blocking, filtering, or spam-tagging calls from designated number series used for promotional, service, and transactional communications, the regulator has clarified that individual users retain the autonomy to manually block such calls on their personal devices. A spokesperson for Truecaller acknowledged this continued restriction, stating, "While our data and user sentiment clearly show that spam has skyrocketed due to this free pass to spammers, we have been compliant with this since late last year."
The new directive effectively bridges two distinct layers of the telecommunication ecosystem. Sumeysh Srivastava, a partner at The Quantum Hub, a New Delhi-based consulting firm specializing in telecom regulation policy, explained that telecom operators provide the fundamental network infrastructure and manage the blockchain-based anti-spam system. Conversely, caller-identification apps operate on top of this network, utilizing their own proprietary algorithms and user-generated data to identify and filter unwanted calls. This integration, however, raises a complex web of technical and jurisdictional questions. Srivastava highlighted critical points of contention, including the precise reporting standards that these third-party applications will be required to adhere to, and more importantly, how the mandate will be effectively enforced against companies that are not licensed telecom operators themselves.
A draft proposal released in March had indicated the potential use of India’s Information Technology (IT) Act to enforce these requirements. However, Srivastava noted with concern that the final announcement did not explicitly confirm whether this enforcement mechanism has been retained in the finalized rules, leaving a degree of uncertainty regarding the legal teeth behind the new regulations. Furthermore, the exact scope of information that these applications will be compelled to share remains ambiguous. Kazim Rizvi, the founding director of The Dialogue, a New Delhi-based policy think tank, elaborated on this crucial distinction. He pointed out that mandating an app to transmit a specific spam report generated by an individual user is fundamentally different from requiring the sharing of broader datasets, proprietary reputation signals, or the sophisticated analytical systems these apps employ to detect suspicious calls. Rizvi emphasized the urgent need for greater clarity on the precise nature of the information to be transmitted, the procedures for obtaining user notification and consent, and the subsequent protocols for data retention and utilization.
When approached by TechCrunch for clarification, TRAI did not provide specific details regarding the exact nature of the information apps would be required to share. Crucially, they also did not address whether these new rules would extend to the built-in spam-reporting functionalities present in major smartphone operating systems, such as Android and iOS, leaving a significant gap in the regulatory landscape.
Beyond the realm of user-reported spam, the recent amendments also introduce significant changes pertaining to the rapidly evolving landscape of AI-powered calls. Recognizing the growing prevalence of automated systems and AI voice agents in making outbound communications, TRAI has officially classified all calls initiated automatically, without direct human dialing, as falling under the purview of its Application-to-Person (A2P) framework. This broad definition encompasses not only traditional robocalls but also calls utilizing prerecorded messages or artificially generated voices.
Companies employing such automated calling systems will now be mandated to preemptively declare their usage and the specific phone numbers involved to their respective telecom operators. Failure to comply with this disclosure requirement will result in undeclared A2P calls being automatically classified as spam, subject to appropriate penalties. Srivastava clarified that the determining factor for classification under the A2P framework is the method of call initiation, rather than solely the presence of an AI-generated voice. This distinction introduces a degree of ambiguity for AI-assisted calls where human involvement is still present in the initiation process.
Satya N. Gupta, a former additional secretary at TRAI, offered reassurance that the new rules are not intended to stifle innovation in the use of AI or other automated calling technologies. Instead, the primary objective is to ensure transparency and accountability by requiring businesses to disclose their utilization of these tools to telecom operators. In a related development, telecom operators will now be empowered to levy a termination charge of up to five paise (approximately 0.052 cents) per minute on A2P calls. However, an exemption from this charge will be granted for calls originating from certain designated number ranges, likely those used for essential services or public announcements. Rizvi raised a pertinent concern regarding the broad interpretation of the A2P definition, suggesting that it could potentially encompass calls initiated through software even when human agents are involved, such as those originating from contact centers or click-to-call services. He cautioned that without a clearer distinction, the A2P category risks becoming overly expansive, potentially extending beyond the specific regulatory harms it is designed to address.

