India's telecom regulator ordered caller-ID and call-management apps to share user-generated spam reports with telecom operators on Friday, a move that forces companies like Truecaller to hand over data they've spent years accumulating. The Telecom Regulatory Authority of India (TRAI) amended its commercial communications rules to require these apps to feed spam flags into a blockchain-based platform that telecom operators maintain and control.
What TRAI Actually Changed
The amended rules apply to any app that lets users flag calls as spam or junk. Those reports must now be transmitted to the telecom industry's blockchain platform, which tracks commercial communications and enforces anti-spam rules across the network. TRAI said the change is meant to broaden the pool of spam reports available for enforcement action against spammers, connecting data collected by apps with the telecom infrastructure that can actually act on it.
The rules also restrict apps from blanket blocking, filtering, or spam-tagging calls from designated number series used for promotional, service, and transactional communications. Individual users can still block these numbers on their own devices, but the apps themselves cannot apply bulk filters to government-designated ranges.
This is not the first time Truecaller and TRAI have clashed over this issue. The Swedish company previously objected to restrictions preventing call-management apps from automatically labeling calls from certain government number ranges as spam, arguing the exemption let unwanted calls slip through. TRAI kept the restriction in the final rules.
Truecaller Calls It Anti-Competitive
Truecaller sees the requirement as a "one-way exchange" that transfers commercially valuable data from apps to telecom operators. The company's position is straightforward: it spent years building a user base that generates the spam reports, and now the regulator is forcing it to share that data with the very operators who benefit from better spam filtering without having to build it themselves.
India is Truecaller's largest market by a wide margin. The Stockholm-based company has more than 500 million monthly active users globally, and well over 350 million of them are in India. In 2025, Truecaller said its Indian users encountered approximately 42 billion spam calls, including calls that were blocked, labeled, or ignored. The company blocked nearly 12 billion of those calls.
"While our data and user sentiment clearly show that spam has skyrocketed due to this free pass to spammers, we have been compliant with this since late last year," a Truecaller spokesperson said about the designated number range restrictions.
The Enforcement Questions Are Unanswered
Several policy experts flagged gaps in the new rules. Sumeysh Srivastava, a partner at The Quantum Hub in New Delhi who leads telecom regulation policy work, pointed out that the amendment bridges two distinct layers: telecom operators provide the underlying network and run the blockchain platform, while caller-ID apps operate on top of that network to identify and filter calls.
That raises technical and jurisdictional questions. What reporting standards will apps have to follow? How will the requirement be enforced against companies that are not themselves telecom operators? A March draft proposed using India's IT laws for enforcement, but the final announcement did not say whether that mechanism survived.
Kazim Rizvi, founding director of policy think tank The Dialogue, highlighted another ambiguity. Requiring an app to transmit a specific spam report made by a user is materially different from requiring it to share broader datasets, reputation signals, or the analytical systems it uses to identify suspicious calls. The rules need clarity on what information must be transmitted, how users are notified or asked for consent, and how that data can subsequently be retained and used.
TRAI did not respond to questions about what information apps would have to share or whether the rule would apply to spam-reporting features built into Android and iOS.
AI-Powered Calls Now Fall Under Anti-Spam Rules
The amendments also address the growing use of AI voice agents and automated calling systems. Calls made without a person directly dialing the number now fall under TRAI's application-to-person (A2P) framework. That includes robocalls, prerecorded voices, and calls using AI-generated speech.
Companies using these systems must declare their use and the phone numbers involved to their telecom operators in advance. Undeclared A2P calls will be treated as spam. Telecom operators can levy a termination charge of up to 5 paise (roughly half a cent) per minute on A2P calls, though calls from certain designated number ranges are exempt.
The key test, Srivastava said, is how a call is initiated rather than whether it uses an AI-generated voice. That leaves uncertainty around AI-assisted calls that involve human initiation, such as contact center agents using AI to draft responses or click-to-call services that connect users to automated systems.
Satya N. Gupta, a former additional secretary at TRAI, said the new rules do not restrict businesses from using AI or automated calling technologies. They require disclosure to telecom operators. But Rizvi warned that without a clear distinction between fully automated and human-initiated calls, the A2P category risks becoming broader than the regulatory harm it is intended to address.
What This Means for App Developers and Telecom
The regulation creates a new data pipeline that runs from user-facing apps to telecom infrastructure. For app developers, the compliance burden includes determining what data must be shared, how to transmit it to the blockchain platform, and how to obtain or manage user consent. For telecom operators, it means gaining access to spam signal data they previously had to generate themselves or go without.
For Truecaller specifically, the ruling threatens a core part of its value proposition. The company's competitive advantage rests on the volume and quality of its spam reports. Forcing it to share that data with telecom operators erodes that advantage while giving operators a free upgrade to their spam detection capabilities.
The broader pattern is clear. Regulators worldwide are grappling with how to handle AI-generated communications, and India is moving faster than most. The combination of mandatory data sharing, A2P classification, and termination charges gives TRAI a toolkit that covers both traditional spam and the emerging wave of AI voice agents. Whether the enforcement mechanism can keep up with the pace of deployment remains an open question.