/

Support Quality

Best Compliant AI for Debt Collections & Outbound Re-engagement (2026)

Best Compliant AI for Debt Collections & Outbound Re-engagement (2026)

Jamie Hall

Jamie Hall

·

Updated

·

Fact-checked against Gartner & Forrester data

Most buyers shopping for an AI collections agent start with the wrong question. They ask which vendor has the most natural voice or the highest contact rate. For a lender, the first question is narrower and harder: which vendor treats the Fair Debt Collection Practices Act, Regulation F, and the Telephone Consumer Protection Act as hard constraints the agent physically cannot break, rather than settings a configuration mistake can switch off. Get that wrong and a single miscalibrated campaign can generate thousands of statutory violations before anyone reads the transcript.

The stakes are concrete. The Consumer Financial Protection Bureau's Regulation F caps a collector at seven call attempts within a seven-day period per debt, and forbids contact for a week after a conversation. FDCPA requires a mini-Miranda disclosure. TCPA governs consent for automated outreach, and states are now layering AI-voice disclosure rules on top. An agent that dials outside a consumer's 8am to 9pm local window, or keeps calling after a cease-and-desist, does not have a quality problem. It has a compliance liability that scales with call volume. This guide ranks eight AI vendors for compliant collections and outbound re-engagement in 2026, weighted toward the controls a regulated lender actually has to answer for.

The 8 best compliant AI agents for collections and outbound re-engagement

Vendor

Best for

Lorikeet

Lenders needing resolution-grade collections with compliance encoded as hard constraints across voice, SMS, chat, and email

Gail

High-volume outbound voice dialing where raw call throughput is the primary metric

Skit.ai

Accounts-receivable teams wanting a collections-specific omnichannel dialer

Decagon

Consumer brands prioritizing inbound deflection over regulated outbound

Sierra

Enterprises wanting a managed, vendor-run agent with polished voice

Gradient Labs

Fintechs wanting a procedure-driven agent layered on an existing helpdesk

Salesforce Agentforce

Servicers already standardized on Salesforce Financial Services Cloud

Cognigy

Contact centers modernizing IVR and voice self-service at scale

What is a compliant AI collections agent?

A compliant AI collections agent is an autonomous system that contacts consumers about past-due balances, negotiates and takes payment or arranges plans, and re-engages lapsed or delinquent customers, while enforcing federal and state collections law as a condition of every interaction. The difference between a collections agent and a general support bot is that the collections agent operates in a space where the manner, timing, and frequency of contact are themselves regulated, independent of what the agent says.

In practice, a compliant AI collections agent has to encode a specific stack of controls:

  • FDCPA mini-Miranda disclosure. The agent states it is attempting to collect a debt and that information obtained will be used for that purpose, at the correct point in the call, every time.

  • Regulation F frequency caps. The seven-in-seven call-attempt limit and the seven-day post-conversation quiet period are tracked per debt and enforced before a dial is placed, not audited after the fact.

  • TCPA consent tiers and AI-voice disclosure. The agent checks the consent state for each channel and number before outreach, and discloses that the consumer is speaking with an artificial voice where required.

  • Time-zone windows. Contact is restricted to the consumer's local 8am to 9pm window, which means resolving the consumer's actual location, not the area code of the phone number.

  • Cross-channel suppression. A cease-and-desist or opt-out on any channel propagates to every channel, so an SMS opt-out also stops the voice campaign.

Encoding these as deterministic controls, rather than as instructions in a prompt the model may or may not follow, is what separates a collections-grade agent from a repurposed chatbot. For the outbound-reminder end of this spectrum, our companion guide to the best AI for outbound collections and payment reminders goes deeper on cadence design.

What lenders and collections ops teams need

Buyers in this category are usually a collections operations lead, a head of servicing, or a compliance officer at a lender, card issuer, buy-now-pay-later provider, or neobank. Their requirements differ from a general CX team's in five ways.

Compliance certainty before contact rate. A 20% higher contact rate is worthless if it comes from dialing outside permitted hours. The agent has to prove it will not place a non-compliant contact, and produce the record showing why each contact was allowed.

Resolution, not deflection. A collections conversation succeeds when a payment is taken, a plan is agreed, or a promise-to-pay is captured and logged. Containing the call without moving the balance is not a win. Buyers should look at true resolution, measured against the actual account outcome, rather than a containment percentage.

Multi-step, stateful workflows. Real collections involves a CRM balance lookup before the call, day-based script escalation as an account ages, negotiation within policy-approved ranges, and payment capture through a compliant processor. The agent has to carry state across all of it.

An operator-owned audit trail. When an examiner or an internal auditor asks why a consumer was contacted at a given time, the team needs a record of what the agent was configured to do, who approved that configuration, and why each contact cleared the rules. A config-level audit trail is worth more than a call recording alone.

True omnichannel with unified suppression. Voice, SMS, chat, and email have to share one consent and suppression state. Lenders serving neobank and digital-lending segments in particular need this cross-channel discipline, a theme we expand in the guide to the best AI customer support for neobanks and digital lenders.

How we evaluated these vendors

We scored each vendor against six criteria weighted for regulated collections work.

Criterion

What we looked for

Compliance as a hard constraint

Whether FDCPA, Reg F, and TCPA controls are enforced deterministically before contact, versus described in prompts or left to the operator to police

Outbound channel coverage

Production outbound voice plus SMS, with unified cross-channel opt-out and suppression

Resolution capability

Ability to take payment, arrange plans, and log promise-to-pay end to end, measured on outcome rather than containment

Audit trail depth

Whether the configuration, approvals, and per-contact eligibility decisions are logged and reviewable

Security posture

SOC 2 Type II, ISO 27001, HIPAA via BAA, GDPR, data residency, and honest disclosure of gaps such as PCI

Operator control

Whether the buying team can configure, test, and change the agent's behavior, or has to route every change through the vendor

A disclosure on method: this is a guide published by Lorikeet, and Lorikeet is ranked first. We have tried to be fair to the alternatives and honest about where Lorikeet has gaps, including that Lorikeet does not hold PCI certification. The vendor summaries draw on public product documentation, security and trust pages, pricing pages, and third-party review sites current as of July 2026. Certifications and features change, so confirm the specifics with each vendor during your own evaluation.

The 8 vendors in detail

1. Lorikeet

Best for: lenders and collections operations that need resolution-grade outreach with FDCPA, Reg F, and TCPA compliance built in as hard constraints across voice, SMS, chat, and email.

Lorikeet is an AI concierge platform built for complex, regulated businesses, the kind of collections and servicing work where basic support automation breaks. Rather than framing success as deflection, Lorikeet is built to resolve the underlying account issue end to end: look up the balance in the CRM before the call, deliver the required disclosures, negotiate within a policy-approved range, take payment or arrange a plan, and log the promise-to-pay. That resolution orientation is measured through a ticket quality score that reflects the actual account outcome, not whether the call was simply contained.

The differentiator for regulated collections is that Lorikeet treats compliance as a set of deterministic constraints the agent operates inside, not as suggestions in a prompt. The mini-Miranda disclosure fires at the correct moment on every call. Regulation F's seven-in-seven attempt cap and post-conversation quiet period are tracked per debt and checked before a dial is placed. TCPA consent tiers are verified per channel and per number, with AI-voice disclosure at the start of the call where required. Contact is confined to the consumer's local 8am to 9pm window using the consumer's resolved location rather than a raw area code. A cease-and-desist or opt-out captured on any channel suppresses outreach across all of them.

Sitting under that is an operator-owned configuration layer with a config-level audit trail. The collections or compliance team configures behavior in natural language and structured workflows, tests it in simulation before it ever touches a live account, and gets a record of what changed, who approved it, and why. When an auditor asks why a given consumer was contacted at a given time, the answer is in the trail, alongside the per-contact eligibility decision that cleared the rules.

On channels, Lorikeet runs voice live in the US, UK, and Australia, with outbound calling in production, alongside chat, email, and SMS on one platform with shared suppression state. Named Outcomes, Coach, guardrails, simulations, and customer-profile memory round out the orchestration. Integrations span Salesforce, Zendesk, Intercom, Front, Genesys, Twilio, Infobip, and MCP. The model stack runs on Anthropic and OpenAI inference with no training on customer data.

Security and compliance: SOC 2 Type II and ISO 27001:2022 achieved, active HIPAA (via BAA) and GDPR programs, hosted on Google Cloud across US, EU, and AU regions, with AES-256 encryption at rest, TLS 1.2 or higher in transit, tenant isolation, RBAC and MFA, and immutable audit logs.

Pricing: per-resolution, at roughly $1.50 per voice resolution and $0.95 per chat resolution, so cost tracks outcomes rather than call minutes or seat licenses.

Honest limitation: Lorikeet does not hold PCI DSS certification today, so lenders that require the agent itself to be in PCI scope for card capture will need a compliant payment processor in the flow. Lorikeet publishes no uptime SLA, and voice, while live in production, is the newer surface relative to chat and benefits from a supervised rollout.

2. Gail

Best for: high-volume outbound voice programs where raw dialing throughput and contact rate are the headline metrics.

Gail is a purpose-built outbound-voice vendor that has competed directly for collections and re-engagement programs, and it is a genuinely strong outbound dialer. Teams that measure success primarily by connect rate and calls placed per hour will find it competitive, and it has held its own against broader platforms on narrow outbound conversion tasks such as credit-line reactivation.

Strengths: focused outbound-voice product, competitive contact throughput, and a design centered on high-volume calling campaigns.

Honest limitation: the outbound-voice focus is also the constraint. Lenders that need one platform to carry chat, email, and SMS with unified cross-channel suppression, plus a config-level audit trail for examiners, will find the surface narrower than a full concierge platform. Confirm directly how FDCPA, Reg F, and TCPA controls are enforced and evidenced.

3. Skit.ai

Best for: accounts-receivable and agency collections teams wanting a dialer purpose-built for the collections industry.

Skit.ai positions itself squarely as a conversational AI platform for collections, with voice, SMS, email, and chat aimed at accounts-receivable management. It speaks the language of the industry, references FDCPA, Regulation F, and TCPA in its positioning, and is designed around collections campaigns rather than adapted from generic support.

Strengths: collections-specific product framing, omnichannel outreach built for AR workflows, and familiarity with the regulatory vocabulary of debt collection.

Honest limitation: the platform is optimized for agency and AR-style collections rather than the deeper account-resolution and in-app servicing that a modern lender or neobank often wants, where the agent has to reason over live account state and take actions beyond the collections call. Validate how much of the compliance stack is deterministic enforcement versus operator-configured cadence.

4. Decagon

Best for: consumer brands whose priority is inbound support deflection rather than regulated outbound collections.

Decagon is a capable AI support agent that has won consumer-facing deployments, and its strength is inbound automation at scale. For collections specifically, the fit is weaker, because the product is framed around deflection and containment rather than the outbound, consent-gated, frequency-capped work that collections requires.

Strengths: polished inbound experience, strong at high-volume consumer support, quick to stand up on common support topics.

Honest limitation: a deflection-first orientation and per-conversation pricing that can charge even when the AI does not resolve the issue are an awkward match for collections, where the outcome, not the contact, is what matters. Teams weighing this trade-off can compare the two approaches directly on our Lorikeet vs Decagon page.

5. Sierra

Best for: enterprises that want a vendor-managed agent with polished, natural-sounding voice and are comfortable with a managed-service model.

Sierra, founded by Bret Taylor, has earned a reputation for voice naturalness and has won notable enterprise deployments, including in regulated payments. It holds PCI Level 1, which matters for teams that need the agent in card-capture scope, and its managed model appeals to buyers who would rather the vendor run the agent than configure it themselves.

Strengths: strong voice quality, enterprise credibility, and PCI Level 1 certification.

Honest limitation: the managed model means the operator is more of a passenger, with less direct control over configuration and a thinner operator-owned audit trail of what changed and who approved it. For collections teams that have to answer to examiners on their own timeline, that accountability gap matters. See the side-by-side on our Lorikeet vs Sierra page.

6. Gradient Labs

Best for: fintechs wanting a procedure-driven agent that layers onto an existing helpdesk, with collections named among its use cases.

Gradient Labs, built by an ex-Monzo team, is the closest pure-play competitor in regulated fintech support. It is explicit about serving fintech use cases including disputes, chargebacks, KYC, and collections, and its procedure-driven approach resonates with compliance-minded buyers.

Strengths: fintech-native focus, procedure-driven design, credible founding team, and a willingness to name regulated use cases directly.

Honest limitation: it is an earlier-stage company that generally requires an existing helpdesk to layer onto and runs a more vendor-managed model, so buyers wanting a single platform to own outbound collections end to end, with a self-owned configuration and audit layer, should scope those boundaries carefully.

7. Salesforce Agentforce

Best for: servicers and lenders already standardized on Salesforce Financial Services Cloud.

Agentforce is Salesforce's agent layer, and its main advantage is proximity to data and workflows already living in Salesforce. For a shop that runs servicing on Financial Services Cloud, keeping the agent inside that estate reduces integration work.

Strengths: native to the Salesforce ecosystem, access to existing CRM data and processes, and enterprise support and governance tooling.

Honest limitation: Agentforce typically depends on Data Cloud and meaningful configuration to work well, is priced per conversation (around $2), and is a general-purpose agent rather than a collections-specific one, so the FDCPA, Reg F, and TCPA control stack is something the implementing team assembles rather than something the product enforces out of the box.

8. Cognigy

Best for: contact centers modernizing IVR and voice self-service across large, multilingual operations.

Cognigy is an enterprise conversational-AI platform strong in voice and IVR modernization, widely deployed in large contact centers. For lenders whose immediate problem is replacing a legacy phone tree and handling high inbound volume, it is a credible enterprise choice.

Strengths: mature enterprise voice and IVR, broad language coverage, and deep contact-center integrations.

Honest limitation: the center of gravity is enterprise IVR and inbound automation rather than regulated outbound collections, so the collections-specific compliance controls and outbound cadence logic are largely built by the implementer on top of the platform rather than provided as deterministic, collections-aware guardrails.

Feature and compliance matrix

The matrix below reflects each vendor's fit for regulated outbound collections as of July 2026. "Built in" means the control is enforced by the product as a deterministic constraint. "Configurable" means the capability exists but is assembled by the implementing team. Confirm all certifications directly, as vendor posture changes.

Vendor

Outbound voice

SMS

FDCPA controls

Reg F caps

TCPA consent

Config audit trail

SOC 2 II / ISO 27001

Lorikeet

Production (US/UK/AU)

Yes

Built in

Built in

Built in

Yes

Both. PCI not held

Gail

Production

Limited

Configurable

Configurable

Configurable

Limited

Confirm with vendor

Skit.ai

Production

Yes

Configurable

Configurable

Configurable

Partial

Confirm with vendor

Decagon

Limited

Yes

Not collections-focused

No

Configurable

Partial

Confirm with vendor

Sierra

Yes (managed)

Yes

Configurable

Configurable

Configurable

Vendor-managed

Both, plus PCI L1

Gradient Labs

Emerging

Yes

Configurable

Configurable

Configurable

Vendor-managed

Confirm with vendor

Salesforce Agentforce

Via add-ons

Yes

Configurable

Configurable

Configurable

Platform logs

Both

Cognigy

Yes

Yes

Configurable

Configurable

Configurable

Platform logs

Both

Two honest notes on this table. First, Lorikeet does not hold PCI certification, so for card capture inside PCI scope, Sierra's PCI Level 1 is a genuine advantage and Lorikeet routes card data through a compliant processor instead. Second, "configurable" is not a criticism on its own, but it does shift the compliance burden onto your team, because a control you assemble is a control you have to test, evidence, and defend yourself.

How to choose

Narrow the field with five factors, in this order.

1. Start with the compliance model, not the demo. Ask whether FDCPA, Reg F, and TCPA controls are enforced deterministically before contact or described in prompts. A great-sounding voice on a non-compliant dial is a liability, not a feature.

2. Define resolution before contact rate. Decide what a successful collections interaction is (payment taken, plan agreed, promise-to-pay logged) and insist the vendor measure against that outcome, not a containment or deflection percentage.

3. Map your channels and suppression. If you run voice plus SMS, confirm that an opt-out on one channel suppresses the others automatically, from one shared consent state.

4. Test the audit trail against a real question. Ask the vendor to show, for a sample contact, why it was permitted, what the agent was configured to do, and who approved that configuration. If the answer is only a call recording, that is a gap.

5. Weigh operator control versus managed service. Decide whether your team needs to configure and change agent behavior directly, or is comfortable routing every change through the vendor. For examiner-facing collections, self-owned control usually wins.

Questions to ask every vendor on compliance:

  • Is the mini-Miranda disclosure enforced on every call as a hard constraint, and can you show it in a transcript?

  • How is the Regulation F seven-in-seven attempt cap tracked per debt, and is it checked before a dial or audited after?

  • How do you determine the consumer's local time zone to enforce the 8am to 9pm window, area code or resolved location?

  • When a consumer opts out or issues a cease-and-desist on SMS, how fast and how completely does that suppress the voice campaign?

  • Where required, how does the agent disclose that the consumer is speaking with an AI voice?

  • What exactly is your certification posture: SOC 2 Type II, ISO 27001, HIPAA via BAA, PCI, and where are the gaps?

  • Can you produce a configuration-level audit trail showing what changed, who approved it, and why a given contact was allowed?

Why Lorikeet leads for compliant collections

Collections is where the gap between deflection and resolution, and between configured and enforced compliance, gets expensive. Lorikeet is built for exactly that regulated, high-stakes work: it resolves the account outcome end to end while treating FDCPA, Reg F, and TCPA as constraints the agent operates inside, backed by an operator-owned configuration layer and a config-level audit trail that answers the questions an examiner actually asks.

The clearest proof is Carmoola, a UK car-finance lender that runs weekly outbound campaigns with Lorikeet to re-engage customers and manage collections in production. It is a live, recurring program in a regulated lending market, not a pilot, and it shows the platform carrying real outbound collections cadence week after week rather than a one-off demo.

The economics can be striking too. In one production deployment, a fintech lender in Mexico found that Lorikeet's outbound voice collections converted 2 to 6% better than its human agents, at roughly 10 to 12 times lower cost. That result belongs to that specific lender's program and is not a general guarantee, but it shows what compliant automated outreach can do when resolution, rather than mere contact, is the target.

Pricing reinforces the alignment: Lorikeet charges per resolution, roughly $1.50 per voice resolution and $0.95 per chat resolution, so you pay for outcomes rather than minutes or seats. Combined with SOC 2 Type II, ISO 27001, active HIPAA and GDPR programs, and hosting on Google Cloud across US, EU, and AU regions, that makes Lorikeet a defensible choice for a lender that has to answer for every contact it places.

To see the compliance controls and the outbound flow on your own accounts, book a demo.

Frequently asked questions

What makes an AI collections agent compliant with the FDCPA and Regulation F?

Compliance depends on enforcing specific controls as hard constraints rather than as prompt instructions. Under the FDCPA, the agent must deliver the mini-Miranda disclosure, stating it is attempting to collect a debt, on every call. Under Regulation F, it must respect the seven-in-seven call-attempt cap per debt and the seven-day quiet period after a conversation, checked before each dial. It also has to confine contact to the consumer's local 8am to 9pm window using the consumer's resolved location. A compliant agent enforces these deterministically and logs why each contact was permitted, so the record survives an examination.

How does TCPA consent and AI-voice disclosure work for automated outreach?

The Telephone Consumer Protection Act governs consent for automated calls and texts, and a compliant agent checks the consent state for each channel and phone number before it reaches out. Consent captured for SMS does not automatically authorize an automated voice call, so the tiers have to be tracked separately. A growing number of states also require disclosure that the consumer is speaking with an artificial voice, so the agent should announce that it is an AI at the start of the call where the rule applies. Getting consent tiers and disclosure wrong is one of the most common and costly failure modes in automated collections.

Can an AI agent take payments and negotiate plans, or only send reminders?

The stronger platforms do more than remind. A resolution-grade agent looks up the balance before the call, negotiates within a policy-approved range, arranges a payment plan, captures a promise-to-pay, and takes payment through a compliant processor, logging the outcome against the account. That said, card capture touches PCI scope. Lorikeet does not hold PCI certification and routes card data through a compliant payment processor rather than handling it in scope itself, so confirm each vendor's PCI posture if the agent needs to capture card details directly.

What should lenders look at instead of deflection or containment rate?

Deflection and containment measure whether a contact ended without a human, which says nothing about whether the balance moved. For collections, the meaningful metric is true resolution: was a payment taken, a plan agreed, or a promise-to-pay captured and logged. A high containment number can hide a low resolution rate. Ask vendors to report outcomes against the actual account state, and to show how they measure it, rather than accepting a containment percentage as a proxy for performance.

How do cross-channel opt-outs and suppression protect a lender?

Consumers opt out or issue a cease-and-desist on whatever channel is in front of them, and the law expects that request to be honored regardless of channel. If an SMS opt-out does not also stop the voice campaign, the next automated call is a violation. A compliant agent maintains one shared consent and suppression state across voice, SMS, chat, and email, so a request on any channel propagates to all of them immediately. When evaluating vendors, test how fast and how completely an opt-out on one channel suppresses outreach on the others.

SEE IT ON YOUR TICKETS

Watch Lorikeet resolve your hardest ticket, live

End-to-end resolution

Not deflection — the ticket actually gets fixed.

Full audit trail

Every backend action, logged and reviewable.

Live in weeks

Not quarters. Forward-deployed setup.