India is redesigning its anti-spam infrastructure by requiring caller-identification and call-management apps to feed user reports into systems operated by telecom companies.
The Telecom Regulatory Authority of India, or TRAI, adopted its Telecom Commercial Communications Customer Preference Third Amendment Regulations on September 18, expanding the country’s framework for dealing with unwanted commercial calls and messages.
Under the new rules, caller-ID and call-management applications that allow users to flag calls as spam or junk must send those reports into the telecom industry’s enforcement infrastructure.
The shift effectively connects crowdsourced signals collected by apps with a telecom system that can investigate and act against suspected spammers.
Spam reports are becoming shared infrastructure
Until now, much of the intelligence generated by caller-ID applications remained inside those platforms.
TRAI’s amendment pushes those reports toward the Distributed Ledger Technology system, the infrastructure telecom operators use to track commercial communications and enforce anti-spam requirements.
The broader framework also formalizes AI and machine-learning systems already used by major telecom operators. TRAI says providers have deployed AI/ML systems to detect suspected unsolicited commercial communications, with operators required to identify calling numbers that have a high probability of being used for spam and share those signals with one another.
If five or more calling-line identities associated with one sender are flagged within 10 days, operators can begin escalating actions including KYC re-verification, physical verification, outgoing-service restrictions and eventual disconnection for repeated misuse.
Automated calls are getting their own rules
The amendment also expands regulation around software-generated calling.
TechCrunch reported that calls made automatically rather than directly dialed by a person will now fall under India’s application-to-person, or A2P, calling framework. That includes robocalls and calls involving prerecorded or artificial voices.
Businesses using those systems will need to declare their use and associated phone numbers to telecom operators in advance. Undeclared A2P calls can be treated as spam.
Operators can also impose termination charges of up to 5 paise per minute on A2P calls, although designated number ranges receive exemptions.
Truecaller says the data flow is one-sided
The regulation has already triggered resistance from one of the largest companies affected.
Truecaller described the mandatory sharing requirement as a “one-way exchange” and “anti-competitive”, arguing that commercially valuable information collected by call-management applications would be transferred to telecom operators.
The company and TRAI have been publicly clashing over spam controls for months. Earlier this year, Truecaller CEO Rishit Jhunjhunwala criticized restrictions affecting community-generated spam labels for India’s designated commercial number ranges.
India is testing a different model for fighting spam
The technical significance goes beyond unwanted phone calls.
Spam detection has traditionally been fragmented: telecom companies see network traffic, smartphone operating systems see device-level behavior, and caller-ID apps collect reports from their own communities.
India is attempting to connect those layers.
That creates potential advantages because a spam report made inside one application can contribute to enforcement beyond that application’s users. It also raises difficult questions about data ownership, competitive advantage, reporting accuracy and how much information private platforms should be required to contribute to shared infrastructure.
For cybersecurity and communications companies, India could therefore become an important test case.
The country is moving anti-spam protection away from isolated apps toward something closer to a shared threat-intelligence network for phone communications—and the dispute with Truecaller shows that deciding who must supply that intelligence may be as complicated as detecting the spam itself.