Collections is where AI economics and regulatory exposure collide harder than anywhere else in consumer finance. The upside is real: better contact strategies, personalized treatment paths, and conversational automation can lift cure rates meaningfully while cutting cost-to-collect. The downside is also real: FDCPA statutory damages, Regulation F violations, CFPB consent orders, and state-by-state rules that turn one wrong message into class-action exposure.
Most vendors resolve this tension with a slide that says "compliant by design." We resolve it by putting the constraints in the decision layer, where they're enforced by code and proven by logs.
The constraint set is the spec
Before any model gets trained, the compliance requirements get written down as machine-enforceable policy. For US consumer collections, the floor looks like this:
- Regulation F call frequency: no more than seven call attempts per debt in seven days, and no calls within seven days of a conversation about that debt. This is a hard counter, enforced per debt, across every channel and every agent — human or machine.
- Time and place restrictions: contact only between 8 a.m. and 9 p.m. in the consumer's local time, which means timezone resolution is a compliance function, not a nice-to-have.
- Channel consent and opt-outs: email and SMS under Reg F require specific opt-out mechanics; revocation must propagate everywhere within your documented SLA, immediately in practice.
- Prohibited communications: no contact at a known workplace after being told not to, no third-party disclosure, mandatory attorney-representation and cease-communication handling.
- State overlays: stricter frequency limits, licensing rules, and disclosure requirements by state — the policy engine has to resolve the applicable rule set per account.
Every one of these becomes a pre-send check in a policy service that sits between any decision system and any outbound channel. Models propose; the policy layer disposes. No message, call, or letter reaches a consumer without passing through it, and every pass/block decision is logged with the rule version that made it.
Where ML earns its keep
With the guardrails as bedrock, the optimization layers are conventional ML with unusual payoff:
Treatment and contact optimization. Propensity-to-pay and right-channel/right-time models decide who to contact, when, and how — inside the compliance envelope. Because Reg F caps attempts, each attempt is a scarce resource; a model that improves right-party contact rates by even 15–20% directly moves cure rates. Uplift modeling matters more than raw propensity here: contacting someone who would have paid anyway is worse than useless, since it burns a capped attempt and goodwill.
Hardship and vulnerability detection. Models and NLP that flag likely financial hardship, bankruptcy signals, or vulnerable-customer indicators — routing those accounts away from standard automation toward trained specialists and forbearance paths. Regulators look for this, and it's also simply the right call. Treating hardship detection as a first-class model, with its own recall targets, changes the tone of the whole program.
Offer optimization. Settlement and payment-plan terms tuned to likelihood of completion, not just promise-to-pay. A plan that breaks in week three is worse than a smaller plan that completes.
Conversational AI: constrained generation only
LLM-driven negotiation over email, SMS, and chat is where collections AI is heading, and it's also where uncontrolled generation is disqualifying. A model that improvises a threat, misstates a balance, or implies legal action that isn't contemplated has just manufactured an FDCPA violation at machine speed.
Our pattern for production collections agents:
- Governed content, assembled dynamically. The LLM plans the conversation and selects and parameterizes from a compliance-approved content library, rather than free-writing legal claims. Amounts, dates, and disclosures are injected from the system of record, never generated.
- Dual-layer checking. Deterministic validators (required mini-Miranda disclosures present, no prohibited phrases, numbers match the ledger) plus an LLM-based compliance critic scoring every outbound draft. Anything below threshold routes to a human queue.
- Hard escalation triggers. Dispute language, cease-communication requests, attorney representation, bankruptcy mentions, or hardship signals immediately stop automation and route to humans, with the trigger logged.
- Evals before traffic. A red-team suite of hundreds of adversarial scenarios — consumers baiting threats, ambiguous dispute phrasing, wrong-debtor claims — run against every prompt or model change in CI. Release is gated on zero critical violations, not on average scores.
Log everything, per your retention policy. In a CFPB examination or FDCPA suit, the question is not whether your AI was well-intentioned — it's whether you can produce the exact message, the policy checks it passed, the model and prompt versions, and the consent state at send time. If you can't reconstruct a conversation, assume it will be construed against you.
Measured outcomes, not vibes
The scoreboard for a compliant collections AI program has two columns, and both are quantitative. Performance: cure rate, roll rates, dollars collected per attempt, plan completion rate, cost-to-collect. Compliance: policy-block rate, escalation-trigger accuracy, complaint rate per thousand contacts, and zero tolerance on frequency-cap breaches. We put both columns on the same dashboard because a lift in collections that comes with a rise in complaints isn't a win — it's a lawsuit on layaway.
How we build it
A StrataHub Pilot in collections runs 4–6 weeks: we stand up the policy engine against your actual rule set, deploy contact-optimization models in shadow against your current dialer strategy, and run the conversational red-team suite against a constrained agent on one channel. You get measured projections on cure-rate lift and cost-to-collect — with the compliance log to show your counsel.
Co-Build (3–6 months) takes it live channel by channel, integrates consent and complaint systems, and hands your compliance team the monitoring and audit tooling. Scale keeps the models, content library, and rule sets current as regulations and portfolios shift.
Collections AI works when the compliance constraints are the architecture, not the appendix. Build the policy layer first, make every model answer to it, and log every decision. Then optimize aggressively inside the fence — that's where the returns are, and it's the only place they're durable.