Since the FCC made the STIR/SHAKEN framework mandatory in 2021, the VoIP industry has been trying to solve robocalls and caller-ID spoofing. The TNS 2026 Robocall Investigation Report shows that the framework works well only in certain segments of the network — and now that AI voice cloning has entered the game, robocalls in 2026 are more complicated than before.
What STIR/SHAKEN can and cannot do
STIR (Secure Telephony Identity Revisited) and SHAKEN (Signature-based Handling of Asserted Information Using toKENs) are a framework in which the originating provider cryptographically signs the caller ID so the terminating provider can verify that the number shown really belongs to the caller.
There are three levels of attestation:
- A-level (full attestation): the provider knows the subscriber and confirms the number is theirs
- B-level (partial attestation): the provider knows the subscriber but has not confirmed ownership of the number
- C-level (gateway attestation): the traffic is transiting a gateway and the subscriber is unknown
STIR/SHAKEN says that an identity claim was signed. It does not say whether the caller has a legitimate reason to be calling.
The real figures from the TNS 2026 report
TNS analysed traffic between the Tier-1 carriers (Verizon, T-Mobile, AT&T, Lumen, Comcast, Charter, US Cellular):
- 85% of voice traffic between Tier-1 carriers was signed and verified in 2025, with 93% of it at A-level
- but between smaller providers signing drops to just 17.5%
- there is still 20% over-attestation on some networks — calls from "known invalid" or Do-Not-Originate (DNO) numbers wrongly signed at A-level
- 13% of traffic using an invalid number was signed A-level
Which is why enterprises relying on STIR/SHAKEN alone still get robocalls through.
Why the FCC opened the KYUP proposal in 2026
In 2026 the FCC issued a Further Notice of Proposed Rulemaking adding a Know-Your-Upstream-Provider (KYUP) obligation: a provider receiving traffic from upstream has to verify and document the originating provider. It covers:
- originating providers
- intermediate providers
- gateway providers
- terminating providers
- wholesale, reseller, VoIP, CMRS, MVNO and enterprise voice providers
That means Thai organisations doing outbound calling into the United States — call centres, legitimate telemarketing, SaaS notifications — need to have their upstream provider documentation and full trace path ready, or risk being blocked at the far end.
AI voice cloning — the new robocall STIR/SHAKEN cannot catch
Late 2025 into 2026 has been the season of a new kind of "grandparent fraud": AI cloning the voice of a family member from a TikTok clip or a Facebook live, then calling the victim's mobile with an urgent story (an accident, an arrest, money needed right now). STIR/SHAKEN does not help here, because:
- the calling number may be spoofed legally through a compliant CLI rewrite
- even when STIR/SHAKEN verifies and flags the call, the person answering never sees that metadata
- AI voice in 2026 can clone from 3-5 seconds of audio — the old countermeasures no longer apply
What enterprises are layering on top of STIR/SHAKEN in 2026
Watching deployments at larger enterprise customers, a layered-defence pattern keeps appearing:
Layer 1: an AI voice agent at the front of the system
Before traffic reaches the ACD/PBX, an AI agent asks about and verifies caller intent in natural language, filtering out robocalls and AI clones whose answers do not hold together. Platforms such as Viirtue and PolyAI operate at this level.
Layer 2: voice biometrics
For known customers (banking, insurance), a voice print is compared against a stored template — a good AI clone can fool a human, but fine detail in pitch contour and formants still differs.
Layer 3: predictive call analytics
Providers such as TNS, Neural Technologies and First Orion analyse the originator's pattern (call frequency, regional spread, call duration) before deciding whether to deliver the call to the end user.
Layer 4: network-level blocking
The carrier cuts off calls from flagged originators at the network level, before they ever enter the PSTN.
What Thai organisations should do
STIR/SHAKEN is a US FCC mandate, but international traffic passing through a Tier-1 carrier at the far end is enforced all the same. In Thailand the NBTC has not imposed the same level yet, though the large providers (AIS, True, NT) began pilots through 2025-2026.
Practically, for Thai enterprises:
- If you make outbound calls to the US: ask your SIP trunk provider for the STIR/SHAKEN certificate and check that calls really are signed at A-level — you can see it in a PCAP of the INVITE message
- If you take inbound calls from abroad: use a session border controller (SBC) that performs SIP header inspection — Audiocodes Mediant, Ribbon SBC or Oracle ACME all have features to flag invalid PAI/PAID headers
- For a contact centre: add an AI front end that verifies intent before routing, which cuts out the robocalls that probe an IVR for gaps
- Update the call recording policy: keep voice biometric templates for VIP customers (with PDPA consent) so high-value transactions can be verified
STIR/SHAKEN is the starting point, not the destination. Stopping robocalls in 2026 takes defence in depth.
This is the year "trust but verify" replaces "trust because authenticated" in voice security. Any executive still reading a vendor brochure that says "STIR/SHAKEN is enough" needs a briefing update.