Regulators have moved from “encouraging best practice” to levying fines, enforcing block‑lists and even creating criminal offences.
2025’s headline is the UK’s forthcoming ban on SIM‑farms, but the same liability‑shift is visible across the US, EU and Asia‑Pacific. In this blog post, the messaging experts from Openmind Networks explore how the rulebook has hardened since 2023 – and what your messaging stack must do about it.
The brief below captures only the measures adopted (or finalized) since January 2023; draft bills and consultations are flagged so you can plan ahead.
Key Takeaways
- Know‑Your‑Sender is now black‑letter law – Singapore’s SRF and Australia’s Sender‑ID Register (coming via SPF codes) mean networks pay if they deliver unauthenticated SMS.
- AI & spoofing are the new front lines – The FCC and Ofcom have shifted from guidance to outright blocking for AI‑voice robocalls and caller‑ID spoofing.
- Refund regimes are creeping into telecom – The EU PSR and the UK APP rules expose operators to charge‑backs when their filters miss a smishing message.
- Global convergence is real – Expect similar liability‑sharing proposals to surface in the US and Canada during 2025‑26.
United Kingdom – The Landmark SIM‑Farm Ban
What’s Changing?
A new offence in the Crime and Policing Bill will make it illegal to possess or supply multi‑SIM gateways “without a legitimate reason”.
- Penalties: Unlimited fines in England & Wales, £5 000 in Scotland/Northern Ireland.
- Timing: the ban activates six months after Royal Assent (expected Q4 2025 → compliance deadline roughly April 2026). GOV.UK
Why it Matters
SIM Gateways let fraudsters rotate cheap pre‑pay SIMs, defeating sender‑ID vetting and velocity filters. Removing this hardware from the UK should significantly impact the availability of low‑cost grey routes for A2P smishing and other fraud actions.
First Steps for Operators and Aggregators
- Run diagnostics on every gateway you, your test‑houses or enterprise customers control.
- Prepare evidence (business use‑case, location, IMSI range) for the Home Office licensing scheme now in consultation.
- Retune firewalls to alert on high‑velocity MSISDN swaps and improbable IMSI sequences.
Global Rule Changes Since 2023 – Region by Region
United States
- FCC 23‑21 (Targeting & Eliminating Unlawful Texts, March 2023) – Mandatory blocking of texts from Do‑Not‑Originate numbers and a single restoration contact per provider. Federal Communications Commission
- FCC 23‑107 (Second Robotext Order, January 2024) – Closes the lead‑generator consent loophole and compels traceback cooperation.
- AI‑Voice Declaratory Ruling (February 2024) – Any call or text using a cloned voice is an “artificial voice” under TCPA; prior express written consent is required. Federal Communications Commission
Action: Add “AI‑generated” flags to campaign‑vetting APIs and ensure DNO feeds are live across all ingress points.
United Kingdom
- Ofcom CLI‑spoofing rules (effective 29 January 2025) – Force networks to block calls and texts that present a UK number from overseas without authorization. www.ofcom.org.uk
- PSR APP‑Fraud Reimbursement Regime (from 7 October 2024) – Obliges payment providers – and, indirectly, telecom partners – to refund victims up to £85,000 within five business days. Home
- SIM‑Farm ban (see Section above).
Action: Extend firewall logic to HLR‑impossible UK CLIs and map number‑allocation logs to bank fraud reports for potential refund disputes.
European Union
- Digital Services Act – Fully applicable to all intermediary services as of 17 February 2024, imposing annual risk‑assessments and “effective mitigation” duties for systemic scams, including smishing ads and fake SMS landing pages. Steptoe
- Payment Services Regulation / PSD3 – Draft Article 59 widens refund liability to “impersonation fraud”; trilogue deal expected late 2025.
Action: Fold SMS‑URL takedown feeds and scam‑advert monitoring into your platform risk‑assessment paperwork.
Singapore
- Shared Responsibility Framework (effective 16 December 2024) – Banks, telcos and consumers split losses if phishing duties aren’t met; telcos must deliver Sender‑ID SMS only via licensed aggregators and deploy network‑level URL filters. MAS
Action: Verify every aggregator’s license number and enable real‑time URL‑reputation checks on outbound traffic.
Australia
- Scams Prevention Framework Act 2025 (assented February 2025) – Empowers regulators to impose civil penalties up to AU $50m on telcos or digital platforms that fail to block scams. Home
Action: Budget for new AI classifiers and engage early in ACMA code‑drafting workshops.
India
- TRAI TCCCPR Second Amendment 2025 (gazetted 12 February; in force 14 March 2025) – Tightens template traceability, mandates annual sender self‑certification and halves the complaint threshold for automatic blacklisting to five. Telecom Regulatory Authority of India
Action: Build a self‑serve portal so enterprise senders can upload yearly compliance certificates – then auto‑suspend headers that cross the five‑complaint line.
To learn more about the topics covered in this article, or to discuss how Openmind Networks can help you navigate the future of fraud prevention, please get in touch or contact our team of messaging experts online here.