Can you tell an AI voice clone by ear?
Why "spot the fake" advice keeps failing
| The tell people are taught | Why it stops working |
|---|---|
| Flat or robotic delivery | Prosody is the single most improved dimension of speech synthesis; emotional, distressed delivery is now the default sales demo |
| Odd breathing or no breaths | Breath and disfluency are synthesised deliberately because they raise perceived realism |
| Short calls, "bad line" excuses | Still common, but it is a script choice, not a technical limit — and a real relative in trouble also has a bad line |
| "It didn't sound quite right" | Under adrenaline, people accept far weaker matches. The scam's first job is to remove your ability to judge |
All four are detection claims. Detection is a race you re-run every time a model ships. Verification is a fixed procedure that works no matter how good the audio gets — which is why it is what law enforcement actually recommends.
The 60-second procedure
- Hang up. "Don't hang up", "don't tell anyone", "stay on the line" — each of those is the reason to hang up, not a reason to stay.
- Call back on a number you already had. Not the number that called, not a number the caller reads out. If there is no answer, call a second family member.
- Ask the code word and one small recent fact. Make a card now if you do not have one — it takes two minutes.
Money moves last, never first. No verification codes, no gift cards, no crypto, no "bail bond" wire, no matter who the caller says they are. Run the 60-second checklist if you are in the middle of one of these calls right now.
What the rules do and do not do
| Rule | What it covers | Dated source |
|---|---|---|
| FCC Declaratory Ruling (TCPA) | An AI-generated voice is an "artificial or prerecorded voice" under the TCPA — AI voice robocalls fall under the same restrictions | Adopted 8 February 2024, effective immediately (FCC 24-17) |
| FTC Impersonation of Government and Businesses Rule | Bans impersonating government agencies or businesses in commerce; lets the FTC go straight to federal court to claw money back | Effective 1 April 2024 (FTC rule page) |
| EU AI Act, Article 50 | Disclosure that you are dealing with an AI system; deepfake content must be disclosed | Applies from 2 August 2026 |
| EU AI Act, machine-readable marking + new prohibitions | Synthetic content marked in a machine-readable way; two prohibitions added by the Digital Omnibus on AI | From 2 December 2026 (Regulation (EU) 2026/1744) |
None of these stop the call from reaching you. Labelling duties bind lawful providers; a criminal ignores them. So an unlabelled voice proves nothing, and a labelled one proves only that someone complied. Treat the law as what happens after, and the code word as what happens during.
The AGI-2027 Thesis Tracker — our parent site scores the "AGI by 2027" predictions one by one against evidence. It is upstream of this page: every step up in generative capability is another step down for "I'd know my own child's voice".
Reading as of 2026-09-06; the parent site is authoritative. agiscorecard.com/progress-index
What would change this verdict
| Watch | Flip condition | Status (2026-09-15) |
|---|---|---|
| Carrier-side detection | Live synthetic-voice warnings on ordinary consumer calls, deployed by default and relied on by law enforcement → "detection" becomes part of the defence | No such default consumer deployment found |
| Official advice | FBI or FTC guidance moves from "verify by callback / code word" to "you can authenticate by voice" → this page is rewritten | Guidance remains verification-first |
| Provenance marking | Machine-readable marking (EU, from 2 December 2026) actually surfaces in ordinary phone and video calls → a partial detection signal exists for compliant content | Obligation dated, consumer-visible effect not yet demonstrated |
| Generative capability | Parent tracker moves materially upward → this verdict only gets stronger, never weaker | 62.5/100 (2026-09-06) |
Frequently asked
Can you tell an AI voice clone by ear?
No, and trying to is the mistake. Voice cloning is built to defeat exactly the test you are running: does this sound like my son. Advice that tells you to listen for robotic pauses or odd breathing is advice that ages badly, because each model generation removes another tell. The defence that does not age is verification: hang up, call back on a number you already had, and ask a code word only your family knows.
What should I do in the first sixty seconds of a call like this?
Three things, in order. One: hang up. If the caller says do not hang up, that is the reason to hang up. Two: call back on a number already saved in your phone, not a number the caller gave you, and if that fails call a second family member. Three: ask the code word and one small recent fact only the real person would know. Do not send money, gift cards, cryptocurrency or a verification code before all three are done.
Are AI voice scam calls illegal in the United States?
Yes. On 8 February 2024 the FCC adopted a Declaratory Ruling confirming that an AI-generated voice is an artificial or prerecorded voice under the Telephone Consumer Protection Act, so AI voice robocalls are covered by the same restrictions, effective immediately. Separately, the FTC's Impersonation of Government and Businesses Rule took effect on 1 April 2024 and lets the Commission go to federal court directly against impersonation schemes. Neither rule stops a call from reaching you, so the practical defence is still verification.
Does the EU require AI content to be labelled?
Yes, from 2 August 2026. The AI Act's Article 50 transparency duties apply from that date: people must be told when they are interacting with an AI system, and deepfake content must be disclosed. Machine-readable marking of synthetic content follows on 2 December 2026, along with two new prohibitions added by the Digital Omnibus on AI, Regulation (EU) 2026/1744. Labelling duties bind lawful providers; criminals ignore them, so an unlabelled voice proves nothing either way.
What makes a good family code word?
Something no one can find online and everyone in the family can say under stress. Not a birthday, a pet's name, a school or an anniversary — those are reconstructable from social media, and the person cloning a voice has usually done that homework. A shared family memory works well: the tree in the old back garden, the floor of the first flat. Keep the answer short, agree a backup question, and never say the answer first on an incoming call.
Make a family code word card60-second checklistIs this a scam? 12 questions
Written by the AGI Scorecard editorial desk (about us). Not legal advice; rules are summarised, the linked originals govern. Last updated 2026-09-15.