CodeWord

Can you tell an AI voice clone by ear?

Verdict: no — and trying is the mistake. Cloning is built to beat the exact test you are running (does this sound like my daughter?). Every "listen for robotic pauses" checklist ages out with the next model. The defence that does not age is verification: hang up, call back on a number you already had, ask a code word. The FBI's own public advice is a family code word plus callback verification. Updated 2026-09-15.

Why "spot the fake" advice keeps failing

The tell people are taughtWhy it stops working
Flat or robotic deliveryProsody is the single most improved dimension of speech synthesis; emotional, distressed delivery is now the default sales demo
Odd breathing or no breathsBreath and disfluency are synthesised deliberately because they raise perceived realism
Short calls, "bad line" excusesStill common, but it is a script choice, not a technical limit — and a real relative in trouble also has a bad line
"It didn't sound quite right"Under adrenaline, people accept far weaker matches. The scam's first job is to remove your ability to judge

All four are detection claims. Detection is a race you re-run every time a model ships. Verification is a fixed procedure that works no matter how good the audio gets — which is why it is what law enforcement actually recommends.

The 60-second procedure

  1. Hang up. "Don't hang up", "don't tell anyone", "stay on the line" — each of those is the reason to hang up, not a reason to stay.
  2. Call back on a number you already had. Not the number that called, not a number the caller reads out. If there is no answer, call a second family member.
  3. Ask the code word and one small recent fact. Make a card now if you do not have one — it takes two minutes.

Money moves last, never first. No verification codes, no gift cards, no crypto, no "bail bond" wire, no matter who the caller says they are. Run the 60-second checklist if you are in the middle of one of these calls right now.

What the rules do and do not do

RuleWhat it coversDated source
FCC Declaratory Ruling (TCPA)An AI-generated voice is an "artificial or prerecorded voice" under the TCPA — AI voice robocalls fall under the same restrictionsAdopted 8 February 2024, effective immediately (FCC 24-17)
FTC Impersonation of Government and Businesses RuleBans impersonating government agencies or businesses in commerce; lets the FTC go straight to federal court to claw money backEffective 1 April 2024 (FTC rule page)
EU AI Act, Article 50Disclosure that you are dealing with an AI system; deepfake content must be disclosedApplies from 2 August 2026
EU AI Act, machine-readable marking + new prohibitionsSynthetic content marked in a machine-readable way; two prohibitions added by the Digital Omnibus on AIFrom 2 December 2026 (Regulation (EU) 2026/1744)

None of these stop the call from reaching you. Labelling duties bind lawful providers; a criminal ignores them. So an unlabelled voice proves nothing, and a labelled one proves only that someone complied. Treat the law as what happens after, and the code word as what happens during.

62.5 / 100

The AGI-2027 Thesis Tracker — our parent site scores the "AGI by 2027" predictions one by one against evidence. It is upstream of this page: every step up in generative capability is another step down for "I'd know my own child's voice".

Reading as of 2026-09-06; the parent site is authoritative. agiscorecard.com/progress-index

What would change this verdict

WatchFlip conditionStatus (2026-09-15)
Carrier-side detectionLive synthetic-voice warnings on ordinary consumer calls, deployed by default and relied on by law enforcement → "detection" becomes part of the defenceNo such default consumer deployment found
Official adviceFBI or FTC guidance moves from "verify by callback / code word" to "you can authenticate by voice" → this page is rewrittenGuidance remains verification-first
Provenance markingMachine-readable marking (EU, from 2 December 2026) actually surfaces in ordinary phone and video calls → a partial detection signal exists for compliant contentObligation dated, consumer-visible effect not yet demonstrated
Generative capabilityParent tracker moves materially upward → this verdict only gets stronger, never weaker62.5/100 (2026-09-06)

Frequently asked

Can you tell an AI voice clone by ear?

No, and trying to is the mistake. Voice cloning is built to defeat exactly the test you are running: does this sound like my son. Advice that tells you to listen for robotic pauses or odd breathing is advice that ages badly, because each model generation removes another tell. The defence that does not age is verification: hang up, call back on a number you already had, and ask a code word only your family knows.

What should I do in the first sixty seconds of a call like this?

Three things, in order. One: hang up. If the caller says do not hang up, that is the reason to hang up. Two: call back on a number already saved in your phone, not a number the caller gave you, and if that fails call a second family member. Three: ask the code word and one small recent fact only the real person would know. Do not send money, gift cards, cryptocurrency or a verification code before all three are done.

Are AI voice scam calls illegal in the United States?

Yes. On 8 February 2024 the FCC adopted a Declaratory Ruling confirming that an AI-generated voice is an artificial or prerecorded voice under the Telephone Consumer Protection Act, so AI voice robocalls are covered by the same restrictions, effective immediately. Separately, the FTC's Impersonation of Government and Businesses Rule took effect on 1 April 2024 and lets the Commission go to federal court directly against impersonation schemes. Neither rule stops a call from reaching you, so the practical defence is still verification.

Does the EU require AI content to be labelled?

Yes, from 2 August 2026. The AI Act's Article 50 transparency duties apply from that date: people must be told when they are interacting with an AI system, and deepfake content must be disclosed. Machine-readable marking of synthetic content follows on 2 December 2026, along with two new prohibitions added by the Digital Omnibus on AI, Regulation (EU) 2026/1744. Labelling duties bind lawful providers; criminals ignore them, so an unlabelled voice proves nothing either way.

What makes a good family code word?

Something no one can find online and everyone in the family can say under stress. Not a birthday, a pet's name, a school or an anniversary — those are reconstructable from social media, and the person cloning a voice has usually done that homework. A shared family memory works well: the tree in the old back garden, the floor of the first flat. Keep the answer short, agree a backup question, and never say the answer first on an incoming call.


Make a family code word card60-second checklistIs this a scam? 12 questions

Written by the AGI Scorecard editorial desk (about us). Not legal advice; rules are summarised, the linked originals govern. Last updated 2026-09-15.