Your Voice Is No Longer Yours

I have been watching the conversation around voice cloning for the past few years, and most of it is focused on the wrong problem.

The fear is identity theft. Someone clones your voice, pretends to be you, and causes damage. That fear is not unfounded, but incomplete, and in its incompleteness, it has led us to build the wrong defenses and ask the wrong questions.

The real issue is this: your voice is intellectual property. And right now, there is almost no legal infrastructure to protect it.

Your Voice Is an Asset the Law Has Not Caught Up With

Think about what you have always been able to claim as yours. Your face. Your name. Your signature. Your likeness. The legal system, however imperfectly, has spent decades building frameworks around these. Publicity rights, trademark law, copyright, these exist because society recognized that your identity has value, and that value belongs to you.

Then AI arrived and created something the legal system had not anticipated: a digital self.

A version of you that can speak, respond, and act.

A version that can exist simultaneously in a thousand places.

A version that does not age, does not get tired, and does not need your permission.

Ownership problems require an entirely different set of solutions than identity theft problems. And right now, we are solving for the wrong one.

Three Cases That Show How Exposed We Already Are

By now, most people in business and tech have heard about Scarlett Johansson and OpenAI. The allegation was that a voice used in an AI product sounded strikingly similar to hers, close enough that she felt compelled to retain legal counsel. The company responded. The voice was pulled. But the deeper question was never fully answered: if a synthetic voice is not a direct copy but is clearly modeled on a specific person, who owns it?

The music industry has been wrestling with the same ambiguity. AI-generated tracks mimicking the vocal qualities of known artists began circulating on streaming platforms in 2023. Some were flagged, some were not. The artists themselves had no formal mechanism to claim those outputs as violations, because the law does not cleanly address the replication of a voice as a pattern rather than a direct sample.

And then there are the financial fraud cases. Executives at companies across multiple industries have received calls from people who sound exactly like their CEOs. In documented incidents, employees authorized wire transfers, disclosed sensitive information, and took consequential actions because they believed the voice on the other end was someone they trusted. The technology made detection nearly impossible in real time.

Each of these cases is being framed as a fraud or impersonation problem. We are looking at the surface when we should be looking at the structure.

The Question We Are Not Asking Yet

Right now, when we encounter a cloned voice, we ask: is this real?

That is the wrong question. The question that matters is: does this voice have permission to exist in this context?

Authentication tells you whether something is genuine. Authorization tells you whether it is permitted. We have built extensive systems around authentication: voice recognition, biometrics, and verification layers. We have built almost nothing around authorization.

Think about how we handle financial transactions. We do not simply confirm a transaction is real. We confirm it is authorized. There are protocols, verification layers, and liability frameworks built around that question. That ecosystem took decades to build. It still has gaps. But it exists.

We have nothing equivalent for digital voice. And the gap is growing faster than our awareness of it.

Every Executive Should Assume These Three Things

I work with organizations across industries, and when I raise this topic, I usually encounter one of two responses. Either the issue seems too abstract to act on, or there is a vague assumption that the legal system will catch up before it becomes a real problem.

Neither response reflects the actual risk environment in which we operate.

Here is what I tell every leadership team:

  • Your voice can already be cloned. A few minutes of publicly available audio is sufficient for current technology to produce a convincing replica. If you have given a keynote, recorded a podcast, or appeared in any recorded public forum, that material is accessible.
  • Your employees' voices can already be cloned. Anyone who has been on a recorded call, whose name appears in a company directory, or who has any kind of professional digital presence is potentially replicable.
  • Your customers' voices can already be cloned. If your organization uses voice authentication, that system is operating in a threat environment it was not designed for.

You cannot prevent cloning. The technology is too accessible, the audio materials are too available, and the gap between attackers and defenders is not closing fast enough.

The organizations that will navigate this well are the ones building systems designed to answer a different question: is this voice authorized in this context, at this moment, for this action?

That means multi-factor protocols for high-stakes communications, verification procedures that do not rely on voice alone, and internal cultures trained to pause when something feels off and empowered to ask a second question without embarrassment.

The Law Is Not Ready, and You Cannot Wait for It

Current law is not equipped for this.

The right of publicity protects against unauthorized commercial use of your likeness in some jurisdictions. Copyright protects specific recorded expressions. Neither captures the problem of a synthetic voice trained on your patterns and used to authorize transactions, influence decisions, or represent you in contexts you never consented to.

A handful of states have begun addressing deepfakes in specific contexts, primarily electoral content or non-consensual intimate imagery. Some countries are developing broader AI governance frameworks. But the gap between the pace of technology and the pace of the law is wide and will remain so for the foreseeable future.

Organizations cannot wait for regulatory clarity. They have to act ahead of it.

Three Questions Every Leadership Team Should Answer Today

The next generation of digital identity challenges will not require proving you are you, but proving that a digital version of you is authorized to act. That requires governance, not just verification.

Start here:

  • Do you have a policy for how your executives' voices and likenesses may be used in AI-generated content?
  • Do your employees know what to do if they receive a voice-based request to take a high-value action?
  • Do your authentication systems account for the possibility that voice alone is no longer sufficient evidence of identity?

Most organizations cannot yet answer yes to all three. That is the gap worth closing.

In the age of AI, hearing is no longer believing.

The organizations that understand this early will build the protocols that protect them. Those who wait will learn the lesson the hard way.

This is only a preview.

The deeper insights, including how AI reshapes education, finance, leadership, cybersecurity, and communication, are inside Neil's Substack, where policymakers, founders, and Fortune 500 leaders get strategies they won't find anywhere else.

Read Disrupting the Box on Substack
← Back to all articles