Voice biometrics identifies a caller by matching their voiceprint to a registered template, replacing security questions for routine verification. AI uses it as one factor in a layered identity stack, where lawful and where it actually adds signal. The legal frame (consent, retention, jurisdiction) and the AI-voice-cloning question both matter; the technology alone does not resolve either.

A bank customer calls. The voice AI greets them, listens for a few seconds, matches their voice against the enrolled template, and treats the call as authenticated to a routine level. The customer never had to recite an account number. The verification took less time than greeting the call took. The customer wonders briefly whether anyone else's voice could have done the same.

What people in the field are saying

Service Matters covers the contact-centre security question in "Is your contact centre a cybersecurity...", naming voice biometrics as an emerging factor that solves one problem (security-question friction) and introduces another (the cloned voice).

What does voice biometrics do well?

Replaces low-value-add verification questions. Removes the customer's need to remember account details. Works passively in the background as the call begins, so verification happens while the customer is talking about their actual problem. Improves with the customer's history (more calls means a more robust template).

Where does it not work?

Customers with a cold, unusual background noise, or speakerphone. Customers on a different phone than the one used for enrolment. First-time callers without a template. Customers who decline to enrol (some jurisdictions require opt-in). Each is a fallback path the system has to handle gracefully.

What about voice cloning?

A material risk and growing. Public voice samples are easier to obtain than ever (podcasts, videos, voicemail greetings). The clone quality is high enough to fool consumer-grade voice biometric systems some of the time. The mitigation is to use voice biometrics as one factor of several, not as a sole authentication method, especially for high-value actions.

What does the legal frame require?

Voice biometrics is biometric data and is regulated separately from other identity factors in many jurisdictions. Explicit consent. Defined retention period. Right to be deleted. Disclosure that the voice is being analysed, not just transcribed. The compliance frame is non-trivial; many deployments hit it after launch rather than before.

What is the practical pattern?

Voice biometrics as a low-friction factor for routine verification. Step up to a different factor (a code to a registered device) for high-value actions. Compliance sign-off on the enrolment, retention, and disclosure flow before launch. Treat voice cloning as a known risk and plan for it explicitly.

Related: how AI handles authentication, use case 7: authenticating a caller, and AI in regulated industries.