The Sound of a Voice Stopped Being Proof in 2023
A recording of your voice no longer establishes that you spoke. Marking rules are arriving in Europe, detectors are worse than the marketing suggests, and the layer that actually holds is a phrase your family agreed on before the phone rang.
By Chris Williams, Founder and CEO, Afterlife.ai™. Published July 30, 2026.
The call lands at eleven at night, because that is the hour when people are least able to think.
Your mother picks up and the voice is yours. Your name, your accent, the way you crush two words together when you are in a hurry. There has been an accident, or an arrest, or a payment that has to move in the next ten minutes. She has about three seconds to decide whether her son is on the line.
She will not be able to tell. On the research set out below, neither would you, and neither would a bank.
How to prove a voice recording is really me has become a question about records rather than sound, and the rest of this page is about which records hold up.
The other version of this points at you. A recording surfaces of you saying something you never said: a voice note to a colleague, a line from an interview you never gave, a sentence read aloud in a family argument as evidence of what you think of them. Now you are the one who has to prove a negative about your own mouth.
Both are the same problem wearing different clothes. For almost the whole history of recorded sound, hearing a voice was itself the proof, and that property has quietly expired.
Start building your legacy Free build, 50 memories, no card required.
Written by Chris Williams, Founder, Idy Pty Ltd, Afterlife.ai™. · Last reviewed: 29 July 2026
Proof Moved Out Of The Waveform And Into The Paperwork
To prove a voice recording is really you, five kinds of record can settle the question, in a bank's fraud queue or a courtroom or a family group chat, and none of the five is the audio.
A machine-readable mark on synthetic output shows a compliant generator produced the file. From 2 August 2026, Article 50 of the EU AI Act (Regulation (EU) 2024/1689) requires providers of AI systems generating synthetic audio to mark their outputs in a machine-readable format and make them detectable as artificially generated or manipulated. The mark fails when the generator is open-weights, offshore or non-compliant, or when the mark is overwritten.
Embedded provenance metadata, a C2PA hard binding, shows who signed the file and which edits happened. The metadata fails when a platform re-encodes an upload and silently drops the bundle.
A soft binding, meaning an invisible watermark or a perceptual fingerprint, lets a stripped credential be looked up again from a registry. Soft bindings fail under adaptive attacks and ordinary codec round-trips.
A dated consent record shows a named person agreed on a specific date. The record exists only if some platform captured and kept one.
A callback to a number you already had shows you reached the number on file for that person. Callbacks fail when the saved number is wrong, out of date, or diverted.
Four of those are engineering. The fifth is a phone number already sitting in your mother's contacts, and the phone number holds up best under attack.
Provenance is the verifiable history of a file: where the audio came from, what was done to it, who signed off at each step. The industry standard is the C2PA specification, whose consumer-facing label is Content Credentials, and the approach is unglamorous and sound. Take cryptographic hashes of the asset. Bind statements to those hashes, covering what device captured the audio, what edits were applied, whether a generative model was involved. Sign the bundle (C2PA Technical Specification 2.2, May 2025). Break the file and the signature fails. Nothing about the sound is trusted. Only the signed chain is.
The weakness shows up the moment you use a platform, because metadata rides alongside the file and platforms re-encode uploads. C2PA answers with soft bindings, so a credential stripped in transit can be recovered from a registry by watermark or fingerprint (C2PA Soft Binding API). That helps, and nobody should call the arrangement a guarantee, for reasons two sections down.
Authentication used to live in the sound of a voice. It now lives in the paperwork around a recording, and the cheapest layer in the whole stack is a phrase your family agreed on before the phone rang.
Proof is one corner of a larger question, which is who controls your identity, your face and your voice after you die. That page is the map, and this one takes the corner marked authentication.
A Bank Built Authentication On A Voice And A Journalist Walked Straight Through
In February 2023, the journalist Joseph Cox recorded five minutes of his own speech, generated a clone with a free consumer tool, phoned Lloyds Bank, and got through Voice ID by playing the synthetic audio down the line, including the enrolment phrase "my voice is my password". The early attempts failed. He got in after adjusting the cadence to sound more natural (Vice, 23 February 2023).
A bank had built an authentication product on the premise that a human voice is hard to forge. The premise had expired and nobody had told the product.
Your ear is no better than the bank's. In a study of 529 participants published in PLOS ONE on 2 August 2023, Mai, Bray, Davies and Griffin found that listeners correctly identified deepfake speech only 73% of the time when hearing clips one at a time, with overall accuracy in that single-clip condition at 70.35%, and brief familiarisation training improving accuracy by an average of 3.84% (Mai et al., 2023). The same listeners reached 85.59% when a real clip and a fake one were played side by side, and a scam call is never a side by side comparison. Judged one clip at a time, the way a phone call arrives, people were wrong more than a quarter of the time, and warning them first barely moved the number. That paper is three years old and the generators have improved since.
The input requirement collapsed as well. ElevenLabs' own developer documentation states that "less than two minutes of audio can produce a usable clone" (ElevenLabs voice cloning documentation). Two minutes is a voicemail greeting plus one short video somebody posted of you at a wedding.
Then the concession, because the headline numbers here are usually inflated. The FBI's Internet Crime Complaint Center recorded 22,364 complaints in 2025 that referenced AI, with adjusted losses of $893,346,472. Most of that money was investment fraud: losses in investment complaints with a reported AI nexus passed $632 million. Distress scams, the ones where a cloned voice pretends to be a relative in trouble, accounted for claimed losses of over $5 million in 2025 (2025 IC3 Annual Report, p.39). The cloned-voice call is a small share of a large problem, and the report gives no prior-year comparison for any of its AI figures, so anyone quoting you a growth rate for this specific scam did not get the number from the IC3.
A small share of a large problem is still the call that reaches your mother. Reducing how much of your voice sits in public is a separate job, covered in how to reduce the public sample of your voice.
Detectors Will Not Rescue You And Neither Will Watermarks
The market wants a button that says real or fake, and the evidence says no such button exists yet.
On Deepfake-Eval-2024, a benchmark built from deepfakes actually circulating on social media rather than from lab datasets, the area under the curve for open-source audio detection models fell by 48% against their scores on earlier benchmarks, and the researchers report that commercial detectors and fine-tuned models beat the off-the-shelf open-source ones while still falling short of the accuracy of deepfake forensic analysts (arXiv:2503.02857). Any website offering you a confidence percentage on an uploaded file is selling a number generated by exactly that class of model.
So if you need one specific file authenticated for a court case or a police report, instruct a forensic audio examiner, who is, on the benchmark evidence, still the most accurate option available.
Marking does not save you either, for a reason that is dull rather than technical. Article 50 binds providers and deployers who intend to comply. Somebody running an open-weights speech model on a laptop in a jurisdiction that has never heard of the AI Act marks nothing, and no marking rule reaches inside a live phone call, which carries no metadata at all.
Nor can anyone promise that a mark survives once embedded. Audio watermarks are attackable and the attacks are getting cheaper. In June 2026, researchers publishing as Ding and colleagues demonstrated adaptive attacks that drove watermark detection rates below 10% for replacement and creation, and to zero for removal, across the schemes they tested (arXiv:2606.22310).
And there is no takedown button at the end of any of this. You can reduce the public sample of your voice, you can use the takedown mechanisms platforms provide, and depending on where you live you may have a publicity, personality or data protection claim. None of those prevents the copy from being made, and anyone selling you prevention is overselling.
From 2 August 2026 Synthetic Audio Has To Declare Itself In Europe
Article 50 creates a transparency duty rather than an ownership right, and the difference matters for what you can do with the rule.
Article 50(2) requires providers of AI systems generating synthetic audio, image, video or text to ensure the outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated" (Article 50). Article 50(1) requires that a person be told they are interacting with an AI system unless that is obvious to a reasonably well-informed person. Article 50(4) requires deployers of deepfake image, audio or video content to disclose that the content is artificially generated or manipulated. All of it in a clear and distinguishable manner, at the latest at the time of first interaction or exposure.
There are carve-outs. Assistive editing that does not substantially alter the input is out of scope, as is certain authorised law enforcement use, and artistic, creative or satirical work only has to disclose the existence of the synthetic content in an appropriate manner.
The teeth are in Article 99. Breaching Article 50 attracts administrative fines of up to EUR 15,000,000 or, for an undertaking, up to 3% of total worldwide annual turnover, whichever is higher (Article 99). The reach is in Article 2, which applies the Regulation to providers and deployers established outside the Union where the output produced by the AI system is used in the Union (Article 2). Read this in Sydney or Chicago and the tools you use are still likely to mark their output, because their vendors sell into Europe.
Two dates matter for marking specifically. The obligation applies from 2 August 2026. Under the AI Omnibus package provisionally agreed on 7 May 2026, providers whose generative systems were already on the market before that date have until 2 December 2026 to meet the Article 50(2) marking requirement, while every other Article 50 obligation applies from 2 August with no transitional period (Mishcon de Reya, May 2026). On 10 June 2026 the European Commission published the final Code of Practice on marking and labelling of AI-generated content. Signing the Code is voluntary, and the obligations it helps providers meet apply either way (European Commission).
What the Article buys you is narrow and worth having. Compliant synthetic audio declares itself, which makes an unmarked clip circulating on a European platform a question worth asking out loud. The Article does not decide who is allowed to copy your voice, and no version of the Article reaches the criminal calling your mother. Scope, deadlines and who carries which duty are set out in what Article 50 requires and who it binds.
Start building your legacy Free build, 50 memories, no card required.
Three Household Rules That Beat A Cloned Voice And They Cost Nothing
None of the three costs a cent, and together they defeat the attack that every provenance standard on earth cannot touch, because a live phone call carries nothing to verify.
Agree a verbal password. One short phrase, shared by everyone in the immediate family, spoken at the start of any call about money or an emergency. Not a pet's name, not a street you have lived on, not a school, not anything that sits on a public profile. Make it easy to say while frightened. If somebody who sounds exactly right cannot produce the phrase, the call ends there. The rule has to be absolute, because the whole design of a distress scam is to make insisting on procedure feel cruel.
Adopt a callback rule. No money moves, and no bank details or codes are read out, on a call that came to you. You hang up, you find the person in your own contacts, and you ring the number that was already there. Never a number the caller supplied. Caller ID authentication does not do what most people assume: in the FCC's own description, STIR/SHAKEN lets providers "verify that the caller ID information transmitted with a particular call matches the caller's real number" (FCC, Caller ID Authentication). That authenticates a number, not a speaker. The number can be entirely genuine and the voice on the line still fake.
Put the promise in writing and sign the page. One paragraph, printed, dated and taped inside a kitchen cupboard door: "I will never ask you for money, gift cards, cryptocurrency, bank details or verification codes by voice call or voice note. If a voice that sounds like me asks for any of those, it is not me. Hang up and call me back on the number in your phone." Signed, with the date under the signature. Excessive, obviously, and it converts a frightening argument at eleven at night into a piece of paper somebody can look at with the phone still in their hand.
Two additions worth ten minutes. Cut the public sample: unlist the wedding video, replace a recorded voicemail greeting with the carrier's default, think twice before uploading long unedited audio of yourself. And know that in the United States, calls using AI-generated voices count as "artificial" under the Telephone Consumer Protection Act, following the FCC's declaratory ruling of 8 February 2024 (FCC 24-17), which handed regulators a hook that did not exist before.
All three rules do the same job. Each replaces a judgement about how a voice sounds with a record somebody can check.
The Law Is Half Built So Keep Your Originals
Anybody describing the law here as settled has not read the docket.
In the United States, the Judicial Conference's Committee on Rules of Practice and Procedure, known as the Standing Committee, approved a proposed new Federal Rule of Evidence 707 on machine-generated evidence for publication on 10 June 2025, with a public comment period that ran from 15 August 2025 to 16 February 2026 (United States Courts). Publication for comment is an early step rather than adoption, and as at July 2026 the rule remains a proposal and is not in force.
The NO FAKES Act of 2026 (S.4591, 119th Congress) was ordered reported by the Senate Judiciary Committee on 18 June 2026 and still requires passage by the full Senate and the House. As at July 2026 the bill is not law (Congress.gov). Stage, carve-outs and what would change on passage are tracked in what the NO FAKES Act would create. Until a federal right exists the rights you can rely on are state ones, and they are uneven, so read which digital replica laws apply in your own state before assuming you have a claim.
The FTC's impersonation rule has covered government and business impersonation since it took effect on 1 April 2024 (FTC, 1 April 2024). The supplemental rulemaking that would extend the rule to impersonation of individuals, including AI voice cloning, was proposed on 15 February 2024 and has not been finalised as at July 2026 (FTC, 15 February 2024).
Europe has a second track running alongside the AI Act. Denmark notified amendments to its Copyright Act to the European Commission that would give people a consent right over realistic digital imitations of their personal characteristics, including voice, lasting 50 years after death, enforced through Digital Services Act takedown machinery. A European Parliamentary Research Service briefing published in January 2026 records the amendments as expected to enter into force in July 2026 (EPRS, PE 782.611).
While all of that grinds on, do the thing that holds whichever way the rules land: keep your originals. If you ever have to demonstrate that a recording is genuinely yours, the useful artefact is the untouched original file with its capture metadata intact, stored somewhere with a timestamp you did not control, alongside a note of when you made the recording and why. Copy the raw file off your phone before an app re-encodes the audio. Five minutes of work, and the closest thing to a chain of custody an ordinary person can build.
One Version Of Your Voice That Comes With Paperwork
Everything above is about proving a voice after the fact, which is the hardest possible time to start. The alternative is to build the record on the way in.
On Afterlife.ai™, a guide called Idy interviews you. Your answers become dated memories, captured under your account at a known time, and the concrete facts of your life come only from those memories, because the instructions behind the product forbid inventing what you never said. Your voice is cloned from recordings you make with the recorder inside the product, against dated consent on your named account, built only from those in-product captures rather than from audio harvested somewhere else. If you would rather run that interview on your own first, the method for interviewing yourself properly is written up separately.
Now the honest limits, from building this. Our records prove our own chain and nothing wider. They say this audio was recorded here, on this date, by this account, under this consent. They cannot authenticate a file that came from anywhere else, and they only help if a bank, a platform or a court asks you to produce them. We do not currently attach C2PA Content Credentials to exported audio, so a file that leaves the product travels as ordinary audio. And no consent record stops anybody cloning you from a podcast episode. What a consent record gives you is a dated, named counter-record on the day you need one.
Personas built this way carry a start date, dated source memories, dated consent on a named account behind the voice, and a named list of the people you chose. Every one of those is a record somebody can be asked to produce, and a scam call has none of them.
While you are alive, the only people who can reach your build are the people you name, and nobody is nominated by default. One limit to know before you choose: after release, the executor you appointed can invite further people, so appoint that person with that power in mind. Release runs through Executor Lock™, a seven day evidence-verified hold. A claim that you have died releases nothing on its own. Evidence has to be filed, a seven day window runs, and you are notified the moment a report is filed, with the closing date of that window, so a false claim can be challenged before anything opens.
The first 50 memories are free, no card, and the free build does not expire. That is the part of the pricing I would defend hardest. The worst version of this industry charges a grieving family at the exact moment they are least able to refuse. For what the paid options add later, the plans page sets them out.
The honest response to voice cloning is not to hide your voice for the rest of your life. Hiding does not work, the sample is already out there, and the people who love you are left guessing. Keep one version of your voice that comes with paperwork.
Start building your legacy Free build, 50 memories, no card required.
Questions Families Ask Before They Record Anything
Can I prove a recording of my voice is fake?
Not from the audio alone, and not with a consumer detector. Attack the file's provenance instead: where it came from, when it first appeared, who uploaded it, whether it carries any signed credential. Then produce your own originals with intact capture metadata for the same period. Courts and platforms respond to that record rather than to an argument about a waveform.
If I clone my own voice, am I making the problem worse?
Only if the clone comes without controls. The risk in voice cloning is an unconsented copy carrying no record of who made it or why. A clone you created yourself, from audio you recorded, with dated consent on your own account and a named list of the people you chose, is the traceable version of your voice. The unsafe copy is the one made without you.
Who owns my voice recordings and memories?
You do. Our terms say you keep ownership of your content, and give Idy a limited, non-exclusive licence to process and store that content solely to run the service for you, with no model training absent a separate agreement. Plan pricing lives on the plans page, because a stale number on an article page is worse than no number. You can delete individual memories whenever you like, and deleting your account removes your memories and your stored recordings. One gap, stated plainly: there is no one-click delete today for the cloned voice held at our synthesis provider, so that removal is a request to us rather than a button.
What happens if Afterlife.ai shuts down?
Take the export while you can. A data export in your account settings returns your profile, your memories and your chat transcripts as a JSON file, as often as you like. Two honest gaps: the export does not yet include your audio recordings, and we have not published a wind-down commitment covering what happens if the company closes. Ask this of every company in this category before you record anything with any of them, and treat a vague answer as an answer.
Sources
European Union. Artificial Intelligence Act, Article 50, Transparency Obligations for Providers and Deployers of Certain AI Systems. Regulation (EU) 2024/1689. Applies from 2 August 2026. https://artificialintelligenceact.eu/article/50/
European Union. Artificial Intelligence Act, Article 99, Penalties. Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/99/
European Union. Artificial Intelligence Act, Article 2, Scope. Regulation (EU) 2024/1689. https://artificialintelligenceact.eu/article/2/
European Commission. Code of Practice on marking and labelling of AI-generated content. Final version published 10 June 2026. https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
Mishcon de Reya. EU AI Act simplified: unpacking the AI Omnibus agreement of May 2026. Provisional agreement reached 7 May 2026; transitional period to 2 December 2026 for Article 50(2) marking by systems already on the market. https://www.mishcon.com/news/eu-ai-act-simplified-unpacking-the-ai-omnibus-agreement-of-may-2026
Federal Bureau of Investigation, Internet Crime Complaint Center. 2025 Internet Crime Report, "Artificial Intelligence (AI) Used in Cybercrime", page 39. 22,364 complaints, $893,346,472 in adjusted losses; investment complaints with a reported AI nexus over $632 million; distress scams over $5 million. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf
Mai KT, Bray S, Davies T, Griffin LD. "Warning: Humans cannot reliably detect speech deepfakes." PLOS ONE, 2 August 2023. 529 participants; 70.35% overall accuracy in the single-clip condition and 73% on deepfake clips; 85.59% in the paired condition; familiarisation improved accuracy by 3.84%. https://doi.org/10.1371/journal.pone.0285333
Cox J. "How I Broke Into a Bank Account With an AI-Generated Voice." Vice, 23 February 2023. Lloyds Bank Voice ID; roughly five minutes of the journalist's own speech; several failed attempts before the clone got through. https://www.vice.com/en/article/how-i-broke-into-a-bank-account-with-an-ai-generated-voice/
ElevenLabs. Voice cloning: how it works. Developer documentation, checked 30 July 2026. "Less than two minutes of audio can produce a usable clone"; voice captcha "cannot guarantee that the provided recording truly belongs to the requester". https://elevenlabs.io/docs/eleven-api/concepts/voice-cloning
Coalition for Content Provenance and Authenticity. C2PA Technical Specification 2.2, May 2025. https://spec.c2pa.org/specifications/specifications/2.2/specs/C2PA_Specification.html
Coalition for Content Provenance and Authenticity. C2PA Soft Binding API, specification 2.2. https://spec.c2pa.org/specifications/specifications/2.2/softbinding/Decoupled.html
Ding W, Guo H, Duan R, Wang G, Wang Y, Chen M, Yan Q. "Learning to Evade: Adaptive Attacks on Audio Watermarking." arXiv:2606.22310, 21 June 2026. Detection below 10% for replacement and creation, 0% for removal, across two watermarking schemes and three voice datasets. https://arxiv.org/abs/2606.22310
Chandra NA, Lee H, Murtfeldt R, et al. "Deepfake-Eval-2024: A Multi-Modal In-the-Wild Benchmark of Deepfakes Circulated in 2024." arXiv:2503.02857. AUC down 48% for audio models against earlier benchmarks; commercial and fine-tuned models still short of forensic analysts. https://arxiv.org/abs/2503.02857
Federal Communications Commission. Declaratory Ruling FCC 24-17, adopted 2 February 2024, released 8 February 2024. AI-generated voices in calls are "artificial" under the Telephone Consumer Protection Act. https://docs.fcc.gov/public/attachments/FCC-24-17A1.pdf
Federal Communications Commission. Combating Spoofed Robocalls with Caller ID Authentication (STIR/SHAKEN). Checked 30 July 2026. https://www.fcc.gov/call-authentication
United States Congress. NO FAKES Act of 2026, S.4591, 119th Congress. Ordered reported by the Senate Judiciary Committee 18 June 2026. Not law as at July 2026. https://www.congress.gov/bill/119th-congress/senate-bill/4591
Federal Trade Commission. "FTC Announces Impersonation Rule Goes into Effect Today", 1 April 2024. Government and business impersonation rule in force. https://www.ftc.gov/news-events/news/press-releases/2024/04/ftc-announces-impersonation-rule-goes-effect-today
Federal Trade Commission. "FTC Proposes New Protections to Combat AI Impersonation of Individuals", 15 February 2024. Supplemental rulemaking on impersonation of individuals not finalised as at July 2026. https://www.ftc.gov/news-events/news/press-releases/2024/02/ftc-proposes-new-protections-combat-ai-impersonation-individuals
United States Courts. Proposed Amendments Published for Public Comment. Evidence Rule 707 approved for publication by the Judicial Conference Committee on Rules of Practice and Procedure on 10 June 2025; comment period 15 August 2025 to 16 February 2026. https://www.uscourts.gov/forms-rules/proposed-amendments-published-public-comment
European Parliamentary Research Service. "The Danish approach to copyright and deepfakes: A model for the EU?" PE 782.611, January 2026. Consent right over realistic digital imitations of personal characteristics including voice, lasting 50 years after death, enforced through the Digital Services Act; expected to enter into force in July 2026. https://www.europarl.europa.eu/RegData/etudes/ATAG/2026/782611/EPRS_ATA%282026%29782611_EN.pdf
Afterlife.ai. Terms of Service. Checked 30 July 2026. "You retain ownership of all content, memories, media, and data you input into the Platform"; limited, non-exclusive licence to process, store and use content solely to provide the service. https://www.afterlife.ai/terms-of-service
How this page was researched
The legal claims come from primary sources: the text of Regulation (EU) 2024/1689, the European Commission's own publication of the Code of Practice on marking and labelling, the bill text and committee record on Congress.gov, the FCC's published declaratory ruling, the FTC's own press releases, and the United States Courts page for proposed rule amendments. The technical claims come from the C2PA specification, the vendor's own developer documentation, and peer-reviewed or preprint research, cited by identifier. Every claim about our own product was checked against the code that runs the product, and the limits stated above are the ones the code actually has. Where a secondary source was used, no primary text is public yet, which is the case for the AI Omnibus provisional agreement of 7 May 2026.
Unsettled, and treated as unsettled above: whether the Omnibus transitional date holds as agreed, whether S.4591 passes at all, whether the FTC extends the impersonation rule to individuals, whether Evidence Rule 707 is adopted, and how courts will treat machine-readable marks as evidence in practice. Watermark durability is contested rather than resolved, and detector accuracy on real-world audio is moving fast enough that the benchmark figures quoted above will date.
If you find something on this page that is wrong or out of date, tell us through the contact page and we will correct the page and reset the review date.
Last reviewed: 30 July 2026. This page carries live legal and regulatory claims, including the 2 August 2026 application of EU AI Act Article 50 and the status of S.4591, and is on a 30 day recheck cycle until those facts settle.