A recent warning from John Walter, President of the Contact Center AI Association, should make contact center AI buyers pause before treating biometric privacy as someone else’s legal problem.
Walter argued that plaintiff lawyers have found another way to identify potential targets for Illinois Biometric Information Privacy Act lawsuits. The post focused on BIPA cases alleging that voice AI tools in the call center capture voiceprints without proper consent.
Walter was careful not to endorse the merits of those claims. His point was more practical: plaintiff lawyers have become effective at using public information to create disputes over whether companies are capturing voiceprints. Walter framed the litigation risk in direct terms:
“I personally believe most of these cases lack merit. But, regardless, these plaintiff lawyers have a knack for creativity. And they are quite good at using publicly available information to create a ‘question of fact’ on whether voiceprints are being captured.”
That matters because BIPA exposure can be large, and factual disputes are harder to resolve quickly. If a court decides there is a genuine question over whether voiceprints are being collected, the case can move closer to a jury, increasing settlement pressure.
The warning lands at a sensitive moment. Earlier this year, a May wave of class actions targeted major technology vendors, including Amazon, Apple, Google/Alphabet, Meta, Microsoft, NVIDIA, Samsung, Adobe, and ElevenLabs. More recent claims against Walmart and Lowe’s have moved the same broad theory closer to customer service, contact center systems, and consumer-facing voice AI.
The May Big Tech Cases Were the Warning Shot
The May lawsuits focused on AI voice training and commercial voice systems. Plaintiffs included journalists, broadcasters, podcasters, actors, and audiobook narrators who alleged that their recorded voices had been used to train or develop AI voice models without the notice, written consent, and retention disclosures required by BIPA.
Those claims remain allegations. The companies have not been found liable. Yet the filings were important because they pushed BIPA beyond older disputes about fingerprints, time clocks, face scans, and authentication systems.
Voice AI changed the risk profile. A person’s voice can now be used in a customer interaction, converted into training data, analyzed for identity, reproduced synthetically, or transformed into a model input. That gives plaintiff lawyers more room to argue that a tool has crossed the line from ordinary recording into biometric processing.
The Big Tech cases were mostly about AI voice systems and model development. For CX leaders, the more important development is what happened next.
Plaintiff attention appears to be moving toward environments where voice AI is embedded into routine customer interactions. Contact centers are an obvious target because they combine recorded calls, automated voice systems, customer authentication, transcription, analytics, and third-party technology vendors.
Walter’s post sharpens that risk. The danger may not only come from what a company says in litigation. It may begin with what the company, its vendors, or its public materials already say about voice AI, call analysis, virtual assistants, authentication, training, and quality monitoring.
Walmart and Lowe’s Bring the Risk Into Customer Service
In August, plaintiffs accused Walmart of using an AI-powered customer-service phone system that allegedly created voiceprints from callers without BIPA-compliant notice, consent, and disclosure. Last week, Lowe’s faced a proposed class action over alleged voiceprint collection in customer-service calls.
The Lowe’s complaint frames the alleged issue as a customer-service infrastructure problem:
“Defendant systematically violated these protections by using its customer service telephone systems to collect or otherwise obtain callers’ voiceprints and voice-derived biometric information, and by disclosing those biometrics to vendors, without the disclosures, written releases, and consent BIPA requires.”
Lowe’s has not been found liable, and that quote is an allegation from a complaint. Still, the claim captures the operational risk now facing brands that deploy AI voice systems.
Many contact centers already disclose that calls may be recorded for quality, training, or monitoring. That may not answer the biometric question if a system also analyzes vocal characteristics to identify a speaker, authenticate a caller, detect fraud, route a call, improve a model, or create a persistent template. The Lowe’s complaint makes that distinction explicit:




