the voice of customer experience technology
Front page
NewsContact Center1h · 09:01 BST · 7 min read

Voice AI Lawsuits Put Contact Centers on BIPA Watch

A recent warning from Contact Center AI Association President John Walter points to a sharper BIPA risk for voice AI. After May lawsuits against Big Tech and newer claims against Walmart and Lowe’s, contact center buyers need to know when call recording becomes biometric processing.

Voice AI Lawsuits Put Contact Centers on BIPA Watch

A recent warning from John Walter, President of the Contact Center AI Association, should make contact center AI buyers pause before treating biometric privacy as someone else’s legal problem.

Walter argued that plaintiff lawyers have found another way to identify potential targets for Illinois Biometric Information Privacy Act lawsuits. The post focused on BIPA cases alleging that voice AI tools in the call center capture voiceprints without proper consent.

Walter was careful not to endorse the merits of those claims. His point was more practical: plaintiff lawyers have become effective at using public information to create disputes over whether companies are capturing voiceprints. Walter framed the litigation risk in direct terms:

“I personally believe most of these cases lack merit. But, regardless, these plaintiff lawyers have a knack for creativity. And they are quite good at using publicly available information to create a ‘question of fact’ on whether voiceprints are being captured.”

That matters because BIPA exposure can be large, and factual disputes are harder to resolve quickly. If a court decides there is a genuine question over whether voiceprints are being collected, the case can move closer to a jury, increasing settlement pressure.

The warning lands at a sensitive moment. Earlier this year, a May wave of class actions targeted major technology vendors, including Amazon, Apple, Google/Alphabet, Meta, Microsoft, NVIDIA, Samsung, Adobe, and ElevenLabs. More recent claims against Walmart and Lowe’s have moved the same broad theory closer to customer service, contact center systems, and consumer-facing voice AI.

The May Big Tech Cases Were the Warning Shot

The May lawsuits focused on AI voice training and commercial voice systems. Plaintiffs included journalists, broadcasters, podcasters, actors, and audiobook narrators who alleged that their recorded voices had been used to train or develop AI voice models without the notice, written consent, and retention disclosures required by BIPA.

Those claims remain allegations. The companies have not been found liable. Yet the filings were important because they pushed BIPA beyond older disputes about fingerprints, time clocks, face scans, and authentication systems.

Voice AI changed the risk profile. A person’s voice can now be used in a customer interaction, converted into training data, analyzed for identity, reproduced synthetically, or transformed into a model input. That gives plaintiff lawyers more room to argue that a tool has crossed the line from ordinary recording into biometric processing.

The Big Tech cases were mostly about AI voice systems and model development. For CX leaders, the more important development is what happened next.

Plaintiff attention appears to be moving toward environments where voice AI is embedded into routine customer interactions. Contact centers are an obvious target because they combine recorded calls, automated voice systems, customer authentication, transcription, analytics, and third-party technology vendors.

Walter’s post sharpens that risk. The danger may not only come from what a company says in litigation. It may begin with what the company, its vendors, or its public materials already say about voice AI, call analysis, virtual assistants, authentication, training, and quality monitoring.

Walmart and Lowe’s Bring the Risk Into Customer Service

In August, plaintiffs accused Walmart of using an AI-powered customer-service phone system that allegedly created voiceprints from callers without BIPA-compliant notice, consent, and disclosure. Last week, Lowe’s faced a proposed class action over alleged voiceprint collection in customer-service calls.

The Lowe’s complaint frames the alleged issue as a customer-service infrastructure problem:

“Defendant systematically violated these protections by using its customer service telephone systems to collect or otherwise obtain callers’ voiceprints and voice-derived biometric information, and by disclosing those biometrics to vendors, without the disclosures, written releases, and consent BIPA requires.”

Lowe’s has not been found liable, and that quote is an allegation from a complaint. Still, the claim captures the operational risk now facing brands that deploy AI voice systems.

Many contact centers already disclose that calls may be recorded for quality, training, or monitoring. That may not answer the biometric question if a system also analyzes vocal characteristics to identify a speaker, authenticate a caller, detect fraud, route a call, improve a model, or create a persistent template. The Lowe’s complaint makes that distinction explicit:

“An ordinary audio recording preserves the sounds and words spoken during a call. Speaker and language recognition technology goes further by analyzing characteristics of the speaker’s voice and converting those characteristics into a mathematical representation or template that may be used to recognize, distinguish, identify, or authenticate the speaker.”

That is the line contact center leaders need to understand. The question is not simply whether a call is recorded. The question is what the voice stack does with the recording after capture.

Public Information May Become the Litigation Map

Walter’s post is especially relevant because it points to plaintiff lawyers’ use of public information. He did not disclose the third technique in the public post, noting that the Contact Center AI Association would cover it with members. But the broader warning is clear enough.

Companies can become easier targets when public materials create uncertainty over whether voiceprints are being captured. CX Today has already reported on the regulatory pressure building around customer emotion AI in contact centers, and the BIPA voiceprint cases add another reason for CX teams to understand exactly how AI systems interpret customer speech.

That public information may include privacy policies, product pages, vendor case studies, AI assistant descriptions, call recording disclosures, authentication language, chatbot terms, training statements, and references to speaker recognition or voice analysis. None of those materials automatically prove a BIPA violation. They can, however, help plaintiffs argue that a factual question exists. Walter explained why that matters:

“This is important because ‘questions of fact’ are decided by a jury. And the potential damages in BIPA cases are so large (up to $5k per call), that all these cases settle for significant amounts before a jury trial.”

For CX teams, that should trigger a practical review of how voice AI capabilities are described externally and governed internally. Marketing language that sounds harmless in a product context may look different when paired with call recordings, customer-service automation, and biometric privacy claims.

The risk also extends beyond a brand’s own website. Vendor documentation, implementation guides, procurement materials, and public case studies may describe features in ways that create ambiguity over whether the system identifies, distinguishes, or authenticates a caller through vocal characteristics.

Contact Center AI Now Needs Voice Governance

The stronger market signal is not that every voice AI deployment creates BIPA liability. Courts have already shown that outcomes depend on facts, geography, statutory exemptions, vendor roles, and the actual flow of biometric data.

A recent Seventh Circuit development involving Nuance, for example, showed that exemptions can narrow BIPA exposure in specific financial-services contexts. That does not remove the risk for retail, healthcare, recruitment, customer service, or general contact center deployments.

The buyer implication is more straightforward. Contact center AI governance now needs to include voice-specific questions.

Does the system create a speaker template? Does it authenticate callers using vocal characteristics? Does it identify or distinguish speakers? Does it retain voice-derived data? Does it share audio or biometric outputs with vendors or sub-processors? Does it use customer calls to improve AI models? Are disclosures aligned with the system’s actual behavior?

Enterprise teams should also review public language. If a company says it uses AI voice tools, call analytics, virtual assistants, voice authentication, or automated quality monitoring, it needs to know whether those statements accurately reflect the underlying technology.

The May Big Tech cases showed BIPA moving into AI voice training. Walmart and Lowe’s suggest the next pressure point may be customer-service infrastructure. Walter’s warning adds another layer: plaintiff lawyers may not need inside knowledge if public materials already create enough ambiguity to survive early dismissal.

For contact center leaders, the operational question has changed. The enterprise now needs to know whether customer voices are being analyzed, transformed, stored, shared, or reused in ways that could be characterized as biometric processing.

rate this story
helps rank stories across CX Today
The discussion0 takes · attributed & checked

Does this reflect your experience?

opening the room…
Read nextordered by techtelligence · every pick explained
same beat · Contact Center

How Dr. Martens Kicked Its CX Strategy Into Gear

24 Sept 2026
same beat · Contact CenterISG, Telstra, Cresta, and ScorebuddyCX Expose AI’s Contact Center Test22 Sept 2026same beat · Contact CenterOracle’s Agentic AI Gamble: Replacing Human Support to Fund Data Centers16 Sept 2026