AI-powered voice cloning technology is now so powerful that it is breaking sophisticated customer authentication systems, including those of several UK banks.
A BBC investigative journalist demonstrated the risk by successfully bypassing a bank’s voice ID system using sophisticated voice cloning software.
Shari Vahl of the BBC branch "You and Yours" came up with the idea after playing around with voice-cloning technology and being startled by its sophistication, noting colleagues struggled to tell the difference between the two voices.
She then wanted to see if it could convince security tech instead of just human beings and tested whether it could access her bank account's voice ID system.
Vahl used a recording of her AI clone saying, "My voice is my password," when calling up Santander and Halifax and being asked for her voice ID. Both attempts to access her account were successful.
Just in case the BBC studio-quality speakers, which Vahl used to play the AI voice, were a factor in her success, she also tried it at home using an iPad-quality speaker. It still worked.
This breach, achieved by replicating the nuances of a voice—including tone, pitch, and emotion—highlights the limitations of many current biometric security measures.
As voice cloning tools become more accessible, including through commercial services and the dark web, the threat to voice authentication systems grows.
OpenAI warned businesses about this earlier this year, asking them to phase out voice-based authentication. It also stalled the development of its Voice Engine solution, a voice cloning tool that produces natural-sounding speech that OpenAI says “closely resembles” the original speaker.
"We encourage steps like phasing out voice-based authentication as a security measure for accessing bank accounts and other sensitive information," OpenAI wrote in a blog.
The organization urged businesses to accelerate the development and adoption of methods for tracking the origins of AV content.

