Research Note

Voice Assistant Privacy Consent and Likeness Matrix

A voice interaction can involve the account holder, active speaker, bystander, recorded third party, person discussed, voice actor, person whose likeness is simulated, cu

Aug 4, 20262 min readBy Dalton Anderson
In this article

People and roles

A voice interaction can involve the account holder, active speaker, bystander, recorded third party, person discussed, voice actor, person whose likeness is simulated, customer, employee, child, reviewer, vendor, and downstream recipient.

Account-holder consent does not automatically resolve every person's rights or expectations.

Interaction path

Map microphone activation, wake or start state, visual and audible notice, background capture, audio transport, speech recognition, model processing, generated voice, transcript, logs, human review, retention, training or improvement use, sharing, deletion, and incident handling.

NIST's Privacy Framework supports lifecycle and affected-person analysis. It does not supply jurisdiction-specific consent.

Product evidence

The product record must identify the exact account, plan, application, voice mode, settings, retention state, data controls, and documentation date. Current product behavior cannot be inferred from the May 2024 GPT-4o demonstration.

OpenAI's GPT-4o System Card documents evaluated voice risks. A vendor evaluation does not certify a voice experience for a particular setting.

Likeness and impersonation

Naturalness, voice casting, voice cloning, similarity, authorization, deception, and disclosure are separate questions.

The FTC's voice-cloning record describes fraud and authentication concerns. The FCC's 2024 declaratory ruling concerns artificial or prerecorded voice calls under the TCPA. Neither source is a universal rule for every assistant interaction.

Decision matrix

The evaluator should record the setting, people, purpose, task, consequence, identity disclosure, capture indicator, allowed data, consent or other authority, interruption, correction, retention, access, training use, deletion, export, impersonation safeguards, accessibility, child and bystander treatment, and exit.

The result can be allow for the exact setting, modify the interaction, require qualified review, or reject.

Sources

Follow the evidence.

  1. June 2024 Recall updateblogs.windows.com
  2. Current Recall privacy and controlsupport.microsoft.com
  3. Current GPT-4o API documentationdevelopers.openai.com
  4. Manage Recall for Windows clientslearn.microsoft.com
  5. Recall security and privacy architectureblogs.windows.com
  6. GPT-4o system cardcdn.openai.com
  7. Spotify episodeopen.spotify.com
  8. Current Recall use and requirementssupport.microsoft.com
  9. OpenAI API deprecationsdevelopers.openai.com
  10. Introducing Copilot+ PCsblogs.microsoft.com

From this episode

Two useful next steps.

Evergreen · 1 min

AI adoption should start with bounded tasks and accountable review

Early AI adoption is most useful when a team chooses one bounded, reversible task, protects the data boundary, defines what a reviewer must check, and learns from observe

Article · 1 min

Microsoft Recall Privacy, Security, and Product Record

Trace Microsoft Recall from its May 2024 announcement through opt-in redesign, current local snapshot controls, managed-device policy, DLP, and residual risk.

Return to the episode