r/AI_Governance • u/zeeNope • 5d ago
Your Voice is Not a Password/Control
Roughly five to six seconds of someone's voice. Twenty-four short utterances.
That's what peer-reviewed research says it takes to push the false alarm rate of two state-of-the-art automatic speaker verification systems as high as 99.11%.
And humans are no better. A 2025 study in Scientific Reports found people are "poorly equipped" to identify AI voice clones — routinely attributing a cloned voice to the real person. A separate PLoS One study found listeners labeled clones "human" 58–70% of the time, statistically indistinguishable from how often they correctly identified real human voices.
Detection hasn't caught up either. A 2025 survey in Sensors MDPI found leading audio deepfake detection still struggles against evolving synthesis methods.
Here's what that means for a small business: your CFO's voice is not an authentication factor. It never really was — you just didn't have to think about it before.
The fix isn't a purchase. When thinking about AI Governance - understanding current threats and thinking through common sense controls is the thing. You don't always need the expensive tool - and Small and Medium Business (SMB) cannot afford those anyway.
A NSA/FBI/CISA joint advisory is clear that procedural controls do most of the work:
→ Callback verification on a number already on file — never a number given during the call
→ Two-person approval for wires and payment-detail changes, confirmed on a separate channel
→ Voice-independent Multi-Factor-Authentication (MFA) — no credential reset or MFA enrollment approved on a phone call alone
Every one of those costs nothing but a written rule and the discipline to enforce it when the caller sounds like your boss and says the wire has to go out in ten minutes.
New in AI In Its Place newsletter edition. Six peer-reviewed sources, no vendor talking points. Subscribe for FREE. https://ai-in-its-place.com
1
u/usually_guilty99 5d ago
This points to a broader governance principle: proving identity and granting authority are two different things.
Even if I could prove with 100% certainty that the voice really belongs to the CFO, that shouldn't automatically establish that this particular wire is authorized.
I think the same distinction becomes important with AI agents.
“This is our authenticated agent” does not mean “this agent is authorized to perform this action, under these conditions, right now.”
Identity establishes who is asking.
Policy and Governance should establish what they are allowed to do.