The Rise of the Machine Caller: Stopping Voice Scams Without Blocking Every Bot
Cloned voices and scam bots now call contact centers. How to stop them without shutting out the few machine callers you want.

Cloning a voice used to take a studio. Now it takes a short recording, the kind anyone can find in a voicemail greeting or a video posted online, and an off-the-shelf AI tool. Running a scam script on a thousand calls used to take a call center. Now it takes a bot.
The phone is where accounts get recovered, payments get moved, and claims get filed, and it still trusts voices. That makes it the easiest place for a machine voice to do damage.
The Short Version
Machine voices are now a scam tool. A short recording is enough to clone a customer’s voice, and a bot can run a scam script on thousands of calls at once.
The phone has no liveness check. Voiceprints, security questions, and agents all ask whether this is the right person. Few ask whether it’s a person at all.
Check before you trust. Screen every call before it reaches authentication, or check on demand at the moments that matter, like a payment change or a password reset.
Be selective, not absolute. A few machine callers are welcome: agents you’ve approved, and people who speak through an assistive voice. Let those through on your terms, and question the rest.
Log every decision. When a call is blocked, challenged, or let through, you should be able to say why.
How Scammers Use Machine Voices
Cloned customers. A scammer calls your contact center in a policyholder’s voice to change a payout account, file a claim, or reset access. The agent hears the voice they expect.
Cloned colleagues. The same trick works inside the business: a call to the help desk in an employee’s voice asking for a password reset, or a call to finance in an executive’s voice asking for a payment. In 2019, the chief executive of a UK energy company wired €220,000 after a call in what sounded like the voice of the head of its parent company.
Scam bots at scale. Bots dial through phone menus looking for accounts, test stolen details against them, and now talk to agents in a voice human enough to get through, thousands of calls at a time.
The Phone Has No Liveness Check
Identity teams know this problem from onboarding. A photo of a face isn’t a face, so KYC added liveness: a check that a real person is in front of the camera, not a printout, a mask, or a deepfake.
The phone never got that check. Voiceprints, security questions, one-time codes read aloud, and the agent’s own ear all answer one question: is this the right person? None of them asks whether it’s a person at all. A clone answers the first question well, because it was built to. In 2023, a Vice journalist used a few minutes of recorded speech and a free AI tool to clone their own voice, then used the clone to get into their own bank account through its voice check.
So the first check on a call should be the one the phone never had: is a live person speaking, or a machine?
Not Every Machine Caller Is a Scam
If every machine voice were a scam, the answer would be simple: detect it and hang up. A few aren’t.
- Assistants working for your customers. Google’s AI has phoned businesses to book tables since 2018, and to check prices and availability since 2025. Consumer AI agents that run errands by phone are now arriving from the largest tech companies.
- Agents working for partners. Health care providers have used AI agents for years to call insurers about benefits and authorizations.
- People who speak through a synthetic voice. Some people with speech impairments call this way every day.
Blocking all of them shuts out customers, and people who most need a way in. So be selective:
- Approve agents; don’t guess them. Let in only agents that prove who they are, and give each one limits. An agent booking an appointment is not an agent changing bank details.
- An agent is never the customer. A legitimate agent says it’s an AI working for someone, and since August 2, 2026, the EU AI Act has required that people be told when they’re talking with an AI system. A machine voice that claims to be the customer isn’t an agent. It’s a clone.
- Question before you block. A keypad code or a callback gives a person using an assistive voice a way through, and stops a bot.
What Contact Centers Should Do Now
- Measure before you act. Screen in the background first, without changing any routing. Learn how many of your callers are machines, on which lines, and at what times.
- Check before you trust. Put the check ahead of authentication, so a clone doesn’t get the chance to pass a voiceprint or win over an agent.
- Alternatively, check on demand. Screening every call isn’t the only option. An agent who doubts a caller can press Check this call and see a verdict while the caller is still talking, and your flow can run the same check automatically before risky steps, like a payment change or a password reset. Tie checks to the action rather than to how a caller sounds, and log who asked for each one. Bots that work the phone menu never reach an agent, though, so only screening every call catches them.
- Keep the riskiest steps with a person. Let approved agents handle information and routine servicing. Payment changes always go to a person.
- Log every decision. Record the verdict, the reason, and the action for every call you check, so you can answer a customer, an auditor, or a regulator.
Why We Created BotBlock™
We started deetech™ to catch synthetic media in insurance claims: altered photos, forged documents, cloned voices. On calls, our voice work kept running into two problems.
- Detection has to happen during the call. A report after the call doesn’t stop a payout. The check has to run in the opening seconds, or at the risky step, before anyone acts on the voice.
- Blocking every machine voice is wrong. Some machine callers are customers’ assistants or approved partners, and some are people who need a synthetic voice to speak. A useful screen has to know the difference.
So we designed BotBlock™ to catch cloned voices and scam bots on live calls, and to let through only the machine callers you choose.
What’s in BotBlock™
Catch machine voices
- Three verdicts. Every checked call gets Human, Unknown bot, or Known agent from its opening seconds, with the reasons attached. A cloned voice is a machine voice, so it’s screened like any other.
- Every call, or on demand. Screen whole lines, or let agents press Check this call and trigger checks automatically before risky steps.
- Mid-Call Handoffs. Screening continues after hello and flags a person handing the call to a machine.
Choose the machines you trust
- The Known Agents Register. Agent builders register who runs each agent, what it’s for, and what it may ask for.
- Signed calls. Registered agents can sign their calls, so identity is checked, not guessed.
- Scoped access. Each agent’s limits travel with the verdict into your routing.
Decide what happens
- Policy Builder. Pick an action for each verdict, per line: continue, route, step up, or block.
- Challenges before blocks. A spoken question, a keypad prompt, or a callback to the number on file gives a person a way through.
- Screen Pop. Your agents see the verdict, and any agent’s limits, right on their screen.
Prove it, then plug it in
- Shadow Mode and Replay. Log every verdict without touching a call, and run past recordings to size your bot traffic before go-live.
- Every verdict, logged. Verdicts and their reasons stream to your SIEM, data warehouse, or webhook.
- No voiceprints. BotBlock™ doesn’t identify people or store voiceprints. It tells people from machines and names registered agents.
- Your platform. Native connectors for Twilio Flex and Amazon Connect, and anything else connects over SIPREC or the API. Connectors for more contact-center platforms are launching soon.
Where Identity Providers Fit
BotBlock™ is designed to sit next to identity verification, not replace it.
- Liveness for calls. You check that a real person is behind a selfie. BotBlock™ checks that a real person is behind a voice, on every call or whenever your risk rules ask.
- A step-up check for the phone. Your risk engine can ask for a check when a call reaches a risky step, the way it asks for a selfie when an app session looks wrong.
- It backs the checks you already run. A voiceprint or a spoken passphrase is only as strong as the assurance that a live person said it. BotBlock™ adds that check to the call.
- No biometric data added. BotBlock™ stores no voiceprints and identifies no one, so it adds no biometric data to your compliance scope.
- Verdicts as signals. Verdicts, reasons, and agent limits arrive through an API and an event stream, ready to feed the risk decisions your platform already makes.
- Next: vouching for agents. As more customers send AI agents to call for them, someone has to vouch that an agent acts for a verified person. Identity providers already know the customer. We’d rather build that link with you than around you.
If you verify identities for banks, insurers, or fintechs and want liveness on the phone channel, we’d like to talk. See how BotBlock™ works.
The Bottom Line
Machine voices have made the phone the cheapest place to run a scam. The answer isn’t to block every machine, and it isn’t to trust every voice. It’s to check whether a person is speaking before anyone acts on what they say, and to let in only the machines you’ve chosen.
Stop the machine voices you didn’t invite. Let in the ones you did.
Postscript: Meta’s Muse Starts Calling
Added September 27, 2026.
Meta launched Muse, its personal AI agent app, on September 8, and on September 16 began a beta that lets Muse call US businesses for its users: booking a haircut, checking stock, getting a contractor’s quote. The app logged about 730,000 US downloads in its first days, according to Sensor Tower data cited by TechCrunch. Instinct’s Concierge added phone calls the same week, and on September 24, Google began testing Gemini phone calls for US Pixel owners.
Muse’s first weeks showed how unready businesses are. Reuters reported on September 22 that businesses often hung up once they heard an AI; one Meta employee said their insurance company kept doing just that. Reuters also found that Meta had been testing a “human concierge,” in which a trained contractor, not the AI, placed some of the calls, and that Meta cited higher success rates for those calls. Meta rolled the test back after employees objected, saying the feature would return only with proper disclosures.
Here’s the scam risk. Once assistants like Muse are normal, “I’m an AI assistant calling for your customer” becomes the easiest opening line a scammer has. A business that can’t check it has two bad choices: hang up on real customers’ assistants, or believe anyone who says it. What tells them apart is proof: an agent you’ve approved, signing its call, working within the limits you set. See how BotBlock™ sorts callers.