12 terms

Trust, privacy and compliance

The obligations that arrive with a synthetic voice speaking on a company behalf. Dates matter more than definitions in this category, and several of them fall inside the next eighteen months.

AI disclosure and the EU AI Act

AI disclosure means telling people they are interacting with an AI rather than a human, and the EU AI Act turns that into a legal obligation in defined circumstances when its Article 50 transparency provisions become enforceable on 2 August 2026.

CCPA and CPRA

The CCPA, as amended by the CPRA, gives California residents rights to know about, delete, correct and stop the sharing of the personal information a business holds, and it asks whether that business disclosed and can service requests rather than whether it had a basis to collect at all.

Consent and call recording law

Consent in a voice deployment is three separate permissions, one to record the conversation, one to use what it produced and one to contact the person at all, and holding any of them does not grant the others.

DPDP Act

The DPDP Act is the Indian data protection law, built around consent as the principal basis for processing, which makes it narrower than GDPR in exactly the place most international deployments assume it will be looser.

GDPR

The GDPR is the European Union data protection regulation, and it sets the rules for collecting and using personal data about people in the EU no matter which country the organization holding that data is registered in.

HIPAA

HIPAA is the United States law governing the privacy and security of health information, and any voice AI vendor that handles patient information on behalf of a healthcare provider becomes a business associate directly bound by it.

PCI DSS

PCI DSS is the contractual security standard the payment card industry imposes on anyone who stores, processes or transmits cardholder data, and for a voice agent the compliant approach is almost always to make sure it never touches card details at all.

PII redaction and data residency

PII redaction removes personally identifiable information from transcripts and recordings, while data residency governs which country that data is stored and processed in, and both are standard enterprise requirements with specific consequences for a voice pipeline.

SOC 2

SOC 2 is an independent audit report, issued under the AICPA Trust Services Criteria, giving an auditor's opinion on whether the controls an organization has described are suitably designed and, in a Type II report, whether they operated effectively over a period.

TCPA

The TCPA is the United States law restricting calls and texts made with autodialers or with an artificial or prerecorded voice, and since a February 2024 FCC declaratory ruling it plainly covers AI-generated voices.

Voice biometrics and anti-spoofing

Voice biometrics identifies or verifies a person by the characteristics of their voice, and anti-spoofing is the countermeasure that tries to work out whether the voice on the line is a real person or a synthetic copy.

Watermarking of synthetic audio

Watermarking of synthetic audio embeds an imperceptible signal into generated speech so it can later be identified as machine-made, and it is the main technical answer to the question of how anyone will know what was synthesized.

Every entry is reviewed and dated. Browse all categories.