← All guides

They can clone your grandchild's voice. Here's what still works.

6 min read

AI voice cloning can reproduce a person's voice from a few seconds of recorded audio, which means recognising a familiar voice is no longer proof of identity. Reliable defences ask the caller to produce information rather than asking the listener to detect a fake.

For as long as impostor scams have existed, the defence has been the ear. You knew your grandson’s voice. Something in it would be wrong, and that wrongness would save you.

That defence is gone, and it is worth being blunt about why.

What the technology can do now

Modern voice synthesis needs only a few seconds of clean speech to produce a convincing imitation of a specific person. A birthday video, a graduation clip, a podcast appearance, a voicemail greeting — any of these is enough.

The result is not perfect, but it does not need to be. The script already explains away imperfection: the caller is crying, injured, on a bad line. Those details were in the script long before cloning existed, and they now do double duty.

What does not work any more

  • Recognising the voice. This is the whole point of the technology.
  • Asking something personal. Names, schools, pets and family details are widely available from social media and data breaches, and a prepared caller will have them.
  • Listening for hesitation. A caller who pauses is explained by distress; a caller who does not is explained by urgency. Either way you learn nothing.

What still works

The reliable defences share one property: they ask the caller to produce something, rather than asking you to detect something.

  1. A shared code word. The caller either has it or does not. Voice quality is irrelevant.
  2. Calling back on a number you already have. This routes around the caller entirely and reaches the real person's phone.
  3. Refusing the payment method. Gift cards, wire transfers, crypto and couriers collecting cash are not how bail, hospitals or lawyers are paid. The request itself is the evidence.

Talking about it without frightening anyone

This subject is often raised in a way that leaves an older relative feeling tested or patronised. It lands better as a family rule than as a warning aimed at one person: we all ask, we all answer, nobody takes offence. Framed that way it is a shared habit rather than an accusation of gullibility.

Common questions

Can AI really clone someone's voice from a short clip?

Yes. Current voice synthesis tools can produce a convincing imitation of a specific person from a few seconds of recorded speech, which is often available from social media videos or voicemail greetings.

How can I tell if a voice on the phone is AI-generated?

In practice you often cannot, and you should not rely on trying. Instead of judging the voice, ask the caller for something only the real person would have — an agreed code word — or hang up and call the person back on a number already saved in your phone.

Do personal questions protect against voice cloning?

Not reliably. Details such as pet names, schools, birthdays and family members are widely available from social media and data breaches, so a prepared caller can often answer them correctly.

What payment methods should make me suspicious?

Gift cards, wire transfers, cryptocurrency, payment apps, and couriers collecting cash in person. Legitimate bail, hospital and legal costs are never paid this way, so the payment method alone identifies the scam.