# My bank wants my voice as a password. Is voice ID safe against AI cloning?

Source: https://forum.global100.org/q/my-bank-wants-my-voice-as-a-password-is-voice-id-safe-against-ai/
Site: Global 100 Forum, category AI voice and audio
Published: 2026-10-11. Updated: 2026-10-11. Replies: 3.

## Question by Jules, 2026-10-11

ok so this one is personal. my bank nags me to enrol in voice ID every time I call ("my voice is my password") and now the company I do contract audio work for wants a voice check to get into the payroll portal. two different places want my voice to be the key.

here is my problem. I have something like 400 hours of my voice on the open internet. every episode, every guest spot, clean studio audio with nothing under it. if someone wanted training material for a clone of me, I have basically published the dataset myself.

I remember the stories a couple of years back about reporters cloning their own voice to get into their accounts, but the bank says they have "liveness" and anti-spoofing now. is that real? can the system actually tell a cloned voice from a live human on a phone line, or is it mostly marketing? and is the fixed passphrase version any safer than the "just talk naturally" version?

I am not paranoid about this, I just want to know if I should say no, and what I should ask for instead. would love the security people's take.

## Reply 1 by Dan Okafor, 2026-10-11

My credit union describes the voiceprint as being like a fingerprint, over a hundred characteristics, unique to you. I enrolled last year and honestly it is a relief not to remember another PIN. I would assume the people building this have thought about cloning; it is their money on the line as much as ours.

Jules, your case is unusual because you have so much audio out there. For most of us there are maybe a few voicemails floating around. I would not lose sleep over it.

## Reply 2 by Sam Whitlock, 2026-10-11

The fingerprint comparison is marketing, and it points the wrong way for a threat model. A fingerprint is hard to collect without touching you. A voice is broadcast every time you open your mouth, and in Jules's case it is literally published with show notes. Biometric security rests on the sample being hard to obtain. Voice is the one biometric you hand out for free.

Anti-spoofing is a real research area, not pure vapour. There is a whole community building countermeasures, and they do catch a lot of synthetic audio. But it is an arms race with the generators, and the defender has to win on every call while the attacker only needs one. The fixed passphrase is marginally better because the attacker needs the words too, except everyone's passphrase is the same sentence and it is printed on the bank's website.

What to ask for instead: any factor you can revoke. You cannot rotate your larynx.

## Reply 3 by Tomas Reyes (staff), 2026-10-11

Treat voice ID as a convenience, not a security control. A cloned voice has already passed a major bank's voice authentication, and the raw material for a clone is any clip of you talking, which for a podcaster is unlimited. Decline where you can, and ask for a factor you can change, like an authenticator app or a hardware key.

The demonstration most people half-remember is Joseph Cox's ["How I Broke Into a Bank Account With an AI-Generated Voice"](https://www.vice.com/en/article/how-i-broke-into-a-bank-account-with-an-ai-generated-voice/) from February 2023. He recorded about five minutes of his own speech, built a clone on a free tier of a commercial voice service, and played the clips from a laptop into his phone. Lloyds Bank's Voice ID asked for his date of birth and then for the phrase "my voice is my password". It rejected the clone several times, then accepted it after he adjusted the generation settings, and he was into balances and transaction history. Lloyds said Voice ID is optional, that it sits inside a layered approach, and that it had not seen a real fraud case using synthetic voice. A social engineering specialist quoted in the piece recommended organisations move to multi-factor authentication instead. Both things can be true: the attack is rare today, and the control fails when it is tried.

On the supply side, the FTC's consumer alert ["Scammers use AI to enhance their family emergency schemes"](https://consumer.ftc.gov/consumer-alerts/2023/03/scammers-use-ai-enhance-their-family-emergency-schemes) puts it plainly: all a scammer needs is a short audio clip of someone's voice, which could come from content posted online, and a cloning program. Its advice for the receiving end is "don't trust the voice". That is good advice for a bank too.

Liveness checks exist and are improving, and Hana or Sam can say more about how they fail. The practical position: the bank one is optional, so decline it. For payroll, ask HR for an app-based code or a key, and ask what they do with the voice template and for how long. The [voice cloning thread](/q/how-do-you-tell-if-a-voice-recording-or-call-is-ai-cloned/) covers how little audio is needed.

---
Cite as: Global 100 Forum, "My bank wants my voice as a password. Is voice ID safe against AI cloning?", https://forum.global100.org/q/my-bank-wants-my-voice-as-a-password-is-voice-id-safe-against-ai/, accessed 2026-10-11.
