The technology behind the phrase "this call may be recorded"
Two court developments in August 2026 landed on opposite sides of the same question: when a contact center turns a caller's voice into a biometric identifier, who has to consent, and to what.
On August 4, two Illinois residents, Carol Krupke and Jeanne Thomas, filed a proposed class action against Walmart in the U.S. District Court for the Northern District of Illinois. The complaint alleges that when customers call a Walmart store, an AI system isolates vocal characteristics such as pitch, cadence, tone and frequency spectra to build a mathematical template of the caller's voice, then stores it for future identification. The suit claims Walmart never obtained the written consent Illinois' Biometric Information Privacy Act (BIPA) requires. It also argues that the standard "this call may be recorded for business purposes, including fraud prevention" disclaimer does not tell callers a voiceprint is being created, how long it is kept, or who else might receive it (Biometric Update, 2026; Bloomberg Law, 2026; ABA Journal, 2026).
Three weeks earlier, on a related question, the Seventh Circuit went the other way. In Cisneros v. Nuance Communications, decided August 28, the court held that Nuance's voice-ID service for Charles Schwab customers is exempt from BIPA because Nuance, in that role, qualifies as a financial institution's affiliate under BIPA's Gramm-Leach-Bliley carve-out. The plaintiff had standing to bring a consent claim, but the exemption ended it on the merits (Justia, 2026; FindLaw, 2026).
Neither case involves a novel technology. Vendors have sold voice biometric authentication into contact centers for over a decade. What changed is that two rulings, three weeks apart, mapped where the legal exposure actually sits: banks and their vendors may have a statutory shield that retailers do not.
What the technology does
Voice biometric authentication converts a caller's speech into a numerical template, sometimes called a voiceprint, built from physical and behavioral traits of how someone speaks rather than what they say. There are two deployment models. Active, or text-dependent, enrollment asks a caller to repeat a fixed phrase during setup, then checks that phrase on later calls. Passive, or text-independent, authentication runs continuously in the background of natural conversation, without asking the caller to say anything special. Retailers and banks generally use passive matching so the check does not add a step to the call.
Why contact centers adopted it
The alternative is knowledge-based authentication: date of birth, account number, mother's maiden name. Federal banking regulators have pushed institutions away from relying on it alone. Interagency guidance from the Federal Reserve, FDIC and other banking agencies specifically flags customer call centers as a risk area and says verification should not depend solely on knowledge-based questions, given how much of that information is now exposed in data breaches (Federal Reserve, FFIEC interagency guidance, 2021). Vendors pitched voice matching as a way to authenticate a caller without asking questions a fraudster might already know the answers to.
Where the legal exposure sits
Only three states currently have dedicated biometric privacy statutes that cover voiceprints: Illinois, Texas and Washington. They are not equivalent. Illinois' BIPA carries a private right of action with statutory damages, which is why nearly all the voiceprint litigation surfaces there. Texas's Capture or Use of Biometric Identifier Act and Washington's biometric law are enforced by the state attorney general only; individual consumers cannot sue directly under either.
BIPA also contains exemptions, and Cisneros shows one of them working as a defense: a vendor authenticating callers for a bank, in a role tied to financial transactions, can fall under BIPA's financial-institution carve-out. Walmart, authenticating retail customer service calls, has no comparable statutory exemption available to it. That is the practical distinction the two rulings draw, even though neither company disputes that voiceprints were created.
This is not a new fact pattern. In 2023, Whole Foods settled a BIPA claim for roughly $297,000 after distribution center workers alleged the company collected their voiceprints through Honeywell Vocollect headsets without the required consent (Hunton Andrews Kurth, 2023; Law360, 2023). The mechanism was employee headsets rather than customer calls, but the underlying complaint, generic notice standing in for specific biometric consent, matches the one now made against Walmart's call line.
What commonly goes wrong
The recurring failure in these cases is not the biometric matching itself. It is the disclosure. A recording notice satisfies wiretap and call-recording law in most states, but BIPA requires something more specific: written notice that a biometric identifier is being collected, a stated retention and destruction schedule, and consent before collection, not a general reference to "fraud prevention."
What to evaluate before deploying voice authentication
Buyers evaluating a voice biometric vendor for a contact center should confirm four things in writing: how consent is captured and whether it names the biometric collection specifically, what the published retention and deletion schedule is, and which jurisdictions the deployment touches, since Illinois, Texas and Washington enforce their statutes differently. They should also ask whether any statutory exemption plausibly applies to the specific use case. Cisneros shows that exemption is not automatic; it depends on the underlying transaction being financial in nature.
What to watch
Walmart has not yet responded to the complaint, and the court has made no findings on the merits. What happens next matters: whether Walmart raises a financial-institution-style defense, or the case proceeds to a direct ruling on whether a generic recording disclaimer satisfies BIPA's consent requirement, will affect more than one retailer's call centers.