Voice cloning technology crossed a specific, consequential threshold in the past few years: the amount of source audio needed to produce a convincing clone dropped from minutes to seconds. The scale of the resulting fraud problem is no longer speculative. In 2025, one in ten Americans had already experienced a voice-clone scam, and 70% of people said they weren't confident they could tell a cloned voice from a real one.
What ElevenLabs actually requires now
As the market-leading voice cloning platform, ElevenLabs' consent policy is worth examining in detail because it's become something close to an industry reference point. The platform requires users to record a specific verbal consent statement before it will clone a voice, and its Prohibited Use Policy (updated in September 2025) explicitly forbids replicating another person's voice without consent or legal right, using AI voices to harass or sexually exploit someone, or generating audio designed to deceive listeners about whether it's AI-generated. Beyond the recorded consent statement, ElevenLabs has implemented voice captcha verification, requiring the original speaker to provide real-time audio samples matching specific prompts to confirm the person granting consent actually owns the voice being cloned.
Why verification matters more than a policy statement
That verification layer is the meaningful part, a policy that simply forbids unauthorized cloning is easy to write and easy to ignore; a captcha that requires the actual voice owner to prove presence in real time is a genuine technical barrier, not just a terms-of-service line. It's worth being direct about the limit here too: this blocks the most casual misuse but not a sufficiently determined bad actor, which is exactly why the fraud numbers above remain as high as they are despite these safeguards.
Why legitimate use cases still matter alongside the fraud risk
The same underlying capability has real, consent-based legitimate uses that shouldn't get lost in the fraud coverage: audiobook narrators licensing their voice for translated editions, actors consenting to voice work for accessibility applications, and individuals losing their voice to illness banking a clone in advance. What distinguishes these from the fraud cases isn't the technology. It's explicit, verifiable, documented consent from the actual person, which is precisely the layer ElevenLabs' captcha system is built to enforce.
How this compares to the entertainment industry's own AI voice fight
The consent question isn't unique to consumer fraud. It's also the center of an active labor fight in entertainment. SAG-AFTRA's June 2026 TV/Theatrical Agreement extended prior AI and digital-replica protections, and California's AB 2602 requires explicit, informed, written consent before a studio can train a model on or deploy a synthetic version of a performer's voice. The union has already taken enforcement action on this: in May 2025, SAG-AFTRA filed an unfair labor practice charge after an AI voice replaced a union-covered role without notification or bargaining, a direct, real-world test of how seriously these consent requirements are being enforced outside the fraud context entirely.
The regulatory pattern taking shape
Between platform-level technical verification (ElevenLabs' captcha), industry labor agreements (SAG-AFTRA), and state law (California's AB 2602), voice cloning has moved faster toward concrete consent infrastructure than most other generative media categories, a dynamic worth tracking alongside our broader AI regulation landscape guide, precisely because the fraud and impersonation harm here is concrete and already measured, not speculative.
What to actually check before using a voice cloning tool
For any legitimate use, confirm the platform requires active, verified consent from the person being cloned (not just an uploaded audio sample and a checkbox) and treat any tool that skips real-time voice verification as a meaningfully higher-risk choice, for your own liability as much as anyone else's.
