The idea that a phone is secretly listening to everyday conversations has circulated for years. In August, the Federal Trade Commission finalized three orders involving companies that marketed something even more direct: an “Active Listening” advertising service said to use AI and conversations captured from smart devices to target local ads. The FTC says the service did not use voice data at all.
On August 27, 2026, the FTC announced final approval of consent orders involving CMG Media Corporation, which does business as Cox Media Group, MindSift LLC, and 1010 Digital Works LLC. The companies agreed to pay a combined $930,000: $880,000 from CMG and $25,000 from each of the two marketing firms. The Commission approved the final orders by a 2–0 vote after receiving two public comments.
This was not a trial verdict finding that the companies secretly recorded consumers. It was an administrative settlement of FTC allegations. The CMG final order states that the company neither admitted nor denied the complaint’s allegations except for facts necessary to establish jurisdiction. The resulting orders are nevertheless final and binding on the companies’ future conduct.
What the FTC alleged
The FTC’s original May announcement described marketing claims that the service listened for relevant conversations through smart devices, used a special algorithm to identify potential customers, and placed ads in selected geographic areas. According to the complaints, the actual service did not listen to voice data and did not accurately deliver the advertised geographic targeting. Instead, it consisted of reselling email lists obtained from other data brokers at a significant markup.
The FTC also alleged that the companies told prospective business customers that consumers had opted into Active Listening. The supposed consent was said to come from the terms people accept when they download and use apps. But the agency said the companies had not sought or obtained consumer consent for the advertised service. Its May announcement made the point plainly: clicking through mandatory terms of service does not amount to opt-in consent for an invasive service using voice data from inside a home.
That last point reaches beyond these three companies. Consent is not a label that can be attached to data after the fact. A business needs to know what people were told, what choice they were offered, what data practice the choice covered, and whether the product actually honored the resulting preference. A distant reference inside general app terms is not automatically evidence that a person knowingly agreed to an unexpected use of a microphone or voice data.
Why this is still a privacy case
It may sound strange to call this a privacy case when the FTC alleges that the advertised listening did not occur. But the deception itself concerned privacy. The product was sold by representing that intimate data could be captured and used, while the companies allegedly described consumers as having consented when they had not. If the service had operated as advertised, the FTC said that collecting and using voice data without adequate consent would itself violate Section 5 of the FTC Act.
The FTC Act gives the Commission authority to challenge unfair or deceptive acts or practices affecting commerce. In this matter, the final orders prohibit misrepresentations about the features of advertising services, the collection or use of voice data, whether consumers consented to the collection, use, or disclosure of voice data, and the geographic targeting capabilities of the services.
The CMG order illustrates that this is more than a direction to rewrite a sales page. It requires payment, compliance reporting, recordkeeping, and distribution of the order to relevant personnel. Its core obligations can remain in place for 20 years. The order also requires records supporting covered advertising representations, including evidence the company relied upon and material that may contradict or qualify those representations.
What product and development teams should learn
The first lesson is that marketing claims need a technical source of truth. If a sales deck says a system listens to voice data, targets within a defined location, uses AI to infer intent, or relies on consumer opt-in, a company should be able to map each claim to how the product actually works. Product, engineering, privacy, and marketing teams should review the same data-flow documentation rather than relying on separate stories.
Second, consent needs to be designed around the actual practice. Teams should document the exact disclosure presented to the consumer, when it appeared, whether the choice was optional, which data and purposes it covered, and how a withdrawal travels through the system. A generic representation that “users consented through app terms” should trigger questions, especially when the proposed practice involves microphones, homes, health information, precise location, or other sensitive contexts.
Third, vendor due diligence cannot stop with a polished demonstration. A business buying an advertising or AI service should ask what data powers the product, where it comes from, how consent was obtained, and what validation supports targeting claims. Developers integrating a vendor’s SDK or audience product should understand permissions, identifiers, and outbound data rather than assuming the product name explains the architecture.
Finally, adding “AI-powered” to a claim does not reduce the need for evidence. It may increase the need for careful explanation because customers and consumers cannot easily see what a model, algorithm, or data pipeline is doing. An AI label should describe a real function, not act as a substitute for verifiable product behavior.
What consumers should take away
People should not assume that a surprisingly relevant advertisement proves a microphone captured their conversation. Ad systems can make uncomfortable inferences using browsing activity, location, purchases, email lists, and information acquired from data brokers. At the same time, companies should not be free to market secret listening as a feature or claim that consumers agreed to it without evidence.
Consumers can review microphone permissions and privacy controls on their devices, question services that make unusually broad data claims, and report deceptive practices to the FTC. The larger lesson is that meaningful privacy depends on both sides of a representation: what the technology actually does and what the company tells people about it.
The FTC’s Active Listening orders are a reminder that privacy accountability is not limited to proving that sensitive data was collected. It also includes truthfulness about product capabilities and honesty about consent. For developers and businesses, the safest foundation is simple: know the system, document the claim, and never describe consent that the product did not actually obtain.
About Joseph Sides
Joseph Sides is a South Florida-based data privacy advocate, consultant, and entrepreneur whose work focuses on consumer rights, digital transparency, website tracking, meaningful privacy choices, and responsible technology. His public DEV introduction describes a bachelor’s degree in criminology, a minor in business, and training in data analytics. These interests connect questions about how technology operates with questions about what people understand and how organizations remain accountable for their decisions.
The educational purpose of these articles is to make privacy developments easier to follow and their practical implications easier to examine. That means connecting the language of laws and regulatory actions with familiar experiences: visiting a website, choosing an app, responding to a consent request, or trying to delete information. For developers, the discussion also considers how interface choices and data practices shape the choices available to consumers. The aim is informed understanding and thoughtful questions, with attention to both individual rights and responsible product decisions.
Educational Information — Not Legal Advice
This article provides general education and commentary, not legal advice. Joseph writes as a privacy advocate and consultant, not as an attorney. Reading this article does not create an attorney-client relationship, and the discussion is not a substitute for advice from a qualified attorney about your particular circumstances.
Laws, interpretations, applicability, exemptions, and deadlines vary by jurisdiction and can change. A requirement that applies to one organization or activity may apply differently to another. Readers should consult current primary sources and a qualified attorney when evaluating obligations, available rights, or a specific course of action. This article does not promise complete coverage, guaranteed outcomes, or personal legal guidance.
AI Disclosure
Prepared with AI assistance.
Top comments (0)