Articles

Good AI vs. Bad AI: The Courts Just Took a Side

August 31, 2026
Author
Clarissa Cerda
Chief Legal Officer
colin-lloyd-SQZtpwXnY1Q-unsplash

Two federal courts sided with the AI that stops voice fraud — one calling the technology “inherently secure.” Pindrop cut the path the others now follow, and set the bar they must clear to walk it.

There are two kinds of artificial intelligence on a phone call now. One is working to confirm that you are who you say you are. The other is working to sound exactly like you, so it can rob you.

For years, that fight lived only in technology. This year it reached the courts — and the courts took a side.

They sided with the defense.

First, they had to bring to light a small problem with the law as written. Artificial intelligence can now copy a human voice from seconds of audio. A criminal can call your bank sounding like you, or call you sounding like your child. The only thing fast enough to catch the forgery is software that checks the voice in real time. Yet Illinois’s biometric privacy law, read literally, required that the software obtain the caller’s written consent before it could run the check. A fraudster will never consent to being caught. A law written to protect consumers would have protected the people robbing them.

What the courts decided

In May, the Third Circuit ruled in McGoveran that a company authenticating identity in financial transactions is a “financial institution” under the federal Gramm-Leach-Bliley Act, and therefore exempt from the Illinois law. The company the court was describing was Pindrop — the first to win that recognition at the federal appellate level. Last week, the Seventh Circuit followed that path in a second case, Cisneros. Invited to disagree, it refused to break ranks.

That sequence is the whole point. Pindrop did not ride a trend. Pindrop set the precedent — and when a second court faced the same question, it answered the same way.

To be precise, because precision matters here: this is not a Supreme Court decision. But two major circuits — one covering Delaware, where most U.S. companies are incorporated, the other covering Illinois itself — now agree, and none has ruled the other way. That is about as close to settled as federal law gets short of the Supreme Court.

The exemption is not a loophole. It is a higher standard.

To qualify, a company does not escape regulation — it takes on more of it. Gramm-Leach-Bliley binds a financial institution to its Safeguards Rule and its Privacy Rule: strict, auditable, examinable duties for how consumer data is protected. The right to skip a consent form is earned by accepting a standard far more demanding than any consent form ever was.

That is how Pindrop was built from the start — inside the framework that governs banks themselves, not adjacent to it. So when the court examined what Pindrop does, and how it is governed, it did not have to stretch. It recognized what was already there.

The courts understood the technology, too. Judges have recognized that one-way voice authentication — a system that confirms whether a caller matches the real customer, but cannot be reversed into a copy of their voice — is, in one court’s words, “inherently secure.” No one in security believes anything is unbreakable. But a signal that cannot be turned into a weapon is exactly the kind you want on the front line. That is the line between good AI and bad AI — and a federal court just put it on the record.

The door is open to all — but not everyone can meet the bar.

Pindrop authored the doctrine now spreading across the courts. Every provider that follows inherits a precedent with Pindrop’s name on it. And it does not stop at banking. Both courts turned to the Federal Reserve’s own rule — one that treats authenticating the identity of persons conducting “financial and nonfinancial transactions” as closely related to banking itself. Followed to its logic, the exemption looks first to what a company is — an institution bound by GLBA — before it weighs any single transaction as financial or not. Read that way, it reaches the authentication of identity for bank and nonbank institutions alike. Today the holdings rest on financial ground. Tomorrow the principle reaches identity itself — and Pindrop was there first.

Let others follow. That was always the goal — not to protect one company, but to make the protection durable for consumers.

But the door only opens for those who can meet the bar. This shield belongs to companies genuinely subject to those Safeguards and Privacy Rules — companies that have done the demanding, unglamorous work and can prove it to a regulator. For years, “we take security seriously” was a line anyone could say. These rulings turn it into a line you either clear or you do not.

Where this is going

Underneath these cases, something larger is moving.

For a generation, security worked like a gate: you proved who you were once, at the login or the start of a call, and were trusted until you left. That era is ending. Fraud today does not strike at the front door. It strikes in the middle of the conversation — a familiar voice, forty seconds in, talking a real employee into moving real money. A gate guards the door, not the conversation.

So the strongest security teams are shifting from gated security to continuous security — verification that does not stop at the threshold but listens for the length of the interaction. Today the question is simple: is the caller a person, and the right person? That is the protection Pindrop delivers now.

Real human, right human — and, tomorrow, the right bot. Pindrop sees it coming.

Security can no longer be bolted on after the fact. It has to be built in from the start — recognized by regulators, relied on by consumers, and strong enough to hold when the caller is a machine.

That is the standard Pindrop set out to build long before a court required it — and the standard the courts have now recognized. The institutions that saw it early, and built accordingly, are the ones consumers can trust today. The rest will spend the next few years catching up to a bar Pindrop helped set.

I am proud of what we built to get here. I am prouder of who it protects — you, on the other end of the line. A cloned voice tried to reach your money and failed. You will never know how close the call was. And you will never have to.

Good AI is winning. And this time, the law is on our side.

Clarissa

Digital trust isn’t
optional—it’s essential

Take the first step toward a safer, more secure future for your business.