Why the Defense That Beat Facebook May Not Save AI Voice Cloning
For years, the winning move against biometric privacy suits was to argue the data could not identify anyone. Against a 2026 wave of lawsuits over voices scraped to train AI, that argument runs backwards, because identifying a specific person is the entire point of a voice clone.

For most of the last decade, Illinois's Biometric Information Privacy Act was a story about faces. The statute, which lets people sue over the capture of a biometric identifier without written consent and carries statutory damages of $1,000 for each negligent violation and $5,000 for each reckless or intentional one, produced enormous class actions over facial-recognition and photo-tagging features.
Then the most dangerous version of that theory, brought by people who never used the product at all, ran into its most serious obstacle. In 2026 the action moved somewhere new and more consequential: biometric identifiers used as training data for artificial intelligence.
The first and largest front is not the face. It is the voice.
The defense that stalled the last frontier
The turning point was Zellmer v. Meta Platforms, 104 F.4th 1117 (9th Cir. 2024). Clayton Zellmer had never used Facebook, but his friends uploaded photos of him, and Meta's tag-suggestion feature generated a “face signature” from them. He sued under BIPA on behalf of non-users.
The Ninth Circuit affirmed judgment for Meta, reasoning that a biometric identifier must be capable of identifying a specific person and that Meta's face signatures could not: they were transient, never stored, and could not be reverse-engineered back to a face. It separately held that Zellmer lacked Article III standing on his retention claim.
Two things temper that decision for anyone reading closely, and both matter here. Zellmer is Ninth Circuit authority, persuasive but not binding in the Northern District of Illinois, where the voice cases sit, and district courts remain split on whether an identifier must be capable of identification at all, with no Seventh Circuit ruling to resolve it.
The holding was also inflected by its facts, transient signatures that were never retained, unlike a voiceprint baked permanently into a commercial model. So Zellmer did not end the scraped-biometric theory. It handed defendants their single most powerful argument, that the data must actually identify a person, and left the plaintiffs' bar looking for an identifier that meets that test beyond dispute.
User-facing photo cases have continued in the meantime, including an August 2026 class action that seeks tens of billions from Apple over grouping in the Photos app. The change is not that faces are safe. It is that voice is an identifier whose entire purpose is to identify.
A wave built on the human voice
In May 2026, the Chicago firm Loevy & Loevy filed a coordinated set of nine BIPA class actions in the Northern District of Illinois against essentially the entire commercial AI industry at once: Adobe, Alphabet/Google, Amazon, Apple, ElevenLabs, Meta, Microsoft, Nvidia, and Samsung.
The named plaintiffs are not ordinary consumers. They are professional voice workers, among them the Chicago broadcast journalist Carol Marin, broadcast journalist Phil Rogers, podcast journalist Robin Amer, audiobook narrator Lindsay Dorcus, audio storyteller Yohance Lacour, voice actor Victoria Nassif, and journalist Alison Flowers, a group whose work has collected Pulitzer, Peabody, Emmy, and Edward R. Murrow honors.
The theory is voice, not face. The complaints allege that the defendants extracted the plaintiffs' voiceprints from publicly distributed recordings, their broadcasts, podcasts, and audiobooks, and used them to train commercial voice-AI systems that can clone a person's voice from a short sample, all without notice, written consent, or a published retention policy.
The class is defined around speakers “whose recorded voices are publicly distributed.” The ElevenLabs complaint, which runs to more than a hundred pages and pleads all five operative subsections of the statute, alleges that the harvested voiceprints were embedded in foundational voice-synthesis models powering a platform reported to generate more than $500 million in annual recurring revenue, and that there is no public mechanism by which the company deletes biometric data extracted from non-user training audio.
Each plaintiff, the pleadings state, “never consented, in writing, electronically, or otherwise.” With the whole AI industry named at once, these are not cases anyone expects to be quietly settled away.
This is a different animal from the earlier voiceprint cases, which targeted the capture of customers' and employees' voices in call centers and AI meeting assistants. Here the alleged violation is not a live recording but the use of already-public voices as training data.
Why the standard defenses fit this wave poorly
This is not simply the old theory with a new body part. On the three fronts that decided the face cases, the usual defense playbook fits awkwardly, which is what makes the voice wave worth watching regardless of which side you sit on.
The Zellmer defense runs backwards
Meta prevailed because its face signatures could not identify a specific individual. A voiceprint used to clone a particular person's voice is the opposite: its entire commercial value is that it reproduces one identifiable human's distinctive sound.
The very feature that let the face data fall outside BIPA, an inability to single out a person, is not available to a product whose purpose is to single out a person. Wherever a court adopts the identify requirement, it cuts for the defense on faces and for the plaintiffs on voice.
The non-user problem inverts into an advantage
In consumer biometric cases, defendants usually escape into their own terms of service: the user clicked “I agree,” which brings an arbitration clause, a class-action waiver, and a consent defense. These plaintiffs never used the products.
There is no account, no click, no contract, and therefore nothing to compel arbitration or to characterize as consent. What was a weakness in the scraped-face cases, the absence of any relationship, is here a clean path around the procedural tools defendants rely on most.
The class is narrow, identifiable, and high-value
The blockbuster BIPA classes have often swept in millions of residents. At $5,000 per intentional violation, a class of 6.5 million people implies exposure on the order of $32.5 billion, the same magnitude as the recent Apple Photos claim, and numbers that large invite a due-process objection that pushes courts and parties toward steep per-person discounts.
A class of professional voice workers whose recordings were commercially exploited is comparatively small, concrete, and well-documented. That helps on ascertainability and predominance, and it keeps the aggregate in a range a court is less likely to treat as annihilating, which can make each claim more, not less, valuable.
The defendants are not without answers
None of this makes the cases easy for the plaintiffs. The most serious defense borrows the very move that won Zellmer, but aims it at a different target. There, the fight was whether a face signature could identify anyone. Here, the fight is whether what actually ends up inside a trained model is a “voiceprint” at all.
BIPA lists “voiceprint” as a protected identifier, but a modern voice model does not tuck away a tidy template of each speaker. It distributes statistical patterns across billions of parameters, and a defendant can argue that this diffuse representation is no longer a biometric identifier tied to a specific person, closer to an accent absorbed by listening than to a stored template.
If that argument lands, the plaintiffs' identify-by-design advantage narrows: the finished product can clone a voice, yet the artifact the statute actually regulates may not be a voiceprint in the statutory sense. The defense fight will be over the definition of the identifier, not over whether a voice can identify.
There is a jurisdictional flank as well. BIPA protects Illinois residents and is generally applied to conduct that occurs primarily in Illinois. Defendants whose scraping and model training ran on out-of-state servers will contest whether the relevant conduct happened “in” Illinois at all, a question that has split BIPA rulings for years and that a nationwide training pipeline makes genuinely hard.
These are not throwaway defenses. They are the reason serious firms are litigating rather than settling, and the reason the outcome is far from foreordained.
The argument is already reaching new biometric identifiers
The training-data theory is not staying in one lane. On July 4, 2026, a separate complaint, Mettler v. Apple, No. 1:26-cv-07825 (N.D. Ill.), took the same underlying idea to a different identifier.
It alleges that Apple's Face ID does not merely map facial geometry, as disclosed, but captures iris and retinal scans, converts them into mathematical data sets, and uses machine learning to keep training its own algorithms, with the data locked in the device's Secure Enclave where users cannot delete it or stop the training.
Mettler is a different animal from the voice wave: it is a user case, with an Illinois class reported to reach millions of residents, so it carries the consent, arbitration, and large-aggregate questions the voice cases avoid.
But it matters as a signal. The organizing concept, biometric identifiers repurposed as perpetual AI training fuel that the subject cannot claw back, is being pointed at faces, eyes, and voices alike.
What the first ruling decides
For all its strengths, the voice campaign turns on a threshold question that no court has yet answered: is scraping publicly distributed audio a “collection” of a biometric identifier under Section 15(b) of the statute? The recordings were public.
The plaintiffs put them into the world themselves. Defendants will argue that lifting a voiceprint from already-public audio is not the kind of active capture the section was written to govern. Plaintiffs will argue that extracting a biometric identifier is collection no matter where the raw material came from.
The first motion-to-dismiss ruling on that point will do more than resolve one case. It will tell every other plaintiff and every un-sued company whether this lane is open.
What is clear now is that the center of gravity in biometric privacy litigation has shifted. The scraped-face theory that drove the last wave now carries a definitional vulnerability, while the same conduct applied to voice arrives with the one feature that vulnerability targets: an identifier that works precisely because it identifies.
The suits are only months old, they name much of the AI industry simultaneously, and they are being litigated by a firm that does this for a living. The companies already named are not likely to be the last, and the modality already extends past voice.
The question is no longer whether biometric-training-data claims have a theory. It is how far the theory travels, and the first judge to rule on “collection” will point the way.
See where the biometric-AI frontier moves next.
Rain maps emerging theories to the companies, industries, and modalities most exposed before the next complaint is filed. Book a 30-minute walkthrough.