Key Takeaways
- AI voice cloning can convincingly replicate a person's voice from just ten seconds of audio, and attackers increasingly use it to impersonate executives, employees, and trusted brands, not just consumers.
- STIR/SHAKEN confirms a signed, validated call's signaling path wasn't tampered with in transit. It cannot confirm the caller's identity or intent, and it does not guarantee that every part of the signaling path is trusted or that the caller is legitimate. A cloned voice on a legitimately assigned number passes it cleanly. It does not prevent all forms of spoofing, especially when calls originate from networks that don’t support STIR/SHAKEN or traverse legacy systems.
- Brands impersonated in AI voice fraud absorb reputational damage even when their own systems were never breached, including "collateral answer-rate destruction" as wary consumers stop picking up calls altogether.
- First Orion's Call Authentication goes beyond the STIR/SHAKEN mandate, powering verified identity and spoofed call blocking.
Why STIR/SHAKEN Can't Stop AI Voice Fraud
Businesses spent years meeting STIR/SHAKEN requirements to prove they were legitimate. That work is not wasted, but it is no longer enough. AI voice cloning has changed what "legitimate" means, and the compliance framework built for the old threat has no answer for the new one.
How Is AI Voice Fraud Changing Business Communications?
Voice fraud used to require effort: a scammer needed a script, a spoofed number, and some luck. AI removed the effort. Cloning tools can now replicate a person's voice with high accuracy from a sample as short as ten seconds, pulled from a social media clip or a recorded customer service call.
That capability has moved the threat well past the classic "grandparent scam." Banks, utilities, hospitals, and government agencies are now routinely used as cover stories in social engineering scripts, lending false credibility to scams that have nothing to do with the organizations themselves. Employees and supply chains are now targets too, not just retail consumers.
The scale is measurable. The FBI's Internet Crime Complaint Center tracked AI-related fraud as its own category for the first time in its 2025 Internet Crime Report, logging over 22,000 complaints and nearly $893 million in losses1, a figure that is likely conservative since AI involvement is only flagged when a victim recognizes it. Separately, global losses to robocall fraud topped $80 billion in 2025, and the FTC logged more than 2.6 million complaints about unwanted calls that same year2.
For the brand being impersonated, the damage does not stop at the fraud itself. Even when an enterprise's own systems were never touched, consumers connect the scam's harm to the brand the attacker claimed to represent. Wary consumers then stop answering calls altogether, so real fraud alerts and appointment reminders see their answer rates fall too. Regulators have noticed as well, and are pushing enterprises to authenticate caller intent before calls ever reach the network.
Why Can't STIR/SHAKEN Protect Against AI Voice Fraud?
STIR/SHAKEN was built to solve a different problem: number spoofing. It confirms that a signed, validated call's signaling path has not been tampered with in transit, essentially checking whether a caller has the right to use a specific phone number. That is a real and necessary function, but it stops there.
A cloned voice does not need a fake number to work. Attackers now rent clean, verified numbers and pair them with an AI-generated voice, and the call passes STIR/SHAKEN cleanly. The framework has no mechanism for evaluating who is actually speaking or what they intend to do once the customer answers.
“In legacy messaging environments, bad actors can imitate legitimate enterprises by manipulating sender names, message formatting, and visual details that appear authentic to consumers,” said Josh Whitehurst, Head of Product at First Orion, in RCR Wireless. “In voice, the risk is even higher. A scammer can take a customer service number from the back of a credit card, download a spoofing app, and quickly impersonate a trusted brand.
That is why identity at the exact moment of interaction has become so important. End-to-end call authentication combined with a branded caller ID protects against unauthorized use of business numbers. Authentication creates a protective layer around enterprise communications, removing an attack vector from bad actors attempting to impersonate legitimate businesses.
“Consumers are increasingly relying on visible identity cues to decide whether communication can be trusted,” said Whitehurst. “When a verified logo or authenticated identity disappears, the inconsistency becomes immediately noticeable. Fraudulent interactions stand out because they no longer resemble the trusted experiences consumers expect. Trust is becoming visual.”
How Does First Orion's Call Authentication Close the Gap?
First Orion treats STIR/SHAKEN as the floor, not the ceiling. Call Authentication is the core technology behind INFORM® Branded Calling with Logo and SENTRY® Call Blocking, and an added feature of INFORM® Branded Calling, and it works by verifying identity continuously rather than checking a box once at call setup.
It ensures your brand – business name and logo appear only on verified calls or illegitimate calls are blocked from reaching end-users. It means real-time risk assessment that evaluates dialing frequency, timing, and anomalies against an established baseline to flag risk before damage occurs. And for the highest-risk scenarios, it means challenging callers to confirm information only a legitimate representative would know, while verifying the caller is human rather than a synthetic voice.
This layered approach gives businesses something STIR/SHAKEN alone cannot: a business name and logo that appear only on calls fully verified end to end, with spoofed or illegitimate calls identified and blocked before they reach the customer.
The Bottom Line
AI voice fraud has outpaced the compliance frameworks built to stop it. STIR/SHAKEN still matters as a foundation, but it authenticates numbers, not people. Businesses that want to protect their brand and their answer rates need identity verification that operates in real time and travels with every interaction, not just a passport check at the border. That is what First Orion's Call Authentication is built to do.
Voice Cloning FAQs
Does STIR/SHAKEN protect against AI voice cloning? No. STIR/SHAKEN confirms a call's signaling path and that a caller has rights to a phone number. It cannot detect whether the voice on the call is synthetic or whether the caller's intent is fraudulent.
How much audio does it take to clone a voice? Voice cloning tools can now produce a convincing replica from a sample as short as ten seconds, often pulled from public social media content or a recorded customer service call.
What makes First Orion's Call Authentication different? It layers continuous, real-time verification, including number vetting, risk scoring, and caller challenges, on top of network-level authentication, then ties that verified identity to a business's name and logo through INFORM Branded Calling with Logo and SENTRY Call Blocking.
Does brand impersonation hurt companies that were never actually hacked? Yes. Consumers associate scam losses with the brand the attacker claimed to represent, which erodes trust and drives down answer rates for the company's legitimate outreach, even when its own systems were never compromised.
Learn About the Solutions Behind Every Trusted Connection
From small businesses to global enterprises, First Orion helps you increase answer rates, verify identity, and build customer trust and transparency.
INFORM® Branded Calling - Show your business name, logo, and reason for call so more customers answer with confidence.
ENRICH® Branded Messaging – Deliver personalized, secure RCS messaging with verified sender identity and rich media.
AFFIRM® Reputation Monitoring - Monitor how your outbound calls appear and catch labeling discrepancies fast.
SENTRY® Call Blocking - Block bad actors from spoofing your numbers, protecting trust with your customers.
PROTECT+ Risk Detection - Detect suspicious inbound call activity in real time with intelligent risk analysis.
Related Resources
Combating AI-Driven Fraud with New Call Authentication Standard
How First Orion’s Call Authentication Works
Your Phone Number is a Target. Here's How to Protect it.
Sources:


