A study undertaken by the University of Melbourne and KPMG across nearly 35,000 employees from 47 countries, including South Africa, found that voice-based assistants like Siri, Alexa and Google Assistant were the second most-used category of workplace AI tool. And yet, existing privacy settings on these smart speakers and tools are not up to the right business standards, with many leaving the privacy door wide open. The risks include the collection of data without permission or knowledge, location tracking, unauthorised sale of information, and unfair discrimination through profiling.
Many of these devices are always listening and always on, waiting for an activation signal whenever their microphones and wake features are on, so a name made in passing that sounds close enough to a wake word will invite the tool into a conversation it shouldn’t attend. The challenge isn’t just transparency and access to data, but where that data is located and who has access to it. A recording is an asset with a long life, and it can sit in a cloud account that the business doesn’t control. Captured audio is also raw material for impersonation because a usable voice clone can be built from only a few seconds of recorded speech.
Whether activated by a name, a passing word or a phone call, the proliferation of these devices asks that companies start rethinking their internal perimeter. The office is now full of devices that can listen – from the assistant on the desk to the phone in the pocket – and each one widens the attack surface. Treating them as a harmless convenience is a mistake, because almost everything connected to the business carries an indirect security risk.
The recordings can contain business strategy, confidential pricing information, passwords spoken aloud, customer details or board discussions. If transmitted to an externally controlled account or cloud service, the information could leave systems that are governed by your business and its own access and retention controls. Under POPIA, personal information cannot be recorded and stored without permission, and an audio recording can create a new personal information record, even if it wasn’t planned.
Protecting against the influx of voice-activated tools comes down to discipline rather than technology. Companies need to develop policies around their usage, whether they are the obvious Alexa on the counter at the home office or a mobile device using a voice-activated assistant, so employees know what the rules are and how to protect business information. You need to keep always-on devices out of the rooms where sensitive matters are discussed and mute or physically disable their microphones rather than trusting a wake word to ensure they behave. Decide deliberately which assistants belong in the workplace at all, review their default privacy settings and treat every single one of them like a device that could expose anything it happens to hear.
The convenience part of the digital conversation is only as good as far as it doesn’t cross a security line. You need to know the devices will only listen when asked, where their data is stored, who has access to that data, and in which rooms these devices sit. Protecting the business means reducing the number of digital witnesses to your conversations with a clearly defined security policy and ongoing employee education. The voices are listening, after all.
