Skip to content

Regulatory Pulse

FTC finalises ‘Active Listening’ AI marketing orders: claims, consent and vendor evidence

The FTC’s final orders turn alleged false claims about AI-powered listening, consent and local targeting into a practical test for claim substantiation and vendor evidence.

United States
AI governance, advertising and vendor risk
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Final consumer-protection enforcement orders · Reviewed 28 August 2026 · 8 min read

The 60-second summary

On 27 August 2026, the Federal Trade Commission announced final approval of three consent orders concerning an “Active Listening” marketing service. The FTC alleged that Cox Media Group, MindSift and 1010 Digital Works falsely claimed the service used AI to identify conversations captured by smart devices, relied on consumer opt-in and delivered local audience targeting. The complaints say the service did not use voice data: it relied on purchased consumer email lists, and its location results did not match the claims. The orders require payments totalling $930,000, prohibit specified misrepresentations and impose long-running compliance and recordkeeping duties. The FTC also stated that collecting and using voice data without adequate consent would itself violate the FTC Act if the service had worked as advertised.

Timeline that matters

  1. 2023 to mid-2024

    Active Listening claims made

    The complaints allege that the respondents marketed the service using claims about voice data, AI, consent and local targeting.

  2. 21 May 2026

    Proposed settlements announced

    The FTC announced proposed consent agreements and opened the administrative settlement process.

  3. 26 August 2026

    Final orders issued

    The Commission issued final decision and order documents for all three respondents.

  4. 27 August 2026

    Final approval announced

    After considering two comments, the Commission announced its 2–0 vote to approve the consent agreements.

  5. Effective on publication

    Orders become binding

    Each order states that it is final and effective when published on the FTC website as a final order.

  6. 20-year order term

    Continuing compliance

    The core order obligations run for 20 years, subject to the extension provisions in each order.

What changed

The Commission moved three proposed administrative settlements to final orders. Cox Media Group must pay $880,000; MindSift and 1010 Digital Works must each pay $25,000, for a total of $930,000 that may be used for customer redress. The respondents are prohibited from misrepresenting the qualities or features of advertising or marketing services, the collection and use of voice data, consumer consent to collect, use or disclose voice data, and geographic-targeting capabilities. Each order also requires acknowledgements, a one-year compliance report, records supporting covered representations, retention of contradictory or qualifying evidence, and compliance monitoring. The central factual nuance is essential: the FTC alleges the service did not listen to consumers or use voice data; it resold purchased email lists while making claims about AI-powered voice analysis, consent and local targeting.

Who should pay attention?

Advertising and marketing service providers

Claims about AI, voice data, consent and local targeting must match the service actually delivered.

Brands, agencies and media buyers

Customers need evidence that vendors can substantiate data sources, permissions and audience accuracy before campaigns launch.

Data brokers and audience providers

List provenance, interest inference, matching and location quality require documented controls and accurate descriptions.

AI product and governance teams

The orders show that AI branding does not reduce the need to prove capabilities, limitations and data-use claims.

Privacy, legal, procurement and compliance teams

Vendor diligence should connect contract language, technical evidence, consent records, marketing copy and complaint handling.

What the guidance clarifies

The orders are final
The FTC announced final approval on 27 August 2026 after considering two comments; the three orders were issued on 26 August 2026 and are effective when published as final orders.
The alleged service did not use voice data
The complaints allege that the service was based on purchased consumer email lists, not conversations captured from smart devices.
The consent claim was also challenged
Because the service did not collect voice data, the alleged opt-in claims were not proof of consent for the advertised practice.
The FTC identified a counterfactual privacy violation
The agency stated that collection and use of voice data without adequate consent would itself violate the FTC Act if the service had functioned as advertised.
The remedies cover more than one campaign
The orders prohibit misrepresentations about service features, voice-data collection and use, consent, and geographic-targeting capabilities.
Settlement is not an admission of the allegations
Each respondent neither admits nor denies the complaint allegations except for facts needed to establish jurisdiction for the proceeding.

Global relevance — AI and privacy claims need traceable proof

Why this matters for global organisations

Claims about data-intensive products travel through vendors, resellers, sales teams and customer contracts. Organisations need a single evidence chain connecting what a service says it does, the data it actually uses, the permissions relied on and the results it can deliver. Unsupported claims create privacy, procurement, contractual and consumer-protection exposure even when the advertised data collection never occurred.

  • Treat product claims as controlled compliance artefacts, not only marketing copy.
  • Verify underlying data flows and permissions before repeating a vendor or reseller claim.
  • Keep technical testing, limitations and contradictory evidence with each approved representation.
  • Make white-label partners responsible for accurate downstream descriptions and change notices.
  • Investigate mismatches quickly and preserve decisions about suspension, correction and redress.

12 actions to start now

  1. Inventory marketing, audience, analytics and AI services that claim to use voice, device, behavioural, location or consent data.
  2. Require a named owner to validate every material product claim before it reaches proposals, sales scripts, websites or customer communications.
  3. Trace each claimed data type to its source, collection method, licence, consent signal, transformation and permitted use.
  4. Test whether audience lists, geofencing and model outputs perform within the stated geographic and technical limits.
  5. Prohibit teams from treating platform acceptance, device permissions or buried terms as proof of consent without supporting evidence.
  6. Review white-label and reseller arrangements so downstream claims cannot exceed what the underlying provider can substantiate.
  7. Add contractual warranties covering data provenance, consent, targeting accuracy, claim substantiation, audit rights and notification of material changes.
  8. Create a pre-launch review involving privacy, legal, procurement, security, AI governance and marketing owners.
  9. Retain the evidence supporting each representation, including tests, limitations, contradictory results, complaints and remediation decisions.
  10. Establish escalation routes for sales objections, customer complaints and signals that a service differs from its description.
  11. Reassess existing campaigns, suspend unsupported claims and provide accurate corrections or redress where specialists advise it is required.
  12. Test the control through sampling: select live claims, reproduce the evidence chain and compare delivery against promised outcomes.

Evidence worth retaining

  • Current inventory of AI, advertising, audience and analytics services, including white-label and reseller relationships.
  • Approved claims register linking each representation to an owner, evidence, limitations, review date and customer-facing wording.
  • Technical architecture and data-flow maps showing whether voice, device, behavioural, location or identifier data is actually collected or used.
  • Data-source contracts, licensing terms, provenance records and permitted-use restrictions.
  • Consent records and specifications showing the action, notice, purpose, data types, parties and revocation mechanism.
  • Geographic-targeting validation results, accuracy thresholds, exception handling and known limitations.
  • Model and algorithm documentation sufficient to support claims about inputs, outputs and capabilities.
  • Pre-launch approvals from privacy, legal, procurement, security, AI governance and marketing owners.
  • Copies of sales scripts, proposals, training material, websites and each materially distinct claim version.
  • Vendor due-diligence records, warranties, audit results, subprocessor disclosures and change notifications.
  • Complaints, objections, test failures, contradictory evidence, investigations, corrections and redress decisions.
  • Periodic sample-testing reports showing that delivered services match approved claims and contracted specifications.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Can each claim about AI, data sources, consent and targeting be reproduced from current technical evidence?
  • Does any team use device permissions, platform matching or general terms as a proxy for purpose-specific consent?
  • What personal data is actually used if the vendor’s headline description is inaccurate or incomplete?
  • Are data-broker lists and inferred interests described truthfully to customers and assessed for permitted use?
  • How is geographic accuracy measured, and what happens when lists fall outside the promised area?
  • Do white-label arrangements allocate responsibility for claims, evidence, complaints, corrections and redress?
  • Could a reasonable customer misunderstand a service name, demo or sales script even if a contract contains caveats?
  • What evidence would show that an asserted AI capability exists and performs as represented?
  • Which current campaigns should be paused or corrected while substantiation gaps are investigated?
  • Do applicable privacy, recording, biometric, communications or consumer-protection rules impose additional duties?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.