The Federal Trade Commission has locked in consent orders against Cox Media Group and two marketing shops that sold a story about AI that could hear living-room talk and aim local ads at it. The total is $930,000. The Commission voted 2-0 after two public comments on the proposed deals first announced in May.
What they sold was not what ran
The complaints said the companies told customers they used a special algorithm to listen in on smart devices, pick out useful conversation, and target ads in a defined area. The FTC’s account is simpler. The service was not built on voice data. Consumers had not opted into any such targeting.
That second point matters as much as the first. If the product had worked as advertised, grabbing voice from devices without adequate consent would itself have been an FTC Act problem. The Commission charged deception on the claims. It also flagged the consent hole that would have opened if the listening had been real.
“Active listening” has been a marketing phrase in ad tech for years. It sounds like a mic in the kitchen. What buyers often get is something closer to ordinary targeting dressed up as a miracle sensor. Here the agency says the miracle was the product. The voice layer was not there.
Why a CPO should care about a B2B lie
This is not a consumer class about Alexa. It is a vendor-to-marketer case. The people who paid CMG were businesses that thought they were buying conversation-based geo targeting. Privacy officers still inherit the fallout.
If your media plan or your agency deck still lists “active listening” or “device conversation signals,” pull the contract and the data-flow diagram. Ask what sensor, what legal basis, what opt-in, what retention. If the answer is a shrug and a case study, you are buying a claim, not a processing activity you can defend.
Voice is sensitive in every serious privacy statute even when it never reaches a courtroom. Selling the idea of voice without collecting it is still a deception problem. Collecting it without the consent you claimed is a different problem and a worse one. The FTC wrote both into the theory of this case.
The conduct bans in the orders are the checklist. Do not overstate qualities of the ad product. Do not misstate collection or use of voice. Do not invent consent. Do not puff geographic precision. Those sentences belong in vendor questionnaires and in the appendix of every DSP or local-media MSA.
What the orders do not do
Nine hundred thirty thousand dollars is not a market-changing fine for a large media group. It is a price for a specific set of claims the Commission was willing to settle. There is no industry-wide ban on using audio. There is no new AI statute. There is a public record that three firms sold listening they did not perform and consent they did not have.
Marketers who actually ingest device audio, call recordings, or in-store mics are in a different bucket. They need notices, a real opt-in where the law requires one, a map of processors, and a story that matches the SDK. The CMG matter is a warning about the sales layer. It is also a reminder that “AI-powered” does not excuse a targeting claim you cannot reconstruct from logs.
Practical next steps
Inventory any vendor that promises conversation, sentiment from speech, or smart-speaker adjacency as a targeting input. Get the architecture in writing. If voice never leaves the device, say so in the customer-facing description and stop using “listening” as shorthand. If voice does leave the device, treat it as a high-risk processing activity and prove consent, purpose, and deletion.
Train sales and agency partners the same way you train them on health and kids’ data. The forbidden sentence is the one that implies a microphone you do not run and an opt-in you cannot produce.
The FTC will keep using Section 5 on ad-tech stories that outrun the stack. This settlement is small money and a clean order. The expensive version is the campaign you cannot unwind because the targeting memo described a product that was never on.