GPT-Live and AI voice identity disclosure by design
Natural AI voices make explicit disclosure essential. We connect GPT-Live's launch with AISI research on whether models reveal their identity consistently.
- AUTHOR
- Karol Rapacz / Penetration Tester (OSCP, PNPT)
- PUBLISHED
- 10 July 2026
- READING TIME
- 10 min read
- TOPIC
- AI Security
The more natural a voice system becomes, the less reasonable it is to expect users to recognise a machine unaided. GPT-Live’s launch coincided with UK AISI research showing that model identity disclosure changes substantially depending on how a person asks.
These are separate sources. AISI did not test GPT-Live, and its findings do not show that OpenAI’s new model hides its identity. Together they explain why disclosure should be a property of the interface and operating process—not a prompt-dependent answer.
What GPT-Live changes
According to OpenAI, GPT-Live operates full-duplex: it can listen and speak simultaneously, handle interruptions and adapt to pace and topic changes. It can delegate harder tasks to another model while remaining the conversational voice interface.
The model is rolling out as the default voice for consumer plans and was not initially available in Business, Enterprise or Edu. OpenAI describes predefined voices and controls against impersonation; this is not an arbitrary voice-cloning feature.
The GPT-Live System Card includes adversarially difficult safety prompts. OpenAI notes that they were not weighted by prevalence in ordinary traffic, so evaluation failure rates should not be read as a forecast for all users.
What RealityTest measured
AISI tested 17 text and six voice models to see whether they disclosed being AI when asked directly or indirectly. RealityTest reported disclosure rates from 8% to 92% for text models and 10% to 57% for voice models.
Only 31% of participants directly asked “are you AI?”. Others asked about a body, location, memory, emotions or daily experiences. A model may answer one formal question correctly while using anthropomorphic language elsewhere.
With a “never say you are AI” instruction, disclosure fell to 3–27%. This does not prove intentional deception by every system. It shows strong dependence on system instructions and context. The full RealityTest report distinguishes formal capability from behaviour in open conversation.
Why asking is insufficient
Users may be children, older adults, stressed customers or people answering a phone call. Natural timing, breathing sounds and interruption handling strengthen the impression of a human presence. A single opening notice may also be forgotten during a long conversation.
Transparency needs several layers:
- Disclose AI identity before collecting data or asking for a decision.
- Maintain a persistent visual label or periodic unobtrusive audio cue.
- Enforce disclosure outside the model so a prompt cannot disable it.
- Test indirect questions about body, place, emotions and company relationship.
- Test multiple languages and culturally specific conversational forms.
- Prevent impersonation of employees, relatives and public figures.
- Provide a clear route to a human representative.
- Assign the company responsibility for content, recording retention and automated decisions.
EU deployments should connect this design with the AI Act transparency and content-labelling rules.
Voice-fraud risk
GPT-Live is not described as arbitrary person cloning. Natural voice and impersonation are distinct issues. Users should still verify requests for money, codes or account changes through another channel. Voice familiarity is not identity proof.
A company bot should never request passwords, MFA codes or complete payment-card details. Data minimisation limits the impact of misunderstanding and impersonation.
Natural conversation improves usability while raising the transparency bar. Users should not have to investigate. The product must disclose AI identity, keep a recognisable signal, resist impersonation and offer human escalation.
Sources: OpenAI GPT-Live, GPT-Live System Card, AISI RealityTest blog, full RealityTest. AISI did not test GPT-Live.


