Google’s Phone App Now Flags Deepfake Callers, Using a Digital Handshake

  • AI, Tech
  • June 3, 2026
  • 0 Comments

MOUNTAIN VIEW, Calif. — The call came from the number of a contact saved in the phone, and the voice on the line sounded like that person, warm and familiar, asking for help with a payment that had gone wrong. On a phone running Google’s new caller verification, the app would have stopped the call cold: a warning banner explaining that the caller’s identity could not be verified, and that the voice may be synthetic. The feature, rolled out this week in Android’s Phone by Google app, is the first system-level defense against AI voice cloning to ship in a mainstream operating system.

The mechanism is a digital handshake. When a caller uses RCS, the modern messaging standard that carriers have been rolling out for years, the caller’s phone and the recipient’s phone exchange cryptographic confirmation of identity before the call connects. If the handshake succeeds, the call displays as verified. If it fails, or if the caller is not using RCS, the app flags the call as unverified and warns the recipient that an AI-generated impersonation is possible. The feature is on by default, which matters more than any single demonstration of the technology.

Voice-clone fraud has become one of the fastest-growing scams in telecommunications. Criminals capture a few seconds of a person’s voice from social media, feed it to a cloning model, and call family members, employees, or business partners pretending to be the victim. Losses have climbed for years as the tools have gotten cheaper and harder to detect, according to industry surveys and law enforcement warnings. Phone carriers have tried their own defenses, but they have been limited to blocking suspicious numbers, which does nothing when the number itself belongs to the victim’s contact list.

Google’s approach attacks the problem at a different layer. Instead of trying to detect whether a voice is synthetic, which becomes harder as the models improve, the phone verifies that the caller is actually who the number says they are. A deepfake can copy a voice, but it cannot complete a cryptographic handshake tied to a real device and a real subscriber account. The defense does not depend on detecting the fake; it depends on proving the real.

The limitation is reach. The handshake only works when both parties use RCS, and while carrier adoption has accelerated over the past two years, it is still incomplete. Calls from non-RCS numbers, which include landlines and users on older networks, cannot be verified, and the app will flag those calls rather than letting them through silently. Google’s design choice is deliberate: an unverified call is treated as suspect by default, shifting the burden of proof onto callers who cannot prove who they are.

That default position is the feature’s most consequential decision. Most phone security features are opt-in, and most people never turn them on. Google has made deepfake detection active for everyone, which means the protection exists without requiring users to understand the technology behind it. Security researchers said the default-on approach is the difference between a feature that exists in a settings menu and a defense that actually changes outcomes.

The move also gives carriers a reason to accelerate RCS deployment. The standard has been positioned as a messaging upgrade, a way to replace aging SMS with modern features like read receipts and high-quality media. Caller verification gives RCS a security use case that messaging alone never provided, and analysts said the feature could push carriers that have been slow to upgrade. The more phones connected via RCS, the larger the verified-call population, and the more effective the defense becomes for everyone.

Apple’s adoption of RCS in 2024 opened the door for cross-platform handshakes, and Google’s implementation is designed to work with any carrier and any RCS-enabled device. The standard’s governing body is the arbiter of the cryptographic details, which means the verification scheme is not a Google secret but an industry protocol. That matters for trust: a verification system controlled by one company would be hard for carriers to accept, while a protocol everyone implements benefits from the network effect.

The scam industry will not stand still. Fraudsters have already adapted to email filters, SMS blocks, and two-factor authentication, and they will adapt to call verification, likely by moving to channels the handshake does not cover, such as WhatsApp calls or video calls, where identity is established by account rather than by telephone number. Google’s answer is that the warning banner travels with the call, teaching users to treat unverified contact with suspicion regardless of the channel.

For now, the feature changes the default experience of receiving a call on Android: verified calls reassure, unverified calls warn, and the burden of proof has moved from the recipient to the caller. In a world where a stranger can sound exactly like your mother, that reversal is the point.

Related Posts

  • September 6, 2026
  • 7 views
Anthropic Moves Its IPO Filing to Late September

The bankers and lawyers running Anthropic’s initial public offering had told investors to expect the company’s registration documents as soon as this week. The calendar has moved. Anthropic now plans…

  • September 6, 2026
  • 6 views
OpenAI Quietly Revises GPT-6 Astra Scores After Launch

When OpenAI released GPT-6 Astra on Sept. 3, the launch post carried the usual furniture of a modern model debut: coding results, speed comparisons and a figure for how often…