AI Bot Calls, Impersonation, And Constitutional Rights To Privacy

Dr S.A.Thameemul Ansari

31 Aug 2026 8:00 PM IST

  • AI Bot Calls, Impersonation, And Constitutional Rights To Privacy
    Listen to this Article

    There was a time when an unsolicited telephone call was merely an annoyance. Today, it can be something far more disturbing. A machine that sounds like a human, knows something about you, speaks in your language, responds to your questions and, in some cases, can imitate the voice of someone you know can turn an ordinary telephone call into a powerful instrument of surveillance, manipulation, impersonation and commercial intrusion. An automated system can dial thousands of numbers, engage recipient in apparently natural conversations and collect information on a scale impossible for a human call centre.

    More troublingly, voice-cloning technology can make an artificial voice sound remarkably similar to an identifiable individual. A recipient may therefore be confronted not merely with an unwanted communication, but with a technologically manufactured representation of another human being. This context raises a fundamental legal question: When a machine can enter our most private communication space, imitate another person's identity, and exploit personal information. is India's existing legal framework adequate to protect the individual?

    Of course, India is not without regulation. The Telecom Regulatory Authority of India (TRAI) has developed a substantial framework for dealing with Unsolicited Commercial Communications (UCC), including auto-dialler calls and robocalls using artificial or pre-recorded voices. Its Customer Preference Registration Facility also allows subscribers to regulate preferences concerning voice calls, auto-dialler calls and robocalls. The regulatory framework therefore recognizes the problem of automated calling. But recognition of robocalling is not the same thing as regulation of AI-generated identity manipulation. A traditional robocall generally delivers a pre-recorded message. An AI voice system can potentially do much more. It can converse, adapt its responses, imitate a person's voice, extract information from the recipient, and create the impression that there is a real human being on the other end.

    The distinction is crucial. The problem is no longer simply: "Why am I receiving an unwanted call?" It is increasingly: "Who—or what—is actually speaking to me?" That question exposes a major weakness in the existing regulatory architecture. The most serious threat posed by AI voice technology is its capacity to collapse the distinction between a genuine speaker and a synthetic representation.

    Indian criminal law already contains provisions capable of addressing some forms of such conduct. Section 319 of the Bharatiya Nyaya Sanhita, 2023, for example, criminalises cheating by personation where a person pretends to be someone else or represents that a person is someone other than who that person really is. But this provision illustrates the larger problem. It is fundamentally a law designed around human deception. AI introduces a different intermediary: the person who creates, deploys, trains, commissions or controls the artificial voice may be physically absent from the interaction. The voice itself may be synthetic. The recipient may have no idea whether the caller is human, automated or an AI-generated imitation.

    Consequently, traditional offences may be available after deception has occurred, but they do not necessarily provide a comprehensive preventive regulatory architecture for synthetic voice impersonation. The constitutional dimension is even more significant. India's Supreme Court has unequivocally recognized privacy as a fundamental right under Article 21 of the Constitution. In Justice K.S. Puttaswamy (Retd.) v. Union of India, the Court recognized informational privacy as an important dimension of the right to privacy and emphasised the individual's interest in controlling the dissemination of personal information.

    The Court has also specifically recognized the privacy of telephone conversations. In its discussion of earlier precedent, the Supreme Court observed that telephone conversations constitute an important facet of private life and that interference with telephone conversations implicates Article 21. This constitutional recognition acquires a new significance in the age of AI. Privacy cannot mean merely that the State should not tap our telephone conversations. Privacy in the digital age must also mean that private individuals cannot be continuously subjected to technologically enabled intrusion into their personal communicative space without adequate legal safeguards.

    The mobile telephone has become an extension of the individual. It accompanies us at home, at work, while travelling and even during moments of personal vulnerability. A telephone call therefore does not merely enter a device. It enters a person's immediate sphere of attention. When an automated system repeatedly invades that space, the injury is not necessarily financial. It can be psychological, informational and dignitary.

    The concept of consent is central to India's emerging data-protection framework. The Digital Personal Data Protection Act, 2023 recognizes the individual's interest in protecting personal data while permitting lawful processing of digital personal data. The Digital Personal Data Protection Rules, 2025 were subsequently notified by the Ministry of Electronics and Information Technology, with substantive provisions being brought into operation through a phased framework.

    But consent must not become a legal fiction. A person who enters a website, downloads an application or purchases a product cannot reasonably be presumed to have consented to unlimited future telephone intrusion by automated systems. Nor should consent to receive one category of communication be transformed into permission for unrestricted profiling, behavioural inference or AI-driven conversational engagement.

    Consent must be specific, meaningful, informed and capable of withdrawal. Otherwise, the language of consent risks becoming nothing more than a convenient legal justification for technological intrusion.

    There is another dimension that deserves much greater attention. How did the caller obtain the telephone number? How does the system know the recipient's name? How does an AI caller know that the recipient recently purchased a particular product? How does it know the person's geographical location, professional position, financial interests or previous interaction with an organisation? The telephone number may be only the visible part of a much larger data ecosystem.

    Behind an apparently innocent automated call may lie databases containing names, telephone numbers, purchasing histories, behavioural profiles, inferred interests and other personal information. The bot call is therefore not merely a telecommunications problem. It is also a data-governance problem. It connects telecommunications regulation, privacy law, consumer protection, cybercrime, artificial intelligence governance and criminal law. That is precisely why a fragmented regulatory response may prove inadequate.

    India's constitutional jurisprudence has already moved beyond a narrow understanding of privacy. Privacy encompasses bodily privacy, informational privacy and decisional autonomy. The next logical question is whether privacy must also protect individuals against algorithmic intrusion into their communicative space. An individual should not have to constantly distinguish between a genuine human caller; a conventional pre-recorded message; an automated call centre; an AI conversational agent; an AI-generated impersonation; and a cloned voice designed to resemble a person known to the recipient. The burden of technological authentication should not be shifted entirely onto the citizen.

    If corporations and other entities possess the technological capacity to generate thousands of automated calls, they should also bear the corresponding responsibility to identify those calls transparently. A basic regulatory principle should therefore be simple: An AI-generated or automated voice call should be required to disclose, at the beginning of the interaction, that the recipient is communicating with an automated or AI system. The disclosure should not be hidden in terms and conditions. It should not be buried in an unreadable privacy policy. It should be audible, immediate and intelligible. A person has a right to know whether he or she is speaking to another human being. This is particularly important where the call concerns financial transactions, health, employment, education, government services, insurance, banking or other sensitive matters. AI voice cloning also forces us to rethink the legal status of the human voice. A person's voice is not simply sound. It can function as an identifier. It can communicate identity, emotion, authority, trust and familiarity. When technology reproduces that voice without permission, the issue is therefore not merely copyright or intellectual property. It may involve identity, dignity, autonomy and privacy. India urgently needs to examine whether unauthorised voice cloning should constitute a distinct legal wrong, particularly when the cloned voice is deployed for commercial exploitation, deception, harassment, fraud or manipulation.

    TRAI already provides mechanisms through which consumers can register preferences and complain about unsolicited commercial communications. That is valuable. But the regulatory model largely places the burden on the individual: Register your number. Change your preference. Block the caller. File a complaint. Report the communication. This approach becomes increasingly inadequate when AI enables millions of calls to be generated cheaply and rapidly. The citizen should not have to become the first line of defense against an industrial-scale technological system. The principle should be reversed: Those who deploy automated communication systems should bear the primary responsibility for ensuring that their systems comply with consent, identification, privacy and anti-impersonation requirements.

    The answer is not to prohibit AI voice technology.AI can legitimately improve customer service, accessibility, multilingual communication and public services. The objective should instead be responsible regulation. India should consider a dedicated legal or regulatory framework incorporating at least the following safeguards such as Mandatory AI disclosure, Prior consent, Easy withdrawal, Voice-cloning restrictions, Authentication, Traceability Audit trails, Special protection for valuable person, Platform responsibility, Effective remediation and others.

    The greatest danger is that the law will once again arrive after technology has transformed society. That has happened repeatedly in the history of technological regulation. The legal system first encounters a new technology as an inconvenience. It then encounters it as a social problem. Eventually, it discovers that the technology has altered the structure of rights itself. AI voice calls are approaching precisely that point. The issue is no longer whether an individual should be disturbed by an unwanted telephone call. The issue is whether technology can enter a person's private communicative sphere, manipulate identity, process personal information, and influence human decision-making without sufficiently strong legal restraints. That is a constitutional question. The Supreme Court has already told us that privacy is intrinsic to life and personal liberty under Article 21. The challenge now is to translate that constitutional promise into the technological realities of the twenty-first century.

    The emerging legal principle should be broader than simply a "right against spam." It should be a right to communicative autonomy. An individual should have meaningful control over: who communicates with them, why they are being contacted, what personal information is being used, whether the speaker is human or artificial, and whether the identity being presented is genuine. The telephone was once a tool through which people exercised communication. Artificial intelligence has transformed it into a potential instrument of automated persuasion. The law must therefore move from regulating merely the content of calls to regulating the architecture of automated communication itself. India does not need to wait for an epidemic of AI-enabled impersonation before acting. The technology has already arrived. The law must now catch up.

    India has taken important steps. TRAI's framework recognizes unsolicited commercial communication, auto-dialler calls, and robocalls, while the country's criminal law contains provisions addressing cheating by personation. The DPDP framework also represents an important development in the protection of personal data.

    But these measures were not designed around the full complexity of AI-generated voice interaction. The regulatory gap therefore lies not in the complete absence of law, but in the absence of a sufficiently integrated, AI-specific framework dealing with synthetic voices, automated persuasion, identity simulation, traceability and communicative privacy. That gap should concern every citizen. Because the next time the telephone rings, the question may not simply be:” Who is calling?" It may be: "Is there actually a person calling me at all—and why does the machine know so much about me?" In a constitutional democracy committed to dignity, liberty and privacy, that is a question the law cannot afford to ignore.

    Author serves as a Professor & Officiating Head, School of Law at Graphic Era Hill University, Dehradun. Views are personal.

    Next Story