I have never fully believed that my phone listens to me. I have also never fully stopped believing it.
That is an awkward position to hold for ten years, and I have held it comfortably. There was the evening I complained about my knee — out loud, in a kitchen, to one other human being — and then spent three days being shown braces and physical therapy clinics. I did not investigate. I did not audit my permissions. I filed it in the mental drawer marked probably not true, but it would explain a lot, and went on using the phone exactly as before.
What I never pictured was somebody walking into a small business — a florist, a roofer, a dentist — and saying: yes, that is precisely what we do, here is the invoice.
Three companies have now settled for $930,000 over the Federal Trade Commission's allegations that they sold exactly that. The part that stayed with me is not the pitch, extraordinary as it is. It is the paragraph at the end deciding where the money goes.
First, the part that is on the record
On August 27, 2026, the FTC finalized orders against Cox Media Group and two marketing firms it worked with. The agency's description is unusually plain: CMG Media Corporation, which does business as Cox Media Group, together with MindSift LLC and 1010 Digital Works LLC, "deceived customers by claiming they used a special algorithm to listen in on and detect pertinent conversations from smart devices in order to target ads to consumers within a specific geographic region."
The product had a name: Active Listening.
CMG pays $880,000; MindSift and 1010 Digital Works pay $25,000 each, a sum the FTC says "will be used to provide redress to CMG customers impacted by these practices." Two comments arrived on the proposal and the Commission voted 2-0 for final approval. The case file runs from that proposal on May 21, 2026 to a binding order logged August 27; the signed decision and order carries one date at the bottom, August 26, 2026. The Commission's notice published for comment says it stays in effect for 20 years.
Fix one thing in your head first. This is a consent order, not a verdict: CMG "neither admits nor denies any of the allegations in the Complaint," the standard price of settling. So — allegations, throughout. I will keep saying so, and you should keep hearing it.
The pitch, in their own words
The administrative complaint quotes the marketing copy, and the copy did not hedge. "We can identify buyers based on casual conversations in real time," the sales page said, before the flourish I still cannot believe somebody approved: "It may seem like black magic, but it's not — it's AI." The same document records the line that tells you they knew what they were selling. "Creepy? Sure. Great for marketing? Definitely."
The sales conversation, per the complaint, opened with a question: Where do you want us to listen? When small businesses pushed back — and some did — the company allegedly doubled down, naming Amazon, Samsung and Google as its sources, alongside numbers that sounded like engineering: "570 different data sources," and "voice related behaviors make up 40%-50% of behavior volumes we consume."
And what was in the box?
According to the complaint, the service "did not collect or use voice data in any manner." It was, the FTC alleges, "nothing more than consumer email list buying" — broker lists of people presumed to have the right interests, resold at a significant markup. The geography was allegedly fiction too: a business told it could reach consumers within ten miles of Orlando, Florida got nationwide lists, "with only a fraction of consumers located near the small business advertising customer."
The consent story is the part I would put on a poster. How had those households agreed to be recorded? Technically, by using their own devices — you "accept" terms when you set things up, "and those terms include allowing them to access your microphone." The FTC's reply is one of the cleanest sentences it has written this year: clicking through mandatory terms "does not constitute 'opt-in consent' for such an invasive service or for use of consumers' voice data from inside their homes."
The agency did not say the microphone theory was impossible. It said the consent was garbage. Which brings us to the sentence everyone quotes and nearly everyone bends: if it had actually worked as advertised, the FTC says, "this collection and use of consumers' voice data without adequate consent would itself violate Section 5 of the FTC Act." A conditional about a product that did not exist — not a holding that ambient ad-listening is illegal. Useful. Not a rule.
The two smaller firms drew a second count, for supplying the "means and instrumentalities" of the deception — and lawyers reading the file noticed what that meant. On Andrew Folks's reading at Frankfurt Kurnit, the vendors wrote the copy and ghostwrote the answers to skeptical prospects. Somebody was paid to draft the rebuttal to are you seriously telling me you record people?
Now read the paragraph about the money
So far, so good — a deceptive product, caught, priced, prohibited for twenty years. Then you reach the redress provision, and the story quietly changes species. The order requires CMG to hand over enough customer information "to enable the Commission to efficiently administer consumer redress to all purchasers of the advertising and marketing services subject to the misrepresentations identified in the Complaint."
All purchasers of the advertising and marketing services. The florist. The roofer. The dentist. The people who wrote the checks.
The Federal Register analysis calls the same group "those affected by the deception" — which here means the ones who signed the invoice. If direct redress proves impracticable, or money is left over, the Commission may apply it to "other relief (including consumer information remedies)," and "any money not used is to be deposited to the U.S. Treasury."
Why is that legally correct? Because the deception ran from CMG to its customers. Those businesses paid for a capability and got a mailing list — a measurable loss, provable from an invoice. The households in the pitch lost nothing you can put in a spreadsheet, because according to the complaint nothing was ever recorded. There is no injury to price.
And still. A company allegedly sold your kitchen as inventory, and told buyers that your tap on a terms-of-service screen was consent to be listened to at home. When the government finally priced that conduct, the whole fund went to the buyers. The broadcast trade press covered the August 28, 2026 payment the way you would cover a settled invoice; the radio and television business press ran it as a compliance item. Neither was wrong. That is genuinely what it was.
Why the lie was sellable in the first place
Here is the uncomfortable bit, and the reason I opened with my knee.
The pitch worked because a very large number of us — me included, in the drawer of things I never checked — already half-believe it. You do not have to sell a small business a capability it finds implausible; you sell it one it has already privately accepted as true. When 404 Media obtained the pitch deck and published it on August 26, 2024, two years before the FTC acted, the reaction was recognition rather than disbelief. Of course they are listening. We knew it.
And that belief has a property worth naming: it is aimed at the wrong organ. While we check the microphone, the machinery that actually profiles us runs in the open, unexamined, perfectly legal.
Australia gave the conduct a name. It has not yet swung the stick.
Now the comparison I found most clarifying — and it is not a story about anyone doing it better.
Australia's competition regulator gave it a name: AI-washing, which its industry snapshot — published in December 2025 — defines as "misleading or overstated claims about the functionality of a system's AI capabilities." Read that with Active Listening in mind. It fits like a glove.
Careful, though — the Australian Competition and Consumer Commission hedges the harm, and I will not un-hedge it. Such claims "may, in some circumstances, lead to consumer detriment," it writes, where a consumer might pay more for a product that purports to have AI functionality. May. In some circumstances. That is a regulator naming a risk it is watching, not announcing a campaign: its commitment is to "take action under the ACL where appropriate," which is not a docket number. And the priority list itself — the 2026–27 priorities chair Gina Cass-Gottlieb announced in Sydney on February 19, 2026 — never uses the words "AI" or "artificial intelligence" at all. Its nearest item is technology-neutral: "Manipulative and false practices and unsafe consumer goods in digital markets."
So what does Australia have that we do not? Three things, all architecture rather than enthusiasm. (Figures are Australian dollars.)
A stick of a different order of magnitude. For conduct on or after March 28, 2026, the maximum corporate penalty is the greater of $100 million, three times the benefit obtained, or 30 percent of adjusted turnover over the breach period. Against that ceiling, $930,000 is a rounding error.
A deliberate decision not to write an AI statute. Treasury reviewed the question and declined, concluding in October 2025 that the Australian Consumer Law is "broadly capable of adapting effectively to the increasing uptake of AI-enabled goods and services." Old law, new product — the same instinct behind Operation AI Comply, the 2024 FTC sweep launched on then-Chair Lina M. Khan's premise that "there is no AI exemption from the laws on the books."
And the one that reframes this whole article. Under the same review, Australia's consumer guarantees "will apply to a business transaction if the goods or services purchased cost less than $100,000" — so a small business buying an off-the-shelf AI service is itself a consumer, with rights it enforces directly. The review hedges that the law "may operate to protect small businesses," and I will not pretend that away. But the difference is structural: the florist would not be a claimant waiting on a regulator's fund, she would be a person with a remedy.
What Australia does not have is an AI-washing case. Its live AI matter is a different species: the ACCC took Microsoft to the Federal Court in October 2025, alleging it misled roughly 2.7 million customers about subscription options after folding Copilot into Microsoft 365 plans. Australia's public broadcaster ran it as a consumer story; Microsoft says "consumer trust and transparency are top priorities." Untested allegations — but note the difference. That is a real AI, allegedly sold badly. Ours, per the complaint, was never there.
One Australian case did end in a cell. The corporate regulator ASIC announced that Metigy's former chief executive — whose software was "marketed as using artificial intelligence" for small-business marketing — was sentenced to nine years' imprisonment. Not for the AI claim. For giving investors false information about revenue. Lie to the people who fund you and the state takes nine years of your life; overstate what your software does to the people who buy it, and nobody anywhere has gone to prison for it yet.
Now run it forward five years
Here is the version that keeps me up, and I do not think it is a stretch.
It is 2031. A vendor sells small businesses something called ambient intent. No microphone in the pitch — that fight is over, everybody knows it looks bad. Instead, a model that takes your purchases, your location trail, your searches and the same broker lists CMG was reselling, and infers what you were probably talking about last Tuesday. Then it sells that inference to the dentist two miles away.
And the pitch is entirely true.
That is the trap. This whole theory rests on falsity — the claims "are false or misleading," one count, three representations. A deception case needs a lie, and a true description of a genuinely creepy capability gives the agency no such handle. Verification gets harder too, exactly as the ACCC warned: by 2031 nobody outside the company can tell whether the model is a transformer or a lookup table with good marketing — not even the regulator, without a subpoena.
Just imagine the settlement that follows. Same shape. A number with six zeros, a twenty-year ban on repeating the sentence somebody got caught writing, and a fund distributed to purchasers. The people the system was pointed at get a line in an order. Again.
What the people who study this actually say
I have read across the spectrum here, because my argument has to survive people who think the FTC already does too much.
Start with the evidence on the belief. Academics spent a year testing it: a Northeastern team ran 17,260 Android apps — over 9,000 of which could reach the camera and microphone — and, as Kashmir Hill reported in 2018, "found no evidence of an app unexpectedly activating the microphone or sending audio out when not prompted to do so." Then notice what they refused to do: call that proof your phone isn't listening. The peer-reviewed study found something worse and less cinematic — third-party libraries that "record and upload screenshots and videos of the screen without informing the user and without requiring any permissions" — work later presented to the FTC itself at PrivacyCon. David Choffnes, who ran it and now directs Northeastern's Cybersecurity and Privacy Institute, has a whole talk on why it feels like your phone is listening when it isn't: "companies track your interests, connections, and even conversations in your household. That's how ads seem so eerily spot-on."
The Electronic Frontier Foundation names the mechanism that makes a microphone unnecessary: advertising IDs, it argues, "have become the linchpin of the data broker economy, and allow brokers and buyers to easily tie data from disparate sources across the online environment to a single user's profile." EFF would ban behavioral targeting outright. You may think that goes too far; it is at least aimed at the right organ.
Now the other side, which deserves a real hearing. Writing about the FTC's separate policy statement on AI accuracy, Daniel J. Gilman and Ben Sperry of the International Center for Law and Economics warn that cases built on contested readings of marketing language give AI companies "an incentive to tell us less, not more." From the R Street Institute, Spence Purnell and Adam Thierer make the structural version: Section 5 authority is broad, and in speech-adjacent territory that breadth carries "real dangers of censorial over-reach."
Both address a different proceeding, not this case. But they sharpen the real question — not should the FTC police AI claims but what is enforcement for. If the answer is only "make the buyer whole," we keep getting outcomes like this one.
And to be fair to this one: the households did get something. The order forbids all three firms, for twenty years, from misrepresenting the collection and use of voice data, whether consumers consented, and what their geographic targeting can do. Binding, real, and unpaid.
What does this mean for you?
Stop using "my phone is listening" as your shorthand for surveillance. It is the one claim that keeps losing on the evidence, and every time we reach for it, the machinery that actually profiles us gets a pass. Say "ad IDs and data brokers" instead — less cinematic, far more accurate.
Reset your advertising identifier and turn off ad personalization, on the phone and in your accounts. Ten minutes, buried in privacy settings. It will not fix the broker economy, but it breaks the thread stitching your profile together across apps.
Audit microphone permissions anyway. More than half the apps in that Northeastern sample could reach the camera and the microphone. No hot mics turned up — and there is still no reason a flashlight app needs either.
If you buy software for a business, ask about the data source, not the capability. Where does the data come from? What is the match rate? What share of a delivered list falls inside my radius? Then put the answer in the contract, as a promise you can enforce without waiting for a regulator.
If you were one of the buyers, go find out about the redress. The order requires CMG to give the Commission the customer information needed to administer it. That fund exists for you — and whatever nobody claims goes to the Treasury.
The lesson, as I see it
A company allegedly rented a belief it never had to build. The belief was already sitting in millions of heads — in mine, in the drawer — and the trick was noticing it did not need a microphone. It needed a sales page and somebody willing to write creepy? sure.
When the state answered, it answered in the only currency it had: the loss it could count. The florist gets a check; the household gets a promise.
My vote? Stop grading these settlements by the size of the number and start reading the paragraph that says who receives it. That paragraph is the real policy — it tells you whose injury the law can see. Right now it can see the invoice. It cannot see the kitchen. Until that changes, we will keep getting orders that punish the lie about the surveillance far better than they touch the surveillance itself.
Somebody you know still half-believes the phone is listening; somebody else is about to buy software on a promise they have no way to check. Send this to whichever one you like better. The HAIA Foundation spends its week on the gap between a claim and a capability, and it all lands here.




