TL;DR
- Walmart deployed an AI voice system across 152 Illinois stores that collects, stores, and disseminates customer voiceprints without written consent.
- Plaintiff Amber Smith called her local Walmart three times (twice in December 2025, once in July 2026) and had her voiceprint harvested without disclosure or consent.
- The AI system greets callers with “your voice may be recorded for business purposes, including fraud detection” but never informs users that voiceprints are being extracted as biometric identifiers.
- Walmart violated every requirement of Illinois’ Biometric Information Privacy Act (BIPA): no written notice, no disclosure of retention/deletion schedule, no written consent.
- Voiceprints are as permanent and unique as fingerprints. Once collected, they can be used to unlock bank accounts and other sensitive services, creating massive identity theft risk.
- A federal class action seeks statutory damages for millions of Illinois residents whose voiceprints were unlawfully collected since the system’s deployment.
The automated greeting you thought was just “customer service efficiency” was actually a biometric data extraction operation. The full legal complaint is attached at the bottom of this article.
When You Called Walmart, They Took Your Voiceprint Without Asking
The Automation Bait-and-Switch
Every time Amber Smith called her local Walmart in Winnebago County, Illinois, she expected to reach a human being who could answer a simple question about an item she wanted to buy. Instead, she was greeted by an artificial intelligence voice system that delivered a rehearsed script: “Thank you for calling your local Walmart. We are open daily from [time] to [time] and this call and your voice may be recorded for business purposes, including fraud detection.”
What the AI didn’t tell Smith was that “fraud detection” meant extracting her voiceprint, converting the unique acoustic signature of her vocal cords into a permanent biometric identifier, storing it indefinitely, and potentially disseminating it to third parties. It didn’t tell her she could refuse. It didn’t tell her how long Walmart would keep her voiceprint or when it would be deleted. It didn’t ask her to sign anything. It simply took her voice and filed it away in a digital vault she cannot access, control, or erase.
Smith called twice in December 2025 and once in July 2026. Three calls. Three harvests. Zero disclosures. On July 6, 2026, she filed a federal class action lawsuit in the U.S. District Court for the Northern District of Illinois, alleging that Walmart Inc. violated every single requirement of the state’s Biometric Information Privacy Act.
The lawsuit seeks to represent millions of Illinois residents who, like Smith, called one of Walmart’s 152 Illinois store locations and unknowingly surrendered their biometric data to a corporation that prioritized cost-cutting automation over the informed consent required by state law.
The Legal Machinery: What BIPA Requires and What Walmart Ignored
Illinois’ Biometric Information Privacy Act, enacted in 2008, is one of the strictest biometric privacy laws in the United States. The statute was passed because state legislators recognized that biometric identifiers create permanent, unchangeable digital fingerprints that can be weaponized for surveillance, identity theft, and fraud. Unlike a stolen password or credit card number, a voiceprint cannot be reset. Once compromised, it is compromised forever.
BIPA defines a “biometric identifier” to include voiceprints, which are as unique as fingerprints, facial recognition templates, and iris scans. Many financial institutions now allow customers to unlock bank accounts over the phone using voiceprint authentication. The statute exists to ensure that private companies cannot harvest these identifiers in secret.
Under 740 ILCS 14/15(b), a private entity is prohibited from collecting, capturing, purchasing, receiving through trade, or otherwise obtaining a person’s biometric identifiers or biometric information unless it first completes three mandatory steps:
- Informs the subject in writing that a biometric identifier is being collected or stored;
- Informs the subject in writing of the specific purpose and length of term for which the biometric identifier is being collected, stored, and used;
- Receives a written release executed by the subject of the biometric identifier.
Walmart’s AI voice system completed exactly zero of these steps. The automated greeting mentions that “your voice may be recorded for business purposes, including fraud detection,” but this verbal disclosure does not constitute written notice under BIPA. The system does not disclose that voiceprints are being extracted, stored, or used as biometric identifiers. It does not disclose how long the data will be retained or under what circumstances it will be deleted. It does not provide a consent form. It does not give the caller an opportunity to opt out.
The complaint also alleges that Walmart violated BIPA’s retention and deletion requirements under 740 ILCS 14/15(a), which mandates that any private entity in possession of biometric identifiers must develop a publicly available written policy establishing a retention schedule and guidelines for permanently destroying the data when the initial purpose for collection has been satisfied or within three years of the individual’s last interaction with the entity, whichever occurs first. Walmart has published no such policy.
“No private entity may collect, capture, purchase, receive through trade, or otherwise obtain a person’s or a customer’s biometric identifier or biometric information unless it first: informs the subject in writing that a biometric identifier or biometric information is being collected or stored; informs the subject in writing of the specific purpose and length of term for which a biometric identifier or biometric information is being collected, stored, and used; and receives a written release executed by the subject of the biometric identifier or biometric information.”
β 740 ILCS 14/15(b), Illinois Biometric Information Privacy Act
The Non-Financial Ledger: Surveillance Disguised as Customer Service
Amber Smith did not lose money when Walmart’s AI system harvested her voiceprint. She did not suffer a physical injury. She was not denied a service or charged an unlawful fee. But the harm she experienced is real, and it is the harm that BIPA was designed to prevent: the loss of control over her own identity.
Voiceprints are not abstract data points. They are biometric keys that unlock access to sensitive systems. Smith uses her voiceprint to authenticate her identity when she calls her bank. If Walmart’s database is breached, or if Walmart shares her voiceprint with a third-party vendor, or if the data is sold to a data broker, Smith’s voiceprint could be used to impersonate her, access her financial accounts, or commit fraud in her name. Unlike a stolen credit card, which can be canceled and replaced, a stolen voiceprint cannot be changed. It is permanent.
The complaint describes Smith as “gravely concerned and upset about the collection of her biometric information, which she views as a form of surveillance without adequate consent.” She is “especially worried because she also uses her voiceprint to unlock other highly confidential services, like her bank accounts, which legally collect her voiceprint due to its ability to serve as a biometric identifier.”
This is the erasure of dignity that BIPA seeks to prevent. Smith did not consent to having her identity permanently cataloged by a corporation that prioritizes operational efficiency over privacy. She called Walmart to ask a question about a product. She did not volunteer to participate in a biometric surveillance program.
The lawsuit estimates that millions of Illinois residents have been subjected to the same unlawful collection. Walmart operates 152 stores in Illinois. If even a small fraction of customers called one of those stores during the system’s operational period, the scale of the privacy violation is staggering.
The “Fraud Detection” Loophole That Wasn’t a Loophole
Walmart’s defense is likely to hinge on the phrase “fraud detection.” The AI system’s greeting states that calls “may be recorded for business purposes, including fraud detection.” Walmart’s privacy policy defines personal information collected for fraud detection purposes to include “biometric information, such as voiceprints.”
The implication is clear: Walmart wants to argue that voiceprint collection is necessary to prevent fraud and that the verbal disclosure during the phone call satisfies the notice requirement.
This argument fails on multiple levels. First, BIPA requires written notice, not verbal notice. The statute’s language is explicit: a private entity must inform the subject “in writing” that biometric information is being collected. A pre-recorded audio greeting played over the phone does not constitute written notice under any reasonable interpretation of the statute.
Second, even if the verbal greeting could be considered adequate notice (which it cannot), the greeting does not disclose the specific purpose and length of term for which the voiceprint is being collected, stored, and used. It does not tell the caller how long Walmart will retain the voiceprint, under what circumstances it will be deleted, or whether it will be shared with third parties. The phrase “fraud detection” is vague and does not satisfy BIPA’s specificity requirement.
Third, and most importantly, BIPA requires a written release executed by the subject of the biometric identifier. Even if Walmart provided written notice and disclosed the purpose and retention period (which it did not), the statute still requires affirmative written consent. Walmart never obtained this consent. The caller is not asked to press a button to agree to the collection, sign a digital form, or confirm consent in any way. The system simply harvests the voiceprint automatically and without interruption.
The complaint is unequivocal on this point: “Merely including the collection of biometric information in Walmart’s privacy policy is inadequate under state law and for purposes of providing consent in writing.”
Societal Impact Mapping: The Automation Surveillance Economy
The Erosion of Informed Consent
Walmart’s voiceprint harvesting system is not an isolated incident. It is part of a broader corporate strategy to replace human labor with automated systems that extract data from consumers in ways that are legally ambiguous, ethically questionable, and operationally invisible. The AI voice system saves Walmart money by eliminating the need to staff customer service lines with human employees. It also generates valuable biometric data that can be used for identity verification, fraud prevention, and potentially other purposes that Walmart has not disclosed.
This dual functionβcost reduction and data extractionβis the defining feature of the automation surveillance economy. Corporations deploy AI systems under the banner of “efficiency” and “customer experience,” while quietly harvesting biometric, behavioral, and transactional data from users who have no idea the extraction is taking place. The informed consent model that underpins privacy law is rendered meaningless when consent is neither informed nor freely given.
The Biometric Privacy Crisis in Retail
Walmart is not the only major retailer to face biometric privacy litigation. In recent years, companies including Amazon, Google, Facebook, and numerous smaller firms have been sued under BIPA for collecting facial recognition data, fingerprints, and voiceprints without adequate consent. The Illinois statute has become the primary legal tool for holding corporations accountable for biometric data abuses, because most other states have not enacted comparable protections.
The retail sector is particularly vulnerable to BIPA litigation because retailers interact with millions of consumers daily and increasingly rely on biometric systems for identity verification, loss prevention, and customer tracking. Self-checkout kiosks equipped with facial recognition cameras, employee timekeeping systems that scan fingerprints, and AI-powered customer service systems that harvest voiceprints all present potential BIPA violations if deployed without proper consent and disclosure.
The Permanent Identity Theft Risk
The long-term societal impact of mass voiceprint collection is difficult to overstate. Voiceprints are permanent biometric identifiers. If a database containing millions of voiceprints is breached, the consequences cannot be undone. Financial institutions, healthcare providers, and government agencies are increasingly adopting voice authentication as a security measure because voiceprints are supposed to be unique and difficult to forge. But if voiceprints are harvested at scale by private corporations with inadequate security protocols, the entire voice authentication infrastructure becomes compromised.
A data breach at Walmart could result in millions of Illinois residents losing the ability to use voice authentication for banking, healthcare, or government services. The voiceprints could be used by criminals to impersonate victims, access accounts, and commit fraud. Unlike a stolen password, which can be changed, a stolen voiceprint is permanent. The victim cannot grow a new voice.
Legal Receipts: What the Court Filing Says
“Each time an individual calls their local Walmart store, they frustratingly have to go through the process of talking to an automated interactive voice system (‘Walmart’s AI Voice System’) which collects, stores, and disseminates their voiceprints. While this adds convenience for Walmart and saves them money by thwarting the necessity of having customer service controlled by actual human beings, it forces Walmart’s customers to unknowingly surrender their biometric information to Walmart as voiceprints are as unique as fingerprints, facial recognition templates, and iris scans.”
β Class Action Complaint, Smith v. Walmart Inc., Case No. 1:26-cv-07861, ΒΆ 2
“Plaintiff Smith’s biometric identifiers were unlawfully collected by Walmart by way of her calling Walmart’s AI Voice System twice in December of 2025 and once in July of 2026. Plaintiff Smith had no idea that her biometric identifiersβspecifically, her voiceprintβwhich was used to identify her when Walmart’s AI Voice System was being utilized upon her calling each time to her local Walmart store in Illinois.”
β Class Action Complaint, Smith v. Walmart Inc., Case No. 1:26-cv-07861, ΒΆ 8
“Walmart systematically and automatically collected, used, and stored Plaintiff’s and Class members’ biometric identifiers and/or biometric information without first obtaining the written release required by 740 ILCS 14/15(b)(3).”
β Class Action Complaint, Smith v. Walmart Inc., Case No. 1:26-cv-07861, ΒΆ 40
“In fact, Walmart failed to properly inform Plaintiff or the Class in writing that their biometric identifiers and/or biometric information was being ‘collected or stored’ by Walmart, nor did Walmart inform Plaintiff or Class members in writing of the specific purpose and length of term for which their biometric identifiers and/or biometric information was being ‘collected, stored and used,’ as required by 740 ILCS 14/15(b)(1)β(2).”
β Class Action Complaint, Smith v. Walmart Inc., Case No. 1:26-cv-07861, ΒΆ 41
What Now?
The class action lawsuit is in its early stages. Walmart has not yet filed a response to the complaint. The court has not yet ruled on class certification. But the legal framework is clear, and the factual record is damning. Walmart deployed an AI voice system that harvests biometric data from millions of Illinois residents without written consent, without disclosure of retention policies, and without providing any mechanism for users to opt out or delete their data.
If the case proceeds to trial and the plaintiff class prevails, Walmart could face statutory damages of $1,000 per negligent violation or $5,000 per intentional or reckless violation under 740 ILCS 14/20. With millions of potential class members, the financial exposure is significant.
Corporate Leadership and Board
The complaint does not name individual executives or board members, but Walmart Inc. is headquartered in Bentonville, Arkansas, and is incorporated in Massachusetts. The company’s leadership and board of directors are ultimately responsible for the deployment of the AI voice system and the failure to implement BIPA-compliant consent and disclosure protocols.
Watchlist: Regulatory Bodies
Illinois residents affected by this data collection should be aware of the following regulatory and advocacy organizations:
- Illinois Attorney General’s Office: Enforces consumer protection laws and can investigate BIPA violations.
- Federal Trade Commission (FTC): Has authority over unfair and deceptive trade practices, including unlawful data collection.
- Electronic Privacy Information Center (EPIC): Advocacy organization that tracks biometric surveillance and privacy violations.
- American Civil Liberties Union (ACLU) of Illinois: Litigation and advocacy organization focused on privacy rights and surveillance abuses.
Mutual Aid and Grassroots Resistance
Corporate surveillance cannot be dismantled through litigation alone. The fight for biometric privacy requires collective action, consumer education, and legislative advocacy. Illinois residents should demand that their state representatives strengthen BIPA’s enforcement mechanisms and close loopholes that allow corporations to bury biometric data collection disclosures in privacy policies that no one reads.
Support local consumer protection organizations. Share information about BIPA rights with friends and family. Push for federal biometric privacy legislation that extends Illinois’ protections to all 50 states. The voiceprint you lose today could be the identity theft case you fight tomorrow.



