- The context: why voice spoofing has become a business problem
- What Google announced and how the system works
- The immediate impact on Italian SMEs
- What nobody says: the real battlefield is organizational
- What to do now: three priority actions for SMEs
- Outlook: where the voice security market is heading
Google has announced the release of a system AI-based automatic detection of fraudulent calls . The feature identifies in real-time phone calls where a synthetic voice impersonates authority figures, family members, or colleagues. Therefore, phone spoofing—already widespread—is now harder to pull off on updated Android devices.
However, the risk doesn't go away: scammers adapt quickly. In fact, Italian SMEs remain a primary target, especially in the retail and B2B sectors where payment authorizations still happen over the phone. Consequently, relying solely on operating system updates isn't enough. You need to integrate internal policies, staff training, and multi-channel verification tools.
We at SHM Studio we monitor the evolution of AI threats to help SMEs build a stronger digital posture. In this article, we analyze what has changed with the Google update, what concrete impact it has on businesses, and which priority actions should be taken in the coming weeks.
The context: why voice spoofing has become a business problem
In recent years, phone scams have undergone a profound transformation. Scammers no longer limit themselves to calling from unknown numbers. In fact, they exploit techniques of spoofing to make trusted numbers show up on the recipient's display. Plus, thanks to AI-driven voice cloning models, they manage to replicate the voice of a manager, a bank official, or a relative with an impressive level of accuracy.
This phenomenon — known as deepfake vishing — is growing rapidly. According to Gartner , by 2026 30% of businesses will view traditional identity check systems as unreliable, all because of generative deepfakes. So, the issue isn't just about regular folks: it hits companies' operations directly.
Italian B2B and retail SMEs are especially at risk. Many approve wire transfers, rush orders, or access to company systems just with a quick phone confirmation. Because of this, a convincing synthetic voice can cause heavy financial damage in a few minutes.
What Google announced and how the system works
As reported by TechCrunch on June 2, 2026 , Google has started the rollout of a feature fake call detection on Android. The system analyzes the voice and behavioral patterns of the incoming call in real time. Specifically, it flags typical signs of synthetic voices: audio artifacts, unnatural rhythms, and a lack of consistent background noise.
The feature works directly on the device, without sending audio data to Google servers. So user privacy stays safe while it checks. When the system spots a high chance of fake voice, it pops up a warning right on your screen during the call.
However, it is important to clarify the limitations. The system does not automatically block the call. Furthermore, its effectiveness depends on the quality of the deepfake model used by the scammer: more sophisticated systems might evade detection, at least in the early stages. Therefore, this is an extra layer of protection, not a definitive fix.
The immediate impact on Italian SMEs
For companies with sales, administrative, or customer service teams, this new feature has practical implications. First of all, employees receiving calls from alleged managers or suppliers now have a visual warning signal. This reduces the psychological pressure typical of scams CEO fraud , where simulated urgency is part of the tactic.
Plus, keeping Android updated at work is now a security must-have, not just a tech preference. Small businesses managing fleets of work phones should check if their devices can handle this feature. Older models, in particular, might miss out on the update.
Conversely, those operating mainly on iOS or on corporate VoIP systems do not directly benefit from this protection. Therefore, the coverage remains partial and asymmetrical. We at SHM Studio we recommend not considering this update as a final destination, but as a signal that the tech sector is finally taking the problem seriously.
What nobody says: the real battlefield is organizational
Google's technology solves part of the problem. However, the most critical component remains the human element. According to research by Harvard Business Review , most social engineering attacks succeed not due to a lack of tools, but a lack of clear internal procedures.
In many Italian SMEs, there is no formal protocol to verify the caller's identity before performing sensitive operations. Therefore, even with a visual warning on the phone, a stressed employee might ignore it. As a result, staff training remains the most effective short-term lever.
Along with this, it's a good idea to review authorization processes. For example, any urgent wire transfer request received by phone should require confirmation through a separate channel—company email, internal messaging app, or a callback to a verified number. Likewise, access to system credentials should never be authorized verbally.
What to do now: three priority actions for SMEs
Companies must not wait for the problem to manifest itself to act. Therefore, it is useful to identify actions with the best ratio between impact and speed of implementation.
- Update corporate Android devices to versions compatible with the new detection feature. Check with your IT provider for the mobile fleet update roadmap.
- Introduce a dual-channel verification protocol for all sensitive operations requested by phone. In particular, payments, system access, and changes to supplier master data.
- Train the staff on the signs of a deepfake call: artificial urgency, request for secrecy, emotional pressure. These behavioral patterns are often more recognizable than the synthetic voice itself.
Finally, it is advisable to integrate these measures into a broader digital security plan. The AI solutions for digital risk management are evolving fast, and SMBs that build a solid framework today will be in a better spot come 2027-2028, when deepfake models will be even easier to use and way more convincing.
Outlook: where the voice security market is heading
Google isn't the only player moving in this direction. Microsoft, Apple, and several enterprise security vendors are developing similar solutions. Therefore, over the next 18-24 months, we can reasonably expect a more structured ecosystem of anti-deepfake tools built right into operating systems and business communication platforms.
However, the arms race between defenders and scammers is bound to continue. Voice cloning models are constantly improving. Therefore, technological protections will need to keep up at the same speed. In this scenario, SMBs that build a culture of verification today—independent of the tools available—will have a structural advantage.
For companies that want to learn more about integrating digital security into their digital marketing strategy and communication, or who wish to understand how the AI technologies are reshaping operational risks, the team at SHM Studio is available for a preliminary consultation. You can contact us through the page contacts or explore our services for Italian SMEs.
Furthermore, for those operating in B2B and managing business relationships on digital channels, it can be useful to evaluate how to strengthen their presence on verified platforms. For example, the LinkedIn campaigns allow the construction of a traceable and authenticated communication channel with clients and partners. Likewise, a strategy SEO solid contributes to making the brand recognizable and difficult to impersonate online.
Finally, those who wish to delve deeper into these topics can consult our Blog , where we publish updated analyses on the evolution of the digital landscape for Italian businesses.
Related articles
Discover more articles exploring similar topics, selected to offer you a more complete and stimulating perspective. Each piece of content is carefully chosen to enrich your experience.