Voice AI Trust & Safety

Your Outbound Voicebot Sounds Like a Scam Call: Earning Caller Trust in the Voice-Cloning Era

Malaysians have been trained by two years of deepfake fraud to distrust an unfamiliar voice on an unknown number. That is now the first obstacle every legitimate outbound voice agent has to clear — and most are designed as if it does not exist.

· 7 min read
Illustration of two identical speech waveforms side by side, one marked with a solid verification badge and one dissolving into fragments, representing a genuine call and a cloned one

Your Outbound Voicebot Sounds Like a Scam Call: Earning Caller Trust in the Voice-Cloning Era

Short answer: Voice cloning fraud has taught Malaysian consumers a simple heuristic — an unfamiliar voice on an unknown number asking for anything is probably a scam. Legitimate AI voice agents trip that heuristic on every single dial. The fix is not a better voice; it is a call design that lets the caller verify you through a channel you do not control, within the first twenty seconds, without ever asking for the things scammers ask for.

Key takeaways


Why does a legitimate call now feel like a threat?

Because the public defence against AI fraud is a blunt heuristic, and blunt heuristics catch legitimate traffic too.

The Malaysian cases that made the news set the pattern: a familiar-sounding voice, an urgent request, an irreversible payment. Reported incidents include victims transferring five-figure sums to callers who sounded like a close friend, and staff reading prepaid top-up PINs to a voice they believed was their employer. Voice cloning now needs only a short clip of someone speaking — a voice note, a video, a public interview — and the tooling is widely available.

The regional context is worse than the national one. UN agencies have described industrial-scale fraud infrastructure across Southeast Asia, where deepfakes and voice cloning are developed and sold as services alongside malware and laundering.

So consumers adopted the advice that actually works: do not trust caller ID, do not act under time pressure, verify on a separate channel, never give codes over the phone. That advice is correct. It also describes exactly what your outbound campaign is asking people to do.

What do scam calls and legitimate voicebots have in common?

Uncomfortably much. Four shared surface features:

A synthetic voice. Yours is disclosed and theirs is not, but the acoustic signature is similar enough that "it sounded a bit AI" is no longer evidence of anything.

An unrecognised number. Most outbound campaigns dial from pooled or rotating numbers. So does fraud.

An ask. Confirm your appointment, verify your address, update your policy. Every one of these is also a scam opener.

Time pressure. "Before the offer closes," "your booking expires today." Fraud runs on exactly this, and consumers have been explicitly told that urgency is the tell.

Two of the four you cannot remove — you have a synthetic voice and you have an ask. So the entire trust burden falls on the other two, plus what you do with them.

How do you make a legitimate call look legitimate?

Design the call so that a cautious person can safely say yes, and an unusually cautious person can safely hang up and still complete the task.

  1. Identify the organisation before anything else. Name the company, then the AI status, then the reason for the call, in one breath. Fraud calls almost never lead with a verifiable institution, because naming one invites a callback.

  2. Dial from a stable, published number. One number per campaign, listed on your own website, on the page a customer would find by searching your brand. Rotating numbers to dodge spam labels destroys the one thing that lets a caller check you.

  3. Offer the callback exit in the first thirty seconds. "If you'd rather call us back, our number is on the back of your card / on our website — I'll be here." An agent that welcomes verification is doing something no fraud call can afford to do.

  4. Ask for nothing that a scammer would ask for. No OTP. No PIN. No full IC number. No card details. No bank transfer. No prepaid top-up codes. If your workflow needs identity confirmation, use a low-value confirmation the caller can give safely — a yes/no against something you already hold, not a secret they recite aloud.

  5. Move payments to a channel the customer initiates. Send a link to the app they already have, or have them call the number on their card. Never take the money on the call, even when you technically can.

  6. Strip artificial urgency from the script. Real deadlines can be stated once, plainly, with the date. Anything that sounds like a countdown reads as fraud.

  7. Make hanging up a supported outcome. "That's completely fine — you can verify with us any time and we'll pick it up from there." Callers who hang up and call back are your best-converting segment; treat them as a success path, not a failure.

  8. Escalate to a human on first request, without a retention loop. Three refusals before a transfer is a pattern consumers now associate with predatory calls.

Scam call vs trustworthy AI call

Signal

Fraud call

Well-designed AI call

Opening

Claims a relationship or an authority, vaguely

Names the organisation, then states it is an AI

Number

Spoofed or rotating, unlisted

Stable, published on the company's own site

Verification

Discourages callbacks: "don't hang up"

Volunteers the callback route unprompted

Sensitive data

Requests OTPs, PINs, card details, ID numbers

Never requests any of them, in any flow

Money

Wants an irreversible transfer on the call

Never takes payment on the call

Urgency

Manufactured countdown

A real date, stated once

"Are you a bot?"

Denies or deflects

Confirms plainly, in the caller's language

Exit

Pressure to stay on the line

Hanging up is offered as a valid option

What about "how do I know you're really from the bank?"

Answer it as a first-class intent, not an edge case. The agent should have a scripted, tested response that does three things: acknowledges the question as reasonable, refuses to prove itself with secrets, and hands over a channel the caller controls.

"That's a fair question, and honestly you shouldn't take my word for it. I'm not going to ask you for a PIN, a code or a card number at any point. If you'd like to check, hang up and call the number on the back of your card or on our website, and any colleague can pull up this same case."

Note the refusal in the middle. Volunteering what you will never ask for is the single most differentiating sentence available to you, because it is the one sentence a fraud call cannot say.

Also plan for the escalation: some customers should be encouraged to verify with the National Scam Response Centre or their bank's own fraud line if they believe they have been targeted. An agent that helps a suspicious customer protect themselves has converted a hostile call into a trust event.

The language dimension

Trust cues are language-specific, and this is where regional deployments quietly fail.

A caller who switches into Malay mid-call is often signalling comfort — or testing you. An agent that answers a Malay question in English reads as a foreign script running on rails, which is precisely the fraud stereotype. The verification sentence, the "I will never ask for" sentence, and the callback offer all need to exist natively in every language you deploy, with the same warmth and the same directness. Translated word for word, "I am not going to ask you for your PIN" often lands as either robotic or oddly aggressive in Malay, both of which increase suspicion.

This is one more reason single-language pipelines are a business risk and not just a quality problem — see why code-switching breaks voice AI. And the AI disclosure itself has to be handled properly in each language too, which we cover in the disclosure rules guide.

Our data: [Insert your own numbers here: rate of "are you a scam / are you a bot" challenges per 100 outbound calls, by market and language; completion rate for calls that received a challenge versus those that did not; and conversion for customers who hung up and called back. This is a genuinely under-reported metric and yours would be citable.]

What does good look like on a live call?

The agent opens with the company name and its AI status. The customer says, flatly, that they get scam calls every week and do not believe this one. The agent agrees that is sensible, states plainly that it will never ask for a code, a PIN or a payment, and gives the number on the back of their card as the way to check. The customer hangs up. Four minutes later they call the published number, reach the same case, and finish the task in ninety seconds.

That call looks like a failure in a dashboard that counts completions per dial. It is the best possible outcome, and your reporting should be built to recognise it.

Frequently asked questions

Why do customers assume an AI call is a scam?

Because the public advice for surviving voice-cloning fraud — distrust unknown numbers, distrust urgency, never give codes — describes the surface features of a normal outbound campaign. The heuristic is correct and it catches you as collateral.

Should an outbound voice agent ever ask for verification details?

Never ask for OTPs, PINs, full ID numbers or card details. If you must confirm identity, use a yes/no confirmation against data you already hold, or move the customer to a channel they initiate themselves.

Does disclosing that the caller is speaking to an AI make trust worse?

The opposite, in most deployments. Discovering the deception later is what damages trust. Disclosure also separates you from fraud calls, which have every incentive to hide what they are.

How should the agent respond to "are you a scam?

Treat it as a first-class intent with a tested script: acknowledge the question as reasonable, state what you will never ask for, and offer a callback on a number the customer already has. Never argue.

Does a stable caller ID actually help if caller ID can be spoofed?

It helps because it is checkable, not because it is unforgeable. A number published on your own website gives a cautious customer a way to confirm you independently. Rotating numbers remove that option entirely.

What should the agent do if the customer says they have already been defrauded?

Stop the sales flow, and point them to their bank's fraud line and Malaysia's National Scam Response Centre. Speed matters enormously in these cases, and no campaign metric is worth more than that.

See it on one of your own call flows

Bring one workflow. We will configure it, validate it with controlled test calls, and show you the whole system around it.