Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature AI Risk

Cox Media Group's 'Active Listening' Fallout: What the FTC Settlement Means for AI Vendor Due Diligence

The FTC finalized consent orders against Cox Media Group and two smaller firms on August 27, 2026, over deceptive 'active listening' AI claims — marketing that phones were capturing voice data to target ads. They weren't. The $930,000 in penalties and 20-year oversight period signal what the FTC will do with vendors who overclaim AI capabilities. Here's what your AI vendor due diligence program needs to cover.

By Rebecca Leung · September 6, 2026 ·
Table of Contents

TL;DR

  • On August 27, 2026, the FTC finalized consent orders against CMG Media Corporation (Cox Media Group) and two smaller firms over an “active listening” AI product that marketed itself as capturing smartphone voice data to target ads — but actually used purchased email lists.
  • Total penalties: $930,000. Oversight period: 20 years. The case turns on two violations: AI capability overclaiming and invalid consent.
  • The FTC’s position: accepting app terms of service is not consent to voice data collection. Capability claims must describe what the technology actually does.
  • Due diligence implication: if a vendor says their AI captures behavioral signals, you need to verify that claim before buying, deploying, or reselling their product.

If your vendor tells you their AI “listens” to consumers, you should probably ask what that means. The FTC just demonstrated what happens when the answer turns out to be nothing — and someone sold the product anyway.

On August 27, 2026, the Federal Trade Commission finalized consent orders against CMG Media Corporation (Cox Media Group), MindSift LLC, and 1010 Digital Works LLC over a product marketed as “active listening” AI. The product claimed to capture voice conversations from smartphones and smart devices — the microphone-always-on concern that has circulated in consumer privacy circles for years — and use that data to target advertising. It didn’t. The underlying technology used email lists purchased from data brokers.

The FTC’s response: $930,000 in civil penalties, a 20-year compliance oversight period, and a set of prohibitions that read like a checklist of things AI vendors should not do.

What Cox Media Group’s “Active Listening” Product Actually Was

CMG Media Corporation is the advertising sales arm of Cox Media Group, one of the largest broadcast media companies in the United States. The “active listening” product was an advertising targeting service that CMG sold to advertisers based on the claim that it could identify consumers who had recently spoken about topics relevant to the advertiser’s product.

The pitch was that a consumer who said aloud “I’m thinking about buying a new car” near their phone would then see car ads. Advertisers paid for the targeting capability under the assumption that this was what they were getting.

According to the FTC’s complaint, the reality was different. The behavioral targeting came from purchased email lists — data broker lists matched to the advertiser’s desired consumer profiles. There was no voice capture. There was no always-on microphone data collection. There was a data broker arrangement with “AI-powered” branding applied to justify higher pricing.

The two smaller defendants — MindSift LLC and 1010 Digital Works LLC — were parties to the same scheme. Their consent orders mirror CMG’s, though at a much lower penalty level ($25,000 each) reflecting their relative size and role in the operation.

The FTC’s case against CMG rests on two separate theories, and both matter independently for how AI products and services are sold.

Violation 1: Misrepresenting AI Capabilities

The FTC’s complaint alleged that CMG’s marketing materials, sales presentations, and product documentation represented that the “active listening” feature captured and processed voice data. The FTC’s position — consistent with its broader AI enforcement approach — is that capability claims must be accurate.

This is not a new standard. The FTC has enforced accuracy in product claims under Section 5 for decades. What’s new is applying that standard systematically to AI-specific claims. “AI-powered,” “machine learning enabled,” “advanced targeting,” and capability-specific claims like “active listening” or “intent capture” are product claims. They need to describe what the product actually does.

The FTC’s enforcement policy statement on AI and Section 5 has articulated this clearly: the fact that a product uses AI doesn’t give it a different standard for accuracy than any other product claim. If your AI capability claim can’t survive a basic accuracy check — does the technology actually do what the marketing says it does? — you have a Section 5 problem.

For advertisers who bought CMG’s product believing they were getting voice-based targeting, the case also raises a secondary issue: did they make downstream representations to their own customers based on CMG’s false claims? A business that tells its clients it uses “AI that captures consumer intent from voice signals” and then discovers its vendor was using email lists has its own deceptive advertising exposure.

The second theory is arguably more important for the industry: the FTC found that CMG’s consent argument was invalid.

CMG’s defense — or at least its implied justification — was that consumers had agreed to data collection through app terms of service. The FTC rejected this. Accepting a standard app ToS is not consent to voice monitoring. For an invasive and specific data collection practice like real-time microphone access, consent must be specific, informed, and affirmative.

This aligns with what the FTC has said in other data collection contexts and reflects the broader regulatory direction: general consent provisions don’t cover specific sensitive practices. A privacy policy that says “we may collect data about your behavior” does not authorize voice capture. An app that says “we may share your data with advertising partners” does not authorize continuous microphone access.

For fintech and financial services companies thinking about AI-driven data collection — behavioral analytics, session monitoring, voice-enabled customer service that processes and stores content — the consent requirement the FTC is articulating is specific: consumers need to know what you’re collecting, how, and for what purpose, and they need to affirmatively consent to each material use.

The 20-Year Oversight Period: Why It Matters More Than the Dollar Figure

$930,000 across three defendants is not a figure that moves the needle for a company the size of CMG. The 20-year compliance oversight period is the real consequence.

Under the consent order, CMG is subject to FTC monitoring, reporting requirements, and compliance certification for two decades. That means the order follows the company — and potentially its executives and successors — through ownership changes, product redesigns, and evolving technology. A private equity buyer of a media company with a 20-year FTC consent order has inherited a regulatory compliance obligation that affects integration planning, product development, and future acquisition targets.

The compliance report requirement — annual filings confirming adherence to the order’s prohibitions — creates an ongoing administrative burden and a recurring opportunity for the FTC to examine whether the prohibited conduct has resumed. It also creates liability for false compliance certifications.

The 20-year period signals that the FTC treats AI capability deception as serious enough to warrant structural oversight, not just a one-time financial penalty. That’s the same posture the agency has taken in other technology consent orders — the goal is a long-term change in conduct, not just a check.

What This Means for AI Vendor Due Diligence

If you are buying AI-powered services from third-party vendors — advertising technology, marketing platforms, consumer targeting tools, behavioral analytics — the CMG case establishes due diligence requirements that your vendor management program should reflect.

Verify what the technology actually does. A vendor who claims their AI “captures consumer intent,” “listens for behavioral signals,” or uses any capability that implies data collection from devices needs to be able to demonstrate the actual mechanism. Ask for technical documentation. Ask for a system description. Ask specifically: “What data inputs drive this product’s outputs?” If the answer involves consumer behavioral data from a novel or invasive collection method, that claim should be verified before you purchase or resell.

Distinguish AI marketing from AI capability. The gap between what AI vendors say their products do and what they actually do is a documented problem in the AI industry. “Powered by machine learning” often means “we applied a classification model to a structured dataset.” “Active listening” apparently meant “we bought email lists.” Your vendor questionnaire should include questions that require the vendor to describe their AI system’s inputs, outputs, and methods — not in marketing language, but in technical terms.

Review consent representations. If a vendor’s data collection relies on consumer consent, verify what form of consent is actually obtained. Generic ToS acceptance is not sufficient for invasive data collection practices. Ask to see the consent mechanism, the disclosure language, and the opt-in or opt-out structure. For any vendor whose product reaches your customers or uses your customers’ data, you are relying on that vendor’s consent practices to avoid your own regulatory exposure.

Document your due diligence. The AI Risk Assessment Template includes a vendor questionnaire designed for exactly this kind of review — questions on data inputs, model purpose, bias testing, and the consent and disclosure practices underlying the vendor’s data collection. The questionnaire creates a paper trail that your vendor made specific representations about what their AI does, which is both your governance record and your defense if the vendor’s representations turn out to be false.

Contractually allocate risk for AI misrepresentation. Your vendor contracts should include representations from the vendor about the accuracy of their AI capability claims and the validity of their consent practices. If the vendor misrepresents their technology and you suffer regulatory consequences as a result, your recourse is through the contract. Most off-the-shelf SaaS agreements don’t include AI-specific reps and warranties — you need to add them.

The Broader AI Enforcement Pattern

The FTC’s personalized pricing statement — published just two weeks before the CMG orders finalized — reflects the same enforcement posture: AI doesn’t get a different standard for accuracy, consent, or disclosure than any other product or data practice.

The CMG case adds vendor overclaiming to the FTC’s AI enforcement taxonomy alongside AI-generated fake reviews, deceptive AI capability advertising, and AI pricing that misrepresents its basis. The common thread is that AI-flavored language doesn’t insulate conduct from FTC Act review.

For compliance programs managing AI governance, this case reinforces a priority that should already be in your framework: third-party AI products that you buy, deploy, or resell carry the same representation risk as products you build internally. If you tell your clients you’re using a technology, and that technology doesn’t work the way you described, you’re in the same position CMG’s advertiser clients were in — and potentially in the same position CMG was in with the FTC.

The CMG case made this exposure concrete at $930,000 and 20 years of compliance overhead. The cost of a vendor questionnaire and a technical verification call is substantially lower.


Sources:

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What did Cox Media Group actually do wrong?
CMG Media Corporation (Cox Media Group) marketed an 'active listening' advertising product that it claimed could capture voice conversations from smartphones and smart devices to target ads. In reality, the product used email lists purchased from data brokers — not captured voice data. The FTC's complaint alleged two violations: (1) CMG misrepresented the capabilities of its AI technology, and (2) it represented that consumers had consented to voice data collection when they had not — accepting a standard app terms of service is not consent to voice monitoring.
What were the penalties and oversight requirements?
CMG Media Corporation paid $880,000. Two smaller defendants — MindSift LLC and 1010 Digital Works LLC — paid $25,000 each, for a total of $930,000. All three are subject to a 20-year compliance oversight period. The orders prohibit misrepresenting AI capabilities, voice data collection practices, and consumer consent, and require submission of compliance reports.
What does this mean for companies that market AI products?
The FTC will treat AI capability claims the same way it treats any product claim: they need to be accurate and substantiated. 'AI-powered,' 'machine learning,' 'advanced targeting,' and capability-specific claims like 'active listening' must describe what the technology actually does, not what its marketing deck implies. This applies both to companies building AI products and to companies that purchase and resell AI-enabled vendor services.
What is invalid consent in the AI context?
The FTC found that CMG's consent argument — that consumers agreed to voice data collection through app terms of service — was invalid. The agency's position is that consent to a product's general terms does not constitute opt-in consent to a specific, invasive data collection practice like voice monitoring. For AI products that collect or process sensitive behavioral data, consent must be specific, informed, and affirmative.
Does this settlement affect AI vendor due diligence requirements?
Yes, directly. If you are purchasing AI-powered vendor services — particularly for marketing, advertising targeting, or consumer profiling — the CMG case establishes that you need to verify that vendor capability claims are accurate. A vendor who tells you their AI 'listens' to consumers, 'reads' intent signals, or captures behavioral data should be able to demonstrate exactly how the technology works. Overclaimed capabilities are both a vendor management risk and a potential deceptive advertising exposure for the businesses that buy and rely on those claims.
How is this case related to the FTC's broader AI enforcement posture?
CMG is part of the FTC's growing pattern of AI enforcement under Section 5. The agency has pursued AI cases under its existing authority — no new AI statute required. Cases include AI-generated reviews, AI capability overpromising, and AI-enabled data practices that exceed disclosed use. The Commission under its current leadership has treated AI enforcement as a priority area, and the CMG case adds vendor overclaiming to the list of enforcement-worthy practices.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.