Google is adding an AI-impersonation warning to its Phone by Google app, flagging incoming calls where a scammer has spoofed a contact's number and faked their voice. The feature is on by default for users running Android 12 and later, and rolls out first on Pixel phones. Google is anchoring the launch to an FBI figure showing Americans lost more than $893 million to AI-powered scams in 2025.
The mechanism is a silent handshake between devices. When a real contact calls you and both of you use Phone by Google, the caller's device transmits a confirmation signal verifying the call is genuinely originating from that number. If a scammer spoofs the same number from a different device, the signal never arrives, and the app surfaces a warning with a one-tap option to end the call.
The in-app notification reads bluntly, telling the user that someone may be pretending to call from their contact's number. Google said in its announcement that when a spoof attempt is in progress, the initial confirmation signal will be missing, which is the cue the app uses to throw the warning.
“Someone may be pretending to call from your contact's number”— Google, Phone by Google in-app notification
Key facts
- 01Phone by Google will flag calls where a scammer has spoofed a contact's number but cannot produce a silent confirmation signal from the real device.
- 02The FBI logged over $893 million in US losses to AI-powered scams in 2025, the figure Google cites as the threat backdrop.
- 03The feature is on by default for Android 12 and later, rolling out first on Pixel phones.
- 04It works only when both caller and recipient use Phone by Google, and is built on end-to-end encrypted RCS so other apps can adopt it.
- 05Google is also opening its Personal Safety app to kids under 13 and expanding AirDrop support, Circle to Search outfit search, and Play Books AI summaries.
The architecture sits on top of end-to-end encrypted RCS, the messaging standard Google has spent years pushing as the Android answer to iMessage. Google said the design allows other apps to adopt the same verification layer, which matters because the silent-handshake model only works when both parties are on a participating app. A Pixel-to-Pixel call is covered on day one; a Pixel-to-iPhone call is not.
The threat Google is targeting is voice-cloning fraud, where attackers scrape a few seconds of someone's voice from social media, clone it with off-the-shelf AI, then call a relative or employee from a spoofed number asking for money or credentials. The $893 million FBI tally captures only reported AI-related losses in the US for a single year, which makes it a floor rather than a ceiling. Carrier-level STIR/SHAKEN caller ID authentication has reduced some spoofing but does not address the voice-cloning layer on top.
The Phone by Google approach is narrower than carrier authentication but more direct: it verifies device-to-device rather than network-to-network, and it surfaces the result inside the call screen the user is already looking at. The tradeoff is reach. Until non-Google calling apps implement the RCS-based confirmation, the warning will only fire on a subset of calls, and the absence of a warning will not be a guarantee a call is genuine.
Google bundled several other Android updates with the announcement. Children under 13 will be able to use the Personal Safety app, displaying emergency contacts and medical information on the lockscreen and turning on car crash detection. Apple AirDrop interoperability is rolling out more widely, as is the AI-powered clothing try-on feature in Google Photos and the ability to identify items in an outfit through Circle to Search.
Google Play Books is also getting an AI insights feature that summarizes how far a reader has gotten in select titles and answers questions about specific passages. The grab bag follows the pattern Google has used throughout 2026, threading Gemini-powered features into existing apps rather than launching new standalone products. The Gemini Spark agent, which we covered earlier this month, is the most ambitious example, and the Phone app update is the most defensive.
The limits of the scam warning are worth naming. The feature does not detect AI voice cloning itself; it detects spoofing, which is the delivery mechanism cloning attacks usually ride on. A scammer who calls from their own real number and uses a cloned voice would not trigger the missing-signal flag. Google's defense assumes attackers care enough about caller ID trust to spoof a known contact, which is true of most high-conversion scams but not all of them.
Caller authentication is one of the few areas where platform owners have a structural advantage over standalone AI safety tooling: they control the dialer, the OS, and the messaging backbone, so they can ship a default-on protection without asking the user to install anything. For Google, the Phone by Google update doubles as another argument for why RCS adoption matters beyond messaging — verified-call infrastructure is the kind of feature carriers and Apple cannot easily replicate without buying into the same stack. The harder question is whether scam economics shift fast enough that voice-cloning attackers move off spoofed numbers entirely, at which point the next round of defenses has to live inside the audio itself.
Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.
Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.



