Voice Actor Alleges Unconsented Use of AI-Generated Voice on ScotRail Trains

Voice actor Gayanne Potter alleged that her voice data, recorded in 2021 for accessibility software, was used by ReadSpeaker to create a synthetic AI announcer for ScotRail without her informed consent. Potter expressed distress, feeling her identity was 'burgled' and that she was being forced to compete with a 'dreadful' robotic version of herself. While ReadSpeaker maintained they had a valid contract, the incident highlighted gaps in UK law regarding the protection of voice likeness in AI models. ScotRail eventually replaced the voice with that of an internal employee following public and professional backlash.

Scottish voice actor Gayanne Potter alleges her voice was used without proper consent in ScotRail's AI train announcements. She claims she had agreed to limited use of her voice data by ReadSpeaker but was not informed it would be used in a synthetic voice system called "Iona." ScotRail continues to use the voice, stating the dispute is between Potter and ReadSpeaker.

Source: AI Incident Database

Risk classification

  • Primary risk domain: 6 Socioeconomic & Environmental
  • Primary risk subdomain: 6.3 Economic and cultural devaluation of human effort

The incident involves a professional voice actor being forced to compete with an AI-generated clone of her own voice, devaluing her creative effort and threatening her career.

Additional risk subdomains

  • 7.3 Lack of capability or robustness: The AI announcer initially failed to perform reliably, mispronouncing local Scottish place names like Milngavie.

Causal factors

  • Entity: Human
  • Intent: Intentional
  • Timing: Post-deployment

The risk arose from intentional human decisions by ReadSpeaker and ScotRail to commercialize and deploy the voice model, which Potter alleges violated her consent.

EU AI Act risk tier

  • Risk tier: 3 Limited Risk

Limited Risk: The system generates synthetic audio content (voice cloning/text-to-speech) which falls under transparency obligations for AI-generated content.

AI system and alleged parties

  • AI system: None named
  • AI purpose: Voice Generation; Accessibility Assurance
  • Behaviour type: Tool
  • Alleged developer: ReadSpeaker
  • Alleged deployer: ScotRail
  • Alleged harmed parties: Voiceover artists, Individuals affected by unauthorized biometric data use, Gayanne Potter

Harm severity

Highest direct severity in any category: Minor. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.

  • Physical: direct Negligible, indirect Negligible
  • Infrastructure: direct Negligible, indirect Negligible
  • Property: direct Negligible, indirect Negligible
  • Financial: direct Negligible, indirect Negligible
  • Environmental: direct Negligible, indirect Negligible
  • Malicious content: direct Negligible, indirect Negligible
  • Differential treatment: direct Negligible, indirect Negligible
  • Civil rights: direct Negligible, indirect Negligible
  • Democracy: direct Negligible, indirect Negligible
  • Privacy: direct Minor, indirect Negligible
  • Psychological: direct Minor, indirect Negligible
  • Epistemic: direct Negligible, indirect Negligible
  • Child sexual exploitation and abuse: direct Negligible, indirect Negligible

Privacy

Reported: The report explicitly describes concerns over the unauthorized use of biometric voice data, which Potter felt was 'burgled'.

Directly caused: Potter's voice recordings were processed to create a synthetic voice clone without her ongoing consent or control over her biometric data.

Indirectly caused: N/A

Inferred additional harm: N/A

Psychological

Reported: The report explicitly describes psychological distress experienced by the voiceover artist.

Directly caused: Gayanne Potter experienced severe distress, feeling 'violated', 'furious', and 'devastated' upon discovering her voice was cloned and used without her consent.

Indirectly caused: N/A

Inferred additional harm: N/A

People affected

  • Occurrences reported: 1
  • People reportedly harmed: 1
  • People reportedly exposed: 1

Potential causes

Management

  • Prioritizing Control Over Ethics: ScotRail chose automated control and consistency over ethical sourcing.
  • Refusal to Cease Data Use: ReadSpeaker refused to delete data or stop using the voice model.
  • Inadequate Vendor Due Diligence: ScotRail failed to verify the ethical provenance of the AI voice model.

Technology

  • AI Voice Cloning Technology: ReadSpeaker used AI to learn accents and speech patterns from recordings.
  • Robotic and Poor Voice Quality: The synthetic voice sounded robotic and drew heavy criticism from passengers.
  • Mispronunciation of Place Names: The AI system initially struggled with complex Scottish place names.

Data Inputs

  • Use of Biometric Voice Data: Artist's biometric voice data was used to train the AI announcer model.
  • Out of Scope Data Reuse: Recordings meant for accessibility/e-learning were reused for commercial AI.
  • Lack of Phonetic Inputs Initially: The system lacked phonetic inputs for Scottish names, causing errors.

Human Factors

  • Lack of Artist Consent: The voiceover artist did not consent to her voice being used for AI.
  • Artist Distress and Violation: The artist felt violated and distressed upon hearing her cloned voice.
  • Negative Passenger Reception: Passengers criticized the robotic and unnatural sound of the announcements.

Process and Methods

  • Outdated Historical Contracts: Contracts from 2021 did not account for rapid generative AI developments.
  • Inadequate Consent Withdrawal: No mechanism existed for the artist to withdraw consent or delete data.
  • Lack of Direct Communication: Neither ScotRail nor ReadSpeaker informed the artist prior to deployment.

Regulatory Environment

  • No Voice or Likeness Protection: UK copyright law does not protect an individual's likeness or voice.
  • Regulatory Jurisdiction Gaps: The ICO could not act because the data controller was based in Sweden.
  • Lack of Generative AI Legislation: No clear laws exist to prevent unauthorized digital replicas of artists.

Information quality

  • Classification confidence: High
  • Reason for confidence: The reports provide clear, detailed accounts from the affected artist, the technology provider, and the deploying organization, presenting a well-documented contractual and ethical dispute.
  • Ambiguities identified: The exact terms and scope of the 2021 contract between Potter and ReadSpeaker remain disputed.
  • Alternative interpretations: The incident could be viewed strictly as a contract dispute rather than an AI safety failure, though the use of generative AI voice cloning is central to the harm.

A localized commercial dispute in the UK involving a voice actor whose biometric data was used to create an AI announcer for ScotRail without explicit consent. While the incident raises important questions about biometric privacy rights and legal gaps regarding digital replicas, it presents negligible threat to national security, critical infrastructure, or societal stability.

  • Overall national security impact: Minor
  • Response level: Moderate
  • Scope: Single nation
  • Primary target: United Kingdom
  • Alleged perpetrator: ReadSpeaker

Threat characteristics

  • Imminence: Long-term. Represents an ongoing regulatory and legal challenge regarding digital likeness rights rather than an active crisis.
  • Autonomy: Human-controlled. The text-to-speech system operates based on direct human inputs and scripts provided by the operators.
  • Novelty: Evolved capability. Represents an evolution of commercial voice cloning disputes into public sector deployments, highlighting legal gaps in biometric protections.

Impact by dimension

  • Physical security: Negligible. The AI system was used for public transit announcements and did not impact the physical control, safety, or operational integrity of critical rail infrastructure.
  • Information security: Negligible. This was a commercial contract dispute regarding voice cloning for transit announcements, with no connection to state-sponsored disinformation or intelligence compromise.
  • Sovereignty: Negligible. While a government-owned entity (ScotRail) was involved, the incident did not disrupt core government operations, democratic processes, or state sovereignty.
  • Economic security: Negligible. The incident is a localized intellectual property and contract dispute affecting an individual artist, presenting no threat to national economic stability or strategic industries.
  • Societal stability: Minor. The incident highlights emerging challenges in biometric data protection and privacy rights, but remains a localized dispute with minimal threat to broader societal stability.
Explore in the interactive Incident Tracker