Trustworthy
Voice Agents
Safety, Security, and Privacy
Bringing AI safety to voice agents, and voice-first interaction to AI safety.
Voice agents are emerging as one of the most important interfaces for multimodal AI systems, enabling natural, real-time, and human-centered interaction. Their rapid deployment in consumer, healthcare, and assistive applications introduces urgent challenges in safety, security, and privacy that are not fully captured by existing text-centric AI safety, multimodal foundation model, or conversational AI studies. How should trustworthy AI principles adapt when systems perceive, reason, and communicate through speech?
SafeVoiceAgents aims to connect researchers from the AI safety and speech communities. Rather than replacing existing venues, the workshop provides a dedicated forum to identify voice-specific challenges, develop shared evaluation principles, and build a research agenda for trustworthy voice agents as they become increasingly prevalent in real-world applications.
Voice is rapidly becoming a primary interface between humans and AI. Recent audio language models and spoken-dialogue systems are moving beyond cascaded ASR–LLM–TTS pipelines toward increasingly speech-native, low-latency, and full-duplex interaction. Open large audio language models such as Qwen-Audio, Audio Flamingo, SALMONN, and MERaLiON-AudioLLM further illustrate the growing capability and accessibility of this technology. As voice agents move into consumer, enterprise, healthcare, education, and assistive applications, ensuring that they are safe, privacy-preserving, and aligned with human intent and value is an immediate trustworthy AI problem.
Voice agents create safety challenges that are not fully captured by text-centric AI safety. At the interaction level, speech conveys semantic content together with speaker identity, prosody, emotion, speaking style, turn-taking behavior, and environmental audio; two acoustically different utterances can share the same transcript while carrying substantially different intent or social meaning. At the system level, voice agents combine acoustic perception, language reasoning, real-time generation, memory, and full-duplex interaction — so failures may arise from acoustic attacks, privacy leakage, identity misuse, latency and interruption behavior, or incorrect reliance on transcripts. At the evaluation level, established text-based guardrails and LLM-as-a-judge methods do not directly solve the problem of judging spoken, multi-turn, and beyond-transcription behavior.
The timing matters because capability and deployment are advancing faster than shared safety practice. Work on voice-agent safety is currently distributed across speech processing, AI safety and alignment, multimodal learning, and human–AI interaction. Without a focused forum, these communities risk developing incompatible terminology, benchmarks, threat models, and evaluation protocols. SafeVoiceAgents convenes this emerging community while the research agenda is still forming.
Rather than treating voice-agent safety as separate from general AI safety, this workshop positions voice agents as a critical deployment setting where multiple AI subfields converge and where modality-specific risks limit the direct transfer of text-centric safety methods.
SafeVoiceAgents makes trustworthy, real-time spoken human–AI interaction its central focus, jointly considering safety, security, and privacy. It is therefore neither a general agent-safety workshop nor a conventional speech-capability workshop. The intended audience spans AI safety and alignment, speech and audio research, multimodal learning, security and privacy, human-centered AI, and responsible AI.
Contribute to the first workshop on trustworthy voice agents.
We welcome research across five topic areas, from safety evaluation and adversarial audio to privacy, human factors, and governance.
Read the Call for Papers →