Compliance

Voice AI and Monitoring Workers: The ICO Rules

Dilr Voice is an enterprise voice AI platform. When AI scores, transcribes or flags your own contact centre agents, you are monitoring workers under UK data protection law, not just callers. This guide explains the ICO monitoring rules, why worker consent rarely holds, the lawful basis to use, and what you must tell staff.

DILR.AI ENGINEERING · COMPLIANCE One call, two data subjects The caller you serve, and the agent you score. CALLER Personal data · transparency owed WORKER Monitoring duty · a separate ICO line PURPOSE → PROPORTIONALITY → LAWFUL BASIS → TELL WORKERS → REVIEW

Every enterprise that puts voice AI on its phone lines is told to think about the caller: consent, call recording, retention, the subject access request that lands three months later. Far fewer buyers notice the second person on the same call. When the AI transcribes the conversation, scores the human agent who handled it, or flags that agent's tone, script adherence or silence, the enterprise has quietly started to monitor its own workers. That is a separate data protection duty, owed to employees, and it does not disappear because the primary purpose was customer service.

The gap matters because adoption is now mainstream. McKinsey's State of AI 2025 found that around 88 percent of organisations report using AI in at least one function, while only about 6 percent capture material EBIT impact from it. A large share of that usage sits in the contact centre, where the same models that answer callers are also the cheapest way to grade agents at scale. The regulator has already drawn the line for that second use, and most deployment plans do not read it.

This guide sets out the worker-facing side of a voice AI deployment: when call handling tips into staff monitoring, what lawful basis actually holds, why worker consent is the wrong instrument, what you must tell your people, and who carries the duty when a vendor's model does the scoring.

This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system.

What does it mean to monitor workers with voice AI?

Monitoring workers with voice AI means using the same call system to observe your own staff, not only your customers. When an AI agent transcribes a call, scores the human who handled it, or flags their tone or handle time, the enterprise is processing worker personal data. That engages the ICO's monitoring-workers rules, a distinct data protection duty owed to employees. Dilr Voice treats the worker side of a deployment as a first-class obligation.

The practical consequence is that one recording now sits under two duties at once. The caller is a data subject, owed the transparency, retention and access rights covered in our multi-jurisdiction call recording consent map. The agent on the same line is also a data subject, owed a duty the caller work never mentions. Treating the recording as a single customer-service artefact is where the compliance gap opens. The Information Commissioner's Office published dedicated guidance on monitoring workers in October 2023, and it applies to any monitoring of people who carry out work for you, whether systematic or occasional.

When does voice AI cross from monitoring calls to monitoring your own agents?

Voice AI crosses into worker monitoring the moment its output is used to observe, assess or manage the person handling the call rather than the call itself. Recording a conversation for a caller's benefit is one purpose. Running automated quality scoring, sentiment flags or productivity metrics against the agent is a second, worker-facing purpose. The ICO treats these as different processing activities, and Dilr Voice keeps them separated so an enterprise controls agent analytics itself.

The line is easy to miss because the feature looks like a natural extension of quality assurance. A product built to grade calls at scale, like the approach in our automated agent quality scoring guide, becomes a monitoring system the instant those scores attach to a named employee and shape coaching, ranking or discipline. The data protection question is not whether the scoring is accurate. It is whether the enterprise has a lawful basis, has told the worker, and has kept the monitoring proportionate to a purpose it can state plainly.

You need a lawful basis under Article 6 of the UK GDPR before you monitor workers, and for most voice AI analytics that basis is legitimate interests under Article 6(1)(f), not consent. The reason is structural: an employer and a worker are not equals, so a worker cannot freely refuse. The ICO is direct about this in its monitoring-workers guidance, which is why the enterprise, not the agent, has to carry the justification through a documented balancing test.

The ICO puts the point plainly:

"consent is not usually appropriate in the employment context, due to the imbalance of power between you and your workers."

Leaning on legitimate interests is not a free pass. It requires the three-part balancing exercise set out in our GDPR legitimate interest balancing test guide: a genuine interest, monitoring that is necessary to serve it, and interests that are not overridden by the worker's rights. Where special category data is in play, for example a call that reveals health or union membership, a further condition is needed, as our special category data playbook sets out. The DUAA's newer processing routes do not change this analysis for routine agent monitoring, and our recognised legitimate interests guide explains where those narrow grounds do and do not reach.

What must you tell your workers about AI monitoring?

You must tell workers, clearly and before it starts, that AI monitoring is happening, what it covers, why, and what you do with the results. Transparency to workers is a duty in its own right, distinct from the notice you give callers. A voice AI deployment that has a privacy notice for customers but nothing written for staff has only done half the work, and Dilr Voice ships the worker-facing configuration alongside the caller one.

The ICO's own framing is that monitoring must be the least intrusive route to a stated aim. In its words, you "must be clear about your purpose and select the least intrusive means to achieve it." In practice that means naming the purpose before choosing the tool, not reverse-engineering a purpose to fit a system you have already bought. The matrix below maps three common voice AI monitoring purposes to the worker-facing duty each one triggers and who holds the controller obligation.

Monitoring purposeWhat the worker must be toldLawful basis questionWho is controller
Automated QA scoring of callsThat AI grades their calls, on what criteria, and how scores are usedLegitimate interests, balancing test recordedThe employer
Sentiment or tone flaggingThat tone and wording are analysed, and the limits of that analysisLegitimate interests, necessity documentedThe employer
Productivity and handle-time metricsThat timing and activity are measured against a stated purposeLegitimate interests, proportionality shownThe employer
Covert monitoring of a suspected issueExceptional; justified and time-limited, not a standing defaultHigh bar; specific, evidenced groundsThe employer
Biometric or keystroke monitoringThat high-risk monitoring is used, with a DPIA behind itLegitimate interests plus DPIAThe employer

How do you set up compliant AI monitoring of agents?

You set up compliant agent monitoring as a sequence, not a switch: define the purpose, test whether the monitoring is necessary and proportionate, choose a lawful basis that is not consent, tell your workers, and record the decision so you can review it. Each step gates the next. If you cannot state the purpose in a sentence, you cannot test proportionality. Dilr Voice is built so an enterprise can evidence each of these stages rather than assert them.

The same discipline underpins our AI operating model consulting, where monitoring controls are designed in before a system goes live rather than retrofitted after a complaint. The flow below is the order the ICO's expectations impose.

The compliant agent-monitoring path
01Define the purposeOne plain sentence02Test necessity and proportionalityLeast intrusive means03Choose a lawful basisLegitimate interests, not consent04Tell your workersClear, before it starts05Record and reviewDPIA where high risk
Each stage gates the next; the lawful basis cannot be chosen before the purpose is fixed.

Who is the controller when a vendor's AI scores your agents?

The employer is the controller for worker monitoring even when a third-party model does the scoring. The vendor supplying the voice AI is typically a processor acting on the enterprise's instructions, so the duty to have a lawful basis, to tell workers and to keep monitoring proportionate falls on the employer, not the provider. That allocation matters because it is the enterprise, not the vendor, that answers to the ICO if the monitoring is challenged.

This is the same controller logic that governs the caller side, and getting the roles right is why we treat the DATS methodology as a compliance exercise as much as a technical one. A governed platform can give the employer the audit trail and configuration to meet its duty, but it cannot assume the duty on the employer's behalf. When roles blur, the fix is a written allocation, not a hopeful assumption, and our work on placing AI inside enterprise systems starts from that premise. For teams that want that allocation run as a standing function rather than a one-off document, our AI execution office owns it after go-live. If monitoring outputs later feed a decision that significantly affects an agent, the enterprise should also read across to the safeguards our subject access request guide for call recordings covers, because the worker has access rights over their own data too.

What is the best way to monitor voice AI agents compliantly in 2026?

The best way to monitor voice AI agents in 2026 is to treat the worker side as a designed control, not a reporting afterthought: a stated purpose, legitimate interests with a recorded balancing test, a written notice to staff, and a data protection impact assessment where the monitoring is high risk. The right platform then depends on how much scrutiny that monitoring will face, not on any vendor's marketing claims about quality scoring.

Self-serve builders such as Vapi, Retell AI, Bland AI and Synthflow can wire up agent analytics quickly, and for a small internal line that nobody will ever audit that may be all you need. Where the monitoring is systematic and the workforce is unionised or regulated, a governed platform such as PolyAI or Dilr Voice earns its place by making the lawful basis, the notice and the review auditable. The honest concession is that governance you never have to evidence is overhead, so scale and scrutiny decide the answer, not any single vendor.

Telephony and routing choices, whether you build on Twilio or a managed stack, do not change the analysis. The worker-facing duty attaches to the enterprise that decides why and how the monitoring happens, and that is a decision no integration removes.

Want to see this in production? Try Dilr Voice live, book an AI placement diagnostic, see our DATS methodology, or read about our approach to placing AI inside enterprise systems.

Do you need a DPIA to monitor workers with voice AI?

You need a data protection impact assessment where the monitoring is likely to be high risk, and systematic monitoring of workers frequently is. The ICO gives examples of high-risk monitoring such as keystroke monitoring and the use of workers' biometric data. Rather than repeat the mechanics here, our voice AI DPIA template walks through the assessment step by step; the point for worker monitoring is that the DPIA is where you evidence necessity and proportionality before you start.

Can you monitor agents covertly with voice AI?

Covert monitoring of agents is possible only in narrow, evidenced circumstances, never as a standing default. The ICO expects covert monitoring to be exceptional, tied to a specific suspected problem, time-limited, and justified in writing before it begins. For everyday voice AI quality work the right posture is overt monitoring that workers know about, because the transparency duty and the difficulty of justifying secrecy make covert analytics a poor fit for routine agent management under UK data protection law.

Does monitoring workers need a different approach from monitoring callers?

Yes. The same recording carries two data subjects, so it carries two duties. The caller work covers consent, retention and access from the customer's side, while worker monitoring adds a separate lawful basis, a notice written for staff, and a proportionality test the caller journey never asks for. Enterprises that change contact centre roles as AI scales should also plan the employment side early, which our workforce redeployment planning guide sets out alongside the wider compliance library.

Service
AI Placement Diagnostic
Service
AI Operating Model
Product
Dilr Voice
Talk to the operators

Score your agents without failing your workers.

30-min scoping call · No deck · Confidential. We will tell you where AI monitoring fits, and how to keep it lawful.

Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.

voice AI worker monitoringmonitoring workers UK GDPRemployee monitoring data protectionAI call quality scoring agentsvoice ai monitoring redditbest voice ai monitoring compliance 2026Dilr Voice

Questions this article answers

What does it mean to monitor workers with voice AI?

Monitoring workers with voice AI means using the same call system to observe your own staff, not only your customers. When an AI agent transcribes a call, scores the human who handled it, or flags their tone or handle time, the enterprise is processing worker personal data. That engages the ICO's monitoring-workers rules, a distinct data protection duty owed to employees. Dilr Voice treats the worker side of a deployment as a first-class obligation.

When does voice AI cross from monitoring calls to monitoring your own agents?

Voice AI crosses into worker monitoring the moment its output is used to observe, assess or manage the person handling the call rather than the call itself. Recording a conversation for a caller's benefit is one purpose. Running automated quality scoring, sentiment flags or productivity metrics against the agent is a second, worker-facing purpose. The ICO treats these as different processing activities, and Dilr Voice keeps them separated so an enterprise controls agent analytics itself.

What lawful basis can you use to monitor workers, and why not consent?

You need a lawful basis under Article 6 of the UK GDPR before you monitor workers, and for most voice AI analytics that basis is legitimate interests under Article 6(1)(f), not consent. The reason is structural: an employer and a worker are not equals, so a worker cannot freely refuse. The ICO is direct about this in its monitoring-workers guidance, which is why the enterprise, not the agent, has to carry the justification through a documented balancing test.

What must you tell your workers about AI monitoring?

You must tell workers, clearly and before it starts, that AI monitoring is happening, what it covers, why, and what you do with the results. Transparency to workers is a duty in its own right, distinct from the notice you give callers. A voice AI deployment that has a privacy notice for customers but nothing written for staff has only done half the work, and Dilr Voice ships the worker-facing configuration alongside the caller one.

How do you set up compliant AI monitoring of agents?

You set up compliant agent monitoring as a sequence, not a switch: define the purpose, test whether the monitoring is necessary and proportionate, choose a lawful basis that is not consent, tell your workers, and record the decision so you can review it. Each step gates the next. If you cannot state the purpose in a sentence, you cannot test proportionality. Dilr Voice is built so an enterprise can evidence each of these stages rather than assert them.

Who is the controller when a vendor's AI scores your agents?

The employer is the controller for worker monitoring even when a third-party model does the scoring. The vendor supplying the voice AI is typically a processor acting on the enterprise's instructions, so the duty to have a lawful basis, to tell workers and to keep monitoring proportionate falls on the employer, not the provider. That allocation matters because it is the enterprise, not the vendor, that answers to the ICO if the monitoring is challenged.

What is the best way to monitor voice AI agents compliantly in 2026?

The best way to monitor voice AI agents in 2026 is to treat the worker side as a designed control, not a reporting afterthought: a stated purpose, legitimate interests with a recorded balancing test, a written notice to staff, and a data protection impact assessment where the monitoring is high risk. The right platform then depends on how much scrutiny that monitoring will face, not on any vendor's marketing claims about quality scoring.

Do you need a DPIA to monitor workers with voice AI?

You need a data protection impact assessment where the monitoring is likely to be high risk, and systematic monitoring of workers frequently is. The ICO gives examples of high-risk monitoring such as keystroke monitoring and the use of workers' biometric data. Rather than repeat the mechanics here, our voice AI DPIA template walks through the assessment step by step; the point for worker monitoring is that the DPIA is where you evidence necessity and proportionality before you start.

Compliance

Deploy voice AI without failing an audit

Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.

Related articles

← Previous
AI Voice for Pest Control: Callout Triage Guide

One email, once a month. No hype. Just what we learned shipping.