Dilr Voice is an enterprise voice AI platform. When AI scores, transcribes or flags your own contact centre agents, you are monitoring workers under UK data protection law, not just callers. This guide explains the ICO monitoring rules, why worker consent rarely holds, the lawful basis to use, and what you must tell staff.
DE
Dilr.ai EngineeringEngineering team
Published Sep 6, 2026Read 11 min
Every enterprise that puts voice AI on its phone lines is told to think about the caller: consent, call recording, retention, the subject access request that lands three months later. Far fewer buyers notice the second person on the same call. When the AI transcribes the conversation, scores the human agent who handled it, or flags that agent's tone, script adherence or silence, the enterprise has quietly started to monitor its own workers. That is a separate data protection duty, owed to employees, and it does not disappear because the primary purpose was customer service.
The gap matters because adoption is now mainstream. McKinsey's State of AI 2025 found that around 88 percent of organisations report using AI in at least one function, while only about 6 percent capture material EBIT impact from it. A large share of that usage sits in the contact centre, where the same models that answer callers are also the cheapest way to grade agents at scale. The regulator has already drawn the line for that second use, and most deployment plans do not read it.
This guide sets out the worker-facing side of a voice AI deployment: when call handling tips into staff monitoring, what lawful basis actually holds, why worker consent is the wrong instrument, what you must tell your people, and who carries the duty when a vendor's model does the scoring.
This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system.
What does it mean to monitor workers with voice AI?
Monitoring workers with voice AI means using the same call system to observe your own staff, not only your customers. When an AI agent transcribes a call, scores the human who handled it, or flags their tone or handle time, the enterprise is processing worker personal data. That engages the ICO's monitoring-workers rules, a distinct data protection duty owed to employees. Dilr Voice treats the worker side of a deployment as a first-class obligation.
The practical consequence is that one recording now sits under two duties at once. The caller is a data subject, owed the transparency, retention and access rights covered in our multi-jurisdiction call recording consent map. The agent on the same line is also a data subject, owed a duty the caller work never mentions. Treating the recording as a single customer-service artefact is where the compliance gap opens. The Information Commissioner's Office published dedicated guidance on monitoring workers in October 2023, and it applies to any monitoring of people who carry out work for you, whether systematic or occasional.
When does voice AI cross from monitoring calls to monitoring your own agents?
Voice AI crosses into worker monitoring the moment its output is used to observe, assess or manage the person handling the call rather than the call itself. Recording a conversation for a caller's benefit is one purpose. Running automated quality scoring, sentiment flags or productivity metrics against the agent is a second, worker-facing purpose. The ICO treats these as different processing activities, and Dilr Voice keeps them separated so an enterprise controls agent analytics itself.
The line is easy to miss because the feature looks like a natural extension of quality assurance. A product built to grade calls at scale, like the approach in our automated agent quality scoring guide, becomes a monitoring system the instant those scores attach to a named employee and shape coaching, ranking or discipline. The data protection question is not whether the scoring is accurate. It is whether the enterprise has a lawful basis, has told the worker, and has kept the monitoring proportionate to a purpose it can state plainly.
What lawful basis can you use to monitor workers, and why not consent?
You need a lawful basis under Article 6 of the UK GDPR before you monitor workers, and for most voice AI analytics that basis is legitimate interests under Article 6(1)(f), not consent. The reason is structural: an employer and a worker are not equals, so a worker cannot freely refuse. The ICO is direct about this in its monitoring-workers guidance, which is why the enterprise, not the agent, has to carry the justification through a documented balancing test.
The ICO puts the point plainly:
"consent is not usually appropriate in the employment context, due to the imbalance of power between you and your workers."
Leaning on legitimate interests is not a free pass. It requires the three-part balancing exercise set out in our GDPR legitimate interest balancing test guide: a genuine interest, monitoring that is necessary to serve it, and interests that are not overridden by the worker's rights. Where special category data is in play, for example a call that reveals health or union membership, a further condition is needed, as our special category data playbook sets out. The DUAA's newer processing routes do not change this analysis for routine agent monitoring, and our recognised legitimate interests guide explains where those narrow grounds do and do not reach.
What must you tell your workers about AI monitoring?
You must tell workers, clearly and before it starts, that AI monitoring is happening, what it covers, why, and what you do with the results. Transparency to workers is a duty in its own right, distinct from the notice you give callers. A voice AI deployment that has a privacy notice for customers but nothing written for staff has only done half the work, and Dilr Voice ships the worker-facing configuration alongside the caller one.
The ICO's own framing is that monitoring must be the least intrusive route to a stated aim. In its words, you "must be clear about your purpose and select the least intrusive means to achieve it." In practice that means naming the purpose before choosing the tool, not reverse-engineering a purpose to fit a system you have already bought. The matrix below maps three common voice AI monitoring purposes to the worker-facing duty each one triggers and who holds the controller obligation.
Monitoring purpose
What the worker must be told
Lawful basis question
Who is controller
Automated QA scoring of calls
That AI grades their calls, on what criteria, and how scores are used
Legitimate interests, balancing test recorded
The employer
Sentiment or tone flagging
That tone and wording are analysed, and the limits of that analysis
Legitimate interests, necessity documented
The employer
Productivity and handle-time metrics
That timing and activity are measured against a stated purpose
Legitimate interests, proportionality shown
The employer
Covert monitoring of a suspected issue
Exceptional; justified and time-limited, not a standing default
High bar; specific, evidenced grounds
The employer
Biometric or keystroke monitoring
That high-risk monitoring is used, with a DPIA behind it
Legitimate interests plus DPIA
The employer
How do you set up compliant AI monitoring of agents?
You set up compliant agent monitoring as a sequence, not a switch: define the purpose, test whether the monitoring is necessary and proportionate, choose a lawful basis that is not consent, tell your workers, and record the decision so you can review it. Each step gates the next. If you cannot state the purpose in a sentence, you cannot test proportionality. Dilr Voice is built so an enterprise can evidence each of these stages rather than assert them.
The same discipline underpins our AI operating model consulting, where monitoring controls are designed in before a system goes live rather than retrofitted after a complaint. The flow below is the order the ICO's expectations impose.
The compliant agent-monitoring pathEach stage gates the next; the lawful basis cannot be chosen before the purpose is fixed.
Who is the controller when a vendor's AI scores your agents?
The employer is the controller for worker monitoring even when a third-party model does the scoring. The vendor supplying the voice AI is typically a processor acting on the enterprise's instructions, so the duty to have a lawful basis, to tell workers and to keep monitoring proportionate falls on the employer, not the provider. That allocation matters because it is the enterprise, not the vendor, that answers to the ICO if the monitoring is challenged.
This is the same controller logic that governs the caller side, and getting the roles right is why we treat the DATS methodology as a compliance exercise as much as a technical one. A governed platform can give the employer the audit trail and configuration to meet its duty, but it cannot assume the duty on the employer's behalf. When roles blur, the fix is a written allocation, not a hopeful assumption, and our work on placing AI inside enterprise systems starts from that premise. For teams that want that allocation run as a standing function rather than a one-off document, our AI execution office owns it after go-live. If monitoring outputs later feed a decision that significantly affects an agent, the enterprise should also read across to the safeguards our subject access request guide for call recordings covers, because the worker has access rights over their own data too.
What is the best way to monitor voice AI agents compliantly in 2026?
The best way to monitor voice AI agents in 2026 is to treat the worker side as a designed control, not a reporting afterthought: a stated purpose, legitimate interests with a recorded balancing test, a written notice to staff, and a data protection impact assessment where the monitoring is high risk. The right platform then depends on how much scrutiny that monitoring will face, not on any vendor's marketing claims about quality scoring.
Self-serve builders such as Vapi, Retell AI, Bland AI and Synthflow can wire up agent analytics quickly, and for a small internal line that nobody will ever audit that may be all you need. Where the monitoring is systematic and the workforce is unionised or regulated, a governed platform such as PolyAI or Dilr Voice earns its place by making the lawful basis, the notice and the review auditable. The honest concession is that governance you never have to evidence is overhead, so scale and scrutiny decide the answer, not any single vendor.
Telephony and routing choices, whether you build on Twilio or a managed stack, do not change the analysis. The worker-facing duty attaches to the enterprise that decides why and how the monitoring happens, and that is a decision no integration removes.
Do you need a DPIA to monitor workers with voice AI?
You need a data protection impact assessment where the monitoring is likely to be high risk, and systematic monitoring of workers frequently is. The ICO gives examples of high-risk monitoring such as keystroke monitoring and the use of workers' biometric data. Rather than repeat the mechanics here, our voice AI DPIA template walks through the assessment step by step; the point for worker monitoring is that the DPIA is where you evidence necessity and proportionality before you start.
Can you monitor agents covertly with voice AI?
Covert monitoring of agents is possible only in narrow, evidenced circumstances, never as a standing default. The ICO expects covert monitoring to be exceptional, tied to a specific suspected problem, time-limited, and justified in writing before it begins. For everyday voice AI quality work the right posture is overt monitoring that workers know about, because the transparency duty and the difficulty of justifying secrecy make covert analytics a poor fit for routine agent management under UK data protection law.
Does monitoring workers need a different approach from monitoring callers?
Yes. The same recording carries two data subjects, so it carries two duties. The caller work covers consent, retention and access from the customer's side, while worker monitoring adds a separate lawful basis, a notice written for staff, and a proportionality test the caller journey never asks for. Enterprises that change contact centre roles as AI scales should also plan the employment side early, which our workforce redeployment planning guide sets out alongside the wider compliance library.
Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.
voice AI worker monitoringmonitoring workers UK GDPRemployee monitoring data protectionAI call quality scoring agentsvoice ai monitoring redditbest voice ai monitoring compliance 2026Dilr Voice
Questions this article answers
What does it mean to monitor workers with voice AI?
Monitoring workers with voice AI means using the same call system to observe your own staff, not only your customers. When an AI agent transcribes a call, scores the human who handled it, or flags their tone or handle time, the enterprise is processing worker personal data. That engages the ICO's monitoring-workers rules, a distinct data protection duty owed to employees. Dilr Voice treats the worker side of a deployment as a first-class obligation.
When does voice AI cross from monitoring calls to monitoring your own agents?
Voice AI crosses into worker monitoring the moment its output is used to observe, assess or manage the person handling the call rather than the call itself. Recording a conversation for a caller's benefit is one purpose. Running automated quality scoring, sentiment flags or productivity metrics against the agent is a second, worker-facing purpose. The ICO treats these as different processing activities, and Dilr Voice keeps them separated so an enterprise controls agent analytics itself.
What lawful basis can you use to monitor workers, and why not consent?
You need a lawful basis under Article 6 of the UK GDPR before you monitor workers, and for most voice AI analytics that basis is legitimate interests under Article 6(1)(f), not consent. The reason is structural: an employer and a worker are not equals, so a worker cannot freely refuse. The ICO is direct about this in its monitoring-workers guidance, which is why the enterprise, not the agent, has to carry the justification through a documented balancing test.
What must you tell your workers about AI monitoring?
You must tell workers, clearly and before it starts, that AI monitoring is happening, what it covers, why, and what you do with the results. Transparency to workers is a duty in its own right, distinct from the notice you give callers. A voice AI deployment that has a privacy notice for customers but nothing written for staff has only done half the work, and Dilr Voice ships the worker-facing configuration alongside the caller one.
How do you set up compliant AI monitoring of agents?
You set up compliant agent monitoring as a sequence, not a switch: define the purpose, test whether the monitoring is necessary and proportionate, choose a lawful basis that is not consent, tell your workers, and record the decision so you can review it. Each step gates the next. If you cannot state the purpose in a sentence, you cannot test proportionality. Dilr Voice is built so an enterprise can evidence each of these stages rather than assert them.
Who is the controller when a vendor's AI scores your agents?
The employer is the controller for worker monitoring even when a third-party model does the scoring. The vendor supplying the voice AI is typically a processor acting on the enterprise's instructions, so the duty to have a lawful basis, to tell workers and to keep monitoring proportionate falls on the employer, not the provider. That allocation matters because it is the enterprise, not the vendor, that answers to the ICO if the monitoring is challenged.
What is the best way to monitor voice AI agents compliantly in 2026?
The best way to monitor voice AI agents in 2026 is to treat the worker side as a designed control, not a reporting afterthought: a stated purpose, legitimate interests with a recorded balancing test, a written notice to staff, and a data protection impact assessment where the monitoring is high risk. The right platform then depends on how much scrutiny that monitoring will face, not on any vendor's marketing claims about quality scoring.
Do you need a DPIA to monitor workers with voice AI?
You need a data protection impact assessment where the monitoring is likely to be high risk, and systematic monitoring of workers frequently is. The ICO gives examples of high-risk monitoring such as keystroke monitoring and the use of workers' biometric data. Rather than repeat the mechanics here, our voice AI DPIA template walks through the assessment step by step; the point for worker monitoring is that the DPIA is where you evidence necessity and proportionality before you start.
DE
Dilr.ai Engineering
Engineering team
Compliance
Deploy voice AI without failing an audit
Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.