What happened
It was reported that in August 2026 the United States Federal Trade Commission announced final orders against CMG Media Corporation, MindSift LLC and 1010 Digital Works LLC, settling charges over an advertising service marketed as Active Listening.
The Commission alleged that advertisers were told the service used an algorithm to listen for relevant conversations through smart devices, and that consumers had agreed to this kind of targeting. In its complaint against CMG, the Commission quoted the company’s marketing: “Voice data goes beyond search engine data, so every casual conversation between two consumers becomes a tool for you to target, retarget, and retain customers”.
But on the Commission’s account, that was not how the service worked. The Commission alleged that it did not collect or use voice data in any manner, and that what customers were actually buying were leads based on purchased consumer email lists, resold at a significant markup. The Commission also alleged that consumers had not consented to the targeting.
The complaints against MindSift and 1010 Digital Works also alleged that the firms provided the means for the deception. No respondent admitted the allegations, and the matters were settled through consent orders requiring payments totalling 930,000 United States dollars, including 880,000 from CMG.
What an auditable version would have shown
According to the complaints, many of the customers buying Active Listening were small businesses. They were reportedly told they were buying leads produced by a system that listened for and detected relevant conversations, but the complaints do not show customers being given evidence of how an individual lead had actually been produced.
One exchange reported in the complaint makes that particularly interesting. When a CMG customer became sceptical about how the service worked, the Commission alleged that the explanation the customer received had been ghost written by one of the firms supplying the service.
In this entry’s reading, the evidence should have travelled with the leads. For each one, a customer should have been able to see what triggered it, where it came from, when it was generated and what consumer permission allowed the information to be used.
If the Commission’s allegation is right, those records would have exposed the problem fairly quickly, because on the Commission’s account there was no listening or detection behind the leads to record. The orders do not require this kind of record, instead they prohibit the firms from making claims about capabilities they cannot support and define Voice Data so it is clear what those restrictions cover.
Where the gap was
In this entry’s reading, the gap was between what customers were reportedly told the technology was doing and the evidence they were given to support it.
A ConductRecord keeps one signed record for each action a system takes, including the inputs, tool calls and output, written at the time it happens. If a lead was said to come from a particular mechanism, there would be a record of that mechanism actually operating.
A MetricRecord is designed to compute signed aggregate metrics over those records, with a hash linking the overall figure to the events underneath it. That gives a customer, board or regulator somewhere to go when a seller makes a claim about how the system is performing, rather than having to accept the claim on the seller’s word.
Neither is a control the Commission required. ConductRecord and MetricRecord are Headlights designs.
What governance should have looked like
The Commission reportedly took a more direct approach in its orders, prohibiting the firms from making the categories of misrepresentation set out in the complaints and requiring compliance reporting and recordkeeping for the period covered by the orders.
Where the capability itself is what a customer is buying, best practice would be to make the evidence part of the sale. If a service is sold on the basis that a particular technology produces the leads, customers should be able to see evidence of that technology operating on their own campaigns.
The same applies to performance claims. If a figure is being used to sell the service, there should be a clear way to trace where it came from and what sits underneath it. A small business should not need an enforcement action years later to find out what it was actually paying for.
Failure Pattern: an advertising capability was described to buyers in terms of what a system could hear and detect, and the regulator alleged that the service did not collect or use voice data or use AI to detect pertinent conversations, and that what was delivered was consumer email list buying.
Governance Principle: where a capability is sold on what an automated system does, the seller should be able to produce a record of that system operating on the buyer’s own campaign, and the buyer should be able to check the claim against something other than the marketing.
The reference implementation of ConductRecord and MetricRecord is open source. It lives at github.com/saffronandindia/headlights-oss, Apache 2.0 licensed and free to install. The repository is public now.
Sources
- FTC finalizes orders with Cox Media Group and two other firms over Active Listening claims (Federal Trade Commission, 27 August 2026)
- Complaint against CMG Media Corporation, matter 242-3029 (Federal Trade Commission)
- Final order, CMG Media Corporation, docket C-4838, issued 26 August 2026 (Federal Trade Commission)
- Complaint against MindSift LLC, matter 242-3030 (Federal Trade Commission)
- Complaint against 1010 Digital Works LLC, matter 242-3033 (Federal Trade Commission)