AI-powered plush toys, smart pets, and voice-clone services — what they collect from a child, how cloned voices are used to bait families into scams, and how to evaluate one before bringing it into the home.
AI Toys is the risk posed by internet-connected or AI-powered toys that can record, respond to, or imitate a child's voice, raising privacy and safety concerns.
A new generation of children's toys ships with cloud-connected microphones, large-language-model chatbots, and the ability to imitate a family member's voice. Some are aimed at toddlers (AI plush companions); some at older children (chatbot bracelets and pendants); and adjacent services let anyone clone a 30-second voice sample for a few pounds. The result is a category of products that hold extended conversations with children, store recordings on a third-party server, and — at the same time — make it trivially easy for scammers to fake a parent or grandparent's voice. The Children's Code (Age-Appropriate Design Code) and UK GDPR set the rules for how children's data may be processed; many imported AI toys do not meet them.
An AI toy typically streams a child's voice to a cloud service, transcribes it, sends it through a large language model, and streams a response back. Some keep recordings indefinitely; some do not encrypt them; some have been found exposing data through unsecured APIs. Separately, voice-clone services can take a short clip from a school play, YouTube video, or Instagram story and generate a near-identical synthesised voice — already used in UK family-impersonation phone scams ('Mum, I'm in trouble, please send money'). The two trends overlap: an AI toy is also a high-quality voice sample of a child.
In your child's behaviour
On their device
Check the privacy policy before the toy enters the house
Look for a clear UK or EU-based data controller, a stated retention period for recordings, an off-switch for the microphone, and parent access to delete recordings. If any of those are missing, treat the toy as unsuitable.
Keep voice samples of the family small and private
Avoid posting long, clean voice recordings of children or grandparents publicly. Voice-clone services need very little material to produce a convincing fake.
Agree a family code phrase
A short, mundane phrase only the family knows, used to verify any phone call asking for money, lifts, or sensitive information — this defeats almost all voice-clone scam calls.
Use the ICO if data is mishandled
Under UK GDPR you can request access to or deletion of a child's data. If a manufacturer refuses or ignores you, complain to the ICO on 0303 123 1113.
In immediate danger: call 999. For non-emergency police matters, call 101.
Concerned about a child but it's not an emergency? NSPCC helpline 0808 800 5000. Childline for young people 0800 1111.
This is practical educational content to support families. For case-specific concerns about a child's safety, contact the NSPCC helpline on 0808 800 5000 or your local safeguarding team.
Myth: If a talking or AI toy is on sale in a big UK shop or marketplace, it must have passed proper privacy and security checks.
Fact: Physical safety marks such as CE or UKCA cover things like choking hazards and electrical safety, not data privacy or cybersecurity, and being listed by a large retailer is not a safeguarding guarantee. Consumer testing by Which? has found connected toys with unsecured Bluetooth that let a stranger nearby pair with the toy and speak to a child without any password. It is worth checking the privacy policy and security of a connected toy yourself before it comes into the house.
Myth: Whatever my child says to the toy just stays on the toy, so a chatbot toy is harmless.
Fact: Many AI toys do not process speech on the toy itself; they stream a child's voice to a company's servers, where recordings may be stored, shared with third parties, or used to train systems. The CloudPets connected-toy breach exposed children's and parents' voice recordings that had been left in an insecure database. Look for a toy with a clear data controller, a stated retention period, an off-switch for the microphone, and a way for you to delete recordings.
Myth: Regulators would have taken any genuinely dangerous connected toy off the market by now.
Fact: Oversight is patchy and varies by country, so availability is not proof of safety. Germany's telecoms regulator banned the 'My Friend Cayla' doll as an unauthorised surveillance device because it could transmit what a child said and be paired with over an insecure connection, yet similar imported toys have continued to appear elsewhere. A toy being on sale does not mean it meets the ICO's Children's Code, so it is worth evaluating each one on its own merits.
Before any talking or AI toy enters the home, check who makes it, whether recordings are stored and can be deleted, and whether the microphone can be switched off. If there is no clear UK or EU data controller and no obvious off-switch, choose a simpler toy that does not listen or connect.
Keep connected toys out of the bedroom, switch them off when they are not being played with, and read the app's permissions and privacy policy before setting it up. If you want a child's recordings removed you can ask the maker, and escalate to the ICO if they refuse or ignore you.
Sit with your child when they use a chatbot toy so you can hear what it says back, and remind them not to tell it secrets, their full name, or where they live. Turn off Bluetooth or the connection when the toy is not in use to reduce the chance of anyone else pairing with it.
Explain that a connected toy or companion app records their voice and sends it to a company, so it is not a private space and personal details should not be shared with it. Encourage them to come to you if the toy ever says something that confuses or worries them, and review together what data the app collects.
Was this page helpful?
Get practical child safety updates in your inbox. No spam.