The Short Answer: More Than the Marketing Suggests
Smart home devices - speakers, doorbells, TVs, thermostats, plugs - now number in the tens of billions worldwide, and by most industry estimates, the majority collect meaningfully more data than users realise. One widely cited industry analysis found 82% of smart home devices gather behavioural data beyond their core function, 57% send that data to manufacturer cloud servers by default, and 38% of smart home networks have experienced some form of security breach. None of this means every device is secretly spying with malicious intent - but it does mean the default configuration of most smart homes collects and transmits far more than the average buyer assumes when they unbox a smart speaker.
What "Always Listening" Actually Means
Smart speakers are technically designed to only process and transmit audio after detecting a wake word, using local buffer storage that constantly listens for that trigger without transmitting anything. In practice, researchers at Northeastern University's Mon(IoT)r Lab tested multiple popular smart speakers and found they misactivate - falsely triggering recording mode without an actual wake word - during normal television viewing surprisingly often, in some cases nearly once per hour. Roughly one in ten of those false activations lasted ten seconds or longer, each one sending an audio clip to the manufacturer's cloud servers, where it's stored, sometimes indefinitely, unless the user has specifically configured automatic deletion.
The Regulatory Record Isn't Reassuring
This isn't purely hypothetical concern - it has produced real enforcement action. The US Federal Trade Commission sued Amazon over allegations the company made it deliberately difficult for users to delete Alexa voice recordings and retained data longer than its own privacy policy promised. Google faced separate scrutiny over how Google Home collected location data without sufficiently clear user consent. Security researchers have also documented cases of popular smart devices - including models from major manufacturers - transmitting audio and usage data to cloud servers considerably more often than their published privacy policies disclosed, including instances where devices sent data even when the microphone was supposedly muted.
The Bigger Risk Might Not Be Listening - It's the Network Door
Beyond the privacy question, smart home devices represent a genuine security vulnerability that's easy to underestimate. A compromised smart plug or bulb isn't dangerous on its own - the risk is that it shares your home network with your laptop, phone, and every account you're logged into on those devices. Security firm Bitdefender's threat intelligence team documented smart plugs, TVs, and other connected consumer electronics among the most frequently targeted device categories in attacks on home networks throughout late 2025, precisely because they're often the weakest-secured entry point into an otherwise reasonably protected home network.
What Actually Reduces Your Exposure
A few concrete steps meaningfully cut your risk without requiring you to abandon smart home devices altogether. Setting up a separate guest network specifically for IoT devices - a ten-minute task on most routers made in the last five years - isolates a compromised smart bulb from your laptop and financial accounts. Reviewing and disabling microphone or camera access for smart TV apps that don't need it for core functionality closes an unnecessary data channel. Checking whether your devices support local-only processing standards like Matter, which can operate without sending data to manufacturer cloud servers at all, is worth prioritising for any new purchase. And periodically reviewing and deleting stored voice recordings through your device manufacturer's account settings - a feature every major platform now offers, even if it's not prominently advertised - closes the gap between what you assume happens to your data and what actually does.