10 Ways To Avoid Privacy Risks Revealed In AI Notetaker Suits

By Jennifer Ruehr (August 28, 2026)

On Aug. 13, the U.S. District Court for the Northern District of California allowed significant portions of the proposed class action in In re: Otter.ai Privacy Litigation to proceed.

The suit, first filed in August 2025, challenges Otter.ai Inc.'s transcription and AI notetaking services. The plaintiffs allege that the company's meeting assistant joined virtual meetings, recorded and transcribed conversations in real time, collected voice-related information, retained meeting content, and used that information to improve its products and machine-learning systems.

Key Rulings From the Otter.ai Order

The ruling addressed several important privacy and communications-law issues, and reflects a common theme across claims involving standing, the Electronic Communications Privacy Act, the California Invasion of Privacy Act and the Illinois Biometric Information Privacy Act: When a vendor captures, retains or uses conversation content or voice-related data for its own business purposes, an AI transcription tool may look less like a passive service provider and more like an independent actor raising privacy, wiretap, and biometric risks.

Standing

The plaintiffs plausibly alleged a concrete privacy injury based on the unauthorized interception, recording, transcription, retention and use of their private conversations. The decision suggests that courts may view the capture and use of conversation content as meaningfully different from less intrusive forms of tracking.

The Electronic Communications Privacy Act

The ECPA claims survived because the plaintiffs plausibly alleged real-time interception of their communications.

The party exception did not defeat the claims at the pleading stage, particularly where the vendor allegedly used captured data for its own business purposes. The ruling highlights the importance of notice, consent and the role of service providers.

The California Invasion of Privacy Act

The claim involving Section 631 of CIPA also moved forward based on allegations that Otter independently retained and used communications, rather than acting as a passive service provider.

A vendor's independent use of meeting data may affect whether it is viewed as an extension of the customer or as a third-party interceptor.

The Biometric Information Privacy Act

For BIPA, the Illinois plaintiffs plausibly alleged that Otter collected and retained voiceprints capable of identifying speakers without providing the notice and consent required under the Illinois law. The ruling underscores the importance of evaluating speaker recognition, voice profiles and similar functions for potential biometric privacy implications.

By contrast, the Computer Fraud and Abuse Act, California Comprehensive Computer Data and Access Fraud Act and certain state privacy claims were dismissed where the plaintiffs did not sufficiently allege unauthorized computer access, statutory loss or the confidential nature of specific communications.

Those dismissals demonstrate how detailed factual allegations regarding the information collected and the sensitivity of communications can affect claim viability.

Related Litigation Development: Hidden AI Notetaker Risk

In addition to the Otter.ai order, a complaint was filed on July 30 against a provider of AI-powered notetaking services in the Northern District of California in Chamberlain v. Granola Inc. and Granola Labs Ltd. This underscores that litigation risk is not limited to tools that visibly join meetings as bots.

The complaint alleges that Granola intentionally designed and marketed its AI notetaker to operate without a visible meeting bot or participant notification, captured microphone and system audio in real time, generated transcripts and speaker attribution, enabled downstream sharing of meeting notes, and used meeting-derived data for product improvement or model training by default for certain users.

These allegations, if proven, highlight a broader risk area for organizations: AI meeting tools may raise privacy and wiretap concerns not only when they record or transcribe conversations, but also when their operation is not obvious to all participants, when notice and consent controls rest solely with the tool user, and when meeting data may be retained, shared, integrated with other systems, or repurposed for the vendor's benefit.

AI Transcription Compliance Tips

Organizations using AI transcription, notetaking or meeting assistant tools should review these technologies as communications-capture tools, not just productivity aids. Before deployment, consider the following steps.

1.  Make recording and AI processing clear.

Provide participant-facing notice that identifies any third-party AI vendor and explains what the tool does, including recording, transcription, summarization, speaker identification, analytics or other AI-enabled processing.

Confirm what content, audio, video, transcripts, summaries, metadata, and speaker data the tool collects, how those outputs are used, and how long they are stored.

2.  Build notice and consent into the user experience.

Evaluate when participants receive notice and how consent is obtained and documented where required, including for all-party consent states and non-U.S. participants. Consider whether advance notice is needed in addition to in-meeting prompts, and whether the tool can operate without a visible bot, watermark, chat notification or other participant-facing disclosure.

3.  Review default settings before rollout.

Confirm whether recording, transcription, speaker attribution, sharing, integrations, analytics or model training uses are enabled by default. Determine whether IT administrators can centrally manage those settings or whether controls are left to individual users.

4.  Assess nonuser participant controls.

Determine whether participants who are not account holders can receive notice, object, opt out, request deletion or restrict secondary uses of their communications. This is especially important where external participants may not know their communications are being captured or reused.

5.  Limit vendor secondary use.

Review whether the vendor uses customer or participant data for analytics, product improvement, model training, quality control, personalization or other secondary purposes. Confirm whether those uses can be disabled or contractually restricted.

6.  Evaluate biometric and speaker-identification risk.

Determine whether the tool identifies speakers or creates voice-based profiles, voiceprints, voice embeddings or similar identifiers. If so, assess whether biometric privacy notice, consent, retention or deletion obligations may apply and whether the tool can be configured for plain transcript generation.

7.  Control access, sharing and integrations.

Limit who can view, download, share, search or export recordings, transcripts, summaries, and speaker profiles. Review whether meeting content can be shared through public links, collaboration platforms, customer relationship management systems, productivity tools, or workflow automations, and whether copies, previews, or summaries remain available after the original content is restricted or deleted.

8.  Set retention and deletion rules.

Establish retention periods for each category of meeting-derived data, including recordings, transcripts, summaries, metadata, speaker profiles, exports, integrations, and data used for analytics or model training. Confirm whether the organization can enforce deletion or retention limits centrally.

9.  Restrict sensitive use cases.

Identify categories of meetings where recording, transcription, summarization, speaker identification, sharing or model-training uses should be disabled.

Examples may include privileged legal advice, investigations, accommodations, health or medical information, sensitive human resources matters, confidential strategy sessions, student or applicant information, or client-confidential discussions.

10.  Coordinate ownership across teams.

Align procurement, IT, privacy, security, HR and legal review both before deployment and during ongoing vendor governance. The review should result in clear decisions about approved tools, required notices, consent workflows, default settings, retention controls and policies, vendor commitments, restricted meetings, and user guidance.

Looking Ahead

The Otter.ai ruling and the Granola complaint underscore a common lesson: Organizations should evaluate AI meeting tools not only for productivity benefits, but also for how they collect, process, retain and use communications data.

As these technologies continue to evolve, companies' legal, privacy and compliance teams should ensure that their governance frameworks address transparency, consent, biometric considerations, vendor practices, retention and downstream data use.

 

Jennifer Ruehr is a co-managing partner and co-chair of the employment privacy and the cybersecurity and breach response groups at Hintze Law PLLC.

 

The opinions expressed are those of the author(s) and do not necessarily reflect the views of their employer, its clients, or Portfolio Media Inc., or any of its or their respective affiliates. This article is for general information purposes and is not intended to be and should not be taken as legal advice.