Google Meet's Gemini AI and the Thele v. Google Lawsuit: What the July 2026 Dismissal Means for Your Meeting Privacy
Published July 21, 2026
- On July 7, 2026, Judge Noël Wise dismissed Thele v. Google (5:25-cv-09704) for lack of standing but granted 21 days to refile — the case is paused, not over.
- The complaint alleges Google flipped Gemini 'smart features' from opt-in to on-by-default across Gmail, Chat, and Meet on October 10, 2025, potentially exposing 1.8 billion accounts to AI scanning.
- CIPA §637.2 authorizes $5,000 per violation — the same statute driving the Otter.ai and Fireflies BIPA lawsuits, all pending in the Northern District of California.
- Turning off your own Gemini toggle does not stop AI scanning by other participants who still have it on — the only reliable defense is capturing meetings on-device.
- Basil AI transcribes 100% on-device using Apple Speech Recognition, so no audio, transcript, or voiceprint reaches Google, Otter, Fireflies, or any other cloud vendor.
Quick answer: As of July 2026, Google Meet's Gemini 'smart features' were switched on by default in October 2025, prompting the Thele v. Google class action alleging illegal interception under CIPA. A federal judge dismissed the case on July 7, 2026 for lack of standing, but gave plaintiffs 21 days to refile. The default-on design remains — and is not blocked by turning Gemini off manually if others on the call still have it enabled.
Published July 21, 2026 · 10 min read
If you have used Google Meet, Gmail, or Google Chat since October 10, 2025, a federal class action alleged that Google's Gemini AI has been silently reading your private communications by default. On July 7, 2026, that case — Thele v. Google LLC, No. 5:25-cv-09704 (N.D. Cal.) — was dismissed for lack of standing, but the judge gave plaintiffs 21 days to refile. The default-on design the complaint targets is still live in your account today.
This article explains exactly what the complaint alleged, why Bloomberg Law reported Google beat the first round, and — critically for privacy-conscious professionals — how to run meetings so that no AI vendor (Google, Otter, Fireflies, or otherwise) receives your audio or transcripts in the first place.
What Thele v. Google Actually Alleges
The complaint, filed on November 11, 2025 by Illinois consumer Thomas Thele in the Northern District of California, is short — 21 pages — but its factual claim is dramatic. According to a summary by ClassAction.org, on or about October 10, 2025 Google "quietly began to utilize 'Smart Features'—including Gemini, its flagship AI program capable of tracking, analyzing, and storing private information—for Gmail, Chat, and Meet users." Users who had previously chosen not to enable Gemini allegedly had it switched on for them.
Coverage in the National Law Review summarized the mechanic: Google "activated its Gemini AI features across its portfolio of services without obtaining user consent, in violation of the California Invasion of Privacy Act (CIPA)." A separate walkthrough by Gblock's lawsuit breakdown claims the flip affected roughly 1.8 billion Gmail users.
The categories of data Gemini could allegedly access were broad. The complaint lists financial records, employment information, medical information, political and religious affiliations, family and contact identities, and social habits — essentially anything discoverable from an inbox or a Meet call.
The Statutes at Play
The Thele complaint runs on five overlapping legal theories, laid out by Open Class Actions: CIPA §§ 631 and 632 (California's two-party-consent wiretap law), CDAFA (California Penal Code § 502), the federal Stored Communications Act (18 U.S.C. § 2701 et seq.), intrusion upon seclusion, and the California constitutional right to privacy. CIPA § 637.2 authorizes statutory damages of $5,000 per violation, which is what makes these cases scale into billions when brought as class actions.
Why July 7, 2026 Matters: The Dismissal
On July 7, 2026, U.S. District Judge Noël Wise granted Google's motion to dismiss. Per the Bloomberg Law docket note, the plaintiffs "failed to allege a concrete harm sufficient to establish their standing to sue in federal court," though the judge gave them leave to amend.
Law Commentary's analysis identified the specific gaps Judge Wise cited: plaintiffs never explained when they signed up for Google's services, whether Gemini's features were already active when they created their accounts, or which particular messages or communications Gemini actually analyzed. The court noted that "merely alleging that Gemini theoretically could access their data wasn't enough to establish a real injury."
Critically, Judge Wise gave the plaintiffs 21 days to file an amended complaint. As Lawfold's July 14, 2026 update put it, the case's outcome "could shape how courts treat AI-era email privacy claims going forward."
How Thele Fits the Broader AI Wiretap Wave
Thele is not an isolated theory. Analysis in Email Expert's three-case roundup groups Thele with two other Northern District of California cases: In re Otter.AI Privacy Litigation (a consolidation of four suits led by Brewer v. Otter.ai) and a Perplexity AI class action. All three ask the same question: do wiretap and eavesdropping laws written for telephone taps apply to AI products that read, relay, or transcribe private communications?
The Otter case is procedurally furthest along. UC Today's trial preview reported that Judge Eumi K. Lee held the motion-to-dismiss hearing on May 20, 2026 in Courtroom 7 of the San Jose federal courthouse, and "the ruling will be the first federal test of whether decades-old wiretap statutes reach an AI bot sitting quietly" inside a video call.
A parallel biometric strand runs through Illinois. Jackson Lewis's Workplace Privacy Report covers Cruz v. Fireflies.AI Corp., No. 3:25-cv-03399 (C.D. Ill.), which alleges Fireflies violated the Biometric Information Privacy Act by creating voiceprints of meeting participants without written notice or consent. Our earlier analysis of that wave lives in the article on voiceprint harvesting under BIPA.
The Consent Problem Google Meet Can't Solve
Turning off your own Gemini toggle is a start. But it does not solve the harder problem: you cannot consent on behalf of the other participants on a Google Meet call, and they cannot consent on your behalf. This is the same fault line the Otter and Fireflies plaintiffs have exposed.
As TopReviewed.ai's analysis of the Cruz, Fricker and Brewer complaints puts it: "The vendor's terms of service binding the meeting organizer do not bind the other participants. A meeting host who clicked 'I agree' when installing Fireflies has not, under BIPA, consented on behalf of the candidate they are interviewing, the prospect on a sales call, or the witness in a deposition." The same logic applies to a Google Meet host with Gemini smart features on: their consent does not bind the other people on the screen.
California's California Consumer Privacy Act (CCPA) and CIPA both push toward all-party awareness. In two-party-consent states, this quickly becomes a legal exposure question, not just an etiquette one.
Cloud Meeting AI vs. On-Device Transcription: A Comparison
The most useful lens is architectural. Where does the audio go? Where does the transcript live? Who else's servers see the words?
| Dimension | Google Meet + Gemini | Otter.ai / OtterPilot | Fireflies.ai | Basil AI (on-device) |
|---|---|---|---|---|
| Processing location | Google servers | Otter.ai servers | Fireflies servers | Your iPhone / Mac |
| Default state (2026) | On by default since ~Oct 10, 2025 (per Thele) | Opt-out training default | Voiceprint generation on by default | User-initiated only |
| Active class action | Thele v. Google (dismissed w/ leave, 7/7/26) | In re Otter.AI Privacy Litigation (MTD under submission) | Cruz v. Fireflies, Fricker v. Fireflies | None |
| Statutory exposure | CIPA §637.2 ($5,000/violation) | CIPA, ECPA | BIPA ($1,000 negligent / $5,000 intentional) | N/A — audio never leaves device |
| Training-data use | Google denies Gmail-training; disputed | Uses de-identified data by default | Voiceprints retained per complaint | No training use — no cloud pipeline |
| Works offline | No | No | No | Yes |
What Google Says (and What the Complaint Says They Say)
Google's public posture is that no settings were secretly changed. Per Gblock's coverage, a company spokesperson called the underlying reports "misleading" and stated, "We do not use your Gmail content to train our Gemini AI model." The National Law Review's write-up notes Google issued that statement in response to "viral social media posts accusing Google of automatically opting Gmail users into AI model training."
The Thele complaint, however, draws a distinction that Judge Wise will have to grapple with if plaintiffs refile: using data to train an AI is not the only privacy harm — using an AI to analyze data without consent is arguably its own CIPA violation, regardless of what the model is trained on. Whether that theory survives the standing bar is now the question of the amended complaint.
Workflow: How to Actually De-Risk a Google Meet Call Today
Whatever the eventual ruling in Thele or the parallel In re Otter.AI Privacy Litigation, you can reduce your exposure right now with concrete steps. Here is a copy-paste workflow.
Step 1 — Disable Gemini smart features on your own account
- Open Gmail on the web → click the gear icon → See all settings.
- Scroll to Smart features and personalization and switch it off.
- Repeat for Smart features and personalization in other Google products.
- Visit myaccount.google.com/data-and-privacy and review any Gemini Apps Activity and Gemini in Workspace controls.
Step 2 — Do not rely on Google Meet's own transcription for sensitive calls
Meet's "Take notes for me" and built-in transcription both process audio in Google's cloud. For any call touching privileged, health, or financial information, turn those off.
Step 3 — Give a verbal all-party consent notice if you are going to record
A defensible script: "For note-taking accuracy I'm running an on-device transcription tool on my own laptop. No audio is being sent to Google, Otter, Fireflies, or any other cloud service. If anyone objects, please say so now." This is the model recommended in our guide to two-party consent state recording compliance.
Step 4 — Capture with an on-device tool
Run Basil AI on iPhone or Mac. It uses Apple's Speech framework for on-device recognition, so the audio and transcript never leave your machine. No Google account, no Otter bot, no Fireflies voiceprint.
How Basil AI Solves This
The uncomfortable truth of the AI wiretap wave is that Google, Otter, and Fireflies all share the same architectural assumption: ship the audio to our servers, then reason about it there. Every legal theory in Thele, Brewer, Cruz, and Fricker eventually cashes out to that one design decision. Once your voice is in a vendor cloud, the vendor's consent posture, retention policy, training default, and subpoena exposure become your problem.
Basil AI inverts that pipeline. Recording, speaker identification, transcription, and summarization all run on the Apple Neural Engine of your iPhone or Mac. There is no Basil server that stores your recording, because there is no Basil server in the pipeline at all. Apple's privacy documentation describes the on-device Speech Recognition that Basil uses; the recordings and transcripts stay in your local file system (and, if you choose, your own private iCloud).
The practical consequences map directly to the Thele complaint's theory:
- No CIPA interception risk — nothing is transmitted to a third party during the call.
- No Stored Communications Act exposure — there is no vendor "store" of your communications to be improperly accessed.
- No training-data ambiguity — there is no cloud pipeline in which your audio could be used to train a foundation model, by anyone.
- No opt-in/opt-out toggle Google can flip on you — you turn Basil on when you want to record, and it is off otherwise.
For a deeper technical walk-through of how the on-device architecture differs from bot-based cloud tools, see our comparison of bot-free versus on-device notetakers.
Jurisdiction Risk Matrix
Because Thele, Otter, and Fireflies each rely on different state statutes, your exposure depends on where the participants are physically located, not where the vendor is headquartered.
| Jurisdiction | Statute | Key rule | Statutory damages |
|---|---|---|---|
| California | CIPA (Penal Code §§ 631, 632) | All-party consent to record confidential communications | $5,000 per violation (§637.2) |
| Illinois | BIPA (740 ILCS 14) | Written notice + consent before voiceprint collection | $1,000 negligent / $5,000 intentional |
| Federal (all states) | ECPA / Wiretap Act (18 U.S.C. §§ 2510–2522) | One-party consent floor; state law can be stricter | Greater of $10,000 or $100/day |
| Federal (stored data) | Stored Communications Act (18 U.S.C. § 2701) | No unauthorized access to stored communications | Statutory + actual damages |
| EU/UK | GDPR | Lawful basis + data minimization | Up to 4% global turnover |
The GDPR angle is not academic. Article 5 of the GDPR requires data minimization and purpose limitation — both are hard to satisfy when a US cloud vendor's AI ingests a Meet call between two European employees to "personalize" services.
What Happens Next
Judge Wise's dismissal was without prejudice, meaning the plaintiffs' 21-day window to refile expires in late July 2026. Any amended complaint will need to allege, specifically, which of Thele's or Porter's Gmail, Chat, or Meet communications Gemini actually accessed, and what concrete harm followed. If the amended complaint survives, the case rejoins the Otter and Fireflies suits as one of the first federal tests of whether wiretap statutes reach frontier AI systems integrated into everyday communication tools.
Meanwhile, the Otter motion to dismiss remains under submission before Judge Lee, per the Open Class Actions docket tracker. Whichever case's motion is decided first will effectively price the risk for every cloud meeting-AI vendor.
For enterprises, the safer bet is to stop being a defendant in that experiment. Move the AI off the vendor's servers and onto the device where the meeting is already happening. That is what Basil AI was built for, and it is the position we take in our broader analysis of AI meeting notetakers compared.
Meetings That Never Touch a Vendor Cloud
Basil AI records, transcribes, and summarizes on your iPhone or Mac. No Google, no Otter, no Fireflies. No CIPA exposure.
Frequently Asked Questions
Does Google Meet record my meetings with Gemini AI by default?
According to the Thele v. Google complaint, Google switched Gemini 'smart features' from opt-in to on-by-default across Gmail, Chat, and Meet on or around October 10, 2025. Google disputes this framing and says users control the setting. To disable it, open Gmail → Settings → Smart features and personalization, and switch it off — but the setting only controls your own account, not the other participants on a Meet call.
Was the Thele v. Google Gemini lawsuit dismissed?
Yes, on July 7, 2026, U.S. District Judge Noël Wise of the Northern District of California dismissed Thele v. Google LLC (No. 5:25-cv-09704) for lack of Article III standing — the plaintiffs did not allege a concrete injury or identify specific communications Gemini accessed. Judge Wise gave plaintiffs 21 days to file an amended complaint, so the case is not over.
What laws does the Thele v. Google complaint invoke?
The complaint asserts claims under the California Invasion of Privacy Act (Cal. Penal Code §§ 631 and 632), the California Comprehensive Computer Data Access and Fraud Act (Penal Code § 502), the federal Stored Communications Act (18 U.S.C. § 2701), intrusion upon seclusion, and the California constitutional right to privacy. CIPA authorizes statutory damages of $5,000 per violation.
Is Google Meet's Gemini different from Otter.ai or Fireflies?
Legally, all three face similar wiretap and privacy theories — In re Otter.AI Privacy Litigation, Cruz v. Fireflies.AI, and Thele v. Google are moving through the Northern District of California and Illinois on overlapping CIPA, BIPA, and ECPA claims. Architecturally they are also similar: audio and text leave the user's device and are analyzed on a vendor server, which is exactly the design element the plaintiffs challenge.
How do I record a Google Meet call without any AI in the cloud?
You cannot fully do that inside Google Meet — Meet's own recording, transcription, and 'take notes for me' features all run on Google servers. To capture a meeting entirely on-device, run a separate on-device recorder (like Basil AI on iPhone or Mac) that transcribes using Apple's on-device Speech Recognition, keeps audio local, and never sends the recording to any cloud vendor.
Can I be sued for using Google Meet's AI features in a two-party consent state?
There is no ruling yet, but the theory in Thele, Brewer (Otter), and Cruz (Fireflies) is that the vendor and, in some cases, the meeting host can be liable when AI captures the words or voiceprints of participants who never consented. California and Illinois are the highest-risk states because both authorize statutory damages ($5,000 under CIPA §637.2; $1,000–$5,000 under BIPA) without proof of actual harm.