August 12, 2026 · 11 min read

Does Microsoft Teams Live Transcription Create Biometric Voiceprints? Inside the Basich v. Microsoft BIPA Lawsuit

Key takeaways
  • Basich v. Microsoft (W.D. Wash., Feb. 5, 2026) is the first major BIPA class action alleging that Microsoft Teams' Live Transcription extracts voiceprints without written consent.
  • The 'diarization = biometric identifier' theory, if it survives dismissal, exposes every enterprise SaaS product that labels 'who said what' — Teams, Zoom AI Companion, Otter, Fireflies, Google Meet.
  • SB 2979 (August 2, 2024) caps recovery at one violation per person, but at $1,000–$5,000 per Illinois participant, class-wide exposure remains material.
  • Cloud AI notetakers extract voiceprints on vendor servers by design; on-device transcription keeps the numerical embedding on the user's device and never triggers BIPA §15(b)'s vendor-collection standard.
  • Compliance teams should audit Teams tenant settings, disable auto-transcription for meetings with Illinois participants absent written consent, and publish a BIPA-compliant retention schedule.

Quick answer: A February 5, 2026 class action, Basich v. Microsoft Corp. (W.D. Wash., No. 2:26-cv-00422), alleges Microsoft Teams' Live Transcription feature extracts biometric voiceprints from every meeting participant, including Illinois non-users, without the written notice and consent required by BIPA §15(b). No court has ruled yet, but the case is the first major test of whether AI speaker diarization in enterprise SaaS is 'biometric identifier' collection under Illinois law.

A February 2026 class action argues that every time Live Transcription runs in a Teams meeting with an Illinois participant, Microsoft is collecting a biometric identifier the same way a fingerprint scanner does — and that has consequences for every enterprise AI notetaker in the market.

The lawsuit that treats "who said what" as biometric collection

On February 5, 2026, five Illinois residents filed a putative class action in the U.S. District Court for the Western District of Washington against Microsoft Corporation. The case is Basich et al. v. Microsoft Corp., Case No. 2:26-cv-00422. According to Top Class Actions, the complaint claims that Teams' real-time transcription feature captures speakers' voices during online meetings and assesses qualities like pitch, tone, and timbre to identify who said what — and that Microsoft failed to inform users how that voice data would be used, in violation of the Illinois Biometric Information Privacy Act (BIPA).

The complaint's central technical claim, as summarized by Darrow's litigation-risk analysis, focuses on a background process called "diarization": to distinguish Speaker A from Speaker B in a real-time transcript, Microsoft's Azure servers extract unique vocal features from each participant. Plaintiffs argue those numerical vectors are voiceprints — the exact biometric identifier BIPA §10 protects.

Why this case is different from Otter, Fireflies, and Granola

2025 and 2026 have produced a wave of AI-notetaker privacy suits — Brewer v. Otter.ai, Cruz v. Fireflies.AI, and Chamberlain v. Granola among them. Most of those cases rest on federal and California wiretap theories (ECPA and CIPA) built around the argument that a notetaker joined a meeting without all-party consent. Basich is different in kind. It doesn't argue that Teams is secretly recording — Teams' transcription is a documented, user-visible feature. It argues that the mathematical fingerprint used to attribute a sentence to Speaker B is itself a biometric identifier collected without notice.

That distinction matters. As a No Boiler analysis put it, courts in two different jurisdictions — the Basich court in Washington and the Cruz v. Fireflies.AI court in the Central District of Illinois — will soon be considering whether AI-powered speaker attribution constitutes voiceprint collection under BIPA. If either court says yes, every enterprise SaaS product that labels "who said what" faces the same theory.

What BIPA §15(b) actually requires

BIPA is unusual among U.S. privacy statutes: it gives individuals a private right of action with statutory damages. Under Section 15(b), a private entity may not "collect, capture, purchase, receive through trade, or otherwise obtain" a person's biometric identifier — including a voiceprint — unless it first (a) informs the person in writing that data is being collected, (b) states the specific purpose and length of the term of collection, and (c) receives a written release.

The Basich complaint alleges Microsoft did none of that for the Live Transcription feature. According to a ClassAction.org summary of the 24-page complaint, plaintiffs say Microsoft creates uniquely identifying voiceprints by analyzing vocal pitch, cadence, timbre and other characteristics of Teams participants, then stores the information as numerical values — without the disclosure or written consent BIPA §15(b) requires.

How SB 2979 changes the damages math (but doesn't eliminate it)

Damages are the reason BIPA has produced settlements of hundreds of millions of dollars. Under the statute, plaintiffs can recover $1,000 for negligent violations and $5,000 for intentional or reckless violations — per violation. Prior to 2024, the Illinois Supreme Court's Cothron v. White Castle ruling meant every single scan or transmission counted as a separate violation.

That changed on August 2, 2024, when Governor J.B. Pritzker signed SB 2979. According to Practical Law's analysis of the amendments, SB 2979 established that a single BIPA §15(b) violation occurs when a defendant's repetitive conduct — scans, collections, or disclosures — involves the same biometric identifier from the same person, limiting plaintiffs to one statutory damage award. In April 2026, the Seventh Circuit held that the SB 2979 damages cap applies retroactively to cases pending when it became effective — meaning Microsoft will benefit from the per-person cap in Basich.

Even so, the exposure is not small. At $1,000–$5,000 per Illinois class member, Darrow's projected settlement value for Basich is in the $41 million to $61 million range. That's the floor for a single feature in a single collaboration product.

The "no BIPA policy" problem

One detail in the complaint is worth flagging for any compliance officer inheriting a Teams tenant. According to the same independent analysis of the complaint, plaintiffs allege that Microsoft maintains a U.S. State Data Privacy Laws Notice covering California but has no Illinois-specific or BIPA-specific policy addressing its collection of voiceprints from Teams users — an omission plaintiffs describe as "reckless, if not intentional," given how much BIPA litigation has run since 2019.

BIPA §15(a) separately requires any private entity in possession of biometric identifiers to develop a publicly available written policy establishing a retention schedule and destruction guidelines. A missing or California-only privacy notice doesn't satisfy that requirement. This is a template failure — one that every SaaS vendor with a diarization feature should audit against their own privacy pages this week.

Cloud diarization vs on-device transcription: the architectural difference

Whether Basich succeeds or fails on the merits, the theory forces a clean architectural question: where does the numerical voice embedding live? That question has one answer for cloud-based AI notetakers and a very different answer for on-device transcription.

Dimension Cloud AI notetakers (Teams, Zoom AI Companion, Otter, Fireflies) On-device transcription (Basil AI on Apple Silicon)
Where diarization runsVendor's servers (Azure, AWS, GCP)Locally on the user's Mac or iPhone Neural Engine
Voice embedding transmitted off-device?Yes — audio uploaded, embedding computed server-sideNo — audio and embedding stay on the device
Triggers BIPA §15(b) vendor collection?Yes — vendor "collects, captures, or otherwise obtains" the identifierNo — no third party obtains the identifier
Requires BIPA §15(a) retention schedule?Yes — vendor possesses biometric dataUser controls retention on their own device
Discoverable in litigation?Yes — vendor server holds the artifactOnly if the user's device is subject to discovery
Voice used for model training?Often yes, unless disabled by adminNo — nothing leaves the device

Why speaker diarization is a BIPA magnet

Speaker diarization — the technical task of segmenting audio by speaker — is genuinely useful. It's the reason a Teams recap can say "Alice committed to shipping the feature by Friday" instead of "someone said something about Friday." But the entire pipeline depends on extracting a per-speaker feature vector that is stable enough to identify the same speaker across turns. That stability is what makes it identifying — and what makes plaintiffs' lawyers argue it's a biometric.

The Amundsen Davis employment law update notes that under BIPA's broad definition of biometric data, voiceprints — like facial scans or fingerprints — may qualify as biometric identifiers, and plaintiffs have already filed class actions against vendors like Fireflies.AI alleging voiceprint collection from meeting participants, including non-users, without BIPA's statutory prerequisites.

For enterprises, the concerning implication is that the Basich theory doesn't care whether your vendor calls the artifact a "voiceprint," a "speaker embedding," or a "diarization vector." It cares whether the artifact uniquely identifies a person by biological voice characteristics. If it does, and the vendor didn't get written consent from every Illinois participant, exposure follows the diarization architecture wherever it runs.

What compliance and IT teams should do this week

Basich hasn't produced a substantive ruling, and Microsoft will fight the biometric-identifier characterization hard. But waiting for the motion to dismiss isn't a defensible posture. Here's a practical checklist compliance and IT teams can adapt into internal docs:

1. Inventory diarization features across your SaaS stack

Teams Live Transcription and Copilot recaps are the obvious targets, but Zoom AI Companion, Google Meet's speaker attribution, Otter, Fireflies, and every AI meeting assistant your employees have signed up for on their own do the same thing. Enumerate them.

2. Map Illinois exposure

Identify employees, contractors, vendors, and regular external meeting guests physically located in Illinois. BIPA reaches non-users, so counterparties on a Teams call count. If you have any Illinois exposure, the diarization features in your stack need a BIPA analysis.

3. Audit vendor privacy pages against BIPA §15(a)

Look for a publicly available written retention and destruction schedule specific to biometric identifiers. "See our general privacy policy" is not one. If the vendor's page only names California, treat that as a red flag.

4. Disable auto-transcription by default for meetings with Illinois participants

Until written consent workflows are in place, the safest Teams tenant setting is off-by-default for Live Transcription and Copilot recap on meetings that include Illinois attendees.

5. Consider on-device transcription for sensitive internal conversations

For internal executive discussions, deal calls, HR conversations, or attorney-client meetings, on-device transcription avoids the vendor-collection trigger entirely. See our related analyses of the Granola invisible-notetaker wiretap suit and the broader wave of BIPA voiceprint lawsuits for context on why cloud transcription vendors keep landing in court.

How Basil AI solves this

Basil AI is an on-device AI meeting recorder for iOS and Mac. Transcription runs entirely on the device's own Apple Neural Engine using Apple's Speech framework. That is not a marketing distinction — it is the architectural fact that makes the BIPA §15(b) analysis different.

In the Basich theory of the case, the trigger for liability is a vendor collecting, capturing, receiving, or otherwise obtaining the voiceprint. When diarization runs on the user's own Mac or iPhone, there is no vendor server that receives the audio, no vendor pipeline that computes an embedding, no vendor database that stores it. The numerical representation of a speaker's voice — if it exists at all — exists only on the device the user already owns. That does not "make Basil compliant" — compliance is always a determination for your firm's counsel — but it does change which questions your DPA even has to answer, because there is no vendor-side collection to disclose.

Apple's design of the Speech framework and the Neural Engine reflects the same posture. As Apple describes on its privacy overview, on-device processing is a core principle: keep personal data on the device the user controls, not on a distant server. Basil AI is built directly on that principle for the meeting-transcription use case. For a deeper look at the trade-offs, see our comparison of AI meeting notetakers and our explainer on what "compliant" AI meeting notes actually means.

The bigger picture: enterprise SaaS is the next BIPA frontier

For years, BIPA litigation focused on employee fingerprint timeclocks, retail facial-recognition, and social-network face tagging. Basich is the moment enterprise collaboration software joined that list. As UC Today's coverage put it, the case highlights a dangerous gap in the SaaS supply chain: when a vendor updates a Terms of Service agreement to enable a new AI feature, that feature does not automatically comply with laws like BIPA — and the burden of that "shadow AI" can shift from vendor to customer.

That is the deeper lesson for anyone deploying AI meeting features to thousands of employees. Every new AI capability shipped inside an incumbent productivity tool — diarization, sentiment analysis, meeting scoring — is a potential new biometric-collection surface. The safest architecture is the one that never puts the biometric on someone else's server in the first place.

Try Basil AI — on-device by design

Basil AI records and transcribes meetings entirely on your Mac or iPhone. No cloud upload, no vendor voiceprint database, no shadow AI.

Download on the App Store Download on the Mac App Store

This article is journalism and general information, not legal advice. Basil AI does not claim to be "BIPA compliant" — compliance is a determination only your firm and counsel can make based on your specific deployment. Case citations and quoted allegations reflect complaints and public reporting as of August 12, 2026; no substantive rulings have issued in Basich v. Microsoft as of that date.

Frequently Asked Questions

What does Basich v. Microsoft actually allege?

The complaint alleges that when Live Transcription is enabled in a Microsoft Teams meeting, Azure servers extract vocal pitch, tone, and timbre from each speaker to create a numerical voiceprint used for speaker diarization ('who said what'). Plaintiffs claim Microsoft failed to publish a BIPA-compliant retention schedule or obtain written consent from Illinois participants before capturing those voiceprints, in violation of BIPA §15(a) and §15(b).

Are voiceprints really 'biometric identifiers' under BIPA?

BIPA (740 ILCS 14/10) expressly lists 'voiceprint' alongside retina scans, fingerprints, and face geometry as a protected biometric identifier. The unsettled legal question is whether numerical embeddings used only for real-time speaker attribution — never stored as a labeled 'voiceprint' file — still qualify. Basich argues they do because the data uniquely identifies an individual, matching BIPA's statutory definition.

Does the 2024 SB 2979 amendment limit Microsoft's exposure?

Yes, materially. SB 2979, signed August 2, 2024, caps recovery at one violation per person per method regardless of how many meetings were transcribed, overturning Cothron v. White Castle's per-scan theory. In April 2026 the Seventh Circuit held SB 2979 applies retroactively to pending cases. Damages remain $1,000 per negligent or $5,000 per intentional violation — still potentially tens of millions across a Teams user base.

What should compliance teams do about Teams Live Transcription today?

Treat Live Transcription and Copilot's recap features as biometric-collection features until courts say otherwise. Map which employees, contractors, and external meeting guests are in Illinois; disable auto-transcription for meetings that include Illinois residents unless you have BIPA-compliant written consent, a published retention schedule, and a policy that prohibits use for AI model training. Consider on-device transcription alternatives for sensitive internal conversations.

How does on-device transcription avoid BIPA voiceprint exposure?

On-device transcription using Apple's Speech framework runs the acoustic model locally on the user's own Mac or iPhone. No voice data — raw audio or numerical embedding — is transmitted to a vendor server, and speaker labels are generated on the device itself. Because no third party 'collects, captures, purchases, receives through trade, or otherwise obtains' the biometric identifier, the vendor-collection trigger in BIPA §15(b) is not activated.

Does Basich apply outside Illinois?

Not directly — BIPA is Illinois law. But Texas (CUBI), Washington (H.B. 1493), and New York City's biometric ordinance all impose similar notice-and-consent requirements on biometric identifiers, and several 2025-2026 state comprehensive privacy laws treat voiceprints as sensitive data. Enterprise Teams deployments with employees in any of these jurisdictions face parallel risk from the same diarization architecture.