AI Notetakers in Job Interviews: The HR Compliance Trap After Chamberlain v. Granola
Published August 13, 2026
- Two class actions — In re Otter.AI Privacy Litigation and Chamberlain v. Granola — now pending in the Northern District of California put cloud AI notetakers in candidate interviews at legal center stage.
- Interview recordings carry higher risk than internal meetings: candidates are external, protected characteristics surface naturally, and the recording can become hiring-discrimination evidence.
- Overlapping regimes now apply simultaneously — CIPA/ECPA wiretap, BIPA voiceprints, EEOC Title VII disparate impact, NYC Local Law 144 bias audits, and Illinois AIVIA notice-and-deletion.
- Host-only consent defaults (the Otter/Granola model) likely fail in the 12 all-party consent states and under GDPR's freely-given-consent standard.
- On-device transcription removes vendor-side wiretap, training, and breach exposure — but does not remove the interviewer's duty to obtain explicit candidate consent.
Quick answer: Using cloud AI notetakers (Otter, Fireflies, Granola) in candidate interviews now triggers overlapping legal exposure: wiretap suits in all-party consent states, BIPA voiceprint claims, EEOC disparate-impact scrutiny, NYC Local Law 144 bias-audit duties, and Illinois AIVIA notice-and-deletion rules. HR should default to no cloud recording of interviews — or capture on-device with explicit candidate consent.
Using a cloud AI notetaker to record a candidate interview is no longer a productivity choice — it's a compliance decision that touches at least five overlapping legal regimes at once. Two federal class actions filed within twelve months in the Northern District of California — Chamberlain v. Granola and the consolidated In re Otter.AI Privacy Litigation — allege the same defect: cloud notetakers recorded conversations without notifying most participants and, by default, used those recordings to train AI models. When the participants include job candidates, the exposure compounds fast. This piece maps the actual risk surface HR leaders are staring at in August 2026 and lays out a decision framework you can copy into internal policy today.
Why interview recordings carry higher legal risk than internal meetings
Every AI notetaker vendor sells the same story: hit record, get a transcript, save time. That framing works for a standup. It collapses inside a candidate conversation. As one SocialTalent analysis of the current wave of AI notetaker lawsuits put it plainly, interview recordings carry higher legal risk than internal meetings because candidates are external, protected characteristics surface naturally, and recordings can become evidence in hiring disputes. Three structural facts drive the mismatch:
- Candidates are external parties — they haven't signed your acceptable-use policy or your BYOD agreement, and they have no employment relationship that softens the consent analysis.
- Protected characteristics surface naturally — accent, age markers, disability disclosures, pregnancy, caregiving obligations, religious observance. Once captured on a vendor server, that content becomes discoverable evidence in any downstream discrimination claim.
- Speaker-identification features add a separate biometric layer — as Amundsen Davis warned employers in February 2026, plaintiffs are alleging that vendors like Fireflies.AI collect and store voiceprints — unique biometric identifiers derived from speech — without the written notice, informed consent, or retention policies BIPA demands.
The two lawsuits reshaping the risk picture
In re Otter.AI Privacy Litigation
The consolidated case now before Judge Eumi K. Lee in the Northern District of California originated with Brewer v. Otter.ai, filed in August 2025. As Embertype's tracker of the AI notetaker lawsuits summarizes, the complaint alleges Otter's Notetaker and OtterPilot services joined Google Meet, Zoom, and Microsoft Teams calls, recorded participants, and used their conversations to train AI models without securing the consent required under federal ECPA and California's CIPA. Otter's motion to dismiss was fully briefed and, per ZwillGen's practical-lessons analysis, oral argument was set for August 2026 — meaning the first federal ruling on whether an AI bot qualifies as an unlawful interceptor under decades-old wiretap statutes could arrive during the same quarter you're reading this.
Chamberlain v. Granola
Filed July 30, 2026, the Granola complaint uses a nearly identical theory but adds a devastating exhibit. Per PPC Land's reporting on the filing, plaintiff Tarra Chamberlain sued on behalf of a proposed nationwide class and California subclass, extending California's wiretapping and privacy statutes — already applied against Meta, Perplexity, and OpenAI — to an AI product whose core function is recording conversations and repurposing them for model training. The kicker, per Robinson & Cole's National Law Review analysis: Granola's software allegedly recorded a virtual meeting participant without giving notice that an AI notetaker was present or seeking permission to record, and used meeting contents by default for commercial purposes including training AI systems unless the user turned that setting off.
The plaintiffs' most quotable line comes from Granola's own marketing. As the SocialTalent analysis notes, Granola's marketing copy told prospective customers that other people on a call "won't know it's there" — a sentence plaintiffs cite in a federal court filing as evidence that the company built its product around avoiding disclosure rather than defaulting to it. If you are the HR leader whose recruiter chose Granola specifically because it doesn't show up as a visible bot, that marketing pitch is now Exhibit A against you.
Basich v. Microsoft — the biometric flank
Then there's Basich v. Microsoft Corp., filed February 5, 2026, which alleges Microsoft Teams uses speaker diarization to create biometric voiceprints from meeting participants without proper notice or written consent in violation of Illinois's BIPA. The suit matters for interview compliance because Teams is where most Fortune 500 first-round interviews happen — and because BIPA damages ($1,000–$5,000 per violation) scale linearly with the number of Illinois candidates you interview.
The five regimes that hit a single interview simultaneously
A single 30-minute video interview with a cloud notetaker running can trigger all five of the following at once:
| Regime | What it requires | Trigger for an interview notetaker | Exposure |
|---|---|---|---|
| CIPA / ECPA wiretap (12 all-party consent states) | Consent from every participant before recording | Cloud bot joins call; candidate not separately notified | Statutory damages + injunctive relief (Otter, Granola theory) |
| Illinois BIPA | Written notice, informed consent, published retention/destruction policy before capturing voiceprints | Speaker diarization extracts vocal characteristics | $1,000–$5,000 per violation, per person |
| EEOC / Title VII (federal) | No disparate impact in selection procedures; "the algorithm did it" is not a defense | AI-derived interview scores, summaries, or ranking | Class action, back pay, injunctive relief |
| NYC Local Law 144 | Annual independent bias audit, public audit summary, 10 business days' candidate notice | Tool "substantially assists" hiring decision for NYC-located role | $500 first violation, $500–$1,500 per additional day |
| Illinois AIVIA | Notify applicant, explain the AI, obtain consent, delete recording within 30 days on request | AI analyzes recorded video interview for Illinois role | Civil rights violation under 2026 amendments to state Human Rights Act |
The all-party consent problem, mechanically
The cloud notetaker business model assumes the meeting host clicks "start recording" and that click satisfies consent for everyone in the room. As the HR Executive analysis of the Otter litigation summarizes, valid consent must be freely given, specific and unambiguous from each individual whose data is processed — a model that relies on one meeting participant to authorize recording on behalf of all others would likely not satisfy the regulations. The article quotes Bradford Kelley, a Littler Mendelson shareholder who co-authored a February 2026 analysis, calling AI transcription "a hot issue" and warning HR teams in all-party consent states to be "very interested in this case."
Even in one-party jurisdictions, in-interview consent is fragile. As Honeit's Talent Acquisition analysis of the Otter case puts it, recruiting conversations involve compensation expectations, career frustrations, personal circumstances, location constraints, and employment history — data that falls under GDPR, CCPA, and state-level biometric and wiretap statutes, and that in California, Illinois, and at least nine other all-party consent states creates a legal violation whenever recording occurs without explicit consent from all parties. A candidate asked mid-call whether the notetaker is okay has no meaningful ability to say no.
EEOC disparate impact: the second wave lawyers are watching
Even if you cleared the wiretap and BIPA problem, you still have the EEOC problem. Per JTNY Law's 2026 EEOC hiring-algorithms analysis, the agency has intensified focus on algorithmic bias in 2026, and its Strategic Enforcement Plan for 2024–2028 prioritizes "algorithmic fairness," targeting automated systems in selection procedures — including AI-driven video interview analysis. The federal benchmark is the four-fifths rule: if one group passes a screen at less than 80% of the rate of the highest-scoring group, that gap is treated as evidence of adverse impact. AI interview summaries, sentiment scores, and "culture fit" rankings all sit squarely in that crosshair, and "the algorithm did it" is not a defense.
Combine that with the pending Workday class action alleging AI hiring tools discriminate against Black, older, and disabled candidates — a case that broadens liability from standalone AI interviewers to any ATS+AI platform — and the exposure profile of a cloud notetaker feeding transcripts into a downstream ranking system starts to look like a compliance officer's worst afternoon.
NYC Local Law 144 and Illinois AIVIA: the notice regimes you can't skip
The DCWP is the enforcement body for NYC Local Law 144, which requires employers using AEDTs for hiring or promotion decisions to conduct a bias audit no more than one year prior to use, publish a summary of the audit results on their website, and properly notify candidates that an AEDT will be used, how it will be used, and what data will be collected. Civil penalties run between $500 and $1,500 per day for violations. The New York State Comptroller's December 2025 audit — summarized by DLA Piper — concluded that DCWP enforcement has been "ineffective," which practitioners read as a signal of increased enforcement pressure, not a green light.
Illinois goes further. Per BrightHire's 2026 AI interview compliance guide, the Illinois AI Video Interview Act (in force since 2020) requires employers that use AI to analyze recorded video interviews to notify applicants first, explain how the AI works, get their consent, and delete the recording within 30 days on request. A 2026 amendment to the state Human Rights Act (effective January 1, 2026) additionally makes it a civil rights violation to use AI in hiring in a way that discriminates against a protected group. Whether your notetaker's summary counts as "AI analysis" of the interview is exactly the kind of question you don't want litigated on your dime.
Why "just turn off training" isn't the fix
The obvious mitigation — flip the vendor's "don't train on my data" toggle — helps but doesn't close the exposure. Three reasons:
- Default-on is the plaintiff's exhibit. The Granola complaint specifically alleges that meeting contents were used by default for commercial purposes including training AI systems unless the user turned that setting off — meaning class members' data was arguably already ingested before anyone read the settings page.
- Vendor-side storage still creates discovery surface. Even without training, the vendor now holds a copy of the interview transcript subject to subpoena in any downstream discrimination or wrongful-termination claim. Cloud storage of raw recordings expands, per Meeting Notes' 2026 review of AI notetakers, both discovery exposure and ongoing regulatory risk.
- Voiceprints are extracted at inference time. Speaker diarization requires clustering voice characteristics regardless of whether the transcript is used for training. That's the mechanic underlying every BIPA notetaker complaint — the biometric identifier exists whether you "turn off" downstream use or not.
A copy-paste HR decision framework for August 2026
The most useful thing an HR leader can do this week is not memorize the case law — it's write down a defensible policy. Here is a framework you can adapt:
- Default: no AI notetaker in candidate interviews. The productivity gain (a searchable transcript) does not clear the combined wiretap + BIPA + EEOC + LL 144 + AIVIA hurdle for most organizations.
- If recording is required (say, for structured-interview validation), use on-device transcription that never sends audio to a vendor server, disable speaker-identification/voiceprint features where possible, and obtain written pre-interview consent in the invitation email with a genuine, penalty-free option to decline.
- Ban invisible "botless" cloud recording during interviews. The Granola marketing line — that other people "won't know it's there" — is precisely the design pattern plaintiffs are targeting. Tools that hide their presence do not solve the consent problem; they aggravate it.
- Map every AI tool that touches candidate data. As the Layer3 Labs compliance guide observes for MNPI, you cannot control what you have not mapped — the same applies to protected-class candidate data. Include notetakers, ATS AI features, scheduling copilots, and CRM AI assistants.
- Set a short retention default (e.g., delete raw audio at meeting end, retain structured notes only) and honor Illinois AIVIA's 30-day deletion-on-request rule for any AI-analyzed video.
- Publish a candidate-facing notice that meets NYC LL 144's 10-business-day advance-notice requirement if the tool substantially assists hiring — and post the annual bias audit summary if applicable.
How Basil AI solves this: on-device transcription for candidate conversations
Basil AI is a fully on-device meeting recorder for iPhone and Mac. Audio is transcribed locally using Apple's on-device Speech Recognition — the same architecture Apple describes in its privacy documentation and its developer documentation — and never leaves the interviewer's device. There is no vendor server holding candidate audio, no default training pipeline to disable, and no visible bot joining the call to alarm the candidate.
What that changes concretely for the risk map above:
- Wiretap-by-vendor exposure disappears — there is no third-party interceptor between interviewer and candidate. The interviewer still owes candidate consent under CIPA/ECPA, but the vendor-side theory that drives Otter and Granola doesn't apply because there is no vendor in the loop.
- BIPA voiceprint exposure narrows — Apple's on-device speech pipeline does not create the shared voiceprint database that plaintiffs allege in Cruz v. Fireflies.AI and Basich v. Microsoft.
- Discovery surface shrinks — the interviewer controls retention and deletion locally, so honoring an Illinois AIVIA 30-day deletion request is a one-click operation, not a vendor ticket.
On-device processing is an architecture fact, not a compliance guarantee. Basil AI is not "HIPAA compliant" or "GDPR compliant" — compliance is a determination your firm, employment counsel, and DPO make. What on-device architecture does is remove the third-party vendor from the data flow that generates most of the current wave of litigation. For deeper reading, see our breakdown of Chamberlain v. Granola, our two-party consent state guide, and our earlier piece on AI meeting bots in job interviews.
What to do this week
- Monday: Pull a list of every AI notetaker or transcription tool active in a recruiter's Zoom/Teams/Meet stack. Ask specifically about invisible "botless" tools like Granola that don't show up as visible participants.
- Tuesday: Read the actual privacy policies. Start with Otter.ai's privacy policy and Fireflies.ai's privacy policy. Flag the training-data and retention clauses.
- Wednesday: Draft candidate-facing disclosure language for interview invitations. Make declining a genuine, penalty-free option.
- Thursday: If any tool "substantially assists" hiring decisions and you have NYC-located roles, confirm the vendor's most recent bias audit summary is published and that your invitation meets the 10-business-day notice window.
- Friday: Sit with employment counsel on the Otter oral argument (Judge Lee) and the Granola motion schedule. First rulings will shift the risk map.
The bottom line
The current wave of AI notetaker lawsuits is not really about AI. It is, as the SocialTalent piece puts it, about consent design — what your vendor assumed on your behalf the moment someone hit record inside a candidate conversation. For HR leaders, the safest posture in August 2026 is: no cloud notetaker in interviews by default; if you must capture the conversation, use on-device transcription with explicit, written, pre-interview candidate consent; and never rely on a tool marketed as invisible. The regulatory frameworks that already apply — GDPR Article 5, BIPA, Title VII, LL 144, AIVIA — do not require you to wait for the first federal ruling. They require you to design consent in, not bolt it on.
Interview transcripts that never touch a vendor server
Basil AI records and transcribes interviews entirely on-device — no cloud upload, no vendor-side training, no invisible bot in the meeting.
Frequently Asked Questions
Is it legal to use an AI notetaker in a job interview?
It depends on the state and the tool. In the 12 all-party consent states (California, Illinois, and others), every participant — including the candidate — must knowingly consent before an AI notetaker records. Recent lawsuits against Otter.ai and Granola allege host-only consent isn't enough. Employers using cloud notetakers without explicit candidate notice risk wiretap, BIPA, and employment-law claims simultaneously.
What is Chamberlain v. Granola about?
Chamberlain v. Granola is a proposed class action filed July 30, 2026 in the U.S. District Court for the Northern District of California. The complaint alleges Granola recorded meeting participants without notice and, by default, used those recordings to train its AI models. Plaintiffs cite Granola's own marketing line that other people on a call "won't know it's there" as evidence of intentional non-disclosure.
Does BIPA apply to AI interview notetakers?
It can. The Illinois Biometric Information Privacy Act covers voiceprints — unique biometric identifiers derived from speech. Cases like Cruz v. Fireflies.AI and Basich v. Microsoft Corp. allege that speaker diarization features create voiceprints without the written notice, consent, and retention policy BIPA requires. Statutory damages run $1,000–$5,000 per violation, per person.
What does NYC Local Law 144 require for AI in hiring?
NYC Local Law 144 makes it unlawful to use an automated employment decision tool (AEDT) to substantially assist hiring or promotion decisions unless the tool has been independently bias-audited within the past year, the audit summary is publicly posted, and candidates receive at least 10 business days' notice. DCWP penalties run $500 for a first violation and $500–$1,500 per subsequent day.
Can we just ask the candidate on-camera if recording is okay?
In-interview verbal consent is fragile. Employment counsel note the power imbalance makes candidate consent arguably not "freely given" under GDPR standards, and mid-call requests do not satisfy NYC LL 144's 10-business-day advance notice or Illinois AIVIA's pre-interview disclosure. Best practice is written disclosure in the interview invitation with a genuine option to decline.
How does on-device transcription change the interview compliance picture?
On-device processing removes the third-party vendor from the data flow — no cloud server holds the audio, no model trains on the transcript, no visible bot joins the call to alarm candidates. It doesn't eliminate consent obligations (the interviewer still needs candidate permission to record) but it removes the wiretap-by-vendor, BIPA-voiceprint, and vendor-breach exposure that drives current litigation.