AI Notetakers in Job Interviews: The HR Compliance Trap After Chamberlain v. Granola

Published August 13, 2026

Key takeaways

Quick answer: Using cloud AI notetakers (Otter, Fireflies, Granola) in candidate interviews now triggers overlapping legal exposure: wiretap suits in all-party consent states, BIPA voiceprint claims, EEOC disparate-impact scrutiny, NYC Local Law 144 bias-audit duties, and Illinois AIVIA notice-and-deletion rules. HR should default to no cloud recording of interviews — or capture on-device with explicit candidate consent.

August 13, 2026 · 11 min read

Using a cloud AI notetaker to record a candidate interview is no longer a productivity choice — it's a compliance decision that touches at least five overlapping legal regimes at once. Two federal class actions filed within twelve months in the Northern District of California — Chamberlain v. Granola and the consolidated In re Otter.AI Privacy Litigation — allege the same defect: cloud notetakers recorded conversations without notifying most participants and, by default, used those recordings to train AI models. When the participants include job candidates, the exposure compounds fast. This piece maps the actual risk surface HR leaders are staring at in August 2026 and lays out a decision framework you can copy into internal policy today.

Why interview recordings carry higher legal risk than internal meetings

Every AI notetaker vendor sells the same story: hit record, get a transcript, save time. That framing works for a standup. It collapses inside a candidate conversation. As one SocialTalent analysis of the current wave of AI notetaker lawsuits put it plainly, interview recordings carry higher legal risk than internal meetings because candidates are external, protected characteristics surface naturally, and recordings can become evidence in hiring disputes. Three structural facts drive the mismatch:

The two lawsuits reshaping the risk picture

In re Otter.AI Privacy Litigation

The consolidated case now before Judge Eumi K. Lee in the Northern District of California originated with Brewer v. Otter.ai, filed in August 2025. As Embertype's tracker of the AI notetaker lawsuits summarizes, the complaint alleges Otter's Notetaker and OtterPilot services joined Google Meet, Zoom, and Microsoft Teams calls, recorded participants, and used their conversations to train AI models without securing the consent required under federal ECPA and California's CIPA. Otter's motion to dismiss was fully briefed and, per ZwillGen's practical-lessons analysis, oral argument was set for August 2026 — meaning the first federal ruling on whether an AI bot qualifies as an unlawful interceptor under decades-old wiretap statutes could arrive during the same quarter you're reading this.

Chamberlain v. Granola

Filed July 30, 2026, the Granola complaint uses a nearly identical theory but adds a devastating exhibit. Per PPC Land's reporting on the filing, plaintiff Tarra Chamberlain sued on behalf of a proposed nationwide class and California subclass, extending California's wiretapping and privacy statutes — already applied against Meta, Perplexity, and OpenAI — to an AI product whose core function is recording conversations and repurposing them for model training. The kicker, per Robinson & Cole's National Law Review analysis: Granola's software allegedly recorded a virtual meeting participant without giving notice that an AI notetaker was present or seeking permission to record, and used meeting contents by default for commercial purposes including training AI systems unless the user turned that setting off.

The plaintiffs' most quotable line comes from Granola's own marketing. As the SocialTalent analysis notes, Granola's marketing copy told prospective customers that other people on a call "won't know it's there" — a sentence plaintiffs cite in a federal court filing as evidence that the company built its product around avoiding disclosure rather than defaulting to it. If you are the HR leader whose recruiter chose Granola specifically because it doesn't show up as a visible bot, that marketing pitch is now Exhibit A against you.

Basich v. Microsoft — the biometric flank

Then there's Basich v. Microsoft Corp., filed February 5, 2026, which alleges Microsoft Teams uses speaker diarization to create biometric voiceprints from meeting participants without proper notice or written consent in violation of Illinois's BIPA. The suit matters for interview compliance because Teams is where most Fortune 500 first-round interviews happen — and because BIPA damages ($1,000–$5,000 per violation) scale linearly with the number of Illinois candidates you interview.

The five regimes that hit a single interview simultaneously

A single 30-minute video interview with a cloud notetaker running can trigger all five of the following at once:

Regime What it requires Trigger for an interview notetaker Exposure
CIPA / ECPA wiretap (12 all-party consent states) Consent from every participant before recording Cloud bot joins call; candidate not separately notified Statutory damages + injunctive relief (Otter, Granola theory)
Illinois BIPA Written notice, informed consent, published retention/destruction policy before capturing voiceprints Speaker diarization extracts vocal characteristics $1,000–$5,000 per violation, per person
EEOC / Title VII (federal) No disparate impact in selection procedures; "the algorithm did it" is not a defense AI-derived interview scores, summaries, or ranking Class action, back pay, injunctive relief
NYC Local Law 144 Annual independent bias audit, public audit summary, 10 business days' candidate notice Tool "substantially assists" hiring decision for NYC-located role $500 first violation, $500–$1,500 per additional day
Illinois AIVIA Notify applicant, explain the AI, obtain consent, delete recording within 30 days on request AI analyzes recorded video interview for Illinois role Civil rights violation under 2026 amendments to state Human Rights Act

The all-party consent problem, mechanically

The cloud notetaker business model assumes the meeting host clicks "start recording" and that click satisfies consent for everyone in the room. As the HR Executive analysis of the Otter litigation summarizes, valid consent must be freely given, specific and unambiguous from each individual whose data is processed — a model that relies on one meeting participant to authorize recording on behalf of all others would likely not satisfy the regulations. The article quotes Bradford Kelley, a Littler Mendelson shareholder who co-authored a February 2026 analysis, calling AI transcription "a hot issue" and warning HR teams in all-party consent states to be "very interested in this case."

Even in one-party jurisdictions, in-interview consent is fragile. As Honeit's Talent Acquisition analysis of the Otter case puts it, recruiting conversations involve compensation expectations, career frustrations, personal circumstances, location constraints, and employment history — data that falls under GDPR, CCPA, and state-level biometric and wiretap statutes, and that in California, Illinois, and at least nine other all-party consent states creates a legal violation whenever recording occurs without explicit consent from all parties. A candidate asked mid-call whether the notetaker is okay has no meaningful ability to say no.

EEOC disparate impact: the second wave lawyers are watching

Even if you cleared the wiretap and BIPA problem, you still have the EEOC problem. Per JTNY Law's 2026 EEOC hiring-algorithms analysis, the agency has intensified focus on algorithmic bias in 2026, and its Strategic Enforcement Plan for 2024–2028 prioritizes "algorithmic fairness," targeting automated systems in selection procedures — including AI-driven video interview analysis. The federal benchmark is the four-fifths rule: if one group passes a screen at less than 80% of the rate of the highest-scoring group, that gap is treated as evidence of adverse impact. AI interview summaries, sentiment scores, and "culture fit" rankings all sit squarely in that crosshair, and "the algorithm did it" is not a defense.

Combine that with the pending Workday class action alleging AI hiring tools discriminate against Black, older, and disabled candidates — a case that broadens liability from standalone AI interviewers to any ATS+AI platform — and the exposure profile of a cloud notetaker feeding transcripts into a downstream ranking system starts to look like a compliance officer's worst afternoon.

NYC Local Law 144 and Illinois AIVIA: the notice regimes you can't skip

The DCWP is the enforcement body for NYC Local Law 144, which requires employers using AEDTs for hiring or promotion decisions to conduct a bias audit no more than one year prior to use, publish a summary of the audit results on their website, and properly notify candidates that an AEDT will be used, how it will be used, and what data will be collected. Civil penalties run between $500 and $1,500 per day for violations. The New York State Comptroller's December 2025 audit — summarized by DLA Piper — concluded that DCWP enforcement has been "ineffective," which practitioners read as a signal of increased enforcement pressure, not a green light.

Illinois goes further. Per BrightHire's 2026 AI interview compliance guide, the Illinois AI Video Interview Act (in force since 2020) requires employers that use AI to analyze recorded video interviews to notify applicants first, explain how the AI works, get their consent, and delete the recording within 30 days on request. A 2026 amendment to the state Human Rights Act (effective January 1, 2026) additionally makes it a civil rights violation to use AI in hiring in a way that discriminates against a protected group. Whether your notetaker's summary counts as "AI analysis" of the interview is exactly the kind of question you don't want litigated on your dime.

Why "just turn off training" isn't the fix

The obvious mitigation — flip the vendor's "don't train on my data" toggle — helps but doesn't close the exposure. Three reasons:

  1. Default-on is the plaintiff's exhibit. The Granola complaint specifically alleges that meeting contents were used by default for commercial purposes including training AI systems unless the user turned that setting off — meaning class members' data was arguably already ingested before anyone read the settings page.
  2. Vendor-side storage still creates discovery surface. Even without training, the vendor now holds a copy of the interview transcript subject to subpoena in any downstream discrimination or wrongful-termination claim. Cloud storage of raw recordings expands, per Meeting Notes' 2026 review of AI notetakers, both discovery exposure and ongoing regulatory risk.
  3. Voiceprints are extracted at inference time. Speaker diarization requires clustering voice characteristics regardless of whether the transcript is used for training. That's the mechanic underlying every BIPA notetaker complaint — the biometric identifier exists whether you "turn off" downstream use or not.

A copy-paste HR decision framework for August 2026

The most useful thing an HR leader can do this week is not memorize the case law — it's write down a defensible policy. Here is a framework you can adapt:

  1. Default: no AI notetaker in candidate interviews. The productivity gain (a searchable transcript) does not clear the combined wiretap + BIPA + EEOC + LL 144 + AIVIA hurdle for most organizations.
  2. If recording is required (say, for structured-interview validation), use on-device transcription that never sends audio to a vendor server, disable speaker-identification/voiceprint features where possible, and obtain written pre-interview consent in the invitation email with a genuine, penalty-free option to decline.
  3. Ban invisible "botless" cloud recording during interviews. The Granola marketing line — that other people "won't know it's there" — is precisely the design pattern plaintiffs are targeting. Tools that hide their presence do not solve the consent problem; they aggravate it.
  4. Map every AI tool that touches candidate data. As the Layer3 Labs compliance guide observes for MNPI, you cannot control what you have not mapped — the same applies to protected-class candidate data. Include notetakers, ATS AI features, scheduling copilots, and CRM AI assistants.
  5. Set a short retention default (e.g., delete raw audio at meeting end, retain structured notes only) and honor Illinois AIVIA's 30-day deletion-on-request rule for any AI-analyzed video.
  6. Publish a candidate-facing notice that meets NYC LL 144's 10-business-day advance-notice requirement if the tool substantially assists hiring — and post the annual bias audit summary if applicable.

How Basil AI solves this: on-device transcription for candidate conversations

Basil AI is a fully on-device meeting recorder for iPhone and Mac. Audio is transcribed locally using Apple's on-device Speech Recognition — the same architecture Apple describes in its privacy documentation and its developer documentation — and never leaves the interviewer's device. There is no vendor server holding candidate audio, no default training pipeline to disable, and no visible bot joining the call to alarm the candidate.

What that changes concretely for the risk map above:

On-device processing is an architecture fact, not a compliance guarantee. Basil AI is not "HIPAA compliant" or "GDPR compliant" — compliance is a determination your firm, employment counsel, and DPO make. What on-device architecture does is remove the third-party vendor from the data flow that generates most of the current wave of litigation. For deeper reading, see our breakdown of Chamberlain v. Granola, our two-party consent state guide, and our earlier piece on AI meeting bots in job interviews.

What to do this week

The bottom line

The current wave of AI notetaker lawsuits is not really about AI. It is, as the SocialTalent piece puts it, about consent design — what your vendor assumed on your behalf the moment someone hit record inside a candidate conversation. For HR leaders, the safest posture in August 2026 is: no cloud notetaker in interviews by default; if you must capture the conversation, use on-device transcription with explicit, written, pre-interview candidate consent; and never rely on a tool marketed as invisible. The regulatory frameworks that already apply — GDPR Article 5, BIPA, Title VII, LL 144, AIVIA — do not require you to wait for the first federal ruling. They require you to design consent in, not bolt it on.

Interview transcripts that never touch a vendor server

Basil AI records and transcribes interviews entirely on-device — no cloud upload, no vendor-side training, no invisible bot in the meeting.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

Is it legal to use an AI notetaker in a job interview?

It depends on the state and the tool. In the 12 all-party consent states (California, Illinois, and others), every participant — including the candidate — must knowingly consent before an AI notetaker records. Recent lawsuits against Otter.ai and Granola allege host-only consent isn't enough. Employers using cloud notetakers without explicit candidate notice risk wiretap, BIPA, and employment-law claims simultaneously.

What is Chamberlain v. Granola about?

Chamberlain v. Granola is a proposed class action filed July 30, 2026 in the U.S. District Court for the Northern District of California. The complaint alleges Granola recorded meeting participants without notice and, by default, used those recordings to train its AI models. Plaintiffs cite Granola's own marketing line that other people on a call "won't know it's there" as evidence of intentional non-disclosure.

Does BIPA apply to AI interview notetakers?

It can. The Illinois Biometric Information Privacy Act covers voiceprints — unique biometric identifiers derived from speech. Cases like Cruz v. Fireflies.AI and Basich v. Microsoft Corp. allege that speaker diarization features create voiceprints without the written notice, consent, and retention policy BIPA requires. Statutory damages run $1,000–$5,000 per violation, per person.

What does NYC Local Law 144 require for AI in hiring?

NYC Local Law 144 makes it unlawful to use an automated employment decision tool (AEDT) to substantially assist hiring or promotion decisions unless the tool has been independently bias-audited within the past year, the audit summary is publicly posted, and candidates receive at least 10 business days' notice. DCWP penalties run $500 for a first violation and $500–$1,500 per subsequent day.

Can we just ask the candidate on-camera if recording is okay?

In-interview verbal consent is fragile. Employment counsel note the power imbalance makes candidate consent arguably not "freely given" under GDPR standards, and mid-call requests do not satisfy NYC LL 144's 10-business-day advance notice or Illinois AIVIA's pre-interview disclosure. Best practice is written disclosure in the interview invitation with a genuine option to decline.

How does on-device transcription change the interview compliance picture?

On-device processing removes the third-party vendor from the data flow — no cloud server holds the audio, no model trains on the transcript, no visible bot joins the call to alarm candidates. It doesn't eliminate consent obligations (the interviewer still needs candidate permission to record) but it removes the wiretap-by-vendor, BIPA-voiceprint, and vendor-breach exposure that drives current litigation.