AI Notetakers and NDAs: How Consultants Are Quietly Breaking Client Confidentiality Agreements
Published September 06, 2026
- Standard NDAs prohibit disclosing confidential information to third parties — cloud AI notetakers are third parties.
- Federal class actions against Otter.ai and Granola allege recording without all-party consent and training AI on captured meetings by default.
- In California and 11 other two-party consent states, silent AI recording exposes consultants to $5,000-per-violation statutory damages under CIPA.
- On-device transcription eliminates the third-party disclosure problem because audio never leaves the user's device.
- Consultants should get written client approval before any AI notetaker touches an NDA-covered call, or use on-device tools that don't upload.
Quick answer: In most cases, yes — a cloud AI notetaker on a client call almost certainly breaches a standard NDA. Sending audio or transcripts of confidential discussions to a third-party vendor that stores, processes, and (often by default) trains its models on that content is a disclosure to a third party. Most NDAs prohibit exactly that unless the client has approved the vendor in writing.
Someone on your team joined a client discovery call yesterday with an AI notetaker running in the background. It captured 45 minutes of confidential strategy discussion, pushed a summary to Slack, and quietly used the transcript to train a foundation model. It saved them thirty minutes of writing. It also, in all likelihood, breached the NDA you signed with that client — and neither the consultant nor the client is aware.
This is not a hypothetical. It is now a documented pattern behind two federal class actions and a growing wave of enforcement risk. In Chamberlain v. Granola, Inc., filed July 30, 2026 in the Northern District of California, a plaintiff alleges Granola's silent notetaker recorded calls without notice to most participants and used the content for AI model training by default. It joins In re Otter.AI Privacy Litigation, where a California court allowed wiretap and biometric-privacy claims against Otter.ai to proceed on August 13, 2026.
For consultants — whose entire commercial relationship is built on client confidentiality — the practical question is simpler than the legal one: does an AI notetaker on my client calls violate my NDA? This article answers that question, walks through the specific NDA clauses at issue, and explains how on-device transcription eliminates the third-party disclosure problem that sits at the heart of every current lawsuit.
The Simple Rule: A Cloud AI Notetaker Is a Third Party
Every standard NDA contains a variation of the same clause: the receiving party will not disclose Confidential Information to any third party without the disclosing party's prior written consent. That clause is not aspirational language. It is the operational core of the agreement.
When you enable Otter, Fireflies, Granola, Zoom AI Companion, or any other cloud-based notetaker on a client call, you are doing three things simultaneously: (1) making a recording of the confidential discussion, (2) transmitting that audio or transcript to a vendor's servers, and (3) authorizing that vendor to process, store, and — under most default settings — improve its models using that content. Every one of those steps is a disclosure to a third party.
The Legal Chain analysis of NDAs in the AI era puts it bluntly: the non-disclosure agreement is one of the most commonly executed legal documents in commercial life, and it is also one of the most outdated in the face of how work is actually done in 2026. The person pasting a client brief into an AI tool almost certainly does not know they may have violated the NDA. The NDA almost certainly does not address it explicitly. And the AI tool almost certainly used the input to improve its model.
What the Granola and Otter Complaints Actually Allege
The two lead cases are worth reading not as abstract privacy litigation but as a specification of exactly how AI notetakers create NDA exposure.
Chamberlain v. Granola: The Silent-Capture Model
According to PPC Land's coverage of the filing, Tarra Chamberlain filed the class action on July 30, 2026 on behalf of a proposed nationwide class and a California subclass. The complaint accuses Granola of intercepting virtual conversations without the knowledge of most participants, then feeding those recordings into its own AI model training by default.
The Mondaq legal analysis highlights the detail that makes this a confidentiality case as much as a wiretap case: Granola actively markets the absence of a visible meeting bot as its core differentiator, quoting the company's own website — "Other people in the room won't know it's there." A product feature became the argument that concealment was designed rather than incidental. Crucially, Granola's own privacy policy acknowledges that data incorporated into models cannot be extracted once training is complete. If a client's confidential strategy discussion is inside the weights of a foundation model, no delete request will remove it.
In re Otter.AI: The Visible-Bot Model Isn't Safer
The HR Executive analysis of the consolidated Otter case notes that plaintiffs allege Otter's notetaking tools recorded private conversations without the consent of all participants and used those recordings to train its AI models without adequate disclosure. Employment attorney Bradford Kelley of Littler Mendelson calls AI transcription and recording "a hot issue" that is already signaling where liability will land for employers.
The takeaway for consultants: a bot notetaker joining the call as a visible participant does not automatically fix the NDA problem. The client can see "Otter Notetaker" in the participant list, but visibility is not consent — and it certainly is not the "prior written consent" that most NDAs require.
Two-Party Consent States Turn NDA Risk Into Statutory Damages
The NDA is a contract claim. The wiretap laws are something else entirely: statutory violations with fixed per-incident damages, and in some jurisdictions, criminal exposure. For a consultant operating across state lines, the wiretap overlay is the more urgent risk.
California AI meeting recording law makes this explicit: under Cal. Penal Code §§ 631 and 632 (CIPA), recording a confidential conversation requires the consent of every participant. AI meeting recorders are lawful in California only when every participant consents before recording begins, and recording without that consent exposes users and companies to civil damages of at least $5,000 per violation, or three times actual damages, whichever is greater. Because California residents can invoke CIPA even when the recording happens outside the state, a nationwide consulting practice is a nationwide CIPA exposure.
The National Law Review's takeaway from the Granola case generalizes the point: when a company designs technology to capture communications without clear notice to everyone involved, especially in a two-party consent state like California, privacy and wiretapping claims may follow. For a consultant, that reads as: your Granola or Otter subscription is not just a tooling decision — it is a personal liability decision.
Cloud vs. On-Device Notetakers: The NDA-Relevant Differences
The single fact that determines whether a notetaker creates NDA exposure is where the audio and transcript live after the meeting ends. Everything else — features, integrations, pricing — is downstream of that one architectural choice.
| Dimension | Cloud AI Notetaker (Otter, Fireflies, Granola, Zoom AI) | On-Device AI Notetaker (Basil) |
|---|---|---|
| Where audio is processed | Uploaded to vendor's servers | Processed locally on iPhone/Mac Neural Engine |
| Third-party disclosure under NDA | Yes — vendor is a third party receiving confidential info | No — no vendor server receives the audio |
| Default training on customer content | Common (opt-out); Granola complaint alleges opt-out only applies going forward | Not applicable — content never leaves device |
| Retention | Indefinite until user deletes; some vendors retain even after deletion | Controlled entirely by the user on their device |
| Subpoena exposure | Vendor can be subpoenaed for transcripts | No vendor copy exists to subpoena |
| Bot visibility in meeting | Bot notetakers visible; silent-capture tools invisible | No bot; consultant still must disclose recording verbally |
| CIPA all-party consent | Required regardless of vendor | Required regardless of vendor |
The last row matters: on-device architecture does not, by itself, satisfy state consent laws. A consultant still needs to announce the recording and get consent. What on-device architecture does eliminate is the third-party disclosure problem — the specific NDA clause that cloud notetakers structurally cannot honor.
The Consultant-Specific NDA Clauses That Cloud Notetakers Trip
Not all NDA clauses are equally sensitive to AI. In practice, four categories are where cloud notetakers create trouble:
1. "No disclosure to third parties without prior written consent"
This is the core clause and the one cloud notetakers structurally cannot honor. The vendor is a third party. The user did not obtain the client's prior written consent to disclose to that vendor. Full stop.
2. "No reproduction or copying of Confidential Information"
A transcript is a reproduction. So is an AI summary. So are the derivative embeddings a foundation model creates during training. Most NDAs prohibit reproduction without explicit authorization for a specified purpose.
3. "Return or destruction of Confidential Information upon request"
This is where AI training becomes uniquely dangerous. Once content is incorporated into model weights, it cannot be selectively deleted. The Mondaq analysis of the Granola case makes this explicit — Granola's own privacy policy acknowledges data in models cannot be extracted once training is complete. A consultant who agrees to a return-or-destroy clause cannot honor it after their notetaker vendor has trained on the transcript.
4. "Use limited to the purpose of the engagement"
Confidential Information is typically disclosed for a specific purpose (the consulting engagement). Using it to train a general-purpose foundation model is a categorically different use — one the client never authorized.
The "But We Anonymize It" Defense Doesn't Work
Vendors often argue their AI training uses "de-identified" or "anonymized" data. That defense collapses in a consulting context. The confidential information in a client discovery call is often not personally identifiable — it is a product roadmap, a pricing strategy, an M&A rationale, a competitive threat assessment. None of that becomes non-confidential when you strip out names. The Carta analysis of AI clauses in NDAs notes the emerging drafting trend is to limit the use of confidential information in training or fine-tuning generative models specifically, rather than prohibiting all AI use — precisely because "anonymization" does not solve the confidentiality problem for business-sensitive content.
The Practical Checklist for Consultants in 2026
Consultants who take client confidentiality seriously — meaning consultants who want to keep their clients — should be doing the following before any AI notetaker touches a client call:
- Audit every notetaker vendor against your NDA obligations. If you signed an NDA that prohibits disclosure to third parties, list every AI vendor your team uses and check whether the client would have approved that specific vendor.
- Get client approval in writing before enabling any cloud AI on their calls. A verbal "I'm going to record this" is not the "prior written consent" most NDAs require. A short email exchange approving a specific vendor is.
- Announce recording verbally at the start of every call. The Lilach Bullock analysis of AI notetakers and NDA risk emphasizes that a quick verbal check at the start solves most of the risk in under ten seconds — and creates the record you need if consent is ever disputed.
- Turn off default AI training. On Otter, Fireflies, Granola, and most cloud tools, training on customer content is opt-out. Opt out on every account, and confirm the opt-out applies retroactively (in most cases it does not).
- Prefer on-device tools for NDA-covered calls. If audio never reaches a vendor server, the third-party disclosure clause is not triggered. That is the only architectural fix.
- Update your engagement letters. Add a paragraph that specifies which AI tools may be used on the engagement and how transcripts will be retained. This makes future disputes about "implied consent" much cleaner.
- Set short retention on any transcripts you do keep. Auto-delete after 30 or 60 days materially reduces discovery exposure without meaningfully hurting your workflow.
How Basil AI Changes This Analysis
Basil AI is a fully on-device transcription app for iPhone and Mac. Every step of the pipeline — audio capture, speech recognition via Apple's Speech framework, transcript generation, summary — runs on the user's device. Nothing is uploaded to a Basil server for processing. There is no "Basil cloud" holding a copy of the meeting.
For a consultant facing an NDA that prohibits disclosure to third parties, that architectural fact does specific work: because no vendor server receives the confidential audio or transcript, there is no third-party disclosure to consent to. The consultant is not making Basil a receiving party of the client's confidential information — Basil is a tool running on the consultant's own hardware, in the same category as a notepad or a personal recorder, not a category with Otter or Granola. This is an architecture claim, not a compliance guarantee: the consultant is still responsible for state consent laws, retention policies, and their own client agreements. But the specific NDA clause that trips every cloud notetaker is not tripped.
For a deeper technical walkthrough of how the on-device pipeline works, see our analysis for asset managers handling MNPI, our comparison of Granola, Otter, and Basil on privacy, and our breakdown of bot vs. botless architectures for client-facing meetings.
What About Zoom AI Companion and Microsoft Copilot?
Two objections come up. First: "Zoom says it doesn't train on customer content." That is currently true — Zoom's AI Companion privacy documentation states Zoom does not use customer audio, video, chat, screen sharing, or other communications-like customer content to train Zoom's or its third-party AI models. But the no-training commitment does not eliminate the third-party disclosure problem. Zoom still processes the audio to generate summaries, still retains transcripts for a period, and can share summaries within your organization's account. The training question and the disclosure question are separate; the NDA cares about both.
Second: "My client uses Microsoft Copilot on their end." Client-side use of an AI product changes the analysis only if the client has explicitly authorized it in the NDA or in a separate approval. In practice, most clients have not — they have deployed Copilot inside their own environment for their own workflows, not authorized their vendors to feed confidential information into third-party AI systems.
The Direction of Travel
The Otter and Granola cases are early. As Jennifer Ruehr at Hintze Law observes in her Law360 analysis, the August 13, 2026 ruling in In re: Otter.AI Privacy Litigation allowed significant portions of the class action to proceed — meaning the plaintiffs' theory that AI notetakers are communications-capture tools with privacy and wiretap risks now has a live litigation vehicle. The same district is hearing the Granola case. The precedent that emerges over the next twelve months will define AI notetaker liability for the rest of the decade.
Consultants do not need to wait for the case law to settle. The NDA analysis is available now, and the on-device fix is available now. The consultants who move first will look like the careful professionals their clients hired. The ones who wait will find out from a client who mentions it once, politely, and then never books another call.
Frequently Asked Questions
Does using Otter, Fireflies, or Granola on a client call violate my NDA?
Almost certainly, unless your client has approved that specific vendor in writing. Standard NDAs prohibit disclosure of confidential information to any third party without consent. Uploading audio or transcripts to Otter, Fireflies, or Granola's servers is a disclosure to a third-party processor. Otter and Granola are currently defendants in federal class actions alleging exactly this pattern — recording non-consenting participants and training AI models on the content.
Do I need explicit consent from every meeting participant before recording with AI?
In California and other two-party consent states, yes. California's Invasion of Privacy Act requires all parties to consent to recording confidential communications, with statutory damages of $5,000 per violation. Even in one-party states, silent AI capture without disclosure will typically breach an NDA and violate professional ethics rules for consultants, lawyers, and healthcare workers.
Is on-device AI transcription safer for NDA-covered client calls?
Yes, materially. If audio and transcripts never leave the user's device, there is no third-party processor receiving confidential information — which removes the classic NDA breach vector. On-device tools like Basil AI process everything locally on the Apple Neural Engine, so no vendor server holds a copy of the meeting. That said, you still need all-party consent under state recording laws.
What should an AI clause in an NDA actually say in 2026?
A modern NDA should (1) prohibit inputting confidential information into any AI system that retains or trains on customer data, (2) require pre-approval of any AI transcription or notetaking vendor, (3) require deletion of any AI-generated output on request, and (4) require all-party consent before any AI recording of the covered discussions. Blanket AI bans are increasingly unworkable since Microsoft 365 and Google Workspace embed AI features.
Can I be sued personally for using a bot notetaker on a client call?
Potentially, yes. The Chamberlain v. Granola and In re Otter.AI class actions target the notetaker vendors, but individual users have also been sued directly under state wiretap laws for recording non-consenting participants. California CIPA and Florida Statute 934.03 both allow suits against the person who caused the recording, not just the vendor. Consultants should treat AI notetakers as a personal liability exposure, not just a vendor risk.
What's the difference between bot notetakers and botless ones for NDA compliance?
Bot notetakers (Otter, Fireflies, Read AI) join calls as visible participants — clients can see them and object. Botless tools (Granola, some Zoom Companion configurations) capture device audio silently, so participants often never know a recording exists. Both send content to cloud servers, so both create NDA exposure. Botless tools arguably create worse exposure because the lack of notice defeats any 'implied consent' defense.