Bot vs. Botless AI Notetakers: Which Approach Actually Fits Your Meetings?
Published September 08, 2026
- Bot vs. botless is a capture-method choice; cloud vs. on-device is a privacy choice — do not confuse the two.
- The July 2026 Chamberlain v. Granola class action reframes silent, no-bot capture as a wiretap risk, not a feature.
- In all-party consent states, no court treats a bot in the participant list as sufficient legal notice — you still need explicit disclosure.
- For external client calls and in-person meetings, botless is usually the right capture mode; for internal all-hands, a visible bot can be an asset.
- The only architecture that avoids both bot-fatigue and vendor-side cloud exposure is on-device botless capture on hardware you already own.
Quick answer: Bot-based AI notetakers join a call as a visible participant that shows up in the attendee list; botless (bot-free) notetakers capture microphone or system audio directly from a device with nothing joining the call. Bots give clearer notice but announce themselves to clients; botless tools feel invisible but shift the entire burden of consent onto the human host — and, as the July 2026 Chamberlain v. Granola lawsuit shows, invisibility can create wiretap exposure of its own.
Two capture architectures dominate AI meeting notes in 2026: bots that join the call and botless tools that listen from your device. The July 2026 Chamberlain v. Granola lawsuit just proved that picking between them is more consequential than most buyers realize.
The core difference in one sentence
A bot-based AI notetaker sends a virtual attendee into your video call — an entity that appears in the participant list and typically joins via a calendar link. A bot-free (botless) tool captures meeting audio directly from your microphone or your computer's system audio, so nothing joins the call at all. As Fathom puts it in its 2026 comparison, no bot appears in the attendee list and no admission is required for the third-party recorder.
Everything else — where audio is processed, whether it trains a model, how long a vendor retains it, whether admins can see it — is a separate question. Conflating "botless" with "private" is the single biggest mistake buyers make in 2026, and it is the mistake that turned the year's most talked-about botless product into a defendant.
How bot-based notetakers actually work
A bot-based tool like OtterPilot, Fireflies, Read AI, or Gong watches your calendar, and when a meeting starts, dispatches a virtual participant into the Zoom, Google Meet, or Microsoft Teams call. The bot receives the same audio feed the humans do, streams it to a vendor cloud, and returns a transcript, summary, and action items after the call.
The upside is transparency: everyone in the meeting sees an attendee named something like "Fireflies Notetaker" or "Otter.ai." That visibility is a real, if imperfect, disclosure. It is also the enterprise-friendly path — admin consoles, retention policies, and audit trails all live in the vendor's control plane. Guidance from Dark Reading's Black Hat USA 2026 coverage emphasizes exactly this: if you see an AI notetaker in a call you didn't invite, that is itself a red flag worth acting on.
The downsides are equally real. The bot is a third party in every legal and technical sense. It joins external client calls uninvited, gets denied entry by security-conscious hosts, and cannot participate in an in-person conversation at all. And the entire recording sits on a vendor server, subject to subpoena, breach, and — historically — training use.
How botless notetakers actually work
A botless tool runs as a desktop or mobile app on the device of the person taking notes. When a meeting starts, it captures microphone input, system audio, or both, and pipes them to a transcription engine. Popular botless products in 2026 include Granola, Jamie, Fathom's bot-free mode, Krisp, Shadow, and Basil AI.
The upside is that the meeting looks and feels normal. There is no unfamiliar attendee, no join notification, no admission click. That matters most for three scenarios called out by Fathom's 2026 guide: external client calls where an uninvited bot reads as unprofessional, compliance-sensitive industries where a third-party participant raises its own data-handling questions, and fully in-person meetings where there is no video call for a bot to join in the first place.
The downside is subtler and, until 2026, largely ignored: silent capture removes the very cue that prompts other participants to ask about recording. When the tool announces nothing, the burden of disclosure falls entirely on the human user — and if the human forgets, the tool has captured people who never had any signal that recording was occurring.
The Chamberlain v. Granola lawsuit: when invisibility becomes a liability
For most of 2024 and 2025, botless was pitched — by vendors and the tech press alike — as the elegant answer to bot fatigue. That story changed on July 30, 2026, when Tarra Chamberlain filed a putative class action against Granola, Inc. and Granola Labs Ltd. in the U.S. District Court for the Northern District of California (Case No. 3:26-cv-07926-EMC).
According to a legal analysis published by Barnes & Thornburg, Granola's design captures audio via system input and microphone on Google Meet, Zoom, Microsoft Teams, and other platforms — with no bot in the participant list and no notification for other attendees. The complaint alleges Granola uses those captured communications for AI model training by default, and that Granola's own privacy policy acknowledges data incorporated into models cannot be extracted once training is complete.
The Tool Directory litigation tracker summarizes the significance in a single line: the case is about notice, not bots. A bot at least appears in the attendee list; a tool that announces nothing removes the signal that would prompt someone to object, which is why bot-free capture does not, on its own, resolve the consent question. Plaintiffs' counsel even pointed to Granola's own marketing that other participants "won't know it's there" as evidence of intent.
Chamberlain builds on a broader pattern. In the parallel In re Otter.AI Privacy Litigation, four consolidated class suits before Judge Eumi K. Lee allege OtterPilot recorded participants without every-party consent under the federal Electronic Communications Privacy Act (ECPA) and the California Invasion of Privacy Act (CIPA), and used the recordings to train AI models. On August 13, 2026, the court dismissed the computer-intrusion claims with leave to amend but allowed the Wiretap Act, CIPA, and Illinois biometric claims to proceed into discovery. For a deeper look at that ruling, see our analysis of the Otter.ai August 13 ruling.
Consent law does not care what the bot looks like
The wiretap statutes at the center of these cases were written decades before AI notetakers existed, and their text applies to any "device" used to capture a communication. As RecordingLaw's 2026 guide explains, AI notetakers count as recorders — tools like Otter, tl;dv, Fireflies, and the built-in AI companions in Zoom and Microsoft Teams capture the audio of a meeting to produce transcripts, and two-party consent laws treat that exactly like any other recording. Sending a bot into a meeting without telling the other participants can be unlawful recording in the 12 all-party states, even when the tool appears in the participant list.
That last point deserves emphasis. Circleback's consent guide states it flatly: a visible meeting bot is not legally sufficient consent, and no jurisdiction treats bot presence in a participant list as informed agreement. Explicit disclosure is required regardless of recording method — bot or bot-free.
The 12 all-party consent states, per Layer3Labs' 2026 roundup, include California (Penal Code § 632, the heart of CIPA), Florida (Fla. Stat. § 934.03), and Illinois (720 ILCS 5/14-2). Cross-state calls should default to the most restrictive jurisdiction — which for a distributed team almost always means all-party by default. For a full breakdown of which states and which statutes, see our detailed two-party consent compliance guide.
Bot vs. botless: side-by-side
| Dimension | Bot-based (Otter, Fireflies, Read AI) | Botless cloud (Granola, Jamie, Fathom) | Botless on-device (Basil AI) |
|---|---|---|---|
| Visible in attendee list | Yes | No | No |
| Works for in-person meetings | No | Yes (mobile app required) | Yes |
| Works when host denies bot entry | No | Yes | Yes |
| Audio uploaded to vendor cloud | Yes | Usually yes | No |
| Content used to train AI (default) | Historically yes | Varies — Granola: yes unless opted out | No — no vendor server |
| Subpoena / breach exposure at vendor | High | Moderate to high | None |
| Provides its own visible notice to guests | Bot icon (not legally sufficient) | None | None |
| Named in a 2026 wiretap class action | Otter, Fireflies | Granola | No |
Sources: AI Notetaker Lawsuits 2026, Krisp 2026 review, MeetingsAI comparison.
The privacy-vs-capture matrix most reviews miss
Bot vs. botless is a capture decision. On-device vs. cloud is a processing decision. Those two axes are independent, and mapping them makes the real trade-space visible.
- Bot + cloud: Otter, Fireflies, Read AI. Maximum transparency to guests, maximum vendor exposure.
- Botless + cloud: Granola, Jamie, Fathom, Krisp. No bot friction, but audio still leaves the device.
- Botless + on-device: Basil AI. No bot, and the transcript never touches a vendor server.
- Bot + on-device: effectively empty — a bot has to phone home to some cloud to be useful.
Reviews that rank tools on a single axis miss this. MeetingsAI's 2026 comparison puts it well: bot-free is a capture method, not a privacy guarantee, and Granola in particular says little publicly about where processing happens while offering an opt-out of model training — a signal that notes pass through vendor servers.
A decision framework: which capture mode fits which meeting
Use a bot-based tool when
- The meeting is a large internal all-hands or team standup where every attendee already knows recording is standard and the calendar invite documents it.
- You need an admin-managed audit trail and centralized retention policy across the whole team.
- Everyone on the call is in a one-party consent state and the host is a participant.
Use a botless tool when
- The meeting is external — client discovery, sales, candidate interview — and an uninvited third-party attendee would read as unprofessional or get denied entry.
- The meeting is in-person, in a room, at a coffee shop, or on a phone call where no video-conference bot can attend.
- You're a solo consultant or small firm without the infrastructure (or need) for a bot admin console.
Use a botless on-device tool when
- The conversation is privileged (attorney-client, doctor-patient) or covers material non-public information.
- The meeting is subject to regulator recordkeeping — SEC/FINRA, HIPAA-adjacent, EU AI Act workplace monitoring — where a vendor-held recording becomes a discovery and breach surface.
- You need capture that keeps working when Wi-Fi drops or when the customer's firewall blocks unknown bots.
The point of the third bucket is that on-device botless does not eliminate your consent obligation — you still need to disclose recording verbally in all-party states, per RecordingLaw's guidance. What it does eliminate is the vendor as a potential third-party interceptor, which is the exact theory the Chamberlain and Otter plaintiffs are pressing.
What buyers keep getting wrong
Three assumptions are especially common — and especially wrong in 2026.
"Botless means private." It does not. A botless tool can still stream every syllable to a vendor cloud, train on it by default, and hand it to a regulator on a subpoena. Mondaq's write-up of the Granola case notes that the complaint alleges captured communications are used for AI model training by default — meaning silent capture and permanent model incorporation can coexist.
"A bot icon in the participant list is enough." It is not. Circleback, RecordingLaw, and NimitAI all note that recording indicators — even visual ones from Zoom and Google Meet — typically count as notice in one-party states but are generally NOT sufficient for two-party consent.
"On-device solves consent." It solves architecture, not law. You still owe every participant in an all-party state a real disclosure and a real chance to opt out. On-device just means the vendor is not a co-defendant when things go wrong.
How Basil AI solves this
Basil AI is a botless, on-device AI notetaker for iPhone, iPad, and Mac. It captures audio through your device's microphone (in-person or on the desk during a video call), transcribes it in real time using Apple's Speech Recognition APIs running on-device, and stores the resulting transcript in your local storage and, if you choose, in Apple Notes via iCloud — which itself uses end-to-end encryption when Advanced Data Protection is enabled, per Apple's privacy commitments.
What that means for the trade-offs in this article:
- No bot in the call. Nothing to explain to a client, nothing for their IT to block, and it works for in-person conversations that a bot could never join.
- No vendor cloud. The transcript is generated on the same Apple Neural Engine that Siri uses. There is no vendor-side recording for a plaintiff to demand or a breach to expose — the architectural fact at the heart of why Chamberlain-style theories don't attach to on-device tools.
- No training by default. There is no vendor server collecting your audio to train on. Your recordings are yours.
- Consent is still your job. Basil AI does not pretend to remove your legal obligation to announce recording. In an all-party state, you still say "I'm going to take notes with an on-device AI assistant — is that okay with everyone?" at the top of the call. The difference is that when consent is given, the resulting transcript never leaves your device.
For the deeper technical picture, see our coverage of iOS 26's on-device SpeechAnalyzer and our comparative AI notetaker comparison guide.
What to do Monday morning
- Inventory your meeting mix. If more than 30% of your meetings are external or in-person, a bot-only stack is already leaving value on the table — and creating friction with clients.
- Map your team to consent states. If any regular participant sits in California, Florida, Illinois, Massachusetts, Pennsylvania, or the other 12 all-party states, default your recording policy to all-party disclosure — regardless of tool.
- Read the training default. Open your current notetaker's settings and find the model-training toggle. If it's on by default, turn it off; if you can't tell, that itself is a data point.
- Pilot on-device for sensitive conversations. Use a botless on-device tool for the calls where a subpoena, breach, or privilege waiver would matter most — legal, HR, M&A, executive one-on-ones, healthcare.
- Write the disclosure into your meeting template. A one-sentence verbal announcement plus a line in the calendar invite is cheap insurance in any jurisdiction.
The bottom line
Bot vs. botless was framed for two years as a UX preference. In 2026, the Granola lawsuit made it a legal one — but for a subtler reason than most headlines suggest. Bots create friction; silent tools create liability. The right answer for most professionals is not "pick a side" but "pick the right mode per meeting, and prefer architectures where the vendor cannot become a co-defendant." That is the entire case for on-device, botless capture.
Try Basil AI — botless, on-device, private by design
Basil AI captures meetings on your iPhone, iPad, or Mac with zero cloud upload. No bot joins the call. Your transcript never leaves your device.
Frequently Asked Questions
Is a botless AI notetaker more private than a bot-based one?
Not automatically. 'Botless' describes how audio is captured, not where it's processed. Most botless tools still stream audio to a vendor cloud for transcription and, in some cases, model training. True privacy depends on whether the transcript ever leaves your device — an architectural question separate from bot vs. bot-free.
Do two-party consent states treat a visible bot as legal notice?
No. Guidance from privacy counsel and vendors like Circleback is that no U.S. jurisdiction treats a bot's presence in the participant list as informed agreement. In the 12 all-party consent states, you still need explicit verbal or written disclosure and a chance for participants to object — bot icon or not.
Why was Granola sued if no bot joins the call?
Because Chamberlain v. Granola (N.D. Cal., July 30, 2026) argues the case is about notice, not bots. The complaint alleges Granola captured a participant with no indication any notetaker was present and used the content for AI training by default. A silent capture tool removes the very signal that would prompt someone to object.
When should I choose a bot-based tool over a botless one?
Bot-based tools fit large internal meetings where a shared calendar invite already documents the recording, and where the visible attendee gives every participant a chance to opt out. They fail for in-person conversations, ad-hoc huddles, and external client calls where an uninvited bot reads as unprofessional or gets denied entry.
When should I choose a botless tool?
Botless capture fits external client calls, sales discovery, in-person meetings, and any conversation where a third-party attendee would be denied entry or damage rapport. But you must still deliver consent verbally, and you should prefer botless tools that process on-device rather than uploading audio to a vendor server.
Can an on-device tool still violate wiretap laws?
Yes, if the human user doesn't secure consent. On-device architecture removes the vendor as a potential third-party eavesdropper and eliminates cloud subpoena exposure, but it doesn't change your obligation under CIPA, ECPA, or state statutes to disclose recording and get agreement from every participant in all-party consent states.