SoundHound, Chipotle, and the CIPA Trap: When AI Voice Agents Intercept Your Phone Calls

Key takeaways
  • Thompson v. SoundHound AI (filed July 30, 2026, Alameda County) is the first major CIPA class action targeting AI voice agents answering restaurant phone lines.
  • The complaint invokes CIPA § 632.7, which requires no showing of confidentiality — every recorded cellular or cordless call without all-party consent is potentially in scope.
  • The ConverseNow ruling (Aug. 11, 2025) already let similar CIPA claims survive dismissal against an AI voice vendor used by Domino's, previewing how courts may treat SoundHound.
  • Businesses that deploy third-party AI voice agents face aiding-and-abetting co-liability, not just vendor risk.
  • On-device AI transcription (no vendor server, no cloud upload) eliminates the third-party-eavesdropper theory at the architectural level.

Quick answer: A July 30, 2026 California class action, Thompson v. SoundHound AI, alleges that AI voice agents answering Chipotle's published phone numbers secretly routed callers through SoundHound's servers, recorded conversations, and shared audio with third parties like OpenAI — all without disclosure. Plaintiffs argue this violates California's Invasion of Privacy Act (CIPA §§ 631 and 632.7), which requires all-party consent to record calls.

If you called a Chipotle in Oakland this year to order a burrito, you may not have been talking to Chipotle. According to a class action complaint filed July 30, 2026 in Alameda County Superior Court, the voice on the other end of the line was an AI voice agent operated by SoundHound AI, Inc. — routed through SoundHound's servers before the call was ever answered, recording the conversation, and allegedly sharing the audio with third parties including OpenAI. The plaintiff, Sandra Thompson, says she consented to none of it. She just wanted food.

That's the fact pattern behind Thompson v. SoundHound AI, Inc., and it opens a new front in the AI-recording lawsuit wave that has already ensnared Otter, Fireflies, Granola, and Microsoft Teams. The novelty here isn't a meeting notetaker joining a Zoom call. It's an AI voice agent quietly sitting between a customer and the business the customer thought they were calling — and the theory of liability reaches all the way back to California's 1967 wiretap statute.

What the Complaint Actually Alleges

The complaint tells a simple, old-fashioned story with a modern twist. Thompson dialed the phone number Chipotle publishes for its Broadway location in Oakland. According to reporting on the filing at Mondaq's summary of the case, the call was quietly routed to SoundHound's servers before anyone said hello, where an AI voice agent — not a Chipotle employee — answered, transcribed the conversation in real time, and allegedly retained the audio for training and data-sharing purposes.

The plaintiff's theory has two moving parts. First, SoundHound is a third party to the phone call between Thompson and Chipotle. Second, California's Invasion of Privacy Act (CIPA) prohibits third parties from intercepting the contents of communications in transit without the consent of every participant. Bolting an AI processor into the middle of that call, plaintiffs argue, is exactly the interception the statute was written to prevent — even if the restaurant that hired SoundHound is fine with it.

Why CIPA § 632.7 Is the Real Sleeper Threat

Most CIPA cases that reach the news involve § 631 (interception in transit) or § 632 (recording of a confidential communication). Confidentiality is a fact-specific fight — courts routinely dismiss claims where a caller couldn't reasonably expect a business call to be private. But Holland & Knight's analysis of the SoundHound complaint highlights the strategic move plaintiffs made: they anchored the case on § 632.7, which prohibits recording any cellular or cordless communication without all-party consent, with no confidentiality element to argue about.

That's a materially lower threshold. Almost every consumer call to a restaurant today comes from a mobile phone. If § 632.7 governs, every such recording without upfront disclosure is potentially actionable. Statutory damages under CIPA start at $5,000 per violation — and when you multiply by the volume of calls flowing through a national restaurant chain's AI ordering system, the math gets loud fast.

This Isn't the First AI Voice Agent to Get Sued

The SoundHound case didn't emerge in a vacuum. On August 11, 2025, in Taylor v. ConverseNow Technologies, the U.S. District Court for the Northern District of California denied a motion to dismiss a CIPA class action against another AI voice-assistant vendor that Domino's Pizza used to answer phone orders. As Wilson Sonsini's write-up of the ConverseNow ruling explains, the court held that a communications software provider that could potentially improve its own models by ingesting call content was plausibly acting as a third-party eavesdropper under § 631 — even though ConverseNow had a contract with the restaurant.

That ruling matters because it broke the industry's assumption that a vendor-under-contract is automatically "the business" for CIPA purposes. As Squire Patton Boggs's Privacy World blog noted at the time, the decision was a cautionary note not just to software companies but to any business deploying those technologies, because of the aiding-and-abetting exposure that flows back to the restaurant.

Where SoundHound Fits in the Broader AI Wiretap Wave

Zoom out and 2025-2026 has become the year the AI-recording defense bar started billing overtime. Every major architecture for AI conversation capture is now in federal court somewhere:

Case Defendant Capture architecture Lead legal theory Status
In re Otter.AI Privacy Litigation Otter.ai Meeting bot joins virtual calls ECPA / CIPA §§ 631, 632 Motion to dismiss partly denied Aug. 13, 2026
Cruz v. Fireflies.AI Corp. Fireflies.ai Meeting bot + speaker recognition Illinois BIPA §§ 15(b), (d) Filed Dec. 18, 2025
Chamberlain v. Granola, Inc. Granola Bot-free device-audio capture ECPA / CIPA / CDAFA Filed July 30, 2026
Basich v. Microsoft Corp. Microsoft Teams Cloud diarization voiceprints Illinois BIPA Filed Feb. 5, 2026
Thompson v. SoundHound AI SoundHound (Chipotle) Inbound AI voice agent CIPA §§ 631, 632.7 Filed July 30, 2026

Read together, the through-line is unmistakable: whenever an AI vendor's cloud captures audio from someone who did not personally click "I agree," plaintiffs' firms are finding a wiretap or biometric statute that fits. Bot-based, bot-free, phone-based — the architecture doesn't save you when the audio still leaves the user's device.

The OpenAI Angle: Data Sharing as a Damages Multiplier

One detail from the SoundHound complaint deserves its own paragraph. Plaintiffs allege the call audio wasn't just processed by SoundHound — it was shared with third parties like OpenAI. As the Mondaq analysis emphasizes, the theory is that routing calls through SoundHound's servers for AI training and data sharing with OpenAI constitutes unauthorized eavesdropping, even when customers believe they're speaking directly with the restaurant.

Why the Downstream Sharing Matters

CIPA does not just police the initial interception. It also cares about what happens to the recording afterward — use, disclosure, and retention are each potential violations. Once your voice ends up in a third-party foundation-model training pipeline, it becomes very hard for the vendor to argue the recording was ever "just for order fulfillment." That's the same dynamic that made the training-by-default allegation in the Granola complaint so damaging: once audio is in the model, it can't be extracted.

What About Federal Law? The ECPA Overlay

California is the marquee jurisdiction, but the federal GDPR's Article 5 data-minimization principles and the U.S. Electronic Communications Privacy Act (ECPA) create parallel exposure. ECPA prohibits the intentional interception of wire, oral, or electronic communications and, unlike CIPA, applies nationwide. Cases like Chamberlain v. Granola and In re Otter.AI pair ECPA claims with state statutes precisely to give plaintiffs a fallback if the state-law class fails.

For AI voice agent vendors, the practical implication is that even a Nevada or Texas restaurant chain doesn't escape wiretap risk just by avoiding California. ECPA travels with the call.

Do Restaurants (and Employers) Share the Liability?

Yes — and this is the part most enterprise buyers underestimate. The ConverseNow ruling made clear that businesses using AI voice vendors can face aiding-and-abetting claims. In the meeting-notetaker world, an HR Executive analysis of the AI notetaker litigation wave pointed out that under the federal Wiretap Act, private plaintiffs may seek statutory damages calculated as the greater of a per-day amount or a minimum statutory award — exposure that flows through to the employer that turned the tool on, not just the vendor that built it.

For a restaurant chain, that means every location that piped its published phone number through a third-party AI voice service is a potential co-defendant. For a corporate compliance officer, it means "we bought it from a vendor" is not the shield it used to be — a point we've covered in depth for compliance officers in financial services.

The Consent Design Problem

The lawsuits keep landing on the same design flaw: the AI capture is invisible, and the burden of disclosure is punted downstream. Granola's own website, quoted in the Chamberlain complaint, marketed the tool with the line "other people in the room won't know it's there," per the Barnes & Thornburg analysis of the consent problem. SoundHound's Chipotle deployment has the same architectural signature: the caller has no reasonable way to know that dialing the restaurant's number will put an AI vendor in the middle of the call.

An audible "this call may be recorded" tone at the start of every AI-answered call is necessary — but even that may not be legally sufficient in an all-party-consent state, particularly for § 632.7 recording of cellular calls. The safer design is not routing the audio to a third party at all.

A Decision Framework for AI Voice Deployments

How Basil AI Solves This: On-Device by Architecture

Basil AI is not an AI voice agent for inbound calls — it is a private AI meeting recorder for iOS and Mac. But the reason we exist is exactly the architectural problem SoundHound is now defending. When transcription runs on Apple's on-device Speech framework and the Apple Neural Engine, no vendor server ever receives the audio. There is no third party in the middle to be an "eavesdropper" under CIPA. There is no cloud pipeline to accidentally repurpose the recording as training data. There is no vendor database to subpoena.

That doesn't discharge the user's consent obligations under California, Illinois, or Florida law — those still bind whoever hits "record" — but it eliminates the class of lawsuit that has been the industry's most expensive risk in 2025-2026. For a deeper technical breakdown of the on-device model, see our iOS 26 SpeechAnalyzer explainer. For a side-by-side product comparison across every major cloud AI notetaker, see the Basil AI comparison guide.

Cloud AI Voice vs. On-Device AI: The Liability Delta

Dimension Cloud AI voice/notetaker On-device AI (Basil)
Audio processing locationVendor cloud (US or global)User's iPhone / Mac
Third-party eavesdropper theory (CIPA § 631)Live risk — vendor is a third partyNo third party in the audio path
Recording under CIPA § 632.7Applies to every mobile call capturedUser controls the recording locally
Model training on your audioCommon default; opt-out often opaqueNo cloud, no training pipeline
Subpoena exposure at the vendorVendor holds discoverable recordingsVendor holds nothing
Voiceprints / biometric identifiersGenerated and stored server-side (BIPA risk)Any embeddings stay on-device
Data sharing with OpenAI / third-party modelsAlleged in Thompson v. SoundHoundN/A — no cloud pipeline

What to Do Monday Morning

  1. Inventory every AI system that touches customer or employee audio — phone systems, meeting tools, drive-thru, contact-center bots.
  2. Map the audio path. For each system, answer: does audio leave our infrastructure? Where does it go? Who else touches it? Is it used to train a model?
  3. Update your vendor contracts to require disclosure of subprocessors, training use, retention windows, and deletion SLAs. If a vendor cannot answer these in writing, that's your answer.
  4. Add an audible upfront disclosure to every AI-answered inbound call, and a visible in-meeting disclosure to every AI-transcribed meeting.
  5. For regulated conversations (legal, medical, financial, HR), prefer architectures where the vendor never receives the audio. Read our related coverage on the August 13 Otter ruling on vendor training and on AI notetakers and NDA-covered client work.

The Bottom Line

Every AI recording lawsuit filed in 2025 and 2026 has the same skeleton: a cloud AI vendor captured audio from people who did not personally consent, and a decades-old privacy statute is now the plaintiffs' bar's tool of choice. Thompson v. SoundHound extends the theory from meeting notetakers to inbound phone calls. If your product routes third-party audio through a vendor's servers, you now have to underwrite that risk explicitly — or you have to architect it out. On-device processing is the only architecture that removes the vendor from the audio path entirely, and that is why it will keep winning the compliance conversation.

Try Basil AI — Meeting Transcription That Never Touches the Cloud

100% on-device. 8-hour continuous recording. Apple Notes integration. No vendor server ever receives your audio.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

What is Thompson v. SoundHound AI about?

Filed July 30, 2026 in Alameda County Superior Court, the complaint alleges that when plaintiff Sandra Thompson called a Chipotle location in Oakland, her call was silently rerouted to SoundHound's servers where an AI voice agent — not a Chipotle employee — answered, recorded the conversation, and allegedly shared audio with OpenAI for AI training, all without her consent under California's wiretapping law.

Does CIPA apply to AI voice agents answering business phone lines?

Plaintiffs argue yes. CIPA § 631 prohibits third-party interception of communications in transit without all-party consent, and § 632.7 prohibits recording any cellular or cordless call regardless of confidentiality. If an AI vendor sits between a caller and the business — routing, transcribing, and retaining audio on its own servers — plaintiffs contend the vendor is an unconsented third-party eavesdropper.

Can businesses that deploy AI voice agents be sued too?

Yes. In Taylor v. ConverseNow (N.D. Cal. Aug. 11, 2025), the court allowed CIPA claims against an AI voice-assistant vendor used by Domino's to survive a motion to dismiss, and the ruling flagged potential aiding-and-abetting exposure for the restaurants themselves. Any business routing customer calls to a third-party AI processor faces similar co-defendant risk.

How is this different from Otter, Fireflies, and Granola lawsuits?

The notetaker cases (In re Otter.AI, Cruz v. Fireflies, Chamberlain v. Granola) target AI transcription of virtual meetings under ECPA, CIPA, and BIPA. SoundHound extends the same theory to inbound telephone calls to businesses. All share one root problem: an AI vendor's cloud captures audio from people who never agreed to it — and CIPA § 632.7 lowers the bar by not requiring the call to be 'confidential.'

How does on-device AI transcription avoid this risk entirely?

If speech never leaves the device — no cloud upload, no vendor server, no third-party model training — there is no third-party interception to sue over. That is the architectural bet behind Basil AI: transcription runs on Apple's Speech framework and Neural Engine locally, so recordings, transcripts, and any speaker embeddings stay on the user's iPhone or Mac. Consent still matters, but the vendor-side liability disappears.

What should companies deploying AI phone or meeting AI do Monday morning?

Inventory every AI tool that touches customer or employee audio; map the data path (does audio leave your infrastructure?); require vendors to disclose training use, retention, and subprocessors in writing; add an audible upfront disclosure before any AI-processed call; and, for regulated conversations, prefer on-device architectures where the vendor never receives the audio in the first place.