After the Otter Ruling: What Enterprise Buyers of AI Notetakers Must Change Now
Published September 16, 2026
- Judge Lee's August 13, 2026 order in In re Otter.AI Privacy Litigation (No. 5:25-cv-06911-EKL) let the federal Wiretap Act, CIPA §631, and Illinois BIPA voiceprint claims proceed — the theories most likely to reshape enterprise procurement.
- The court found it plausible that an AI notetaker acts as a third-party eavesdropper, not just a tool of the consenting host — undercutting the single-host-consent defense many enterprises have relied on.
- Chamberlain v. Granola (filed July 30, 2026) extends the same theory to 'bot-free' notetakers, so switching from a visible bot to invisible capture does not, by itself, resolve consent exposure.
- For sensitive meetings, procurement teams should require written all-party consent, a documented voiceprint policy, training opt-out by default, and — where feasible — an on-device architecture where audio never reaches a vendor server.
Quick answer: On August 13, 2026, a federal judge let the core wiretap, CIPA, and Illinois BIPA voiceprint claims against Otter.ai proceed to discovery. For enterprise buyers, that means single-host consent is no longer a defensible procurement assumption — you need written all-party consent flows, a BIPA-grade voiceprint policy, training-data opt-outs, and, for sensitive meetings, an on-device architecture that never sends audio to a vendor server.
On August 13, 2026, a federal judge in the Northern District of California decided that the core privacy claims against Otter.ai are strong enough to proceed to discovery. The order does not decide whether Otter broke the law. It does decide something arguably more consequential for every enterprise using an AI notetaker in 2026: the theory that a transcription bot is a third-party eavesdropper — not just a tool of the meeting host — is plausible enough to survive a motion to dismiss. That single legal characterization now sits underneath every AI-notetaker procurement decision, and if your current risk model is "the host consented, we're fine," it needs a rewrite this quarter.
What Judge Lee actually decided on August 13
The case is In re Otter.AI Privacy Litigation, No. 5:25-cv-06911-EKL — four class actions filed in August and September 2025 that were consolidated before Judge Eumi K. Lee in October 2025. According to UC Today's coverage of the order, Judge Lee granted Otter's motion to dismiss in part on August 13, but allowed the central claims under federal wiretap law, California privacy law, and Illinois biometric privacy law to move forward.
The specific breakdown, per Recording Law's tracker: the federal Wiretap Act claim, the California Invasion of Privacy Act §631 claim, both Illinois BIPA voiceprint claims, unjust enrichment, and the California Unfair Competition Law claim all survive. Both counts under the Computer Fraud and Abuse Act, the CDAFA claim, the Washington Privacy Act claim, and most intrusion-upon-seclusion claims were dismissed with leave to amend.
The framing in Tool Directory's litigation summary is the one to internalize: the court was unpersuaded that a notetaker is like hacking a computer, but persuaded, at the pleading stage, that a notetaker might be like a stranger listening to a call. Discovery now runs on that question — and the answers Otter has to provide about consent flows, speaker-identification, retention, and training will become the template every other vendor is measured against.
Why this is a procurement problem, not just a vendor problem
The most important consequence of the ruling is not what happens to Otter. It is what happens to the enterprises that deployed Otter, Fireflies, Granola, or any of a dozen similar tools. Jennifer Ruehr at Hintze Law argues that companies should now assess these technologies as communications-capture tools with privacy and wiretap risks — the same category as call recorders, not the same category as productivity software.
The reason is procedural. In most all-party-consent states, the obligation to obtain consent from every participant sits with the person running the meeting — not the vendor. Your employees are the people running the meeting. Which means the exposure your vendor is now defending in court is, in practical terms, your exposure the next time a plaintiff sues over a recording your team made.
The single-host-consent defense is now legally contested
For years, enterprise procurement leaned on a simple story: our employee turned on the bot, our employee is a party to the conversation, so the recording is lawful. Layer3 Labs' analysis of the Otter case reframes that same story as the exact question the case turns on: is an AI transcription service a neutral tool of the person who invited it, or a separate third party secretly listening in? If the service is just a tool, the user's consent can satisfy federal law. If the service is a separate eavesdropper, its own listening can violate wiretap statutes no matter what the user agreed to.
Judge Lee's August 13 order does not resolve that question. It says the second reading is plausible enough to go to a jury. For procurement, "plausible enough to go to a jury" is the moment you rewrite the consent language in your meeting SOP.
The Granola case: bot-free is not automatically consent-safe
Some vendors are pitching a fix: build a notetaker that does not send a visible bot into the call. On July 30, 2026, that fix hit its own lawsuit. Holland & Knight's analysis of Chamberlain v. Granola, Inc., No. 3:26-cv-07926 (N.D. Cal.), describes a Florida plaintiff alleging Granola's AI notetaking application secretly intercepted her Microsoft Teams and Zoom communications without her knowledge or consent. The complaint highlights Granola's own marketing copy — that "Other people in the room won't know it's there" — as evidence the invisibility was designed rather than incidental.
According to PPC Land's reporting on the complaint, the theory advances a novel class against a non-party to the communication: the plaintiff never used Granola or agreed to its terms but was on a call where Granola was running. The claims include the federal Electronic Communications Privacy Act, the California Invasion of Privacy Act, California's computer-access statute, and common-law invasion of privacy.
The takeaway for buyers is uncomfortable: switching from a visible bot to invisible capture does not solve the underlying consent question — and if the vendor uses the captured audio to train its models by default, as Mondaq's summary of the complaint alleges Granola does, the exposure gets worse, not better.
The BIPA voiceprint problem is separate and cumulative
Even in a world where wiretap statutes ultimately land in vendors' favor, the biometric-privacy theory sits in a different circuit and does not depend on the same consent analysis. As the American Bar Association's biometric-privacy roundup explains, BIPA lets plaintiffs argue they never consented to the collection or use of their voiceprints, and the May 2026 wave of coordinated BIPA class actions against Meta, Google, Apple, and NVIDIA shows how aggressively that theory is being pushed against AI voice systems.
Speaker diarization — the feature that labels who said what — is exactly what plaintiffs frame as biometric-identifier collection. In the Otter litigation, per the same Recording Law summary, both Illinois BIPA voiceprint claims survived the motion to dismiss. That matters because BIPA carries statutory damages per violation and, under a 2024 amendment that the Seventh Circuit ruled applies retroactively in Clay v. Union Pacific Railroad Co., per-violation damages calculations are still very much a live question for pending cases.
A single all-hands or applicant interview processed through a diarization pipeline can generate dozens of voiceprints. If the vendor has not obtained a written release from each person whose voice is captured — the standard BIPA §15(b) demands — every one of those voiceprints is a potential separate statutory violation.
Cloud AI notetakers vs. on-device: the architectural comparison
Architecture is the variable that changes what discovery in cases like Otter can actually reach. If audio never leaves the participant's device, there is no vendor-side recording repository to subpoena, no training pipeline to enjoin, and no voiceprint database to certify a class around. Compare the two models:
| Dimension | Cloud AI Notetaker (Otter / Fireflies / Granola) | On-Device Notetaker (Basil AI) |
|---|---|---|
| Audio processing location | Uploaded to vendor servers for transcription and summarization | Processed locally via Apple Speech Recognition on the participant's device |
| Vendor-side recording repository | Yes — subject to subpoena and discovery | No — vendor has no copy to produce |
| Voiceprint / speaker-ID storage | Speaker diarization performed and often retained server-side; BIPA-exposed | Speaker labeling stays on device; no vendor voiceprint database |
| Training on customer content | Often opt-out by default (contested in Otter and Granola complaints) | Not applicable — no vendor pipeline receives the audio |
| All-party consent burden | Sits with meeting host; single-host defense now contested | Sits with meeting host; still needed, but attack surface is dramatically smaller |
| Third-party sharing of transcripts | See each vendor's DPA and privacy policy | Zero — content never reaches Basil's servers |
This is not a claim that on-device architecture makes an organization "compliant." Compliance is a determination your general counsel and CCO make against your specific regulatory footprint. It is a claim that on-device processing removes the vendor as a factual actor in the recording — which is the exact factual predicate the Otter and Granola complaints attack.
The new AI notetaker procurement checklist
Given the August 13 ruling and the Granola filing, five questions should be the minimum for any AI-notetaker renewal or new deployment:
1. Where is audio processed, and where is it stored?
You want a specific answer, not a marketing answer. If audio is uploaded to a vendor cloud — even briefly — the vendor becomes a party in the fact pattern plaintiffs are pursuing. Ask for a data-flow diagram.
2. Are voiceprints or speaker embeddings created, and where are they stored?
Any product that labels speakers is doing something with voice characteristics. Confirm in writing whether those characteristics are retained, whether they are used across meetings or accounts, and whether the vendor has a BIPA §15(a) retention-and-destruction schedule.
3. Is training on customer content opt-in, opt-out, or unavailable?
The Granola complaint centers on training-by-default. Confirm the current default, whether it applies at the meeting level or account level, and whether a non-user participant has any way to opt out at all.
4. What is the retention schedule, and can we set it to zero?
Retention is the multiplier on every other risk. As tl;dv's 2026 privacy overview puts it, unlimited retention feels convenient, but the longer data exists, the greater the chance it will be accessed, misused, or breached.
5. Is there a signed DPA and, where relevant, a signed BAA?
For any meeting that could touch protected health information, HHS's business-associate-agreement guidance is unambiguous: covered entities need a BAA with any vendor that creates, receives, maintains, or transmits PHI. No BAA, no PHI touching the tool. For EU personal data, the same holds for GDPR Article 28 processor obligations.
What consent notice should actually look like now
The safest posture, and the one plaintiffs' counsel will have the hardest time attacking, is written, on-the-record, all-party consent — not a spoken announcement, not a calendar-invite footer. In two-party-consent states, that means a visible banner or an explicit verbal acknowledgment logged in the transcript before capture begins. For biometric statutes, spoken consent is not enough; BIPA §15(b) requires written notice and a written release before a voiceprint is extracted.
For a step-by-step breakdown of what jurisdictional consent flows look like in practice, see our two-party-consent state compliance guide and the deeper analysis of the Chamberlain v. Granola complaint.
The employer-liability angle: transcripts as evidence
The Otter ruling did not land in a vacuum. One day earlier, on August 12, 2026, a Fireflies transcript became the centerpiece of a gender-discrimination suit against Marathon Engineering. According to reporting summarized by Zvi Melkman's analysis of the two 24-hour events, a terminated employee left the call, her supervisors stayed on, and the AI notetaker captured what they said next — comments that became the core of the pleading. That is the second-order risk of unconsented recording: your own transcript becomes discoverable evidence against you.
Our earlier write-up on the Marathon case walks through the employment-law implications in detail — see the Marathon Engineering employer-liability analysis.
How Basil AI solves this at the architectural level
Basil AI is a fully on-device AI notetaker for iPhone, iPad, and Mac. Every second of audio is transcribed locally using Apple's on-device Speech Recognition framework and stored only on the participant's device. There is no Basil server holding the recording. There is no Basil training pipeline receiving the audio. There is no Basil voiceprint database. Apple's public position on on-device processing is the same architectural fact from the platform side.
Concretely, in the fact pattern the Otter complaint attacks:
- No third-party interception theory to argue. Basil is not a participant on the call; it is a local recorder on the device of a person who is already a party to the conversation.
- No vendor-side recording to subpoena. The audio and transcript never leave the device unless the user chooses to export them (typically to Apple Notes via iCloud, under Apple's encryption).
- No voiceprint database at the vendor. Speaker labeling happens locally and is not stored in any Basil-controlled database that a BIPA claim could target.
- No training-on-customer-content default. There is no pipeline that could be turned on or off — the audio does not reach us.
None of this makes the meeting host's consent obligation disappear. Consent still sits with the person recording, in every jurisdiction. But the architecture removes the vendor from the fact pattern that plaintiffs' firms are currently attacking, which is exactly the surface area a modern procurement review is trying to shrink. For more on the technical approach, see our deep dive on voiceprint harvesting and the BIPA lawsuit wave.
The bottom line for enterprise buyers
The August 13, 2026 ruling did not end the Otter litigation, and it did not decide the wiretap question on the merits. It did move the ball far enough down the field that every enterprise still relying on single-host-consent language in its meeting SOP is out of step with the current record. Combined with Chamberlain v. Granola's attack on bot-free capture and the ongoing BIPA voiceprint theories, the direction of the case law is clear: the vendor-controlled cloud pipeline is where the exposure lives, and the way to shrink it is to move the pipeline off the vendor.
Your CCO decides the acceptable risk level. Your GC decides the consent language. Your procurement team decides which vendors clear the bar. The one decision that is no longer defensible is doing nothing until a court issues a merits ruling — because by then, the discovery in cases like Otter will have already produced the internal documents plaintiffs need to run the playbook against the next vendor in line.
Frequently Asked Questions
What did Judge Lee's August 13, 2026 order actually decide in the Otter case?
Judge Eumi K. Lee granted Otter.ai's motion to dismiss only in part. The federal Wiretap Act, California Invasion of Privacy Act §631, both Illinois BIPA voiceprint claims, unjust enrichment, and California's Unfair Competition Law claims all survived. Claims under the Computer Fraud and Abuse Act, California's CDAFA, and the Washington Privacy Act were dismissed, mostly with leave to amend. It is a pleading-stage ruling, not a finding of liability.
Does the ruling mean Otter.ai broke the law?
No. The August 13 order only decides that the plaintiffs pleaded enough facts for the core claims to proceed to discovery. It accepts the complaint's allegations as true for that limited purpose and makes no finding on the merits. Otter denies unlawful interception, and no class has yet been certified. Your general counsel decides how much weight to give a pleading-stage survival in your own risk model.
Can we still rely on 'the meeting host consented' as our compliance story?
That single-host-consent theory is exactly what the surviving claims attack. The court found it plausible that Otter acted as a third-party eavesdropper, not merely a tool of the host, meaning host consent alone may not cover other participants under the federal Wiretap Act or state all-party-consent statutes like CIPA. In all-party-consent states, your CCO should require written, on-the-record consent from every participant.
How does the Chamberlain v. Granola lawsuit change the bot-free calculus?
Chamberlain v. Granola, filed July 30, 2026, targets a 'bot-free' notetaker that captures audio invisibly on the user's device. The complaint argues invisibility itself is the wiretap problem because other participants have no notice. Bot-free architecture does not automatically solve consent — what matters is whether audio ever leaves participants' devices for vendor training and whether every participant is given notice.
What should we ask vendors before renewing an AI notetaker contract?
Ask five things: where audio is processed (device vs. vendor cloud), whether voiceprints are generated by speaker-diarization features, whether training on customer data is opt-in or opt-out, retention duration, and whether a signed BAA and DPA are available. Your procurement team decides which of these are dealbreakers based on your jurisdictional and industry exposure.
Are on-device notetakers exempt from these lawsuits?
No architecture is automatically exempt — consent obligations sit with the meeting host, not the vendor. But an architecture where audio is captured and transcribed locally on a participant's device, with no vendor server holding the recording and no vendor training pipeline, materially shrinks the surface plaintiffs' firms attack in Otter, Fireflies, and Granola. Your GC determines whether that architectural fact is a sufficient control for your risk profile.