AI Notetakers in Job Interviews: BIPA Voiceprints, Candidate Consent, and What Recruiters Must Do in 2026
Published September 29, 2026
- Cruz v. Fireflies.AI and BIPA claims in In re Otter.AI Privacy Litigation put voiceprint capture during interviews squarely in the litigation crosshairs.
- Chamberlain v. Granola (filed July 30, 2026) shows bot-free capture is not a legal shield — invisible recording can be the aggravating factor, not the defense.
- Recording consent and biometric consent are separate obligations; interviews often require both under Illinois BIPA and state wiretap laws.
- On-device transcription eliminates the vendor-server copy that most 2026 class actions target, but does not eliminate the recruiter's own consent duty to candidates.
Quick answer: Using cloud AI notetakers in job interviews creates two overlapping legal exposures in 2026: recording-consent violations under statutes like California's CIPA, and biometric-privacy violations under Illinois BIPA when speaker-identification features generate voiceprints. Cruz v. Fireflies.AI and the surviving BIPA claims in In re Otter.AI Privacy Litigation show voiceprint capture without written candidate consent can trigger $1,000–$5,000 per violation.
On August 13, 2026, Judge Eumi K. Lee of the U.S. District Court for the Northern District of California let the core wiretap, California Invasion of Privacy Act, and Illinois Biometric Information Privacy Act claims against Otter.ai proceed toward discovery in In re Otter.AI Privacy Litigation, No. 5:25-cv-06911-EKL. Two weeks earlier, on July 30, 2026, a Florida resident sued the “bot-free” notetaker Granola in the same court over meetings on Zoom and Microsoft Teams. Both cases matter for one specific workflow most talent teams have already normalized: turning on an AI transcription tool during a job interview with an external candidate. This piece explains what recruiters and TA leaders need to change in 2026, and why the biometric layer of these cases — voiceprints created by speaker identification — is the exposure most hiring teams are still missing.
Why interviews are the highest-risk meeting your team runs
Interviews are unlike any other meeting on a recruiter’s calendar. The candidate is an external party who has not agreed to your vendor’s terms of service, is often in a different state (frequently one with all-party consent laws), and is being evaluated on the very speech being captured. SocialTalent’s August 2026 analysis put the risk bluntly: interview recordings carry higher legal exposure than internal meetings because candidates are external, protected characteristics surface naturally in the conversation, and the recording itself can become evidence in a hiring dispute.
The current wave of class actions doesn’t care whether your team was well-intentioned. It cares about consent design — specifically, whether every person on the call affirmatively agreed to be recorded and to have their voice analyzed before any bit of audio was captured. Most hiring workflows fail that test today.
Two lawsuits every talent leader should be able to name
In re Otter.AI Privacy Litigation (consolidated August 2025)
The consolidated Otter litigation alleges that Otter’s AI notetaker joined virtual meetings, transcribed all participants including non-users, retained the content, and used it to improve its models — violating the federal Electronic Communications Privacy Act, California’s CIPA, and Illinois BIPA. On August 13, 2026, the court granted Otter’s motion to dismiss only in part; the National Law Review’s coverage notes the court rejected Otter’s argument that its bot was an authorized meeting participant and let the wiretap, CIPA, and BIPA claims proceed. As Hintze Law’s analysis put it, when a vendor captures, retains, or uses conversation content for its own business purposes, the tool looks less like a passive service provider and more like an independent actor raising wiretap and biometric risk.
Chamberlain v. Granola (filed July 30, 2026)
Runtimewire’s reporting lays out the theory: Granola captures microphone and computer audio locally, without sending a visible bot into the meeting, so participants get no notice the tool is running. According to Tool Directory’s 2026 litigation roundup, plaintiffs’ attorneys pointed to Granola’s own marketing that other participants “won’t know it’s there,” arguing that a bot at least appears in the attendee list, whereas a tool that announces nothing removes the very signal that would prompt someone to object. For a job candidate joining a Zoom interview, that is exactly the scenario: they see the recruiter’s name and nothing else.
Cruz v. Fireflies.AI Corp. (Northern District of Illinois)
The BIPA angle for hiring teams runs through Amundsen Davis’s February 2026 alert on the uptick in BIPA suits against AI notetakers. The complaint in Cruz v. Fireflies.AI Corp. asserts that the software recorded, analyzed, and retained participants’ voices — including non-users — without providing the written notice, informed consent, or transparent retention and destruction policies BIPA requires. The theory: voiceprints derived from speech qualify as biometric identifiers under BIPA’s broad definition.
The BIPA voiceprint problem, in plain English
Most talent leaders think of consent as a single yes/no question about recording. That is not how Illinois works. As WorkSignal’s 2026 hiring-compliance guide explains, a compliant review needs two separate decisions: first, whether the conversation may be recorded, and second, whether the audio becomes protected biometric data because the system identifies a speaker, creates a voiceprint, or verifies identity. Consent, biometric privacy, and AI hiring rules can all apply to the same interview, so a recording approval alone does not clear the workflow.
The processing performed after capture — not the microphone itself — is often the highest-risk component. BIPA treats voiceprints as biometric identifiers in speaker-identification contexts. Before collection, the organization needs informed written notice, a written release, a stated purpose and retention period, and a public retention and destruction policy. Statutory damages under BIPA are $1,000 per negligent violation and $5,000 per intentional or reckless violation, per person and per violation. In a hiring pipeline running hundreds of interviews per quarter, that math scales fast.
Why “the calendar invite said the meeting may be recorded” won’t save you
The tl;dv 2026 litigation summary makes the point directly: knowing what your tool does by default and whether participants can genuinely decline is what matters, not whether a disclaimer appeared in a calendar invite. A generic “this meeting may be recorded” line in a calendar description is not the same as affirmative consent, and it may not satisfy the requirements in California or other all-party consent states.
The design pattern — recording without every participant’s explicit yes — is what the federal court is testing. The tool name on the bot is irrelevant. Whether it is Otter, Fireflies, Granola, or the next well-funded competitor, if the workflow puts audio into a vendor’s system without candidate consent, the exposure attaches.
Cloud AI notetakers vs. on-device transcription for interviews
Here is how the two architectures compare specifically for a hiring workflow. On-device processing removes the vendor-server copy that most current class actions target; it does not remove the recruiter’s consent obligation to the candidate.
| Attribute | Cloud AI Notetakers (Otter, Fireflies, Granola, Zoom AI Companion) | On-Device (Basil AI) |
|---|---|---|
| Where audio is processed | Vendor server | On the interviewer’s Mac or iPhone |
| Vendor copy of candidate’s voice | Yes — sent to and typically retained by vendor | No vendor server holds the recording |
| Voiceprint / speaker embedding location | Vendor infrastructure | Local device only |
| Model-training use by default | Alleged in Otter and Granola complaints; often opt-out buried in settings | None — nothing leaves the device to train anything |
| Subpoena / breach surface | Vendor holds data; discoverable and breachable | No vendor cache to subpoena or breach |
| Bot visible to candidate | Sometimes (Otter, Fireflies); no bot but no notice (Granola) | No bot — recruiter must still obtain and document consent |
| Consent obligation | Still on the recruiter; vendor terms don’t discharge it | Still on the recruiter; architecture makes it easier to honor |
What HR and TA leaders should actually change this quarter
Fisher Phillips’ guidance for businesses spells out a seven-step response to AI notetaker lawsuits, and two of the steps land squarely on hiring: obtain consent from all participants including external parties before using a notetaker, and consider the need to obtain that consent each and every time. For interviews specifically, that means:
- Announce transcription before it starts, and let the candidate genuinely decline. A calendar-invite disclaimer is not affirmative consent.
- Get the biometric release in writing when speaker identification is used. Have your privacy counsel draft the BIPA-compliant notice.
- Set the model-training toggle deliberately. Two of the three 2026 complaints allege meeting content fed model training unless a user found and changed a buried setting.
- Map candidate locations. If the candidate is in California, Illinois, or another all-party consent state, the exposure changes materially.
- Designate conversations that are never captured. Salary negotiations, references discussing protected characteristics, and interviews with candidates who decline are strong candidates.
For lawyers advising internal HR clients, the Illinois Supreme Court Commission’s 2Civility guidance from May 2026 is a useful reference point on the ethical vendor-diligence duty for third-party AI tools — the same posture of a “reasonable assessment” of storage, access, retention, and model-training practices is what a defensible hiring program looks like.
A vendor-evaluation framework for interview transcription tools
Before your talent org standardizes on any AI transcription vendor for interviews, walk procurement through these questions. If a vendor cannot answer them in writing, that is your answer.
- Where is candidate audio processed — on the recruiter’s device, on your servers, or on a third-party model provider’s infrastructure?
- Is a voiceprint or speaker embedding generated? Where is it stored? For how long?
- Is candidate audio ever used to train your models or a subprocessor’s models — by default, ever, or opt-in only?
- What consent workflow does the tool present to non-account-holders (candidates) before capture begins?
- What is the default retention period for transcripts, summaries, and any derived biometric identifiers?
- What does your DPA say about subpoena response and breach notification if a candidate’s audio is exposed?
- Can the workflow satisfy Illinois BIPA’s written-notice, written-release, and public-retention-schedule requirements before any voiceprint is created?
- If a candidate demands deletion, can you actually delete their audio, transcript, and any embeddings derived from them — and can you prove it?
The final question is where cloud vendors typically break down. Once audio has been fed into training pipelines, isolating a specific individual’s contribution is not achievable with current techniques — a point the National Law Review’s Chamberlain analysis flags directly, noting Granola’s own privacy policy acknowledges that data incorporated into models cannot be extracted once training is complete.
How Basil AI solves this for interview workflows
Basil AI is a Mac and iPhone app that transcribes meetings using Apple’s on-device Speech framework. That is an architecture, not a compliance claim: no audio, no transcript, and no derived voice data ever leaves the interviewer’s device to reach a Basil server, because there is no Basil server holding meeting content. Speaker labeling is generated locally; summaries and action items are produced locally; storage lives in the user’s own Apple Notes via their iCloud account, under their control.
What that changes for interviews:
- There is no vendor-server copy of the candidate’s voice to breach, subpoena, or accidentally use for training.
- Any speaker embedding generated for diarization stays on the device and can be deleted with the meeting file itself.
- Because Basil aligns with Apple’s on-device privacy model, the “where does the audio go?” question — the first question in the vendor framework above — has a simple, testable answer.
None of this replaces the recruiter’s own duty to obtain candidate consent, and none of it makes Basil “BIPA compliant” — whether any particular workflow satisfies BIPA, CIPA, or the federal Wiretap Act is your general counsel’s determination, not ours. What on-device architecture does eliminate is the vendor-server surface that is doing most of the plaintiffs’ work in the 2026 cases.
Related reading from Basil AI
For deeper context on the litigation landscape, see our analysis of the enterprise-buyer procurement checklist after the Otter ruling, our breakdown of AI notetakers in termination meetings and employer liability, and our guide to bot-free vs. bot-based notetakers in client-facing meetings.
The bottom line for talent teams
The 2026 lawsuits are not really about AI. They are about consent design, and interviews sit at the exact intersection of every risk factor: external participants, protected characteristics surfacing naturally in conversation, high volume, multi-state candidate pools, and speaker-identification technology that may qualify as biometric. Cloud AI notetakers concentrate that risk on a vendor server that plaintiffs and regulators can reach. On-device transcription moves the audio processing back inside the interviewer’s own device, so the only remaining consent question is the one that always mattered: did you actually ask the candidate before you hit record?
Frequently Asked Questions
Do I need candidate consent to use an AI notetaker in a job interview?
Yes, and in most jurisdictions consent must be affirmative and documented before recording begins. A generic calendar-invite disclaimer is not affirmative consent. In all-party consent states like California and Illinois, every participant — including the candidate — must agree. Your general counsel or employment counsel should draft the specific script and written release your recruiters use before turning on any AI transcription.
Does Illinois BIPA apply to AI notetakers that identify speakers?
Potentially yes. BIPA treats voiceprints as biometric identifiers when used for speaker identification. If an AI notetaker performs speaker diarization or voice-based identification, it may trigger BIPA's requirements for written notice, a signed release, a stated retention schedule, and a public destruction policy — with statutory damages of $1,000 per negligent violation and $5,000 per intentional or reckless violation. Your privacy counsel determines whether a specific tool crosses that line.
Is a bot-free AI notetaker safer for interviews?
Not automatically. Chamberlain v. Granola, filed July 30, 2026, alleges that invisible endpoint capture is actually worse for consent because participants get no signal to object. A candidate joining a Zoom or Teams interview has no way of knowing a bot-free tool is running on the interviewer's laptop. The consent obligation still sits with the person running the meeting.
What damages do AI notetaker wiretap and BIPA claims carry?
Under the federal ECPA, damages are the greater of actual damages, $100 per day of violation, or $10,000. California's CIPA provides $5,000 per violation. Illinois BIPA provides $1,000 for negligent and $5,000 for intentional or reckless violations, per person and per violation. In a hiring pipeline running hundreds of interviews per quarter, per-violation math scales quickly.
How does on-device transcription change the exposure?
On-device processing keeps the audio and any speaker embeddings on the interviewer's own device — no vendor server holds a copy to breach, subpoena, or use for model training. It does not eliminate the recruiter's consent obligation to the candidate, but it removes the vendor-server surface that most of the current class actions target. Your general counsel still decides whether the workflow satisfies BIPA and applicable state wiretap law.
Can we just skip the AI notetaker for interviews?
That is one defensible answer. Fisher Phillips and other employment firms have advised organizations to designate specific conversations that are never captured. Interviews with external candidates — especially candidates dialing in from all-party consent states or Illinois — are the highest-risk category. If your team decides transcription is essential, pair explicit written consent with a tool architecture your privacy counsel has actually reviewed.