AI Notetakers for Wealth Managers After the Otter Ruling: Why RIAs Are Rethinking Client-Meeting Capture in 2026

Published October 01, 2026

Key takeaways

Quick answer: After a federal judge let wiretap, CIPA, and BIPA claims against Otter.ai proceed on August 13, 2026, every wealth manager running a cloud AI notetaker in client meetings now carries documented consent risk. The safer architecture for RIAs is on-device transcription that never sends client audio to a vendor server, paired with explicit all-party disclosure and firm-controlled retention.

Published October 1, 2026 · 11 min read

On August 13, 2026, Judge Eumi K. Lee of the U.S. District Court for the Northern District of California granted Otter.ai's motion to dismiss only in part in In re Otter.AI Privacy Litigation (Case No. 5:25-cv-06911-EKL) — allowing the federal Wiretap Act claim, the California Invasion of Privacy Act (CIPA) claim, and both Illinois Biometric Information Privacy Act (BIPA) claims to proceed into discovery. According to RecordingLaw's analysis of the order, Judge Lee held that the plaintiffs plausibly alleged Otter acts as a third-party eavesdropper rather than a mere tool of the meeting host. For every registered investment advisor, broker-dealer, and wealth management firm that has quietly let an AI notetaker ride along into client meetings, that single sentence changed the risk calculus.

If your advisors are capturing portfolio reviews, estate conversations, or trust discussions through Otter, Fireflies, Granola, or any cloud notetaker that retains audio, this piece explains what the ruling actually says, why wealth managers are a particularly exposed ICP, and how an on-device architecture — where the audio literally never leaves the advisor's Mac or iPhone — shrinks the attack surface to something your CCO can defend.

Why Wealth Managers Became the New Target

Three facts collided this summer. First, AI notetaker adoption inside RIAs went from novelty to default: panelists at RIA Edge Los Angeles reported that advisors in the audience were already using AI note-taking to help run and follow up on client meetings. Second, the plaintiffs' bar found a federal theory that works: the Electronic Communications Privacy Act / Wiretap Act, paired with state all-party-consent statutes. Third, the Wealth Solutions Report did the math and published a direct warning on September 3, 2026: the AI notetaker in your client meetings is not a passive tool — it is a third party recording conversations that may include people who never agreed to be recorded.

Advisors sit in a bad spot on that Venn diagram. Nearly every client call involves at least one non-advisor (spouse, trustee, CPA, attorney) who did not accept the vendor's terms of service. The conversations touch material nonpublic information, estate planning, and health-adjacent facts that drive risk-tolerance analysis. And the SEC's recordkeeping rules make the resulting transcript a durable artifact that will be produced in any future enforcement or arbitration proceeding.

What the Otter Ruling Actually Held

The complaint, originally four separate class actions consolidated before Judge Lee in October 2025, alleged that OtterPilot joined Zoom, Microsoft Teams, and Google Meet calls and recorded, transcribed, and retained conversations without the consent of every participant, and that those recordings were used to improve Otter's systems. Tool Directory's case tracker reports that Judge Lee dismissed the computer-intrusion claims with leave to amend, but allowed the Wiretap Act, CIPA, and Illinois biometric claims to move into discovery.

The analytical move that matters for wealth managers: Otter raised the Wiretap Act's "party exception," which permits a party to a communication to record it. The court held that the exception can fall away at the pleading stage because the plaintiffs allege Otter "tortiously used their conversational data without their knowledge or consent to train its machine learning systems." In other words, when a vendor's commercial use of the recording goes beyond serving the host, the vendor stops looking like a tool and starts looking like a separate interceptor — one who needed its own consent.

The Granola Companion Case: Bot-Free Isn't a Shield

Eleven days before the Otter ruling, on July 30, 2026, Tarra Chamberlain filed Chamberlain v. Granola, Inc. (Case No. 3:26-cv-07926) in the same court. According to reporting by Marketing Helm, the seven-claim complaint alleges Granola captures audio from the user's microphone and the system audio output — picking up everyone else on the call — and uses what it captures to train AI models by default. The twist: Granola markets itself as bot-free. The complaint turns that marketing against the company, pointing to website copy promising other participants "won't know it's there."

For wealth managers who assumed moving to an invisible, device-side tool solved the consent problem, the Chamberlain complaint is sobering. Voibe's analysis of the Granola lawsuit describes it as the cleanest no-notice theory of the three major cases — "no bot, no notification, and — per its own marketing — sells that absence as the product's defining feature." The lesson for an RIA: the question isn't whether a bot joins the call. The question is where the audio goes next.

Cloud Notetakers vs. On-Device Transcription for RIA Client Meetings

Here is how the two architectures actually differ on the dimensions that drive wealth-management liability.

Dimension Cloud notetakers (Otter, Fireflies, Granola, Zoom AI Companion) On-device transcription (Basil AI)
Where client audio is processed Vendor servers in the U.S. (or chosen region) Advisor's Mac or iPhone, via Apple Speech Recognition
Third-party interception theory applies? Yes — the pleading survived in In re Otter.AI No vendor server receives audio; no interception to allege
Model training on client audio Often on by default (central Granola allegation) Not possible — audio never leaves the device
Voiceprint / BIPA exposure Live claim in Cruz v. Fireflies and In re Otter.AI No biometric extraction or storage
Subpoena / discovery surface Vendor can be served; copies of client audio exist off-firm Only firm-held transcripts; no vendor copy to produce
Offline capture (plane, lodge, retreat) Degrades or fails without connectivity Full capability offline
Who holds consent responsibility Vendor TOS pushes it to the account holder Advisor obtains consent directly, as with any voice memo

State Wiretap Exposure: The Twelve That Matter

Federal law under 18 U.S.C. § 2511 permits one-party consent. State law is where RIAs get hurt. Mayer Brown's June 2026 analysis identifies the all-party-consent jurisdictions as California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Pennsylvania, and Washington. CIPA warrants particular attention because of the sheer volume of demand letters it has generated and because Cal. Penal Code § 631(a) separately prohibits unauthorized third parties from "reading, attempting to read, or learning the contents" of communications without consent.

The jurisdictional math gets worse when you consider that a single California-resident client dialing into a call from Palo Alto can pull CIPA onto a meeting hosted from Dallas. For a national RIA practice, this means the strictest state's rule effectively becomes your firm's floor. For deeper background on the state matrix, see our 2026 compliance guide to two-party consent states.

What SEC Recordkeeping Actually Requires

There is a persistent myth in the advisor community that FINRA or the SEC demands recording. They do not. What they demand is a record. Rule 204-2 of the Investment Advisers Act requires RIAs to retain records related to advice given, fund movements, and order execution for five years, with the first two years in an easily accessible location. An on-device transcript, exported to the firm's archive, satisfies the recordkeeping input just as well as a cloud transcript does — without creating a second copy on a vendor server that discovery counsel can subpoena.

For broker-dealer context, our earlier piece on FINRA's 2026 GenAI guidance and broker-dealer recordkeeping walks through the same analysis from the securities-industry angle. The core framing — the architecture is a fact, the compliance determination belongs to your CCO — is identical.

The Vicarious-Liability Problem: Firms in the Chain

Bloomberg Law's analysis of the AI-notetaking wiretap wave notes a specific worry for enterprise buyers: a vendor with data-mining rights can expose a customer company to vicarious liability for the vendor's CIPA violations. Littler Mendelson's employer guidance reaches the same conclusion from the labor-and-employment side: wiretap laws present the greatest risk for U.S. employers using AI note-taking technologies.

For a wealth manager, the practical effect is that the firm-issued Google Workspace account connecting OtterPilot to the calendar is almost always a company asset. The hostie — the person who turned the bot on — is almost always an employee acting in the scope of employment. HR Executive called the Otter class action a lawsuit every HR leader should have on their radar precisely because the consent, privacy, and employer-liability questions it raises have not been answered by most firms' policies.

How Basil AI Solves This for Wealth Managers

Basil AI is an on-device AI transcription app for iPhone and Mac. The architectural fact that matters for an RIA practice is simple: audio captured by Basil is transcribed on the Apple Neural Engine using Apple's Speech framework, locally, in real time. No audio file is uploaded to a Basil server. No transcript is uploaded to a Basil server. No voiceprint is extracted and stored on a Basil server. There is no Basil server in the audio path.

For each of the live legal theories in the current litigation wave, the on-device design changes the pleading story. The In re Otter.AI Wiretap Act theory requires alleging that a third party intercepted the communication — there is no third-party processor to allege. The Granola / Chamberlain theory requires alleging that captured content is used to train vendor models by default — there is no training signal flowing anywhere. The BIPA theory in Illinois requires alleging biometric extraction and storage without written consent — no voiceprint is extracted or stored by Basil. For the broader architectural pattern, see our deep dive on AI meeting notes for compliance officers in financial services.

None of that is a compliance claim. On-device processing is an architecture fact; whether your use of any tool satisfies CIPA, BIPA, Rule 204-2, FINRA 3110, or your firm's own written supervisory procedures remains your Chief Compliance Officer's determination. What on-device architecture does is remove the vendor-server attack surface from the pleadings. That is a smaller attack surface to defend.

A Buyer's Checklist for RIAs Evaluating AI Notetakers

Bring these questions to any AI-notetaker procurement conversation. If the vendor cannot answer them in writing, that is itself the answer.

  1. Where is client audio processed? On the advisor's device, or on your servers? If your servers, in which jurisdiction?
  2. Do you train models on captured meeting content? By default? Only on opt-in? Is the opt-in setting advisor-level or firm-level?
  3. Do you extract or store voiceprints or any biometric identifier? If yes, do you have a written retention and destruction policy that meets BIPA § 15(a)?
  4. What is your audio-retention timeline, and can we set it to zero?
  5. Who holds responsibility for obtaining all-party consent under your TOS? Vendor or deploying firm?
  6. Can you produce a current SOC 2 Type II report, your sub-processor list, and your DPA?
  7. If a client's attorney subpoenas you for audio, what will you produce?
  8. What is your incident-notification SLA for a tenant-isolation or data-exposure event? (The tl;dv Firestore disclosure is a cautionary pattern here.)

A Practical Transition Plan for an RIA Practice

If you are an advisor or an operations lead at an RIA, here is a defensible 30-day path.

Week 1 — Inventory. List every AI notetaker any advisor has connected to a firm calendar or video account. Include Otter, Fireflies, Granola, Zoom AI Companion, Microsoft Copilot, Fathom, Jump, Zocks. You cannot govern what you have not inventoried.

Week 2 — Policy. Update your written supervisory procedures to require (a) explicit verbal all-party consent at the start of every recorded client call, (b) a prohibition on tools that train on client content by default, and (c) a prohibition on bot-based tools in meetings that include California, Illinois, or Pennsylvania participants unless disclosure is given on-screen and verbally.

Week 3 — Pilot. Stand up on-device transcription on two advisors' devices. Capture the client meeting locally. Export the transcript into the firm's existing archive system. Measure the actual workflow friction.

Week 4 — Decide. Keep what works, retire what doesn't. Document the decision in a CCO memo so that if a future enforcement examiner asks why the firm made the choice, there is a contemporaneous record.

Where This Is Heading

The Otter case is still at the pleading stage. The Granola case is at the pleading stage. Fireflies is at the pleading stage. None of these allegations has been proven. But as one practitioner analysis put it, the three questions that matter now for anyone using a notetaker at work are: who else gets commercial use of the audio, who does your vendor say is responsible for participant consent, and can the vendor actually delete your data once it has been baked into a model.

For wealth managers, those three questions have a straightforward architectural answer: pick a tool where the audio never left the device in the first place. The litigation then becomes somebody else's problem.

Private AI Meeting Notes for Advisors — No Cloud, No Vendor Server, No Bot

Basil AI runs 100% on your Mac or iPhone. Client audio never touches our servers because we don't have any in the audio path. Try it on your next client meeting.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

Can RIAs legally use AI notetakers like Otter or Fireflies in client meetings?

Yes, but with real exposure. Federal law allows one-party consent, yet 12 states — including California, Florida, Illinois, Massachusetts, and Pennsylvania — require all-party consent. The August 13, 2026 Otter ruling means a cloud notetaker can be treated as a third-party eavesdropper, not just a tool, which puts the deploying firm in the chain of liability alongside the vendor.

Does FINRA or the SEC require consent before recording a client meeting?

Neither agency sets a universal recording-consent rule, but Rule 204-2 of the Investment Advisers Act requires RIAs to retain records tied to advice and transactions for five years. State wiretap statutes govern the consent itself. Fiduciary duty and the SEC's marketing/communications rules make undisclosed recording a reputational and regulatory risk even where it is technically legal.

What is the fastest way to reduce AI-notetaker wiretap risk in client meetings?

Three steps: (1) stop using tools where a vendor retains client audio or trains on it; (2) obtain explicit verbal all-party consent on every call and log it; (3) move capture to an on-device transcription tool so the audio never leaves the advisor's Mac or iPhone. Your CCO decides the policy, but the architecture choice shrinks the attack surface.

Is on-device AI transcription compatible with SEC and FINRA recordkeeping?

On-device transcription produces a text transcript and summary the advisor can export, timestamp, and archive into the firm's books-and-records system — exactly as they would any other client-meeting note. The architectural fact is that no vendor server holds the audio; the compliance determination of whether the resulting record satisfies Rule 204-2 or FINRA 3110 remains with your CCO.

Are wealth management firms being named in AI notetaker lawsuits?

Not yet in the four lead cases — Otter, Fireflies, Granola, and the tl;dv matter — but attorneys writing for Bloomberg Law and HR Executive have flagged that calendar integrations and firm-issued accounts put the deploying organization in the chain. Wealth Solutions Report called the August 13 ruling a direct liability event for wealth managers.

What should a wealth management vendor-diligence checklist for AI notetakers cover?

At minimum: where audio is processed (device vs. vendor cloud), whether the vendor trains on meeting content, data-retention and deletion timelines, sub-processor list, DPA terms, SOC 2 report, incident-notification windows, state-wiretap disclosures, voiceprint/biometric handling under BIPA, and whether the vendor accepts contractual responsibility for participant consent or pushes it onto the advisor.