SB 690 Signed, But AI Notetakers Still Face CIPA Wiretap Lawsuits: What the Carve-Out Actually Changes

Published October 05, 2026

Key takeaways

Quick answer: No. California's SB 690, signed by Governor Newsom on September 30, 2026, only eliminates private lawsuits under CIPA Section 638.51 (the pen-register/trap-and-trace provision used against website tracking pixels). It leaves Sections 631 (wiretapping) and 632 (recording confidential communications) fully intact — the exact provisions driving the Otter.ai and Chamberlain v. Granola class actions over AI meeting recording.

Published October 5, 2026 · 10 min read

On September 30, 2026, California Governor Gavin Newsom signed Senate Bill 690 into law, eliminating private claims under the California Invasion of Privacy Act's pen-register and trap-and-trace provision. Within hours, a wave of LinkedIn posts and vendor blog updates declared the website-tracking litigation era over — and some AI meeting notetaker vendors quietly implied the ruling was good news for them, too. It isn't. SB 690 does not touch the statutes being used against Otter.ai, Granola, or any other AI meeting recorder. If your compliance team is reading SB 690 as cover for cloud-based AI notetakers, you're reading the wrong section of the bill.

What SB 690 Actually Does

SB 690 is a narrowly drafted statute. According to the official summary from Procopio, Newsom's September 30 signing "eliminat[es] private standing for alleged violations of the California Invasion of Privacy Act's pen-register and trap-and-trace provisions while preserving enforcement authority for the California Attorney General." The legislation also provides for two-year retroactive application to qualifying pending claims.

The bill was chaptered as Chapter 976, Statutes of 2026 on September 30, 2026, and becomes operative January 1, 2027. In other words: it addresses one specific provision — California Penal Code § 638.51 — and transfers private enforcement to the state Attorney General.

What SB 690 Does Not Do

Here is the sentence that matters for every executive, lawyer, and compliance officer evaluating AI meeting tools after October 1. From Fenwick's analysis: the bill "does not amend CIPA's traditional wiretapping and eavesdropping provisions, §§ 631 and 632, which remain fully available to private plaintiffs."

Earlier versions of SB 690 would have gone much further. As Baker Donelson documented, the original 2025 draft "would have exempted from CIPA any processing of personal information undertaken for a defined 'commercial business purpose,' removing routine online business activity from the ambit of the statute altogether." That version was abandoned by Assembly amendments on July 2, 2026. The enacted version is dramatically narrower.

Translation: the broad vendor-friendly exemption that would have swept in audio processing is dead. What survives covers only one category of claim — the website pixel/analytics theory — and only one Penal Code section.

Why This Matters for AI Notetakers

Every active class action against an AI meeting notetaker right now is built on CIPA §§ 631 and 632, plus federal ECPA, plus (in Illinois cases) BIPA. None of these claims arise under § 638.51. SB 690 is irrelevant to all of them.

Consider the two headline cases:

In re Otter.AI Privacy Litigation (N.D. Cal., Case No. 5:25-cv-06911). On August 13, 2026, Judge Eumi K. Lee refused to dismiss the central privacy claims. As VoIP Review reported, the ruling "lets claims proceed under federal wiretap law, California privacy law, and Illinois biometric law" after the court found plaintiffs plausibly alleged independent data use by Otter — "using conversations to improve products and machine-learning models."

Chamberlain v. Granola (N.D. Cal., Case No. 3:26-cv-07926-EMC), filed July 30, 2026. According to Computerworld's coverage, Florida plaintiff Tarra Chamberlain alleges Granola "'purposefully' designed its app to record calls without requiring disclosure to all participants" in violation of CIPA's all-party consent rule. The complaint, detailed in Barnes & Thornburg's analysis, raises claims under common-law intrusion upon seclusion, ECPA, CIPA § 631, and CIPA § 632 — not § 638.51.

The Statutes SB 690 Left Alone

CIPA § 631 — The Wiretapping Statute

Section 631 prohibits any party from using any "instrument or contrivance" to intentionally tap into, or read, any communication in transit without consent of all parties. In Judge Lee's August 13, 2026 Otter ruling, the court held that "Plaintiffs plausibly allege that Otter independently collects, retains, and uses communications for its own commercial purposes," sufficient to allege Otter is "a third-party eavesdropper under section 631," as covered by The Little Binger's case roundup. That interpretation is now the operative federal-court framing of § 631 as applied to AI notetakers — and SB 690 did nothing to disturb it.

CIPA § 632 — Recording Confidential Communications

Section 632 is the all-party consent recording statute. It is the single most dangerous provision for any AI meeting tool that records audio without obtaining consent from every participant. The PPC.land briefing on the IAB's October 1, 2026 litigation paper flagged a parallel action — "Granola sued for recording meetings without consent to train AI models — An AI notetaker case under the CIPA provisions SB 690 leaves intact." The industry's own litigation trackers now explicitly separate the SB 690-covered pixel cases from the § 631/632 recording cases.

Statutory Damages Haven't Moved

Under Penal Code § 637.2, a prevailing CIPA plaintiff can recover $5,000 per violation or three times actual damages, whichever is greater. In a class with thousands of recorded meeting participants across years of enterprise deployment, that math is what makes these cases viable — and SB 690 did not touch § 637.2 damages for § 631 or § 632 claims.

SB 690 vs. The AI Notetaker Litigation Wave: A Reality Check

CIPA Provision What It Covers Changed by SB 690? AI Notetaker Exposure
§ 631 (Wiretapping) Interception of communication in transit by a "third party" No — fully intact Core theory in Otter and Granola suits
§ 632 (Confidential Recording) Recording confidential communications without all-party consent No — fully intact Core theory in Chamberlain v. Granola
§ 637.2 (Statutory Damages) $5,000 per violation or 3x actual damages No — fully intact Primary class-wide exposure driver
§ 638.51 (Pen-Register/Trap-and-Trace) Devices capturing dialing/routing/addressing data Yes — private right of action eliminated Not used in AI notetaker suits

Every row that touches audio recording is unchanged. The one row that changed is for website tracking pixels. That is the beginning and the end of SB 690's effect on the AI meeting tool category.

Why Vendors Would Want You to Misread SB 690

A cloud-based AI notetaker business model depends on vendor servers receiving, storing, and (in many cases) training on meeting audio. That architecture is exactly what Judge Lee's Otter ruling calls a plausible § 631 interception. If a vendor can convince its enterprise customers that "California just fixed CIPA," it buys another sales cycle before procurement realizes the exposure is still $5,000 per participant per meeting.

A sober reading of the enacted bill does not support that narrative. According to Jones Walker's AI Law Blog, the enrolled bill "arrived at the Governor's desk in a form significantly narrower than the CIPA reform measure it was in 2025." The AI-tool-friendly version — the one that would have carved out "commercial business purpose" processing from §§ 631, 632, and 632.7 — never made it out of the Assembly. The version that did pass does not help audio recorders.

The Larger Legal Trajectory for AI Notetakers

SB 690 arrives in the middle of an accelerating wave of AI meeting tool litigation. In addition to Otter and Granola, Microsoft faces a BIPA case (Basich, 2:26-cv-00422, W.D. Wash.) over live transcription voiceprints, filed February 5, 2026, as tracked by The Little Binger's docket overview. The theory connecting these cases is simple: when a vendor server receives meeting audio and uses it beyond the immediate transcription task, the vendor stops being a "tool of the host" and starts looking like an independent interceptor.

The National Law Review's analysis of the Granola case puts the industry-wide pattern plainly: "Granola operates on stealth by design, Otter.ai operates on viral credential propagation, and Fireflies.ai on biometric data collection." Each architecture creates its own flavor of § 631/§ 632 exposure. None of them are protected by SB 690.

The Compliance-Officer Reading List for Q4 2026

If you are a GC, CCO, or privacy lead responsible for AI meeting tools in a California-exposed deployment, your post-SB 690 checklist should look like this:

  1. Confirm which CIPA sections your vendor is defending against. If the vendor's talking points reference SB 690 as cover, ask specifically about § 631 and § 632 exposure.
  2. Audit vendor data-use terms. The Otter ruling made training-on-recordings a material factor in the court's third-party-eavesdropper analysis.
  3. Document all-party consent flows. SB 690 did not change the obligation to obtain consent from every participant in a California call.
  4. Evaluate on-device architectures. If no vendor server receives the recording, the § 631 third-party-interceptor theory does not attach to the vendor.
  5. Review retroactivity exposure separately. SB 690's two-year retroactivity applies only to § 638.51 claims — it does not clean up pending § 631/632 recording suits.

Our earlier breakdown of the discoverability and litigation risk of cloud notetaker transcripts covers the downstream problem: even if the recording itself survives a consent challenge, the transcript becomes a document subject to subpoena.

How Basil AI Solves This

Basil AI's architecture is deliberately on-device. Audio captured on your iPhone or Mac is transcribed locally using Apple's Speech Recognition framework, which can operate without sending audio to any server. The practical consequence for CIPA analysis:

None of that is a compliance claim about Basil — compliance determinations are the customer's call. It is a description of the architecture, and it is why SB 690's narrow pixel carve-out doesn't matter to Basil the way it (fails to) matter to vendors that hold your meeting audio on their servers.

Buyer's Checklist: Post-SB 690 Vendor Evaluation

Bring these questions to your next AI notetaker procurement call:

  1. Where is meeting audio processed — on the user's device, or on vendor infrastructure?
  2. Does your vendor use any meeting content for model training, by default or opt-out?
  3. What is your vendor's response to the August 13, 2026 Otter ruling on § 631 third-party eavesdropping?
  4. Does your vendor obtain affirmative consent from every meeting participant, or only from the account holder?
  5. If subpoenaed tomorrow, what meeting content does your vendor possess that it could be compelled to produce?
  6. Does your vendor create voiceprints (speaker-ID features) and if so, how does it handle Illinois BIPA?
  7. Has your vendor represented that SB 690 reduces CIPA exposure for AI meeting tools? (If yes, ask them to identify the specific statutory section.)

The Bottom Line

SB 690 is a real win for website operators facing pen-register pixel suits. It is not a win for cloud-based AI meeting notetakers, their customers, or the compliance teams relying on them. The statutes being used against Otter.ai and Granola — CIPA §§ 631 and 632, plus federal ECPA, plus Illinois BIPA — are completely untouched. The $5,000-per-violation damages math under § 637.2 is unchanged. Judge Lee's August 13 Otter ruling, in which the court let the third-party-eavesdropper theory survive against a vendor that trains on recordings, is still the controlling framing of CIPA for AI notetakers.

The architectural question — does your meeting audio leave the device? — is still the only question that moves the risk needle. SB 690 doesn't change the answer. On-device transcription does.

Keep Meeting Audio Off the Cloud. Period.

Basil AI records and transcribes meetings 100% on your iPhone and Mac — no vendor server, no training corpus, no third-party interceptor.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

Does SB 690 protect AI notetakers like Otter or Granola from lawsuits?

No. SB 690 only strips the private right of action under CIPA § 638.51, the pen-register and trap-and-trace provision used in website pixel suits. Sections 631 (wiretapping) and 632 (recording confidential conversations) — the statutes plaintiffs are using against Otter.ai and Granola — are untouched and remain fully available to private plaintiffs for AI notetaker claims.

When does SB 690 take effect?

SB 690 was chaptered as Chapter 976, Statutes of 2026, on September 30, 2026, and becomes operative January 1, 2027. The law applies retroactively to qualifying Section 638.51 claims filed within two years of the effective date — meaning businesses facing pending pixel-tracking suits may have a new defense, but the retroactivity does not reach § 631/632 recording claims.

What is the statutory damages exposure if an AI notetaker violates CIPA?

California's Invasion of Privacy Act allows up to $5,000 per violation under § 637.2, or three times actual damages, whichever is greater. In a class action involving thousands of recorded meeting participants, that math is what makes the Otter and Granola cases viable — and SB 690 did nothing to lower that number for recording claims.

Is on-device transcription a safer architecture after SB 690?

The architecture question hasn't changed. If audio never leaves the device and no vendor server receives the recording, there is no third-party interceptor to argue about under § 631 and no vendor-held recording to argue about under § 632. All-party consent obligations still apply to the person doing the recording, but on-device processing removes the vendor-as-eavesdropper theory that drives the current wave of lawsuits.

Does SB 690 affect the Otter.ai or Granola class actions?

No. Both In re Otter.AI Privacy Litigation (N.D. Cal., Judge Eumi K. Lee) and Chamberlain v. Granola (N.D. Cal., filed July 30, 2026) are built on federal ECPA, CIPA § 631, CIPA § 632, and Illinois BIPA theories. None of those claims arise under § 638.51, so SB 690's carve-out provides no defense.

What should compliance and legal teams do before January 1, 2027?

Audit which AI meeting tools are deployed, where they process audio, and whether vendors retain or train on the recordings. The all-party consent exposure under CIPA § 632 is unchanged by SB 690, and the Otter ruling makes clear that courts will scrutinize vendors that use meeting content for their own commercial purposes. Document consent flows and consider architectures where no third-party server holds the audio at all.