Can My Company Be Sued for Using an AI Notetaker? Deploying-Organization Liability After In re Otter.AI
Published October 08, 2026
- The August 13, 2026 Otter.ai ruling exposes deploying organizations — not just vendors — to realistic wiretap, CIPA, and BIPA liability.
- Federal wiretap law's 'procurement' rule (18 U.S.C. § 2511) reaches the employer whose employee authorized the recording.
- The Ninth Circuit's Javier 'capability test' means any AI vendor that can reuse your audio for training is presumptively a third-party eavesdropper.
- Twelve states require all-party consent; a single cross-state call can trigger the strictest standard.
- On-device transcription removes the third-party vendor from the architecture entirely, eliminating the 'eavesdropper' theory at its source.
Quick answer: Yes. After the August 13, 2026 ruling in In re Otter.AI Privacy Litigation, deploying organizations — not just vendors — face realistic wiretap, CIPA, and BIPA exposure when employees launch cloud AI notetakers in meetings with non-consenting participants. Federal wiretap law's 'procurement' rule reaches whoever authorized the recording. On-device transcription eliminates the third-party vendor from the equation entirely.
For two years, in-house counsel treated AI notetaker risk as a vendor problem. Otter's terms of service, Fireflies' DPA, Zoom's security whitepaper — all of it framed consent as something the account holder was supposed to handle. That framing is no longer safe. On August 13, 2026, Judge Eumi K. Lee of the Northern District of California let federal Wiretap Act, California Invasion of Privacy Act (CIPA), and Illinois biometric-privacy claims against Otter.ai proceed to discovery in In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL. The pivotal holding was that Otter plausibly acted as an independent third-party eavesdropper, not a tool of the meeting host. And the moment that holding exists, the next question — the one every GC and CCO is now asking — is whether the organizations that deployed the tool share the exposure.
The short answer is yes, under multiple active theories. Federal wiretap law has always reached the party who "procures" an unlawful recording. CIPA reaches aiders and abettors. BIPA reaches anyone "in possession" of biometric data collected without written release. This article walks through the specific statutes, the specific cases, and a procurement framework your legal team can use before the next AI notetaker contract hits the signature line.
What Judge Lee Actually Held in In re Otter.AI
The ruling is more surgical than the headlines suggest. The National Law Review's analysis of the order walks through the piece-by-piece disposition: the CIPA, ECPA, BIPA, UCL, and unjust-enrichment claims survived in full; the CFAA, CDAFA, Washington Privacy Act, and most intrusion-upon-seclusion claims were dismissed with leave to amend.
The surviving claims matter more than the dismissed ones. According to the Metropolitan News-Enterprise, Judge Lee rejected Otter's "invited participant" defense — the argument that the Notetaker is merely the account holder's recording tool — because Otter also retains conversation content and uses it to train its own AI models. That dual-use fact, the court held, converts the vendor from an extension of the host into a separate commercial party with its own interception interest.
Why this matters for buyers: once the vendor is a third party, every participant whose voice was captured without affirmative consent has a plausible statutory claim. The analysis in Corporate Compliance Insights puts it bluntly: "Future cases may be brought against deploying organizations themselves." Every recording in the Otter litigation happened because an organization onboarded the tool and let an employee launch it in meetings with people who had not consented.
The 'Procurement' Rule: Why Your Company Is on the Hook
Federal wiretap law under 18 U.S.C. § 2511(1) prohibits not only intercepting a communication but "procuring any other person to intercept" one. California's Penal Code § 631(a) likewise reaches anyone who "aids, agrees with, employs, or conspires with" an unlawful interceptor. These procurement and aiding-and-abetting hooks are what pull deploying organizations into the frame.
The vendor contract tries to shift this risk back to you. Otter's privacy policy expects the account holder to secure consent from all participants. Fireflies' privacy terms operate on the same model. Zoom's privacy statement does the same for AI Companion. When the vendor-side analysis finds inadequate consent, the plaintiffs' bar follows the contractual breadcrumbs back to the enterprise customer that clicked "accept."
As the analysis at BryanJDriscoll.com notes, "Wiretap law's procurement rule reaches the person who set up the bot and let it auto-join, not only the vendor." In an enterprise deployment, "the person" is usually the employer that provisioned the account.
The Javier Capability Test — The Precedent Under Everything
If you want to understand why these cases survive motions to dismiss so routinely, read Javier v. Assurance IQ, the Ninth Circuit's 2022 session-replay decision. Per the AI Lawsuit Tracker's doctrinal summary, Javier established a "capability test": a third-party vendor that could re-use intercepted data for its own purposes qualifies as an eavesdropper under CIPA § 631, even if the website operator (or meeting host) authorized the technology.
That standard is doing the quiet work in every AI-wiretap case now in federal court. If the vendor can use your audio to improve its models — and most SaaS AI notetakers reserve exactly that right in their terms — the vendor is presumptively a third party. The Wealth Solutions Report analysis of the Otter ruling spells out the practical effect: the Notetaker is "not a passive tool. It is a third party recording conversations that may include people who never agreed to be recorded."
The Granola Variant: Invisible Capture Is Worse, Not Better
If your IT team has been evaluating "bot-free" alternatives in response to the Otter news, pause. On July 30, 2026, Florida resident Tarra Chamberlain filed a proposed class action against Granola Inc. and Granola Labs Ltd. in the Northern District of California. Per Computerworld's coverage, the complaint alleges Granola "purposefully" designed its app to record calls without requiring disclosure to all participants and uses transcription data to train AI models by default.
The National Law Review's follow-up analysis highlights that Granola's facts are arguably worse than Otter's on the notice question, because Otter at least sends a visible bot into the meeting. Granola's silent capture — marketed with language like "other people in the room won't know it's there" — removes even that minimal cue.
For a deploying organization, the lesson is architectural, not product-selection: cloud transmission plus vendor training equals third-party exposure. For a deeper walkthrough of the Granola complaint, see our breakdown in Chamberlain v. Granola: The Invisible AI Notetaker Wiretap Lawsuit.
The BIPA Layer: Voiceprints and Written Consent
Wiretap claims are only half the exposure. The Illinois Biometric Information Privacy Act requires written consent and a published retention schedule before any entity collects a "biometric identifier" — a category that includes voiceprints. In the Otter ruling, according to the NJ Business Attorney analysis, the court held Illinois plaintiffs plausibly alleged Otter created speaker-identification profiles tied to participants' names — enough to proceed on both § 15(a) retention-policy and § 15(b) consent claims.
BIPA liquidated damages run $1,000 per negligent violation and $5,000 per intentional or reckless violation. Multiply by every call, every participant, every voiceprint, every meeting over the statute's five-year lookback, and the exposure math gets large quickly. The Amundsen Davis labor and employment update explicitly warns employers that "although the initial litigation often names the AI technology provider as a defendant, employers that deploy these tools aren't insulated from liability."
Cloud AI Notetaker vs On-Device: The Liability Map
The following table compares how each architecture interacts with the specific statutes now being litigated.
| Legal Risk Factor | Cloud AI Notetaker (Otter, Fireflies, Zoom AI, Granola) | On-Device Transcription (Basil AI) |
|---|---|---|
| Third-party vendor receives audio | Yes — vendor server is the processor | No — audio never leaves the device |
| Vendor can train on your content | Yes — common default across SaaS tools | No vendor to train — Apple on-device models |
| Voiceprint collection on vendor infrastructure | Yes — speaker ID requires biometric profile | Diarization runs locally on Apple Neural Engine |
| Vulnerable to "third-party eavesdropper" theory | Yes — see In re Otter.AI (Aug 13, 2026) | No vendor party exists to be an eavesdropper |
| BIPA § 15(a)/(b) exposure for voiceprints | Documented in multiple active class actions | No vendor "in possession" of biometric data |
| Subpoena surface for discovery | Vendor retains data for years; subject to subpoena | User device only; no vendor custodian |
| State all-party consent compliance | Required of account holder; vendor passes the risk | Still required — architecture ≠ consent |
Note the last row: on-device processing does not relieve your employees of the obligation to secure recording consent under state law. That is a human-process control, not a technology control. What on-device does eliminate is the vendor third-party eavesdropper theory, because there is no vendor server in the audio path at all.
The Twelve-State All-Party-Consent Trap
Twelve U.S. states require consent from every party to record a confidential communication: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, Washington, and Michigan (via case law). A sales call between a Chicago rep, a Boston prospect, and a London buyer must satisfy the strictest applicable rule — in that example, Illinois BIPA and Massachusetts' two-party consent statute both apply.
CIPA damages are $5,000 per violation or three times actual damages, whichever is greater. Pennsylvania wiretap violations are felonies. If your employee's cloud notetaker auto-joined a call with participants in any of those states, and participants did not affirmatively consent, each call is a potential statutory count.
What "Affirmative Consent" Actually Requires
Platform notifications like "this meeting is being recorded" generally are not enough on their own in all-party states — courts analyze whether participants had a meaningful opportunity to object. A bot that joins mid-call and starts transcribing before late-arriving attendees can read a chat message is a poor factual record. Written pre-meeting disclosures in the invite, verbal confirmation at the top of the call, and a documented objection process is the compliant pattern.
Attorney-Client Privilege: The Overlay Risk
For meetings that touch legal advice, there is a second liability vector: privilege waiver. In United States v. Heppner, No. 25 CR. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026), Judge Rakoff held that content a defendant shared with Anthropic's Claude was not protected by attorney-client privilege. Per Mayer Brown's analysis of the ruling, the court left open a narrow Kovel-style exception where counsel directs the use of the AI — but absent that direction, consumer-grade AI platforms do not carry privilege.
Applied to meeting notetakers, the implication is direct: a cloud AI notetaker in a privileged conversation is a non-attorney third party receiving the communication, and third-party receipt is a classic waiver event. For the full doctrinal walk-through, see Does an AI Notetaker Waive Attorney-Client Privilege? and the related buyer's guide at AI Notetakers for Lawyers: Avoiding Privilege Waiver with On-Device Transcription.
How Basil AI Solves This: On-Device Processing Removes the Third-Party Vendor
Every one of the theories above — Javier capability, Otter third-party eavesdropper, BIPA voiceprint possession, Heppner privilege waiver — requires a vendor to exist in the audio path. Basil AI is designed so that no such vendor exists.
The architecture runs entirely on-device using Apple's on-device Speech framework and the Neural Engine documented at Apple's privacy features page. Audio capture, transcription, speaker diarization, and summarization all execute on the user's iPhone or Mac. Nothing is uploaded to a Basil server because there is no Basil server in the audio path. Transcripts route to Apple Notes via the user's own iCloud account, under Apple's end-to-end encryption posture.
For the full capture-to-share workflow, see Bot-Free vs Bot-Based AI Notetakers. For the specific wealth-management and compliance-officer use cases driving the current enterprise migration, see AI Notetakers for Wealth Management After the Otter Ruling and AI Meeting Notes for Compliance Officers in Financial Services.
Important caveat, in the brand voice we use throughout this site: on-device architecture is a fact about the data flow, not a compliance guarantee. Your general counsel decides whether a given deployment meets GDPR, HIPAA, FINRA, or state wiretap obligations in your jurisdiction. What architecture determines is whether a vendor custodian exists to be subpoenaed, trained on your content, or named as a third-party eavesdropper. On-device removes that custodian from the equation.
Six Questions to Put to Every AI Notetaker Vendor
Bring this checklist to procurement before signing or renewing. Each question maps to a specific statutory risk now in active litigation.
- Where is audio processed? Vendor cloud or on-device? If cloud, you have Javier capability-test exposure.
- Is model training on our content enabled by default? If yes — or if opt-out is user-level rather than enterprise-level — you have the Chamberlain v. Granola fact pattern.
- What is the retention schedule for audio, transcripts, and voiceprints? Required under BIPA § 15(a) and increasingly under state consumer privacy laws like the California Consumer Privacy Act.
- Do you build voiceprints? Any speaker-ID feature likely does. Written BIPA consent and a published destruction schedule are prerequisites.
- Will you sign a DPA with no-training and deletion-on-request guarantees? If the sales rep hedges, treat it as a hard no. See GDPR Article 28 on processor obligations.
- What indemnification do you provide if the product is held to violate wiretap or BIPA statutes? After In re Otter.AI, this is no longer theoretical.
The Decision Framework for IT, Legal, and Procurement
For most enterprises, the honest decision tree after August 13, 2026 is: (1) if your meetings touch any regulated information — privileged legal content, PHI, MNPI, HR performance data, M&A deliberations — move to on-device capture; (2) for routine internal operational meetings, continue with cloud tools only if you can document participant consent and vendor DPAs that disclaim training rights; (3) in all cases, update your meeting policies to require explicit all-party consent on calls with any participant in an all-party-consent state.
The underlying point is that the vendor contract is no longer a defense. Your CCO and GC decide the policy. The architecture decides what's technically possible to defend.
Capture meetings without a vendor in the audio path
Basil AI runs 100% on-device on iPhone, iPad, and Mac — no cloud, no training on your content, no vendor custodian to subpoena.
Frequently Asked Questions
Can my company be sued if an employee uses an AI notetaker without participants' consent?
Yes. The federal Wiretap Act's procurement provision (18 U.S.C. § 2511) and California's CIPA reach the party who 'procures' the recording — typically the employer whose account was used. After the August 13, 2026 Otter ruling, legal analysts expect the next wave of cases to target the deploying organizations, not just the vendors.
What did the August 13, 2026 Otter.ai ruling actually decide?
Judge Eumi K. Lee of the Northern District of California denied Otter's motion to dismiss on the core claims. The federal Wiretap Act, California Invasion of Privacy Act, Illinois BIPA, UCL, and unjust enrichment claims all survived and will proceed to discovery. The court held Otter plausibly acted as a third-party eavesdropper because it retains conversations and trains its models on them.
What is the 'capability test' from Javier v. Assurance IQ?
The Ninth Circuit's 2022 Javier decision established that a third-party vendor that records interactions for its own purposes — including AI model training — qualifies as an eavesdropper under CIPA § 631 even when the account holder authorized the technology. This 'capability' standard underlies every current AI-wiretap case, including the Otter, Granola, and Fireflies suits.
Does on-device transcription eliminate this risk?
On-device transcription materially changes the analysis because there is no third-party vendor receiving the audio. The processing happens on the device's Neural Engine, nothing is uploaded to a vendor server, and no voiceprints are built on vendor infrastructure. State all-party consent laws still apply to the act of recording itself — your CCO or GC decides the overall policy — but the third-party-eavesdropper theory does not reach a tool that never transmits audio to a vendor.
Which states require all-party consent for AI meeting recordings?
Twelve states require all-party consent to record a confidential communication: California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Pennsylvania, Washington, and Michigan (under state case law). Federal law and the remaining states require only one-party consent. Any cross-state call defaults to the strictest applicable rule.
What should our procurement team ask AI notetaker vendors before signing?
Six questions: (1) Where is audio processed — vendor cloud or on-device? (2) Does the vendor train models on our content by default? (3) What is the retention schedule for audio, transcripts, and voiceprints? (4) Does the vendor collect biometric voiceprints under BIPA? (5) Will the vendor sign a DPA with no-training and deletion-on-request guarantees? (6) What indemnification does the vendor provide if its product is held to violate wiretap or BIPA statutes?