Abstract microphone and soundwave illustration on a dark teal background, representing AI meeting transcription and data exposure risk

Alert: AI notetakers are on trial for recording people without consent, what your business should do

An AI notetaker quietly joins a video call, sits in the corner of the participant list, and transcribes everything said, often without the people in the meeting having agreed to it. That everyday scene is now the centre of a major US court case, and a judge’s ruling is expected shortly. For any business that uses, or sits in meetings with, AI meeting assistants, it is worth understanding what is at stake and what to check this week.

This is a different shape of AI Leakage from the vendor policy changes we have covered recently. It is not about a tool training on data you handed it. It is about a tool capturing the words of people who never agreed to be recorded, and sending them to a third party.

What is actually happening

Otter.ai, maker of the widely used Otter Notetaker, is fighting a consolidated class action in California federal court (In re Otter.AI Privacy Litigation, No. 5:25-cv-06911, N.D. Cal., before Judge Eumi K. Lee). It bundles several suits filed from August 2025 onward. The core allegation: Otter’s assistant auto-joins Zoom, Microsoft Teams and Google Meet calls, records and transcribes everyone present, and uses those transcripts to improve its models, without obtaining consent from all participants, only (at most) from the meeting host.

Otter’s motion to dismiss was heard on 20 May 2026, and the ruling that follows is being described as the first real federal test of whether decades-old wiretap laws apply to an AI bot sitting silently in a meeting. Otter contests the claims; it points to its terms, which tell account-holders to make sure they have the necessary permissions, and to an opt-in step for training. It is important to be clear that these are allegations a court has not yet ruled on, and Otter will have its chance to defend them.

And it is not only Otter. Rival notetaker Fireflies.ai was hit with its own class action in Illinois in December 2025. The pattern is being read across the industry: the entire AI meeting-assistant category is being tested at once.

Why this is a leakage problem, not just a legal one

Strip out the courtroom and the business risk is simple. A meeting where a client’s details, a pricing discussion, a personnel matter, or a legally sensitive conversation are spoken aloud gets captured by a third-party service, stored on its servers, and in some cases fed into model training. The people whose words were taken may never have known it was happening. That is sensitive information leaving your control through a tool, which is exactly what AI Leakage means (see What is AI leakage?).

It is also a textbook case of the two ideas we keep separate (see AI Leakage vs Shadow AI). Very often the bot in the room is running off one colleague’s personal notetaker account, set to auto-join their calendar, that nobody signed off on. That is shadow AI, the behaviour. The whole room’s conversation ending up with a third party is the leakage, the outcome.

And, as always, the tier matters. In our AI Tool Risk Directory, the free and personal tiers of Otter.ai carry our highest risk rating, precisely because of this litigation and the consent and training questions behind it. Other notetakers we track, including Granola, Fathom and Zoom AI Companion, sit at different levels depending on tier and recording behaviour. Read the rating before you rely on one.

The New Zealand and Australian angle

The lawsuit is American, but the underlying issue travels. Under the New Zealand Privacy Act 2020, when a notetaker captures participants’ voices and words, your organisation is collecting other people’s personal information, which brings obligations to be transparent about why, and to collect it fairly rather than covertly. New Zealand law does generally allow a participant to record a conversation they are part of, so the recording itself is not automatically unlawful, but that does not remove your responsibility for the information once it is collected, or your duty to be open about it.

Australia can be stricter on the recording itself: several states have surveillance-device and listening-device laws that require the consent of all parties to record a private conversation, on top of the Privacy Act and the Australian Privacy Principles. So a quiet bot recording an external meeting can be a sharper problem across the Tasman. The practical takeaway for both countries is the same: do not assume that one person clicking accept covers everyone in the room. (This is general information, not legal advice; check your own situation.)

What to do this week

  1. Name notetakers in your AI policy. Spell out which meeting assistants are allowed, on which tier, and the rule that recording requires the agreement of everyone on the call, not just the host.
  2. Disclose and ask first. Before any AI notetaker records, especially in external or client meetings, tell participants and get their agreement. Silence is not consent.
  3. Turn off silent auto-join. Check whether your tool seeks permission from every participant or just the host, and disable the setting that lets a bot slip into calls automatically.
  4. Use the business tier, not the free one. Enterprise and business tiers generally carry better data terms and training controls. Check the current position for your tool in the AI Tool Risk Directory before you trust it with real conversations.
  5. Empower your team to say no. Tell staff that if an unfamiliar notetaker bot appears in a meeting they are in, it is fine to ask the host to remove it before sensitive matters are discussed.

This is the third alert in a run watching how everyday AI tools quietly capture business data, after Atlassian training on Jira and Confluence data and Google’s new media-training default. The thread running through all three is the same: the default tends to favour the vendor, and the defence is a written policy plus a habit of checking before you trust a tool.

Get the next one in your inbox. We send a plain-English alert whenever an AI tool businesses rely on changes its data policy or runs into trouble, no hype, just what changed. Subscribe to AI Leakage Alerts.


How this was written

This alert was drafted with AI and checked by a person before publishing. It draws on the public court record for In re Otter.AI Privacy Litigation (N.D. Cal.) and on reporting from NPR (August 2025), UC Today (April 2026) and legal analyses from Fisher Phillips. The allegations described are unproven and contested. This is general information, not legal advice. Tool risk ratings change as vendors change their terms; we update them, and we date our sources.

Similar Posts