A class action against AI notetaker Otter flags real liability risks with meeting assistants. Patrick E. Zeller, general counsel of JetStream Security, writes that organizations that will feel the pain of meeting assistant liabilities are ones that never consider their risk.
In August, a federal judge in the Northern District of California rejected Otter.ai’s motion to dismiss the core wiretap and biometric privacy claims in In re Otter.ai Privacy Litigation, allowing class-action plaintiffs to move forward against the maker of the popular AI-powered Notetaker meeting assistant.
Otter.ai argued that Notetaker joins meetings only as an invited participant and functions as the host’s recording tool, an extension of the customer who deployed it. Judge Eumi K. Lee did not accept that framing. Because plaintiffs allege Otter.ai also retains and trains its models on the conversations and voiceprints captured, the court found plaintiffs had sufficiently alleged Otter.ai acted as a third-party eavesdropper. As a motion to dismiss, the plaintiffs’ allegations are accepted as true; the merits will be decided as the case continues.
In-house counsel may be tempted to read this as a vendor-side liability question. But if a vendor can be held liable for capturing confidential information and voiceprints, it raises the question of whether companies that deploy the technology without participants’ consent may also face liability. Every recording at issue happened because an organization onboarded the tool and an employee launched it in meetings with people who had not consented. Otter.ai simply happens to be the defendant here. Future cases may be brought against deploying organizations themselves. Under the federal Electronic Communications Privacy Act (ECPA), a deploying organization may face liability as an active “procurer” of the interception, particularly where it configures the meeting assistant’s recording functions.
AI’s creation of discoverable corporate records
Organizations have rapidly adopted AI-driven meeting assistants that generate a new trove of digital records of executives’ and employees’ communications, often without the consent of other participants. Tools like the Otter Notetaker pull data outside the customer’s firewall and transfer it to the vendor’s computing environment, where meeting data may be processed in ways that include:
- Storing the raw audio recording for analysis.
- Analyzing audio to create biometric “voiceprints” used to identify each speaker.
- Generating a digital transcript.
- Exposing that transcript to machine learning for analysis and potential model training.
- Producing summaries, action items and other analytics.
- Retaining all of this data indefinitely unless the vendor has and exercises a purge capability and schedule.
Recordings and transcripts of executive, financial, legal or HR meetings may need to be classified as a new variety of confidential corporate records even when the contents have been ingested into the meeting assistant vendor’s machine learning databases. Legal and compliance teams must determine whether those records are shared outside the organization’s control, whether they are subject to the vendor’s retention policies rather than the customer’s and whether they will be discoverable in litigation or required for regulatory investigations.
Failure to obtain consent increases legal risk
A key fact sustaining plaintiffs’ claims was Otter.ai’s failure to obtain affirmative consent from all participants, despite the Notetaker’s visible presence on the meeting screen. That failure supported the court’s refusal to dismiss claims under the federal ECPA, California Penal Code (eavesdropping on a confidential communication) as well as California’s Invasion of Privacy Act, unfair competition law and common-law claims for unjust enrichment. The court dismissed the state intrusion-upon-seclusion tort claims on behalf of three of the plaintiffs, whose allegations were deemed merely conclusory. However, the claim brought by one California plaintiff survived dismissal because she adequately alleged that the recorded conversation (a medical discussion) involved a reasonable expectation of privacy.
Do not assume a visible bot satisfies state privacy law consent requirements. The court rejected Otter.ai’s argument that appearance in the attendee list constitutes consent. Some tools are not visible at all. Another recent proposed class action, Chamberlain v. Granola, Inc., filed in the Northern District of California in July concerns an AI meeting assistant called Granola that allegedly is silent and invisible to participants and captures audio directly from a single participant’s computer. Granola allegedly offers transparency and consent features, but they must be enabled by the customer, which raises the question of whether a failure to enable consent features exposes the customer to liability.
While the federal Wiretap Act generally treats one party’s consent as a defense, a dozen or so states, including California, require all-participant consent. Lawyers must not rely on one-party consent; wiretapping liability depends on the residency of meeting participants, and organizations should meet the standards of the strictest likely jurisdictions and insist on mandatory consent collection from all attendees.
AI in Investigations: What Courts Are Saying (So Far) About Privilege
Emerging case law shows how easily AI-assisted investigation work can lose attorney-client privilege
Read moreDetailsDiscovery exposure and risk of privilege waiver
A conversation that once disappeared is now a discoverable record subject to the same preservation duties as any other document. When litigation is reasonably anticipated, transcripts must be preserved, and no legal department can preserve what it cannot locate. Retention schedules written for email do not automatically reach transcripts stored in a vendor’s cloud. AI meeting transcripts likely will become a key target in litigation and regulatory investigations, subject to legal holds and potential production.
Transcripts often live in the vendor’s environment, where the organization’s retention schedule may not apply in a provable way. If the tool retains audio, trains on it or permits subprocessor access, the discoverability analysis must account for parties the customer and the meeting participants never contemplated. Organizations are presumably deemed to have possession, custody and control over vendor-held data — but can the vendor locate and retrieve that data in a producible format? Can it implement a legal hold as to recordings of specific meetings?
Privilege protection may be affected as well. Attorney-client and work-product privilege depend on confidentiality, which is fragile in the presence of a third party that may reuse the privileged information for its own benefit. If opposing counsel challenges privilege designations because transcripts were shared with a vendor that may use them to train its AI, can the organization prove privileged content was never exposed to vendor employees or other customers? Many vendors will offer that assurance, but can it be proved to the satisfaction of a court or regulator?
Conclusions
I spent years as a federal and computer crimes prosecutor before advising companies on governance, and the pattern is consistent. The organizations that get hurt are rarely those that weighed a risk and built appropriate controls. They are the ones that never seriously appreciated the risk until it materialized.
Consider potential controls including:
- Establish a “consent-first” deployment framework that defaults to the strictest applicable state standard, all-participant consent and documents participant acknowledgment.
- Investigate vendors’ confidentiality claims before onboarding, confirming the tool is not used to train models in ways that expose sensitive data. Confirm retention and deletion practices; shorter retention periods reduce discovery exposure. Ensure the vendor can implement a defensible legal hold if necessary.
- Prohibit AI meeting assistants for sensitive or privileged conversations, and consider disabling AI transcription for top executives and counsel.
- Enforce a ban on “silent capture” tools, like Granola, that record without any visible presence on the meeting interface.
AI meeting assistants are useful and unlikely to be banned. But these risks call for a risk assessment.


Patrick E. Zeller is general counsel and corporate secretary at JetStream Security. He began his career as a federal computer crimes prosecutor and regulator and has spent more than 20 years advising companies on privacy, cybersecurity and data protection. 











