No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

AI Meeting Assistants Raise Eavesdropping Concerns & Discovery Headaches

A federal court has allowed wiretap and privacy claims against an AI notetaker to proceed

by Patrick E. Zeller
October 5, 2026
in Risk
ai notetaker robot on zoom call

A class action against AI notetaker Otter flags real liability risks with meeting assistants. Patrick E. Zeller, general counsel of JetStream Security, writes that organizations that will feel the pain of meeting assistant liabilities are ones that never consider their risk.

In August,  a federal judge in the Northern District of California rejected Otter.ai’s motion to dismiss the core wiretap and biometric privacy claims in In re Otter.ai Privacy Litigation, allowing class-action plaintiffs to move forward against the maker of the popular AI-powered Notetaker meeting assistant.

Otter.ai argued that Notetaker joins meetings only as an invited participant and functions as the host’s recording tool, an extension of the customer who deployed it. Judge Eumi K. Lee did not accept that framing. Because plaintiffs allege Otter.ai also retains and trains its models on the conversations and voiceprints captured, the court found plaintiffs had sufficiently alleged Otter.ai acted as a third-party eavesdropper. As a motion to dismiss, the plaintiffs’ allegations are accepted as true; the merits will be decided as the case continues.

In-house counsel may be tempted to read this as a vendor-side liability question. But if a vendor can be held liable for capturing confidential information and voiceprints, it raises the question of whether companies that deploy the technology without participants’ consent may also face liability. Every recording at issue happened because an organization onboarded the tool and an employee launched it in meetings with people who had not consented. Otter.ai simply happens to be the defendant here. Future cases may be brought against deploying organizations themselves. Under the federal Electronic Communications Privacy Act (ECPA), a deploying organization may face liability as an active “procurer” of the interception, particularly where it configures the meeting assistant’s recording functions. 

AI’s creation of discoverable corporate records

Organizations have rapidly adopted AI-driven meeting assistants that generate a new trove of digital records of executives’ and employees’ communications, often without the consent of other participants. Tools like the Otter Notetaker pull data outside the customer’s firewall and transfer it to the vendor’s computing environment, where meeting data may be processed in ways that include:

  • Storing the raw audio recording for analysis.
  • Analyzing audio to create biometric “voiceprints” used to identify each speaker.
  • Generating a digital transcript.
  • Exposing that transcript to machine learning for analysis and potential model training.
  • Producing summaries, action items and other analytics.
  • Retaining all of this data indefinitely unless the vendor has and exercises a purge capability and schedule.

Recordings and transcripts of executive, financial, legal or HR meetings may need to be classified as a new variety of confidential corporate records even when the contents have been ingested into the meeting assistant vendor’s machine learning databases. Legal and compliance teams must determine whether those records are shared outside the organization’s control, whether they are subject to the vendor’s retention policies rather than the customer’s and whether they will be discoverable in litigation or required for regulatory investigations.

Failure to obtain consent increases legal risk

A key fact sustaining plaintiffs’ claims was Otter.ai’s failure to obtain affirmative consent from all participants, despite the Notetaker’s visible presence on the meeting screen. That failure supported the court’s refusal to dismiss claims under the federal ECPA, California Penal Code (eavesdropping on a confidential communication) as well as California’s Invasion of Privacy Act, unfair competition law and common-law claims for unjust enrichment. The court dismissed the state intrusion-upon-seclusion tort claims on behalf of three of the plaintiffs, whose allegations were deemed merely conclusory. However, the claim brought by one California plaintiff survived dismissal because she adequately alleged that the recorded conversation (a medical discussion) involved a reasonable expectation of privacy.

Do not assume a visible bot satisfies state privacy law consent requirements. The court rejected Otter.ai’s argument that appearance in the attendee list constitutes consent. Some tools are not visible at all. Another recent proposed class action, Chamberlain v. Granola, Inc., filed in the Northern District of California in July concerns an AI meeting assistant called Granola that allegedly is silent and invisible to participants and captures audio directly from a single participant’s computer. Granola allegedly offers transparency and consent features, but they must be enabled by the customer, which raises the question of whether a failure to enable consent features exposes the customer to liability.

While the federal Wiretap Act generally treats one party’s consent as a defense, a dozen or so states, including California, require all-participant consent. Lawyers must not rely on one-party consent; wiretapping liability depends on the residency of meeting participants, and organizations should meet the standards of the strictest likely jurisdictions and insist on mandatory consent collection from all attendees.

meeting with attorney
Risk

AI in Investigations: What Courts Are Saying (So Far) About Privilege

by Gorev Ahuja
September 15, 2026

Emerging case law shows how easily AI-assisted investigation work can lose attorney-client privilege

Read moreDetails

Discovery exposure and risk of privilege waiver

A conversation that once disappeared is now a discoverable record subject to the same preservation duties as any other document. When litigation is reasonably anticipated, transcripts must be preserved, and no legal department can preserve what it cannot locate. Retention schedules written for email do not automatically reach transcripts stored in a vendor’s cloud. AI meeting transcripts likely will become a key target in litigation and regulatory investigations, subject to legal holds and potential production.

Transcripts often live in the vendor’s environment, where the organization’s retention schedule may not apply in a provable way. If the tool retains audio, trains on it or permits subprocessor access, the discoverability analysis must account for parties the customer and the meeting participants never contemplated. Organizations are presumably deemed to have possession, custody and control over vendor-held data — but can the vendor locate and retrieve that data in a producible format? Can it implement a legal hold as to recordings of specific meetings?

Privilege protection may be affected as well. Attorney-client and work-product privilege depend on confidentiality, which is fragile in the presence of a third party that may reuse the privileged information for its own benefit. If opposing counsel challenges privilege designations because transcripts were shared with a vendor that may use them to train its AI, can the organization prove privileged content was never exposed to vendor employees or other customers? Many vendors will offer that assurance, but can it be proved to the satisfaction of a court or regulator?

Conclusions

I spent years as a federal and computer crimes prosecutor before advising companies on governance, and the pattern is consistent. The organizations that get hurt are rarely those that weighed a risk and built appropriate controls. They are the ones that never seriously appreciated the risk until it materialized.

Consider potential controls including:

  • Establish a “consent-first” deployment framework that defaults to the strictest applicable state standard, all-participant consent and documents participant acknowledgment.
  • Investigate vendors’ confidentiality claims before onboarding, confirming the tool is not used to train models in ways that expose sensitive data. Confirm retention and deletion practices; shorter retention periods reduce discovery exposure. Ensure the vendor can implement a defensible legal hold if necessary.
  • Prohibit AI meeting assistants for sensitive or privileged conversations, and consider disabling AI transcription for top executives and counsel.
  • Enforce a ban on “silent capture” tools, like Granola, that record without any visible presence on the meeting interface.

AI meeting assistants are useful and unlikely to be banned. But these risks call for a risk assessment.

Tags: Artificial Intelligence (AI)
Previous Post

Tax Compliance Company Sovos Acquires Finance Orchestration Platform

Next Post

Exploring California’s Generative AI Training Data Transparency Act

Patrick E. Zeller

Patrick E. Zeller

Patrick E. Zeller is general counsel and corporate secretary at JetStream Security. He began his career as a federal computer crimes prosecutor and regulator and has spent more than 20 years advising companies on privacy, cybersecurity and data protection.

Related Posts

data being parsed conceptual illustration

Exploring California’s Generative AI Training Data Transparency Act

by Stephanie Sharron, Marian Waldmann Agarwal & Joshua Fattal
October 5, 2026

AB 2013 obligations are live now, and the practical question is not whether to comply but how much to disclose

data abstract vintage

Company Leaders Wary Over AI-Related Labor Issues

by Staff and Wire Reports
October 1, 2026

Plus: Most companies experienced a cyberattack recently; C-suite rift revealed on business disruption

robot showing records to employees collage

That AI-Drafted Termination Memo Could Become Evidence

by Hekim Colpan and Phillip Wikes
September 29, 2026

AI reproduces subjective phrasing across files, so language that looks neutral in one record can reveal a pattern across a...

hands raised at meeting

AI Governance Frameworks Won’t Save You, but an Ethically Engaged Workforce Might

by Caterina Bulgarella
September 29, 2026

The frameworks and safeguards that make boards feel AI risk is handled usually leave out the one defense that actually...

Next Post
data being parsed conceptual illustration

Exploring California’s Generative AI Training Data Transparency Act

GGR sq
No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • The Business of GRC
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Research
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
  • Webinars
  • Videos
  • Subscribe

© 2026 Corporate Compliance Insights