Organizations that fail to proactively assess and mitigate the risks associated with AI-powered meeting assistants are likely to face significant legal and financial repercussions, according to legal experts. A recent class-action lawsuit against Otter.ai, a popular AI notetaker, has brought these burgeoning liabilities into sharp focus, signaling a critical inflection point for businesses integrating such technologies into their daily operations.

In August, a federal judge in the Northern District of California delivered a significant blow to Otter.ai by rejecting its motion to dismiss key claims in the In re Otter.ai Privacy Litigation. This ruling allows plaintiffs to proceed with their class-action lawsuit, alleging violations of wiretap and biometric privacy laws. The core of the legal challenge revolves around Otter.ai’s AI-powered Notetaker, a tool designed to automate meeting transcription and summarization.

Otter.ai had argued that its Notetaker functions solely as an invited participant and an extension of the meeting host’s recording capabilities. The company contended that it was merely facilitating the recording process on behalf of its users. However, Judge Eumi K. Lee did not find this argument persuasive. The court’s decision hinged on the plaintiffs’ allegations that Otter.ai not only records conversations and voiceprints but also retains and trains its AI models on this captured data. This practice, the court determined, sufficiently supports the claim that Otter.ai acted as a third-party eavesdropper, potentially infringing on privacy rights. It is crucial to note that at this stage, the court accepts the plaintiffs’ allegations as true for the purpose of the motion to dismiss. The substantive merits of these claims will be adjudicated as the litigation progresses through the legal system.

The implications of this ruling extend far beyond Otter.ai, casting a wide net of potential liability over companies that deploy similar AI meeting assistants. While it might be tempting for in-house legal counsel to view this as a vendor-specific issue, the reality is more complex. If a vendor like Otter.ai can be held accountable for capturing confidential information and voiceprints without adequate consent, then organizations that enable the use of these tools in meetings where participants have not explicitly consented to recording and data retention also face significant exposure.

Every meeting recording at the heart of these lawsuits occurred because an organization integrated the technology and an employee activated it. The participants in these discussions, often unaware of the full extent of data collection and usage by the AI vendor, may not have provided their informed consent. While Otter.ai is currently the named defendant, future legal actions could very well target the deploying organizations themselves. Under federal statutes like the Electronic Communications Privacy Act (ECPA), a company that procures or actively facilitates the interception of communications, particularly through the configuration of recording functionalities, could be deemed liable. This means that the very act of onboarding and enabling these tools without robust consent mechanisms places the organization in a precarious legal position.

The Emergence of Discoverable Corporate Records Through AI

The rapid adoption of AI-driven meeting assistants has fundamentally altered the landscape of corporate record-keeping. These tools are generating an unprecedented volume of digital records that document executive and employee communications, often without the explicit consent of all involved parties. Technologies like the Otter Notetaker extract data from a company’s internal network and transfer it to the vendor’s cloud environment. Within these external computing platforms, meeting data can be subjected to a range of processing activities, including:

  • Transcription and Summarization: Converting spoken words into text and generating concise summaries.
  • Analysis and Insights: Identifying key themes, action items, and sentiment within conversations.
  • Model Training: Utilizing captured voiceprints and conversational data to improve the AI’s performance and accuracy.
  • Data Storage and Retention: Storing recordings and transcripts, often subject to the vendor’s data retention policies, which may differ significantly from the client organization’s.

Recordings and transcripts of sensitive meetings—whether concerning executive strategy, financial planning, legal matters, or human resources—can now be classified as a new category of confidential corporate records. This classification becomes particularly relevant even when the content has been ingested into the AI vendor’s machine learning databases. Legal and compliance teams must meticulously ascertain whether these records are being shared beyond the organization’s direct control, whether they are governed by the vendor’s retention schedules instead of the customer’s, and crucially, whether they will be subject to discovery in litigation or required for regulatory investigations. The potential for these AI-generated records to become central pieces of evidence in legal proceedings is a significant, and often underestimated, risk.

The Heightened Legal Risk of Failing to Obtain Consent

A pivotal factor in the sustainability of the plaintiffs’ claims against Otter.ai was the company’s alleged failure to secure affirmative consent from all meeting participants. Despite the Notetaker’s visible presence on the meeting screen, the court’s refusal to dismiss claims under the federal ECPA, California Penal Code (prohibiting eavesdropping on confidential communications), California’s Invasion of Privacy Act, unfair competition law, and common-law claims for unjust enrichment underscores the importance of explicit consent.

While the court dismissed intrusion-upon-seclusion tort claims for three plaintiffs whose allegations were deemed too general, a claim brought by one California plaintiff survived. This plaintiff successfully alleged that the recorded conversation, a medical discussion, involved a reasonable expectation of privacy, thereby strengthening the argument for a breach of privacy.

The ruling serves as a stark warning: the mere visual presence of an AI assistant on a meeting interface does not automatically satisfy state privacy law consent requirements. Otter.ai’s argument that its appearance in the attendee list constituted consent was rejected by the court. This highlights a critical oversight: some AI meeting tools may not be visible at all, further complicating consent protocols.

A parallel case, Chamberlain v. Granola, Inc., filed in July in the Northern District of California, illustrates this concern. This proposed class action involves an AI meeting assistant named Granola, which allegedly operates silently and invisibly, capturing audio directly from a single participant’s computer. While Granola reportedly offers transparency and consent features, these functionalities must be actively enabled by the customer. This raises a crucial question: does a customer’s failure to enable these consent features expose them to liability?

The legal landscape regarding consent for recording conversations is multifaceted. The federal Wiretap Act generally permits one-party consent, meaning that if one participant in a conversation consents to the recording, it may be legal. However, a significant number of states, including California, require all-party consent. This means that every individual participating in a recorded conversation must give their explicit permission. Legal professionals must not rely solely on one-party consent laws. The legality of wiretapping and recording is heavily dependent on the residency of all meeting participants. Therefore, organizations should err on the side of caution and adhere to the strictest consent requirements, mandating affirmative consent from all attendees, regardless of their location. This approach mitigates the risk of violating the laws of any jurisdiction where a participant may be located.

Discovery Exposure and the Perilous Risk of Privilege Waiver

Conversations that were once ephemeral are now transforming into discoverable corporate records, subject to the same stringent preservation duties as any other form of documentary evidence. When litigation is reasonably foreseeable, transcripts of meetings must be preserved. However, a legal department cannot preserve what it cannot locate. Existing retention schedules, often designed for traditional electronic communications like email, may not adequately encompass transcripts stored in a vendor’s cloud environment. AI meeting transcripts are increasingly likely to become a prime target in litigation and regulatory investigations, subject to legal holds and mandatory production.

The decentralized nature of data storage, with transcripts often residing within a vendor’s infrastructure, poses a significant challenge to the enforcement of an organization’s retention policies. If the AI tool retains audio recordings, utilizes them for model training, or permits access by subprocessors, the discoverability analysis becomes far more complex. This analysis must account for third parties that neither the customer nor the meeting participants may have ever contemplated. Organizations are generally presumed to have possession, custody, and control over data held by their vendors. However, the critical questions arise: Can the vendor efficiently locate and retrieve this data in a legally producible format? Can the vendor effectively implement a legal hold on recordings pertaining to specific meetings?

Furthermore, the confidentiality that underpins attorney-client and work-product privileges can be severely compromised. These privileges are fragile when sensitive information is shared with a third party that may reuse the privileged content for its own commercial benefit. If opposing counsel challenges privilege designations by arguing that transcripts were shared with a vendor capable of using them for AI training, can the organization definitively prove that privileged content was never exposed to vendor employees or other customers? While many vendors may offer assurances of confidentiality, substantiating these claims to the satisfaction of a court or regulatory body can be an arduous and often insurmountable task. The potential for inadvertent disclosure and subsequent privilege waiver necessitates a rigorous review of vendor data handling practices.

Strategic Mitigation and Proactive Control Measures

Patrick E. Zeller, General Counsel of JetStream Security, emphasizes a consistent pattern observed in his extensive career as a former federal and computer crimes prosecutor and his subsequent advisory roles in corporate governance. The organizations that ultimately suffer the most significant harm are rarely those that have diligently assessed risks and implemented appropriate controls. Instead, it is typically those that have failed to adequately appreciate the potential risks until they have already materialized, leading to costly legal battles and reputational damage.

To navigate this evolving legal landscape, organizations should consider implementing a comprehensive suite of potential controls. These may include:

  • Robust Vendor Due Diligence: Thoroughly vetting AI meeting assistant vendors to understand their data handling, security, privacy, and retention policies. This includes scrutinizing their subprocessors and their ability to comply with legal holds.
  • Clear and Explicit Consent Mechanisms: Implementing mandatory, affirmative consent protocols for all participants in any meeting where an AI assistant will be used. This should go beyond mere visual notification and require active acknowledgment from each attendee.
  • Data Minimization and Deletion Policies: Configuring AI tools to collect only the necessary data and establishing clear policies for the prompt deletion of recordings and transcripts once they are no longer required for their intended purpose.
  • Confidentiality Agreements and Training: Ensuring that all employees using AI meeting assistants are thoroughly trained on data privacy, confidentiality obligations, and the potential risks associated with unauthorized recording or data sharing.
  • Regular Risk Assessments: Conducting periodic assessments of AI tool usage, identifying potential vulnerabilities, and updating policies and controls accordingly. This includes staying abreast of evolving legal and regulatory requirements.
  • Data Governance Frameworks: Developing and enforcing comprehensive data governance frameworks that clearly define ownership, access, usage, and retention of all corporate data, including AI-generated records.
  • Legal Hold Procedures: Establishing clear and executable procedures for implementing legal holds on AI-generated records, ensuring that the vendor can comply with such requests promptly and effectively.
  • Privilege Protection Protocols: Implementing strict protocols to safeguard privileged communications, ensuring that AI tools are not used in ways that could compromise confidentiality and lead to privilege waiver. This may involve avoiding the use of AI assistants in meetings where privileged discussions are expected.

AI meeting assistants offer undeniable utility and are unlikely to be proscribed outright. However, their increasing prevalence and the attendant legal complexities necessitate a comprehensive and proactive risk assessment. The legal challenges spearheaded by the Otter.ai case are not isolated incidents but rather indicators of a broader trend. Organizations that fail to adapt their governance and compliance strategies to address these emerging liabilities will find themselves unprepared for the significant legal and financial fallout that awaits. The time for a thorough risk assessment and the implementation of robust controls is now, before these potential liabilities become an unavoidable reality.

By