The Privacy Paradox: Navigating the Legal Minefield of AI Notetaking Tools
In the modern digital workplace, the allure of AI-driven productivity is undeniable. Tools that automatically record meetings, generate granular transcripts, and distill complex discussions into actionable to-do lists have become standard equipment for millions of professionals. Yet, this efficiency has triggered a growing legal backlash. As AI notetakers proliferate, a wave of high-profile lawsuits is challenging the core practices of these platforms, forcing organizations to reconsider the intersection of convenience and compliance.
Brian McGinnis, a partner at the law firm Barnes & Thornburg and co-chair of its Data Security and Privacy Law practice group, suggests that we are at a critical inflection point. "The common allegation," McGinnis explains, "is that these companies capture communications of people who did not agree to the recording or receive adequate notice." As the legal system grapples with these claims, businesses are finding themselves caught in the middle, forced to balance the benefits of AI against the risks of violating stringent privacy statutes.
The Chronology of Conflict: A Rising Legal Tide
The legal challenges surrounding AI notetakers are not merely theoretical; they are rapidly evolving into a significant body of case law.
The trouble began in earnest last year when Otter.ai, a market leader boasting over 35 million users, faced a federal class-action complaint in California. The suit alleged that the company was recording participants without their explicit consent and, more controversially, using the captured audio to train its proprietary speech-recognition models. While a judge recently narrowed the scope of the case, the survival of the core claims signals a robust judicial appetite for examining the boundaries of AI data processing.
Following this, late last year, Fireflies.ai—which supports over 20 million users and one million organizations—was hit with a lawsuit in Illinois. The complaint alleges that the company violates the Illinois Biometric Information Privacy Act (BIPA) by collecting and storing biometric voiceprints without proper authorization.
The scope of these legal battles widened earlier this year when a class-action complaint filed in Washington challenged Microsoft Teams. The plaintiffs argued that the platform’s live transcription features function as an unauthorized collection of biometric data. Most recently, the startup Granola faced allegations that its product was intentionally designed to operate in stealth mode, bypassing participant awareness and violating the federal Electronic Communications Privacy Act (ECPA).
The Legal Landscape: Wiretapping and Biometrics
At the heart of these lawsuits are two primary legal battlegrounds: federal and state wiretapping laws, and the burgeoning field of biometric privacy regulations.
The Wiretapping Debate
The Electronic Communications Privacy Act (ECPA) is the primary federal statute governing the interception of communications. Under federal law, "one-party consent" is generally sufficient, meaning that if one person on a call consents to the recording, the act is typically considered legal. However, as McGinnis points out, this creates a conflict with "two-party" or "all-party" consent states, such as California.
"California and a minority of other states are what we call ‘two-party consent’ states," McGinnis explains. "It’s not sufficient for you as the person who turns the notetaker on to provide the consent—you also have to get the consent of others." The California Invasion of Privacy Act (CIPA) has become a favored tool for plaintiffs’ attorneys, who are effectively retrofitting a statute originally designed for telephone wiretapping to address the nuances of modern internet-based communication.
The Biometric Frontier
The Illinois Biometric Information Privacy Act (BIPA) represents a much more potent threat to tech vendors. Because BIPA includes a "private right of action," individuals can sue companies directly for damages.
"With an audio recording or ‘dumb’ video that isn’t running any algorithms, you’re not necessarily collecting any biometrics," says McGinnis. "But when you start identifying people—recording things like faceprints or voiceprints—you are collecting highly sensitive information." When AI tools process audio to create a unique voiceprint, they cross the threshold into biometric data collection, triggering strict disclosure and consent requirements that many platforms are currently failing to meet.
The "Silent" Threat: AI Wearables and Future Risks
The current litigation is likely just the "first wave" of a larger shift in privacy law. While the focus remains on desktop software for virtual meetings, the technology is moving into the physical world.
"We are moving from an online meeting where you can provide notice and there’s a structure to obtain consent, to walking down the sidewalk and recording people," notes McGinnis. Devices like smartglasses or small, "always-on" recorders that attach to smartphones represent a new frontier. These devices lack the digital interface—the "pop-up" window—that allows for easy, informed consent.
If courts eventually rule that tools like Granola are illegal due to their lack of transparency, it could set a precedent that extends to wearable AI. The legal system will soon be forced to decide if the convenience of ambient recording outweighs the expectation of privacy in public and semi-public spaces.
Corporate Implications: Implementing Safe AI Policies
For businesses, the uncertainty is a major point of anxiety. Many firms are eager to leverage AI to boost productivity but are terrified of the liability associated with these tools. McGinnis advises that companies cannot simply rely on the "out-of-the-box" settings provided by software vendors.
Strategies for Corporate Compliance:
- Prioritize the Most Stringent Law: When dealing with multi-state operations, businesses should adopt the most restrictive standard. If a company operates in Illinois or California, they should mandate all-party consent for all meetings, regardless of where the participants are located.
- Mandate Transparency: Relying on automated, background recording is a liability. Policies should require that notice be given verbally at the start of every meeting, with a clear opportunity for participants to opt-out.
- Governance and BYOD Policies: Companies must treat AI notetakers with the same rigor as Bring Your Own Device (BYOD) policies. An internal "AI Usage Policy" should clearly state which tools are approved, which features (such as data training) must be disabled, and what happens to the resulting transcripts.
- Review Vendor Settings: As noted with apps like Granola, many tools ship with privacy features—like visual watermarking or recording notifications—disabled by default. It is the responsibility of the enterprise to ensure these settings are active before deployment.
Conclusion: The Path Forward
It is unlikely that the courts will issue an outright ban on AI notetakers. The technology is too deeply embedded in the modern corporate workflow. However, a shift toward mandatory, affirmative, opt-in consent appears inevitable.
"The notion that only one person in the meeting has to say it’s okay and you can just automatically record everybody else—I think that’s probably at risk," McGinnis concludes. As the law catches up to the pace of innovation, the companies that succeed will be those that prioritize transparency and user agency. For now, the safest path for any organization is to assume that if you are not getting explicit, documented consent from every participant in the room, you are operating in a high-risk legal zone. The future of AI in the workplace will not be defined by the sophistication of the algorithms, but by the strength of the consent frameworks surrounding them.