All posts
Governance

Are AI Meeting Notetakers Safe? The Compliance Risk Hiding in Your Zoom Calls

ShieldWays Team5 min read

Somewhere in the last two years, a third participant started showing up to nearly every video call: a small icon labeled "Otter," "Fireflies," or "Fathom," quietly recording, transcribing, and summarizing the conversation. Adoption happened fast and mostly without anyone asking permission from legal or security teams first — one employee added a notetaker bot to their calendar, it worked well, and it spread.

That casual adoption is now colliding with a wave of real litigation. Two of the largest AI notetaker vendors are currently defending lawsuits over exactly how their bots collect and retain data from meeting participants who, in many cases, never agreed to anything. This is not a hypothetical compliance exercise anymore — it is active federal litigation, and it exposes a category of legal risk most companies have not mapped.

What these bots actually collect

The instinct is to think of an AI notetaker as a fancier version of a transcript — text in, text out. But several of these tools do not just transcribe speech; they process and store the underlying audio characteristics of a persons voice, sometimes described in litigation as a "voiceprint." That distinction matters enormously under privacy law, because a voiceprint is treated as biometric data in the same legal category as a fingerprint or a retina scan in states that regulate biometrics.

A December 2025 class action complaint filed in the U.S. District Court for the Central District of Illinois — Cruz v. Fireflies.AI Corp. — alleges the company collected and stored voiceprints from meeting participants without the safeguards Illinois law requires. According to reporting on the complaint from the National Law Review and Top Class Actions, the suit alleges Fireflies violated the Illinois Biometric Information Privacy Act (BIPA) in three specific ways: it never published a legally required retention schedule and destruction policy for biometric data, it never informed participants in writing that their voiceprint was being collected or why, and it never obtained a written release — including from people who were simply present in a recorded meeting and had no Fireflies account at all.

The lawsuits are no longer hypothetical

The Cruz case is part of a broader pattern legal publications have started calling an uptick in BIPA litigation targeting AI note-taking software specifically, not an isolated incident against one vendor. Otter.ai, meanwhile, is facing four separate lawsuits consolidated into one federal case in the Northern District of California, centered on a related but distinct problem: recording and analyzing meeting participants who never explicitly consented to being recorded at all, biometric data aside.

What makes the Fireflies case notable is who the plaintiff is. The named plaintiff was not a paying customer who agreed to a terms of service — she was a participant in a nonprofit meeting someone else recorded, with no Fireflies account of her own. That is the crux of the exposure: the legal risk does not attach only to the company that bought the notetaker subscription. It attaches to every meeting where the bot was present, including with external clients, candidates, and partners who had no relationship with the vendor and no opportunity to decline.

The all-party consent trap

Separate from biometric law, most U.S. states are "one-party consent" states, meaning only one person on the call needs to agree to a recording. But a meaningful cluster of states require every participant to consent — and getting this wrong is not a civil footnote in some of them, it can carry criminal exposure.

The states that generally require all-party consent for recording remote or telephonic conversations include:

  • California
  • Connecticut
  • Delaware
  • Florida
  • Illinois
  • Maryland
  • Massachusetts
  • Montana
  • Nevada
  • New Hampshire
  • Pennsylvania
  • Washington

Legal guidance on this point is blunt: using an AI meeting recorder without securing consent from every participant can trigger felony-level exposure in most of these jurisdictions, not just a civil claim. And because video meetings routinely mix participants from multiple states, the safe operating assumption — the one several law firms are now advising clients to adopt — is that if even one participant is in an all-party-consent state, everyone on the call needs to consent, every time, regardless of where the meeting organizer is sitting.

Why enterprise IT and legal teams are pulling back

None of this is stopping adoption at the individual level. Fireflies advertises significant Fortune 500 penetration, and Otter has reportedly transcribed well over a billion meetings to date. The tools are genuinely useful, which is exactly why they spread bottom-up before anyone in security reviewed them.

But the tide inside larger organizations is turning. Industry coverage in 2026 has repeatedly noted that enterprise IT departments and legal teams are increasingly restricting or banning cloud-based recording bots outright — citing both the consent litigation above and a second concern: what happens to the recorded content afterward, including whether it is retained or used to train the vendors own models. That second concern is precisely why a bot-free architecture is gaining ground as the safer default for regulated or risk-conscious teams: if there is no third-party bot in the call and no meeting audio ever leaves the device to begin with, there is no voiceprint to collect, no recording to misuse, and no consent question to get wrong in the first place. ShieldWays Notetaker Guard is one example of this shape — it produces meeting notes on-device, with PII redacted before anything is stored, and no external bot ever joins the call.

The broader lesson from the Fireflies and Otter litigation is not that AI meeting notes are a bad idea. It is that the convenience of a bot joining silently was never actually free — someone was always going to have to answer for what it collected, and in 2026, that bill is starting to come due.

Related posts