The Fourth Participant in Your Meeting Is a Company, and in a Dozen States That's a Wiretap.
Everyone agreed to a colleague taking notes. Nobody agreed to a vendor keeping the recording — and in roughly a dozen states, one host's click may not be consent at all.
About a year ago I put the pen down.
Not metaphorically. I had taken notes in meetings for two decades — a spiral notebook, one page per meeting, initials in the margin beside whoever owed what. Then a notetaker joined a call and produced a tidy summary eleven seconds after we hung up, and I felt something I want to name precisely, because it is the whole subject of this piece: relief. I trusted it immediately and completely. For three weeks I told anyone who would sit still how much better I was listening.
Here is the part I am less proud of. I was the host on most of those calls. Somewhere in a settings panel is a toggle that makes the assistant join every meeting automatically, and I turned it on once, on a Tuesday, while running late for something else. Every person who joined a meeting of mine from that Tuesday onward had their voice recorded and sent to a company they had never heard of — because I had clicked something. Nobody asked them. I did not experience it as a decision at all. I experienced it as a setting.
On August 13, 2026, a federal judge in San Jose declined to make a lawsuit about exactly that distinction go away.
What the judge did, and what she pointedly did not do
Judge Eumi K. Lee, of the federal district court in San Jose, allowed the core privacy claims to proceed against Otter.ai, the company behind a widely used AI meeting assistant.
Otter had asked the court to throw the case out. The judge refused in substantial part: the wiretapping and privacy claims under the federal Electronic Communications Privacy Act, the California Invasion of Privacy Act and the Illinois Biometric Information Privacy Act all survive. She also dismissed the computer-hacking claims and several narrower privacy counts, with permission to amend. That is a mixed ruling, and anyone telling you Otter lost is describing something that has not happened.
More importantly — and I cannot stress this enough — nothing here has been proven. A motion to dismiss asks one narrow question: if everything the plaintiffs say turned out to be true, would that be against the law? Everything below is still an allegation in a live case. At the hearing this month the judge said she was "not persuaded" the plaintiffs even lacked standing — a signal, not a finding.
The part nobody really disputes: what it does, and who it asks
The mechanics are not much contested. The complaint alleges that when the assistant joins a meeting whose host has no account, it asks that host for consent and no one else, and does not let any other participant switch it off mid-meeting; and that when the host is an account holder with a connected calendar, it may join with no affirmative consent from anyone at all. The plaintiffs' account, not a court's finding — but it matches the reporting. The Register wrote that the suit says the tool records account holders and guests alike, and that the guests are never asked before their voices are recorded or fed into a machine learning model.
The vendor's own documents are more interesting. Otter's privacy policy, updated June 16, 2026, lists among its purposes training its proprietary AI on de-identified audio recordings and on transcriptions — and asks the account holder to "please make sure you have the necessary permissions from your co-workers, friends or other third parties." The consent problem, handed to the customer. Its security page does say "No" to a training question, and the scope of that sentence does enormous work: imported customer data will not be used to create, train or improve its models, the example given being "imported documents from Google Workspace." That is an answer about documents you upload, not about the audio of your meeting.
The structural break from a tape recorder: record a call the old way and the recording sits with whoever made it. But with AI, the vendor also has access to recordings. The fourth participant in your meeting is a company, and it keeps a copy. At scale: Otter told NPR in August 2025 that some 25 million people used its tools across more than a billion meetings since 2016; by April 28, 2026 its blog said more than 35 million people, across over one billion meetings — the company's own figures, a year apart.
In fairness: a spokesperson told Computerworld that "nobody should be recorded without their knowledge or permission, regardless of the recording device used." NPR, reporting the suit the day it was filed, noted that Otter did not return its request for comment.
The law is not one law. It is a federal floor with a dozen or so trapdoors.
Federal law sets the floor, and it is permissive: under the Wiretap Act it is not unlawful for a party to a conversation, or for someone with one party's prior consent, to intercept it — unless the purpose is criminal or tortious. One party is enough. California is not one party: its eavesdropping statute punishes recording a confidential communication without the consent of all parties, up to $2,500 per violation.
How many states like that? Here I have to be honest rather than tidy: the sources disagree. Employment lawyers at Littler, writing on February 26, 2026, call wiretap laws the greatest risk for US employers using these tools and say about a dozen states require the consent of all parties. A recording-law reference counts twelve while conceding on the same page that the exact number is debated because some states run mixed rules. The Reporters Committee for Freedom of the Press counts "about 11 states primarily", with a partly different list. So: roughly a dozen — and which dozen depends on who is counting.
That fuzziness is not academic. As two attorneys wrote in December 2025, in a note titled eavesdropping by algorithm, a lawful recording in a one-party state may become illegal if even a single participant joins from an all-party jurisdiction.
Then there is Illinois, which regulates the body rather than the wire. Under its biometric privacy act a voiceprint is a biometric identifier, and no private entity may collect one without first informing the subject in writing of the purpose and retention period and obtaining a written release. Which is why this is spreading past one company: a parallel Illinois suit alleges a competing assistant stores the vocal characteristics of every participant, including people who never created an account. Privacy attorney Joseph Lazzarotti made the mechanical point in April 2026 — a speaker-recognition feature necessarily generates voiceprints — and Fisher Phillips attorney Danielle Kays calls these tools the latest target of Illinois BIPA class actions.
It all funnels into one question: is the assistant a tool the customer holds, or a third party in the room? Plaintiffs cast it as a third-party eavesdropper rather than a passive tool, because the audio lands on the vendor's servers and trains the vendor's systems. The defense says it sits on the tool side, having obtained consent, at most, from the meeting host.
Now the other side, which is stronger than you would like
Here is the counter-case at full strength — not silly, and it might win. The broad objection is that these are old statutes re-aimed at new technology. As a privacy analyst argued for the IAPP in November 2025, laws written decades ago for telephone lines have found fresh significance against automated systems — an evolution spurred by a creative plaintiff's bar.
The specific defense that could end this is sharper. The Ninth Circuit has held that a party to a conversation cannot be liable for "eavesdropping" on its own conversation under California's statute, analogizing the software at issue to "a person recording a phone call using a tape recorder." If the vendor is the customer's tape recorder, the customer is a party, and a party cannot eavesdrop on itself. Courts have bought that before.
There is a policy critique too. California's statute carries $5,000-per-violation statutory damages, which a June 2026 analysis blames for countless demand letters and class actions over ordinary technology; a state bill would carve out a "commercial business purpose" exception. A business coalition launched in April 2026 puts it plainer: predatory lawsuits under an outdated act.
Every one of those can be right and the thing that bothers me can still be true. The party exception answers a legal question — third party, or tape recorder? It does not answer the human one: what five people in a room owe each other when one of them has clicked something.
France runs this argument in the opposite order
Change countries — not because one side wins, but because the sequencing differs.
Kill the myth first: France does not ban this. The CNIL, the French data protection regulator, lets employers install an occasional listening or recording system to train or evaluate staff. What it prohibits is the permanent or systematic recording device — "un dispositif d'écoute ou d'enregistrement permanent ou systématique." Its simplified norm excludes such recording even "à des fins probatoires", for evidentiary purposes, though that document now notes CNIL norms lost legal force on May 25, 2018. The workplace guidance adds two requirements that read, from here, like science fiction: staff representative bodies "doivent être informées et consultées avant toute décision," informed and consulted before any decision to install one; and the person on the other end must be told of their right to object "avant la fin de la conversation," before the call ends, so they can actually exercise it. Hold that next to a pop-up banner and a host's checkbox.
The rest runs the same way. Any monitoring device must be disclosed to the people concerned before it is put in place, the works council must be consulted in private companies of fifty or more, and the device must be proportionate — not regulator invention but Article L1222-4 of the Code du travail: no information about an employee may be collected by a device not disclosed to them beforehand. Ask the regulator directly and the answer is blunt: an employer has neither the right to record nor to listen to employees' phone calls if they have not been informed. And it is enforced — in eleven sanctions announced on October 8, 2024, the CNIL held that improving sales and training staff "ne justifie pas d'enregistrer systématiquement et en intégralité les conversations téléphoniques."
Now the honest complication, because a comparison that flatters one side is not worth writing. On December 22, 2023 the Cour de cassation, in plenary session, reversed its own case law, holding that unfairly obtained evidence — a covert recording included — can be produced in civil proceedings where it is indispensable and the interference strictly proportionate. France's rules about collecting are stricter than America's; its rule about what a court will look at afterward just got looser. Anyone selling you France as uniformly stricter has not read the case.
What arrives next matters more. The CNIL's work plan for 2026, published April 7, 2026, commits it to clarifying the conditions for automatic transcription and analysis tools — naming call centers and, explicitly, videoconferencing software. And under the EU AI Act, as the ETUI's Aida Ponce Del Castillo noted in January 2026, AI used for worker management and monitoring is classified as high-risk under Annex III, with obligations on whoever deploys it even when the provider sits outside the EU.
So: not prohibition versus permission, but when the argument happens. There, justification, notice, consultation and deletion come before the tool is switched on. Here, they come out at deposition.
Just imagine where this goes if nobody touches it
The ambition was never "notetaker." That April 2026 blog post describes evolving toward a conversational knowledge engine for enterprises: a searchable memory of everything an organization has ever said out loud. Genuinely valuable. Also a corpus, and corpora do not forget.
Now stack the research on it. Speech anonymization is usually judged by average-case metrics, and a large per-speaker analysis submitted in June 2026 found those averages hide large disparities in re-identification risks across individuals. Translation: "anonymized" is an average, and you cannot know whether yours is one of the exposed voices. A separate paper, from a team including a NIST-affiliated researcher, found adversaries using only pre-trained models can still reliably recover soft biometric information from anonymized output: age range, dialect, sex of the speaker, speaking style.
So imagine the next five years, none of which requires new physics. A hiring manager searching the corporate transcript archive and getting a hit on a candidate from a vendor call three years ago. Performance reviews quietly informed by who talked least.
The smallest version has already happened. NPR reported the case of an AI researcher sent a transcript of the part of the meeting held after he had left — "intimate, confidential details" about a business, in his description. Those portions killed a deal. One misdirected transcript, one deal. Now multiply by a billion meetings.
What the people who actually work on this keep saying
The striking thing is how little the concern tracks ideology.
The Associated Press, reporting in July 2026 on professionals questioning these tools, framed it plainly: the technology turns everything said during meetings into data. In the same piece, Thorin Klosowski of the Electronic Frontier Foundation noted that some meeting software does not make clear when a notetaker is present; Amy Dufrane of the HR Certification Institute said there are "huge risks to the organization" in AI notetakers; and Kays advised finding out whether the companies "retain recordings, transcripts or metadata indefinitely or use them to train AI models."
The EFF's objection to biometric collection is one sentence and hard to argue with: unlike a credit card or even a social security number, your biometric data can't be revoked or re-issued. The ACLU frames the pattern above it — deployment of surveillance technologies happens faster than our social, political, educational, or legal systems can react.
And from the other end of the spectrum, the R Street Institute — which wants fewer state privacy statutes, not more — calls the increasing patchwork of state privacy laws a real problem for industry and argues for one federal law instead. Notice what that concedes. Nobody here thinks the current arrangement works; they disagree about who should fix it, not whether it is broken.
What does this mean for you?
Practical, and mostly free:
If you are the host, you are the consent decision for everybody else. That is the whole lesson of my Tuesday toggle. Own it in the first ten seconds: "There's a notetaker here, it keeps a transcript, does anyone want it off?"
Turn off automatic join. Auto-join converts one past click into a standing decision about every future room. Make it a per-meeting choice, so it stays a choice.
Ask the retention question before the accuracy question. Everyone asks whether the summaries are good. Almost nobody asks how long the recording, transcript and metadata are kept, or whether they train the vendor's models. Ask in writing.
A banner is not consent. Georgetown's guidance on Zoom's own AI Companion says participants are notified with a pop-up banner when a host turns the feature on — and the options it lists for an uncomfortable attendee are to raise it with the host, limit your participation, leave, or host meetings yourself. Every one costs the participant something; none costs the recorder anything.
Check your state, then everybody else's. A fifty-state recording chart is a fair starting point, though that one was last updated in February 2022 — a map, not a legal opinion. And in Illinois the biometric statute gives you a written right: notice, purpose, retention period and a signed release before a voiceprint is collected.
If you run a business, borrow the French order of operations voluntarily. Write down why you are recording, tell everyone before you switch it on, keep the least data that serves the purpose, set a deletion date, consult the people affected. That sequence produces fewer lawsuits and fewer betrayed colleagues.
The part that will not be settled in a courtroom
Everyone on those calls had already consented to something. They had consented to a colleague taking notes — an ancient arrangement — a human being, in the room, invested in the relationship continuing, writing down what matters and forgetting the rest, including the part where somebody was unfair to their co-founder and regretted it eight seconds later.
Nobody consented to the other thing — a fourth participant with a business model, a retention schedule, a training pipeline and a corporate parent, whose memory is perfect, permanent, searchable and subject to discovery. Those two arrangements share a word, "notes," and nothing else.
The courts will resolve part of this, slowly, and either way the ruling will answer a question about laws drafted for telephone lines, leaving the interesting one untouched. Because the interesting question was never whether it is legal in your state. It is whether you would say it out loud. If the answer is yes — "I'm recording this, a company keeps a copy, all right with everyone?" — say it, and the problem evaporates in five seconds. If the answer is no, then you already know what you are doing, and no settings panel is going to absolve you of it.
I put the notebook back on the desk, by the way. Not out of principle; the summaries really are good. I just wanted to go back to being someone who decides.
Say the bot's name out loud at the top of your next call and ask whether anyone minds. Five awkward seconds is a bargain price for consent — and if that landed, forward this to whoever schedules your meetings.





