Your AI Notetaker Recorded a Meeting Without Everyone's Consent. In California, That's a Crime
Hybrid / Non-FEHA Claims

Your company uses Otter.ai for meeting transcripts, Fireflies, Fathom, or the built-in recording feature in Zoom, Teams, or Google Meet configured to auto-record. Each of those tools may create legal risk if used in a meeting with California participants who did not meaningfully consent to being recorded.
This is not a theoretical concern.
As of August 2025, at least four proposed class action lawsuits had been filed against Otter.ai in the U.S. District Court for the Northern District of California, alleging violations of federal and California wiretapping and privacy laws. A separate proposed class action was filed against Fireflies.ai in December 2025 alleging biometric privacy violations under Illinois law. Microsoft also faces separate biometric privacy litigation concerning Teams.
This guide explains what California's recording law actually requires, how it applies specifically to AI notetakers, what the current lawsuits signal for employers, and what you must do right now to protect your business.
Key Takeaways
California is a two-party consent (all-party consent) state under CIPA (Cal. Penal Code §§631–632). Every meeting participant must consent before any recording occurs, including AI transcription.
California's standard applies wherever a California participant is located. Your company's headquarters state is irrelevant.
CIPA violations are criminal (misdemeanor) and civil ($5,000/violation), multiplied per participant, per meeting.
A visible bot name in a participant list is NOT sufficient consent under California law.
The employer who deploys the AI tool is in the liability chain.
Explicit verbal or written consent before recording begins remains the most conservative and legally defensible approach to compliance for meetings involving California participants.
Is California a Two-Party Consent State for Recording?
Yes. California is one of the strictest recording consent states in the country.
Under California's Invasion of Privacy Act (CIPA), recording a confidential conversation requires the consent of every participant. This is called all-party consent or two-party consent, and it covers:
In-person conversations
Telephone calls
Video meetings
Electronic communications
Where participants have a reasonable expectation of privacy.
The critical difference between California vs. federal law:
Standard | Law | What It Requires |
|---|---|---|
Federal (ECPA) | 18 U.S.C. §2511 | One party's consent is sufficient |
California (CIPA) | Cal. Penal Code §§631–632 | ALL parties must consent |
Federal law generally allows one-party consent, meaning the meeting host's consent alone may be sufficient in most states. California refuses to follow that standard.
The California law applies to your employees, not to your company's location. Even if your business is headquartered in Texas or New York, if a meeting participant is in California, California's all-party consent requirement applies to that meeting. With remote workforces spread across states, this means California's stricter standard effectively governs any meeting that includes a California resident.
The penalties are not administrative fines. They are criminal.
Violation Type | Consequence |
|---|---|
Criminal (first offense) | Misdemeanor - up to 1 year imprisonment + $2,500 fine |
Civil - CIPA §637.2 | $5,000 per violation OR 3x actual damages (whichever is greater) |
Civil - ECPA | $10,000 per violation OR $100/day |
Attorney's fees | Awarded to prevailing plaintiff |
Each meeting participant who was recorded without consent represents a separate violation. Multiply $5,000 by the number of participants across months of recordings, and you see why these class action complaints are filed.
How AI Notetakers Create Employer Liability Right Now
Traditional recording consent violations were relatively straightforward: someone hit record on a phone without telling the other person. AI notetakers created a new problem: tools that join meetings automatically, often without the host even realizing they are recording every participant who walks in.
The plaintiffs allege that Otter effectively acted as an unauthorized third-party eavesdropper, intercepting communications and repurposing them for product training without consent.
The consolidated Otter.ai litigation bundles four separate lawsuits filed between August and September 2025:
1.
Brewer v. Otter.ai (Aug 15, 2025):
plaintiff never had an Otter account. He was in a sales call where the other participant had OtterPilot running. He had no notice, no chance to decline, no account, no terms of service. The recording happened anyway.
2.
Walker v. Otter.ai (Aug 26, 2025):
adds biometric voiceprint collection claims under Illinois BIPA.
3.
Theus v. Otter.ai (Sept 3, 2025):
alleges Otter joins as a "silent participant," capturing audio, screenshots, and calendar data without disclosure.
4.
Winston v. Otter.ai (Sept 10, 2025):
alleges Otter sends follow-up emails with partial transcripts to all meeting invitees, even those who never attended.
As Zoom, Teams, and Google Meet have quickly become the default way we gather, a new trend has emerged: many virtual meetings now end up being "attended" by more AI notetakers, like Fireflies.ai or Otter.ai, than actual people.
What makes this an employer liability problem:
The account holder who deployed OtterPilot is the employer. The employer enabled the tool, integrated it with their calendar, and pointed it at their meetings. The fact that the software vendor also has independent liability does not remove the employer from the chain of exposure.
Relying on account holders to provide notifications, rather than on proactive disclosures by the service itself, may not be sufficient, especially for organizations with participants in "two-party consent" states.
The "Capability Test": The Legal Theory That Changes Everything
The most important legal development for employers to understand is the "capability test" emerging from Ambriz v. Google LLC and applied in the Otter.ai litigation.
Traditional CIPA analysis asked: did the vendor actually intercept and use the communication? The capability test asks a different question: does the vendor have the capability to use your data, even if it chooses not to?
Courts are now "grappling with how to classify AI transcription tools: Are they third parties or merely software tools?" The firm emphasized that plaintiffs recently survived a motion to dismiss, in which the court found that a vendor's "mere capability to use the data for its own purposes was sufficient to implicate CIPA liability."
This matters for employers because Otter.ai's own terms of service reserve the right to use de-identified data for model training, precisely the type of "capability" courts are treating as sufficient for liability. The vendor's defense is that it didn't actually use the data improperly. The court's emerging standard is that having the right to use it is enough.
If this theory is confirmed at the May 20, 2026 hearing, it has sweeping implications: nearly every cloud-based AI meeting tool that reserves training rights in its ToS could expose California employers to CIPA liability for meetings with California participants.
What Does NOT Constitute Valid Consent Under California Law
Most employers using AI notetakers believe they are covered by one of these scenarios. None of them reliably satisfy California's all-party consent standard.
"The bot is named 'Otter.ai Notetaker' in the participant list." A visible bot name in a participant list is likely insufficient. Simply having a bot join the meeting with a visible name, such as "Otter.ai Notetaker," may not provide adequate notice to obtain consent, particularly if participants do not understand what the bot is doing.
"The Zoom platform shows a recording indicator." Platform recording indicators may satisfy implied consent if participants are clearly informed and choose to remain, but this analysis is fact-specific and contested. It is not a guaranteed safe harbor.
"Our Terms of Service mention AI tools." If the participant has not agreed to your ToS, it cannot bind them. Employees in meetings, external vendors, and candidates in interviews are common examples of participants who have not signed your ToS.
"We only use AI tools for our own employees." Employees have California privacy rights too. Using an AI notetaker in a performance conversation, HR meeting, or disciplinary discussion without obtaining explicit consent creates exactly the type of CIPA liability CIPA was designed to address.
For broader context on the intersection of employer privacy obligations and workplace investigations, read At-Will Employment in California: What Employers Are Actually Protected From.
The Employer Compliance Framework: How to Set it Up
Step 1: Audit your current AI tools immediately.
List every AI-powered meeting, recording, or transcription tool your company has deployed or approved: Otter.ai, Fireflies, Fathom, Gong, Chorus, Zoom AI Companion, Teams Copilot, Google Meet transcription. For each tool, document whether it auto-joins. Does it notify all participants? Does it record by default or only on demand?
Step 2: Obtain explicit consent before every recording.
The safest standard under California law is explicit verbal or written consent from every participant before recording begins. The safest approach under California law is to obtain explicit verbal or written consent from all participants before activating any recording or AI transcription tool.
Practical consent mechanisms by meeting type:
Meeting Type | Recommended Consent Method |
|---|---|
Internal team meetings | Written policy in employee handbook + verbal announcement at meeting start |
Client or vendor calls | Pre-meeting email notice + verbal announcement before recording starts |
HR/disciplinary meetings | Written consent form signed before meeting begins |
Candidate interviews | Consent statement in interview invitation + verbal confirmation |
Customer service calls | Automated pre-call announcement before connection |
Step 3: Update your employee handbook with a recording policy.
Your handbook should specifically address: (a) what AI tools the company uses, (b) when recordings occur, (c) how participants will be notified, and (d) what happens when a participant declines consent.
Step 4: Configure your tools; don't rely on defaults.
Otter.ai's auto-join feature was enabled by default and, according to complaints, continued to join meetings even after users attempted to turn it off. Actively configure your tools to:
Require manual activation (not auto-join)
Display clear recording notifications to all participants
Provide an opt-out mechanism before recording begins
If a tool cannot be configured to notify all participants without upgrading to an enterprise plan, that default setting is a liability you are inheriting.
Step 5: When a participant declines consent, stop recording.
If any participant declines to be recorded, stop the recording. Document the declination. Continue the meeting through other means, such as notes, written summaries, and post-meeting documentation. Attempting to override a refusal or secretly continuing the recording is the exact violation you are trying to avoid.
Step 6: Train your managers.
The employee who enables OtterPilot on a call with a vendor who didn't consent, or the manager who auto-records a performance meeting without notifying the employee. These are ground-level decisions that generate CIPA exposure. Training must reach the people making those decisions.
What Happens When You Receive a CIPA-Based Demand or Complaint
CIPA violations do not require the recording to be used harmfully. Recording without consent is itself the violation. A demand letter or lawsuit can arrive from a meeting participant who simply discovered they were recorded.
If that happens:
Preserve all documentation: the tool's access logs, consent records, policy documents, and any communications about the specific meeting
Do not delete recordings or tool configurations. Preservation is mandatory from the moment you receive notice
Do not contact the complainant directly about the claim
Engage employer defense counsel immediately
At DefendMyBiz, we represent California employers exclusively. CIPA-based employee privacy claims often accompany broader FEHA and hybrid claims, and the same documentation gaps that create CIPA exposure frequently appear across multiple claim categories at once. Our employer defense attorneys assess your actual liability, identify your strongest defenses, and build a strategy around your specific facts.
The DefendMyBiz Hybrid/Non-FEHA Claims defense team handles CIPA-based privacy claims as part of broader employer defense.
Book a free 15-minute consultation. If your company uses AI recording tools in meetings with California participants and you have not yet built a consent framework, get a direct assessment of your exposure now.
FAQ
Is California a two-party consent state for recording?
Can I sue someone in California for recording me without my permission?
Do you have to tell someone they're being recorded in California?
Does California's recording law apply to AI transcription tools?
What if meeting participants are outside California?
Disclaimer: The above content is for informational purposes only. This is not legal or tax advice. Laws, IRS guidance, and withholding requirements can change, and outcomes depend on specific facts. You are advised to contact a qualified attorney for any legal advice.


