· By Marcus Webb

The Otter.ai Ruling Every AI Notetaker Vendor Should Be Reading

On 13 August a federal judge let most of the privacy claims against Otter.ai proceed — and the reasoning applies to almost every meeting assistant on the market, not just Otter.

On 13 August 2026, Judge Eumi K. Lee of the Northern District of California ruled on Otter.ai’s motion to dismiss in In re Otter.AI Privacy Litigation. She granted it in part and denied it in part. The coverage focused on the score — Otter mostly lost — but the score is the least interesting thing about the decision.

The interesting part is a single line of reasoning that has very little to do with Otter specifically, and quite a lot to do with how nearly every AI meeting assistant is built.

What was decided

Five claims survived: the federal Electronic Communications Privacy Act, California’s Invasion of Privacy Act wiretapping provisions, the Illinois Biometric Information Privacy Act, unjust enrichment, and California’s Unfair Competition Law.

Three were dismissed: the Computer Fraud and Abuse Act, California’s Comprehensive Computer Data Access and Fraud Act, and the Washington Privacy Act. The common-law privacy claims of every plaintiff but one also went.

Two things to be clear about before going further. This is a pleading-stage ruling. It decides that the plaintiffs alleged enough to proceed to discovery. It does not decide that Otter broke the law, and Otter may well prevail on the merits. And the case is not new — it began as Brewer v. Otter.ai and was consolidated from four separate 2025 suits in October of that year.

The facts that got it here are worth recalling, because they are so ordinary. Justin Brewer, the named plaintiff, had never signed up for Otter. He joined a sales call in February 2025 where another participant was running OtterPilot. He had no account, no privacy policy presented to him, no notice, and no opportunity to decline. His conversation was recorded anyway.

That is not an exotic scenario. That is Tuesday.

The holding that generalises

Here is the part vendors should be reading closely.

California’s CIPA section 631 targets, among other things, third parties who eavesdrop on a communication. The natural defence for a software vendor is that it is not a third party at all — it is a tool, an extension of the customer who deployed it, in the same way a telephone or a notepad is. Courts have accepted versions of that argument before. It is the reason most people assumed this claim would fail.

The court did not accept it here. It held that Otter can be treated as a third-party eavesdropper because it independently collects, retains, and uses the communications for its own commercial purposes rather than merely passing them through on the customer’s behalf.

Read that again with your own vendor in mind. The distinction the court drew is not about bots. It is not about notification. It is not about California. It is about whether the vendor does something with the recording for itself.

Training a model on customer conversations is exactly that. So is retaining recordings indefinitely to improve a product. So is analysing them in aggregate to build features. A tool that transcribes and hands the result back looks like a tool. A tool that keeps a copy and mines it looks, on this reasoning, like a participant with its own interests.

Why this lands where it lands

Of the 28 AI meeting assistants we rank, several train on customer data by default unless the user finds and flips a setting. Otter.ai does. So does Granola, which trains on anonymized data unless you switch it off in Settings, and Notta, which has been reported to train on Japanese-language conversations with the opt-out gated to Enterprise.

We built a criterion for this into our methodology last year — data retention and training transparency, weighted at double — precisely because we thought the training default was underweighted by buyers relative to its risk. That judgement now has a published court decision behind it, which is not something we expected quite this fast.

The tools that look best after this ruling are the ones that made the opposite architectural choice. Circleback and Jamie both state plainly that they do not train on customer data, and Jamie deletes meeting audio after transcription. Fathom has the same no-training commitment. Those are contractual and procedural positions, and they are the right ones.

The strongest position is not contractual at all. Hedy can run its full pipeline — transcription, summarisation, and real-time analysis — on-device on supported hardware. A vendor cannot independently collect, retain, and use communications it never receives. Whatever else is true, that is a structurally different exposure than a promise not to look.

The other thing vendors should notice

Bot-free capture is having a moment, and this ruling complicates the marketing around it in a way worth naming.

Recording without a bot is not itself a problem. Several tools we rate highly capture from the user’s own device, and doing so avoids the meeting-platform friction that has made bots increasingly unwelcome. But the absence of a bot means the absence of an announcement, and the absence of an announcement means the other participants may not know.

Some vendors handle this responsibly, pairing bot-free capture with clear guidance that the user must disclose. At least one — Bluedot — actively markets its invisibility to other participants as a selling point, and suggests it for job interviews and investor calls. After a ruling that turned on non-consensual capture of someone who had never agreed to anything, that positioning looks less clever than it did in July.

If you deploy a bot-free tool, say out loud at the start of the call that you are recording, and note the agreement. In all-party consent states — California, Illinois, Pennsylvania and others — that is not etiquette, it is the law. Under GDPR, one participant’s consent has never covered the rest of the room.

What to do this quarter

Find out whether your assistant trains on your conversations, and whether that is the default. Not what the marketing page implies. What the data processing terms say. If it is opt-out, someone in your organisation has almost certainly not opted out.

Check your retention setting. Indefinite retention is the second half of the “collects, retains, and uses” formula.

Write down your disclosure practice. If you use bot-free capture, the obligation to tell people sits with your staff, and staff need to know that.

Ask about Illinois. BIPA survived here, and BIPA has a private right of action with statutory damages. Any tool doing voiceprint-based speaker identification on Illinois residents deserves a specific conversation.

The direction of travel

Two weeks before this ruling, the EU AI Act’s enforcement provisions came fully online, including a workplace prohibition that consent cannot cure. Now a US court has held that what a vendor does with a recording can determine whether it was eavesdropping in the first place.

These are different legal systems reaching for the same idea from opposite ends. Both are moving away from “did someone click accept” and toward “what does this software actually do with what it hears.” That is a harder question to paper over, and it rewards products designed to need less.

The meeting assistant category grew up in a period where recording everything and sorting out the governance later was a viable strategy. That period is closing.


This is analysis, not legal advice. If your organisation records meetings across multiple jurisdictions, take advice specific to your deployment.