August 6, 2026
ai-meeting-notetakers-face-mounting-legal-scrutiny-over-consent-and-data-training-sparking-hr-concerns

A proposed class action lawsuit filed on July 30 in the U.S. District Court for the Northern District of California has accused Granola, a venture-backed artificial intelligence (AI) meeting notetaker, of recording conversations without adequately informing most participants and, by default, feeding those recordings into its proprietary AI model for training. This new litigation, Chamberlain v. Granola, mirrors an earlier consolidated case, Otter.AI Privacy Litigation, in the same district, which similarly alleges that Otter.ai recorded private conversations without the explicit consent of all participants and subsequently used this sensitive audio to train its AI models. Both cases are currently navigating pre-trial motions and the complex process of class certification, signaling a pivotal moment for the burgeoning AI notetaker industry and the broader landscape of workplace technology.

The Granola Allegations Unpacked: Intentional Opacity?

The complaint against Granola highlights specific language from the company’s own marketing materials, which the plaintiffs argue reveals a deliberate design choice to obscure the presence of the AI notetaker. The filing quotes Granola’s website as explicitly stating to prospective customers that "other people on a call won’t know it’s there" and posits that visible recording indicators tend to alter participant behavior in critical discussions such as interviews and client conversations. Attorneys for the plaintiffs contend that this language underscores a conscious decision to forego clear disclosure, rather than an accidental oversight, thereby potentially violating privacy statutes. This specific point of contention could be particularly damaging for Granola, as it suggests a knowledge of the non-disclosure and its potential impact.

Bradford Kelley, a shareholder at Littler Mendelson who has been advising employers on the implications of the Otter.ai litigation, emphasized the gravity of these issues to HR Executive in April. "The AI transcription and recording issue is a hot issue," Kelley stated, underscoring that human resource teams should be "very interested in this case." His observation reflects a growing unease among businesses regarding the legal and ethical implications of deploying AI tools that interact with sensitive conversational data.

A Precedent in the Making: The Otter.ai Litigation

The Otter.AI Privacy Litigation has been underway for some time, setting a crucial precedent for the Granola case. Filed in the same federal district, it consolidated multiple complaints alleging similar privacy violations. The core of these allegations revolves around the recording of private conversations without explicit, universal consent and the subsequent utilization of this recorded data for AI model training. The parallels between the two cases are striking, suggesting a systemic issue within the AI notetaker sector regarding consent, data utilization, and transparency. As these cases progress, they are expected to shape the legal framework and industry standards for AI-powered conversational tools. The outcomes could dictate how companies design their consent mechanisms, manage data, and market their products, potentially leading to a paradigm shift towards greater transparency and user control.

The Legal Labyrinth: Navigating Consent Laws Across Jurisdictions

One of the most significant challenges for employers adopting AI notetakers lies in the fragmented legal landscape surrounding recording consent. Consent laws are not uniform; they vary considerably by federal and state regulations within the United States, and even more so internationally. Littler Mendelson’s analysis of the Otter.ai case strongly advises employers to meticulously check every jurisdiction involved in a meeting. A single virtual meeting, for instance, could include participants from several different states or even countries, each with its own distinct consent obligations. Many employers, historically accustomed to singular office locations, have never had to map such complex, overlapping legal requirements.

The Granola complaint specifically leverages California’s Invasion of Privacy Act (CIPA), a stringent "two-party consent" law. CIPA dictates that all parties to a confidential communication must consent to its recording. Violations under CIPA can incur significant statutory damages of $5,000 per violation or three times actual damages, whichever amount is greater. Given that the Granola complaint describes a proposed class reaching into the millions, as reported by PPC Land, the potential financial liability could be astronomical, posing an existential threat to the company. This highlights the critical importance of understanding and adhering to the most restrictive applicable consent laws, particularly for companies operating in or serving residents of states with robust privacy protections.

The Peril of Passive Data Collection: Model Training and Opt-Out Defaults

A common practice among many AI notetaker platforms is to default to an "opt-out" model for data utilization, particularly concerning the feeding of recordings into their AI models for training purposes. This means that, by default, user data is used unless explicitly disabled by the account holder. The Granola complaint explicitly references the company’s own materials, which reportedly acknowledge the impossibility of confirming whether a user’s data was excluded from training that occurred before an opt-out setting was changed. Furthermore, isolating specific data from an already-trained model is often technically unachievable with current techniques.

This "opt-out" paradigm creates a significant ethical and legal dilemma. Crucially, the people whose voices are captured and subsequently used for model training are frequently not the account holder themselves. A job candidate participating in an interview, or an employee joining a colleague’s call, typically has no direct access to the notetaker’s settings and therefore no means to adjust their data preferences or opt-out of model training. This fundamental disconnect between the data subject and the control over their data is a central point of contention in both the Granola and Otter.ai lawsuits, raising serious questions about true informed consent and data autonomy.

Biometric Data: The Added Layer of Risk

Beyond the recording of conversations, the functionality of many AI notetakers introduces another layer of privacy risk: biometric data. Littler Mendelson’s analysis of the Otter.ai case specifically points out that tools attributing transcript lines to individual speakers by analyzing voiceprints may fall under various state biometric privacy laws. The Illinois Biometric Information Privacy Act (BIPA) is a prime example, known for its strict requirements regarding the collection, use, and storage of biometric identifiers and information, and for carrying its own substantial statutory damages for violations.

The Granola complaint, according to PPC Land, describes a similar speaker-attribution feature. Such features, which create unique "voiceprints" to differentiate speakers, inherently collect and process biometric data. The collection and storage of these voiceprints, even if for benign purposes like improving transcription accuracy, can trigger stringent biometric privacy regulations depending on how they operate and what specific data points they collect and retain. For companies, this means that merely obtaining consent for recording might not be enough; separate, explicit consent for the collection and processing of biometric data, often with specific disclosure requirements, may be necessary. The failure to secure such consent dramatically increases legal exposure, as BIPA, for instance, has led to numerous high-value class-action settlements.

The Inevitable Integration: Managing AI Notetakers in the Workplace

Despite the mounting legal challenges, a complete prohibition of AI notetakers in the workplace is largely impractical and, according to Littler, unrealistic to enforce. Survey data indicates a rapid adoption rate, with as many as 1 in 5 professionals already utilizing AI to draft meeting notes. This suggests that employees are integrating these tools into their workflows regardless of formal company policies, driven by the promise of enhanced efficiency and productivity. The rise of hybrid and remote work models post-pandemic has further accelerated this trend, as teams seek tools to bridge communication gaps and ensure consistent information capture across distributed workforces.

Given this reality, Littler Mendelson advocates for a proactive and strategic approach rather than outright bans. Their recommended strategy for employers includes:

  1. Selecting and Configuring Vetted Tools: Choose reputable AI notetaker providers with robust privacy policies and customizable settings.
  2. Disabling Voice Identification: Turn off speaker attribution features where the biometric risk outweighs the benefit of identifying individual speakers. This can significantly mitigate exposure to biometric privacy laws.
  3. Mandatory Consent Notices: Implement clear and prominent consent notices at the commencement of every meeting where an AI notetaker is present, treating these as mandatory, not optional. This ensures all participants are aware and can provide consent.
  4. Setting Short Data Retention Windows: Configure tools to retain recordings and transcripts for the shortest necessary period, minimizing the risk associated with long-term data storage.
  5. Developing Clear Policies: Establish comprehensive internal policies outlining where and when AI notetakers are permitted, with specific prohibitions for highly sensitive discussions such as interviews, performance reviews, termination meetings, internal investigations, and client-privileged conversations.

These measures aim to strike a balance between leveraging AI for productivity and upholding employee and participant privacy rights, creating a framework for responsible AI deployment.

A Global Perspective: International Data Privacy and AI Regulations

For multinational employers, the complexity of managing AI notetakers escalates considerably. The European Union’s General Data Protection Regulation (GDPR) imposes a significantly stricter bar for data processing. Under GDPR, meeting recordings and any subsequent AI processing require a valid lawful basis (e.g., explicit consent, legitimate interest, contractual necessity) and clear, transparent notice to all data subjects. Consent under GDPR must be freely given, specific, informed, and unambiguous.

Furthermore, the evolving EU AI Act, which is set to become a landmark piece of legislation, may classify AI systems used for worker monitoring as "high-risk." This category could potentially encompass AI notetakers, particularly those offering advanced features like sentiment analysis or productivity scoring. If deemed high-risk, these systems would be subjected to rigorous conformity assessments, human oversight requirements, and enhanced transparency obligations.

In co-determination countries like Germany and France, the deployment of new technologies that impact workers, such as AI notetakers, can require formal consultation with works councils. This step, which has no direct equivalent in the U.S., adds another layer of complexity and time to the implementation process, underscoring the necessity for comprehensive legal and HR strategy planning for global enterprises.

Industry Reactions and Future Outlook

Neither the Otter.ai nor the Granola case has reached a verdict, and both companies have either indicated they dispute the claims or have not yet publicly responded in detail to the allegations. The legal proceedings are expected to be lengthy and intricate, involving extensive discovery, expert testimony, and potentially appeals. The outcomes of these cases will undoubtedly send ripples through the tech industry, influencing how AI companies design their products, manage data privacy, and communicate with users.

The broader implications extend to corporate governance and risk management. As AI tools become more ubiquitous, the onus on organizations to conduct thorough due diligence, implement robust privacy-by-design principles, and continually monitor regulatory developments will only intensify. These lawsuits serve as a stark reminder that innovation must be tempered with ethical considerations and strict adherence to evolving privacy laws. HR leaders, in particular, are now on the front lines, tasked with navigating this complex terrain to protect both their organizations and their employees from potential legal pitfalls and reputational damage. The future of AI in the workplace hinges not just on technological advancement, but equally on establishing trust through transparency, consent, and unwavering commitment to data privacy.