A federal judge has rejected Otter.ai’s bid to dismiss a privacy class action, allowing core wiretap and surveillance claims to proceed against the AI meeting transcription service.
The August 14 ruling means the consolidated case — In re Otter.AI Privacy Litigation, pending in the Northern District of California — will move to discovery. The decision could reshape how every AI meeting tool operates, not just Otter.
The Allegations
Plaintiffs allege that Otter’s AI assistant automatically joins Zoom, Microsoft Teams, and Google Meet meetings, records conversations, generates transcripts, captures screenshots, creates identifying voiceprints, and transmits meeting data to Otter’s servers — all without notifying every participant or obtaining their consent. According to the consolidated complaint, voiceprints are used to identify speakers across meetings, and recordings and transcripts are used to train Otter’s automatic speech recognition and AI models.
The claims have not been proven in court. Otter disputes them.
Tool or Eavesdropper
The case turns on a single question: is an AI transcription service a neutral tool controlled by the person who invited it, or a separate third party listening in?
If it’s a tool, the user who turned it on is a party to the call, and their consent can satisfy federal wiretap law. If it’s an eavesdropper, its own listening can violate wiretap statutes no matter what the user agreed to.
The lead federal claim is under the Electronic Communications Privacy Act — the Wiretap Act — which bars intentionally intercepting electronic communications without authorisation. The complaint pairs that with California’s Invasion of Privacy Act (CIPA), which requires all parties to consent before a confidential conversation is recorded. Additional claims include computer fraud violations, Illinois biometric privacy law (for voiceprints), and California unfair competition claims.
Otter’s strongest defence is one-party consent: the user invited the assistant, so the vendor argues that user consented on the tool’s behalf. Plaintiffs counter that Otter receives audio on its own servers, uses it to train models, and builds speaker profiles — conduct they say makes it a third-party eavesdropper, not a passive tool.
Why the Ruling Matters
The judge allowed the core privacy claims to survive. That doesn’t mean Otter lost — it means the court found the plaintiffs’ legal theory plausible enough to proceed to discovery, where Otter will have to turn over internal documents about how its product actually works.
The financial exposure is significant. Wiretap statutes carry statutory damages, meaning plaintiffs don’t have to prove actual monetary harm. Multiply per-violation damages across a class of recorded participants and many meetings, and the numbers climb quickly.
But the real weight of this ruling is what it signals to the broader industry. AI meeting assistants — Otter, Granola, Fireflies, Read, and others — have become standard workplace tools. If the court ultimately finds these services are third-party eavesdroppers, every vendor in the category faces the same legal theory. Product roadmaps could shift overnight toward louder, more explicit consent mechanisms.
The Privacy Policy Problem
One detail from the complaint is worth singling out. Otter had a privacy policy. The plaintiffs said it wasn’t enough. They allege the policy placed the burden on Otter’s customers to obtain consent from “co-workers, friends or other third parties” whose communications Otter collects — a delegation that buried the real obligation in fine print few participants ever see.
To learn that conversations were kept indefinitely, a user had to connect one clause saying data is retained “as long as necessary to fulfill the purposes set out in this Policy” to a separate passage revealing that one of those purposes was training Otter’s AI. That’s a purpose with no real end date, hidden across two sections.
This is the pattern that should worry any company building AI tools that process user data. Privacy policies have been treated as legal cover. This case suggests they can become evidence — proof that a company knew what it was doing and chose to disclose it in a way designed to be missed.
The NZ Angle
New Zealand’s Privacy Act 2020 doesn’t have a direct equivalent to the US Wiretap Act. But it does require organisations collecting personal information to do so in a transparent way, and it places responsibility on the collecting agency — not its customers — to ensure collection is fair and lawful.
An AI meeting tool that joins NZ calls, records participants, and trains models on that data would need to disclose those purposes clearly under NZ law. The “delegated consent” model that Otter allegedly used — pushing the obligation onto the meeting host — may not hold up under the Privacy Commissioner’s principles. NZ businesses deploying AI meeting assistants should be checking whether their tools announce themselves to all participants, whether recordings are used for training, and whether the consent chain actually reaches everyone on the call.
❓ FAQ
Is Otter.ai illegal to use? No court has found that. This is a class action at the pleading stage. The judge allowed the case to proceed, which means the legal theory is plausible, not proven. Otter disputes the claims.
What’s the difference between one-party and all-party consent? Federal wiretap law allows recording if one party to the conversation consents. California’s CIPA requires all parties to consent for confidential communications. If a call involves California participants, the all-party standard could apply regardless of where the meeting host is.
Does this affect other AI meeting tools? The legal theory — that an AI note-taker is a third-party eavesdropper rather than a tool — applies to any service that joins calls, records audio, and transmits it to its own servers. Otter is the test case, but the category is wide.
What should NZ businesses do? Check whether your AI meeting tool announces itself to all participants, whether it uses recordings for model training, and whether your privacy obligations under the NZ Privacy Act 2020 are being met by the vendor or silently delegated to you.