Otter.ai Fails to Dismiss Core Privacy Claims in U.S. Court

Federal judge allows claims over alleged captured conversations, voice data and AI model development to proceed.

4
Productivity & AutomationNews

Published: August 18, 2026

Christopher Carey

Otter.ai must continue defending key claims over its meeting-recording and data practices after a U.S. federal judge rejected the company’s attempt to dismiss the core of a consolidated privacy lawsuit.

Judge Eumi K. Lee of the U.S. District Court for the Northern District of California granted Otter’s motion to dismiss in part on August 13, but allowed the central claims under federal wiretap, California privacy and Illinois biometric-privacy law to move forward.

The ruling does not determine whether Otter broke the law, but it finds that the plaintiffs have pleaded enough facts for several allegations to proceed beyond the initial motion-to-dismiss stage.

An Otter.ai spokesperson declined to comment on the ruling when contacted by UC Today.Β Β 

Claims Over Recording and Data Use Survive

The action, In re Otter.AI Privacy Litigation, brings together four proposed class suits filed between August and September 2025.

The plaintiffs allege that Otter’s meeting assistant joined Zoom, Microsoft Teams and Google Meet calls, then recorded, transcribed and retained communications without the consent required by applicable laws. They further allege the company captured voiceprints through speaker-identification capabilities and used meeting information to improve its products and machine-learning models.

Otter argued that it was not a third-party interceptor, characterising its service as a tool used at the direction of a meeting host or account holder. It also argued that the plaintiffs had not demonstrated a sufficiently concrete injury to bring their claims in federal court.

Judge Lee rejected those arguments at this stage.

The order found that the complaint plausibly alleges Otter retained and used conversational data for its own commercial purposes, including the development of machine-learning models and services. That was enough to allow the plaintiffs to continue arguing that Otter could be treated as a third-party eavesdropper, rather than simply a service provider operating on a host’s behalf.

That distinction will be central as the case progresses. A meeting organiser may be responsible for obtaining consent under a provider’s terms of service, but the legal analysis becomes more complicated if a vendor independently retains or benefits from participant data.

Speaking to UC Today in May, Otter.ai CEO Sam Liang said the company wasn’t β€œafraid” of the lawsuit.

β€œLawsuits [are] part of doing business, especially when you are doing something new [or] disrupting a old model – some people are not comfortable, so we’ll just have to deal with that.”

β€œBut if you think about it, the way we capture meeting notes is no different than Microsoft Copilot or Zoom or Google Meeting notetakers, so we’re not afraid of [the] lawsuit. I think we’re on the right side of history.”

The court also found that alleged capture and retention of private medical, financial and professional conversations could constitute a concrete privacy injury, allowing the case to remain in federal court.

Voiceprint Claims Remain in Play

Judge Lee allowed claims under Illinois’ Biometric Information Privacy Act (BIPA) to proceed.

Plaintiffs allege Otter created and retained speaker-identification profiles using voice data without the written disclosures and consent required by BIPA. Otter challenged whether the alleged profiles met the statute’s definition of a biometric identifier, but the court found the complaint sufficient at this point.

BIPA is one of the most consequential privacy laws facing technology providers in the U.S. It permits statutory damages of $1,000 per negligent violation and up to $5,000 per intentional or reckless violation.

Otter Narrows the Case

Otter did however secure the dismissal of several claims.

Judge Lee dismissed claims under the federal Computer Fraud and Abuse Act and California’s Comprehensive Computer Data Access and Fraud Act, finding the complaint did not adequately allege the type of unauthorised computer access or statutory loss required under those laws.

The court also dismissed certain intrusion and California constitutional privacy claims for some plaintiffs because the complaint lacked enough detail about the conversations at issue. A claim under the Washington Privacy Act was dismissed on similar grounds.

Many of the dismissals were with leave to amend. The plaintiffs have 14 days from the August 13 order to submit an amended complaint. Otter then has 21 days to respond, whether the plaintiffs amend or allow the deadline to pass.

The surviving claims, however, remain on track to move into the next stages of the case.

If discovery proceeds, internal material relating to Otter’s notification flows, consent mechanisms, speaker-identification features, transcript retention and use of conversation data could become relevant.

Enterprise Controls Under Growing Scrutiny

The ruling does not make AI note-taking tools unlawful, nor does it establish a universal consent standard for every meeting in every jurisdiction.

It does reinforce the growing need for organisations to govern : knowing when they join calls, who can authorise them, what participants are told, whether speaker-identification functions are enabled, how recordings are retained and whether data can be used beyond providing the service.

Major collaboration providers have already been tightened controls on third-party AI bots, as UC Today reported in May.

Microsoft Teams has moved to flag some external meeting bots as β€œUnverified” and require organiser approval, while Zoom and Google Meet have linked native AI note-taking more closely to host controls and participant prompts.

While still ongoing, the outcome of the case could have far reaching implications for AI meeting assistants that join video calls, record and transcribe discussions, identify speakers and retain the resulting data.

AI Voice AssistantsGenerative AI Security​Security and Compliance
Featured

Share This Post