The recent U.S. court decision allowing key privacy claims against Otter.ai to proceed should prompt organisations to reassess how AI meeting assistants are deployed across their businesses, according to Tate Hilmoe, Chief Legal Officer at Proto Hologram.
The decision in In re Otter.AI Privacy Litigation allows claims under the federal Electronic Communications Privacy Act, California’s Invasion of Privacy Act and Illinois’ Biometric Information Privacy Act to move forward. Otter.ai succeeded in dismissing other claims.
The ruling does not decide whether Otter broke the law. But, as UC Today previously reported, it allows plaintiffs to continue pursuing allegations involving the recording, retention and use of meeting data, alongside the alleged collection of voiceprints.
For Hilmoe, the implications extend beyond the vendor at the centre of the case.
“There are several takeaways in this,” he told UC Today. “So, not only vendor liability, but employer liability. When you point these tools at your own employees or others, there is that exposure.”
AI note-taking tools can be added to Zoom, Microsoft Teams and Google Meet calls in seconds. They can produce transcripts and summaries, record audio, identify speakers and make meeting information searchable after a call has ended.
That convenience has encouraged rapid adoption. However, Hilmoe said organisations need to look beyond the immediate productivity benefit and examine what happens once a meeting assistant has captured information.
The Difference Between Notes and Reuse
A central question in the case is whether the service should be treated as a tool acting on behalf of the meeting host, or as a third party that intercepts communications.
Otter.ai argued that it operated as an extension of the host or account holder – effectively, a note-taking tool used under the customer’s direction. Judge Eumi K. Lee was not prepared to accept that argument at the motion-to-dismiss stage.
Hilmoe said the distinction turns on the allegations around what Otter did with meeting data after collection.
“You had an AI notetaker that was not just recording sensitive, confidential communications,” he said. “We’re talking voiceprints, which are biometric prints as well.”
The complaint includes allegations involving sensitive medical discussions, alongside a venture-capital meeting that was allegedly left running for two hours. The tool was not merely said to have created a summary for the people attending the call. Plaintiffs allege recordings and voice data were retained and used to train and improve Otter’s models.
“The distinction here was it was ongoing,” Hilmoe said.
“It was the retention, the recording. And then the bigger piece was the reusing of this data – the reusing of this voice recording to train their own models.”
Those allegations have not been proven. However, the case illustrates the questions organisations need to ask before approving a meeting assistant: does it act solely for the customer? Can the vendor retain content? Is meeting data used to improve the service or train AI models? And are speaker-identification features creating persistent profiles from voice data?
The answers can change the legal and governance risk.
Consent Cannot Be an Afterthought
Hilmoe’s first practical recommendation is to make non-recording the default.
“Take a look at your vendor list and, at the base level, set it at non-recording,” he said. “Whether you’re using Teams, Meet, whatever Zoom, just set it at non-recording. That should be company-wide policy.”



