powering productive workplaces
Front page
InterviewProductivity AI1h · 17:16 BST · 5 min read

Otter.ai Privacy Case Tests AI Meeting Data Ambitions

Following the Otter.ai privacy ruling, Proto Hologram Chief Legal Officer Tate Hilmoe explains why organisations should adopt clearer consent, non-recording defaults and tighter safeguards for retention, voice data and AI model training in meeting tools

The recent U.S. court decision allowing key privacy claims against Otter.ai to proceed should prompt organisations to reassess how AI meeting assistants are deployed across their businesses, according to Tate Hilmoe, Chief Legal Officer at Proto Hologram.

The decision in In re Otter.AI Privacy Litigation allows claims under the federal Electronic Communications Privacy Act, California’s Invasion of Privacy Act and Illinois’ Biometric Information Privacy Act to move forward. Otter.ai succeeded in dismissing other claims.

The ruling does not decide whether Otter broke the law. But, as UC Today previously reported, it allows plaintiffs to continue pursuing allegations involving the recording, retention and use of meeting data, alongside the alleged collection of voiceprints.

For Hilmoe, the implications extend beyond the vendor at the centre of the case.

“There are several takeaways in this,” he told UC Today. “So, not only vendor liability, but employer liability. When you point these tools at your own employees or others, there is that exposure.”

AI note-taking tools can be added to Zoom, Microsoft Teams and Google Meet calls in seconds. They can produce transcripts and summaries, record audio, identify speakers and make meeting information searchable after a call has ended.

That convenience has encouraged rapid adoption. However, Hilmoe said organisations need to look beyond the immediate productivity benefit and examine what happens once a meeting assistant has captured information.

The Difference Between Notes and Reuse

A central question in the case is whether the service should be treated as a tool acting on behalf of the meeting host, or as a third party that intercepts communications.

Otter.ai argued that it operated as an extension of the host or account holder – effectively, a note-taking tool used under the customer’s direction. Judge Eumi K. Lee was not prepared to accept that argument at the motion-to-dismiss stage.

Hilmoe said the distinction turns on the allegations around what Otter did with meeting data after collection.

“You had an AI notetaker that was not just recording sensitive, confidential communications,” he said. “We’re talking voiceprints, which are biometric prints as well.”

The complaint includes allegations involving sensitive medical discussions, alongside a venture-capital meeting that was allegedly left running for two hours. The tool was not merely said to have created a summary for the people attending the call. Plaintiffs allege recordings and voice data were retained and used to train and improve Otter’s models.

“The distinction here was it was ongoing,” Hilmoe said.

“It was the retention, the recording. And then the bigger piece was the reusing of this data – the reusing of this voice recording to train their own models.”

Those allegations have not been proven. However, the case illustrates the questions organisations need to ask before approving a meeting assistant: does it act solely for the customer? Can the vendor retain content? Is meeting data used to improve the service or train AI models? And are speaker-identification features creating persistent profiles from voice data?

The answers can change the legal and governance risk.

Consent Cannot Be an Afterthought

Hilmoe’s first practical recommendation is to make non-recording the default.

“Take a look at your vendor list and, at the base level, set it at non-recording,” he said. “Whether you’re using Teams, Meet, whatever Zoom, just set it at non-recording. That should be company-wide policy.”

Organisations can then make deliberate decisions about where and when transcription is appropriate, rather than allowing employees to activate tools ad hoc.

Consent is the next issue. Participants need to know that an AI assistant is being used and that it will record, transcribe or otherwise process their information.

“People have to agree,” Hilmoe said. “You need to let these people know that these AI notetakers or these tools are being deployed.”

That is more complex than displaying a quick notification in a meeting lobby. A call may include customers, suppliers, candidates, advisers or partners who have no visibility into an organisation’s policy or a vendor’s terms. In an employment context, a junior employee may also feel unable to object when their manager wants a meeting recorded.

Hilmoe said consent should be documented in writing and made clear before the meeting begins. Organisations should also nominate accountable owners for the tools, rather than leaving employees to decide individually how they are configured.

“Identify someone within the organisation who’s responsible,” he said. “Is this HR? Is it IT? Is it legal?”

He added that some discussions should be excluded altogether, including legal, HR, mergers-and-acquisitions and deeply personal medical conversations.

Retention and Voice Data Need Clear Limits

The BIPA claims that survived Otter's dismissal bid add particular significance to speaker identification and voice data.

Plaintiffs allege the company created and retained voiceprints without the notices and written consent required under Illinois law. Hilmoe said organisations should account for the strictest requirements that may apply when calls include people in multiple states.

“If you’ve got anyone from California or Illinois, you should expect the highest level,” he said.

That means vendors should be asked precise questions about what they capture, how long information is kept, who can access it, whether it is shared with third parties and whether it can be used for AI training.

Hilmoe also pointed to the need for published retention policies with clear deletion or destruction provisions.

Those requirements should be addressed in data-processing terms and vendor negotiations. But Hilmoe cautioned that deletion becomes more difficult once information is absorbed into an AI model.

“If the plaintiffs are found to succeed here,” he said, “and Judge Lee determines that, as maybe part of a relief, it’s injunctive relief and you have to remove or delete the data that was recorded and captured – artificial intelligence right now in these neural networks, it’s not a simple matter of deleting a line of code.”

He described the problem as a “de-identification paradox”: data thought to have been removed may remain capable of being re-identified after it has been incorporated into a model.

While the case is still ongoing, Hilmoe’s message for IT, security and collaboration leaders is immediate: AI meeting assistants need written rules, informed consent, restrictive defaults and clear accountability before they become routine fixtures in enterprise meetings.

rate this story
helps rank stories across uc today
The discussion0 takes · attributed & checked

Does this reflect your experience?

opening the room…
Read nextordered by techtelligence · every pick explained
same beat · Productivity AI

Oracle Turns AI Agents Loose on Talent Management Tasks

13 Aug 2026
same beat · Productivity AIKPMG’s AI Productivity System Goes Global12 Aug 2026same beat · Productivity AIGoogle Gemini Reaches One Billion Monthly Users as AI Assistant Race Accelerates12 Aug 2026