MaShop/Journal/Industry/The Notetaker Joined the Call. Nobody Asked the Cu…
● IndustrySeptember 23, 2026
Read · 5 min
ai notetaker · transcription

The Notetaker Joined the Call. Nobody Asked the Customer

A transcription assistant on a customer call is a recording device. Whether you may run one is decided before the call, not after somebody objects.

Key takeaways
  • An ai notetaker is a recording device with a friendly name, and the law that governs it is the law of recording rather than the law of software.
  • California requires the consent of every party to a confidential communication, with a fine of up to $2,500 per violation under Penal Code 632.
  • A class action filed in August 2025 alleges that a popular notetaker joined meetings, transcribed people without accounts, and used the audio to train its own models.
  • Consent given by whoever booked the meeting does not obviously cover the other people on the call, which is the gap the litigation is testing.
  • In the UK and EU the first question is not consent at all. It is which lawful basis you picked, and you have to pick it before you start.
  • The eight second announcement at the top of the call solves most of this, and almost nobody makes it.

A supplier rings to renegotiate. You take the call at your desk, and a small window appears in the corner of the screen saying the assistant has joined and is taking notes. You did not think about it, because you set it up six weeks ago to run on everything, and it has been quietly useful ever since.

Somewhere in that sentence is a decision you never consciously made: that a third company would receive a recording of a private business conversation, and that the person on the other end would find out only if they happened to notice a notification. For internal meetings that is mostly a cultural question. For calls with customers and suppliers it is a legal one, and it is being litigated right now.

The vendor calls it a notetaker. The statute calls it a recorder

Nothing in the relevant law turns on what the product is named or on whether a human ever listens to the audio. The operative facts are that a device captured a private conversation and that a party to it did not agree.

California Penal Code section 632 is the clearest example because it is the statute most of this litigation runs through. As the codified text puts it, the offence has three ingredients. Somebody acts intentionally. They use an electronic amplifying or recording device to eavesdrop on or record a confidential communication. And they do it without the consent of every party to that communication. The fine reaches $2,500 per violation, rising to $10,000 for repeat offenders, alongside the possibility of imprisonment.

Two definitions in that section do the real work. A confidential communication is one carried on in circumstances suggesting a party wants it kept between the parties, with exclusions for public gatherings and open proceedings. And the consent has to come from all parties, not from the one who scheduled the call. A business conversation about pricing, a customer explaining a complaint, a candidate in an interview: all of these sit comfortably inside the confidential description.

Which states turn this into a criminal question?

The ones requiring every party to agree rather than just one. The split matters more than the detail, because in a one party state your own consent is enough and in an all party state it is worth nothing on its own.

California is the one most often litigated, partly because so many technology vendors sit inside its jurisdiction and partly because its statute carries both criminal penalties and a civil route. The important point for a small business is not memorising a list. It is that you frequently cannot tell which rule applies, because the caller's location decides it and you do not know where they are.

A customer with a mobile number from one state may be sitting in another. A supplier calling from a car has crossed a line you cannot see. Courts have taken different views on which jurisdiction governs a call between two, and none of that uncertainty is resolvable by you in the two seconds before you answer. The workable response is to behave as though the strictest rule applies every time, which is also the only policy you can actually execute without a lookup table.

That sounds burdensome and is not. Behaving as though everyone must agree means saying one sentence at the start of a call. It is a smaller operational change than any of the alternatives, including the alternative of deciding case by case, which requires you to make a legal judgment while someone waits on the line.

Is a transcript safer than a recording?

No, and this is a comforting mistake worth naming. A transcript is produced by capturing the audio, so the act the statute describes has already happened by the time the text exists.

Some tools delete the audio immediately and keep only the words, which is genuinely better for storage risk and for what an attacker or a subpoena could reach. It does nothing for the consent question. The distinction that matters legally is between capturing and not capturing, and every one of these products is on the capturing side by definition.

Where the transcript does change your position is afterwards. A written record of what a customer said, held indefinitely, is personal data you are responsible for, and it is far easier to search than an audio file. If your notetaker writes into a shared workspace, everyone with access to that workspace can now read what a customer told you in confidence. That is a permissions question rather than a recording question, and it is the one most likely to cause an actual complaint, as we set out in the piece on who can read your AI conversations.

What is the Otter case actually about?

It is about whether a bot that sits in your meeting is a participant or an eavesdropper, and about what happens to the audio afterwards. Brewer v. Otter.ai was filed in a federal court in California in August 2025 and it is the case the whole category is watching.

The complaint as summarised by employment privacy counsel alleges that the service joins Zoom, Google Meet and Microsoft Teams meetings as a participant and transmits conversations to the company in real time for transcription. It further alleges that the tool records participants whether or not they hold accounts, that it uses those recordings to train speech recognition and machine learning models, and that non accountholders receive minimal notice. The claims invoke the federal Electronic Communications Privacy Act and Computer Fraud and Abuse Act alongside the California Invasion of Privacy Act and the state's unfair competition law.

Whatever the outcome, the structure of the allegation is the part a small business should absorb. The complaint is not that transcription is wrong. It is that two separate things happened without agreement: a recording was made, and then it was reused for the vendor's own commercial purpose. Those are distinct harms and a shop can be exposed to the first while being entirely indifferent to the second.

QuestionWhat people assumeWhat is actually true
Who has to agreeThe meeting organiserEvery party, in all party consent states
Does a visible bot count as noticeYes, it is obviousUntested, and the subject of live litigation
Who is liableThe vendorThe vendor and the business that switched it on
Does the audio stay with youUsuallyDepends entirely on the contract you did not read
Is a transcript different from a recordingYes, it is just textThe capture already happened to produce it

Does the host's consent cover everybody?

That is precisely the question the litigation exists to answer, and the honest position today is that nobody knows. Running your business on the assumption that it does is taking a position on an open legal question in exchange for saving eight seconds.

The practical asymmetry is what should decide it for you. If host consent turns out to be sufficient, an announcement at the top of the call cost you nothing. If it turns out to be insufficient, the announcement was the difference between compliance and a per violation penalty multiplied by every call you made. There is no version of this where the cautious behaviour is expensive.

Where does the recording actually go?

Into a third party's systems, for a period and a purpose set by a contract, and this is the part that outlives the call. A conversation is a moment. A stored recording is an asset somebody else holds.

Three questions settle it, and all three are answerable from the vendor's own documentation if you look. Is the audio retained after the transcript is produced, and for how long. Is any of it used to improve the vendor's models, and can you switch that off. Where is it stored geographically, which matters for both regulation and for who can compel its production. We went through the general shape of this problem for every AI tool in the piece on what vendors keep after you press delete, and notetakers are the worst case of it because the raw material is other people's voices rather than your own typing.

The pattern worth avoiding is the free tier. Products that cost nothing are frequently the ones whose terms permit the broadest reuse, which is not a scandal so much as an exchange, and it is an exchange you are making on behalf of people who were not asked. A paid plan with a contractual commitment against training is the version you can defend. Our own view of where that line sits is set out on the page describing how we handle data.

Diagram showing six categories of call to keep an AI notetaker out of, including legal, complaints, staff matters and negotiations

Europe asks a different question, and asks it earlier

Consent is one answer in the UK and EU rather than the question itself. Before you record anyone you need a lawful basis for processing their personal data, and a voice recording of an identifiable person is personal data without argument.

The Information Commissioner's Office guide to lawful basis sets out the six available under Article 6: consent, contract, legal obligation, vital interests, public task and legitimate interests. Its guidance is direct about sequencing: you must determine your lawful basis before you start using the personal information. Choosing afterwards, when somebody complains, is not a thing the framework permits.

For a small shop recording customer calls, two of the six are realistic. Consent gives the person control including the ability to withdraw it, which is clean but means honouring a refusal on the spot. Legitimate interests lets you keep control and is appropriate where the processing sits within reasonable expectations and does not harm anyone, which requires you to have actually assessed that rather than assumed it. The guidance is explicit that no one basis is always better and that a single approach applied to everything is the wrong instinct.

The practical consequence is a sentence in your privacy notice and a decision recorded somewhere, both of which take an afternoon once. The same discipline applies to anything you paste into a general purpose assistant, which we covered separately in the piece on what customer data may go into an AI tool.

The announcement that solves most of it

Say it before anything else happens, in your own words, and give a genuine way to decline. Eight seconds, every call, no exceptions for the ones you think are fine.

Something close to this works: I use an automated assistant to take notes on calls so I do not miss anything, it produces a written summary that stays with my business, and I am happy to switch it off if you would rather I did not. Then stop and wait for an answer. The waiting is the part that makes it consent rather than notification.

Two refinements matter. Ask at the start rather than after the small talk, because a recording of the first two minutes is still a recording. And if somebody declines, turn it off rather than muting it or promising not to use the transcript, because the capture is the event the statute describes.

Card listing four practices for running an AI notetaker lawfully, covering announcement, refusal, vendor training terms and lawful basis

What to ask before you buy one

Employment counsel writing about the Otter complaint set out a checklist that translates well to a business with no legal department. Fisher Phillips advises obtaining consent from all participants including external parties, vetting vendors on storage, retention and AI training purposes with contractual guarantees, writing a policy on when the tool may be used, and restricting it entirely from privileged discussions, HR matters and investigations.

The vendor question that reveals the most is narrow: does your product obtain consent only from the host, or from every participant. The answer is usually the former, and most vendors will say so plainly if asked. That tells you the consent obligation is yours rather than theirs, which is the single most useful thing to establish before signing anything.

Ask also whether recording controls exist per participant, whether the transcript can be deleted on request including from backups, and what happens to your data if you stop paying. That last one catches people: a cancelled account with a retained corpus is a worse position than never having used the product.

Where the tool genuinely earns its place

None of this is an argument against notetakers. They are excellent, and for a business where one person does the selling, the delivery and the invoicing, a reliable record of what was agreed on a call is worth real money.

The strongest case is internal and solo: your own dictation, your own planning calls, the walkthrough where a customer explains what they want and you would otherwise be typing instead of listening. The value is highest exactly where the consent question is easiest, which is a happy coincidence and a good default. Use it freely on calls where you are the only party, and deliberately on calls where you are not.

The weakest case is the one most people default to, which is running it on everything automatically. Automatic capture is what turns a useful tool into an obligation you carry on every call, and it removes the moment of judgment where you would otherwise have noticed that this particular conversation is a complaint, a negotiation or a conversation about somebody's health. Keeping the switch manual costs you a click and buys back that judgment.

"You must determine your lawful basis before you start using the personal information."UK Information Commissioner's Office, guide to lawful basis

That instruction is the whole subject in one line, and it is not a European peculiarity. Deciding why you are allowed to record someone before you record them is what the California statute demands through consent, what the class action complaint alleges was skipped, and what the eight second announcement accomplishes in practice. The order of operations is the requirement. Everything else is detail. A business that can say why it was entitled to record a given call, and can point to the moment it told the person, has answered the only question any of these regimes actually asks.

Discussion 0

0 / 4000Your email address is not displayed with your comment.
No comments are published yet.

Explore — related articles.

Build something. Move your work forward.

Start with a software project or an agent task. Describe the result you need, review the work and keep control of your connected accounts.

Open the workspace →