In December 2025, a woman named Katelin Cruz joined an ordinary virtual meeting. She had never created a Fireflies.ai account, never clicked through its terms of service, never agreed to anything. But someone else in the meeting had invited the Fireflies bot, and according to the class action she later filed — Cruz v. Fireflies.AI Corp. — that was enough for the company's "Speaker Recognition" feature to generate a mathematical model of her voice: a voiceprint.
Her case is not an outlier. It joined Brewer v. Otter.ai, filed in August 2025 by another non-user who was recorded on a Zoom call. In February 2026, five Illinois residents filed a class action against Microsoft over Teams' live transcription. And in May 2026, seven broadcast journalists and voice actors filed a coordinated set of nine class actions against Apple, Google, Meta, Amazon, Microsoft, NVIDIA, Adobe, Samsung and ElevenLabs over voiceprints extracted from public audio. The suits differ in their legal theories, but they share one insight worth understanding even if you never set foot in a courtroom: the problem isn't the recording. It's what gets extracted from the recording.
What a voiceprint actually is — and why your transcript needs one
Every meeting transcript that labels speakers — "Sarah: let's push the launch" — depends on a process called speaker diarization: figuring out who spoke when. To do it, the software analyzes the physical characteristics of each voice: pitch, formant frequencies (the resonances shaped by the size of your throat and mouth), prosody, cadence. It compresses those characteristics into a numerical vector, and clusters the audio by which vector each stretch of speech matches.
That vector is a voiceprint. It works exactly like a fingerprint template: unique enough to identify you, stable enough to recognize you next time. That second property is the product feature — it's how Fireflies can label you by name in a meeting you never introduced yourself in, because it matched your voice against a print built from an earlier call. And it's also the legal problem, because a template that identifies a person biologically is not "audio." It's biometric data, the same legal category as fingerprints and face scans.
The distinction matters because you can delete a recording; you can't change your voice. A leaked password gets rotated. A leaked voiceprint is a permanent key to you — usable, in an era of voice cloning and voice-authenticated phone banking, in ways that a plain MP3 never was. Privacy regulators treat biometrics as a special class for exactly this reason.
The 2026 lawsuit wave, case by case
The legal engine behind most of these cases is Illinois' Biometric Information Privacy Act (BIPA), a 2008 law that explicitly lists "voiceprints" as protected biometric identifiers. BIPA is unusually sharp-toothed: it requires written notice before collecting a biometric, a written release from the person, and a public retention-and-destruction policy — and it lets private individuals sue for up to $1,000 per negligent violation and $5,000 per reckless one. Multiply by every participant in every meeting, and you see why class-action lawyers noticed the meeting-bot boom.
- Brewer v. Otter.ai (August 2025). The plaintiff had no Otter account but joined a Zoom call where someone's Otter notetaker was running. The case centers on wiretap statutes alongside the voiceprint claims — recording and analyzing a conversation participant who never consented.
- Cruz v. Fireflies.AI (December 2025). A BIPA claim built directly on the Speaker Recognition feature: the complaint alleges Fireflies generated voiceprints of meeting participants, including non-users, without written notice, written release, or a published retention policy.
- The Microsoft Teams case (February 2026). Five Illinois residents allege that Teams' live transcription — the speaker attribution feature used in millions of workplace meetings daily — collects voiceprints without BIPA's required consent flow.
- The May 2026 coordinated actions. Nine class actions filed by professional voice performers allege that major AI companies extracted voiceprints from publicly available audio to train commercial voice models — extending the theory from meetings to the entire audio internet.
None of these cases has produced a final ruling on the core question — whether the speaker embeddings these tools generate legally qualify as "voiceprints" under BIPA. But the direction of travel is clear, and the settlements in earlier BIPA waves (Facebook paid $650 million over face templates; Google paid $100 million) suggest vendors are not going to litigate these to the end. Several meeting-AI vendors have already started offering settings to disable speaker identification for callers from two-party-consent states.
The uncomfortable part: this is happening in a third of meetings
A July 2026 survey found that one in three employed Americans has had an AI notetaker present in a work meeting — and among them, only about 35% say they were always asked before the tool recorded or transcribed. Nearly one in five discovered after the fact that a meeting had been recorded. If the plaintiffs' theory holds, a very large fraction of those meetings involved biometric collection from people who never consented to it — not because anyone intended harm, but because the person who clicked "invite notetaker" had no idea the transcript's speaker labels were built on voiceprints.
That's the practical takeaway for anyone who runs meetings: when you bring a cloud notetaker into a call, you may be making biometric decisions on behalf of everyone in the room. The etiquette question — should you ask before recording? — has quietly become a compliance question. And if you work under stricter regimes like the EU's AI and data-protection rules, the bar is higher still.
Transcripts without the biometric pipeline
Meetly records and transcribes meetings entirely on your iPhone. The audio never leaves your device, no bot joins the call, and no vendor cloud ever builds a voiceprint database from the people you talk to. You still ask the room before you record — but what happens to their voices afterward stays in your pocket. Free to start.
Download MeetlyHow to keep good transcripts without harvesting anyone's voice
You don't have to give up meeting records to stay on the right side of this. You have to change where the processing happens and what gets retained. A practical checklist:
- Always announce and ask — every meeting, every participant. Consent to recording is the floor in two-party-consent states like California and Illinois, and it's the cheapest insurance there is. "I'd like to record this so I don't have to take notes — everyone okay with that?" takes five seconds.
- Prefer on-device transcription over cloud bots. If the audio is processed locally and never uploaded, there is no vendor building or storing biometric templates of your participants. The privacy question collapses from "what does this company do with everyone's voiceprints?" to "who can see my phone?"
- If you must use a cloud tool, read its biometric disclosures. Look for three things BIPA effectively demands: explicit notice that speaker recognition creates voice models, a written consent mechanism that covers guests (not just the account holder), and a published retention schedule saying when voiceprints are destroyed.
- Turn off speaker identification when you don't need it. For a 1:1 or a lecture, you know who's talking. Diarization is the feature that generates voiceprints — disabling it removes the most legally sensitive processing.
- Don't let summaries auto-send audio or transcripts to third parties. Auto-emailed recaps and CRM integrations multiply the number of systems holding data derived from participants' voices.
Where this is heading
BIPA is the sharpest law, but it's no longer alone. Texas and Washington have biometric statutes; Colorado's privacy act added biometric provisions in 2025; and several state legislatures introduced voiceprint-specific bills after the May 2026 filings made national news. The realistic near future is one where speaker recognition requires the same consent ceremony as a fingerprint scanner — which cloud vendors will solve with click-through flows for account holders, leaving exactly the people the lawsuits are about (guests, clients, interviewees, the other side of the negotiation) as the unresolved problem.
The deeper lesson of the voiceprint wave is the same one the industry keeps re-learning: features that feel free at demo time — "it labels every speaker automatically!" — often have a cost that was quietly externalized onto people who never opted in. For meeting records, there's a version of the technology where that externality simply doesn't exist: the transcription happens on your own device, the biometric math never touches a server, and the only person who can leak your meeting is you.
Record meetings. Keep the voices out of the cloud.
Meetly transcribes and summarizes on-device in 90+ languages — no bot in the call, no account required, no voiceprint database. Ask the room, hit record, and own the only copy.
Download MeetlyFrequently asked questions
Is my voice considered biometric data?
A plain audio recording generally isn't, but a voiceprint — the mathematical template of your vocal characteristics that speaker-recognition systems extract — is explicitly listed as a biometric identifier under Illinois' BIPA and is treated as biometric data under several other state laws and the GDPR. The legal line runs between recording your voice and modeling it.
Do AI notetakers like Otter and Fireflies create voiceprints?
Any tool that automatically labels who said what uses speaker diarization, which works by extracting a numerical model of each voice. Lawsuits filed in 2025–2026 (Brewer v. Otter.ai, Cruz v. Fireflies.AI, and a class action over Microsoft Teams transcription) allege these models are voiceprints collected without the notice and written consent biometric laws require. The vendors dispute the characterization; courts haven't issued final rulings yet.
Can I sue if an AI notetaker recorded me without my consent?
Possibly, depending on where you live. Illinois' BIPA allows private lawsuits with statutory damages of $1,000–$5,000 per violation, and both the Otter and Fireflies plaintiffs were non-users who simply joined a meeting. In two-party-consent states like California, unconsented recording itself can violate wiretap law. Elsewhere your options are thinner — most states still have no biometric statute.
Does BIPA apply if I don't live in Illinois?
BIPA protects Illinois residents, but its effects reach further: vendors rarely build Illinois-only consent flows, so BIPA lawsuits tend to change products for everyone. Texas and Washington have their own biometric laws (enforced by the state, not private suits), and more states are drafting voiceprint provisions after the 2026 lawsuit wave.
How do I stop AI meeting bots from creating a voiceprint of me?
In meetings you run: use on-device transcription instead of cloud bots, or disable speaker identification in your notetaker's settings. In meetings you attend: when a bot joins, you can ask the host to remove it or to disable speaker recognition — and in two-party-consent states you're entitled to refuse recording altogether. Some vendors now offer per-meeting voiceprint opt-outs precisely because of the litigation.
