A new California federal lawsuit against AI notetaking provider Granola highlights a growing privacy risk for companies using meeting transcription tools: consent cannot be an afterthought. According to the complaint, Granola’s software allegedly recorded a virtual meeting participant without giving notice that an AI notetaker was present or seeking permission to record. The plaintiff claims this differs from other AI transcription tools that visibly join meetings, announce their presence, or give participants the ability to remove the notetaker. The suit also alleges that Granola used meeting contents by default for commercial purposes, including training AI systems, unless the Granola user turned that setting off.

For businesses deploying AI notetakers, meeting bots, transcription tools, or other AI-enabled collaboration products, the takeaway is straightforward: build consent and transparency into the workflow. Companies should review whether meeting participants receive clear notice before recording begins, whether consent is obtained from all required parties, whether participants can object or opt out, and whether meeting data is used for model training or other secondary purposes by default. As AI tools become more embedded in ordinary business communications, the privacy controls around them need to be just as visible as the productivity benefits.

Photo of Kathryn Rattigan Kathryn Rattigan

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security…

Kathryn Rattigan is a member of the Business Litigation Group and the Data Privacy+ Cybersecurity Team. She concentrates her practice on privacy and security compliance under both state and federal regulations and advising clients on website and mobile app privacy and security compliance. Kathryn helps clients review, revise and implement necessary policies and procedures under the Health Insurance Portability and Accountability Act (HIPAA). She also provides clients with the information needed to effectively and efficiently handle potential and confirmed data breaches while providing insight into federal regulations and requirements for notification and an assessment under state breach notification laws. Prior to joining the firm, Kathryn was an associate at Nixon Peabody. She earned her J.D., cum laude, from Roger Williams University School of Law and her B.A., magna cum laude, from Stonehill College. She is admitted to practice law in Massachusetts and Rhode Island. Read her full rc.com bio here.