Lawsuit Accuses Granola of Recording Meetings Secretly
A federal class-action lawsuit against AI startup Granola highlights growing legal and privacy risks for enterprises deploying automated meeting transcription tools without consent.

On July 30, Florida resident Tarra Chamberlain filed a proposed class-action lawsuit against Granola in the US District Court for the Northern District of California. The complaint alleges that the AI note-taking software violates the California Invasion of Privacy Act by recording audio directly from a user's computer without obtaining consent from all meeting participants. Unlike competing tools that deploy visible bots to join video calls, Granola operates invisibly, which the lawsuit claims is actively marketed as a primary product advantage.
The lawsuit also targets how Granola handles user data, claiming the company uses transcription records by default to train its proprietary AI models. While Granola has not formally responded to the suit, its website highlights optional transparency features, such as automated chat notifications and video watermarks, to alert participants. The company also states that its AI training data is anonymized and never shared with third parties.
This legal challenge is not an isolated incident. A similar class-action lawsuit is currently proceeding in the same California district against Otter.ai, another major player in the automated transcription space. In that case, US District Judge Eumi K. Lee recently expressed skepticism during a Monday hearing regarding Otter.ai's motion to dismiss, signaling that courts may take a strict stance on unauthorized voice recording and AI training.
For IT leaders and enterprise practitioners, these legal battles underscore the compliance dangers of deploying generative AI assistants. Forrester analyst Enza Iannopollo warns that AI note-taking tools present unique risks because they process biometric voice data and repurpose conversations for model training. To mitigate these liabilities, organizations must thoroughly vet vendor contracts, align deployment with their internal risk management policies, and mandate explicit consent mechanisms for all meeting participants.
This is our own summary of reporting by Computerworld AI



