Here's the trap. Someone on the sales team installs a notetaker, connects it to their Google Calendar, and forgets about it. Three weeks later it is sitting in customer calls nobody decided it should attend. Your general counsel asks whether the customer was told. You go looking for the answer in the vendor's documentation, and the answer is not in there.
That is not a governance embarrassment. California Penal Code section 637.2 gives every person on that call a private right of action worth $5,000 per violation, and the section says in terms that suffering actual damages is "not a necessary prerequisite" to bringing it. Nine states have recording statutes whose text plainly reaches a business video meeting and requires everyone's agreement. Five more reach it only under conditions the compliance blogs never state. The setting your rep never opened decides which side of that line your company sits on, and most of the recording and coaching category will not tell you what that setting is.
The mechanism is dull, which is the problem. A notetaker reads the calendar, sees a meeting with a conference link, and joins it. No human authorises the individual recording, so no human checks the individual jurisdiction. It works like a standing order at a bank. You set it up once and it keeps paying out long after you stopped thinking about it.
This page is not legal advice and does not pretend to be. It reports published statute text with citations, filed court dockets with numbers and posture, and vendor documentation with the date it was read. Nothing here is a measurement. No recordings were made, no accounts were created, and where a question needs a trial account, this page says so. Every case named below is an allegation. As of 2026-08-25, a CourtListener opinion-database search for all three defendant vendors returns zero results, so nothing here has produced a written merits ruling.
What follows: the statute table with penalties and private rights of action, the arithmetic on what one misconfigured quarter is worth, ten docket numbers, the sixteen-tool default audit, what Zoom, Google Meet and Microsoft Teams do underneath all of it, and a 25-minute check you can run before procurement gets involved.
So which notetakers record by default, and which states care?
Two vendors of sixteen state, in their own published documentation, which auto-join setting a new account ships on, and they give opposite answers. Fireflies joins everything: "By default, Fireflies is set to join all meetings with a web-conf link." Chorus does the reverse and is more specific about it, naming its shipped rule as "a default setting", stating that "by default, Chorus does not join video calls for your internal meetings", and adding that it "will not join meetings that are organized by your prospects/customers." Both are vendor statements about their own products, read 2026-08-21 and spot-checked 2026-08-25.
The other fourteen publish the full menu of auto-join options and never name the one that is selected at signup. Fathom lists four. Otter lists five. Avoma documents the admin rule set and the member setup flow in separate articles. Grain spreads its meeting-type rules across four. None of them prints the shipped value, which means the settings screen on a trial account is the only documentation of it that exists anywhere.
On the legal side, the number that circulates is eleven, and every list using it contains a different eleven. Read the statutes instead of the lists and the picture sharpens. Nine states have text requiring the consent, knowledge or informing of every party, reaching a business video meeting on its face. Five more get counted as all-party while the real condition sits in a clause nobody quotes: Connecticut covers telephone calls only, Oregon and Nevada split by channel, Michigan's text and its case law point opposite ways, and Delaware appears on almost every all-party list while its wiretap statute's text is one-party.
What "all-party consent" actually means, now that you have a reason to care
An all-party consent state is one where recording a private conversation is lawful only if every participant agreed, rather than only whoever holds the recorder. The federal position is the opposite. 18 U.S.C. section 2511(2)(d) makes it lawful for a person "not acting under color of law to intercept a wire, oral, or electronic communication where such person is a party to the communication or where one of the parties to the communication has given prior consent". One party is enough federally, with a criminal ceiling of five years under section 2511(4)(a). States legislate above that floor, and the strictest jurisdiction your meeting touches governs it.
Three words do most of the work, and they are different words in each state
California's section 632 protects a "confidential communication", defined in 632(c) as one "carried on in circumstances as may reasonably indicate that any party to the communication desires it to be confined to the parties thereto". Illinois protects a "private conversation" and only prohibits a device used "in a surreptitious manner". Montana's statute turns on a "hidden electronic or mechanical device" used "without the knowledge of all parties". Massachusetts turns on the word "secretly". Oregon's in-person rule asks only whether all participants were "specifically informed", which is a lower bar than consent.
That variation matters enormously to a notetaker buyer and almost nobody writing about this notices it. A bot that shows up in the participant list under a name like "Fireflies.ai Notetaker" is doing something visible. It is a materially harder case under the Illinois surreptitious-manner element, the Montana hidden-device element and the Massachusetts secrecy element than under the California test, which asks about consent and says nothing about visibility. A tool that captures inside the rep's own desktop application with nothing on the call at all is the mirror image: squarely inside the hidden-device language, and the direction several of these vendors are actively moving.
The statute table: nine clear, five conditional, one that has no statute
Every row below was read first-hand from primary text on 2026-08-25 unless the cell says it was not. This is deliberately not sourced from the recording-law aggregator sites that every ranking page on this query copies from each other, because those sites publish a state name and a one-word verdict without the statutory language that decides the case, and the language is where all the surprises are.
| State | Citation | What the text requires | Criminal exposure | Private right of action | The catch |
|---|---|---|---|---|---|
| California | Cal. Penal Code §§ 632, 632.7, 637.2 | Consent of all parties to a "confidential communication" | Up to $2,500 per violation and up to one year, first offence; up to $10,000 on repeat | Yes. § 637.2: $5,000 per violation or 3x actual damages, whichever is greater | § 637.2 says actual damages are "not a necessary prerequisite". This is the section that generates class actions |
| Florida | Fla. Stat. § 934.03(1)(a), (2)(d) | "Prior consent" of all parties to the interception | Third-degree felony under § 934.03(4)(a) | Yes, § 934.10 | Applies to oral, wire and electronic communications alike, not only telephone calls |
| Illinois | 720 ILCS 5/14-2(a)(2) | Consent of all other parties to a "private conversation", where the device is used "in a surreptitious manner" | Felony [not verified first-hand] | Yes, 720 ILCS 5/14-6 [not verified first-hand] | The surreptitious-manner element is a live defence for any bot that names itself in the participant list |
| Maryland | Md. Cts. & Jud. Proc. § 10-402(a), (b), (c)(3) | "All of the parties to the communication have given prior consent" | Up to five years and up to $10,000 | Yes, § 10-410 [not verified first-hand] | The highest criminal ceiling of any state in this table |
| Massachusetts | Mass. Gen. Laws ch. 272, § 99 | Prohibits "secretly" intercepting a wire or oral communication | Not verified first-hand in this pass | Yes, § 99(Q) [not verified first-hand] | Turns on secrecy rather than consent, which is a different test again. Not verified against the statute text |
| Montana | Mont. Code Ann. § 45-8-213(1)(c) | No "hidden electronic or mechanical device" without "the knowledge of all parties" | Fine up to $500 or up to six months, first offence | Not stated publicly in the section text | Express carve-out for "persons given warning of the transcription or recording". A working announcement is an element defeated, not a mitigation |
| New Hampshire | RSA 570-A:2 | Consent of all parties | Not verified first-hand in this pass | Yes, RSA 570-A:11 [not verified first-hand] | Not verified against the statute text. Treat as secondary |
| Pennsylvania | 18 Pa.C.S. §§ 5703, 5704(4) | All-party consent. § 5703 makes interception "a felony of the third degree" | Felony of the third degree | Yes, § 5725 [not verified first-hand] | Legislature site was unreachable; the felony grading was read from a secondary code database |
| Washington | RCW 9.73.030(1), (3) | "Without first obtaining the consent of all the participants" | Not verified first-hand in this pass | Yes, RCW 9.73.060 [not verified first-hand] | 9.73.030(3) requires that the announcement of recording "shall also be recorded". An announcement your tool does not capture may not count as one |
| Connecticut | Conn. Gen. Stat. § 52-570d | Written consent, or a recorded verbal notice at the start, or an automatic tone every 15 seconds | Civil statute. Criminal eavesdropping under § 53a-189 is one-party | Yes, § 52-570d(c): damages, costs and a reasonable attorney's fee | Covers "oral private telephonic communication" only. Whether a video meeting qualifies is genuinely open |
| Delaware | 11 Del. C. § 2402(c)(4) | Lawful where "the person is a party to the communication or where one of the parties ... has given prior consent" | Class E felony and a fine up to $10,000 for a violation of § 2402(a) | Yes, § 2409 [not verified first-hand] | The text is one-party. Delaware still appears on almost every published all-party list. The all-party language people are citing sits in the separate privacy statute at § 1335 |
| Michigan | MCL 750.539c | Eavesdropping on a private conversation "without the consent of all parties thereto" | Felony: up to two years, or a fine up to $2,000, or both | Yes, MCL 750.539h [not verified first-hand] | Text reads all-party. Michigan appellate case law has read a participant's own recording as outside it. Counted both ways by different sources |
| Nevada | NRS 200.620; NRS 200.650 | Split by channel | Not verified first-hand in this pass | Yes, NRS 200.690 [not verified first-hand] | The most misreported state on every list: the telephone rule and the in-person rule are different and only one is all-party |
| Oregon | ORS 165.540(1)(a), (1)(c), (6)(a) | Telecommunications: "unless consent is given by at least one participant". In-person conversation: unlawful "if not all participants ... are specifically informed" | Class A misdemeanor under subsection (8) | Yes, ORS 165.540(9) [not verified first-hand] | Oregon's telephonic rule is one-party and its in-person rule is the strict one, which inverts most people's assumption. A video meeting sits between the two definitions |
| Vermont | No recording statute | Not applicable | None | Common law | Vermont reached a comparable result through its supreme court rather than its legislature, which is why it appears on some lists and not others |
| Federal floor | 18 U.S.C. §§ 2511(2)(d), 2511(4)(a), 2520 | One party's consent is sufficient | Fined, or imprisoned not more than five years, or both | Yes, 18 U.S.C. § 2520 | Every state above legislates on top of this. The federal rule is the floor and never the answer |
Delaware is on every list, and its wiretap statute says one party
This correction is checkable in ninety seconds. 11 Del. C. section 2402(c)(4) makes it lawful "for a person to intercept a wire, oral or electronic communication where the person is a party to the communication or where one of the parties to the communication has given prior consent to the interception". That is the federal one-party formula, word for word.
Delaware still appears in the all-party column of nearly every compliance table on this subject, because a different Delaware statute, the privacy provision at section 1335, uses all-party language. Federal courts have read the two together in the direction of section 2402.
A vendor's own list has the same problem in the other direction. Rilla publishes an eleven-state notice list on its own site that omits Nevada, Delaware, Michigan and Vermont. That is the vendor's list of the states it thinks matter, not a compliance checklist, and it should be read as the former. The useful lesson is not that Rilla is wrong. It is that when two careful parties count the same statutes and get different answers, the count is not the deliverable. The statute text is.
What one misconfigured quarter is actually worth
This is arithmetic and not a measurement. It multiplies a published statutory figure by a headcount and predicts nothing about whether any claim would succeed.
California Penal Code section 637.2 sets statutory damages at $5,000 per violation or three times actual damages, whichever is greater, and states that suffering actual damages is "not a necessary prerequisite" to the action. Take a routine six-person customer call where two participants are in California and neither consented. On the plaintiff-side reading that is two violations and $10,000.
Now run the same misconfiguration for a quarter across a ten-rep team at four external calls a day each: 40 calls a day, roughly 60 selling days, 2,400 recorded calls. If one Californian participant sits on a tenth of them, that is 240 claimed violations and a nominal exposure of $1.2 million before anyone argues about anything.
That figure is deliberately naive and you should treat it that way. It assumes every recording captured a "confidential communication" as section 632(c) defines it, which is contested in nearly every filed case. It assumes no consent arrived by any route, including invite text nobody read. It ignores arbitration clauses, which is what several vendors named on this page are relying on. It is not a prediction and nobody has been ordered to pay it.
What it is good for is one comparison. The cost of getting the setting right is an afternoon. The cost of getting it wrong is a number with six digits in it that somebody else gets to calculate. Set both against the subscription, which in this category runs roughly $10 to $40 per seat per month depending on tier, and where the metering differences between the two most popular tools will occupy your finance team far more than your counsel. The compliance question is priced into none of it.
The plaintiff bar has already found this statute
A CourtListener RECAP search for the phrase "California Invasion of Privacy Act", limited to dockets filed on or after 2026-01-01, returns 298 results as of 2026-08-25. Almost none of them involve notetakers. They are session-replay scripts, chat widgets, retail sites and advertising pixels, and the wave has been building for four years. That number is not evidence that a notetaker claim would succeed. It is evidence that the statute has an active, organised plaintiff bar that already knows how to plead it, which is the relevant fact when you are deciding how carefully to configure something.
Why a bot in the participant list is not the same as consent
Almost every vendor in this set documents that its bot appears as a named participant. Almost none of them ships an actual notice to the other party switched on. Those are two different facts, and the gap between them is where the exposure sits.
Visibility is a fact about a participant list. Consent is a fact about a person's state of mind, and most of the statutes above are written about the second one. Washington makes the distinction unusually concrete: RCW 9.73.030(3) does not merely require an announcement, it requires that the announcement itself "shall also be recorded". A tool that displays a banner and starts its transcript after the banner clears has produced no evidence the banner was ever shown.
Montana runs the same logic the other way, and it is the one genuinely encouraging cell in the table. Section 45-8-213(1)(c) carves out "persons given warning of the transcription or recording", so a working, default-on, in-meeting announcement is not a mitigating factor in Montana. It is an element of the offence that no longer exists. That is the strongest available argument for insisting on default-on disclosure rather than treating it as a configurable extra.
What the vendors actually ship
Gong's setup instruction for its consent page reads "Turn On", which implies it ships off, and Gong does not publish the default. Chorus makes its pre-meeting email an admin checkbox and puts consent capture behind Compliance Mode. Fireflies makes both the email and the in-chat notice opt-in and describes its own posture in its documentation as "Opt-Out Consent: users are considered OK with recording as long as they don't object." That is the vendor's characterisation of its own product, quoted rather than endorsed, and it is the most candid sentence any vendor in this set has published.
Fathom's consent email is off by default on individual accounts and, in Fathom's words, "Fathom does not send consent emails for same-day meetings." Read that against a sales motion where same-day is the whole point. Attention's in-chat compliance message is in beta and can only be switched on by Attention itself through an account manager, so an admin cannot self-serve disclosure at all. Avoma's own instruction reads "Turn Enable Recording Announcement ON", and two Avoma pages disagree with each other on whether the chat notice fires automatically.
Does the invite text count as telling them?
This is the question every rollout eventually rests on, because invite text is the cheapest disclosure available and several vendors add a line to the calendar body automatically. The honest answer is that it depends on which of the five statutory formulas above applies, and that the formulas disagree with each other on exactly this point.
Under Oregon's in-person rule the test is whether all participants were "specifically informed", and invite text the participant received is at least an argument. Under Connecticut's telephone rule three methods are permitted and invite text is not among them: written consent in advance, a verbal notice recorded at the start, or an automatic tone every 15 seconds. Under California's section 632 the question is consent rather than notice, and a person who read a line and joined anyway may or may not have given it. Under Washington's 9.73.030(3) the announcement has to be inside the recording, which invite text by definition is not.
One statute, one method, one answer. Four statutes, four methods, and a single rollout that touches all four. That is why the vendors that let an admin lock a behaviour are worth more than the vendors with the better transcript, and it is why "we put it in the invite" is a position rather than a defence.
What have the courts actually decided? Nothing yet
Every case below was pulled from the CourtListener REST v4 RECAP index on 2026-08-25. Every one is an allegation. A parallel search of CourtListener's opinion database for Otter.ai, Fireflies.AI and Granola returns zero results, so there is no written merits ruling in this category that this page could find. A settlement, where one occurs, is not an admission of anything either. The reason to read this section is not to learn what a notetaker did. It is to learn what your prospect's security review will find in ten minutes, and to have an answer ready.
| Case | Docket | Court | Filed | Posture on the public docket, 2026-08-25 |
|---|---|---|---|---|
| In re Otter.AI Privacy Litigation | 5:25-cv-06911 | N.D. Cal. (Judge Eumi K. Lee) | 2025-08-15 | Open. Consolidates four suits. No termination date |
| Pierson Walker v. Otter.ai, Inc. | 5:25-cv-07187 | N.D. Cal. (Judge Lee) | 2025-08-26 | Open. Federal question |
| Theus v. Otter.ai, Inc. | 5:25-cv-07462 | N.D. Cal. (Judge Lee) | 2025-09-03 | Open. Diversity, personal injury |
| Winston v. Otter.ai Inc. | 5:25-cv-07712 | N.D. Cal. (Judge Lee) | 2025-09-10 | Open. Federal question |
| United States v. Otter.AI Inc | 4:26-sw-00150 | E.D. Ark. | 2026-08-07 | Search-warrant proceeding. Filed and terminated the same day. Two separate dockets carry the number |
| Cruz v. Fireflies.AI Corp | 3:25-cv-03399 | C.D. Ill. (Judge Sue Ellen Myerscough) | 2025-12-18 | Terminated 2026-03-11. Basis not stated on the public record |
| Fricker v. Fireflies.AI Corp. | 1:26-cv-02675 | N.D. Ill. (Judge Steven C. Seeger) | 2026-03-10 | Open. Other Statutory Actions |
| Parrinello v. Fireflies.AI Corp. | 3:26-cv-02479 | N.D. Cal. (Judge Araceli Martinez-Olguin) | 2026-03-23 | Open. Other Statutory Actions |
| Martinez v. Fireflies.AI Corp. | 1:26-cv-03512 | N.D. Ill. (Judge Seeger) | 2026-03-30 | Open. Same judge as Fricker |
| Chamberlain v. Granola, Inc. | 3:26-cv-07926 | N.D. Cal. (Judge Edward M. Chen) | 2026-07-30 | Open. Diversity |
Four Fireflies suits in ninety-nine days
Cruz v. Fireflies.AI Corp was filed in the Central District of Illinois on 2025-12-18 and terminated on 2026-03-11. One day before that termination, Fricker was filed in the Northern District of Illinois. Twelve days after it, Parrinello was filed in the Northern District of California. Nineteen days after it, Martinez landed back in the Northern District of Illinois before the same judge as Fricker. Four suits, three districts, ninety-nine days from first filing to fourth.
This page cannot tell you why Cruz terminated, because the docket entries behind it need a CourtListener account this page does not hold and PACER access it did not buy. What the sequence shows without any interpretation is that the filings did not stop when that case did, and that two different plaintiffs' firms were prepared to try the same theory in two circuits inside a month.
The two search warrants nobody has written about
On 2026-08-07 two separate dockets appeared in the Eastern District of Arkansas, both captioned United States v. Otter.AI Inc, both numbered 4:26-sw-00150, both filed and terminated the same day, carrying PACER case IDs 153807 and 153808. The sw prefix marks a search-warrant proceeding, which ordinarily means a warrant directed at a company for records rather than a prosecution of the company.
This page does not know what those warrants sought and asserts nothing whatever about Otter.ai's conduct. The reportable fact is narrower and more useful to a buyer. Transcripts of your meetings, held by a third party, are records a court can order that third party to produce, and in August 2026 a United States Attorney's office asked a federal magistrate for something from one of these companies. That exposure exists for every vendor in this category, it is a function of the architecture rather than of anybody's conduct, and it is on no comparison page in this market including, until today, ours.
Which vendors state their default in writing, and which will not
Sixteen tools, read from their own help centres, admin guides and terms. Where a vendor does not state something, the cell says so. An unknown is a finding here rather than a gap, because the whole point of the exercise is that a buyer cannot get the answer.
| Tool | Auto-join default | What the other party sees | Notice on by default? | Admin can force it? | Silent capture on the same plan? |
|---|---|---|---|---|---|
| Fireflies | Stated: joins all meetings with a web-conf link [vendor] | Named participant, always | No. Email and chat notices both opt-in [vendor] | Partial | Yes. Chrome extension on Google Meet, named by the vendor as the hidden-capture route |
| Chorus | Stated: excludes internal meetings and customer-organised meetings [vendor] | Named participant, admin can rename it | No. Pre-meeting email is an admin checkbox | Yes. Blocks named domains a rep cannot override | Not stated publicly |
| Gong | Not stated publicly | Named participant | Not stated publicly. Setup wording reads "Turn On" | Yes. "Enforce use of consent page" | Not stated publicly |
| Otter | Not stated publicly. Five options documented | Named participant | Conditional pre-recording email | Enterprise plan only | Not stated publicly |
| Fathom | Not stated publicly. Four options documented | Bot version yes, bot-free version no | No, and none at all for same-day meetings [vendor] | Not stated publicly | Yes. Bot-free desktop capture |
| Avoma | Not stated publicly | Bot yes, native cloud recording no | No. Instruction reads "Turn ON" | Strongest in the set. Org rules with Lock, four-level ladder to "Permission required" | Yes. Native cloud recording path |
| Grain | Not stated publicly. Rules across four articles | Bot Capture yes, Desktop Capture no | Consent modal in Bot Capture only | Not stated publicly | Yes. Desktop Capture: "There is no in-meeting consent mechanism" [vendor] |
| Clari Copilot | Not stated publicly | Named participant | Not stated publicly | Yes. Restricted domains a rep cannot toggle around | Not stated publicly |
| Attention | Not stated publicly. Four boxes referenced, never named | Notetaker participant | No. Beta, and only Attention can enable it | Can force recording off, cannot force disclosure on | Not stated publicly |
| Trellus | Not applicable. Attaches to the dialer | Nothing. Browser extension on WebRTC audio | None published | No. The only off switch belongs to each rep | The product is the silent mode |
| Aircover | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Markets "No Recording Required" while its privacy policy references meeting recordings and transcripts |
| Rilla | Not applicable. In-person, rep-initiated | Nothing on a call. A phone in the room | Not applicable | Contractual, not technical | The product is in-person capture |
| Hyperbound | Not stated publicly | Not stated publicly | Not stated publicly | Not stated publicly | Ships a call recorder and ingests from Gong, Chorus, Zoom and Teams |
| Second Nature | Not applicable. Roleplay only | No counterparty is ever present | Not applicable | Not applicable | No. This one is clean |
| Observe.AI | Not applicable. Ingests from the phone system | A property of your CCaaS, not of this tool | Not applicable | Help centre gated on read | Not applicable |
| Convin | Not applicable. Ingests from the phone system | A property of your CCaaS, not of this tool | Not applicable | Help centre gated on read | Not applicable |
Read the fifth column down and the pattern is the finding. Three vendors can force a policy against a rep who would rather not comply: Avoma, Clari Copilot and Chorus. One can force capture off but not disclosure on. One requires an Enterprise contract to lock anything at all. One publishes no admin control anywhere on its domain. Everything else is a training item, and a training item is not a control.
Two vendors that are not what the category page says they are
Hyperbound is filed as a roleplay simulator almost everywhere, including shortlists that exclude it from consent questions for that reason. It also ships its own call recorder and ingests from Gong, Chorus, Zoom and Teams to score real customer conversations, and its privacy policy does not use the word recording.
Aircover markets "No Recording Required" on its trust centre while its privacy policy states that meeting recordings and transcripts are processed by its third-party sub-processors. Both are first-party pages on the vendor's own domain, read the same day. Where two of a vendor's own pages disagree, publish the disagreement rather than picking the flattering one.
The silent modes ship on the same subscription as the visible ones
This is the part that defeats a policy written on the assumption that you bought one product. Five of these vendors sell a capture mode with nothing visible on the call, on the same plan, to the same user, with no separate purchase. Enabling the visible mode does not disable the other one.
- Grain. Bot Capture is a visible participant with a consent modal participants must accept. Desktop Capture, same subscription, states in Grain's own documentation: "There is no in-meeting consent mechanism, you are responsible for informing participants and obtaining consent." That is a vendor disclaiming the control in writing and handing it to you.
- Fathom. The bot-free experience captures inside the rep's own desktop application. Nothing joins the call, so nothing appears in the participant list, so the Illinois surreptitious-manner element and the Montana hidden-device element both become far easier to plead.
- Fireflies. Asked in its own documentation whether the bot can be hidden, it answers no, then names the workaround itself: for hidden capture, use the Chrome extension on Google Meet. The vendor supplied both halves of that sentence.
- Avoma. Alongside the bot there is a native cloud-recording path where no Avoma participant joins at all.
- Trellus. A browser extension attached to the WebRTC audio of your dialer. There is no per-call step and no channel through which the person called could learn it is there. Its terms state it "makes no representations or warranties with respect to call recording" while its marketing asserts that compliance features exist.
One founder said the quiet part on the record. In the Launch HN thread for the open-source notetaker Hyprnote on 2025-07-29 (item 44725306, 270 points, 180 comments), a commenter (44725708) put the tension plainly: "in many jurisdictions you legally need to disclose recording, having a bot join the call can do that disclosure, but users hate the bot and it takes up too much visibility on many of these calls."
The founder replied in the same thread (44725798): "yes, we're rolling out flexible consent options based on legal needs, like chat messages, silent bots, blinking backgrounds, or consent links before/during meetings." Silent bots, listed among the consent options, by the person building the product, in public. That is a roadmap statement and not a finding about a shipped product. It is worth quoting because it shows the category's own builders treating invisibility and disclosure as two settings on one dial, which is exactly the framing the Montana and Illinois language does not allow.
Zoom, Google Meet and Teams each answer this differently underneath
Underneath every tool in the table is a meeting platform with its own rules about recording notices and bot admission. Those rules are not the same across the three, and a policy written for one does not transfer to the others. More importantly, none of them covers the thing you actually bought.
| Platform | Platform recording notice | Who gets it | Does it fire for a third-party notetaker bot? | What that leaves you |
|---|---|---|---|---|
| Microsoft Teams | "All meeting participants will receive a notification in their Teams desktop, web, or mobile app as soon as a meeting recording starts" [platform] | All participants | No. It reports Teams recording, not a guest bot capturing its own stream | Microsoft's own docs add: "Depending on your region, you may need everyone's permission before you can record them" |
| Google Meet | Participants "get notified when a recording starts or stops, but they can't control the recording" [platform] | People outside your organisation, mobile app users and dial-in phone users. Google names those three groups specifically | No. Same limitation | The notice Google guarantees is about Google's recorder, and the categories it names are the ones least likely to be watching the screen |
| Zoom | Cloud recording is an account-level setting. Zoom's own help centre states it is "automatically enabled for all paid subscribers" [vendor] | Configurable at account, group and user level | No | A default-on recording capability plus a separate bot capturing separately is two recordings with one notice between them |
| Any third-party notetaker | Whatever the vendor ships, per the sixteen-tool table above | Whoever the vendor's setting says | This is the notice, and for most of the sixteen it is off | The platform layer will not save a misconfigured notetaker, and reps assume it will |
A practitioner made this exact point on the 2025 thread about notetakers flooding Zoom calls (44454753): "I think Zoom throws up a consent screen. Obviously if it's some 3rd party thing that joins the call as a recorder, you don't get that." That is one person's understanding on a public thread, not a legal conclusion, and it happens to be exactly what Microsoft's and Google's own documentation describes. Where a vendor doc and a practitioner thread agree, the claim is reportable, and this one is: the platform notice covers the platform's recorder and stops there.
The consequence for a sales team is that the same notetaker produces a different consent posture depending on which platform your customer sent the invite for. If your customers use all three, you have three postures whether or not you chose them, and the one the platform guarantees is never the one your bot is using.
The 25-minute default-capture audit you can run before you sign
You need two accounts you control, a calendar and 25 minutes. Run it on the free tier before procurement gets involved, because for fourteen of these sixteen tools the settings screen is the only documentation of the shipped default that exists.
| Step | Minutes | What to capture | Fail threshold |
|---|---|---|---|
| Photograph the settings screen before touching it | 0 to 3 | Screenshot of the recording settings page immediately after signup and calendar connection, with the file dated | Auto-join enabled, or disclosure disabled, or both |
| Schedule a meeting and do nothing | 3 to 8 | Whether a bot joins a five-minute meeting you never marked or invited it to | Anything joins a meeting you did not designate |
| Join three minutes early and talk | 8 to 13 | Whether the transcript contains conversation from before the nominal start time | Pre-meeting talk appears in the transcript |
| Check what the second account was told | 13 to 17 | In-meeting announcement, chat message or email, and whether it arrived before capture started | No notice reached the counterparty, or the transcript does not contain the announcement (see RCW 9.73.030(3)) |
| Try to delete the second account's words | 17 to 21 | Whether a non-user counterparty has any route to remove their own speech | They do not. Your counterparty's data is now your liability |
| Delete the meeting, then search for it | 21 to 25 | Whether the transcript is gone from search or merely unlisted, plus the default retention period rather than the configurable one | Deleted content is still retrievable, or the default retention is longer than your own policy |
Steps one and four are the two that matter most and they are the two people skip. The screenshot is the only artefact that survives a vendor changing a default later. Step four separates the tools that show a banner from the tools that record having shown one, which is the distinction Washington's statute is written around.
What this audit cannot detect
It cannot tell you what happens server-side after a deletion, whether a copy survives in backup, or whether any of it trained a model. It cannot tell you what happens at fifty seats rather than two, and auto-join behaviour is exactly the kind of thing that differs between a personal plan and a provisioned workspace, because a workspace default is set by whoever provisioned it. It cannot tell you what the vendor will do after an acquisition. For those questions the only route is the DPA and the sub-processor list, which is a slower exercise and a separate one.
What people say when a bot turns up uninvited
The oldest documented instance of the failure this page is about predates every case in the docket table by three years. On 2022-09-07 a Hacker News user posted Tell HN: Otter.ai bot recording meetings without consent (item 32751071, 612 points, 176 comments). The opening words:
That is one person's account of one incident from 2022, not a finding of fact, and it says nothing about how the product ships today. It is worth citing for a narrower reason. It describes a default changing under a user who had already opted out, which is the one failure mode no vendor's documentation covers and the exact thing the dated screenshot in step one is designed to catch.
The disagreement in that thread is more useful than the complaint. One commenter (32752776) argued that "transcriptions of calls don't GENERALLY run into the multi-party consent state laws, because the concept of a non-human listening/transcribing a call didn't exist when most of those laws were created." Another (32752314) replied that "in an all-party consent state you would need everyone in the call to consent for recording to be legal, but even in one-party consent states you would still at least need OP's consent to be recording."
Neither is a legal conclusion. Both are the argument the complaints filed three years later are now testing, and competent engineers being split on it in 2022 tells you how confidently a vendor's marketing page should treat it.
The volume problem arrived later. AI note takers are flooding Zoom calls as workers opt to skip meetings reached the front page on 2025-07-02 (44446916, 321 points, 386 comments), and its most-quoted comment (44454688) draws the distinction this page is built on:
That is one person's characterisation and not a finding of fact. It is also, close enough, the fact pattern pleaded in the Otter and Fireflies complaints, and it is what your prospect's security team believes about your bot before they have met you.
Two further threads make the same complaint from opposite sides: 43053921 (Please Stop Inviting AI Notetakers to Meetings, 2025-02-14, 39 points) and 48823024 (2026-07-07, 60 points, 101 comments), a rebuttal arguing people should simply decline. In the rebuttal a commenter (48824328) names the real objection: "there is an assumption that they are okay with being recorded." A market where the rebuttal outscores the original three to one has no settled norm, and where there is no norm your default setting does the arguing for you.
What breaks in month three
The rollout is not where this goes wrong. Month one is fine, because somebody is watching. Four things show up later and all four are visible in the material above.
- The default moves under you. The 2022 Otter thread describes exactly this: an update that re-enabled auto-join for a user who had disabled it. No vendor in this set publishes a changelog entry when a default changes, so your only defence is the dated screenshot from step one and a recurring reminder to re-take it every 90 days.
- A rep finds the silent mode. Grain's Desktop Capture, Fathom's bot-free mode, Avoma's cloud path and the Fireflies Chrome extension all exist on plans your team already has. A policy that says "the bot must announce itself" does not survive a rep who stops using the bot.
- Someone leaves and the transcripts do not. Meeting transcripts are the most quotable artefact your company produces and they sit in a third-party system on a retention default you did not choose. The two E.D. Ark. search-warrant dockets of 2026-08-07 are a reminder that your vendor is a custodian of your conversations whatever your own retention policy says.
- Your customer's security team finds the dockets. There are ten in the table above and they are free to read. If your enterprise deal is with a company that has staff in California or Illinois, expect this in the security questionnaire, and expect the right answer to be a paragraph about your configuration rather than a defence of your vendor.
The three things this audit could not settle
Three gaps are worth naming here rather than burying, because each one changes what you should do with the rest of the page.
The first is that seven of the fifteen jurisdictions in the statute table have not been checked against primary statute text. Those cells are marked. If your rollout turns on Massachusetts, New Hampshire or Nevada specifically, get the text from your own counsel rather than from this table, because this page does not know what those statutes currently say.
The second is that the litigation posture reported here is what a free, unauthenticated RECAP index shows. Docket entries require an account this page does not hold. This page does not know why Cruz v. Fireflies.AI Corp terminated, and it does not know what the two Arkansas search warrants sought. Where it does not know, it reports the fact of the docket and stops.
The third is the shipped default itself, for fourteen of sixteen tools. It is the measurement this whole category is missing, it is the one you can produce yourself in an afternoon, and the section below says exactly how.
Who should stop reading this page
If your team records only internal meetings, in a single one-party state, on accounts your company owns, most of this does not reach you. Buy on transcript quality and integration depth and stop here. The same applies to Second Nature or any pure roleplay simulator: no counterparty is ever present, the consent question genuinely does not arise, and your real question is about employee monitoring, which is a different statute in a different chapter.
If you are a contact centre buying Observe.AI or Convin, the consent behaviour belongs to your CCaaS platform rather than to these products, because they ingest from your phone system instead of joining meetings. Go and read your dialer's disclosure configuration instead.
What to do on Monday
Four steps in this order, and the first one takes ten minutes.
- Run step one of the audit on whatever is already installed. Not on the shortlist. On the tool a rep installed eight months ago that nobody approved. Screenshot the settings page and date the file. If auto-join is on and disclosure is off, you have found in ten minutes the thing you were going to spend a week looking for.
- Ask your shortlisted vendor two questions in writing. Is the recording notice on by default for a new account on the plan we are buying, and can an admin lock it workspace-wide? For Attention the honest answer is that only the vendor can enable it. For Otter it costs an Enterprise contract. Both are much cheaper to learn now than at renewal.
- Check whether a silent capture mode exists on the plan you are buying. Grain, Fathom, Fireflies and Avoma each have one on the same subscription as the visible mode. If it exists, your policy has to name it, because your reps will find it.
- If you have people in any of the nine clear states, make disclosure a locked setting rather than a training item. Avoma, Clari Copilot and Chorus are the three here that can enforce it against a rep who would rather not. Everything else is a request. Then check the vendor still exists, because a transcript archive at a company that shut down is a different problem again.
So which AI notetakers record by default?
Two of sixteen will tell you and they give opposite answers. Fireflies joins every meeting with a conference link and says so in writing. Chorus stays out of your internal meetings and out of anything your customer organised, and says that too. Those are the only two vendors in this category that have given a buyer a documented starting position, and which one you want depends entirely on whether you would rather over-capture and prune or under-capture and chase.
For the other fourteen the honest answer is that the vendor will not tell you and there is no route to the fact except a trial account and a screenshot. That is a strange thing to be true of a $10-to-$40-a-month product whose misconfiguration carries a $5,000-per-head statutory exposure in the largest state in the country, in front of a plaintiff bar that filed 298 claims under that statute in the first eight months of this year. It is stranger still that ten open dockets across three vendors have not moved a single one of the fourteen to publish one sentence.
So treat the settings screen as the documentation, run the 25-minute audit before procurement rather than after, and choose from the three tools that can lock a policy rather than the eleven that can only recommend one. The statute does not care what your handbook says. It cares what the bot did.