Futureman Labs

Fractional Ops

AI Notetaker Consent Risk: What Sales Teams Must Verify

Otter.ai and Fireflies face recording-consent lawsuits. Here is what to verify before an AI notetaker records sales calls and feeds them into your CRM.

David Yu · September 30, 2026 · 9 min read

A laptop showing a support inbox triaged into queues, beside a headset

Here is a scenario that plays out as sales teams roll out AI notetakers across every call. A RevOps lead turns on Fireflies or Gong for the whole team, the bot joins every meeting automatically from the calendar, and call summaries start flowing into the CRM within minutes of each conversation ending. Three weeks in, a prospect on a discovery call notices the bot's name in the participant list, asks who put it there and what it does with the recording, and nobody on the call has a clean answer. The rep did not choose to add it. The manager who turned it on for the whole team never wrote a disclosure script. The recording already happened.

That gap between "we turned on a useful tool" and "we can explain, in one sentence, why this is legal" is the subject of this post. It is not a reason to avoid AI notetakers or automated CRM logging. It is a reason to close the gap before it becomes a real complaint, or worse, a real lawsuit.

Why This Question Gets Skipped

Most sales teams adopt AI notetakers the same way they adopt any other productivity tool: someone tries it, likes it, and turns it on for the team. The rollout decision usually sits with a sales manager or RevOps lead, not with legal or compliance, because the tool feels like an internal efficiency upgrade rather than a data-collection program. Nobody explicitly decides "we are now recording every external call with strangers on the other end and storing that audio in a third-party system," even though that is exactly what happened.

The recording laws that apply have not changed to accommodate this. US call recording law splits along a line that predates any of these tools: federal law and most states follow one-party consent, meaning the call can be recorded as long as one participant (typically the person who initiated the recording) agrees. A smaller group of states require all-party consent, meaning every person on the call has to agree, not just the rep. California, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington are generally treated as core all-party-consent states, with Connecticut, Michigan, Oregon, and Vermont carrying narrower or mixed rules depending on how the call happens.

For a sales team calling prospects across the country, that means the applicable law is not decided by where your office sits. It is decided by where the person on the other end of the call happens to be, which a rep usually does not know in advance and a notetaker tool has no way to check.

This Is Not a Hypothetical Risk

Two real, reported cases show what happens when this gets skipped at scale. Otter.ai currently faces four consolidated federal lawsuits over how its AI notetaker records meeting participants without obtaining their explicit consent. Separately, Fireflies.ai faces two lawsuits filed in Illinois under that state's biometric information privacy law, which treats a voiceprint extracted from a recording as biometric data subject to its own consent requirements, distinct from ordinary call-recording consent.

Neither company built its product to break the law. Both built a genuinely useful tool that joins calls, listens, and produces a transcript and summary, then scaled it to millions of meetings before consent design caught up with adoption. The lesson for a sales team evaluating or already running one of these tools is not "these vendors are bad." It is that the compliance question does not go away just because the tool is popular, well-funded, and easy to turn on.

Every mainstream AI notetaker (Fireflies, Otter.ai, Gong, Chorus, Fathom, Grain) now joins video calls as a visible participant, usually labeled with the product's name. Some vendors point to this visibility as evidence that recording is disclosed: the other side can see the bot, so they know a recording is happening.

That argument does not hold up well. A participant seeing a bot named "Fireflies.ai Notetaker" in a call window knows that something is present. They do not necessarily know what it does with the audio, whether it is stored, whether it feeds a model, how long it persists, or whether it will end up quoted verbatim inside a CRM record their sales rep's manager can read. The gap between "I noticed a bot joined" and "I agreed to be recorded and understand what happens to that recording" is exactly the gap plaintiffs are arguing about in the Otter.ai and Fireflies cases.

Some notetakers try to close this gap with an automated spoken announcement at the start of the call, or a calendar-invite disclaimer sent to every attendee before the meeting starts, with a real way to decline. Fireflies, for example, supports an email disclaimer to invitees with an opt-out that keeps its bot from joining if a participant declines. Whether that protection actually works for your team depends on whether the setting is turned on, whether it is configured for external as well as internal meetings, and whether anyone has actually checked that the announcement plays before sensitive content gets discussed. Most teams that have this feature available have never verified it fires correctly.

What This Means Once the Recording Reaches Your CRM

For a sales team, this is not only a call-recording problem. It is a CRM data problem, because the output of that recording, a transcript, a summary, sometimes an audio link, does not stay inside the notetaker. It gets pushed into the CRM as an activity note, a task, or an attachment on the deal and contact record. That is the entire point of auto-capture: get the record of what happened onto the deal without a rep re-typing it.

Once that transcript is sitting inside your system of record, any consent problem with the original recording is now a data problem inside your CRM too, and it is retained for as long as the deal record exists, often years. That is a meaningfully different exposure than a recording that lives only in the notetaker vendor's system for a few months. If you cannot show that a call was recorded and stored lawfully, you also cannot cleanly explain why a transcript of that call sits permanently on a contact record that sales leadership, RevOps, and potentially a future auditor can access.

This is the same reasoning behind the approve-before-write model this site covers elsewhere for CRM data hygiene: a human checkpoint before content writes into the system of record catches problems that pure automation does not. Consent is one more thing worth checking at that checkpoint, alongside data accuracy. For a closer look at where AI notetaker output does and does not map cleanly onto CRM fields in the first place, see AI notetaker vs. CRM auto-logging.

A Practical Rollout Checklist

None of this means turning off AI notetakers. It means treating the rollout as a compliance decision with a few concrete steps, not just a tooling decision.

1. Assume you will talk to people in all-party-consent states. If your prospect list includes California, Illinois, or any of the other all-party states even occasionally, design your default process around getting clear consent, rather than trying to detect state law per call in real time. It is simpler to disclose on every call than to build logic that only discloses sometimes.

2. Turn on the vendor's built-in disclosure feature and verify it actually works. Check whether your notetaker sends a pre-meeting disclaimer to external attendees, whether it announces the recording at call start, and whether an opt-out genuinely stops the bot from joining or listening. Test it on an external call before assuming it is live.

3. Put a one-line disclosure into the rep's actual call opener. Something as short as: "Quick heads-up, I've got an AI note-taker on this call so I can focus on the conversation instead of typing. Let me know if you'd rather I turn it off." This takes five seconds, works regardless of which state anyone is in, and tends to build trust rather than create friction, because it frames the tool as being for the prospect's benefit (a better conversation) rather than surveillance.

4. Decide what should not get written to the CRM. A transcript captures everything said on a call, including things a prospect mentions that have nothing to do with the deal. Define what is fair game for the CRM record (deal-relevant content: budget, timeline, decision process, objections) and what should not be copied into a permanent business record just because it was said out loud. This is the same "what stays private" question that governs any automated activity capture system, not a new problem specific to notetakers.

5. Check the vendor's data retention and model-training policy before scaling to regulated conversations. If your sales calls ever touch regulated information (health, financial, or legal details a prospect volunteers), confirm whether the notetaker vendor retains recordings for model training and whether that is something your business can agree to on the prospect's behalf. This is a separate question from call-recording consent and deserves its own review, especially in an all-party state where a biometric privacy statute may also apply to the voiceprint itself.

Where This Fits With the Rest of Your Pipeline

Consent is the first checkpoint, not the whole compliance program, and it is worth solving once rather than per rep. Once calls are being recorded and disclosed properly, the next problem is making sure what gets captured actually turns into accurate, structured pipeline data instead of an unqueryable pile of transcripts. That is the same approve-before-write discipline this site covers for CRM auto-logging generally: capture the activity, draft the update, let a human confirm it before it writes. If you want to see where your own pipeline currently stands on activity capture and structured field accuracy, check your pipeline coverage is a fast starting point.

Getting the consent question right does not slow down adoption. It is a five-second script and a checked setting. What it prevents is a recording program that scales past the point where anyone can explain, in one sentence, why it is legal, which is exactly the position Otter.ai and Fireflies now find themselves defending in court.

Is your firm AI-ready?

Take the free Law Firm AI Readiness Scorecard. Get a grounded, practical report on where AI safely saves your firm time, and where it is a liability.

Get your free AI scorecard

Frequently Asked Questions

Is it legal to use an AI notetaker on sales calls?

It depends on where the people on the call are located. Federal law and most states allow recording with only one party's consent (the rep's), but eleven states require every participant to consent, and a handful of others have mixed or unsettled rules. If any participant is in an all-party-consent state, the safest approach is to get clear, affirmative consent before recording, regardless of what state your team is calling from.

Which states require all-party consent for call recording?

California, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington are generally treated as all-party-consent states. Connecticut, Michigan, Oregon, and Vermont have mixed or narrower rules depending on the type of call. This is a general guide, not legal advice; confirm current requirements with counsel before you scale a recording program.

Are there real lawsuits against AI notetaker companies over recording consent?

Yes. Otter.ai faces four consolidated federal lawsuits over how its notetaker records meeting participants without explicit consent, and Fireflies.ai faces two separate biometric privacy lawsuits filed in Illinois under that state's biometric information law. These are active, reported cases, not a hypothetical risk.

Does a visible AI notetaker bot in a call count as consent?

No. A bot labeled with the tool's name in a participant list shows that something is present, but it does not explain what the tool records, where the audio is stored, whether it is used to train models, or how long it is kept. Awareness that a bot joined is not the same as informed consent to be recorded.

What should an AI notetaker consent disclosure include?

A clear statement that the call is being recorded and transcribed by an AI tool, what the recording is used for (CRM notes, coaching, deal summaries), and a real way to opt out or ask for the tool to stop. Most notetakers now support this as a calendar-invite disclaimer or an automated announcement, but the setting has to be turned on and checked, not assumed.

Want help mapping what to automate first?

Book a short call. No pitch deck, just a working session on where your operations leak time and money and what to fix first.

Book a call