AI note-taking startup Granola faces a class-action lawsuit alleging its software secretly records and transcribes virtual meetings without participant consent and uses the data for AI model training by default.
Tarra Chamberlain, a Florida resident, alleged that Granola captured and transcribed her speech during a virtual meeting without her knowledge or consent after another participant used the AI notetaker. Her July 2026 lawsuit further alleged that Granola uses meeting data to improve its AI models by default, while non-user participants have no comparable opt-out.
Risk classification
- Primary risk domain: 2 Privacy & Security
- Primary risk subdomain: 2.1 Compromise of privacy by obtaining, leaking or correctly inferring sensitive information
The incident centers on the unauthorized capture, transcription, and subsequent AI model training use of private, non-public meeting conversations without participant consent.
Causal factors
- Entity: Human
- Intent: Intentional
- Timing: Post-deployment
The privacy risks and lack of notification were caused by intentional human design and marketing decisions implemented in the deployed Granola software.
EU AI Act risk tier
- Risk tier: 3 Limited Risk
Limited Risk: The system is an AI-powered transcription and note-taking tool. Under the EU AI Act, such systems pose moderate risk and require specific transparency obligations, such as notifying users when they are interacting with an AI or when AI-generated content is being used, which is the core issue in this lawsuit.
AI system and alleged parties
- AI system: Granola
- AI purpose: Voice Recognition; Writing Assistant
- Behaviour type: Assistant
- Alleged developer: Granola, AI transcription technology developers
- Alleged deployer: Granola, AI transcription tool users
- Alleged harmed parties: Tarra Chamberlain, Privacy, People recorded without consent
Harm severity
Highest direct severity in any category: Severe. Severity is scored from Negligible to Catastrophic in each harm category, for harm the reports describe as caused directly or indirectly by the AI system.
- Physical: direct Negligible, indirect Negligible
- Infrastructure: direct Negligible, indirect Negligible
- Property: direct Negligible, indirect Negligible
- Financial: direct Negligible, indirect Negligible
- Environmental: direct Negligible, indirect Negligible
- Malicious content: direct Negligible, indirect Negligible
- Differential treatment: direct Negligible, indirect Negligible
- Civil rights: direct Substantial, indirect Negligible
- Democracy: direct Negligible, indirect Negligible
- Privacy: direct Substantial, indirect Negligible
- Psychological: direct Negligible, indirect Negligible
- Epistemic: direct Negligible, indirect Negligible
- Child sexual exploitation and abuse: direct Negligible, indirect Negligible
Civil rights
Reported: The report describes potential violations of privacy rights protected under federal and state wiretapping laws.
Directly caused: The unauthorized interception and recording of meeting participants' communications directly violates their legal privacy rights.
Indirectly caused: N/A
Inferred additional harm: Millions of individuals may have had their civil privacy rights violated through undisclosed recording and subsequent AI model training.
Privacy
Reported: The report explicitly describes widespread privacy violations concerning the unauthorized recording and transcription of virtual meetings.
Directly caused: Granola's software recorded and transcribed meeting participants' communications without their consent or knowledge, using this personally identifiable voice and conversational data for AI model training by default.
Indirectly caused: N/A
Inferred additional harm: It is highly likely that millions of meeting participants have had their private conversations captured, transcribed, and permanently incorporated into AI models without their consent.
People affected
- Occurrences reported: 1
- People reportedly harmed: 1
- People reportedly exposed: 1
Potential causes
Management
- Prioritizing Stealth as Feature: Management marketed the invisible nature of the tool as its core differentiator.
- Default Opt-Out Training Policy: Management chose default-on training, forcing manual opt-out for users.
- Poor Vendor Risk Assessment: Companies deploy AI tools without evaluating model training data deletion rights.
Technology
- Stealth Recording Mechanism: Captures system audio directly without spawning a visible meeting bot.
- Irreversible AI Model Training: Once data is incorporated into models, it cannot be extracted or deleted.
- Biometric Voiceprint Generation: Fireflies.ai generates biometric speaker profiles without participant consent.
Data Inputs
- Default AI Model Training Use: Meeting transcripts are used for AI training by default on standard plans.
- Non-Consenting Participant Data: Captures audio of external meeting participants who never agreed to recording.
- Public Link Sharing: Shared meeting notes can expose transcript summaries to unauthorized parties.
Human Factors
- User Neglect of Notice Settings: Users rarely enable optional chat notifications or video watermarks.
- Lack of Participant Awareness: Invisible tools leave participants unaware that their voices are being captured.
- Shadow-IT Deployment: Employees deploy unvetted AI tools without IT department approval.
Process and Methods
- Liability Shifting to Users: Vendors shift compliance and consent responsibilities entirely to the end-user.
- Viral Application Propagation: Otter.ai auto-joins calendars and propagates via automated email invites.
- Inadequate IT Auditing: Organizations lack processes to inventory and block unauthorized AI assistants.
Regulatory Environment
- Outdated Privacy Laws: Existing wiretap laws like ECPA struggle with modern ambient AI recording.
- Non-Purchaser Legal Gaps: Privacy laws are inadequate for protecting non-purchasers recorded by AI.
- Strict All-Party Consent Laws: State laws like CIPA require consent from all parties, creating legal exposure.
Information quality
- Classification confidence: High
- Reason for confidence: The reports provide detailed legal and factual descriptions of the class-action lawsuit, the technical mechanism of the Granola software (capturing system audio directly), and the specific privacy laws allegedly violated. The claims are clearly laid out, and the company's public documentation and marketing are quoted directly.
- Ambiguities identified: The exact number of affected individuals is not yet determined as the lawsuit is in its early stages and seeking class certification.
- Alternative interpretations: None. The incident is clearly a privacy and data consent dispute regarding an AI note-taking application.
A class-action lawsuit against AI startup Granola highlights risks of unauthorized meeting recordings and default data usage for AI training. While posing minor risks to corporate privacy and intellectual property, the incident is primarily a civil legal and regulatory matter with negligible immediate national security impact.
- Overall national security impact: Minor
- Response level: Moderate
- Scope: Single nation
- Primary target: United States
- Alleged perpetrator: Granola, Inc.
Threat characteristics
- Imminence: Long-term. The situation is a civil legal dispute regarding privacy policies and product design, representing a long-term regulatory and data governance concern.
- Autonomy: Human-controlled. The AI tool acts as an assistant to transcribe and summarize meetings, operating entirely under the direction and initiation of the human user.
- Novelty: Evolved capability. While automated transcription is established, using direct system audio capture to bypass platform-level recording notifications represents an evolved privacy threat.
Impact by dimension
- Physical security: Negligible. The incident involves a software-based note-taking application and poses no threat to physical systems, critical infrastructure, or human safety.
- Information security: Minor. The secret recording of virtual meetings poses a minor risk of exposing sensitive or proprietary corporate and organizational information, though no active espionage is indicated.
- Sovereignty: Negligible. There is no evidence of foreign state involvement, compromise of government decision-making, or disruption to constitutional processes.
- Economic security: Minor. Default model training on corporate meeting data poses minor risks to intellectual property and proprietary business information of affected organizations.
- Societal stability: Minor. The incident highlights widespread privacy concerns and potential violations of civil privacy rights under wiretapping laws, but does not threaten overall societal stability.