A federal judge in San Jose spent twenty-three pages last Thursday on a question your firm answered months ago by clicking Allow. What decided it was not whether anyone consented. It was what the vendor did with the recording afterward.

THE LEAD PLAY

The Notetaker Kept a Copy for Itself

Judge Eumi Lee denied most of Otter.ai's motion to dismiss on August 13, in a case captioned In re Otter.AI Privacy Litigation, No. 25-cv-06911-EKL (N.D. Cal.). The federal wiretap claim survives. The California Invasion of Privacy Act claim survives. The Illinois biometric claims survive, voiceprints included. The computer-fraud counts were dismissed with leave to amend, and plaintiffs have fourteen days from the order to replead.

The product is the Otter Notetaker, which joins Zoom, Microsoft Teams, and Google Meet calls as what the complaint calls a "silent participant." The court's framing in the first paragraph: it records and transcribes conversations in real time "without obtaining the consent of all meeting participants."

CIPA has a shape everyone in legal ops half-knows. A party to a conversation can record it. A stranger listening in cannot. Every vendor case turns on which one the software is, and the working answer has come from Graham v. Noom, where a court held a software vendor was "an extension of Noom" that provided "a tool . . . that allows Noom to record and analyze its own data," and so was not intercepting anything on its own account.

Otter argued it sat on the Graham side of that line. The court held the allegations put it on the other side:

"Because Plaintiffs plausibly allege that Otter independently collects, retains, and uses communications for its own commercial purposes, they have sufficiently alleged that Otter is a third-party eavesdropper under section 631."

Recording is not what moved Otter across the line. Retention plus use did, and specifically the allegation that Otter keeps conversational data and uses it "to improve its machine-learning models and services." The same fact carried the wiretap count, where the court accepted at the pleading stage that a primary motivation for the interception was tortious. On that point the order quotes another case flatly: "committing a tort and seeking a profit are not mutually exclusive."

So the line runs between a tool your firm points at its own data and a tool that keeps what it hears for the vendor's own benefit. Nothing in that distinction turns on how the recording was disclosed, or on what your engagement letter says.

Otter's fallback argument is the one most firms are quietly relying on. It said the plaintiff saw the Notetaker sitting there in the participant list and should have understood what that meant. The court would not infer it: "Even if the Otter Notetaker appeared in the meeting as another participant, the Court cannot infer that Dolan knew his communications were being recorded, transcribed, and retained by Otter." A visible bot in the roster is not consent.

None of this makes every recorded call actionable, and the order is careful about that. Two plaintiffs who described what was taken as "private conversational data" and as "sensitive" workplace discussion lost their intrusion claims outright. The plaintiff who survived, Chaka Theus, alleged Otter intercepted a call with a medical provider involving "deeply personal and private medical information." Pleaded specificity did the work, which means the calls that generate real exposure at a law firm are the ones where the subject matter is the point.

In footnote 2, Judge Lee flagged Amazon.com Services v. Perplexity AI, decided in the Ninth Circuit nine days earlier, and declined to rely on it because the parties never had a chance to brief it. She noted anyway that it "casts doubt on whether Plaintiffs can state a CFAA claim based on their current theory that Otter accesses Plaintiffs' computers indirectly through the acts of Otter users who deploy the Notetaker." We led on that holding a week ago as an agent-liability case. It is already being read as a defense.

The Play this week: Pull the terms for every meeting assistant, transcription service, and AI notetaker touching your firm's calls. Two questions.

First, does the contract permit the vendor to use your recordings, transcripts, or anything derived from them to train or improve its own models and services? You are not looking for a security promise. You are looking for a reservation of rights, and that clause is the distinction the Otter court drew between a tool and a party. If the answer is yes, find out whether there is a switch, whether it is off, and who at your firm is on a plan that even has one. Enterprise agreements commonly default to no training. Individual and team plans commonly do not, and whoever signed up with a firm card is not on the enterprise agreement.

Second, what does your intake and deposition workflow do about the people on the call who never agreed to anything? The visible-participant argument failed here. If your consent practice amounts to the bot appearing in the roster, it covers your side of the call and nobody else's.

Where the first answer comes back wrong, the renewal ask is one sentence. The vendor processes your data solely to provide the service to you, and does not use it to train, improve, or develop any product or model.

SECOND CHAIR

The tool nobody vetted

On August 11 a senior associate at Musick, Peeler & Garrett filed a declaration in Los Angeles County Superior Court explaining how citations to cases that do not exist ended up in State Farm's motions in limine. Her count, from the declaration: "there were seven (7) case citations across State Farm's eight (8) motions in limine that simply did not exist." The seven were concentrated in three of the motions.

The tool was not ChatGPT. It was Irys, a legal-specific product sold at $299 per seat per month.

Jacquelene Robinson's explanation is the part worth circulating internally: "I regrettably did not check some of the cites I chose to include in the filed pleadings, and I believed, incorrectly, that the program was tied to and vetted through our firm's subscription to the Westlaw legal research tool and performed an internal cite check."

Alongside the invented cases were real ones carrying quotations they do not contain, two attributed to Rattan v. United Services Automobile Association and two more to Nickerson v. Stonebridge Life Insurance. Nobody inside the firm caught any of it. Opposing counsel raised the fabrications at the Final Status Conference on August 7, and Robinson states that was the first she knew. No order to show cause has issued and no sanctions have been imposed.

The read: Verification failed, but the failure that matters happened earlier. A competent associate could not tell which of the tools available to her sat inside the firm's vetted research stack and which one was sitting next to it. Ask your litigators to name every research tool they touched on their last brief, then set that list against what your firm actually pays for and has diligenced. The delta is your exposure.

Your drafts may now carry a mark

Anthropic published documentation this month, followed by a technical post on August 14, describing how Claude now weaves "an imperceptible watermark directly into the text itself." Supported image files get C2PA content credentials in metadata instead. Audio and video are not covered. Models launched on or after August 2 "support marking at launch," older models are still being retrofitted with no announced date, and the marking applies "wherever Claude is offered, worldwide."

The forcing function is Article 50(2) of the EU AI Act, which requires providers of systems generating synthetic text to "ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated." Article 50 applied from August 2. Fines for transparency breaches reach 15 million euros or 3 percent of total worldwide annual turnover, whichever is higher.

The limits are documented as plainly as the feature. Light editing "probably won't remove the watermark completely; a complete rewrite where every word is replaced will." File metadata comes off through "format conversion, re-saving, screenshots, or other means." When Claude proofreads something a person wrote, "there's very little (if anything) for the watermark to attach to." And absence proves nothing: "Lack of a detected mark doesn't mean the content wasn't AI-generated or processed."

The read: No detection tool exists yet. Anthropic says one is coming and has not said who gets access, and a hit will establish only that text "may have been processed by Claude." That is thin. It is also the first time somebody outside your firm will be able to ask how a document was drafted and get an answer that does not come from you.

STILL WATCHING

  • California SB 574 came off the Assembly Appropriations suspense file on August 13, reported do pass as amended on an 11-0 vote, then read a second time and amended the same day. It now sits at second reading. The Code of Civil Procedure section 128.7 language survived: a paper filed in any court "shall not contain any citations that an attorney responsible for submitting the pleading has not personally read and verified, including any citation provided by generative artificial intelligence." The bill also adds a new Business and Professions Code section 6068.1, and that sentence is short enough to quote in full. "An attorney shall not delegate the practice of law to generative artificial intelligence." Both houses must pass bills by August 31, and the Senate still has to concur in the Assembly amendments.

  • Thomson Reuters v. ROSS Intelligence, No. 25-2153, argued in the Third Circuit on June 11. Sixty-seven days, no opinion.

  • The Copilot for Word prompt injection. Microsoft shipped three Copilot CVEs on August 11: a Copilot Chat security feature bypass, a GitHub Copilot elevation of privilege, and a Copilot Cowork authorization flaw. None of them is the chain Håkon Måløy disclosed. That is 165 days since he reported it and 21 since he published it.

  • In Cole v. Hobby Town Unlimited (C.D. Ill.), the response to Judge Darrow's show cause order came due August 7. Nothing has appeared on the public docket since the July 24 order.

QUICK HITS

  • The people getting caught are mostly not lawyers anymore. Damien Charlotin's tracker logged 1,922 hallucination cases worldwide as of Sunday, 1,313 of them American. Of the fifteen decisions dated in the past week, ten involved self-represented litigants, four involved lawyers, and one involved an expert witness. The remedies at that end of the docket are getting inventive. In Voyton v. Voyton (M.D. Pa., August 11), Judge Julia Munley ordered a pro se plaintiff to attach a separate affidavit to any future filing "disclosing whether generative AI has been used to prepare the filing," naming the tool, explaining how it was used, identifying "each section of each filing drafted using AI," and certifying that she "personally checked the accuracy of the citation and the proposition for which it is offered."

  • A sanction that follows the lawyer instead of the case. In Chapman v. City of Priceville (N.D. Ala., August 12), Judge Harold Mooty III found two cases that do not exist, quotations attributed to seven cases that do not contain them, and at least two more statements unsupported by the authority cited. He declined a fine, declined a referral to the Alabama State Bar, declined disqualification and suspension. Instead he publicly reprimanded the attorney and ordered him to deliver the order to opposing counsel and the presiding judge in every pending state or federal case in which he is counsel of record, by 4:00 p.m. on August 24, with certification of compliance within twenty-four hours. The clerk was directed to submit it for publication in the Federal Supplement. From the order: "Attorneys should not wait to take corrective action until they know whether they will get in trouble for failing to do so."

  • Legora is reportedly in early talks above $10 billion. The Financial Times reported on August 13 that the Swedish company is seeking a valuation north of $10 billion, roughly four months after a $600 million Series D closed at $5.6 billion. Legora declined to comment. That lands six days after The Information reported Harvey in talks for at least $500 million at $15.5 billion, against more than $350 million in annualized revenue. Neither company has announced a round.

  • Two competitors agreed on how to hand each other their users. DeepJudge published an Agent Handoff Protocol on August 13, an open specification on GitHub with no license fee and no reference implementation, for passing a user's objectives, supporting materials, conversation history, and prior work from one AI product into another. Harvey says an integration enters beta this month. Thomson Reuters says it is supporting the protocol, with details to follow. Harvey CTO Siva Gurumurthy: "The most capable legal workflows will draw on more than one specialized system." That is an unusual thing to say if you are selling an end-to-end platform, and both of them are.

Somebody at your firm switched on a notetaker this morning. Find out what its contract lets the vendor keep.

See you in the next one.