AI Meeting Bots Are Collecting Your Voiceprint — What the Fireflies.AI Lawsuit Reveals
Two 2026 class actions allege Fireflies.AI harvested voiceprints from participants who never signed up. The EU AI Act enforcement deadline hits August 2.

AI Meeting Bots Are Collecting Your Voiceprint — What the Fireflies.AI Lawsuit Reveals
Something shifted this week.
On July 9, a wire story from the Associated Press ran across dozens of outlets — the Washington Post, ABC News, and regional papers from coast to coast. The headline: "AI notetakers promise easy meeting recaps, but some professionals question their use." Measured framing for what the story actually says: professionals are learning that an AI bot in their meeting may be processing a biometric record of their voice without their knowledge, and some are now refusing to attend recorded meetings until they get straight answers about what's being collected and why.
That's not a technology objection. It's a legal one — and a legal one with class actions already filed to back it up.
What Fireflies' Speaker Recognition Actually Does
Fireflies.ai is one of the most widely used AI meeting tools on the market. Like other bot-based note-takers, it joins your Zoom, Teams, or Google Meet session as a participant, records the conversation, and returns a transcript. One feature sets it apart: Speaker Recognition, which identifies different speakers and attributes their words in the transcript.
To identify speakers across meetings, Fireflies' Speaker Recognition generates a voiceprint — a unique mathematical representation of each voice. It's the audio equivalent of a fingerprint. Under Illinois law, a voiceprint is a biometric identifier, legally equivalent to a fingerprint or retinal scan. Collecting it requires specific written notice, documented retention policies, and explicit consent — none of which is provided to most people in a recorded meeting, because most of them never interacted with Fireflies at all.
Two Lawsuits, Filed Months Apart
In December 2025, Katelin Cruz filed a class action against Fireflies.AI Corp. in the U.S. District Court for the Central District of Illinois — Cruz v. Fireflies.AI Corp., No. 3:25-cv-03399. The core fact in her complaint: she participated in a virtual meeting hosted by an Illinois nonprofit that had Fireflies enabled. She had never created a Fireflies account. She had never agreed to its terms of service. She had no relationship with the company. Her voice was processed by its Speaker Recognition system anyway.
Three months later, on March 10, 2026, a separate plaintiff filed a second class action in the Northern District of Illinois — Fricker v. Fireflies.AI Corp., Case No. 1:26-cv-02675. Same allegations, same legal theory.
Both complaints allege Fireflies violated the Illinois Biometric Information Privacy Act, known as BIPA, in three specific respects: failing to maintain and publicly publish a data retention schedule and destruction policy for biometric data; failing to inform participants in writing that voiceprints were being collected and for how long; and collecting voiceprints without obtaining written consent from participants — including participants who had never signed up for Fireflies and had no agreement with the company at all.
BIPA is among the strictest biometric privacy laws in the United States. Statutory damages run $1,000 per negligent violation and $5,000 per reckless or intentional violation. In a class action with hundreds or thousands of affected meeting participants, those numbers compound quickly.
No court has adjudicated the merits of either case. Fireflies disputes the claims. But the litigation makes specific, detailed allegations about how Speaker Recognition works — allegations that, if sustained, would have significant consequences for any meeting tool that performs speaker identification on people who didn't consent to be identified.
The Person Most Exposed Never Used Fireflies
The aspect of these cases that most professionals don't immediately register: the plaintiffs in both class actions are non-subscribers.
Katelin Cruz had no Fireflies account. She walked into a meeting — one organized by someone else, one where a Fireflies bot had been set up by the organizer — and her voice was processed into a biometric identifier. Nothing she did, no terms she agreed to, no box she checked put her in contact with Fireflies. The legal theory is that this is exactly the problem: BIPA's notice and consent requirements exist precisely to protect people from having biometric data collected by companies they've never heard of.
This matters for anyone who has been in a meeting with a Fireflies user. The bot joins through the organizer's calendar integration. If your counterpart in a sales call, your interviewer in a hiring process, or your colleague in a team sync has Fireflies connected to their calendar, the bot may have attended meetings you were in — and may have generated a voiceprint for your voice — without any action on your part.
You are the affected party. You are not the customer.
This Isn't Limited to Fireflies or to Illinois
Fireflies is the company named in the active class actions. But the underlying legal problem — a speaker identification feature that generates biometric voiceprints and processes the voices of meeting participants who haven't consented — exists anywhere those features do.
Any bot-based meeting tool that identifies speakers across sessions is doing something structurally similar. The question is whether the company has published a biometric data retention schedule, obtained written notice from participants before collection, and secured written releases — including from the non-subscribers who appear in those meetings. Most haven't. The BIPA lawsuits against Fireflies didn't emerge from unusual behavior. They emerged from behavior that is standard in the category.
The Otter.ai situation, covered in an earlier post on this blog, raises a related but legally distinct question under the federal Wiretap Act and California's CIPA. Different statutes, same underlying product architecture: a bot joins a meeting, records everyone present, and processes the audio without requiring individual consent from every participant.
The wave of litigation reflects a single structural fact about how bot-based meeting tools work. They're services that one party adds to a meeting everyone else is in. The legal frameworks — state biometric laws, federal wiretap law, European data protection — are slowly catching up to that architecture.
August 2 Is 16 Days Away
The EU AI Act's transparency obligations come into force on August 2, 2026. What they require is specific: AI systems that interact with people must disclose that they are AI at the start of the interaction, and the disclosure must be audible, in the user's language. A written notice on a website does not substitute for the spoken disclosure during the conversation.
Separately, recording consent under the EU's existing GDPR framework requires explicit, specific, informed consent — not implied consent from a calendar invite that mentions an AI notetaker in passing.
For meeting tools with speaker identification or sentiment analysis features, the exposure is more severe. AI systems capable of emotion recognition or biometric categorization fall into a higher-risk tier under the EU AI Act framework, potentially subject to additional conformity assessments, transparency disclosures, and operational constraints. Penalties for non-compliance with the Act's transparency provisions reach up to €15 million or 3 percent of global annual turnover, whichever is higher.
Most bot-based meeting tools have not reworked their products to meet these requirements. The August 2 date applies to any company deploying these tools for participants in EU member states — which, in a globally distributed workforce, is most companies.
What Professionals Are Doing Right Now
The July 9 wire story reflected a shift already happening in legal and HR departments. Privacy practitioners' position is clear: employees in Illinois have standing to decline to attend a meeting with an AI notetaker until they receive written assurances about what's being collected, how long it's retained, and when it will be destroyed. That's not a theoretical position — it's the direct application of BIPA to a scenario that plays out in workplaces every day.
Organizations that deployed AI notetakers widely before these lawsuits are realizing they may have significant retroactive exposure: they deployed systems that processed biometric data before any legally required policies were in place.
Questions Worth Asking About Any Meeting AI Tool
If you're evaluating or currently using a meeting AI tool, these questions now have legal weight:
Does the tool identify individual speakers? Speaker identification requires creating unique voice models — which are biometric identifiers under BIPA. If your note-taker attributes words to specific named people across sessions, it's likely creating voiceprints.
Has the company published a biometric data retention and destruction schedule? BIPA requires this before any biometric data is collected. Saying data is eventually deleted isn't enough — the schedule and criteria must be documented and available.
What consent mechanism exists for non-subscribers? If the tool joins meetings and captures audio from people who aren't subscribers, what notice and consent is collected from those participants? In most cases: nothing.
Is the tool bot-based or device-local? Bot-based tools enter your meeting as a third-party participant. Device-local tools run on your own machine, capturing audio you already have access to as a participant already in the call. The legal exposure profiles are meaningfully different.
What does the data go toward beyond your transcripts? Some providers permit use of audio or transcripts for model training. Your employees' voices — and the voices of everyone who met with them — may be in a training corpus.
The Architecture That Sidesteps the Problem
The legal issues accumulating around bot-based meeting tools all trace to the same structural fact: a third-party service entering a conversation as a participant, processing the voices of people who are already in the room.
Desktop overlay tools work differently. They run on the user's own machine, capturing audio from the local device — the same audio the user already hears as a participant. No bot joins the meeting. No third-party service appears in the participant list. The audio is processed in service of the person already in the conversation.
Meeting Copilot takes this approach: a local desktop overlay that captures the meeting the user is already in, provides real-time suggestions in a window only they can see, and gives the user direct control over when the session starts, stops, and what's retained. No bot enters the call. No voiceprint is extracted from people who never agreed to anything.
That's not just a privacy preference — it's a legally meaningful distinction at a moment when the legal landscape around the other architecture is getting materially worse.
The Next Few Months Will Matter
Two class actions are active. The EU AI Act enforcement date arrives in 16 days. The July 9 AP story marks the point where this moved from legal circles to mainstream professional conversation.
Whether you created the account, whether you're in Illinois, whether you're in the EU — none of that determines whether your voice was processed. What determines that is whether someone else in the meeting had a bot set to auto-join.
That's the part of the fine print nobody reads until there's a lawsuit to make them.
Meeting Copilot is a desktop overlay for macOS and Windows that provides real-time assistance during interviews, sales calls, and negotiations — without joining the call as a bot or collecting biometric data from other participants. Free trial available.