Judge Eumi K. Lee ruled on Otter's motion to dismiss last Thursday, and by Monday the commentary had settled into a genre. Audit your meeting tools. Turn off the training toggle. Get affirmative consent before the bot joins. All sound advice, and all of it addresses the wrong reader.
For anyone underwriting claims rather than managing an IT stack, the interesting part of the opinion is narrower and more portable. Otter's central defense was that its Notetaker is an invited participant, a recording tool operated at the direction of the meeting host, and therefore a party to the conversation rather than a third party listening in on it. That defense has real support. Under Graham v. Noom and the software-vendor cases that followed it, a service provider that functions as an extension of its client is not a separate interceptor, because a party to a communication may record that communication.
The court accepted the framework and held that Otter falls outside it. The reason was not the invitation. It was that Otter keeps what it records and uses the material to improve its own speech recognition and machine learning systems. A vendor that transcribes and hands the transcript back is a tool. A vendor that transcribes, retains, and trains is operating for its own commercial account, and at that point it is a third party under Section 631.
The business model became an element
That is the holding to carry out of the opinion, because it converts a business decision into a liability trigger.
The extension theory was the defense the entire AI tools layer was relying on, whether or not anyone said so out loud. It is what lets a vendor say it is not in the conversation, it is merely the software the customer chose to use. The Otter court did not reject that theory. It held that you forfeit it the moment you take the data for yourself.
Almost everyone takes the data for themselves. Training on customer content is not an incidental feature of the current AI product economy; it is a substantial part of why the products are priced the way they are. The relevant question for building a defendant list is therefore not what the tool does. It is one line in the terms of service, and it is answerable from the outside without discovery.
Notice also what the theory does not require. It does not require the transcript to be wrong, the summary to be defamatory, the speaker attribution to be mistaken, or the output to have caused anything at all. The alleged injury is complete at ingestion. Nobody has to characterize what the model produced, which means nobody has to litigate whether that production is a product or content.
Why that matters against the rest of the AI docket
The AI injury cases moving through the courts right now all have the same architecture. Something the system generated contributed to a harm, and the case turns on whether that generation is a defective product subject to strict liability or expressive content that carries an immunity and a First Amendment overlay. That question has consumed the wrongful death docket for a year, and it is the question I have argued elsewhere is the doctrinal hinge for the entire field. It is also slow, contested, and unresolved.
The interception theory routes around all of it. Section 631 and the Electronic Communications Privacy Act were written for wiretaps, and a wiretap claim is complete when the interception happens. Section 230 has nothing to say about it, because nobody is being held liable as a publisher of anything. The conduit defense is not available for the same reason. The statutes are decades old, well interpreted, and carry fixed damages that do not require proof of loss.
The strategic read is that plaintiffs have found a way into AI companies that does not depend on winning the argument everyone assumed had to be won first. Whether the output is a product remains the more consequential question in the long run. It is no longer the only door.
What actually prices this
The damages arithmetic is why the Illinois claims matter more than the California ones, even though the California holding is the one being quoted. CIPA carries five thousand dollars per violation under Section 637.2. The ECPA provides the greater of actual damages or a statutory floor. BIPA carries one thousand dollars for a negligent violation and five thousand for a reckless or intentional one, and it does not require any showing of injury beyond the collection itself.
Two things cut against the largest version of that number. Illinois amended BIPA in 2024 to limit recovery to a single violation per person per collection method, which eliminated the per-scan accrual math that produced the headline exposure figures of the Cothron era; whether that amendment reaches conduct predating it is still being fought over. And the surviving claims here belong to a handful of named plaintiffs, not a certified class.
Certification is where this actually gets decided, and the opinion already shows you the shape of that fight. Plaintiff Theus kept his Section 632 claim because he described a call with a medical professional about personal health information. Plaintiffs Brewer and Ryan lost theirs, along with their intrusion and constitutional privacy claims, because they said their conversations were private and sensitive and stopped there. The court called that conclusory and it is hard to argue otherwise.
Now extend it. If the confidentiality of each communication depends on what was actually said in it, the individualized inquiry runs to every meeting of every class member. Predominance under Rule 23(b)(3) is a genuine problem on that record. The BIPA claim is cleaner, because voiceprint collection is uniform conduct and does not require anyone to characterize the conversation, and the court rejected both the argument that speaker identification falls outside the statute and the extraterritoriality defense.
The pleading point has a practical edge for anyone gathering claimants. An intake questionnaire that captures which tools were in the meeting is capturing the wrong field. What survives a motion to dismiss is subject matter, and claimants do not volunteer it.
What was actually lost
The dismissals are worth reading as a map of theories that do not work here. The computer intrusion claims failed because the complaint did not describe how a notetaker joining a video call accesses anyone's files or systems, and Van Buren makes that a real requirement rather than a formality. The federal claim also failed on loss, since diminished data value and emotional distress do not fit the statutory definition, and the state analogue fell for the same reason. The Washington claims went out on the same insufficient-detail ground as the California common law claims. The pen register theories that have been running through the CIPA bar were withdrawn rather than decided.
Most of that came with leave to amend, so the second complaint will tell you how much of it was pleading and how much was fact.
What to watch
Plaintiffs have fourteen days from the August 13 order to amend, with Otter's response due twenty-one days after that. The amended complaint is the document to read, specifically whether the newly pleaded plaintiffs describe the substance of their conversations in a way that cures the Section 632 problem without creating individualized issues that make the class harder to certify. Those two objectives pull in opposite directions, and how counsel handles the tension will tell you how they intend to try the case.
After that, the questions are whether other AI vendors with training-permissive terms start seeing complaints built on this template, whether any defendant gets an early appellate look at the retention-and-training test before it hardens across the district, and whether the theory migrates from notetakers to the much larger population of AI features embedded inside software people did not choose to install.
One caution against reading too much into a single order. A motion to dismiss ruling establishes that a theory is plausible, not that it is right, and this docket has produced no merits ruling, no certification decision, and no settlement history. What it has produced is a workable path to a defendant's balance sheet that does not require anyone to first answer the hardest open question in AI law. On a docket where every other theory is waiting on that answer, that is worth noticing.
For where this sits alongside the other dockets moving this year, see the 2026 mass tort map.