Products using AI collided this year with wiretapping statutes. A new complaint shows how plaintiffs are also turning to biometric privacy laws. A putative class action filed September 25, 2026 in the Northern District of California alleges that Zoom’s AI Companion and “ZoomMate” feature collect and share “voiceprints” in violation of the Illinois Biometric Information Privacy Act (“BIPA”). The same theory could reach any connected device, app, or feature that processes biometrics.
The Allegations Against Zoom
The complaint alleges that Zoom’s speaker “diarization” technology (a fancy word for the process of figuring out “who said what” in a recording) computes a biometric voiceprint for every participant, whether they have a Zoom account or not. Plaintiffs ran their own test. They submitted a meeting recording to Zoom’s public Scribe API with short, independently recorded voice samples, and allege that the API matched each sample to that same speaker’s utterances later in the recording, based on voice alone. The complaint also relies on Zoom’s own patent, which describes a “voiceprint extractor” and a “voiceprint repository” in terms the complaint alleges track peer-reviewed speaker-recognition literature.
The complaint asserts three claims under BIPA, seeking statutory damages of $5,000 for each intentional or reckless violation, or $1,000 for each negligent violation. The claims assert violations of BIPA’s notice-and-consent requirements (Section 15(b)), the requirement to publish a retention and destruction policy (Section 15(a)), and disclosure restrictions (Section 15(d)).
The Case Follows a Significant Decision in Otter.AI
Six weeks earlier, Judge Eumi K. Lee allowed BIPA claims to survive a motion to dismiss in In re Otter.AI Privacy Litigation, No. 5:25-cv-06911 (N.D. Cal. Aug. 13, 2026), based on allegations that Otter’s Notetaker collected voiceprints from meeting audio so it could recognize speakers in future meetings.1 The plaintiffs' bar moves quickly on rulings like this. The Otter.AI decision gave plaintiffs a template. It showed that a complaint could survive a motion to dismiss if it alleges specific facts showing that a technical feature is a biometric-collection feature.
Assessing Risks Under Biometric Laws
Product design can be a deciding factor in whether a company receives a BIPA complaint. The Seventh Circuit, for example, recently held that BIPA’s “possession” and “collection” elements require that the company control the biometric data. It affirmed dismissal because plaintiffs alleged only that face templates were stored on their own devices, not that the company could access, modify, or use them. G.T. v. Samsung Elecs. Am., No. 25-1120 (7th Cir. Aug. 7, 2026).
Companies should identify their products, including connected devices, apps, and voice or camera features, that potentially capture biometric identifiers (face geometry, hand geometry, voiceprints, fingerprints, retina or iris scans, and, in some states like California, “gait patterns or rhythms,” Cal. Civ. Code § 1798.140(c)) and map where that data goes and who controls it.
- We recently published another post on a new hybrid wiretapping/false advertising complaint that likewise builds on the Otter.AI decision, though on its California Invasion of Privacy Act (“CIPA”) § 631 ruling.

/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-10-02-03-11-45-039-6abf20f1792ab853edbc1887.jpg)
/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-09-29-18-56-12-739-6abc09ccf976767f673c6dbc.jpg)
/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-09-10-19-25-14-418-6aa3041aa309dcf7376bc3b9.jpg)
/Passle/69ce4c141e42eea3bd4c2856/SearchServiceImages/2026-09-10-17-17-42-908-6aa2e6364c210030134b8622.jpg)