How AI Turned the Human Voice Into a Biometric Privacy Lawsuit
A dozen new class actions say meeting notetakers, voice assistants, and call centers are building voiceprints without consent. A 2008 Illinois law gives them teeth. A run of recent rulings is deciding how sharp. Inside the BIPA wave, and where it's headed.

A video call begins and a small icon appears in the corner: an AI assistant has joined to take notes. To produce a clean transcript that labels who said what, the software does something most participants never think about.
It measures each speaker's voice, the pitch, cadence, and frequency pattern that make a person's speech recognizable, and turns it into a mathematical template.
Then it stores that template so it can recognize the same person in the next meeting. In the language of privacy law, that template is a voiceprint, and in one state it is regulated as tightly as a fingerprint.
Since 2023, plaintiffs have filed a steady and accelerating run of class actions built on exactly that observation. The defendants are not fringe apps.
They are Otter.ai, Fireflies, Microsoft, Meta, SoundHound, Gong, and large employers running voice systems in call centers and warehouses. The claims all rest on the same statute, and increasingly on the same single word.
Why one state law does the work
Illinois enacted the Biometric Information Privacy Act in 2008, long before anyone was worried about AI. Its drafters were thinking about fingerprint time clocks, but they wrote broadly, and the statute's list of protected biometric identifiers expressly includes the voiceprint alongside the fingerprint, the retina scan, and facial geometry. Two features make BIPA the tool of choice:
It has a private right of action. Unlike most privacy statutes, BIPA lets individuals sue directly, and the Illinois Supreme Court has held they need not show any actual injury beyond the violation itself.
It carries fixed statutory damages. $1,000 for each negligent violation and $5,000 for each reckless or intentional one, before fees.
The mechanics that trip companies up are Section 15(b), which requires informed written consent before a private entity collects a biometric identifier, and Section 15(a), which requires a public, written retention and destruction policy.
An AI notetaker that silently fingerprints every voice on a call has, on the plaintiffs' theory, done neither.
The defendants are the whole voice stack
The filings sort into recognizable layers, and the differences between them matter for how each case will be defended:
Dedicated AI notetakers. Otter.ai, Fireflies, Gong, and Mindtickle build their products around recording, transcribing, and speaker-labeling meetings and sales calls, which necessarily involves creating a voiceprint for each speaker. Otter and Fireflies have each drawn several suits from different plaintiff firms, a pile-up that signals how settled the fact pattern has become.
Platform transcription. Microsoft is sued over Teams live transcription, which allegedly derives and stores voiceprints in its cloud; Meta over voice features in Facebook and Messenger. These are the enterprise and consumer incumbents, not startups.
Voice assistants and voice AI. SoundHound is sued over its Houndify voice platform and Chat AI assistant, and Amazon has faced parallel claims over Alexa.
Restaurant and drive-thru ordering. AI ordering systems have generated their own cluster. Domino's and Wingstop, both using the vendor ConverseNow, have been sued, as have chains whose phone and drive-thru orders ran through the SYNQ3 voice system, over AI that takes a customer's order and, plaintiffs allege, captures a voiceprint in the process.
Telecom voice authentication. Verizon has been sued over its Voice ID caller-verification program, and similar claims are circling other carriers whose call centers use the voice to confirm identity.
Retail call centers. When a customer phones a retailer's service line, the AI system that answers can build a voiceprint to authenticate the caller and screen for fraud. Walmart has been sued in two Illinois districts on exactly that theory, with plaintiffs alleging the only disclosure was a line about the call being recorded for business purposes. Walmart is a repeat BIPA target, having already faced claims over fingerprint time clocks and self-checkout face scans, and plaintiff firms are now examining other large national retailers' call-center voice systems.
The workplace. Employers are sued over their own staff. PepsiCo is targeted over voice-recognition software its warehouse “pickers” are required to use, and Walmart over voice headsets worn by warehouse workers. These are employee cases, a different consent and class posture than the customer and meeting-participant suits.
The aggressive edge is the people who never signed up
The most consequential move in the notetaker cases is who they sue on behalf of. The Otter and Fireflies complaints are brought not by the customers who installed the software, but by other people in the meeting, participants who never created an account, agreed to any terms, or saw a consent screen.
The software captured their voices because they happened to be on the call. If that theory holds, consent obtained from the account holder does nothing to protect the vendor, because the statute's consent requirement runs to every individual whose voiceprint is taken.
It is the voice analogue of the bystander biometric theory now being tested against doorbell cameras, and it vastly enlarges the class.
The theory has already cleared a motion to dismiss
For a while, defendants treated voiceprint BIPA claims as speculative. That is harder to argue now. In Delgado v. Meta, a judge in the Northern District of California ruled in February 2024 on Meta's motion to dismiss a BIPA voiceprint class action tied to voice features in Facebook and Messenger.
The court dismissed the Section 15(c) and 15(e) claims with leave to amend, but denied the balance of the motion, meaning the core Section 15(a) retention and 15(b) consent claims survived.
It rejected Meta's argument that the allegations were not specific enough to its products and declined to throw out the theory that voiceprints of third parties were captured through other users.
A separate BIPA case over Amazon's Alexa also escaped dismissal. The proposition that a voiceprint is a biometric identifier a company can be sued for collecting is no longer novel.
But the ceiling is being lowered at the same time
The reason this is a genuinely two-sided story, and not just a plaintiff run, is that three developments have narrowed BIPA's reach even as the filings multiply:
Damages were capped per person, not per use. In 2023 the Illinois Supreme Court held in Cothron v. White Castle that a claim accrued every time biometric data was scanned, an interpretation that produced a theoretical $17 billion exposure in that case. In 2024, Illinois amended BIPA (SB 2979), signed into law that August, so that repeated collection of the same identifier from the same person by the same method is a single violation. That deflates the per-meeting math that made these cases terrifying.
Extraterritoriality is a hard limit. In May 2026 the Third Circuit, in the McGoveran v. Amazon Web Services voice-authentication litigation, applied the rule that BIPA reaches only conduct occurring primarily and substantially in Illinois. The callers were Illinois residents, but the servers, the vendor, and the company whose line they called all sat elsewhere, and the court held that using an Illinois phone was not enough of an Illinois connection to carry the claim. National cloud platforms will lean on this heavily.
Financial voice authentication may be exempt. The same ruling treated the voice-authentication vendor, which served a financial institution, as exempt under BIPA's financial-institution and Gramm-Leach-Bliley carve-out. Personal jurisdiction is a live defense too: an earlier stage of that same litigation had been thrown out of an Illinois federal court for lack of jurisdiction before the plaintiffs refiled elsewhere.
Where the exposure actually concentrates
Put the two sides together and the profile of a truly exposed defendant comes into focus. The escape hatches, extraterritoriality, the financial-institution exemption, and personal jurisdiction, all point the same way: they protect out-of-state cloud providers and voice-authentication vendors serving banks, and they do very little for anyone else.
The banks look biggest but may be safest
Financial institutions were among the earliest voice-authentication adopters, and the plaintiffs' bar has been circling them since 2021, which is why lenders and card issuers sit near the top of anyone's target list.
But they also hold the single strongest defense: the Gramm-Leach-Bliley carve-out that shielded the vendor in McGoveran points squarely in their favor. The place the exposure looks largest on paper is the place it is most contestable in court.
The meeting assistants have nowhere to hide
The opposite is true for the AI notetaker. A tool that joins Zoom and Teams calls has Illinois participants on it every day, serves no bank, and collects a voiceprint in the ordinary course of doing exactly what it was sold to do. None of the exemptions reach it. It is the cleanest version of the fact pattern the statute was built to catch.
The most active front right now is call centers
The same is true of the retailers and enterprises running voiceprint authentication in their own call centers. That is why Walmart has been sued repeatedly, why the plaintiffs' bar is now working down a list of other national retailers, and why call centers are among the hottest corners of the whole wave.
None of them serves a bank, all of them capture Illinois voices in the ordinary course of business, and the employers running warehouse voice systems face the same problem for their Illinois workforce.
A newer front: the training data itself
Beyond consent entirely, voice professionals have begun suing large technology companies for allegedly using their recorded voices to train commercial AI voice models, pushing the same biometric theory upstream, from how a voice is captured to how it is used to build a product.
For most of history a voice was ephemeral. You spoke, the sound faded, and nothing was left to store. AI changed that quietly and completely: the voice is now a durable, machine-readable identifier, created and kept every time software listens closely enough to tell speakers apart.
A statute written in 2008 fits that new reality with uncomfortable precision, and the fight now moving through the courts is really an argument about how far a nearly two-decade-old idea of consent reaches into a technology its drafters never imagined.
Get the full voiceprint litigation tracker.
Every filed voiceprint case, the defendants, the products, the theories, and the rulings that have shaped them, in one place, updated as the docket moves.
It is the working file behind this article. Open the voiceprint trend report.
Originating or defending in this space? Rain maps emerging theories to the companies, industries, and forums most exposed before the next complaint is filed. Book a 30-minute walkthrough.