ConsentPixel – Privacy · Verified

CIPA & Legal Risk · Analysis

CIPA's Expanding Frontier: From Phone Taps to Pixels to AI

In August 2026, a federal court let a wiretapping case proceed against an AI notetaker that sat in on Zoom calls. The statute it was decided under? A California law written in 1967 for telephone eavesdropping. That's not a stretch — it's the pattern. The same consent theory has marched from phone taps, to website pixels, to AI tools, and each jump makes the last one look settled. Here's the through-line — and why the version that lands on your own website today is the part worth fixing first.

CP ConsentPixel Team September 2026 14 min read Information, not legal advice
1967 → 2026
A phone-wiretap statute now reaching AI meeting assistants — the same theory, three generations of technology
Aug 13, 2026
A federal court let CIPA, Wiretap Act & BIPA claims proceed against Otter.ai's AI notetaker
$5,000
Statutory damages per violation under Cal. Penal Code §637.2 — the same figure across all three eras

Key takeaways

  • CIPA keeps expanding to new technology. A 1967 telephone-wiretap law now reaches website pixels and, as of 2026, AI tools — because its text was written to cover "new devices and techniques."
  • Otter.ai is the frontier marker. A federal court let CIPA, federal Wiretap Act, and BIPA claims proceed against an AI notetaker that recorded meetings and used the data to train its models.
  • The reasoning is constant across all three eras: an interested party captures a communication without the affirmative, all-party consent CIPA requires. Only the device changes.
  • The AI story proves the theory has momentum. But the pixel version — the trackers on your website — is where it already lands on ordinary businesses, with years of precedent behind it.
  • That makes your website the settled, easy case. If courts will apply this to a novel AI bot, the established version aimed at your site's trackers is far easier for a plaintiff to run — and the part you can fix today.

The pattern hiding in plain sight

Here's a fact that sounds like a mistake but isn't: the law being used to sue AI meeting-transcription tools in 2026 is the same law that was written in 1967 to stop people from wiretapping telephones. Not a modernized version. Not a new AI statute. The literal California Invasion of Privacy Act, drafted during the Summer of Love, is what a federal judge applied to Otter.ai's AI notetaker this year.

To a lot of business owners, that reads as absurd overreach — surely a phone-tap law can't govern an AI bot on a Zoom call? But if you follow how CIPA has actually been used over the past few years, it's not absurd at all. It's a straight line. The statute has been quietly expanding its reach with each new generation of technology, and every expansion makes the previous one look obvious in hindsight.

That matters to you for a reason that isn't obvious yet: the newest frontier is the loudest, but the exposure that's already settled is the one sitting on your website right now. Understanding the pattern is how you tell the difference between the litigation theory that's still being worked out (AI tools) and the one that's already landing on ordinary businesses by the thousands (website trackers). Let's walk the line.

Three eras of one statute

CIPA's journey has three distinct chapters, each defined by the technology plaintiffs pointed it at. The remarkable thing is how little the underlying argument changes from one to the next.

1967 Phone taps the original 2022 → Website pixels the current wave · your site 2025 → AI tools the frontier · Otter.ai Same consent theory, three generations of technology — only the device changes.
1967Phone taps — the originalThe source code

CIPA was enacted to stop the eavesdropping and recording of telephone conversations without everyone's consent. Its core provisions — §631 (wiretapping the contents of a communication), §632 (recording a confidential communication), and §638.51 (pen registers and trap-and-trace devices) — were all written with the telephone in mind. The animating idea: you can't secretly capture a private communication that others are party to. Hold onto that idea, because it never changes.

2022 →Website pixels — the current waveWhere you live

Starting around 2022, plaintiffs' firms began arguing that website tracking technology does the same thing a phone tap does — it intercepts a visitor's communication with a site and hands it to a third party without consent. The Javier v. Assurance IQ decision treated session-replay recording as wiretapping when it ran before a privacy policy was shown, and the floodgates opened. The Meta Pixel, session-replay tools like Hotjar and FullStory, chat widgets, analytics tags — all became targets. The pen-register theory got stretched to trackers and SDKs. This is the established, high-volume wave: thousands of lawsuits and demand letters, and the exposure that sits on ordinary business websites today.

2025 →AI tools — the frontierNewest, contested

The newest chapter points CIPA at artificial intelligence: chatbots that pass conversation transcripts to third-party AI vendors, AI-assisted voice agents, and — most vividly — AI notetakers that join meetings, transcribe them, and train models on what they hear. This is where Otter.ai sits, and where a federal court just planted a flag. It's the least settled of the three, but it's the one that proves the theory still has room to run.

The Otter.ai ruling, in detail

Because Otter is the case that marks the frontier, it's worth understanding what the court actually held — and what made it different from earlier cases that went the defendant's way.

In In re Otter.AI Privacy Litigation (N.D. Cal., Aug. 13, 2026), plaintiffs allege that Otter's OtterPilot notetaker joined Zoom, Teams, and Google Meet calls, recorded and transcribed them — including participants who weren't Otter users and never agreed to anything — and then used those recordings to train Otter's AI. On Otter's motion to dismiss, the court let the core claims proceed: CIPA (§631 and §632), the federal Wiretap Act, and Illinois's biometric privacy law (BIPA) all survived. Only the computer-fraud counts were dismissed.

The pivotal moment is how the court handled Otter's main defense — the "party exception." Under CIPA, a party to a conversation can generally record it; a tool acting purely as one participant's agent is treated as an extension of that party, not a third-party eavesdropper. That's the exact defense that won for the defendant in Graham v. Noom, where the recording tool was found to be operating as the customer's own agent.

The court held Otter couldn't claim the party exception, because Otter used the recordings for its own commercial purpose — training its AI. That made it an interested party harvesting the conversation for itself, not a neutral tool acting only for a participant.

— The holding that separates Otter from Noom

That distinction is the whole ballgame, and it's what makes the case matter beyond AI. The court also brushed aside Otter's reliance on Popa v. Microsoft — a website session-replay case — noting that eavesdropping on entire spoken conversations is "materially more invasive than the monitoring of browsing activity." And on standing, it found the alleged harm "closely resembles the common-law privacy tort of intrusion upon seclusion." (These are rulings at the pleading stage; the allegations remain unproven, and the decision is about whether the case can proceed — which it can.)

⚠ The part that reaches past Otter
Otter's terms push the job of getting consent onto its customers — the businesses running the bot. So when an AI notetaker joins a call without everyone's agreement, it isn't only the vendor who's exposed; it's the company that deployed it. That "the tool's convenience becomes your liability" structure should sound familiar — it's exactly how the pixel wave works, where the tracker a marketer added becomes the site owner's problem.

The through-line that connects all three

Strip away the technology and the same sentence describes all three eras: an interested party captured the contents of a communication without the affirmative, all-party consent CIPA requires. That's the phone tap. That's the pixel. That's the AI notetaker. The device is the only variable.

Look at how cleanly each era maps onto the same skeleton:

 Phone tap (1967)Website pixel (2022→)AI notetaker (2025→)
The communicationA phone callA visitor's interaction with a siteA spoken meeting
The interested partyThe eavesdropperMeta, Google, the ad-tech vendorThe AI vendor, training on it
What's capturedThe conversationClicks, form fields, page contentsThe transcript, voiceprints
The failureNo consent from all partiesFired before the visitor agreedRecorded participants who never agreed

Once you see the skeleton, the "how can a phone law govern AI?" objection dissolves. CIPA was never really about telephones — it was about the principle that you can't secretly capture someone else's communication for your own purposes. Telephones were just the technology that existed in 1967. Every expansion since has applied the same principle to whatever new capture technology came along.

The frontier is loud — but check your own front door first

Before you worry about the AI bot in your next meeting, see what's already capturing visitor communications on your website. Scan your site to find every third-party tracker that fires before consent — the established version of this exact theory. About 10 seconds, no account.

Scan your site free →

Why CIPA keeps expanding — it's written into the statute

There's a temptation to see each new application of CIPA as plaintiffs' lawyers getting creative. Some of it is. But the deeper reason the statute keeps reaching new technology is that its own text invites it to. CIPA was drafted with forward-looking language referring to "new devices and techniques" for interception — a phrase that plaintiffs lean on to argue the law was always meant to cover whatever capture technology the future produced.

That's why the "it's a 1967 phone law, it can't apply to X" argument has been a losing one more often than a winning one. The statute didn't freeze in 1967; it was written to travel. Combine that with two other features and the expansion becomes almost structural:

  • Statutory damages with no proof of harm. Under Cal. Penal Code §637.2, a plaintiff can recover $5,000 per violation without showing they lost a dollar. That economics makes each new technology a fresh target the moment a viable theory appears.
  • No threshold to clear. Unlike the CCPA, CIPA has no revenue or traffic minimum. A fifteen-page small-business website is as exposed in principle as a national retailer — the test is whether a Californian's communication was captured, not how big you are.

Put those together — expansive text, no-harm damages, no threshold — and you have a statute built to keep finding new frontiers. AI is simply the current one. It will not be the last.

Why your website is the settled case

Here's the payoff, and it's the opposite of what the headlines suggest. The AI stories get the attention precisely because they're novel — an AI bot getting sued under a phone law is a great headline. But novelty cuts against a plaintiff: the theory is still being tested, defendants have real arguments, and the outcomes are genuinely uncertain. The Otter ruling let the case proceed; it didn't decide liability.

The website-tracker version is the reverse. It isn't novel at all anymore. It has:

  • Years of precedent — a large body of rulings, some favorable to plaintiffs, mapping out exactly how the theory works against pixels, session replay, and chat tools.
  • Thousands of filings and demand letters — an entire cottage industry of firms running the same playbook at scale.
  • Trivial detection — a plaintiff doesn't need discovery to find pre-consent tracking. An automated browser with a clean session captures the network log in seconds, and the timestamps do the rest.

In other words: the frontier is where the theory is being proven, but your website is where it's already settled. If a court is willing to entertain this reasoning against a brand-new category like AI notetakers, the version aimed at the ordinary trackers on your site is the far easier case for a plaintiff to bring — and the one most likely to arrive as a demand letter. You can see the volume and range of it on our CIPA lawsuit tracker, which follows the website cases the AI frontier is built on top of.

The reframe worth keeping. Watching the AI frontier is smart — it tells you where the law is heading. But it can be a distraction if it pulls attention away from the exposure that's already on your doorstep. The AI question for most businesses is "should we let this bot record?" The website question is "are our trackers firing before consent right now?" — and only the second one already has thousands of plaintiffs behind it.

What to actually do about the part you control

You can't single-handedly resolve how CIPA will treat AI tools — that's up to the courts, and worth following. But the website version is squarely within your control, and the fix is the same principle CIPA has always turned on: get affirmative consent before an interested party captures anything. Concretely, for your own site:

  • Block non-essential trackers until consent. Every third-party pixel, analytics tag, session-replay tool, and chat widget should be technically prevented from firing until the visitor gives an affirmative opt-in. Pre-consent firing is the exact fact pattern the website cases are built on.
  • Make the consent real, not passive. An affirmative choice — not a "by continuing to browse" notice, which courts reject. (We cover why in your privacy policy is not a consent banner.)
  • Honor opt-out signals — including Global Privacy Control — so a visitor who's already said "don't track me" is respected before anything loads.
  • Log every decision. A timestamped record of what each visitor consented to, per page, is what turns "we think we're fine" into something you can actually show.
  • Watch for drift. Trackers get added through tag managers and plugin updates without anyone telling compliance. Continuous monitoring catches a new pre-consent tracker in days, not in a demand letter.

And on the AI question specifically — the honest answer is narrower: treat AI notetakers, transcription bots, and chat tools that pass data to third-party AI vendors as consent questions too. Get clear, all-party agreement before a bot records, and understand what a vendor is allowed to do with the data (Otter's problem was using recordings to train its models). That's counsel-and-policy territory more than a technical fix — but the mindset is identical: an interested party shouldn't capture a communication without everyone agreeing first.

Where ConsentPixel fits — and where it doesn't

Worth being precise about scope. ConsentPixel handles the website layer — the pixel era, the part that's already settled and already landing on businesses. It's a single pixel that blocks third-party trackers until a visitor gives affirmative consent, honors opt-out and GPC signals, monitors every page for new trackers, and logs each decision as evidence. That directly closes the "interested party captured a communication before consent" fact pattern on the surface you own. What it does not do is sit inside your Zoom calls policing AI notetakers — that's the frontier, and it's a governance-and-contracts problem, not a website one. The point of this article is that the frontier shows you where the theory is heading, while your website is where you can act on it today. This is information, not legal advice.

Frequently asked questions

Can CIPA really apply to AI tools?

Courts are increasingly allowing it. In August 2026, a federal court let CIPA claims proceed against Otter.ai's AI notetaker, which allegedly recorded and transcribed meetings — including non-users — without all-party consent and used the data to train its models. CIPA is a 1967 wiretapping statute, but its text references "new devices and techniques," and plaintiffs argue it reaches whatever capture technology comes next. The AI application is newer and less settled than the website-tracking version, but the Otter ruling shows courts are willing to apply the same consent theory to it. This is general information, not legal advice.

What did the Otter.ai ruling actually decide?

In In re Otter.AI Privacy Litigation (N.D. Cal., Aug. 13, 2026), the court denied Otter's motion to dismiss the core claims, letting CIPA (§631 and §632), the federal Wiretap Act, and Illinois's BIPA biometric claims proceed. The pivotal holding was that Otter could not rely on the "party exception" — the rule that lets a participant's tool record a conversation — because Otter used the recordings for its own commercial purpose of training its AI, making it an interested party rather than a neutral agent. The allegations remain unproven; the ruling concerns whether the case can proceed, not final liability.

If the AI cases are novel, why should I worry about my website?

Because your website is the opposite of novel. The AI application of CIPA is still being tested, which makes it uncertain for plaintiffs. The website-tracking application has years of precedent, thousands of filings and demand letters, and detection that takes seconds — a plaintiff's automated browser captures a network log showing trackers firing before consent, and the timestamps do the work. The AI frontier proves the theory has momentum; your website is where that theory already lands on ordinary businesses. It's the settled, easier case, and the one you can actually fix.

Does CIPA only apply to large companies?

No. Unlike the CCPA, CIPA has no revenue or traffic threshold. The test is whether a California resident's communication was captured without consent — not how big your business is. A small fifteen-page site is exposed in principle the same way a national retailer is, because statutory damages under California Penal Code §637.2 are $5,000 per violation with no need to prove actual harm. CIPA's reach also depends on the location of the visitor, not the business, so a company outside California with California visitors is still in scope.

How do I reduce my website's CIPA exposure?

The core move is to get affirmative consent before any non-essential tracker fires. Practically: block third-party pixels, analytics, session-replay tools, and chat widgets until the visitor opts in; make the consent an affirmative choice rather than a passive "by continuing to browse" notice; honor opt-out signals including Global Privacy Control; log each consent decision with a timestamp; and monitor continuously so a newly added tracker is caught in days rather than in a lawsuit. Scanning your site to see what fires before consent is the fastest way to find where you stand.

Should we stop using AI notetakers and chatbots?

Not necessarily, but treat them as consent questions. The lesson from Otter is twofold: get clear, all-party agreement before a bot records a conversation, and understand what the vendor is permitted to do with the data — Otter's exposure grew from using recordings to train its own models. For chatbots and AI tools on your website, the same principle applies as for any tracker: disclose and obtain affirmative consent before the tool captures and transmits a visitor's communication. This is governance and contract territory as much as technical, so it's worth reviewing with qualified counsel. This is general information, not legal advice.

The bottom line

CIPA's march from phone taps to website pixels to AI tools isn't a series of stretches — it's one consistent principle applied to each new capture technology: you can't secretly take someone's communication for your own purposes without their consent. The Otter.ai ruling is the newest marker on that line, and it proves the theory still has room to run.

But the frontier is a preview, not your immediate problem. The version already landing on ordinary businesses — thousands of times over — is the tracker on your website. It's the settled case, the easy case, and the one a plaintiff can detect in seconds.

So watch the AI frontier to understand where this is heading — and fix the part that's already here. Get affirmative consent before your trackers fire, honor opt-outs, and keep the record. That's the same principle the whole statute turns on, applied to the surface you actually control.

See what's already capturing communications on your site

The AI frontier is loud, but your website is where CIPA already lands. Scan your site to see every third-party tracker firing before consent — the established version of this exact theory. Free, about 10 seconds, no account.

Scan your site free →
No account needed for the scan · then a 14-day free trial, no credit card required
CP

The ConsentPixel Team

Privacy & Consent Compliance

ConsentPixel — Privacy · Verified is a CIPA-first consent platform delivered as a single JavaScript pixel: it blocks third-party trackers until a visitor gives affirmative consent, honors opt-out and Global Privacy Control signals, monitors every page, and logs each decision as evidence. This article is educational and not legal advice.

Information, not legal advice. This article explains the general trajectory of CIPA litigation for educational purposes and does not constitute legal advice or create an attorney–client relationship. Case descriptions — including In re Otter.AI Privacy Litigation (N.D. Cal., Aug. 13, 2026) — reflect publicly reported court records as of September 2026; the allegations remain unproven and rulings at the pleading stage concern whether a case may proceed, not final liability. The $5,000-per-violation figure reflects statutory damages under California Penal Code §637.2; actual exposure varies by case, and courts remain split on many CIPA theories. How CIPA and related laws apply to your website or your use of AI tools depends on your specific facts — consult qualified counsel. ConsentPixel — Privacy · Verified is not a law firm, and no single tool by itself makes a website compliant with any law.

Scroll to Top