Technology by RateShield. Coverage placed by Lakeshore Risk Advisors LLC, an independent Illinois brokerage.

Want to see how much you could save? Get a free savings estimate in 60 seconds.

← All articles

Does Your AI Notetaker Violate Illinois Biometric Law?

August 24, 2026 · 8 min read

A sales team in the Chicago suburbs runs their Monday morning pipeline review over Zoom. Everyone joins, the AI notetaker bot joins too, and for the next 45 minutes it listens. By the end of the call, it's generated a transcript, a summary, action items by person, and a recording split by speaker. The BDR said something different from what the account executive said. The tool knows which voice is which.

That's not transcription. That's speaker recognition. And in Illinois, that distinction could cost your company $5,000 per person on the call.

What BIPA covers and why voiceprints are on the list

The Illinois Biometric Information Privacy Act, codified at 740 ILCS 14/, is one of the most litigated privacy statutes in the country. It requires companies to:

  • Give written notice before collecting biometric data
  • Obtain written consent before collecting it
  • Publish a publicly available policy stating how long the data will be retained and when it will be destroyed
  • Never sell or profit from biometric data
  • Protect it with at least the same standards applied to other confidential information

The statute defines "biometric identifier" at 740 ILCS 14/10. That definition includes retina or iris scans, fingerprints, voiceprints, scans of hand or face geometry.

Voiceprint is on that list explicitly. Not analogized to something on the list. Not arguably similar to something on the list. It's there, in plain text, as one of the enumerated categories.

The damages are why this matters commercially. Negligent violations carry $1,000 per person per violation. Intentional or reckless violations carry $5,000. BIPA has a private right of action, which means any affected person can sue without waiting for a regulator to act. And Illinois courts have certified BIPA cases as class actions many times.

The Illinois Supreme Court clarified in 2023 that each separate scan or collection can constitute a separate violation, not a single ongoing one. That's the math that makes BIPA exposure genuinely dangerous for companies with any kind of volume.

The line that most AI notetaker guides miss

Every AI notetaker compliance guide you'll find focuses on recording consent. Does your state require one-party or all-party consent to record a conversation? Illinois requires two-party consent under the Illinois Eavesdropping Act, so everyone on the call needs to know they're being recorded.

That's real, but it's a separate legal question.

The BIPA issue isn't recording. The BIPA issue is speaker recognition. Two completely different functions can happen inside the same tool:

Transcription converts audio to text. Speech-to-text. The tool hears words and writes them down. There's no identification of who spoke them. A voiceprint isn't created to do this.

Speaker diarization identifies and separates speakers within the audio. The tool doesn't just transcribe what was said. It labels who said it. "Jack said this. Maria said this. The third person on the call said this." To do that accurately, the tool builds a model of each speaker's voice characteristics. That model is a voiceprint. Voiceprints are a BIPA-covered biometric identifier.

Most commercial AI meeting tools offer diarization as a core feature. The automatic speaker labeling, the summaries broken out by participant, the meeting minutes attributed to individuals. That functionality depends on speaker recognition. And speaker recognition means voiceprint creation.

That's the doctrinal line in Cruz v. Fireflies.AI.

What happened in Cruz v. Fireflies.AI

On December 18, 2025, a plaintiff filed suit against Fireflies.AI in Illinois. The complaint alleges that Fireflies collects voiceprints from meeting participants through its speaker diarization feature without providing the BIPA-required written notice or obtaining written consent.

The theory isn't that Fireflies can't transcribe meetings. It's that speaker recognition, the process of identifying who said what, creates voiceprints that fall squarely within 740 ILCS 14/10's definition of biometric identifiers.

Fireflies markets itself as an AI notetaker and meeting assistant. It joins Zoom, Teams, and Google Meet calls, transcribes, summarizes, and attributes speech to individual participants. That attribution requires the tool to build voice models for each participant. According to the complaint, those models are voiceprints under Illinois law, and collecting them without written consent violates BIPA.

The litigation is active as of August 2026. No final judgment yet. But the case frames the legal theory in a way that applies across the AI meeting tool market, not just Fireflies specifically. Any tool that identifies speakers by voice is in the same doctrinal territory.

Fireflies claims to serve three million users. A class of Illinois participants on calls where the tool ran speaker recognition, at $5,000 per reckless violation, is the kind of math that produces nine-figure exposure. That's not a hypothetical. BIPA class actions have reached that scale before.

Who's actually at risk

It's not just the companies that build the AI tools. The employers using them are in scope too.

If your Illinois company deploys an AI meeting tool on calls that include Illinois residents, and that tool runs speaker diarization, your company may be the one that collected the biometric data. You authorized the tool to join the call. You directed it to record and diarize. You benefited from the output.

The exposure isn't limited to your employees. It extends to anyone on calls where the tool ran, including clients, prospects, candidates interviewing for jobs, vendors, and outside contractors. Every person on a call where speaker recognition ran is potentially a class member if they were an Illinois resident at the time.

Naperville-based companies running Gong on sales calls. Chicago-area manufacturers using Fireflies to document supplier meetings. DuPage County professional services firms using Otter.ai for client calls. Every one of those scenarios generates BIPA exposure if the tool is doing speaker diarization without proper written consent from all participants.

And the consent has to be written. Not implied by the meeting invitation. Not buried in a terms of service nobody reads. Written consent, specifically for the collection of biometric identifiers, obtained before the collection starts.

What compliant consent actually looks like

Before deploying any AI tool that runs speaker recognition, Illinois companies need:

  • **Written notice** to all participants that the tool will collect biometric identifiers (voiceprints) through speaker recognition
  • **Explicit written consent** from each person, obtained before the collection happens
  • **A publicly available retention policy** stating how long the voiceprints are kept and the specific criteria for destroying them

That means the meeting invitation needs to disclose the tool and what it collects. A blanket consent form in your general software terms doesn't cover participants who never agreed to your software terms. External clients and prospects need separate disclosure.

Most companies deploying these tools haven't done any of this. They bought a notetaker subscription, invited the bot to meetings, and let it run. The vendor's own BIPA compliance documentation, if it exists, is mostly written to cover the vendor. It doesn't automatically cover the employer as a separate collector.

This is solvable. A written consent disclosure process isn't operationally complicated. But it needs to be built into the invitation workflow before every call, not retrofitted after a complaint arrives.

Insurance coverage for BIPA claims

BIPA is one of the most active litigation areas in Illinois. Insurers know this, and many have responded by tightening or excluding coverage.

The natural home for BIPA coverage is a combination of cyber liability and employment practices liability. Both have developed gaps.

Cyber policies cover data breaches and privacy violations, but biometric exclusions have started appearing on renewal forms. Some cyber carriers added explicit biometric information exclusions after the wave of Illinois BIPA class actions from 2019 through 2022. If your cyber policy renewed in the last two to three years, check the endorsement schedule for any exclusion language referencing biometric information, Illinois BIPA, or similar statutes. An exclusion filed quietly at renewal can wipe out coverage you assumed you had.

GL policies sometimes responded to early BIPA claims under the personal and advertising injury provisions, specifically the "publication" of private information prong. Carriers have been filing endorsements to remove this coverage for statutory biometric claims. The ISO biometric exclusions filed in recent years have made GL an unreliable fallback for BIPA exposure.

Specialty privacy policies are the most direct coverage for BIPA claims. These are often part of a management liability tower or written as a standalone privacy liability policy. They're also the forms most specifically underwritten for this type of exposure, which means underwriters are asking more questions and setting sublimits on biometric-specific claims.

If your Illinois company uses AI meeting tools with speaker recognition, your broker needs to know that when the account renews. It changes how underwriters evaluate the risk. It also changes which carriers are willing to cover it and at what limit.

There's a timing issue too. If a complaint is filed and you didn't disclose the tool usage when you applied for coverage, the carrier may have a material misrepresentation argument. Coverage under a policy bound without that disclosure could be at risk even before you get to what the policy actually covers.

The voice agent problem extends beyond meeting tools

AI meeting notetakers are the most common exposure right now, but they're not the only one.

Illinois companies running voice AI in any commercial context face the same doctrinal question. Customer service voice bots that authenticate callers by voice. Hiring tools that conduct voice-based candidate screenings. Quality assurance systems that monitor customer calls and identify speakers. Any system that builds a voice model to recognize a specific individual creates what a court will likely analyze as a voiceprint under 740 ILCS 14/10.

Cruz v. Fireflies.AI named the issue directly in the AI meeting tool context. But the legal principle it's litigating applies wherever speaker recognition runs on Illinois residents without written consent and a compliant retention policy.

A voice authentication system that recognizes a returning customer by their voice is doing biometric collection. So is a quality assurance platform that diarizes call center recordings to track which agent handled each interaction. The tool category doesn't matter. The function does.

What Illinois companies should do now

The practical steps aren't complicated, but they're specific.

First, audit which tools in your stack use speaker recognition or speaker diarization. Not all AI meeting tools do. Some offer transcription without diarization. If a tool doesn't identify speakers by voice, the BIPA voiceprint question may not apply. Get clarity from the vendor in writing on exactly what biometric processing the tool performs.

Second, for tools that do diarize, build a written consent workflow into your meeting invitation process. It doesn't have to be legally complex. It needs to say, in plain language, that the meeting will use an AI tool that collects voiceprints through speaker recognition, and it needs a consent mechanism before the collection starts. Get this in front of counsel to get the language right.

Third, review your cyber and privacy liability policies specifically for biometric exclusions. A summary from your broker isn't enough. You need the actual endorsement schedule and someone who knows what to look for. An exclusion buried in a 2024 renewal could mean you're carrying significant BIPA exposure with no insurance backstop.

Fourth, if your company has been running these tools without a consent process, talk to counsel before doing anything else. Prior unconsented collection is a different situation than prospective non-compliance. The remediation path matters and it's not something to improvise.

If you're an Illinois business using AI meeting tools, voice agents, or any system that identifies speakers by voice, reach out to Jack Ray directly. He works with commercial accounts across DuPage County and the Chicago suburbs and can review your current insurance program for biometric liability gaps.

Email: jray@lakeshoreriskadvisors.com

Are you overpaying for home protection?

Compare options from multiple providers in 60 seconds. Free, no obligation.

Get your free estimate