Courts are applying old wiretapping laws to modern AI tools like chatbots and transcription software, claiming they intercept communications without consent.
Legal debates focus on whether AI vendors are eavesdroppers or independent actors. States are starting to pass laws requiring disclosures. Companies should audit AI tools, improve consent, update privacy policies, and stay updated on legal changes to manage risks.
A new wave is rising from courts across the country as plaintiffs have started weaponizing decades-old wiretapping statutes against modern artificial intelligence (AI) programs and tools. These emerging cases span from notetaking software to customer service chatbots and allege that these AI programs act as unauthorized “eavesdroppers” when they intercept, record, and use conversational data without consent.
The implications are profound: as AI vendors increasingly process communications for model training, data enrichment, and analytics, they face unprecedented exposure under statutes dating back to telegraphs and telephone taps.
This article examines the judicial framework emerging from this litigation, analyzes how courts are interpreting foundational privacy statutes in the AI context, and explores the defenses that courts are considering as this novel area of law develops.
I. From Landlines To AI: The Statutory Framework of Wiretapping
For as long as oral communications have been exchanged over wires, third parties have found ways to intercept and monitor these conversations, often covertly. While the earliest form of wiretapping dates back to the Civil War, legislatures didn’t take notice until decades later.
By the 1960s, wiretapping was a critical concern as the Cold War stoked fears of widespread surveillance and law enforcement began using wiretaps in criminal investigations. In response to these concerns, California passed the Invasion of Privacy Act (CIPA) to “protect the right of privacy of the people” by making California an all-party consent state. CIPA prohibits interceptions without all-party consent and banned “pen registers” and “trap and trace” devices absent court order.
Following California’s lead, Congress enacted the Federal Wiretap Act of 1968 (the Wiretap Act). This comprehensive statutory framework sought to regulate wiretapping at the national level by prohibiting the unauthorized and nonconsensual interception of communications.
Two decades later, Congress enacted the Electronic Communications Privacy Act of 1986 (ECPA), amending the Wiretap Act and extending the wiretapping restrictions to digital transmissions, including emails, telephone conversations, and data stored electronically. Today, these statutes have become the framework for the wave of privacy litigation surrounding artificial intelligence.
II. Javier v. Assurance IQ: The Case That Started the Tsunami
The first wave of litigation involved session replay tools. This specialized software, often embedded in websites and mobile phone apps, logs user/visitor behavior in real time—every keystroke, cursor path, scroll, and click—and transmits that data stream to the operator or a third-party vendor, who can then reconstruct the visit as though watching a screen recording of the user’s session.
Businesses commonly deploy the technology to diagnose site errors and study how customers navigate their pages; the plaintiffs’ bar frames that same capture as an unconsented interception of a communication.
Florentino Javier visited an insurance website that allegedly used third-party replay tools to record his electronic movements and data. While attempting to secure an insurance quote, Javier entered his personal information. The website then led Javier to a page stating that clicking the “View My Quote” button also constituted agreeing to an Assurance IQ Privacy Policy.
Javier clicked the button but later filed a putative class action claiming the website owner and third-party software company violated Section 631(a) of CIPA (Section 631) when they recorded his interactions. This case raised a foundational question: does a user’s click-through acceptance of a privacy policy after entering personal information constitute valid consent to third-party surveillance?
The Ninth Circuit in Javier v. Assurance IQ, LLC, 2022 WL 1744107 (9th Cir. May 31, 2022), said “no.” In applying Section 631 broadly to internet connections, the court concluded that the statute imposes liability on anyone who gathers or attempts to gather the contents of a communication without the consent of all of the parties to that communication. Therefore, the court held that retroactive consent to a privacy policy through a post-entry button click does not constitute cognizable consent to third-party surveillance.
On remand, the U.S. District Court for the Northern District of California, also determined that Javier’s claims were time barred, but addressed whether software vendors possessed independent capability to use intercepted information for their own purposes, highlighting that the principle underlying Section 631 is “the right to control the nature and extent of the firsthand dissemination of [one’s] statements.”
The court further found that Javier plausibly alleged that the third party qualifies under Section 631, because it possessed independent capability to use intercepted information for other purposes, regardless of whether they actually used it.
This decision proved to be the impetus for the current wave of AI wiretapping cases.
III. Third-Party AI Vendors: Leading the Wave
In the wake of Javier, the plaintiffs’ bar pounced on session replay class actions. Not every state had the same results, however. Florida has become a hotbed for these modern wiretapping class actions, with cases often targeting the Florida Security of Communications Act and arguing that tracking pixels and session replay software intercepts electronic communications without prior consent.
Unlike California, however, courts in Florida focus on whether the content of an interaction is being recorded, not just the movements of the users.
With this mixed success, the plaintiffs’ bar seemed to ramp up their California litigation and identified a new target: third-party AI vendors. Beginning in 2024, federal courts began addressing whether deploying third-party conversational AI systems to analyze customer interactions without explicit consent violates federal and state wiretapping statutes.
Two analytical frameworks have become central to CIPA based AI wiretapping litigation: (1) the “extension” or “agent” framework, which asks whether a vendor is an extension of the deploying company; and (2) the “capability” framework, which asks whether the vendor possesses the mere ability to use intercepted data for their own independent reasons. These frameworks are not mutually exclusive, but courts are split as to when these frameworks apply.
a. Customer Service AI Tools Under Attack
To date, these frameworks have been applied to various customer-facing AI tools. AI chatbots were the first to fall under attack.
When a company embeds a third-party chatbot on its website and that chatbot engages in real-time analysis of customer conversations by transcribing, analyzing, and storing that content, multiple layers of interception occur simultaneously. Courts recently have held that AI chatbots are indeed a means of interception and that third party vendors are more than extensions of a deployer, rendering them potentially liable as eavesdroppers.
Beyond chatbots embedded in web pages, courts have further addressed a separate category of AI interception: real-time call monitoring and conversation intelligence tools. These programs analyze telephone conversations in real time, transcribing, categorizing, and extracting data while the call is actively occurring.
Among the most recent cases is Taylor v. ConverseNow Technologies, Inc., No. 25-CV-00990-SI, 2025 WL 2308483 (N.D. Cal. Aug. 11, 2025), a CIPA class action where the plaintiff alleges that an AI-powered virtual assistant quietly intercepted her call with Domino’s Pizza and recorded her name, address, and credit card details without her knowledge or consent, in violation of Sections 631 and 632.
In denying defendant ConverseNow’s motion to dismiss, the Northern District of California adopted the “capability” framework, holding that Taylor plausibly alleged that ConverseNow used caller data to enhance its own services.
The court further held that when ConverseNow held itself out to be Domino’s, AI interception occurred in real time and directly engaged the consumer, who was not aware the call had been routed to a third party. With this ruling, federal courts have signaled that AI voice assistants—which are rapidly taking over electronic customer service—could constitute unlawful interception under CIPA and could be liable under Section 631.
Outside of CIPA, however, the landscape looks a little different. In the Northern District of Illinois, AI vendors and deployers scored a significant win in the January 2026 case of Lisota v. Heartland Dental, LLC., No. 25 CV 7518, 2026 WL 91667 (N.D. Ill. Jan. 13, 2026). Plaintiff Megan Lisota brought a putative class against Heartland Dental and RingCentral, Inc., alleging that her dentist contracted with Heartland to provide administrative services including after-hours and overflow call services.
Heartland, in turn, contracted with RingCentral for its AI-based telephone services. Lisota argues that the Defendants violated the ECPA when RingCentral eavesdropped and analyzed her calls, which included personal and protected health information, and when Heartland procured RingCentral’s services.
The defendants moved to dismiss, arguing that the ECPA exempts from liability anyone who intercepts communications in the “ordinary course of its business.”
The court agreed, holding that RingCentral’s AI software is essential and necessary to its business. While marking a significant win for companies who utilize AI tools to assist in the necessary course of business, the case highlights the widening gap between how courts are viewing and applying old statutes to modern tools.
Critically, states such as Florida and Pennsylvania have seen an uptick in “tester” cases, wherein numerous cases have been filed alleging wiretapping for these live chat features, each testing the waters under respective state laws. While California remains the hotbed for these actions, companies in other states need to keep an eye on these budding test cases.
b. The Next Wave: Note Taking and Transcription AI
An emerging category of AI interception cases involves note-taking and transcription applications, which allow users to record and automatically transcribe meetings, lectures, and even doctor’s appointments.
In November 2025, Jose Saucedo filed a class action against Sharp HealthCare in the Superior Court of San Diego, No. 25U063632C, alleging that a medical group systematically used an ambient AI clinical documentation tool to secretly record confidential doctor-patient communications before transmitting the recordings to a third-party vendor for processing in violation of Section 632, among other claims.
Saucedo alleges that while Sharp’s AI produced notes contain boilerplate language that patients consented to the use of the program, Sharp never provided any advisement or obtained any consent.
As AI-powered transcription becomes increasingly ubiquitous in workplace settings, including and especially in health care, the scope of exposure for transcription vendors may prove to be substantial, potentially turning on whether these programs are extensions of the deployer and procured in the ordinary course of business, or whether these third-party vendors have capabilities to use this data sufficient to trigger eavesdropper liabilities.
IV. Defenses and Emerging Legal Arguments
As the plaintiffs’ bar continues to mold their litigation strategies, defendants have developed a sophisticated arsenal of defenses that have met with varying degrees of success.
The Party Exemption Defense
A statutory exception to liability under the federal Wiretap Act and analogous state wiretapping laws—codified at 18 U.S.C.A. §2511(2)(c) and (d)—this defense advances the argument that a party cannot be found liable for eavesdropping on its own conversation.
However, when a company deploys a third-party AI vendor to analyze communications, courts must determine whether the vendor is a “party” to the communication or a liable “non-party” eavesdropper.
Defendants have argued that third-party AI vendors are simply “agents” or “extensions” of the deploying company and therefore qualify for the party exemption. Plaintiffs counter that vendors with independent financial incentives to use data constitute independent entities who lack the exemption.
Status: Mixed success, with newer cases finding more questions of fact sufficient to withstand dismissals and summary judgements. The issue tends to turn on agreements between the company and the vendor, and whether the vendor has the capability to collecting data and use it for its own independent purpose.
The Ordinary Course of Business Exception
A statutory defense under the federal Wiretap Act, this exemption applies to communications service providers using equipment in the ordinary course of business.
Status: Limited success but not universally accepted. The exception has succeeded primarily in cases involving actual communications service providers, like RingCentral. For third-party vendors that are not communications service providers, such as AI chatbot vendors embedded in non-telecom company websites, courts have been skeptical.
Consent/Disclosure Arguments
The federal Wiretap Act and its state counterparts establish a framework under which consent operates as a defense to wiretapping liability. Recently, courts have further held that consent cannot be uninformed or buried in privacy policies and that it must be secured prior to the interception and collection of data. More recent cases have moved the needle towards increasing specific affirmative disclosures and consent.
Status: Success requires substantial compliance with disclosure and consent requirements. Simple reliance on privacy policies or generic “may be monitored” disclaimers will likely fail. Defendants who have succeeded in dismissing claims have typically done so based on explicit, separate consent mechanisms specifically identifying the third-party vendor, explaining the vendor's independent data uses, and obtaining opt-in agreement before interception occurs.
Lack of Harm Arguments
Lack of harm arguments assert that there are no actual damages or that statutory damages are not appropriate. Currently, most federal courts, however, have found, for example, that economic injury is not a prerequisite for standing under federal and state statutes, In re Facebook Internet Tracking Litigation, 140 F. Supp. 3d 922 (2015).
Status: Weak and failing. Courts consistently treat unauthorized interception as constituting concrete privacy harm. Statutory damages provisions are interpreted as deliberately eliminating the need for proof of economic injury. The very fact that interception occurred without consent is treated as harm sufficient for damages, Satchell v. Sonic Notify Inc. et al., 234 F.Supp, 3d. 996 (2017); In re Facebook, Inc. Internet Tracking Litigation, 956 F.3d 589 (9th Cir. 2020).
No Interception
Courts across multiple circuits have consistently held that interception requires acquisition contemporaneous with transmission—meaning the communication must be captured while in transit, not while in electronic storage. Konop v. Hawaiian Airlines, Inc., 302 F.3d 868 (2002); U.S. v. Jones, 364 F.Supp.2d 1303 (2005).
Status. Real-time collection by a chatbot or chat software can constitute interception under federal and state wiretapping laws when the collection is contemporaneous with transmission, involves a non-party third party capturing the actual contents of communications, and is supported by specific factual allegations.
V. Legislative Responses
As litigation has accelerated, legislatures are scrambling to respond. California’s Senate Bill 243 (effective Jan. 2026) requires chatbot operators to disclose AI use and implement safety measures for minors. New York, Washington, Nebraska, and Idaho have passed similar disclosure statutes.
Dozens of additional states have pending legislation. However, while these statutes address some privacy concerns with the use of AI tools, they do not comprehensively regulate data retention, vendor liability, or secondary uses of conversational data. Instead, they tend to focus on the protection of minors and those in mental health crises.
VI. Practical Takeaways
The emerging wave of AI wiretapping litigation has profound implications for companies deploying these third-party AI systems and the AI developers and vendors themselves. The litigation has established several clear principles:
First, courts have determined that third-party AI vendors that possess independent incentives to use intercepted data likely cannot claim the party exemption defense simply by virtue of deployment through another company.
Second, generic privacy policies and catch-all “may be monitored” disclaimers are likely insufficient under modern wiretapping jurisprudence. Companies should look towards specific disclosures and affirmative consent.
Third, statutory damages provisions are being interpreted broadly, with courts holding that concrete privacy injury can exist absent any showing of economic harm. This creates enormous litigation exposure for defendants when class actions are certified.
Companies deploying third-party AI systems might consider the following:
a. Audit Current AI Tools: Audit what’s actually running on your website. Most companies don’t know which third-party tracking tools their marketing team or vendors have installed. Systematically inventory all third-party AI systems deployed across customer-facing platforms, and document the vendor’s identity, the data collected, the vendor’s stated purposes, the vendor’s potential independent uses of data, and whether contractual restrictions limit vendor’s independent use.
b. Fix the Consent Timing. Javier’s core lesson: consent obtained after recording begins is no consent at all. Deploy a banner or interstitial that blocks tracking tools from firing until the visitor affirmatively agrees. Before deploying third-party AI systems, obtain explicit written consent from users. This consent should: (i) identify the specific vendor by name; (ii) explain what communications will be captured and analyzed; (iii) describe the vendor’s independent purposes for using data; (iv) disclose data retention periods; and (v) allow users to opt out without losing core service functionality.
c. Expand Disclosures: Update the privacy policy to name the technology. Generic “we collect usage data” language won’t do. Disclose that session recording, chat monitoring, or AI analytics tools are in use, and identify the categories of third parties receiving the data.
d. Review Vendor Contracts: Require tracking and AI vendors to warrant that they use client data only to provide the service—not to train models or enrich their own datasets. The §631 “third-party eavesdropper” theory turns on what the vendor does with the data.
e. Check the Two-party Consent States. California, Pennsylvania, Florida, Massachusetts, and roughly two dozen other states have similar statutes. A compliance fix scoped only to CIPA leaves exposure elsewhere.
f. Reassess After Every Website Change. New tools get added constantly and quietly. Make tracking-technology review a standing item in website governance, not a one-time cleanup.
g. Monitor Litigation Developments: As this area of law develops rapidly, companies should subscribe to litigation updates and consult regularly with counsel regarding new court rulings that may affect compliance obligations.
VII. Where Will This Wave Take Us?
Critically, courts across the country have split on how to handle these emerging claims and state and federal legislatures are scrambling to keep up. What is clear, however, is that the AI wiretap wave is not a passing trend. Companies, regulators, and legislatures alike must grapple with fundamental questions about who owns conversational data, who may use it, and on what terms.
* * * *
Reprinted with permission from the August 26, 2026 edition of the New York Law Journal © 2026 ALM Global Properties, LLC. All rights reserved. Further duplication without permission is prohibited, contact 877-256-2472 or asset-and-logo-licensing@alm.com."