What happened in the US
Lindsay Waninger worked at Marathon Engineering for fewer than three months before being fired in a video conference. The meeting was automatically transcribed by the AI app Fireflies. Per her lawsuit, filed in August 2026, the transcript recorded a supervisor allegedly saying the 'ideal' replacement for her position would 'hopefully' be a 'relatively strapping young man' - a statement now cited as evidence of gender discrimination. Even if the transcript ultimately isn't fully admissible in court, its existence still has to be disclosed during discovery, and can trigger further witnesses or investigation.
In parallel, a consolidated class action is proceeding in a US federal court in Northern California against Otter.ai, alleging the tool recorded private conversations without every participant's consent and used the recordings to train its own AI models without adequate disclosure. Together, both cases show a pattern: AI meeting tools preserve, and can surface, conversation content that participants never anticipated being used in court or by third parties at the time they spoke.
The German legal position: not a consent problem, a criminal offense
US coverage largely frames this as a question of consent, privacy, and evidence admissibility. Under German law, the starting position is sharper: Section 201 of the Criminal Code (StGB) makes unauthorized recording of another person's non-publicly spoken words a criminal offense - punishable by up to three years' imprisonment or a fine. In principle, consent from every participant in a conversation is required, not just from the person who activated the tool.
A technical nuance is decisive here, one that legal analyses of AI-powered meeting transcription work out in detail: if a conversation is transcribed purely 'on the fly', without the audio material itself being stored, there's no punishable recording. But for most mainstream transcription tools, the processing pipeline includes intermediate or buffer storage of the audio signal that goes beyond merely transient processing in working memory - which technically fixes the spoken word and regularly brings the case within the scope of Section 201(1) No. 1 StGB.
Why consent is especially hard to secure in an employment relationship
Effective consent from every participant rarely proves practical - particularly in an employment relationship, where the voluntariness required for effective consent is often missing. If a manager announces that a meeting will be AI-transcribed, and employees can't realistically object without risking their position, that consent is legally vulnerable. That concerns exactly the situations - termination meetings, performance reviews, conflict conversations - that became the subject of dispute in the Marathon Engineering case, and where a later evidentiary use is most likely to matter.
The additional EU AI Act dimension: emotion recognition
A second, independent legal layer concerns a feature some AI meeting tools advertise as an add-on: sentiment or mood analysis of conversations. Article 5(1)(f) of the EU AI Act has, since 2 February 2025, banned placing on the market, putting into service, or using emotion-recognition systems in workplace settings, aside from narrowly defined medical or safety purposes. An emotion-recognition system in this sense is any AI system designed to identify or infer the emotions or intentions of natural persons based on their biometric data - including voice. Violations fall into the regulation's highest fine tier: up to €35 million or 7 percent of global annual revenue, whichever is higher.
Decisive for companies that merely use such a tool rather than develop it: the ban doesn't just target vendors, it applies to anyone who uses a corresponding system. A company using a licensed meeting tool with a sentiment-analysis feature enabled in a workplace context violates Article 5 under this logic just as much as the tool vendor itself - regardless of whether it actively promoted the feature or simply left it on by default.
What this means in practice
Both legal layers - Section 201 StGB and Article 5 of the EU AI Act - concern a tool already in everyday use at many companies in our audience, often without the legal implications having been actively reviewed.
- Check which AI meeting tools are actually in use across your company - these are often activated independently by individual teams or managers, without central IT or legal sign-off.
- Before any AI-transcribed conversation, obtain effective, documented consent from every participant - and for termination meetings, performance reviews, or conflict conversations in particular, critically assess whether that consent is genuinely voluntary given the power imbalance involved.
- Actively check whether a tool in use includes sentiment or emotion-recognition features, and disable them in workplace contexts unless they fall under one of the narrowly defined exceptions in Article 5 of the EU AI Act.
- Set internal policies for using AI meeting tools that clearly govern the consent process, data retention, and permitted feature scope, rather than relying on a given vendor's default settings.
The real value of this analysis isn't a warning against AI meeting tools as such - they offer genuine value for documentation and follow-up. The point is that the legal starting position in Germany differs from the largely civil-law US debate: where a US company manages a consent and evidence problem, a German company without solid consent from every participant can commit a criminal offense - a difference that shouldn't get lost in the risk assessment.