Meeting Recording Consent Laws by Jurisdiction
State recording consent laws vary widely and override federal minimums for remote calls.

Most compliance teams anchor their recording policy to a single number: one. Federal law under the Electronic Communications Privacy Act and the Wiretap Act sets a one-party consent floor, meaning that if you are a participant in a conversation, your own awareness that it is being recorded satisfies the federal standard. That fact leads a great many organizations to conclude that recording a meeting is lawful anywhere in the country as long as one person in the room knows about it. That conclusion is wrong. The federal rule does not preempt state law, so a recording that clears the federal bar can still violate a state statute carrying criminal penalties far more severe than anything the federal code imposes. Federal penalties are not trivial on their own, running up to five years imprisonment, fines up to $250,000, and civil damages per violation, but state exposure frequently exceeds even that. The federal statute was also written for a different era of surveillance technology. It governs interception of wire, oral, and electronic communications in language drafted for analog wiretapping, and Reed Smith's Employment Law Watch has flagged that AI-powered recording tools raise legal questions under statutes written decades before AI transcription existed. Treating the federal floor as a compliance ceiling is the single most common misunderstanding driving recording-related liability today.
How one-party consent works across the 38-state majority
The one-party rule is the default across most of the country: 38 states plus Washington D.C. allow a participant's own knowledge that a conversation is being recorded to satisfy the law, with no obligation to notify anyone else on the call. That rule applies only to people who are actually part of the conversation. An outsider who is not a participant cannot invoke one-party consent to justify recording a conversation they are merely listening in on. For organizations operating entirely within one-party states, this creates real operational latitude: AI recording tools can run in the background, calls can be logged for quality assurance, and transcripts can be generated without a formal disclosure requirement, though disclosing the practice anyway remains the better business habit. One-party status is a floor, not a blank check. Courts still weigh whether a party had a reasonable expectation of privacy, sector-specific rules in healthcare and legal practice can impose stricter obligations than the general statute, hidden-camera laws operate on separate logic from audio recording, and using a lawful recording for an unlawful purpose, such as blackmail or harassment, strips away the one-party protection. The 38-state majority is the baseline most organizations build their recording practices around. The minority of all-party states function as a trap for teams that assume the rule they know is the rule everywhere.
The all-party consent states and what each requires
Thirteen states require consent from every participant in a conversation for at least some category of communication, and eight of those thirteen can prosecute a violation as a felony. The states most consistently identified as all-party jurisdictions are California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, Nevada, New Hampshire, Pennsylvania, and Washington, with Oregon applying an all-party notice requirement, rather than a consent requirement, to in-person conversations only. RecordingLaw.com, with its legal content checked current as of August 9, 2026, catalogs each of these states alongside its governing statute and maximum criminal penalty, and the details diverge enough from state to state that no single "all-party" template covers them all.
California's statute, Penal Code § 632, requires all-party consent whenever a conversation is reasonably expected to be confidential, and that consent must be express: implied consent does not satisfy the law, and even a quiet exchange in a shared office can qualify as a confidential communication subject to the statute. Florida's statute, Fla. Stat. § 934.03, applies all-party consent to both in-person and electronic communications, and Florida is unusual in criminalizing the attempt itself: activating a recorder that fails to actually capture audio still violates the law. Massachusetts, under Mass. Gen. Laws ch. 272, § 99, takes a different structural approach by banning secret recording rather than mandating affirmative consent, so a recording made when participants reasonably know they might be recorded generally satisfies the statute, though every violation of the law is charged as a felony. Pennsylvania imposes one of the steepest penalties in the country under its wiretapping statute. § 5703, a third-degree felony carrying up to seven years in prison. New Hampshire, under RSA 570-A:2, treats willful violations as a Class B felony carrying up to seven years and a fine, while a knowing violation committed by a party to the communication is charged as a lesser misdemeanor under RSA 570-A:2, I-a.
Connecticut runs two separate tracks at once: a civil statute, Conn. Gen. Stat. § 52-570d, requires all-party consent for electronic communications, while the state's criminal eavesdropping statute, § 53a-189, operates on a one-party basis, so the civil and criminal exposure for the same recording can differ depending on which statute applies. Oregon runs the mirror image of Connecticut's split: ORS 165.540 requires all-party consent for in-person conversations but allows one-party consent for phone calls and other electronic communications. Michigan's statute reads as all-party on its face, but the Michigan Court of Appeals recognized a participant exception in Sullivan v. Gray in 1982, and a federal court explicitly reaffirmed that construction in April 2026, though Reed Smith flags the state's rule as unsettled and recommends caution given the mixed participant standard. No organization should treat "all-party consent state" as a single, interchangeable label. The statute number, the felony threshold, and even which branch of law (civil or criminal) governs a given recording all shift from state to state, and getting any one of those details wrong is what turns a routine business call into a criminal exposure.
The cross-jurisdictional problem that makes remote work a compliance trap
The state-by-state map above assumes a conversation happens inside a single state's borders. Remote and hybrid work routinely breaks that assumption, and when it breaks, the strictest law in the room wins. If even one participant joins a call from an all-party consent state, that state's law governs the entire session, so a meeting with most participants in one-party states and a single participant in Illinois or California is, for consent purposes, an all-party meeting in full. This is not a hypothetical extension of the statutes; it is settled by case law. The controlling precedent is Kearney v. Ct., 2006), in which the court held that California's two-party consent statute applied, for purposes of injunctive relief, to a Georgia-based broker recording a California-based client going forward, while declining to impose monetary damages for past conduct because Georgia's interest prevailed with respect to conduct that had already occurred. The location of the person being recorded was the decisive factor in that ruling for prospective relief.
Courts have generally followed that logic, applying the law of the state where the recorded party is located, but RecordingLaw.com is candid that which state's law governs an interstate call is not definitively settled, and it remains one of the genuinely unresolved questions in this area of law. Remote work has turned that unresolved question into a daily operational fact rather than an edge case. A team distributed across New York, Illinois, California, and Washington has participants in two all-party consent states in every single meeting it holds. Compounding the problem, area codes cannot be trusted as a proxy for a participant's physical location: NextPhone's 2026 compliance guide notes that under federal regulations governing number portability across carriers, a phone number can carry an area code from one state while its user sits physically in another. Given that uncertainty, the only defensible default for any organization running multi-participant meetings is to assume the strictest state's law applies to every session, and to obtain affirmative consent from all participants before recording begins, regardless of where the majority of attendees happen to be.
How AI recording tools compound the consent problem
AI meeting recorders do not just automate a task humans used to do manually. They introduce a legal question that has no equivalent in the era of human-operated recorders: whether the AI bot itself counts as a party to the conversation, which would make host consent sufficient, or as an unauthorized third-party interceptor, which would make the recording unlawful regardless of what the host consented to. That question is not academic. In Ambriz v. Google, the court denied Google's motion to dismiss, finding that plaintiffs had adequately alleged Google acted as an unauthorized third party to their calls under CIPA, on the theory that the company had the capability to use intercepted data for its own purposes. That "capability test", asking simply whether a vendor had the capability to use intercepted data for its own purposes, was sufficient on its own to establish third-party status at the pleading stage, and the reasoning extends to any AI meeting recorder that processes, stores, or uses meeting data beyond producing a plain transcript.
The litigation already underway shows this is not a theoretical risk. Cal., No. 5:25-cv-06911) consolidates four lawsuits alleging OtterPilot joined meetings without participant knowledge, collected voiceprints without BIPA-compliant written consent, auto-joined meetings by default, and in its standard configuration notified only users on Enterprise plans that a recording was taking place. Cruz v. Fireflies.AI Corp., filed in December 2025 under Illinois's biometric privacy law, alleged that the product's speaker-recognition feature collected voiceprints without written consent from participants who did not hold an account, though that case was voluntarily dismissed without prejudice on March 11, 2026. Two further actions followed a similar pattern: Cresta, a CIPA case voluntarily dismissed without prejudice on September 3, 2025, and Lisota v. Heartland Dental, a federal wiretap claim filed in July 2025 and ultimately dismissed with prejudice on July 24, 2026. Dismissal, whether with or without prejudice, does not mean the underlying legal theories were rejected; several of these cases were withdrawn rather than defeated on the merits.
Voiceprint collection opens an entirely separate track of liability, running parallel to wiretapping exposure. Illinois's BIPA classifies voiceprints as protected biometric data and imposes statutory damages per person, per instance; the Clearview AI settlement under that same statute, structured as an equity stake in the company rather than a cash payout, shows how large these valuations can become. A visible AI bot listed as a meeting participant does not, by itself, satisfy consent requirements in any jurisdiction; explicit disclosure is required no matter what recording method is used. Reed Smith recommends that any organization using a third-party AI vendor secure a written data-protection agreement prohibiting the vendor from using meeting data for unauthorized purposes, including training the vendor's own AI models. AI recording tools have not replaced the consent analysis that governed human-operated recorders. They have added a second consent question, about the AI system itself, on top of the one that already existed for the human participants in the room.
Civil and criminal penalties that make noncompliance a business risk, not just a legal one
Recording violations in the strictest states are prosecuted as felonies, not handled as regulatory infractions, and that distinction is frequently lost on teams outside the legal department who assume a compliance failure means a fine rather than a criminal record. In Illinois, a first offense is a Class 4 felony carrying one to three years in prison and substantial fines, and a subsequent offense escalates to a Class 3 felony carrying two to five years. Pennsylvania charges violations as a third-degree felony carrying up to seven years and significant fines. Massachusetts treats every violation as a felony, with penalties reaching up to five years and $10,000. New Hampshire classifies willful violations as a Class B felony carrying up to seven years and a substantial fine. Florida charges violations as a felony carrying up to five years and significant fines.
The civil settlements tied to this wave of litigation put a dollar figure on what these statutes mean in practice for large organizations. Fifth Third Bank for tens of millions of dollars over allegations that it recorded calls to small businesses without the consent the state's statute requires. Wells Fargo settled a related case between 2024 and 2025 for a similarly large sum, covering thousands of California businesses.
GDPR and the EU AI Act on Top of U.S. Consent Rules
GDPR is not a recording-consent statute in the way U.S. wiretapping laws are. It is a data processing framework in which recording is simply one form of processing, and consent is only one of six lawful bases recognized under Article 6, alongside legitimate interest, contractual necessity, and others. That structural difference means an organization can sometimes justify a recording under GDPR through a basis other than consent, even in situations where U.S. law would demand it directly. The scale of exposure if that justification fails is different in kind from anything in the U.S. state system: maximum GDPR penalties are calculated as a percentage of a company's global annual revenue or a fixed ceiling, whichever figure is greater, a formula that dwarfs the civil exposure typical of U.S. state law.
GDPR is also only the floor within the EU. Each member state layers its own criminal consent rules on top of the regulation, so a recording that is lawful under a country's national statute can still violate GDPR if the recorder lacks a valid lawful basis for processing, fails to issue a proper privacy notice, or retains the recording without a defined retention schedule. Germany illustrates how far a national rule can exceed the GDPR baseline: German law requires that all participants clearly consent in advance before an online meeting can be recorded at all.
A third regulatory layer is now active on top of GDPR and national consent law: the EU AI Act. The Act entered into force on 1 August 2024. Prohibited practices under Article 5, including the workplace emotion-recognition ban, have applied since 2 February 2025. Transparency obligations under Article 50, along with most high-risk system obligations, have been pushed back under the Digital Omnibus on AI, with Annex III systems now deferred to 2 December 2027 and Annex I embedded systems deferred to 2 August 2028. For any organization running international meetings with AI recording tools, statutes like Illinois's felony biometric-privacy provisions and GDPR's revenue-based penalty scale can both apply, and satisfying one does not substitute for satisfying the other.
Sources
- Is It Legal to Record a Meeting? U.S. State Laws Explained (2026)
- The legality of AI-powered recording and transcription
- Call Recording Laws by State 2026: Compliance Guide
- AI Meeting Recording Laws by State: Complete Guide (2026)
- Recording Meetings in the US: A State-by-State Consent Guide - Summit AI Notes Blog


