A Voice Recording Can Be Speech, Property, and Biometric Data at the Same Time.
Most AI training lawsuits ask who owns the material a model learned from. A group of cases in Chicago asks a more unsettling question: what if the material is also part of the person? Journalists, podcasters, audiobook narrators, and voice actors allege that technology companies used recordings of their voices to train AI systems without the notice, consent, and data practices required by Illinois law. The defendants dispute both the facts and the law. No court has decided that a podcast or audiobook is automatically biometric data, because it is not. But the cases expose a category problem that AI developers, vendors, and their lawyers can no longer avoid. One file can contain protected expression, commercially valuable performance, ordinary personal information, and a biological characteristic capable of identifying its speaker. Calling it “training data” does not settle which law applies.
These are not ordinary copyright cases
Nine technology companies, including Apple, Amazon, Alphabet, Meta, Microsoft, Nvidia, Samsung, Adobe, and ElevenLabs, face proposed class actions in federal court in Chicago. According to the complaints and Reuters' August 20 report, the plaintiffs include Illinois journalists, podcasters, audiobook narrators, and voice actors whose recorded work was publicly available online. They allege that defendants used those recordings to develop or train voice-related AI systems without their permission.
The complaints do not plead copyright claims. They invoke the Illinois Biometric Information Privacy Act, commonly called BIPA, along with rights of publicity and other state-law theories. That choice is not cosmetic. Copyright asks whether protected expression was copied or used in a legally permissible way. Biometric privacy asks whether a private entity collected or obtained a biometric identifier or information derived from it, and whether the entity followed rules governing notice, consent, retention, disclosure, and profit.
A company could therefore defeat a copyright theory and still confront a biometric one. It could also prevail on the biometric claim if the plaintiffs cannot show that the system obtained a qualifying voiceprint, that conduct occurred within the law's territorial reach, or that the particular defendant used the plaintiffs' recordings at all. The pleadings begin the dispute. They do not resolve it.
A voice recording is not automatically a voiceprint
Illinois law defines a biometric identifier to include a retina or iris scan, a fingerprint, a voiceprint, or a scan of hand or face geometry. It separately regulates biometric information, meaning information based on a biometric identifier that is used to identify an individual. The distinction between a voice and a voiceprint matters.
A recording preserves sound. A voiceprint is generally a measurable representation of vocal characteristics that can be used to recognize or identify a speaker. A voicemail, radio segment, or audiobook does not become a statutory biometric identifier merely because a human voice appears in it. If it did, every recording would trigger biometric law before anyone analyzed it.
The plaintiffs' theory is narrower and more technical. They allege that the defendants extracted distinctive vocal features from recordings and used them in systems capable of modeling or reproducing human speech. The defendants have moved to dismiss and argue, among other things, that the complaints are speculative about which recordings were used and where the alleged processing occurred. Those are not side issues. They are the boundary between a recording as content and a recording as a source of biometric data.
Lawyers evaluating these systems should resist both easy slogans. “It is public on the internet” does not answer whether a company may derive regulated biometric information from it. “It contains a voice” does not prove that the company created or collected a voiceprint. The legal analysis depends on the system's actual data pipeline.
AI training collapses categories the law kept separate
A podcast episode looks like a piece of media to its publisher. To a speech-recognition system, it may be labeled language data. To a generative model, it may supply cadence, pronunciation, accent, timbre, or other acoustic patterns. To the speaker, it may be labor, identity, reputation, and a source of income.
The file has not changed. The use has.
That is why data provenance cannot stop at a license or a URL. A license may authorize copying for one purpose without answering whether the recipient may extract identifiers for another. A public source may reduce an expectation of secrecy without creating consent to biometric processing. A vendor's assurance that data was “lawfully obtained” may conceal the only question that matters: obtained to do what?
The useful compliance unit is not the file. It is the transformation. Counsel should be able to identify the source material, the features extracted, the purpose of extraction, whether the features identify a person, where processing occurred, who received the result, how long it is retained, and whether the resulting model can reproduce or recognize an individual's characteristics. Without that map, legal diligence becomes a debate over labels chosen by the party that built the system.
Consent is an engineering requirement
BIPA requires a private entity collecting or obtaining biometric identifiers or information to give written notice of the collection, its purpose, and its duration, and to obtain a written release. It also requires a publicly available retention and destruction policy, restricts disclosure, prohibits selling or otherwise profiting from biometric data, and imposes a reasonable standard of care.
Those duties are difficult to add after a model has been trained. If the source dataset contains millions of files scraped or licensed through intermediaries, who can connect each voice to a person, prove the scope of consent, honor a retention period, or remove a disputed contribution from downstream artifacts? The engineering decision to ingest first and document later can make legal compliance practically impossible even before a court decides whether a violation occurred.
Illinois narrowed BIPA's damages framework in 2024. Repeated collection of the same person's data using the same method now constitutes a single violation of the relevant collection provision for recovery purposes, and repeated disclosures to the same recipient using the same method are similarly limited. That change reduced the multiplication risk associated with every scan or transmission. It did not erase the private right of action or the statute's basic consent and governance duties.
The business lesson is straightforward. If consent matters, it must be represented in the product's data model. A policy page cannot supply a missing permission record, and a contract cannot reliably allocate risk that the buyer and vendor never traced.
Territory may decide as much as technology
Several defendants argue that Illinois law does not apply because the complaints do not plausibly allege that the relevant collection or processing happened in Illinois. That defense reflects a recurring problem in cloud systems. A plaintiff may live in Illinois, create a recording there, and experience the alleged loss there while the ingestion, feature extraction, model training, and storage occur across data centers and corporate entities elsewhere.
Courts will have to decide whether the pleaded facts connect the regulated conduct to Illinois strongly enough to proceed. The answer may vary by defendant and architecture. It would be premature to describe these cases as a definitive nationwide rule for voice AI.
But the territorial defense also reveals a weakness in ordinary vendor diligence. Many organizations cannot say where a particular training operation occurred or which subcontractor performed it. Location is treated as an infrastructure detail until it becomes an element of the claim. By then, the logs needed to answer the question may be incomplete, scattered, or outside the buyer's control.
The practical questions are more specific than ‘Do you use AI?’
A serious review of a voice system should ask whether recordings are used only to complete the requested service or also to train, fine-tune, evaluate, or improve models. It should distinguish transcription from speaker identification, authentication, emotion inference, synthetic voice generation, and quality testing. Those functions do not create identical risks merely because they begin with audio.
The reviewer should also identify whether raw recordings, embeddings, feature vectors, transcripts, prompts, and model outputs follow different retention schedules. Deleting an audio file may not delete the representation derived from it. Conversely, retaining a transcript may present confidentiality concerns without preserving a biometric identifier. Precision matters.
For law firms, this is not abstract. Calls, depositions, client interviews, recorded statements, and dictated work product can contain privileged, confidential, and personally identifying material. A firm evaluating a vendor should know whether its audio remains confined to the service it purchased. The answer should appear in the agreement and in the technical controls, not merely in sales language.
This does not mean every voice tool is unlawful or that every recording requires biometric consent. It means the phrase “we do not sell your data” is not a complete answer. The more relevant questions concern collection, derivation, training, disclosure, retention, deletion, geography, and control.
The category mistake is the real warning
The Chicago cases may be dismissed, consolidated, narrowed, settled, or eventually tried. The plaintiffs still must prove whose recordings were used, what the systems extracted, where the relevant conduct occurred, and why each defendant's conduct falls within each statutory provision. The companies are entitled to contest every one of those propositions.
The lasting point does not depend on predicting the docket. AI systems transform material across legal categories. A photograph can become facial geometry. A passage can become a model weight. A voice can become a transcript, a performance sample, or a representation of the speaker. Each transformation may activate a different body of law and a different theory of injury.
Organizations that govern data only at the moment of acquisition will keep missing this. The law increasingly cares not only about what the company received, but what the system made from it. That is a harder question. It is also the question the technology makes unavoidable.
The label attached to a source file does not control the law. The transformation performed on that file may matter more.
Sources and further reading
Primary and industry sources used to support this page. External guidance should be reviewed in context and for your jurisdiction.
- Illinois Biometric Information Privacy ActCurrent statutory definitions, duties, private right of action, and damages provisions.
- Public Act 103-0769Illinois's 2024 amendment limiting repeated collections and disclosures to one recovery per method, person, and relevant recipient.
- Marin v. Meta complaintOne of the pending complaints stating the plaintiffs' allegations; the allegations have not been adjudicated.
- Reuters, August 20, 2026Current reporting on the nine cases, motions to dismiss, parties, and defense positions.