The Lawsuit You Didn’t See Coming: AI Class Action Exposure from Routine Deployment Decisions
- August 2, 2026
- Posted by: allan
- Category: Uncategorized
Your company’s marketing team installed a chatbot last quarter. Your developer embedded a session replay tool to debug the checkout flow. Your analytics vendor dropped a tracking pixel on the homepage to measure ad performance. The product team enabled behavioral personalization so returning visitors see relevant content faster. None of these decisions felt like legal risk. They felt like standard operating procedure — because they are.
That is exactly the problem.
Over the past three years, a cottage industry of plaintiffs’ lawyers has reframed these ordinary technology choices as willful violations of decades-old privacy and wiretapping statutes. The theories are creative, the statutory damages are severe, and cases keep surviving motions to dismiss. If your organization has a website — particularly one that serves any California residents — you are operating in a class action environment that your legal team may not have fully mapped.
This post explains how that happened, where the exposure concentrates, and what practical steps can reduce your risk.
How a 1967 Wiretapping Law Became the Plaintiff Bar’s Favorite Weapon
The California Invasion of Privacy Act, codified at California Penal Code sections 630 through 638.55, was enacted in 1967 to prevent wiretapping of telephone calls. For most of its history it was an obscure criminal statute with limited civil application. That changed when plaintiffs’ lawyers noticed that its plain language — prohibiting the unauthorized interception of “any wire, line, cable, or instrument” — could be stretched to cover internet communications, and that it carries $5,000 in statutory damages per violation with no requirement to prove actual harm.
The Ninth Circuit’s 2022 decision in Javier v. Assurance IQ, LLC was the inflection point. The plaintiff had visited an insurance-quoting website that used a third-party tool called TrustedForm to record every keystroke, mouse movement, and interaction in real time. The Ninth Circuit’s key holding was narrow but enormously consequential: CIPA Section 631 requires prior consent. A privacy policy that users agree to after their data has already been captured is worthless as a defense. Retroactive consent — the kind baked into most cookie banners — is no consent at all.
That ruling sent a clear signal to the plaintiffs’ bar: the technical violation was easy to find, the consent problem was endemic to the industry, and the damages were statutory. What followed was a filing surge that has continued to accelerate. Since 2022, courts have seen hundreds of CIPA class actions, and by some estimates tens of thousands of demand letters, targeting websites for deploying tools their own marketing and engineering teams chose from standard vendor catalogs.
The legal theory has since migrated upward from session replay tools to AI-powered chatbots. Chatbot wiretap cases grew from roughly two filed matters in 2021 to more than thirty by the end of 2025, making chatbot-related wiretap claims the fastest-growing category of AI deployer litigation in the country. In August 2025, the U.S. District Court for the Northern District of California denied a motion to dismiss in Taylor v. ConverseNow Technologies, Inc., allowing a CIPA Section 631 claim to proceed against an AI-powered virtual assistant that handled phone and drive-thru orders on behalf of Domino’s Pizza franchises. The plaintiff alleged she was unaware her call had been routed through an AI system that recorded her name, address, and payment information. The court adopted a “capability” test: because ConverseNow’s own website stated that the system uses recorded calls to improve its AI models, the vendor was not merely a passive recording device — it was a third party with its own independent interest in the communications, and therefore potentially an unauthorized eavesdropper under California law.
Similarly, in February 2025, the same court denied Google’s motion to dismiss in Ambriz v. Google, LLC, applying the same capability test to an AI voice product. The logic is straightforward and dangerous for AI deployers: if the vendor contract allows the vendor to use your customers’ conversations to train its models, the vendor may have just become a third-party eavesdropper.
The VPPA: A 1988 Video Rental Law That Now Governs Your Website’s Video Player
Congress enacted the Video Privacy Protection Act in 1988 after a Washington journalist obtained and published Supreme Court nominee Robert Bork’s video rental history. The statute prohibits “video tape service providers” from knowingly disclosing consumers’ video-viewing information to third parties without written consent, and it creates a private right of action for statutory damages of $2,500 per violation — again, without requiring the plaintiff to prove actual injury.
For thirty years, the VPPA was a curiosity. Then plaintiffs’ lawyers discovered the Meta Pixel.
The Meta Pixel is a small piece of JavaScript that roughly 47 percent of all websites deploy — including an estimated 55 percent of S&P 500 companies, 58 percent of retailers, and 33 percent of healthcare organizations. When a site embeds video content and also runs the Meta Pixel, the pixel can transmit data about what videos a user watched along with that user’s Facebook ID, which Meta (and potentially an ordinary person using Facebook) can tie to a real individual. Plaintiffs argued this transmission constitutes knowing disclosure of video-viewing information by a video tape service provider — exactly what the VPPA forbids.
Courts in multiple circuits allowed these claims to survive. In 2024 alone, an estimated 250 VPPA class action complaints were filed — nearly double the prior year. The American Bar Association noted in April 2025 that VPPA pixel-based litigation “shows no sign of slowing.” The BuzzFeed corporation, for example, settled a VPPA class action for $9 million based on its use of Meta Pixel in connection with video content on its site. Dapper Labs, the blockchain company behind NBA Top Shot, reached a $5 million class settlement for disclosing video subscribers’ personally identifiable information to third parties.
There is ongoing circuit court divergence on key questions. In mid-2025, the Second Circuit narrowed the VPPA’s reach considerably, holding that strings of code transmitted by Meta Pixel do not constitute “personally identifiable information” under the statute because an ordinary person, without specialized tools, could not use that code to identify a specific individual’s viewing history. But the Sixth, Ninth, Eleventh, and Third Circuits have not uniformly applied the same standard, and the split leaves the law unsettled for businesses operating across jurisdictions. More importantly, even a defendant who ultimately prevails still faces the cost — and disruption — of surviving class certification proceedings and potential appeals. Settlements in the $5 million to $20 million range have become common even in cases with uncertain merits, because that amount frequently represents a fraction of the litigation cost and uncertainty of going to trial.
State Biometric Privacy Statutes: When AI Features Touch Physical Identity
Illinois’s Biometric Information Privacy Act, enacted in 2008, is the oldest and most litigated state biometric privacy law in the country. BIPA requires companies that collect biometric identifiers — fingerprints, retina or iris scans, voiceprints, face geometry derived from photographs — to first provide written notice, obtain a written release, and publish a publicly available retention and destruction schedule. It provides for statutory damages of $1,000 per negligent violation and $5,000 per reckless or intentional violation, again without requiring proof of actual harm.
The scale of BIPA settlements illustrates what that exposure looks like across a class. Snap settled for $35 million. TikTok settled for $92 million. Six Flags settled for $36 million over fingerprint scanning of season pass holders. Google settled two separate BIPA cases — one for $100 million relating to face grouping in Google Photos, and another for $8.75 million relating to student biometric data in Google’s education products. Clearview AI settled in April 2025 for $51.75 million. These are not outliers; they reflect a systematic pattern of litigation targeting any product that touches face geometry, fingerprints, or voice recognition.
For technology companies and startups, the relevant risk surface is expanding. AI-powered features that use face recognition for customer authentication, voice recognition for customer service, or even sentiment analysis tools that process facial expressions during video interactions can all trigger BIPA’s requirements if the user is in Illinois. The Illinois legislature’s 2024 amendment (SB 2979) provided some relief by capping damages at one recovery per person regardless of how many individual scans or interactions occurred — a response to the Illinois Supreme Court’s 2023 decision in Cothron v. White Castle, which had held that each biometric scan triggered a separate claim and thus potentially “annihilative” liability. The Seventh Circuit Court of Appeals held in April 2026 that this amendment applies retroactively to pending cases. But BIPA’s per-person damages are still substantial when multiplied across a large class, and the statute’s consent and disclosure requirements remain fully in force.
Washington’s My Health My Data Act: The Newest and Broadest Threat
Washington’s My Health My Data Act (MHMDA) took effect for most businesses on June 30, 2024. Its scope is broader than almost any health-data law outside of HIPAA — and it is specifically designed to capture the kind of consumer tracking that HIPAA misses.
The MHMDA defines “consumer health data” to include any personal information linkable to a consumer that identifies their past, present, or future physical or mental health condition. That definition covers not just obvious categories like prescription data or medical appointment scheduling, but also geolocation data that could reveal a visit to a clinic, purchasing data that reveals use of certain products, and in some readings, behavioral data that infers health status from web activity. Companies collecting, sharing, or “selling” such data without explicit consumer authorization face a private right of action through Washington’s Consumer Protection Act, which allows recovery of actual damages plus attorneys’ fees.
The first class action under the MHMDA was filed in February 2025, targeting Amazon for SDK data collection practices. By November 2025, a Washington federal court saw the first MHMDA pixel case: a complaint against Uncle Ike’s, a Seattle marijuana retailer, alleging that tracking pixels on its website transmitted customer data about marijuana purchases and medical card appointment scheduling to Google without consent. The plaintiffs argued this constituted unauthorized sharing of consumer health data under the MHMDA, and also raised claims under the federal Electronic Communications Privacy Act.
The significance of the Uncle Ike’s case for any business selling health-adjacent products — supplements, fitness equipment, cannabis, mental wellness apps, telehealth services — is direct. The MHMDA’s definition of health data is broad enough to sweep in routine e-commerce analytics if the products themselves have any health or medical character. And the law requires not just disclosure, but affirmative opt-in consent before health data is collected, and a separately signed authorization before it is shared or sold.
Why These Cases Survive Motions to Dismiss (and Why That Creates Settlement Pressure)
Understanding why these cases keep reaching discovery and class certification requires understanding the specific dynamics that make early dismissal difficult.
The Statutory Damages Problem
All of the major statutes in play — CIPA, VPPA, BIPA, and MHMDA — provide statutory damages for violations without requiring plaintiffs to prove they suffered actual, concrete harm in any conventional sense. CIPA authorizes $5,000 per violation. VPPA provides $2,500 per violation. BIPA provides $1,000 to $5,000 per person.
The Supreme Court’s 2021 decision in TransUnion LLC v. Ramirez created a standing hurdle in federal court by requiring that plaintiffs demonstrate concrete injury, not just statutory violations. This creates some defensive opportunity, particularly in federal BIPA cases, because a plaintiff who merely alleges a statutory violation without any resulting disclosure or tangible consequence may lack Article III standing. Several federal courts have applied TransUnion to dismiss putative class members who cannot show their data was actually disclosed or accessible to anyone who could identify them.
However, courts have been reluctant to dismiss VPPA and CIPA claims on standing grounds, reasoning that unauthorized disclosure of private communications and viewing habits constitutes a concrete injury analogous to the historically recognized tort of invasion of privacy. Multiple circuits — the Third, Ninth, and Eleventh — had already held pre-TransUnion that VPPA violations satisfy the concrete injury requirement, and those holdings largely survived. State courts are entirely insulated from the TransUnion limitation, which is one reason plaintiffs frequently file CIPA and MHMDA claims in state court.
The Pleading Standard Works for Plaintiffs
These cases are typically filed with thin specific allegations — plaintiff visited the website, chatbot captured communications, vendor received data, no prior consent was obtained — that are sufficient under federal pleading standards to survive a motion to dismiss. The key factual disputes about whether consent was valid, whether the vendor was truly a third party, and whether the data actually constituted the information the statute protects are all merits questions that get resolved at summary judgment or trial, not at the pleading stage.
The capability test applied in ConverseNow and Ambriz v. Google further expands plaintiff-side leverage by making vendor contracts — which defendants typically do not want to produce early — directly relevant to whether liability exists. If the vendor’s terms of service or privacy policy say the vendor can use the data to improve its own AI models, that statement in a public-facing document can itself serve as evidence supporting the third-party eavesdropper theory.
Class Certification Creates Exponential Exposure
Once plaintiffs survive a motion to dismiss and obtain class certification, the arithmetic of statutory damages becomes crushing. A website that serves one million California visitors over three years, each of whom interacted with a chatbot or was captured by session replay software, faces theoretical exposure of $5 billion under CIPA alone. Courts have acknowledged that actual damages at this scale would be disproportionate — but the threat of it drives settlement negotiations. Defense counsel cannot credibly tell a corporate board that a statutory damages class action with certified class members in the millions poses no meaningful risk, because it does.
Settlement amounts in the $3 million to $25 million range have been common in VPPA and CIPA cases where the defendant had meaningful website traffic and a class covering several years. Healthcare companies in particular have faced outsized pressure: Sutter Health settled a pixel-tracking case for $21.5 million in April 2026, and Inova Health settled a similar case for $3.1 million in the same month.
For smaller businesses, the exposure is different in scale but no less real in proportion. Demand letters — the pre-litigation step where plaintiff’s counsel makes a settlement demand before filing — typically cite $5,000 per violation and demand between $15,000 and $40,000 to resolve the claim. These amounts are carefully calibrated: high enough to be meaningful to the plaintiff’s firm, low enough that most businesses calculate it is cheaper to pay than to hire defense counsel and litigate. The Forbes company paid $10 million to end a CIPA class action premised on treating LinkedIn and Microsoft tracking pixels as illegal wiretaps.
Which Deployment Decisions Create the Most Risk
Not all technology choices carry equal litigation exposure. Based on the pattern of cases filed from 2022 through mid-2026, certain categories of deployment consistently generate the highest volume of claims.
AI Chatbots and Voice Assistants
The chatbot is now the highest-risk single deployment decision for businesses serving California customers. The post-ConverseNow legal environment is clear: if you deploy an AI-powered chatbot or voice assistant on your website or phone system, and the vendor has any contractual right to use conversation data to improve its own AI models, you face a plausible CIPA Section 631 claim under the capability test. The risk is not limited to California: Pennsylvania and other two-party consent states have their own wiretapping statutes with similar structure, and the federal Electronic Communications Privacy Act creates parallel exposure.
Session Replay and Behavioral Analytics Tools
Tools like FullStory, Hotjar, and Microsoft Clarity record keystrokes, mouse movements, scroll behavior, and form inputs to help product teams understand how users navigate a site. Under the Javier framework, deploying these tools before the user has provided affirmative prior consent means every captured session is a potential CIPA violation. Courts have not uniformly held these tools unlawful, and the Torres v. Prudential Financial decision in 2025 granted summary judgment for the defendant on the theory that session replay data only becomes readable after storage and reassembly, not during transmission. But the legal question is not settled, and demand letters targeting session replay tools continue to be filed in volume.
Tracking Pixels (Meta Pixel, Google Analytics, LinkedIn Insight Tag)
Any website that hosts video content — even a single embedded YouTube video or a product demo clip — and also runs the Meta Pixel or similar analytics tools faces VPPA exposure. The statute requires only that you are a “video tape service provider” (a term courts have read broadly to include streaming-adjacent services) and that you knowingly disclosed video-viewing information tied to a user’s identity to a third party. The Second Circuit narrowed this theory in 2025 with its holding that pixel-transmitted code strings are not “personally identifiable information” under the ordinary person standard — but that decision does not bind courts in other circuits, and CIPA and state wiretapping theories provide an alternative litigation path in states that do not follow that approach.
Behavioral Targeting and Personalization Engines
Personalization tools that track users across sessions, infer preferences from behavior, and serve targeted content or advertising are increasingly reframed as unauthorized surveillance under the MHMDA when health-adjacent products or services are involved. If your website sells anything from nutrition supplements to fitness equipment to mental wellness apps — even if you are not a healthcare provider — and you use behavioral data to personalize the experience or target advertising, the MHMDA’s definition of consumer health data may reach your data flows.
Facial and Biometric Recognition
Any AI feature that uses face geometry, fingerprints, or voiceprints for authentication, personalization, or analytics runs directly into BIPA if any of your users are Illinois residents. The same risk exists for AI-driven video tools that perform emotion analysis or facial recognition for security or productivity purposes. Given BIPA’s consent and disclosure requirements and the scale of settlements against major technology companies, no startup should deploy biometric AI features without explicit legal review of state law compliance, collected consent, and vendor contract terms.
How a Small Business Should Assess Its Exposure
For most small and medium businesses, the starting point is a realistic inventory of what tracking and AI technologies actually run on your website and in your customer communication systems. This is not as simple as it sounds. Marketing teams, product teams, and IT teams often deploy tools independently, and the person who embedded a vendor pixel eighteen months ago may not still be at the company.
The practical exposure questions are as follows. Does your website serve any California residents? If you operate in the United States and have a public-facing website, the answer is almost certainly yes. Do you run session replay, behavioral analytics, or chatbot tools that communicate data to third-party vendors? If you use tools from companies like FullStory, Hotjar, Intercom, Drift, HubSpot, Salesforce Einstein, or similar platforms, the answer is yes. Do you host video content alongside tracking pixels? If you have a YouTube embed and run Meta Pixel, you have a VPPA surface. Do you sell or provide health-adjacent products or services to Washington state residents? If so, your pixel configuration may generate MHMDA exposure. Does your technology touch biometric data — face images, fingerprints, voice recordings — of people in Illinois? If so, you likely have BIPA obligations you need to audit.
For technology startups specifically, the risk calculus is sharpened by the fact that investor growth mandates push teams toward deploying as many analytics and personalization tools as possible, as quickly as possible, while compliance resources remain lean. A startup that scales to one million California monthly active users while running standard analytics and a vendor chatbot has accumulated significant statutory damages exposure before it processes a single Series B dollar. The plaintiff’s bar is explicitly targeting deployers, not just technology developers — meaning the business that embedded the tool, not just the vendor who built it, faces class action exposure.
Practical Risk Reduction Steps
Addressing this exposure does not require stripping your website of every analytics tool. It requires making deliberate, documented choices and building consent and disclosure frameworks that survive legal scrutiny.
Conduct a Technology Audit
Before you can manage the risk, you need to know what is actually running. Audit every third-party technology deployed on your website and in your customer-facing communication channels. Map each tool to the data it collects, the vendor who receives it, and what the vendor’s terms permit the vendor to do with that data. Pay particular attention to vendor contracts that allow data use for “product improvement,” “model training,” or “service enhancement” — those provisions are the capability test in written form, and they transform the vendor from a service provider into a potential third-party eavesdropper under CIPA doctrine.
Implement Meaningful Prior Consent
The consent requirement is where most businesses currently fail. A cookie banner that fires at page load and records implied consent is not prior consent under Javier. A privacy policy link in the footer is not prior consent. For session replay tools, chatbots, and tracking pixels, you need affirmative, explicit consent obtained before any data capture begins, including for first-time visitors who have not yet had the chance to agree to anything. This typically means a consent management platform that gates tool initialization until consent is recorded, with appropriate session controls and audit logging.
For AI chatbots and voice assistants, you should require the system to announce clearly at the start of every interaction that the conversation is being handled by an AI system and that the conversation may be recorded. This disclosure needs to occur before the customer provides any personal or financial information, not buried in a welcome message that most users skip.
Renegotiate Vendor Contracts
If your vendor’s standard terms allow the vendor to use customer conversation data, behavioral data, or biometric data to train or improve its own AI models, you face an unmitigated capability test risk under current CIPA doctrine. Negotiate data processing agreements that explicitly prohibit the vendor from using your customers’ data for any purpose other than providing the contracted service to you. Require vendors to certify compliance with applicable state privacy laws. Include indemnification provisions covering third-party claims arising from the vendor’s data handling practices.
Build State-Specific Compliance
CIPA applies to California residents; BIPA applies to Illinois residents; MHMDA applies to Washington residents who are consumers of Washington businesses. Texas, Virginia, Colorado, and a growing number of other states have enacted omnibus privacy laws with varying enforcement mechanisms. A compliance framework that assumes one-size-fits-all national consent is adequate will have gaps. For businesses with significant user bases in California, Illinois, or Washington, state-specific legal review of your deployment stack is not optional.
Document Everything
In the litigation context, documented compliance efforts matter. A business that can demonstrate it conducted a formal privacy audit, obtained prior consent through a compliant consent management platform, reviewed vendor contracts for data use restrictions, and trained its engineering team on the consent requirements is in a materially better litigation position than one that installed tools without documentation. Even if the underlying technology creates some legal ambiguity, documented good faith can influence class certification decisions, damages determinations, and settlement negotiations.
Conclusion
The lawsuits being filed against businesses in 2025 and 2026 for deploying AI chatbots, session replay tools, tracking pixels, and behavioral analytics platforms are not a legal fringe phenomenon. They are the predictable product of statutory frameworks that were written without technology in mind, applied by a plaintiffs’ bar that has developed efficient factual templates, in a litigation environment where statutory damages eliminate the need to prove actual harm and class certification multiplies exposure to existential levels.
The business decisions that create this exposure are not exotic. They are the standard operating procedure of any technology-forward company: embed analytics, deploy a chatbot, run retargeting pixels, personalize the user experience. The legal risk was not visible when these tools were installed, because the plaintiff-side theory was not fully developed yet, and because the people who installed the tools were solving marketing and product problems, not mapping legal exposure.
That dynamic has now changed. Every growth-stage company deploying AI-assisted customer interactions, every mid-size retailer running behavioral targeting, every digital health platform using personalization — all are operating within a class action risk environment that requires active legal management. The cost of a privacy audit and consent management infrastructure is modest. The cost of a certified class action is not.
This post is for general informational purposes and does not constitute legal advice or create an attorney-client relationship. Privacy law is rapidly evolving and fact-specific. Consult qualified legal counsel before making compliance decisions for your organization.
