> daily_signal(2026_08_18)
An AI bot records your meetings without asking, Amazon is slicing books apart for AI training, a free tool names where your vacation photo was taken, and a new tool can flag text Claude wrote.
PickBits Daily Signal · Tuesday, August 18, 2026
// tl;dr
- A federal judge refused to throw out the privacy suit over Otter.ai's meeting bot. In In re Otter.AI Privacy Litigation, Judge Eumi K. Lee let wiretap claims under the federal ECPA, California's CIPA, and Illinois' BIPA proceed against the Notetaker bot, which auto-joins meetings, records and transcribes on Otter's servers, and allegedly builds voiceprints without all-party consent. It is the first federal test of whether wiretap law reaches an AI in a video call, and it puts the employer on the hook, not just the vendor.
- A reporter hid a tracker in a shipment of rare books and followed it to an Amazon warehouse that destroys them for AI training. 404 Media's Emanuel Maiberg traced the shipment to an Amazon facility in Las Vegas, where workers cut the bindings off printed books to scan the pages faster, destroying the physical copy. Amazon would only say it buys books through commercial channels to improve its products.
- A free AI named where a vacation photo was taken about 9 times out of 10 in a McAfee test, and scammers are using it. Two free vision models geolocated images with 87% and 91% accuracy across more than 20,000 photos, reading architecture and signage rather than metadata. Scammers feed a target's public holiday photo to a model, get the location, and send a location-aware phishing text posing as the bank.
- Anthropic opened a public detection API for the invisible watermark Claude's text has carried since last August, so anyone can check. Using Google DeepMind's SynthID-Text, every Claude model released after August 2, 2025 watermarks its output automatically; the news this week is the public API that lets schools, newsrooms, and platforms check whether a passage came from Claude. It is weak on short, code, and fact-heavy text, and cannot flag other models.
I kept having the same reaction to all four of these today: nobody asked. A judge let a wiretap suit proceed over an AI notetaker that had been recording whole meetings. A trillion-dollar company bought rare books, cut the bindings off, and fed the pages to a model, with the only trail a tracker a reporter hid in the box. A free AI read a photo you posted and handed your location to a scammer. Then Anthropic went the other way and opened a tool to flag its own model's output, so a teacher or an editor can finally tell what Claude wrote. None of this is new to us; we clocked the notetaker showing up in every meeting nine days ago, and covered Anthropic's $1.5 billion author settlement last month. It just felt strange to get all four on the same day.
This week a judge let an AI-notetaker wiretap suit proceed, a hidden tracker caught Amazon shredding rare books to train on them, a free model located a vacation photo with its GPS tag stripped, and Anthropic opened a public tool to detect the text Claude writes.
1. A federal judge refused to toss the privacy suit over the AI notetaker your team keeps inviting into meetings.
The bot that quietly records your calls is now a wiretap case, and it is the company that let it in that carries the legal risk.
If your team runs Otter, Fireflies, Fathom, or any of the AI notetakers, a federal judge just made the bot in your calls your problem, not only the vendor's. In In re Otter.AI Privacy Litigation, U.S. District Judge Eumi K. Lee in the Northern District of California refused to dismiss the core claims, in a ruling released August 13, 2026. Wiretapping and privacy claims under the federal Electronic Communications Privacy Act, California's Invasion of Privacy Act, and Illinois' Biometric Information Privacy Act all get to proceed; the computer-fraud and several narrower claims were dismissed with leave to amend. The plaintiffs allege Otter's Notetaker bot automatically joins scheduled video meetings, records and transcribes the audio on Otter's own servers, and uses those conversations to train its systems and build speaker voiceprints, without the consent of everyone in the room.
This is the first federal test of whether decades-old wiretap statutes even reach an AI bot sitting in on a video call, and the judge pushed the legal exposure onto the employer whose staff invited the bot in. When the ruling dropped, the sharpest read on the developer boards was blunt: whoever installs the recording software owns what it records, so the argument that a free user is not a customer misses the point entirely, because most states still require consent from everyone on the call. The bot did not ask. Someone on your team pressed accept.
courthousenews.com: Otter.ai faces privacy class action as judge lets wiretap and biometric claims proceed (August 17, 2026)
CourtListener: docket for In re Otter.AI Privacy Litigation (No. 5:25-cv-06911, N.D. Cal.)
2. A tracker hidden in a box of rare books led to an Amazon warehouse that shreds them to feed AI training.
Amazon buys rare books in bulk, cuts the bindings off to scan the pages faster, and the physical original does not survive the process.
Nobody got a say in whether a used book, once sold, could have its binding sliced off and its pages scanned into an AI, but a tracker hidden inside a shipment of rare books just showed Amazon is doing exactly that. 404 Media journalist Emanuel Maiberg embedded a tracking device in the shipment to learn which company was buying it, and followed it to an Amazon facility coded VGT3 in Las Vegas, where employees cut the bindings off printed books so they can be scanned faster, destroying the book in the process, as Amazon buys books in bulk to scan for AI training data. The company would only say it purchases books through commercial channels to improve products and services used by customers. It will not say which models receive the scans, which products use them, or how the books are chosen.
Rare and out-of-print books are valuable precisely because much of their text never made it online, and older writing is less likely to be contaminated with AI-generated text, which degrades a model when it trains on its own output. That is why physical books are worth grabbing in bulk. It also means a scarce copy, once pulled out of circulation and sliced apart, never comes back. The team running the operation, 404 Media reported, identifies itself with a logo of a dinosaur baring its teeth while holding a book, which is a strange amount of self-awareness for a process that ends with the book destroyed.
3. A free AI named where a vacation photo was taken 9 times out of 10, and scammers are already using it.
That beach photo you posted, with the location tag stripped, still tells a free AI almost exactly where you were standing.
Scrub the GPS tag off a holiday photo and you would assume you are anonymous. You are not. McAfee researchers tested freely available AI vision models on more than 20,000 photos, and two of them geolocated images with 87% and 91% accuracy, roughly 9 out of 10, by reading architecture, signage, and the quality of the light rather than any embedded metadata. When they missed the exact city, they were almost always right at the country level. No famous landmark required; ordinary streets, storefront signage, and the slant of the light were enough.
The scam sits right on top of that. A scammer feeds your public holiday photo to one of these models, gets your location, and sends you a convincing location-aware message, a fake bank alert reading "we detected unusual activity while you were traveling in" wherever you actually are, with a link that harvests your login. Stripping GPS metadata off a photo used to be enough to keep your whereabouts private; the picture itself now gives you away, and the model doing it costs nothing to use.
4. Anthropic is watermarking every word Claude writes, and opened a tool that lets anyone check.
An invisible mark now rides inside Claude's text, and for once a teacher or editor has an actual tool to read it, with honest limits attached.
A teacher or an editor staring at a suspicious paragraph now has a real tool to ask whether a machine wrote part of it. Anthropic is applying Google DeepMind's SynthID-Text watermarking to Claude's output: every Claude model released after August 2, 2025 watermarks its text automatically, with older models to follow in the coming months, and the company opened a watermark-detection API so third parties, from schools to publishers to newsrooms and platforms, can check whether a passage was generated by Claude. SynthID works by nudging the randomness the model uses to pick each word, leaving a traceable statistical pattern with, in Anthropic's words, no effect on the content, creativity, or readability of the text. It is launching worldwide, pushed along by the EU AI Act's transparency rules.
The limits are real, and Anthropic lists them itself. The watermark is weak on short passages, on code, and on fact-heavy text. It cannot tell whether Claude wrote a paragraph or merely cleaned up yours. And it cannot identify text from any other AI model. So a positive result is a clue and nothing more, and anyone who treats it as proof is going to get a real person wrong.
the-decoder.com: Anthropic announces a watermark-detection API that lets third parties detect Claude's AI text (August 14, 2026)
theverge.com: Anthropic explains how Claude's invisible text watermark works
» What to watch this week
- Whether the other AI notetakers get named in copycat suits now that Otter's survived dismissal. Fireflies, Fathom, Zoom's AI Companion, and Copilot are all AI meeting assistants in the same space, and the ruling just handed plaintiffs a template. Watch whether any of them quietly ship all-party-consent prompts by default.
- Whether anyone names which models the scanned books feed. Amazon would not say. The copyright cases still forming, including EVOX v. Midjourney and Anthropic's own book litigation, are where "we bought the copy" meets "we destroyed it to train," and that question has not been squarely answered yet.
- Whether "post it after you're home" becomes standard travel advice. The McAfee result means a public vacation photo is now enough to hand a scammer your location, and they are already using it that way. Watch whether platforms add any friction to public, geo-legible posts, or leave it entirely on the user.
- Whether any other lab follows Anthropic on text watermarking plus a public detection API. This is the real tell. A check that only reads one company's writing does not help a teacher much on its own; it only starts to matter if OpenAI or Google turn on the same for their models. I would not bet on that happening fast.
Tomorrow's signal lands here.