> daily_signal(2026_08_18)

An AI bot records your meetings without asking, Amazon is slicing books apart for AI training, a free tool names where your vacation photo was taken, and a new tool can flag text Claude wrote.

PickBits Daily Signal · Tuesday, August 18, 2026

By Mark Pickering · 8 min read · August 18, 2026

// tl;dr

I kept having the same reaction to all four of these today: nobody asked. A judge let a wiretap suit proceed over an AI notetaker that had been recording whole meetings. A trillion-dollar company bought rare books, cut the bindings off, and fed the pages to a model, with the only trail a tracker a reporter hid in the box. A free AI read a photo you posted and handed your location to a scammer. Then Anthropic went the other way and opened a tool to flag its own model's output, so a teacher or an editor can finally tell what Claude wrote. None of this is new to us; we clocked the notetaker showing up in every meeting nine days ago, and covered Anthropic's $1.5 billion author settlement last month. It just felt strange to get all four on the same day.

This week a judge let an AI-notetaker wiretap suit proceed, a hidden tracker caught Amazon shredding rare books to train on them, a free model located a vacation photo with its GPS tag stripped, and Anthropic opened a public tool to detect the text Claude writes.

1. A federal judge refused to toss the privacy suit over the AI notetaker your team keeps inviting into meetings.

The bot that quietly records your calls is now a wiretap case, and it is the company that let it in that carries the legal risk.

If your team runs Otter, Fireflies, Fathom, or any of the AI notetakers, a federal judge just made the bot in your calls your problem, not only the vendor's. In In re Otter.AI Privacy Litigation, U.S. District Judge Eumi K. Lee in the Northern District of California refused to dismiss the core claims, in a ruling released August 13, 2026. Wiretapping and privacy claims under the federal Electronic Communications Privacy Act, California's Invasion of Privacy Act, and Illinois' Biometric Information Privacy Act all get to proceed; the computer-fraud and several narrower claims were dismissed with leave to amend. The plaintiffs allege Otter's Notetaker bot automatically joins scheduled video meetings, records and transcribes the audio on Otter's own servers, and uses those conversations to train its systems and build speaker voiceprints, without the consent of everyone in the room.

This is the first federal test of whether decades-old wiretap statutes even reach an AI bot sitting in on a video call, and the judge pushed the legal exposure onto the employer whose staff invited the bot in. When the ruling dropped, the sharpest read on the developer boards was blunt: whoever installs the recording software owns what it records, so the argument that a free user is not a customer misses the point entirely, because most states still require consent from everyone on the call. The bot did not ask. Someone on your team pressed accept.

Screenshot of Courthouse News's report that a judge let the Otter.ai notetaker privacy suit proceed.
courthousenews.com · August 17, 2026
Why this matters: We wrote about AI notetakers getting invited to every meeting on August 9, and this is the same story with a courtroom attached. The part that should worry a manager is where the liability landed: on the company whose staff clicked accept. A tool your people picked up on their own is now something you can be sued over. Action this week: Audit which notetakers can auto-join your meetings, and turn on all-party consent and recording-disclosure prompts before your next call. Get each vendor's data-retention and model-training terms in writing, especially if anyone on the call sits in a two-party-consent state like California or Illinois, because a vendor saying it "found no evidence of misuse" is still free to train on those recordings later, so make the no-training promise a written line in the contract. Send this to whoever owns your software inventory; right now they are carrying a risk nobody signed off on.

courthousenews.com: Otter.ai faces privacy class action as judge lets wiretap and biometric claims proceed (August 17, 2026)
CourtListener: docket for In re Otter.AI Privacy Litigation (No. 5:25-cv-06911, N.D. Cal.)

2. A tracker hidden in a box of rare books led to an Amazon warehouse that shreds them to feed AI training.

Amazon buys rare books in bulk, cuts the bindings off to scan the pages faster, and the physical original does not survive the process.

Nobody got a say in whether a used book, once sold, could have its binding sliced off and its pages scanned into an AI, but a tracker hidden inside a shipment of rare books just showed Amazon is doing exactly that. 404 Media journalist Emanuel Maiberg embedded a tracking device in the shipment to learn which company was buying it, and followed it to an Amazon facility coded VGT3 in Las Vegas, where employees cut the bindings off printed books so they can be scanned faster, destroying the book in the process, as Amazon buys books in bulk to scan for AI training data. The company would only say it purchases books through commercial channels to improve products and services used by customers. It will not say which models receive the scans, which products use them, or how the books are chosen.

Rare and out-of-print books are valuable precisely because much of their text never made it online, and older writing is less likely to be contaminated with AI-generated text, which degrades a model when it trains on its own output. That is why physical books are worth grabbing in bulk. It also means a scarce copy, once pulled out of circulation and sliced apart, never comes back. The team running the operation, 404 Media reported, identifies itself with a logo of a dinosaur baring its teeth while holding a book, which is a strange amount of self-awareness for a process that ends with the book destroyed.

Screenshot of 404 Media's investigation tracking rare books to an Amazon AI-training facility.
404media.co · August 17, 2026
Why this matters: This has mostly been a courtroom story until now, all settlements and motions and briefs. Maiberg's tracker made it one warehouse, one facility code, and a pile of books with the bindings cut off. This is not new ground for us; we watched Anthropic pay $1.5 billion last month to settle with authors over exactly this kind of scanning, and the courts are still sorting out how far a bought copy lets a company go. Nobody has settled whether buying a used book lets you shred it and train on it, and shredding the original only makes that argument harder for Amazon to win. Action this week: Read your rights-reversion and resale clauses if you write or license written work, and check whether bulk resale and machine scanning are addressed at all, because most contracts written before this was a business are silent. If you run a library, an archive, or an estate that deaccessions books, weigh where sold-off volumes actually go before you offload anything rare. Follow this one; the courts have not settled whether buying a used book lets you shred it and train on it, and how that question lands will tell writers a lot about what their back catalog is worth.

404media.co: We tracked a shipment of rare books, and it ended at an Amazon AI-training facility (August 17, 2026)

3. A free AI named where a vacation photo was taken 9 times out of 10, and scammers are already using it.

That beach photo you posted, with the location tag stripped, still tells a free AI almost exactly where you were standing.

Scrub the GPS tag off a holiday photo and you would assume you are anonymous. You are not. McAfee researchers tested freely available AI vision models on more than 20,000 photos, and two of them geolocated images with 87% and 91% accuracy, roughly 9 out of 10, by reading architecture, signage, and the quality of the light rather than any embedded metadata. When they missed the exact city, they were almost always right at the country level. No famous landmark required; ordinary streets, storefront signage, and the slant of the light were enough.

The scam sits right on top of that. A scammer feeds your public holiday photo to one of these models, gets your location, and sends you a convincing location-aware message, a fake bank alert reading "we detected unusual activity while you were traveling in" wherever you actually are, with a link that harvests your login. Stripping GPS metadata off a photo used to be enough to keep your whereabouts private; the picture itself now gives you away, and the model doing it costs nothing to use.

Screenshot of PetaPixel's report on AI geolocating holiday photos for scams.
petapixel.com · August 17, 2026
Why this matters: For years, clearing a photo's location tag was the one privacy step that reliably worked. This McAfee test is where that stops being true. I used to tell people scrubbing the metadata was the whole job, and I do not say that anymore, because the model is reading the background, not the file. And what makes it dangerous is the timing: a scam text landing mid-trip, naming the city you are standing in, reads like your bank instead of a con. Action this week: Post your trip photos after you are home, not during, and keep them to people you trust while you are away. Treat any message that seems to know where you are as a warning sign rather than a comfort, and if your bank texts you about a problem, call the number on the back of your card instead of tapping the link. Share this with anyone you know who posts from the road; the photo itself is now the tell.

petapixel.com: Scammers are using AI to pinpoint where your holiday photos are taken (August 17, 2026)

4. Anthropic is watermarking every word Claude writes, and opened a tool that lets anyone check.

An invisible mark now rides inside Claude's text, and for once a teacher or editor has an actual tool to read it, with honest limits attached.

A teacher or an editor staring at a suspicious paragraph now has a real tool to ask whether a machine wrote part of it. Anthropic is applying Google DeepMind's SynthID-Text watermarking to Claude's output: every Claude model released after August 2, 2025 watermarks its text automatically, with older models to follow in the coming months, and the company opened a watermark-detection API so third parties, from schools to publishers to newsrooms and platforms, can check whether a passage was generated by Claude. SynthID works by nudging the randomness the model uses to pick each word, leaving a traceable statistical pattern with, in Anthropic's words, no effect on the content, creativity, or readability of the text. It is launching worldwide, pushed along by the EU AI Act's transparency rules.

The limits are real, and Anthropic lists them itself. The watermark is weak on short passages, on code, and on fact-heavy text. It cannot tell whether Claude wrote a paragraph or merely cleaned up yours. And it cannot identify text from any other AI model. So a positive result is a clue and nothing more, and anyone who treats it as proof is going to get a real person wrong.

Screenshot of The Decoder's report on Anthropic's Claude text watermark and detection API.
the-decoder.com · August 14, 2026
Why this matters: The watermark itself is the less interesting half. Anthropic is one lab, so it only ever marks a slice of what a school or newsroom actually sees. The detection tool is the part I would actually use, because a check that works only on Claude, and only sometimes, will not settle whether a human wrote something, but it is still the first one a school or newsroom can run on its own instead of paying for one of those detector tools that is really just guessing. This is close to what we said Meta should have done a few weeks back, when it built an in-house AI detector instead of backing a shared standard; Anthropic went the shared way. Action this week: Treat any detection result as a starting point if you run a classroom, newsroom, or publishing workflow, something to ask a student about rather than punish them over, and back it with a real conversation and a written disclosure policy instead of a single score, because the watermark misses short, code, and AI-edited text. Ask the AI vendors in your stack whether they will adopt the same watermark and publish a detection endpoint, because a check like this only works when it is not just one company doing it.

the-decoder.com: Anthropic announces a watermark-detection API that lets third parties detect Claude's AI text (August 14, 2026)
theverge.com: Anthropic explains how Claude's invisible text watermark works

» What to watch this week

Tomorrow's signal lands here.