Skip to main content
FlowDesk logoFlowDesk

Are AI Meeting Notetakers a Security Risk?

AI meeting notetakers now carry dated risks, not hypothetical ones: recording-consent lawsuits, privilege waivers, and the Otter.ai class action are already on record, and free tiers can reuse meeting content for training. This risk review maps the incidents, the all-party-consent states, and the affected tools so you can decide which meetings to keep a notetaker in — and which to refuse.

Disclosure: No affiliate links; no undisclosed affiliate relationships.

This page does not identify at least two apps, so it remains available as general guidance but is not included in the comparison directory.

An AI assistant quietly joining a team meeting through an automated calendar access grant

At one organization examined by Nudge Security, roughly 800 AI-notetaker accounts appeared within 90 days. There had been no formal deployment. A user shared notes, colleagues encountered prompts to create their own accounts, and permissive calendar authorization allowed the service to follow those users into later meetings.[1]

That sequence captures the most consequential security risk in AI-assisted note-taking and knowledge work. The first user may be running an experiment, but everyone else experiences an infrastructure decision: a bot enters the call, captures people who never opened an account, sends the conversation to a vendor, and leaves recordings or derived notes for someone to govern later. The security problem begins before anyone asks whether the transcript is accurate.

The practical question is therefore not whether AI meeting notetakers are universally safe. It is whether a particular tool, account tier, configuration, and meeting type can satisfy five conditions: lawful and meaningful consent, appropriate handling of confidential material, protection of any privilege, controlled retention and training use, and an identified person who can remove the tool and its data.

Route the meeting before comparing the tools

A compact routing decision is more useful than a generic feature ranking. Federal law provides a one-party-consent baseline under the Wiretap Act, while state law can impose a stricter rule. A June 2026 legal review identified 12 all-party-consent states, and meetings crossing state or national boundaries can require additional analysis.[2] The table below is an operational screen, not a substitute for jurisdiction-specific legal advice.

Meeting typeSensitivityConsent reviewPrivilege concernTraining and retention conditionsDefault posture
Routine internal coordinationLow, with no personnel, legal, customer, or restricted material expectedVerify the applicable rule; disclose the notetaker and provide a workable objection pathLow if no legal advice or protected investigation is involvedTraining disabled; short retention; named deletion ownerKeep
Customer, partner, or vendor discussionCommercially confidential and potentially contract-restrictedAffirmative review before the meeting; do not rely only on the bot appearing in the participant listUsually fact-dependentConfirm the exact account tier, training use, retention period, export rights, and deletion processRestrict
Hiring, performance, compensation, or personnel matterHigh and personally sensitiveObtain affirmative approval under the applicable policy and lawPossible if counsel or an investigation is involvedNo uncontrolled training or indefinite retention; restrict access to authorized reviewersRestrict or refuse
Legal advice, litigation, or internal investigationHighConsent alone does not resolve confidentiality or privilegeMaterial and case-specificNo external processing unless counsel approves the system, terms, access, and retentionRefuse by default
Mixed external attendance or uncertain jurisdictionUnknownApplicable rule cannot be established before capture beginsUnknownTerms, destination, or deletion authority cannot be confirmedRefuse

“Keep” does not mean unrestricted approval for every meeting on a user’s calendar. It means the organization can enforce the listed conditions. “Restrict” means the bot stays out unless someone performs the required review. “Refuse” is appropriate when the unanswered question cannot be repaired after recording—for example, when consent is unresolved or privileged strategy may already have been disclosed.

How a useful experiment becomes shadow infrastructure

Diagram showing an AI-notetaker signup spreading through shared invitations, calendar access, automatic meeting entry, and cloud storage

The 800-account case matters because it exposes an adoption mechanism rather than merely reporting that employees like AI. Each step removes a little friction for the next user while transferring more responsibility to an organization that may not realize a system has been deployed.

  1. One employee creates a freemium account to obtain a transcript or summary.
  2. The resulting notes or invitation expose colleagues to sharing links and signup prompts.
  3. A colleague authorizes calendar access, often because automatic scheduling and joining are presented as convenience features.
  4. The service begins appearing in later calls, including meetings whose participants did not select the tool or create vendor accounts.
  5. Audio, transcripts, summaries, action items, and account metadata accumulate under individual user settings.
  6. Other employees treat the visible bot as evidence that the organization has approved it, accelerating further adoption.
  7. When legal, security, or operations staff eventually investigate, they must locate accounts, revoke OAuth grants, remove auto-join rules, identify stored content, and determine who can request deletion.

No single step looks like a dramatic breach. That is why the mechanism is effective. Sharing appears collaborative, calendar access appears administrative, and a bot in a participant list appears transparent. Taken together, those choices create a recording and knowledge repository outside the normal procurement, retention, and offboarding process.

Scale claims should not be mistaken for evidence that those controls exist. Fireflies has reported 20 million users, 500,000 organizations, and adoption across 75% of the Fortune 500.[1] Those are vendor-reported adoption figures, not independent findings about effectiveness, consent compliance, or the governance of each customer deployment.

Otter, Fireflies, Granola, Fathom, Read, Zoom AI Companion, Supernormal, and similar products also should not be treated as if they have interchangeable policies. The relevant unit of comparison is the current product, account tier, configuration, and meeting—not the broad label “AI notetaker.” A feature included in an organization’s existing conferencing plan may present a different administrative path from a third-party bot, but inclusion alone does not answer the consent, privilege, retention, or training questions.

The exposure is already documented

In Brewer v. Otter.ai, plaintiffs alleged that an Otter bot joined and recorded conversations without obtaining consent from every participant and that recordings were used for model training. The allegations included claims under the Electronic Communications Privacy Act, Computer Fraud and Abuse Act, and California Invasion of Privacy Act. Dark Reading reported those allegations in October 2025; they are allegations, not a finding that Otter is liable.[3]

A parallel matter, In re Otter.AI Privacy Litigation, was filed in the Northern District of California on August 15, 2025.[2] Its existence should change the risk conversation without being converted into a verdict. The operational lesson is narrower: allowing one account holder to invite a bot does not necessarily establish that every captured participant agreed to the recording, vendor processing, or any later model use.

A bot’s visible presence may help provide notice, but notice, legal consent, contractual permission, and internal approval are separate questions. A host also cannot solve them merely by stating that “the AI is taking notes” after the system has begun capturing audio. The meeting policy must specify when capture starts, how objections are handled, and whether the meeting proceeds without the notetaker if someone declines.

The federal one-party baseline is often repeated as though it settles every recording decision. It does not displace stricter state requirements, nor does it resolve which jurisdiction governs a call with participants in different places. As identified in the June 2026 Mayer Brown review, the 12 all-party-consent states are:[2]

  • California
  • Connecticut
  • Florida
  • Illinois
  • Maryland
  • Massachusetts
  • Michigan
  • Montana
  • Nevada
  • New Hampshire
  • Pennsylvania
  • Washington

This is a routing reference, not a claim that every statute operates identically or that every meeting involving one of these states is automatically unlawful. State-specific exceptions, the locations of the participants, the nature of the communication, and changes after June 2026 can affect the analysis. For a broader map of consent, privilege, and biometric exposure, see How AI Regulation Is Reshaping Note-Taking App Choices.

Privilege depends on the system and the circumstances

Two 2026 rulings make categorical assurances especially unhelpful. In United States v. Heppner, decided in the Southern District of New York on February 17, 2026, the court held that the consumer-AI outputs at issue were not privileged. In UKUT 81 [2026], the U.K. Upper Tribunal addressed a distinction between open and closed AI systems.[2]

Neither ruling establishes that every AI-generated note automatically destroys privilege. They do establish that a team should not assume ordinary privilege protections extend unchanged to material disclosed to, generated by, or retained in an AI service. The architecture, access boundaries, purpose of the communication, and facts of the matter can affect the result.

For meetings involving legal advice, litigation strategy, or an internal investigation, the useful control is prior approval by counsel—not a generic banner saying that the vendor uses encryption. Encryption does not decide whether sharing with the service was consistent with maintaining confidentiality, and participant consent does not answer the privilege question.

Training terms and shutdowns leave different kinds of residue

A Fordham privacy analysis highlighted two connected concerns: free-tier meeting content may be used for training, and vendor indemnification provisions can shift responsibility for obtaining participant consent back to the customer.[4] Policies vary by vendor and tier and can change, so this is a reason to inspect current terms rather than assume that every free service follows the same practice.

The combination deserves close attention. A low-friction account encourages adoption precisely where no procurement reviewer is checking whether training can be disabled. The user receives a useful summary; the organization inherits responsibility for permission; and people who never opened accounts may still have their voices and information processed under that arrangement.

Continuity creates a separate exposure. Dark Reading cited the shutdown of AI meeting-notetaker vendor Novacy in its October 2025 risk review.[3] A shutdown does not by itself prove that customer data was lost or mishandled. It does demonstrate why a meeting archive should not depend on an untested assumption that the vendor, export path, account administrator, and deletion interface will remain available indefinitely.

Before admitting a notetaker, the owner should know where the authoritative record will live, how approved notes are exported, what happens to source audio after export, and how content can be removed if the service closes or the employee who created the account leaves. If nobody can answer those questions, automatic joining should be disabled while the answers are found.

Apply the decision at meeting level

Three meeting rooms representing approved, restricted, and refused access for an AI notetaker

A company-wide yes or no is tempting because it is easy to communicate. It is also poorly matched to calendars that move from a routine stand-up to a performance conversation and then to a call with outside counsel. The decision needs to travel with the meeting’s contents and participants.

  1. Determine whether the service receives audio, video, chat, screen content, participant metadata, a transcript, or only user-created notes. Do not infer this from the word “assistant.”
  2. Establish which consent rules may apply before recording starts, especially for cross-state or international calls. Route uncertainty to an authorized reviewer.
  3. Look for personnel information, customer restrictions, trade secrets, legal advice, investigations, regulated data, and other material that should not enter an ordinary meeting archive.
  4. Verify training use, human review, sharing defaults, retention, subprocessors where relevant, administrative visibility, export, and deletion. A paid enterprise policy should not be assumed to govern an employee’s separate free account.
  5. Name the person or role authorized to approve auto-join, answer participant objections, change retention, export approved records, revoke access, and request deletion.
  6. Keep the notetaker, admit it only after review, or refuse it. Removing the bot after sensitive information has been recorded is incident handling, not preventive control.

This test also prevents misleading product comparisons. A tool can be acceptable for a low-sensitivity internal sync and unacceptable for the legal call immediately afterward without having changed any technical feature. Conversely, a locally controlled or tightly administered system may reduce some vendor and retention exposure without resolving recording consent. Readers considering that architectural tradeoff can compare local-first note-taking alternatives.

Model accuracy, prompt injection, and broader application security still matter, but they answer different questions. The EchoLeak-era review of AI note-taking apps discusses adjacent agent exposure, including Granola, while the AI note-app security profile covers application-level security context. Neither replaces a meeting admission rule.

Turn keep, restrict, and refuse into enforceable defaults

Keep

Permit an approved notetaker in defined, low-sensitivity meeting types when participants receive appropriate notice, the applicable consent requirement has been addressed, training use is acceptable or disabled, retention is set, and an administrator can delete the source and derived records. Calendar access should be limited to the approved scope rather than treated as permission to join every event.

Restrict

Require affirmative review for external, customer, personnel, commercially confidential, or otherwise sensitive meetings. Disable global auto-join, require the host to admit the bot deliberately, and document who approved the use. If a participant objects, the policy should state whether the bot leaves, an alternative note-taking method is used, or the meeting is rescheduled.

Refuse or remove

Default to refusal when the consent rule is unresolved, counsel has not approved use in a potentially privileged matter, training cannot be controlled, retention and deletion are unknown, or no one owns the account. For an existing deployment, removal means more than deleting the visible bot: revoke calendar OAuth, disable auto-join, inventory personal and shared accounts, preserve any records that must legally or operationally be retained, export approved material, request deletion where appropriate, and verify that former users no longer control organizational meeting archives.

A reusable implementation template is available in How to Set a Personal AI Policy Across Every Note App. The important move is to make the rule visible before the next shared transcript creates another account and before another calendar grant turns a trial into the default. Vendor claims about AI quality cannot compensate for an unmanaged authorization or a meeting policy nobody can enforce.

References

  1. Shadow AI is taking notes — Nudge Security, January 2026
  2. AI Notetakers: Productivity Tool or Emerging Legal Risk? — Mayer Brown, June 2026
  3. Take Note: Cyber-Risks With AI Notetakers — Dark Reading, October 2025
  4. Balancing Efficiency with Privacy and Risk: Examining the Use of AI Note-Taking Tools — Fordham Intellectual Property, Media & Entertainment Law Journal

Ready to move?

App profiles

No linked app profile yet.

Matching migration guides

No tested migration path for this pair yet.

Spot outdated pricing or a feature that has changed?