
At one organization examined by Nudge Security, roughly 800 AI-notetaker accounts appeared within 90 days. There had been no formal deployment. A user shared notes, colleagues encountered prompts to create their own accounts, and permissive calendar authorization allowed the service to follow those users into later meetings.[1]
That sequence captures the most consequential security risk in AI-assisted note-taking and knowledge work. The first user may be running an experiment, but everyone else experiences an infrastructure decision: a bot enters the call, captures people who never opened an account, sends the conversation to a vendor, and leaves recordings or derived notes for someone to govern later. The security problem begins before anyone asks whether the transcript is accurate.
The practical question is therefore not whether AI meeting notetakers are universally safe. It is whether a particular tool, account tier, configuration, and meeting type can satisfy five conditions: lawful and meaningful consent, appropriate handling of confidential material, protection of any privilege, controlled retention and training use, and an identified person who can remove the tool and its data.
Route the meeting before comparing the tools
A compact routing decision is more useful than a generic feature ranking. Federal law provides a one-party-consent baseline under the Wiretap Act, while state law can impose a stricter rule. A June 2026 legal review identified 12 all-party-consent states, and meetings crossing state or national boundaries can require additional analysis.[2] The table below is an operational screen, not a substitute for jurisdiction-specific legal advice.
| Meeting type | Sensitivity | Consent review | Privilege concern | Training and retention conditions | Default posture |
|---|---|---|---|---|---|
| Routine internal coordination | Low, with no personnel, legal, customer, or restricted material expected | Verify the applicable rule; disclose the notetaker and provide a workable objection path | Low if no legal advice or protected investigation is involved | Training disabled; short retention; named deletion owner | Keep |
| Customer, partner, or vendor discussion | Commercially confidential and potentially contract-restricted | Affirmative review before the meeting; do not rely only on the bot appearing in the participant list | Usually fact-dependent | Confirm the exact account tier, training use, retention period, export rights, and deletion process | Restrict |
| Hiring, performance, compensation, or personnel matter | High and personally sensitive | Obtain affirmative approval under the applicable policy and law | Possible if counsel or an investigation is involved | No uncontrolled training or indefinite retention; restrict access to authorized reviewers | Restrict or refuse |
| Legal advice, litigation, or internal investigation | High | Consent alone does not resolve confidentiality or privilege | Material and case-specific | No external processing unless counsel approves the system, terms, access, and retention | Refuse by default |
| Mixed external attendance or uncertain jurisdiction | Unknown | Applicable rule cannot be established before capture begins | Unknown | Terms, destination, or deletion authority cannot be confirmed | Refuse |
“Keep” does not mean unrestricted approval for every meeting on a user’s calendar. It means the organization can enforce the listed conditions. “Restrict” means the bot stays out unless someone performs the required review. “Refuse” is appropriate when the unanswered question cannot be repaired after recording—for example, when consent is unresolved or privileged strategy may already have been disclosed.
How a useful experiment becomes shadow infrastructure

The 800-account case matters because it exposes an adoption mechanism rather than merely reporting that employees like AI. Each step removes a little friction for the next user while transferring more responsibility to an organization that may not realize a system has been deployed.
- One employee creates a freemium account to obtain a transcript or summary.
- The resulting notes or invitation expose colleagues to sharing links and signup prompts.
- A colleague authorizes calendar access, often because automatic scheduling and joining are presented as convenience features.
- The service begins appearing in later calls, including meetings whose participants did not select the tool or create vendor accounts.
- Audio, transcripts, summaries, action items, and account metadata accumulate under individual user settings.
- Other employees treat the visible bot as evidence that the organization has approved it, accelerating further adoption.
- When legal, security, or operations staff eventually investigate, they must locate accounts, revoke OAuth grants, remove auto-join rules, identify stored content, and determine who can request deletion.
No single step looks like a dramatic breach. That is why the mechanism is effective. Sharing appears collaborative, calendar access appears administrative, and a bot in a participant list appears transparent. Taken together, those choices create a recording and knowledge repository outside the normal procurement, retention, and offboarding process.
Scale claims should not be mistaken for evidence that those controls exist. Fireflies has reported 20 million users, 500,000 organizations, and adoption across 75% of the Fortune 500.[1] Those are vendor-reported adoption figures, not independent findings about effectiveness, consent compliance, or the governance of each customer deployment.
Otter, Fireflies, Granola, Fathom, Read, Zoom AI Companion, Supernormal, and similar products also should not be treated as if they have interchangeable policies. The relevant unit of comparison is the current product, account tier, configuration, and meeting—not the broad label “AI notetaker.” A feature included in an organization’s existing conferencing plan may present a different administrative path from a third-party bot, but inclusion alone does not answer the consent, privilege, retention, or training questions.
The exposure is already documented
Consent allegations against Otter
In Brewer v. Otter.ai, plaintiffs alleged that an Otter bot joined and recorded conversations without obtaining consent from every participant and that recordings were used for model training. The allegations included claims under the Electronic Communications Privacy Act, Computer Fraud and Abuse Act, and California Invasion of Privacy Act. Dark Reading reported those allegations in October 2025; they are allegations, not a finding that Otter is liable.[3]
A parallel matter, In re Otter.AI Privacy Litigation, was filed in the Northern District of California on August 15, 2025.[2] Its existence should change the risk conversation without being converted into a verdict. The operational lesson is narrower: allowing one account holder to invite a bot does not necessarily establish that every captured participant agreed to the recording, vendor processing, or any later model use.
A bot’s visible presence may help provide notice, but notice, legal consent, contractual permission, and internal approval are separate questions. A host also cannot solve them merely by stating that “the AI is taking notes” after the system has begun capturing audio. The meeting policy must specify when capture starts, how objections are handled, and whether the meeting proceeds without the notetaker if someone declines.
The U.S. consent map is not one rule
The federal one-party baseline is often repeated as though it settles every recording decision. It does not displace stricter state requirements, nor does it resolve which jurisdiction governs a call with participants in different places. As identified in the June 2026 Mayer Brown review, the 12 all-party-consent states are:[2]
- California
- Connecticut
- Florida
- Illinois
- Maryland
- Massachusetts
- Michigan
- Montana
- Nevada
- New Hampshire
- Pennsylvania
- Washington
This is a routing reference, not a claim that every statute operates identically or that every meeting involving one of these states is automatically unlawful. State-specific exceptions, the locations of the participants, the nature of the communication, and changes after June 2026 can affect the analysis. For a broader map of consent, privilege, and biometric exposure, see How AI Regulation Is Reshaping Note-Taking App Choices.
Privilege depends on the system and the circumstances
Two 2026 rulings make categorical assurances especially unhelpful. In United States v. Heppner, decided in the Southern District of New York on February 17, 2026, the court held that the consumer-AI outputs at issue were not privileged. In UKUT 81 [2026], the U.K. Upper Tribunal addressed a distinction between open and closed AI systems.[2]
Neither ruling establishes that every AI-generated note automatically destroys privilege. They do establish that a team should not assume ordinary privilege protections extend unchanged to material disclosed to, generated by, or retained in an AI service. The architecture, access boundaries, purpose of the communication, and facts of the matter can affect the result.
For meetings involving legal advice, litigation strategy, or an internal investigation, the useful control is prior approval by counsel—not a generic banner saying that the vendor uses encryption. Encryption does not decide whether sharing with the service was consistent with maintaining confidentiality, and participant consent does not answer the privilege question.
Training terms and shutdowns leave different kinds of residue
A Fordham privacy analysis highlighted two connected concerns: free-tier meeting content may be used for training, and vendor indemnification provisions can shift responsibility for obtaining participant consent back to the customer.[4] Policies vary by vendor and tier and can change, so this is a reason to inspect current terms rather than assume that every free service follows the same practice.
The combination deserves close attention. A low-friction account encourages adoption precisely where no procurement reviewer is checking whether training can be disabled. The user receives a useful summary; the organization inherits responsibility for permission; and people who never opened accounts may still have their voices and information processed under that arrangement.
Continuity creates a separate exposure. Dark Reading cited the shutdown of AI meeting-notetaker vendor Novacy in its October 2025 risk review.[3] A shutdown does not by itself prove that customer data was lost or mishandled. It does demonstrate why a meeting archive should not depend on an untested assumption that the vendor, export path, account administrator, and deletion interface will remain available indefinitely.
Before admitting a notetaker, the owner should know where the authoritative record will live, how approved notes are exported, what happens to source audio after export, and how content can be removed if the service closes or the employee who created the account leaves. If nobody can answer those questions, automatic joining should be disabled while the answers are found.
Apply the decision at meeting level

A company-wide yes or no is tempting because it is easy to communicate. It is also poorly matched to calendars that move from a routine stand-up to a performance conversation and then to a call with outside counsel. The decision needs to travel with the meeting’s contents and participants.
- Determine whether the service receives audio, video, chat, screen content, participant metadata, a transcript, or only user-created notes. Do not infer this from the word “assistant.”
- Establish which consent rules may apply before recording starts, especially for cross-state or international calls. Route uncertainty to an authorized reviewer.
- Look for personnel information, customer restrictions, trade secrets, legal advice, investigations, regulated data, and other material that should not enter an ordinary meeting archive.
- Verify training use, human review, sharing defaults, retention, subprocessors where relevant, administrative visibility, export, and deletion. A paid enterprise policy should not be assumed to govern an employee’s separate free account.
- Name the person or role authorized to approve auto-join, answer participant objections, change retention, export approved records, revoke access, and request deletion.
- Keep the notetaker, admit it only after review, or refuse it. Removing the bot after sensitive information has been recorded is incident handling, not preventive control.
This test also prevents misleading product comparisons. A tool can be acceptable for a low-sensitivity internal sync and unacceptable for the legal call immediately afterward without having changed any technical feature. Conversely, a locally controlled or tightly administered system may reduce some vendor and retention exposure without resolving recording consent. Readers considering that architectural tradeoff can compare local-first note-taking alternatives.
Model accuracy, prompt injection, and broader application security still matter, but they answer different questions. The EchoLeak-era review of AI note-taking apps discusses adjacent agent exposure, including Granola, while the AI note-app security profile covers application-level security context. Neither replaces a meeting admission rule.
Turn keep, restrict, and refuse into enforceable defaults
Keep
Permit an approved notetaker in defined, low-sensitivity meeting types when participants receive appropriate notice, the applicable consent requirement has been addressed, training use is acceptable or disabled, retention is set, and an administrator can delete the source and derived records. Calendar access should be limited to the approved scope rather than treated as permission to join every event.
Restrict
Require affirmative review for external, customer, personnel, commercially confidential, or otherwise sensitive meetings. Disable global auto-join, require the host to admit the bot deliberately, and document who approved the use. If a participant objects, the policy should state whether the bot leaves, an alternative note-taking method is used, or the meeting is rescheduled.
Refuse or remove
Default to refusal when the consent rule is unresolved, counsel has not approved use in a potentially privileged matter, training cannot be controlled, retention and deletion are unknown, or no one owns the account. For an existing deployment, removal means more than deleting the visible bot: revoke calendar OAuth, disable auto-join, inventory personal and shared accounts, preserve any records that must legally or operationally be retained, export approved material, request deletion where appropriate, and verify that former users no longer control organizational meeting archives.
A reusable implementation template is available in How to Set a Personal AI Policy Across Every Note App. The important move is to make the rule visible before the next shared transcript creates another account and before another calendar grant turns a trial into the default. Vendor claims about AI quality cannot compensate for an unmanaged authorization or a meeting policy nobody can enforce.
References
- Shadow AI is taking notes — Nudge Security, January 2026
- AI Notetakers: Productivity Tool or Emerging Legal Risk? — Mayer Brown, June 2026
- Take Note: Cyber-Risks With AI Notetakers — Dark Reading, October 2025
- Balancing Efficiency with Privacy and Risk: Examining the Use of AI Note-Taking Tools — Fordham Intellectual Property, Media & Entertainment Law Journal