AI Note-Takers Are in Your Meetings. Now What?

TL;DR: AI note-takers join meetings, transcribe everything, and store the recording on someone’s servers. Where it lands and who can reach it depends entirely on the tool. Some keep data inside your Microsoft or Google tenant, and others hold it themselves and may train on it. Recording consent rules vary by state and follow the people on the call. Pick one approved tool, announce recording, and keep bots out of sensitive meetings.

A bot joined your last client call, and nobody in the room decided to let it in. It came attached to one person’s calendar, and it introduced itself by appearing in the participant list.

That’s an AI note-taker, and it saves real time, which is exactly why staff adopt these tools on their own. The trouble is what happens next. Every word of that meeting, including the part where your client vented about their business partner, is now a searchable file sitting on a vendor’s servers under terms nobody at your company read.

This is the pattern with almost every AI tool right now. A PagerDuty survey this year found 66% of office professionals had used AI tools at work while believing their company didn’t permit it. The tool doesn’t wait for a policy. It shows up, it works, and it spreads.

Here’s where the recording goes, who can reach it, and how to set rules your team will actually follow.

What Does an AI Note-Taker Actually Do?

An AI note-taker joins your meeting as a participant, records the audio, turns the speech into a written transcript, and produces a summary with action items. Common tools include Microsoft 365 Copilot in Teams, Otter, Fireflies, and Fathom. Most connect to a calendar so they can join on their own.

That auto-join setting is the part people miss. Some tools will sit in on any meeting on a user’s schedule unless someone turns the feature off, including meetings that user isn’t attending.

And the file doesn’t disappear when the call ends. The recording, the transcript, and the summary are saved in the cloud, where they can be searched, shared, and exported months later by anyone with access.

Who Can Actually See the Recording?

Four groups, usually. Anyone the organizer shares the summary with, which often defaults to every person invited including the ones who never showed up. The vendor, whose systems and in some cases staff can reach data stored on their servers. Whoever owns the account the bot came from. And anyone who later gains access to wherever that file lives.

That third group is the one that catches business owners off guard. If a note-taker auto-joined from an employee’s personal account, the recording of your client meeting lives on an account your business doesn’t own, can’t audit, and can’t delete. If that employee leaves, the recording goes with them.

The default sharing setting deserves a look too. A transcript emailed automatically to all invitees is fine for a project standup and a real problem for a conversation about staffing or pricing.

Law firms writing about these tools have raised a further concern for businesses that handle legal matters: letting a vendor access or use meeting transcripts may complicate claims of attorney-client privilege. That’s one of several reasons a vendor review belongs in your cybersecurity consulting checklist before a tool ever touches a client conversation.

Does the Tool Use Your Meetings to Train Its AI?

It depends on the tool, and this is where they differ most. Microsoft states that prompts, responses, and data accessed through Microsoft Graph are not used to train the foundation models behind Copilot, and that the content stays inside your Microsoft 365 service boundary. Many third-party note-takers store recordings on their own servers instead.

Microsoft’s privacy documentation says this directly, and it’s a meaningful distinction. Data that never leaves your own tenant is data you can apply retention policies to, audit, and delete.

Third-party tools vary widely. Some say plainly that they don’t train on customer data. Others reserve the right to use it to improve their models, depending on which plan you’re on and which terms you accepted. Two products with nearly identical interfaces can treat your recordings completely differently, and the only way to know is to read the specific terms for the specific plan.

If that sounds like a chore, it is. It’s also a five-minute chore once, versus an open question forever.

Why Recording Rules Are More Complicated Than They Look

Recording consent rules in the U.S. vary by state, and they’re worth understanding at a general level even though the details of any given situation are a question for your attorney.

Kentucky is a one-party consent state, and so is Indiana. Under federal law and in most states, one participant’s consent is the standard. Roughly a dozen states take the stricter approach and require everyone in the conversation to agree, including California, Illinois, Florida, Pennsylvania, Massachusetts, Maryland, and Washington. You can see the full breakdown in this 50-state survey of recording laws.

Here’s the wrinkle for a Louisville business. A video call rarely stays in one state. When a Kentucky company meets with a client in Chicago or Los Angeles, more than one state’s rules are potentially in play, and the common practice among people who deal with this regularly is to work to the strictest standard on the call. Courts have not resolved these cross-border questions uniformly.

None of that is legal advice, and your situation may turn on details this post can’t see. If you record client conversations regularly, or you work in a regulated field, that’s a conversation to have with a lawyer.

The practical takeaway is simpler than the legal picture. Announce the recording at the start of every meeting, explain why, and skip it when someone objects. Do that consistently and the hardest version of the question stops coming up.

Two Lawsuits Worth Knowing About

The category is being tested in federal court right now, which is new since most businesses adopted these tools.

In re Otter.AI Privacy Litigation, consolidated in the Northern District of California in October 2025, alleges that Otter’s note-taking tools recorded and transcribed meeting participants without the consent of all parties and used that content to help train its models. The complaint raises claims under the federal Wiretap Act and the California Invasion of Privacy Act, among others. A motion to dismiss was heard in May 2026. A separate suit against Fireflies was filed in Illinois federal court in March 2026 on substantially similar theories.

These are allegations. No court has ruled on the merits, and nothing has been decided about whether the practices at issue were lawful.

The part that matters for a business owner regardless of outcome is structural. As employment attorneys analyzing the case have noted, note-taker vendors typically write their terms so the account holder is responsible for getting participant permission. That responsibility lands on you, not on the tool, and it lands there whether or not anyone at your company read the terms.

How Do You Use AI Note-Takers Safely?

You don’t have to ban them. Six rules cover most of the risk, and they take an afternoon to put in place.

  • Approve one tool and say so. Decide which note-taker your business uses and ask staff not to connect others. One tool means one place your recordings live.
  • Turn off auto-join. Set the tool to record only when a person chooses to, rather than joining everything on a calendar.
  • Announce recording every time. Make it a normal opening line, and honor it when someone asks you not to record.
  • Prefer tools that keep data in your tenant. A note-taker storing recordings inside your own Microsoft or Google environment is far easier to govern than one holding everything on its own servers.
  • Check the default sharing setting. Make sure transcripts aren’t emailed automatically to everyone invited, including people who never attended.
  • Keep bots out of sensitive meetings. For legal, HR, financial, and confidential client conversations, the default should be no recording unless there’s a clear reason and everyone agrees.

If you run Microsoft 365, an administrator can control whether Copilot and meeting transcription are permitted in Teams at all. That puts the rule in one place instead of depending on every employee to configure their own settings correctly, and it’s the kind of tenant-level control that comes standard with managed IT services in Louisville. Pair it with security awareness training so people understand the reasoning, not just the restriction.

This Is a Governance Problem, Not a Tool Problem

Note-takers are usually the first AI tool to enter a business, and they almost never arrive through a decision. Someone tries one, it saves them an hour a week, and three months later it’s in client meetings.

The scale of that is bigger than most owners realize. Vanta reported this summer that roughly 70% of companies have shadow AI somewhere in their environment, meaning AI tools with access to company data that nobody vetted, with overall shadow IT up 36% year over year.

Banning the category isn’t the answer, because the productivity gain is real and people will route around a ban. Having a written answer before the next tool shows up is the answer, and there will be a next tool. That’s the work behind AI business consulting: deciding which tools are approved, what data they’re allowed to touch, and who signs off. For businesses without an executive to own that, a virtual Chief Security Officer fills the seat.

Decide Before the Next Bot Shows Up

Three things to take away. The recording outlives the meeting, so treat it like any other business record. Where it’s stored and who can reach it depends entirely on which tool you picked, which makes that choice worth five minutes of reading. And one approved tool with auto-join disabled beats five unapproved ones nobody can inventory.

Most businesses can sort this out in a single meeting. The ones that don’t usually find out what their policy was when a client asks who else has a copy of the call.

If you’re not sure which tools are already connected to your calendars, that’s a good place to start. Schedule an intro call and we’ll walk through what’s running in your environment and what a workable policy looks like.

Frequently Asked Questions

What do recording consent rules say about AI note-takers?

Rules vary by state. Kentucky and Indiana are one-party consent states, as is federal law and most of the country. About a dozen states, including California, Illinois, and Florida, require everyone in the conversation to consent. Calls that cross state lines raise questions courts haven’t answered uniformly, so specific situations are worth discussing with an attorney. Announcing the recording and honoring objections is the practice that avoids most of the ambiguity.

Can an AI note-taker join a meeting without me knowing?

Yes. Many tools connect to a user’s calendar and auto-join scheduled meetings, sometimes ones that user isn’t even attending. The bot typically appears in the participant list, but people don’t always notice. You can turn auto-join off so the tool only records when someone deliberately starts it.

Does Microsoft Copilot use my meeting data to train its AI?

Microsoft states that prompts, responses, and data accessed through Microsoft Graph are not used to train the foundation models behind Copilot, and that content stays inside your organization’s Microsoft 365 service boundary. This applies to commercial Microsoft 365 tenants. Consumer versions of Microsoft’s AI tools operate under different terms.

Where are AI note-taker recordings stored?

In the cloud, but which cloud depends on the tool. With Microsoft Copilot, the data stays inside your own Microsoft 365 tenant. With many third-party note-takers, recordings sit on the vendor’s servers under the terms of whatever plan the user signed up for. Check the specific tool’s documentation before assuming.

Should we let staff use Otter or Fireflies for work?

That’s a business decision, and it works better with rules than without them. Pick one approved tool, turn off auto-join, announce recording and get agreement, read how the tool handles your data, and keep it out of legal, HR, and confidential client meetings. The risk isn’t any single tool. It’s five different tools nobody approved.

Not Sure What’s Already Connected?

Most businesses have more AI tools touching their data than anyone has written down, and meeting recordings are usually the first place it shows up. Get in touch and we’ll help you inventory what’s running, set a policy your team will follow, and lock down the settings that matter.