Sound Networks IT Support
Sound Networks IT Services
IT Support
Managed IT Services
Cyber Security
AI
Insights
Company

Request free IT audit

This site uses cookies for functionality and analytics Manage Close

AI note-takers are recording more than you think

The five questions we're hearing most from businesses using them

AI note-takers have become commonplace in a short space of time. You start a Teams, Zoom, or Google Meet call, a bot joins to record the conversation, and minutes later everyone gets a tidy summary with action points. It saves real time, which is why staff often adopt these tools on their own, before anyone has worked out where the recording ends up.

The trouble is, every word of the meeting, including the parts you would never put in writing, gets captured, stored somewhere, and read by whoever has access. Below are the five questions we hear most often from businesses working out how to use these tools safely.

Question 1: What does an AI note-taker actually do?

An AI note-taker is a tool that joins a meeting, records the audio and sometimes the video, turns the speech into a written transcript, and produces a summary. Common ones include:

  • Microsoft 365 Copilot in Teams. Built into the Microsoft ecosystem, with data staying inside your own tenant.
  • Otter and Fireflies. Third-party tools that connect to your calendar and can join calls automatically.
  • Fathom. Another calendar-linked note-taker, with its own separate storage and sharing defaults.

The recording and transcript do not disappear when the call ends. They are saved, usually in the cloud, where they can be searched, shared, and exported later. Where they are saved, and who can reach them, depends on which tool you use.

Question 2: Who can actually see the recording afterwards?

Start with the obvious group: anyone the meeting organiser shares the summary with. Many note-takers email the transcript to every attendee by default, and some send it to people who were invited but never joined. When the meeting covered a sensitive topic, that distribution list matters.

Then there is the tool's own access. With a cloud note-taker, the recording sits on the vendor's servers, which means the vendor's systems, and in some cases its staff, can reach it under the terms you agreed to. If the tool auto-joined from someone's calendar, the recording may live on an account you do not control, belonging to whichever employee connected the bot. A law firm publication on the legal risks of AI note-takers warned that letting a note-taker vendor access or use your transcripts for its own purposes can even risk waiving legal privilege for businesses that handle legal matters.

Question 3: Does the tool use our meetings to train its AI?

This is where tools differ the most, and it's worth checking before you choose one. Microsoft states that Copilot in Teams does not use your prompts, responses, or meeting content to train its AI models, and that the data stays inside your organisation's Microsoft 365 environment. Microsoft's privacy documentation says this directly, and notes the content is processed within the Microsoft 365 service boundary rather than on the public version of the AI.

Third-party note-takers vary widely. Some store your recordings on their own servers and, depending on the terms you accept, may use that data to improve their models. Others say they do not train on customer data at all. The only way to know is to read the specific tool's privacy terms, because two tools that look almost identical can treat your data very differently.

Question 4: Do we need everyone's consent before recording?

Recording a meeting is not always yours to decide alone, and the rules change depending on where you and the other people are.

The position varies by jurisdiction:

  • Around a dozen U.S. states, and most Australian states, require everyone in the conversation to agree to being recorded.
  • Federal U.S. law, most other states, and the UK allow recording when one participant consents.
  • The UK and Europe treat recording people as handling their personal data, so under GDPR you generally have to tell participants you are recording, explain why, and have a proper reason for doing it.

The safest approach is to tell people the meeting is being recorded, explain why, and give them a chance to object before the bot starts. For client meetings, HR conversations, and anything covered by confidentiality, that matters even more, and in some cases you should check with a lawyer before recording at all.

Question 5: How do we roll these tools out safely?

You don't have to ban these tools to use them responsibly. Businesses in this position typically:

  • Pick an approved tool and say so, asking staff not to connect others to company meetings, keeping recordings in one place you control.
  • Turn off auto-join, so the tool joins only when someone chooses to record, rather than automatically for every meeting on a calendar.
  • Announce recording and get consent as standard practice at the start of a call, skipping the recording when someone objects.
  • Prefer tools that keep data in your own environment and do not train on your data, over ones that hold everything on their own servers.
  • Control who gets the summary, checking the default sharing setting so transcripts are not emailed to everyone, including people who missed the meeting.
  • Keep bots out of sensitive meetings such as legal, HR, financial, and confidential client conversations, unless there is a clear reason and everyone agrees.

If you use Microsoft 365, an administrator can control whether Copilot and transcription are allowed in Teams meetings, giving you one place to set the rule rather than relying on each person to get it right.

Three questions worth sending your IT provider

Each of these corresponds to a decision that shouldn't be left to individual staff to work out on their own.

  • Which AI note-taker are we standardising on, and can auto-join be switched off across the business?
  • Does our chosen tool train on our meeting data, and where exactly are recordings stored?
  • Can we restrict recording bots from legal, HR, and confidential client meetings at an administrator level?
Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Watch Guard network security partner
Datto ticketing and management system
Huntress security partner
Dell Technologies and services
Hyper-V routing technologies
BitDefender defending your hardware
Microsoft 365 professional services
3CX VoIP phone systems
Veeam partner
Signable partner
Cyber Essentials Certification
Power Automate automation workflows
GTIA
Need Help?