AI note-takers have become commonplace in a short space of time. You start a Teams, Zoom, or Google Meet call, a bot joins to record the conversation, and minutes later everyone gets a tidy summary with action points. It saves real time, which is why staff often adopt these tools on their own, before anyone has worked out where the recording ends up.
The trouble is, every word of the meeting, including the parts you would never put in writing, gets captured, stored somewhere, and read by whoever has access. Below are the five questions we hear most often from businesses working out how to use these tools safely.
An AI note-taker is a tool that joins a meeting, records the audio and sometimes the video, turns the speech into a written transcript, and produces a summary. Common ones include:
The recording and transcript do not disappear when the call ends. They are saved, usually in the cloud, where they can be searched, shared, and exported later. Where they are saved, and who can reach them, depends on which tool you use.
Start with the obvious group: anyone the meeting organiser shares the summary with. Many note-takers email the transcript to every attendee by default, and some send it to people who were invited but never joined. When the meeting covered a sensitive topic, that distribution list matters.
Then there is the tool's own access. With a cloud note-taker, the recording sits on the vendor's servers, which means the vendor's systems, and in some cases its staff, can reach it under the terms you agreed to. If the tool auto-joined from someone's calendar, the recording may live on an account you do not control, belonging to whichever employee connected the bot. A law firm publication on the legal risks of AI note-takers warned that letting a note-taker vendor access or use your transcripts for its own purposes can even risk waiving legal privilege for businesses that handle legal matters.
This is where tools differ the most, and it's worth checking before you choose one. Microsoft states that Copilot in Teams does not use your prompts, responses, or meeting content to train its AI models, and that the data stays inside your organisation's Microsoft 365 environment. Microsoft's privacy documentation says this directly, and notes the content is processed within the Microsoft 365 service boundary rather than on the public version of the AI.
Third-party note-takers vary widely. Some store your recordings on their own servers and, depending on the terms you accept, may use that data to improve their models. Others say they do not train on customer data at all. The only way to know is to read the specific tool's privacy terms, because two tools that look almost identical can treat your data very differently.
The position varies by jurisdiction:
The safest approach is to tell people the meeting is being recorded, explain why, and give them a chance to object before the bot starts. For client meetings, HR conversations, and anything covered by confidentiality, that matters even more, and in some cases you should check with a lawyer before recording at all.
You don't have to ban these tools to use them responsibly. Businesses in this position typically:
If you use Microsoft 365, an administrator can control whether Copilot and transcription are allowed in Teams meetings, giving you one place to set the rule rather than relying on each person to get it right.
Each of these corresponds to a decision that shouldn't be left to individual staff to work out on their own.

























