AI note-takers are everywhere now. They promise to capture every word so you can stay present in meetings, and honestly, the convenience is real. But the recording that lands in your inbox isn’t just a summary — it’s a data point that can end up in a training set, a vendor’s server, or even a courtroom. Most of what’s documented here comes from a growing body of reporting and legal filings that paint a clear picture: the privacy risks are not theoretical.
Consent Laws
Voiceprints
Shadow AI
Litigation
The quiet guest in your meeting
When you join a meeting, the first thing to check is whether an AI note-taker is already seated. Some appear as named bots — OtterPilot, Read AI, Fireflies — and the platform may even flash a recording notice. But others are designed to stay invisible. Take Granola: the class action lawsuit filed in July 2026 alleges the app runs locally on a user’s device so “other people in the room won’t know it’s there.” The complaint calls it a textbook illegal wiretap. If that sounds extreme, consider that the product’s marketing itself emphasized discretion.
Thorin Klosowski, senior security and privacy analyst at the Electronic Frontier Foundation, says that while Zoom and Google Meet notify when recording is underway, some meeting software does not make a notetaker’s presence clear. Participants may also use personal devices separate from the platform. “You hope the other person would tell you that they’re doing that,” Klosowski told the Jamaica Gleaner. “Asking everyone for consent before doing a sensitive meeting would be the most polite approach to take.”
It’s one thing to agree to a recorded meeting. It’s another to discover after the fact that your words were captured by a tool you didn’t consent to. That feeling of lost control is exactly what the Granola plaintiffs describe — and it’s a growing concern as AI note-takers become more discreet.
Your voice is a biometric fingerprint
Many AI note-takers do more than transcribe. They analyze your voice to attribute speech to individuals, creating what’s called a voiceprint — a biometric profile as unique as a fingerprint. Chris Pluymers, an associate attorney at The Dillon Law Group in Michigan, explains that voiceprints are used to label speakers “Speaker 1” or “Speaker 2,” but they can also be used to verify bank account holders over the phone. In the wrong hands, a voiceprint could be used to access accounts or commit fraud.
Some states have taken notice. Illinois’s Biometric Information Privacy Act (BIPA) treats voiceprints as biometric identifiers, requiring written notice and informed consent before collection, plus a documented data-retention schedule and destruction policy. Pluymers says most companies using these tools have none of those systems in place. Under Illinois law, employees can refuse to attend meetings with AI note-takers until they get assurances about where and why the data is stored and when it will be deleted.
A voiceprint isn’t just a recording — it’s a biometric identifier. If a vendor stores your voice characteristics without your consent, it may be violating state laws like Illinois BIPA. And if that data is leaked, your voice could be used to impersonate you.
The consent gap: who asked everyone?
The central issue in most lawsuits is consent. Federal law (18 U.S.C. § 2511) requires only one-party consent for interstate calls, but at least twelve states — including California, Florida, Illinois, and Washington — require all parties to consent before recording. That means if you’re on a call with someone in California and you haven’t told them you’re using an AI note-taker, you may be breaking the law.
Otter.ai, which claims 35 million users, is facing a consolidated class action in California federal court alleging it recorded conversations without consent and used voices to train AI models. A judge recently rejected Otter’s attempt to dismiss the main claims. Fireflies.ai is facing multiple suits under Illinois BIPA for harvesting voiceprints from meeting participants. And a separate class action against Microsoft alleges its Teams live transcription feature collected voice biometric data without proper consent.
The common thread: these companies put the burden of obtaining consent on the user, buried in terms of service. As one report notes, courts historically don’t look favorably on tech companies hiding behind terms of service, but the outcomes are case-by-case. For now, the safest approach is to assume you need everyone’s affirmative okay before hitting record.
In most U.S. states, only one person on the call needs to consent to recording. That means you can legally record a conversation you’re part of without telling others — but that doesn’t mean it’s smart. Reputational risk doesn’t check consent statutes.
At least twelve states require every participant to consent: California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, and Washington. If anyone on your call is in one of these states, you need to get their permission first.
What your meeting data becomes
Even if consent is obtained, what happens to the recording matters. AI note-takers convert audio to searchable text, which is far easier to store, search, and share than video files. Danielle Kays, a partner at Fisher Phillips who advises businesses on privacy, says companies should find out whether the vendor retains recordings, transcripts, or metadata indefinitely, and whether they use them to train AI models. “If there is some sort of speaker ID or voice recognition, really understand what that is and how it works,” she told the Jamaica Gleaner.
Text transcripts are also much easier for outsiders to search through, according to the EFF. “Storing a bunch of video isn’t easy, it’s costly and hard to look through, but text is much easier to search and cheaper to store,” Klosowski said. This means a single meeting transcript could expose customer financial data, passwords shared during troubleshooting, API keys, or merger discussions. The StackCyber analysis notes that a single transcript can capture export-controlled technical data, PHI, and HR information.
And even if you delete the transcript, metadata about the meeting may remain with the vendor. That metadata could influence how the AI model behaves, and in some cases, the model might memorize or reproduce sensitive information.
- Check the vendor’s privacy policy to see if transcripts are used for model training
- Opt out of data sharing or model training in app settings — don’t rely on default
- Configure retention settings to delete transcripts after a defined period
- Restrict integrations with CRM and project management tools unless necessary
Shadow AI and the hardware that hides
The risks aren’t limited to virtual meeting bots. Portable AI notetakers — devices like the PLAUD NOTE, Granola’s Apple Watch app, or even a smartphone running a local app — can record in-person conversations without ever joining a meeting. As the Workplace Privacy Report notes, these devices bypass typical security controls: they don’t install software on a company computer, don’t connect to the corporate network, and can upload recordings to a personal account. This is shadow AI, and it’s nearly invisible to IT.
An employee could record a conference-room discussion, an interview, or even a casual conversation in the break room, then send it to a third-party AI service. The organization may never know. This is especially concerning for conversations involving trade secrets, privileged legal discussions, or patient health information.
For WFH professionals, the same risk applies: if you’re on a video call and someone in the room is using a portable recorder, you might not know. The advice from multiple sources is clear: if you’re discussing sensitive information, ask explicitly whether any recording is happening. And if you’re the one using a note-taker, be transparent.
It’s one thing to see a bot in the participant list. It’s another to realize that a small device on the table has been capturing everything you say. The same privacy and consent rules apply, but the notice is harder to give — and harder to receive.
What you can do right now
Most of the advice from experts boils down to a few practical steps. First, make it a habit to check for note-takers when you join a meeting. If you see an unfamiliar participant, ask. If you’re unsure, say at the start: “I’d like to keep this meeting without AI recording tools — I’m happy to take my own notes and share a recap.”
Second, if you’re using an AI note-taker, get explicit verbal consent from everyone on the call, especially if anyone might be in an all-party consent state. Don’t rely on the tool’s default settings — turn on any notice features and opt out of model training. For sensitive meetings, consider using a tool with enterprise-grade security, such as Zoom AI Companion under a Healthcare plan or Microsoft Teams Copilot with appropriate compliance agreements.
Third, treat meeting transcripts like any other sensitive business record. Apply retention policies, limit access, and ensure deletion procedures are in place. The Goodwin law firm’s alert recommends establishing formal governance policies that prescribe who can deploy these tools, what types of meetings are appropriate, and how to validate accuracy through human review.
For organizations, the Workplace Privacy Report recommends a written policy prohibiting unauthorized recording, an AI usage policy that requires approval for specific tools, and employee training on the risks. The bottom line: AI note-takers are useful, but they demand the same diligence as any other vendor relationship.
- Check for bots at the start of every meeting
- Ask for consent — verbally, before recording begins
- Opt out of model training in app settings
- Retain transcripts only as long as necessary
- Use enterprise tools with signed BAAs/DPAs for sensitive data
The legal landscape is still catching up. As one attorney noted, how do you get consent when someone walks into a room wearing smart glasses or a pocket recorder? There’s no digital interface to put a notice in front of people. That question will be worked out in courts and legislatures in the coming years.
For now, the most honest advice is to stay informed and err on the side of transparency. AI note-takers aren’t going away, but neither are the rights of the people whose voices they capture. Knowing what’s at stake is the first step to using them without losing control of your conversations.