AI note-takers have become normal in a surprisingly short amount of time.
You start a Teams, Zoom, or Google Meet call, a bot joins to record the conversation, and minutes later everyone gets a tidy summary with action items. It saves real time โ which is exactly why staff often adopt these tools on their own, before anyone’s asked the obvious question: where does the recording actually end up?
Here’s the problem. Every word of that meeting, including the parts you’d never put in writing, gets captured, stored somewhere, and read by whoever has access. Few business owners have stopped to ask who that “whoever” includes, or what happens to the recording afterward.
That’s exactly the kind of blind spot a proper IT Support or Managed IT review should be catching before it becomes an issue.
What an AI Note-Taker Actually Does
An AI note-taker is a tool that joins a meeting, records the audio and sometimes the video, turns the speech into a written transcript, and produces a summary. Common ones include Microsoft 365 Copilot in Teams, Otter, Fireflies, and Fathom.
Most connect to your calendar so they can join automatically โ and some will sit in on any meeting on your schedule unless you turn that setting off.
The recording and transcript do not disappear when the call ends. They’re saved, usually in the cloud, where they can be searched, shared, and exported later. Where they’re saved, and who can reach them, depends entirely on which tool you use.
Who Can See the Recording?
Start with the obvious group: anyone the meeting organiser shares the summary with.
Many note-takers email the transcript to every attendee by default, and some send it to people who were invited but never actually joined. When the meeting covered a sensitive topic, that distribution list matters more than most people realise.
Then there’s the tool’s own access.
With a cloud note-taker, the recording sits on the vendor’s servers โ which means the vendor’s systems, and in some cases its staff, can reach it under the terms you agreed to (probably without reading closely).
If the tool auto-joined from someone’s calendar, the recording may live on an account you don’t control at all, belonging to whichever employee connected the bot in the first place.
A law firm publication on the legal risks of AI note-takers even warned that letting a note-taker vendor access or use your transcripts for its own purposes can risk waiving attorney-client privilege for businesses that handle legal matters.
Does the Tool Use Your Meetings to Train Its AI?
This is where tools differ the most, and it’s genuinely worth checking before you choose one.
Microsoft states that Copilot in Teams does not use your prompts, responses, or meeting content to train its AI models, and that the data stays inside your organisation’s Microsoft 365 environment. Microsoft’s privacy documentation says this directly, and notes the content is processed within the Microsoft 365 service boundary rather than on the public version of the AI.
Third-party note-takers vary widely.
Some store your recordings on their own servers and, depending on the terms you accept, may use that data to improve their models. Others say they don’t train on customer data at all. The only real way to know is to read the specific tool’s privacy terms โ because two tools that look almost identical on the surface can treat your data very differently underneath.
The Consent Question
Recording a meeting isn’t always yours to decide alone, and the rules change depending on where you and the other people are.
In around a dozen U.S. states, and in most Australian states, everyone in a conversation has to agree to being recorded. Federal U.S. law, most other U.S. states, and the UK allow recording when just one participant consents.
On top of that, the UK and Europe treat recording people as handling their personal data โ so under GDPR, you generally have to tell participants you’re recording, explain why, and have a proper reason for doing it.
That’s why the safest approach is simply to tell people the meeting is being recorded, explain why, and give them a chance to object before the bot starts. For client meetings, HR conversations, and anything covered by confidentiality, that matters even more โ and in some cases, you should check with a lawyer before recording at all.
How to Use AI Note-Takers Safely
You don’t have to ban these tools to use them responsibly. Here’s what actually works.
Pick an approved tool and say so. Decide which note-taker your business uses, and ask staff not to connect others to company meetings. This keeps your recordings in one place you control.
Turn off auto-join. Set the tool to join only when someone chooses to record, rather than automatically for every meeting on a calendar.
Announce recording and get consent. Make it normal to say a meeting is being recorded at the start, and to skip recording when someone objects.
Prefer tools that keep data in your environment. A note-taker that stores recordings inside your own Microsoft or Google tenant, and doesn’t train on your data, is far easier to control than one that holds everything on its own servers.
Control who gets the summary. Check the default sharing setting so transcripts aren’t emailed to everyone, including people who missed the meeting entirely.
Keep bots out of sensitive meetings. For legal, HR, financial, and confidential client conversations, the default should be no recording unless there’s a clear reason and everyone agrees.
If you use Microsoft 365, an administrator can control whether Copilot and transcription are allowed in Teams meetings. That gives you one place to set the rule, instead of relying on each person to get it right on their own โ and it’s exactly the sort of configuration a good Managed Services provider should have set up as standard for teams across Brisbane, Mackay, or anywhere in between.
Frequently Asked Questions
Is It Legal to Record a Meeting With an AI Note-Taker?
It depends on where everyone in the meeting is. Around a dozen U.S. states and most Australian states require everyone to consent. The UK, federal U.S. law, and most U.S. states allow it with one person’s consent, though in the UK and Europe you also have to inform people and have a valid reason under data-protection law. The safe approach everywhere is to announce the recording and let people object before it starts.
Does Microsoft Copilot Use My Meeting Data to Train Its AI?
No. Microsoft states that Copilot in Teams does not use your meeting content, prompts, or responses to train its foundation AI models, and that the data stays within your organisation’s Microsoft 365 environment.
Can an AI Note-Taker Join a Meeting Without Me Knowing?
Yes. Many tools connect to a user’s calendar and can auto-join meetings, sometimes ones the user isn’t even attending. You can turn auto-join off so the bot only records when someone chooses to start it.
Where Are AI Note-Taker Recordings Stored?
In the cloud. With Microsoft Copilot, the data stays inside your Microsoft 365 tenant. With many third-party tools, recordings sit on the vendor’s own servers. Where they live and who can reach them depends on the tool, so check its terms.
Should We Let Staff Use Otter or Fireflies for Work?
You can, with rules in place. Choose one approved tool, turn off auto-join, announce recording and get consent, check how the tool handles your data, and keep it out of legal, HR, and confidential client meetings.
AI note-takers aren’t the problem. Using them without knowing where the recording goes is. A little bit of structure โ one approved tool, clear consent, sensible defaults โ turns a genuine risk into a genuinely useful tool.
If you’d like help reviewing how your team’s tools handle data like this, check out our cybersecurity services, or get in touch with us and we’ll help you sort it out.
—


