Back to Posts

AI Notetakers Create Supersized Cyber Risk

June 29, 2026

Business meeting with several professionals on a video conference call with one AI note taker in the call.

As the market for AI meeting assistants grows, so do the lawsuits, bans, and privacy issues.

AI notetakers request access to your calendar, audio stream, and often your contacts and email, then transmit sensitive conversations to external servers under terms you've likely never read. Any tool sitting on that much access deserves the same vendor scrutiny you'd give anything else on your network.

Executive Summary

AI notetakers aren't a harmless feature bolted onto your calendar app. This guide walks through what a single meeting transcript can expose, how cloud-based bots differ from local hardware recorders, why some meetings should never be recorded, consent and privilege risks of recording others without their knowledge, and the NIST SP 800-171 and Cybersecurity Maturity Model Certification (CMMC) controls these tools touch.

Two Categories of AI Recording Tools

AI meeting assistants are either cloud-based bots or local hardware. Each option carries different risk profiles.

Cloud-Based Meeting Bots

Otter.ai, Fireflies.ai, Read AI, Fathom: these tools connect to your calendar, join the meeting as a named participant, and record audio straight to third-party servers. Transcripts and summaries get generated and stored under whatever terms of service you agreed to, usually without much of a second look. Most default to maximum data collection unless someone configures enterprise controls by hand. That's the pattern behind shadow AI risk, where AI tools get deployed with no governance, running under terms nobody reviewed.

Dedicated Hardware Recorders

Devices like PLAUD NOTE, PLAUD NotePin, and HiDock P1 take a different approach. They capture audio locally and never join the meeting as a participant. No bot shows up in the attendee list. No calendar integration fires automatically. Local processing means the recording bypasses cloud retention policies entirely, which is a real advantage if data sovereignty matters to your company.

Neither category eliminates the need to vet the vendor relationship carefully, even though the risk profiles look nothing alike.

Financials, Passwords, HR Content in Transcripts

List everything that gets said out loud in your average Tuesday meeting. A single meeting transcript can capture any of the following:

  • Customer financial information
  • Passwords or credentials shared verbally during troubleshooting
  • API keys read aloud during a system handoff
  • Active security incident details
  • Merger, acquisition, or strategic planning discussions
  • Employee performance or HR information
  • Protected health information (PHI) subject to HIPAA
  • Controlled Unclassified Information (CUI)
  • Export-controlled technical data

One transcript on a vendor's server under standard terms could capture this entire list at once.

Not All Meetings Carry the Same Risk

An HR conversation about a workplace complaint and a Monday status update aren't the same kind of meeting, even though most AI notetakers treat them so. Zero trust principles call for controls proportional to the sensitivity of what's being protected. That includes conversations, not just files sitting on a server. Companies need clear policies on which meeting types are appropriate for AI recording before deploying tools.

Meeting Type AI Notetaker Appropriate?
Internal operational meetings Generally yes, with disclosure
External client or partner meetings Evaluate; obtain consent from all parties
HR, legal, or compliance discussions Generally no
Strategic, financial, or M&A discussions Generally no

Every AI Notetaker Is a Vendor Relationship

Onboarding a vendor with direct access to your company's conversations isn't the same as flipping on a product feature, even though it feels that casual. That relationship carries the same due diligence obligations as any other third-party access grant. Companies that haven't formally evaluated the tools already running in their environment should start with a cybersecurity risk assessment.

Questions to Ask Before Deploying Any AI Recording Tool

  • SOC 2 Type II certification: An independent auditor verifies the vendor's security controls meet established standards for data handling, confidentiality, and availability, the baseline for evaluating any cloud service provider. STACK Cybersecurity holds this certification, and it shapes how we evaluate vendors we recommend to the businesses we support.
  • Encryption: Is data encrypted in transit and at rest?
  • SSO and MFA support: Does the platform enforce single sign-on (SSO) and multi-factor authentication (MFA)? Unmanaged account access is unmanaged risk, full stop.
  • Data residency: Where are recordings and transcripts stored geographically? Cross-border data transfers carry regulatory implications, particularly for companies subject to GDPR or operating in defense or health care environments.
  • Zero data retention options: Can the vendor process your data without retaining it on their infrastructure?
  • Customer-controlled deletion: Can your company delete data on demand and receive documented confirmation it's been purged from all systems, including backups?
  • Subprocessor disclosure: Every AI notetaker vendor relies on subprocessors, cloud infrastructure providers, AI model hosts, analytics services, and similar partners that touch your data as part of the pipeline. Agreeing to a vendor's terms of service means agreeing, by extension, to the data practices of everyone in that chain. Ask for the subprocessor list before you sign anything.

Platform Comparison: Security and Privacy

Important: Privacy policies, HIPAA offerings, and AI training practices change frequently. Review current vendor documentation before making deployment decisions.

Tool SOC 2 HIPAA Support AI Training on Customer Data Joins Meeting as Participant Local Recording Option
Microsoft Teams Copilot Available with Microsoft 365 compliance controls Customer data not used to train foundation models
Zoom AI Companion Available for eligible Zoom Healthcare plans Customer audio/video not used to train OpenAI or Anthropic models
Google Meet AI Notes (Gemini) Available under Google Workspace and BAA Workspace data not used to train foundation models by default
Fireflies.ai Available on Enterprise plans Customer-controlled; review current privacy policy
Otter.ai Not marketed as HIPAA-compliant for general use Review current privacy policy and workspace settings
Read AI No public HIPAA offering Review current privacy policy
Fathom Available for qualifying companies States customer meeting content is not used to train AI models
Avoma Available on Enterprise Review current privacy policy
Grain Available on Enterprise Review current privacy policy
MeetGeek Enterprise healthcare options available Review current privacy policy
Sembly AI Enterprise healthcare support Review current privacy policy
Granola No public HIPAA offering States notes remain local before optional cloud sync
Jamie AI No public HIPAA offering Processes recordings locally before cloud AI processing
PLAUD NOTE Not publicly advertised Review current privacy policy
PLAUD NotePin Not publicly advertised Review current privacy policy
Pocket AI Recorder Varies by product Review current privacy policy

Active Litigation

Otter.ai is facing a proposed class action filed in August 2025, alleging the tool records conversations without consent from all participants and feeds that data into AI model training (Fisher Phillips, 2025). Fireflies.ai faces a similar suit in Illinois, this one alleging the tool stores the unique vocal characteristics of every meeting participant, including people who never created an account or agreed to anything, in potential violation of the state's Biometric Information Privacy Act (Meetily, 2026). Both cases remain unresolved.

A Note on iFLYTEK

Fully offline transcription sounds like a clean data sovereignty win, and the iFLYTEK Smart Recorder advertises exactly that. But in October 2019, the U.S. Department of Commerce added iFLYTEK to its Entity List for enabling mass surveillance and human rights abuses against Uyghur and other Muslim minority groups in Xinjiang (Davis Wright Tremaine, 2019). The company is partially state-owned, with China Mobile as its largest shareholder and backing from several state investment funds (Wikipedia, 2024). Government contractors and regulated industries should weigh that history carefully before bringing the device in the door.

Risk by Tool Category

Not every recording tool carries the same risk, and the table below breaks down three categories against key zero trust criteria. Products vary within each category. The architecture differences hold steady across the board.

Risk Category Cloud Meeting Bot Local Desktop App Hardware Recorder
Third-party vendor access High Medium Low
Appears in participant list Yes No No
Local recording possible No Sometimes Yes
Cloud dependency High Medium Low
AI model training concerns Varies Varies Low
Data sovereignty Low Medium High
IT visibility and governance High Low Very low

Cloud meeting bots are the easiest to govern and the easiest for IT to see, but they also carry the highest vendor access and data sovereignty risk. Local apps and hardware recorders flip that equation: less third-party exposure, far less visibility. A hardware recorder sitting on a conference table is practically invisible to your security stack.

Zero trust doesn't pick a favorite category. Whatever your company allows, that tool still needs evaluation, approval, and ongoing governance before it touches your environment. Read more about how STACK applies zero trust architecture to protect business environments.

The Recorder Hears Everyone, Not Just Your Team

Picture a vendor call with outside counsel sitting in. AI notetakers don't filter for employees only. They capture everyone in the room: customers, prospects, vendors, outside legal counsel, consultants, government contacts, and partners, none of whom chose your AI vendor or agreed to a word of its terms of service.

Consent Laws Vary by State

Twelve states require consent from every participant before a conversation can be recorded (Meetily, 2026). One-party states only need the person hitting record to know. All-party states need everyone in the room on board.

Consent Requirement States
All-party consent required California, Connecticut, Florida, Illinois, Maryland, Massachusetts, Michigan, Montana, Nevada, New Hampshire, Oregon, Washington
One-party consent All remaining U.S. states and Washington D.C.

Recording a client without telling them can damage the relationship even where the law allows it outright. Reputational risk doesn't check your state's consent statute first. Consent here functions as a professional norm, not just a legal one.

Attorney-Client Privilege

Confidentiality is the whole foundation of attorney-client privilege, and once a notetaker vendor can access or reuse that transcript, the privilege itself may be at risk of waiver (Smith Anderson, 2025). Companies that routinely loop in outside counsel during recorded meetings should walk through this exposure with their attorneys before continuing the practice.

"These tools also present serious risks to attorney-client privilege and confidentiality."

American Bar Association, 2025

Identity and Access Risk

The risk in an AI transcript runs deeper than the words spoken out loud. Modern transcription tools tag speakers by name, pull job titles and departments from calendar metadata, log email addresses straight from the invite, and assign action items to specific people.

Stack enough of those transcripts together and you've built an org chart nobody approved: reporting lines, project assignments, system access, approval authority, and more. That's the exact raw material behind social engineering and business email compromise (BEC). A hacker that already knows who approves wire transfers, who manages vendor accounts, and who holds admin credentials doesn't need much more.

Inadequate vendor controls turn that transcript library into something bigger than a privacy problem. It becomes a direct extension of your attack surface, feeding the same pattern as ungoverned AI tool use elsewhere in the company: exposure that security teams can't see or contain.

NIST SP 800-171 and CMMC Implications

Handling Controlled Unclassified Information, or working toward CMMC certification? AI notetakers introduce compliance considerations under NIST SP 800-171 that are easy to overlook. The table below maps the controls most directly implicated by AI meeting assistant use.

Control Requirement AI Notetaker Considerations
3.1.1 Limit system access to authorized users Who can access meeting transcripts? Are permissions role-based?
3.1.2 Limit transactions and functions Can users download, share, or export transcripts?
3.1.3 Control information flow Are transcripts shared externally or synced to unauthorized applications?
3.1.5 Least privilege Do all employees need access to every meeting transcript?
3.1.20 External connections Has the AI service been approved as an external information system?
3.3.1 Audit logging Are transcript access and downloads logged?
3.4.1 Configuration management Are AI notetakers approved and managed by IT?
3.5.3 Multifactor authentication Is MFA required for access to the AI platform?
3.8.1 Media protection Where are recordings and transcripts stored?
3.8.3 Sanitize media Can recordings and transcripts be securely deleted?
3.13.8 Protect CUI in transit Are recordings and transcripts encrypted during transmission?
3.13.11 Cryptographic protection Is sensitive meeting data encrypted at rest?
3.14.1 Identify and manage risk Has the company assessed the risks of AI meeting assistants?

An unapproved AI notetaker in a meeting where CUI is mentioned is a CMMC compliance gap needing remediation. STACK Cybersecurity is a CMMC Registered Practitioner Organization (RPO). We can help map AI tool use against your compliance obligations.

Applying Zero Trust: What to Do Now

None of this requires a new product purchase. Zero trust governance for AI recording tools comes down to a handful of company decisions. Here is where to start:

  • Classify meetings before deploying tools. Decide which conversation types should never be recorded, by any method, then write it down and enforce it.
  • Apply vendor due diligence before deployment. Evaluate SOC 2 certification, encryption standards, SSO and MFA enforcement, data residency, retention terms, deletion rights, and subprocessor transparency.
  • Skip the default configuration. Most tools default to maximum data collection, and enterprise agreements with explicit data processing terms offer real, measurable protection.
  • Get consent from everyone in the room. Every time, regardless of what your state's minimum legal requirement happens to be.
  • Govern transcripts like the sensitive data they are. Apply the same access controls and retention schedules you would use for any other sensitive company data, with clear deletion procedures built in.
  • Do not forget the identity data hiding inside conversation content. That layer alone is an active part of your attack surface.

Evaluate Your AI Tool Risk with STACK

The tools your employees are already using in meetings may be creating vendor risk, consent exposure, and governance gaps nobody has measured yet. Zero trust means asking these questions before access gets granted, not after something goes wrong.

Cybersecurity Consultation

Is your company secure against cyber threats? If you're not sure, it's time for a cybersecurity risk assessment (CSRA). STACK Cybersecurity's CSRA will meticulously identify and evaluate vulnerabilities and risks within your IT environment. We'll assess your network, systems, applications, and devices. You'll get a detailed report and action plan to improve your security posture. Don't wait until it's too late.

Schedule a Consultation Explore our Risk Assessment