AI notetakers have quietly become one of the most widely used — and least scrutinised — tools in the modern workplace. They join your video calls, transcribe every word, generate summaries, and send action items straight to your inbox. The productivity promise is real. But so is the legal exposure.

According to Fellow.ai's 2025 survey of professionals across IT, Operations, and business leadership, three out of four professionals (75%) said they currently use an AI notetaker in their work meetings.

That level of penetration means IT leaders can no longer treat these tools as a fringe concern.

For IT and HR leaders, these tools introduce a new layer of compliance considerations — creating legal risks involving employee privacy, consent requirements, confidentiality, data security, and workplace decision-making.

This post breaks down exactly what those risks look like, where the law currently stands, and what you can do today to protect your organisation.


The Scale of the Problem: Shadow AI and Ungoverned Adoption

Before you can manage the legal risk, you need to understand how these tools are getting into your organisation in the first place.

In many organisations, employees are signing up for AI notetakers on their own, connecting them to Zoom, Google Meet, or Microsoft Teams without any IT oversight. While the intent is good — making meetings more productive — the outcome can be risky.

This phenomenon, often called "shadow AI," is not a minor inconvenience.

The security risks are distinct from traditional shadow IT because AI systems actively process and may retain sensitive data, creating persistent exposure that outlasts the session.

The scale can be staggering:

notetaking apps spread fast in organisations — one enterprise saw about 800 notetaker accounts appear in 90 days via invite sprawl, where users share the app with one another.

IT teams frequently discover during audits unapproved AI tools that capture sensitive customer data outside enterprise security controls.

By the time the audit happens, the damage may already be done.


One of the most immediate legal risks with AI notetakers is consent — and it's more complicated than most people realise.

In many jurisdictions, recording a conversation requires consent from all participants. Automatic recording by an AI notetaker may inadvertently violate wiretapping or privacy laws if participants are not properly informed.

In the United States, the legal landscape is fragmented by state.

Employment attorneys say recent litigation has revealed a compliance gap that spans federal wiretap law, state biometric privacy statutes, GDPR, and the incoming EU AI Act.

The federal Electronic Communications Privacy Act (ECPA) permits statutory damages of up to $10,000 per violation, and BIPA settlements have reached into the hundreds of millions.

The stakes became very concrete in 2025.

In August 2025, a class action complaint was filed in the U.S. District Court for the Northern District of California. The plaintiff alleges that Otter.ai records and transcribes conversations of non-users without their knowledge or consent, and uses this data to train its machine learning models.

The complaint names violations of the federal ECPA, the Computer Fraud Act, California's Invasion of Privacy Act, and the state's Unfair Competition Law.

The core issue?

One individual may trigger the recording or transcription of a meeting without the knowledge or consent of others.

That single design decision can expose your entire organisation.


GDPR and International Privacy Law: A Deeper Layer of Obligation

For organisations operating in Europe — or handling the data of EU residents — the compliance burden goes even further.

For AI meeting tools in particular, three data types draw the most scrutiny from European data protection authorities: voice recordings (biometric-adjacent), verbatim transcripts, and behavioural inferences drawn from meeting patterns.

Under GDPR, simply having a bot announce that it is recording is not enough.

Data protection experts point out that a recording announcement from software alone does not represent valid consent under the GDPR. Even if a meeting bot announces a recording, it doesn't replace the express consent of each individual participant.

The risks compound further when data crosses borders.

Many AI meeting assistants marketed as "GDPR compliant" only partially meet these requirements. They might encrypt data in transit but store it on US servers subject to foreign surveillance laws — or claim compliance while quietly using customer meeting data to train their AI models.

There is also a surveillance dimension.

Security requirements under Article 32 of the GDPR demand appropriate technical and organisational measures. Automatic synchronisation with calendars and meeting software grants some AI tools broad access to organisational systems — access that the IT department may not even be aware of when individual users install such tools. Compliance cannot be demonstrated where third-party AI tools access internal infrastructure without proper controls.

And looking ahead,

beginning in August 2026, the EU AI Act introduces a separate layer of obligation. AI systems used for worker monitoring and management may be classified as high-risk — a category that could encompass tools offering sentiment analytics or productivity scoring alongside transcription.


Discrimination, Privilege, and the Hidden Employment Law Risks

Consent and data privacy are not the only legal exposure points. AI notetakers create several other employment law risks that IT leaders often overlook entirely.

Transcription bias and disparate impact:

AI transcription tools may consistently misunderstand accents, speech impediments, or other characteristics tied to protected classes. This can create disparate impact exposure if those transcripts inform performance reviews, hiring decisions, or disciplinary actions.

Attorney-client privilege:

Transcripts from notetakers are already surfacing in litigation. Even casual remarks from strategy or HR meetings can be pulled in, and once captured, they live on in ways spoken words do not.

This means that confidential legal conversations that would otherwise be protected may become discoverable evidence — a risk that should alarm any general counsel or legal department.

State-specific AI employment laws:

New York's Local Law 144 mandates bias audits before employers use automated tools in hiring, plus notice to candidates. Illinois has its own AI Interview Act. California continues to expand its AI accountability framework.

If your AI notetaker touches any part of the hiring or performance review process, you may already be out of compliance.


Cybersecurity Risks: The Attack Surface You Haven't Considered

Beyond privacy and employment law, AI notetakers introduce technical security vulnerabilities that deserve serious IT attention.

Cloud exposure is one of the key areas of risk, as many notetaker vendors lack basic cybersecurity maturity: no SOC 2, no GDPR alignment, and no strong encryption.

There is also an emerging and little-known threat vector:

AI-powered notetakers can provide attackers with a new vector for prompt injection attacks. Attackers may join meetings under the pretence of being prospective clients, job candidates, or partners to gain access. Once on the call, the attacker can attempt a prompt injection attack, either by speaking the prompt or by sending it through the chat.

Vendor viability is another concern.

Transcripts these apps create for customers can be mishandled, exposed, or become discoverable in litigation. Sensitive transcripts end up in third-party systems that the legal department has not reviewed, security has not secured, and procurement has not contracted.


Practical Tips: What IT Leaders Should Do Right Now

The good news is that you can significantly reduce your legal and security exposure without banning these tools outright — which, as legal experts note, is likely unenforceable anyway.

In many workplaces, employees already use AI notetakers, making outright bans ineffective and difficult to enforce. As a result, the most reasonable option may be to provide vetted AI notetakers that the organisation selects, configures, and controls.

Here's where to start:

A critical first step to any AI security and governance programme is to create and maintain an inventory of AI assets. On an ongoing basis, IT leaders must be able to answer: What generative AI services do we use in our organisation?

Developing a comprehensive AI acceptable use policy is critical for any organisation implementing AI governance. This policy should clearly articulate which AI tools are permitted, how they should be used, and what data protections must be in place.

A compliant deployment needs four baseline requirements before IT and legal sign off: SSO authentication via SAML, defined data retention and auto-deletion policies, a contractual AI training opt-out, and SOC 2 Type 2 certification.

Central data protection criteria for meeting assistants are: EU hosting, encryption in transit and at rest, automatic audio deletion after transcription, and no use of data for AI model training.

Recording consent rules vary by jurisdiction, and GDPR adds a layer that many AI meeting tools handle inconsistently. Under GDPR, recording a meeting where participants are EU data subjects requires a lawful basis, transparent notice, and in many cases explicit consent before the recording begins.

Organisations should establish clear internal guidance on how AI-generated meeting records interact with manually prepared notes, including which version controls in the event of inconsistency and how factual disputes will be resolved.

Some notetaker vendors shift responsibility for consent to their customers. They include indemnification clauses that make a customer pay in the event of any legal proceedings — pushing risk directly onto the enterprise that thought it was buying convenience.


Conclusion: Governance Is the Real Competitive Advantage

AI notetakers are not going away.

As one industry report put it, "AI note-taking is no longer just a productivity decision, it's a security decision" — and the takeaway is clear: AI note-taking is here to stay, but privacy and security are now part of its DNA.

The organisations that win are not those that resist adoption, but those that govern it intelligently.

AI notetakers are not passive utilities, but data collection systems running inside employment relationships, across jurisdictions, and in evolving legal environments.

Treating them as anything less is where organisations get into serious trouble.

If your organisation is using AI notetakers — or your employees are, whether you know it or not — now is the time to act. Conduct your AI asset inventory, build your acceptable use policy, and work with legal and procurement to establish a compliant vendor shortlist. The regulatory landscape is only tightening, and the cost of being reactive will far outweigh the cost of being prepared. Start your AI governance review today before the next lawsuit, the next audit, or the next data breach forces your hand.