Nudge Security worked with an enterprise customer earlier this year that ran a shadow-AI audit and found something specific. Over a ninety-day window, employees at that company had created 800 new AI-note-taker accounts. Not through IT. Not with approval. Through a viral OAuth pattern where one meeting attendee signs up, invites a note-taker bot, and the bot's calendar integration then asks the other attendees to grant it access to their own calendars going forward.
Ninety days. Eight hundred accounts. One tool.
If that sounds like a security posture problem, it is. If it sounds like a data governance problem, it is also that. And it sounds like a compliance problem because in most US states you are legally required to notify meeting participants that a call is being recorded, and a note-taker bot that joins itself to a meeting is not asking anyone's permission.
The actual question every business owner should ask right now: what is my team using, what does it capture, and where does the data go?
What AI note takers actually capture
The full audio of the meeting, obviously. That is the primary payload. Modern tools also capture:
- The transcript, timestamped and speaker-labeled
- The participant list (names, emails, sometimes titles pulled from calendar or LinkedIn)
- The screen share content (in some tools, with OCR of what was shown)
- The chat log
- Meeting metadata (calendar invite text, meeting title, recurring vs. one-off)
- Behavioral signals (who talked most, who interrupted, sentiment analysis in some tools)
The transcript is usually stored indefinitely by default. The audio may or may not be, depending on the tool. Screen captures are typically kept for a shorter window. All of it lives on the vendor's servers, not yours.
The three failure modes
Failure mode 1: consent. In most US states, informed consent from all recorded parties is required. A bot that joins because it was invited by one attendee does not have consent from the others. Some tools try to solve this with automated "this call is being recorded" announcements. Most owners have never checked whether that announcement actually plays for their bot, in every meeting, before any confidential content is discussed.
Failure mode 2: data residency. Free tiers of most note takers store data in whatever region is cheapest for the vendor. Paid enterprise tiers usually let you pick a region. For US-based businesses in regulated industries, having audio and transcripts sitting on servers in unspecified regions may create compliance exposure your team has never surfaced. For businesses subject to GDPR, the data-residency question is not optional.
Failure mode 3: training data. The most important question and the one most rarely asked. Does your meeting content get used to train the vendor's models? For free tiers of consumer-oriented tools, the answer is usually yes, buried in the terms of service. For paid enterprise tiers, the answer is usually no, but only if you check the setting. Zoom's default changed twice in the last year on this specific question. The tool your team signed up for a year ago may have different defaults today than it did then.
The vendor rundown
Not exhaustive. The ones that show up most often on business owner calendars.
- Otter.ai. Consumer origins. Enterprise tier is available. Free tier has been documented to use meeting content for model improvement.
- Fireflies.ai. Heavy CRM auto-attach. Popular for the same reason it is risky: it aggressively wires into Salesforce or HubSpot with an OAuth grant that scopes broadly.
- Fathom. Cleaner privacy story. Fathom explicitly does not train on customer data on paid tiers. Free tier terms are more permissive.
- Read AI. Automatic calendar integration is the specific pattern that produced the 800-account viral spread in the Nudge Security story.
- Zoom AI Companion. Built into Zoom. Default settings changed twice in the last twelve months on training data use. Check yours.
- Microsoft 365 Copilot Teams recap. Does not train on your data, per Microsoft's contractual commitments. Runs against your existing Microsoft 365 permissions and lives within your tenant boundary. This is the safest option for a Microsoft-heavy shop.
- Google Gemini for Workspace (Meet notes). Similar posture to Copilot. Does not train on your data on paid tiers.
Anything not on this list is likely worth an explicit look. There are dozens of newer entrants, and the safety posture varies wildly.
What to actually check today
Three things. All take about ten minutes each.
- Your own calendar. Search for any recurring invite that includes an unfamiliar bot as an attendee. "Otter.ai," "Fireflies," "Read.ai," "Fathom," "Notetaker" (some tools use the word directly). Any bot on your calendar that you did not personally add is one someone else invited.
- Your CRM auto-attach settings. Salesforce, HubSpot, and Pipedrive all have integration surfaces for note takers. Look at what is authorized to write meeting recordings into your CRM. This is where the "call transcript ends up on a lead record" problem lives.
- Your admin console, if you run Microsoft 365 or Google Workspace. Both have a view of which third-party OAuth apps have been granted access to user calendars and drive contents. This is where you catch the tool no one told you about.
The policy an owner should write
You do not need a fifty-page policy. You need one page that answers three questions.
- Which tool is our tool of record. Pick one and standardize. Copilot Teams recap if you are Microsoft-heavy. Google Gemini for Workspace if you are Google-heavy. A specific third-party if you have a real reason.
- Which meetings can be recorded. Internal team meetings yes, sensitive one-on-ones no, customer calls only with explicit consent, board meetings never. Be specific.
- Where the transcripts live. In your tenant, in a specific folder or system. Not on the vendor's cloud unless you have contractually confirmed retention and residency.
That is the whole policy. Distribute it once. Enforce it by removing unauthorized OAuth grants from your admin console.
Bottom line
The failure mode with AI note takers is not usually a data breach. It is a slow proliferation of tools nobody vetted, transcripts sitting on vendor servers nobody chose, and the eventual realization that a decade of institutional conversation ended up training somebody's model.
Fix that with three moves. Pick a tool of record. Audit your calendar and admin console for anything else. Write a one-page policy and stick to it.
For the broader picture on how permissions and data flow through AI tools you already own, see Microsoft put Copilot in the box and DLP for AI.