AI notetakers, the software bots that join your video calls and spit out a meeting summary minutes after the call ends, have become a standard fixture in business meetings. The time savings are real. The legal and data risks are equally real, and most companies are not thinking about them.
The core issue is simple: when a notetaking bot joins your call, everything said becomes data sitting on someone else's server. That includes strategy discussions, personnel matters, client information, and anything said off-the-cuff that you would not want written down. Text is cheap to store and easy to search, which means all of that stays accessible long after you have forgotten about the meeting.
Some of the most popular tools have faced serious legal challenges over what they do with that data. A class action lawsuit filed in August 2025 alleged that Otter.ai recorded conversations involving people who never agreed to be recorded and then used those recordings to train its AI models. The court consolidated the claims in October 2025, and the case is ongoing. Otter.ai's position is that the responsibility for getting consent sits with the person who deployed the bot, not with Otter itself. That is a common pattern: several notetaker vendors include contract terms that push the legal liability back onto the businesses that pay for the software.
The voiceprint issue is less obvious but worth understanding. To distinguish who said what, most notetaking tools build a unique acoustic profile for each speaker, essentially a voice fingerprint. Voice fingerprints are already used by banks to verify customer identity over the phone. If that data leaked or was sold, someone could use it to impersonate you in a financial context. Illinois has a law requiring written consent before any tool creates such a profile. Most companies using notetakers have no policy on this at all.
There is a legal angle that affects anyone who shares sensitive discussions with a lawyer. A New York federal judge ruled earlier this year that a defendant had lost the protection of attorney-client privilege on documents he had shared with Anthropic's Claude, because sharing them with a third party broke the confidentiality requirement. The same logic can apply to meeting transcripts that pass through a notetaking vendor's servers.
Harvard University banned third-party AI meeting assistants from its internal meetings in February 2025, allowing only tools covered by specific contractual protections. Johns Hopkins did the same, asking staff to disable accounts with services like Otter.ai and Fireflies immediately. These are not small, cautious institutions: they are organizations that have legal teams and have done the analysis.
For any business operator, the questions worth asking before the next call are practical ones. Does this tool use your recordings to train its AI? Where are the recordings stored, and for how long? Who bears the legal responsibility if someone in the call later claims they were recorded without consent? A vendor that cannot answer those questions plainly is a risk you are carrying without knowing it.
Not all tools are equal on this. Some, including Fireflies and Fellow, state explicitly that they do not use meeting content to train their models. Others process recordings entirely on your own device, so nothing leaves your system. The right choice depends on what kind of meetings you are having and who is in them. The important shift is treating this as a decision, not a default.