The Bot Joined the Call Before Anyone Agreed to Be Recorded
AI notetakers were adopted the way calendars are adopted — one person at a time, with no procurement event. But a notetaker is not one act. It is a recording, potentially a voiceprint, and always a disclosure to a vendor, and each of those is governed by a different statute with a different consent standard.
Three Statutes, One Bot
Teams evaluate notetakers as an AI question and get the sequencing backwards. The AI question — what the model does with the content — is the third one to arrive. The first two are older than the category and have real damages attached.
Why the Consent Map Is Not a Map
The familiar advice is to check whether you are in a one-party or all-party state. That framing works for a phone call between two people in one place and fails for a video meeting, because a meeting does not have a location. It has as many locations as it has participants, and the participants change per occurrence of a recurring invite.
The prevailing conservative reading — and the one most counsel land on — is that the strictest applicable rule governs the whole conversation. That is why a per-meeting legal analysis is unworkable in practice: the sales rep who books a call at 4pm is not going to determine which state each attendee is sitting in, and if your control depends on them doing so, you do not have a control. Design for the strict case as the default and treat the permissive case as an optimisation you probably never need.
The Question to Ask Your Vendor, Precisely
"Do you collect biometric data?" gets a no from nearly every notetaker vendor, and the answer is frequently sincere and still unhelpful, because the vendor is answering about identification and you are asking about enrolment. The question that separates the products is narrower:
Does the product create a persistent per-speaker voice model that is reused to identify the same individual in a later, unrelated meeting — and if so, is that model stored after the meeting ends, for how long, and can it be disabled per tenant?
A tool that labels speakers using only the conferencing platform's channel metadata is doing bookkeeping. A tool that recognises an unlabelled voice on a new call has an enrolled template. The first is a transcription product. The second is a biometric one, and in Illinois it needs written consent obtained before collection, which a bot joining a call cannot obtain from an external participant.
Controls That Live at the Calendar Layer
Every effective control here operates before the meeting starts, because consent obtained after the first sentence is not consent to the first sentence. Ranked by yield relative to effort:
Most notetakers can be configured to auto-join internal meetings only, keyed on whether any attendee is outside your domain. This single setting removes the large majority of consent exposure without asking any employee to make a judgment call, and it is usually a tenant-level toggle rather than a project.
A standing line in your scheduling-link templates stating that meetings may be recorded and transcribed, with a contact for opting out, puts the notice before the conversation and produces an artefact you can retrieve later. Scheduling tools support template text; a one-time edit covers every future booking.
Where the platform can play or display a start-of-recording notice, enable it. It is the closest thing to the announcement standard that older recording practice relied on, and it demonstrates that participants were told before they spoke rather than after.
Indefinite is the default in most of these products and is a decision by omission. Pick a number that matches how long the notes are actually useful — commonly far shorter than a year — and confirm it applies to transcripts and derived summaries, not only to the audio file.
Carve out hiring interviews, performance conversations, workplace investigations and anything with counsel present. These are the meetings where a verbatim record is most damaging and where the participant is least free to object, which is exactly the combination a regulator or plaintiff looks for.
The Copy Problem
One meeting rarely produces one artefact. Audio sits with the conferencing platform. The transcript sits with the notetaker. A summary gets posted into a chat channel, often a broad one. Action items land in a project tracker. And the transcript is typically embedded into a vector index so the vendor's search feature can answer questions about past meetings.
That last copy is the one that breaks deletion promises. Removing a transcript from a user-facing list does not necessarily remove its embeddings from an index, and vendors differ substantially in whether they treat that as part of a deletion. It is a fair question to ask in writing, and the answer belongs in your record of processing rather than in a support ticket someone closed.
Frequently Asked Questions
Is it legal to have an AI notetaker join a meeting?
Joining is not the problem; recording is. Federal wiretap law and most states permit recording where one party to the conversation consents, and the employee who invited the bot supplies that consent. A material minority of states require consent from every participant, and a call with one participant in California, Florida, Illinois, Pennsylvania, Maryland or Washington is generally treated under the stricter rule. The practical consequence is that a bot which is lawful on an internal standup becomes a live exposure the moment an external attendee joins from the wrong state.
Does the bot showing up in the participant list count as notice?
It is evidence, not consent, and the two are frequently confused. All-party consent statutes ask whether each participant agreed to being recorded, and a name in a sidebar that a participant may never look at is a weak foundation for arguing they agreed. The stronger posture is an audible or on-screen announcement at the start plus a standing disclosure in the calendar invitation, because both produce a record of what the participant was told before they spoke.
Do AI notetakers create biometric identifiers?
Sometimes, and the answer turns on a product feature rather than on the recording itself. A tool that merely transcribes audio produces text. A tool that performs speaker diarisation by building a reusable voice profile so it can recognise the same person across future meetings is doing something much closer to what Illinois BIPA, Texas CUBI and the Colorado and Washington biometric provisions describe as a voiceprint. That distinction is a vendor configuration question, and it is worth answering in writing before deployment rather than after a demand letter.
Can we rely on the meeting platform's own AI feature instead?
It removes a vendor from the chain, which helps with the disclosure and subprocessor problem, and it does nothing about consent. A first-party summarisation feature inside your conferencing platform records the same conversation under the same statutes as a third-party bot. What it does change is your paper: the recording lives under an agreement you already negotiated, retention is governed by settings you already control, and there is no new subprocessor to add to a DPA.
What happens to the transcripts in litigation?
They become discoverable business records, which is the exposure that surprises people most. Before notetakers, a meeting produced whatever a participant chose to write down. Now it produces a verbatim account of the hedged remark, the personnel discussion and the pricing conversation, retained indefinitely by default, and searchable. None of that is unlawful. It simply means the retention setting is now a litigation decision, and almost nobody treats it as one.
Is a line in the employee handbook enough for internal meetings?
For internal meetings among employees in one-party consent states, generally yes, and a clear notice plus continued participation is the ordinary approach. It is weaker where employees are in all-party states, weaker again where the discussion is a performance review or an investigation, and it collapses entirely for external participants who never saw your handbook. Handbook language is a floor for the internal case, not a control for the external one.
What about recording a job interview?
Treat it as the highest-risk category. It combines an all-party consent question with a candidate who is not an employee and has no realistic ability to object, and in some jurisdictions it collides with AI hiring rules that attach obligations to automated analysis of candidates. If the tool does anything beyond transcription — scoring, sentiment, ranking — the recording question is no longer the largest one. Many organisations conclude the safest configuration is transcription off for interviews entirely.
Does deleting the recording solve the retention problem?
Only if the deletion reaches every copy, and it usually does not on the first attempt. A single meeting commonly generates audio at the platform, a transcript at the notetaker, a summary posted into a chat channel, action items pushed into a project tool, and an embedding inside a vendor's search index. Deleting the recording while the summary sits in a public channel and the embedding remains in the index leaves most of the content in place. Ask vendors specifically what a deletion request removes and what it leaves behind.
Start With the Auto-Join Setting
Of everything above, one tenant setting does the most work: stop the bot from joining meetings that contain an external attendee. It removes the all-party consent problem, the external-participant biometric problem and most of the subprocessor problem in a single change, and it does not require a policy, a training session or a judgment call from anyone booking a meeting.
Then set a retention number, exclude interviews, and put one line in your invite template. That is an afternoon of work covering the exposures that carry statutory damages.