The AI notetaker has become a corporate liability

The AI notetaker has become a corporate liability

Every meeting is now recorded and transcribed by an AI notetaker, but nobody knows where the files reside or who has copied them, says Richard Frost, Head of Technology Solutions and Consulting at Armata Cyber Security.

In August 2026, Dark Reading discovered a vulnerability in tl;dv’s backend that allowed an authenticated user to access meeting information belonging to other customers. The vulnerability put more than 180,000 meeting records across 80,000 or more users at risk. And it is one that can affect any number of companies that are using the more than 100 different notetakers on the market today. From Fireflies to Otter to Granola, these apps have moved into the business faster than the governance required to manage them. According to a Kolmogorov Law, one in three people in the United States use an AI notetaker, and more than 65% have said they didn’t offer consent. While there are privacy concerns that come with the use of the technology, there is also an increasingly pervasive level of risk. 

AI notetakers open up unexpected doors within the business. There’s the risk of confidentiality, especially when a meeting recording has not been cleared with all participants, and then there’s the risk of a data leak or breach. Every recorded meeting creates a trail of data that could, if found in the wrong hands, be a breach of POPIA and provide cybercriminals with access to information that could be used to access the business. At the board level, the exposure is even riskier because transcripts and AI-generated minutes can be used in legal proceedings or shared with the wrong people. And this doesn’t just come down to a potential breach of the notetaker’s site, but to disgruntled employees or internal threat actors accessing the data and sharing it. 

According to the Harvard Law School Forum on Corporate Governance, while the tools themselves have ‘matured quickly ’, the convenience of the AI and its access can turn ‘candid boardroom discussions into a lasting governance record.

The problem is that the notetaker has become as much a part of the average meeting as pen and paper were traditionally. The difference is that a minute-taker used to produce a summary someone had approved; the notetaker, on the other hand, produces a searchable and permanent word-for-word record of everything said, including the parts nobody would have chosen to write down. This could be a pricing tactic, a campaign discussed before launch – all information that could put a company at reputational risk at best, or impact a merger or critical sale at worst. 

Once the recording exists, anyone who was on the call can copy it, forward it or lose it, and the business doesn’t have a paper trail to detect where the information has gone or to whom. For example, what if a C-suite executive left the company to move to another firm? They could take the recordings with them, using the insights and data to enhance their new role or steal a proprietary idea. This is the one side of the AI notetaker coin. The other is the platform itself.  Most notetakers store transcripts centrally and feed them into other systems by default, so a file created for one meeting ends up searchable by people who were never let in the room. 

Banning notetakers isn’t the fix. They’ve become a useful and reliable commodity that allows teams to track calls, information, insights and tasks with relative ease and offer as many benefits as they do security risks. What companies need to do is to apply a level of discipline to their usage and add additional security tools like password access and encryption. The company has to make a deliberate decision about where a sensitive file lives and who can open it – this is key, because many companies make no equivalent decision about a transcript, even though it can carry more information than a single report. 

The goal is to treat the recording the same way you would a meeting. Decide before it starts who is allowed to keep a copy, where it will be stored, how long it lives for, and who gets access afterwards. Companies need to treat AI notetakers as a controlled data-processing system with an approved tool policy, clear meeting classifications that define what kind of meeting can or cannot be recorded, clear processes for consent and visibility, and vendor due diligence. Their use should also be managed within well-defined configuration standards such as workspace-level controls for recording permissions and multi-factor authentication. 

Protecting the data is essential, particularly as regulation and cybercrime become more onerous, and there is a key distinction between what a provider offers the business in its notetaker system and how the business configures and enforces its usage. You don’t have to ditch the tools; you just have to enforce policy, recording, retention and access rules to ensure security and minimise risk. 

Richard Frost, Head of Consulting at Armata Cyber Security.

Scroll to Top