By the Shadow AI Policy team
**Most companies already have an AI meeting notes problem — they just haven't found it yet.** AI transcription tools like Otter.ai, Fathom, and Gong are being added to employee calendars right now, often without IT approval, legal review, or any disclosure to the people on the call. This post covers what your AI acceptable use policy needs to say about meeting recording tools specifically: two-party consent laws, client call risks, transcript retention, personal versus corporate accounts, and when and how to disclose that a bot is in the room.The biggest legal exposure with AI meeting notes tools isn't data storage — it's recording consent. If an employee joins a call from California, Illinois, or another two-party consent state without disclosing the recorder, your company is potentially liable for wiretapping violations, regardless of where your company is headquartered. Get the disclosure rule right first, before you tackle anything else.
Most U.S. states follow a one-party consent rule for recording conversations: as long as one person on the call knows it's being recorded (typically the person hitting record), it's legal. But a significant number of states require that all parties consent before a conversation is recorded. These are called two-party — or more precisely, all-party — consent states.
As of 2025, the all-party consent states include California (Cal. Penal Code § 632), Florida (Fla. Stat. § 934.03), Illinois (720 ILCS 5/14-2), Maryland (Md. Code Ann., Cts. & Jud. Proc. § 10-402), Pennsylvania (18 Pa. Cons. Stat. § 5703), Michigan, Montana, Nevada, New Hampshire, Oregon, and Washington. Violations in California and Illinois carry both criminal penalties and civil liability — in California, statutory damages can reach $5,000 per violation or three times actual damages, whichever is greater.
The practical problem: you don't control where your employees or their meeting participants are located. An employee in Texas (one-party state) recording a vendor in Illinois (all-party state) without disclosure may still trigger Illinois law if the call has a connection to that state. Courts have taken different positions on which state's law applies, but the safest rule is: treat every external call as if all-party consent is required, and build your policy accordingly.
Your policy should explicitly state that no AI transcription or recording tool may be used on any call — internal or external — without first disclosing at the start of the call that a recording or AI-generated transcript is being made. This isn't just a legal hedge; it's the only operationally consistent rule you can actually enforce.
Recording an internal standup is a different risk profile than recording a call with a client, prospective customer, outside counsel, or regulated counterparty. When the other party is external, you layer on contract risk, confidentiality obligations, and in some industries, sector-specific privacy law.
Check your client contracts. Many master service agreements, NDAs, and vendor agreements include confidentiality clauses that cover oral communications. Automatically feeding a client call through a third-party AI transcription tool — storing it on Otter.ai's servers or Gong's cloud — may constitute a disclosure of confidential information under the terms of that agreement, even if no human sees the transcript.
In regulated industries, the exposure is sharper. Under HIPAA, if a call involves protected health information, routing it through an AI transcription service that hasn't signed a Business Associate Agreement (BAA) violates the HIPAA Privacy Rule (45 CFR § 164.502(e)). Otter.ai offers a BAA for enterprise plans; Fathom does not offer a HIPAA-compliant tier as of this writing. Gong has healthcare customers and can execute BAAs, but that requires an enterprise agreement — not the free or team-tier plan most employees use. Check each tool's current documentation before making compliance assumptions.
For financial services firms, FINRA Rule 4511 and SEC Rule 17a-4 require that certain business communications — including those related to securities transactions — be retained in a specific format and be retrievable by regulators. If an AI tool is summarizing or transcribing those calls, the summary may itself be a business record subject to retention rules. Your policy needs to name this explicitly for any employees in covered roles.
AI meeting notes tools don't just create a transcript — they create a persistent, searchable record of conversations that would otherwise have left no written trail. That has real implications for litigation holds, regulatory investigations, and data subject access requests under laws like the CCPA (Cal. Civ. Code § 1798.100 et seq.) and GDPR (Regulation (EU) 2016/679).
Under GDPR, a transcript of a meeting that includes identifiable statements made by employees or customers is personal data. That means it's subject to data minimization requirements (Article 5(1)(c)), purpose limitation (Article 5(1)(b)), and retention limits (Article 5(1)(e)). Storing every call transcript indefinitely in a third-party SaaS tool — which is the default behavior of most AI meeting note tools — almost certainly violates GDPR's retention limitation principle unless you've defined and enforced a specific retention period.
Your policy should specify:
Data residency matters too if you have EU employees or customers. Confirm whether your chosen tool stores data in the EU or offers an EU data residency option. Fathom, for example, processes data through U.S.-based infrastructure; that's relevant for any EU personal data that ends up in a transcript.
This is where most companies' AI policies fall short. An employee signs up for Fathom or Otter.ai using their work email — or sometimes their personal email — on the free tier. They use it to record and summarize every meeting they attend. The transcripts live in that employee's personal cloud account, not in any system your company controls.
When that employee leaves, those transcripts go with them. If there's a dispute, a litigation hold, or a regulatory investigation, your legal team has no way to retrieve or preserve that data. If the employee used a personal email to sign up, you may not even know the account exists.
This is the core of the shadow AI problem: employees using tools that touch company data through accounts your IT and legal teams can't see or control. Meeting transcripts are particularly sensitive because they capture not just what people typed, but what they said — including discussions of strategy, personnel, clients, and deals.
Your policy needs a clear rule: AI meeting tools may only be used through company-provisioned accounts, on approved platforms, with company-managed credentials. Personal accounts, even on approved tools, are not permitted for any meeting that involves company business. This applies even if the employee is paying for the subscription themselves.
If you're formalizing this now, the AI acceptable use policy template guide covers how to structure account ownership rules as part of a broader AUP framework.
Even where consent law doesn't technically require it, disclosure is the right default — and increasingly, it's becoming an expectation that participants will enforce themselves. Gong's notetaker bot, Otter.ai's OtterPilot, and Fathom's assistant all join calls as visible participants, but that visibility varies by platform, and many participants don't know what those bots do with the data.
Your policy should require a verbal or written disclosure at the start of any recorded meeting. For recurring meetings, a standing notice in the calendar invite is acceptable — but only if it's specific ("This meeting will be recorded and transcribed using [Tool]. A summary will be shared with [audience]."). Vague footer text doesn't cut it.
For external calls specifically, consider adding a standard disclosure line to calendar invites sent to outside parties. Something like: "This meeting may be recorded and transcribed using AI meeting assistance software for internal notes purposes. Please let us know if you'd prefer we disable recording." This gives participants a genuine opt-out, which both reduces legal exposure and builds trust.
The disclosure requirement isn't just legal hygiene — it's the mechanism that makes every other control in your policy work. If employees have to announce the recorder, they'll think twice before using a personal account or an unapproved tool to do it.
Build the disclosure requirement into your meeting workflow, not just your policy document. A policy that lives in a handbook doesn't change behavior; a required field in your scheduling template does. If your company uses a standard calendar or meeting platform, work with IT to make the disclosure a default — something employees have to remove rather than remember to add.
General AI acceptable use policies often miss meeting-specific rules. Here's what a policy covering AI meeting notes tools should address directly:
If you want to go beyond a checklist and build a policy that maps these rules to your specific industry and employee population, you can generate a tailored policy kit that covers meeting tools alongside your other AI use cases.
About Shadow AI Policy: We build AI acceptable use policy tools for HR and operations teams at 50–500 person companies. We publish guides on shadow AI, acceptable use policies, and AI governance, updated as regulations and AI tools change.
One-party consent means only one person on the call needs to know it's being recorded — typically the person doing the recording. Two-party (or all-party) consent requires that everyone on the call agrees to being recorded before it starts. The U.S. has both types of states, and all-party consent states like California, Illinois, and Florida carry real criminal and civil penalties for violations. Because you can't always control where participants are joining from, the safest default is to treat every call as if all-party consent applies and disclose the recording at the start.
No — and this should be explicitly prohibited in your policy. When an employee uses a personal account, the transcripts and data are stored in a system your company doesn't control, can't audit, and can't retrieve in the event of a legal hold or regulatory request. When the employee leaves, that data goes with them. Even if the tool itself is approved for company use, personal accounts create a gap in your data governance that's hard to close after the fact. Require company-provisioned accounts for all meeting tool use.
Yes, if the calls involve protected health information (PHI). Under the HIPAA Privacy Rule (45 CFR § 164.502(e)), any vendor that processes PHI on your behalf must sign a Business Associate Agreement (BAA). Not all AI meeting tools offer this: Otter.ai offers a BAA on enterprise plans, Gong can execute BAAs under enterprise agreements, but Fathom does not currently offer a HIPAA-compliant tier. Using a tool without a BAA to record calls that involve PHI is a direct HIPAA violation — it's not a gray area. Confirm BAA availability before approving any meeting tool for healthcare staff.
For most internal calls, a 90-day default retention period is a reasonable starting point — long enough to be useful, short enough to limit accumulating sensitive data. For calls subject to regulatory record-keeping requirements (like FINRA Rule 4511 or SEC Rule 17a-4 for financial services), retention periods are defined by the regulation, not by your internal preference. Under GDPR, indefinite retention of transcripts that include identifiable personal data almost certainly violates the data minimization and storage limitation principles in Articles 5(1)(c) and 5(1)(e). Set a retention period in your policy, configure it in your tools where possible, and document the rationale.
Tailored to your industry and the AI tools your team uses. Free preview, $79 one-time or $149/mo with monthly updates.
Generate my policy kit →