A meeting bot shows up in the waiting room. Someone lets it in without thinking, because it has a friendly name and everybody else on the call is already used to seeing it. Twenty minutes later your team is discussing a client’s financial situation, a personnel problem, and a contract dispute, and all of it is being transcribed to a service nobody on the call has actually vetted.

We are not here to tell you to ban meeting transcription. It is genuinely useful, and for a lot of small teams it is the difference between decisions getting captured and decisions getting forgotten. But it creates a permanent written record of conversations that used to evaporate, and most companies adopt it without deciding who owns that record, where it goes, or how long it lives. Those questions are easy to answer in advance and painful to answer for the first time under a subpoena.

What the Bot Actually Creates

Start by being clear about what gets produced, because “notes” undersells it considerably.

  • A full transcript. Not a summary. A near verbatim record of everything said, attributed to whoever said it, including the offhand remark someone would never put in writing.
  • Often an audio or video recording. Depending on the tool and how it is configured, the transcript may be accompanied by the underlying media file.
  • Generated summaries and action items. Useful, and worth remembering that a summary is an interpretation. It can be confidently wrong about who agreed to what.
  • A searchable, shareable file. This is the part that changes the risk. A transcript can be forwarded, exported, and searched by keyword by anyone with access.

Once that file exists, it is a business record. It can be requested in litigation, exposed in a breach, or read by someone who was never in the room. That is not a reason to avoid the tools. It is a reason to treat them as a records decision rather than a convenience feature.

Where the File Lives, and How Long It Stays

Most people have no idea where their meeting files land. It is worth finding out for the specific platform you use, because the answer drives everything else. Microsoft Teams is a good illustration because its behavior is documented in detail.

Per Microsoft’s documentation, Teams recordings for regular meetings save to the meeting organizer’s OneDrive in a Recordings folder, even if the organizer did not attend. Channel meeting recordings go to the SharePoint team site document library instead, where permissions are inherited from the channel’s owners and members list. For one to one and group calls, the file lands in the OneDrive of whoever pressed record. Access defaults matter too: Microsoft documents that all meeting invitees except external participants automatically get a shared link, while external participants get no automatic access unless the organizer shares it with them deliberately.

Retention is the part that surprises people. Microsoft’s documentation states that Teams meeting recordings and transcripts have a default expiration of 120 days, configurable from one day up to 99,999 days, with an option to never expire. When items do expire they move to the recycle bin, and Microsoft notes that once purged from the recycle bin they cannot be recovered. Two lessons there. First, a default is a decision somebody made for you. Second, “it deletes itself eventually” is not a retention policy, and neither is “it keeps everything forever.”

Third-party note-taking bots are a different situation entirely. Their transcripts live on the vendor’s platform under the vendor’s terms, tied to whichever employee signed up. Confirm the current storage, retention, deletion and data use terms directly with each vendor, because these settings and the plans they belong to change frequently.

Consent Is Not a Formality

Recording a conversation is legally different from taking notes, and the rules are not uniform. As a general concept, some jurisdictions follow a one-party consent rule, where one participant knowing about the recording is sufficient. Others follow an all-party consent rule, where everyone on the call must consent. Multi state calls add a layer, because participants may be in places with different rules.

We are an IT company, not a law firm, so we will not tell you which rule applies to you. Confirm it with your attorney for your state and for the states your clients and staff call in from. What we will say is practical: build your process for the stricter standard. Announce recording at the start of every call, get an audible acknowledgment, note it in the meeting record, and give people a real option to decline. Doing that consistently costs about fifteen seconds per meeting and removes the entire question from your risk register.

Client, Privileged, and Sensitive Conversations

Some conversations should not be transcribed at all. Not because anything improper is happening, but because a written record creates obligations and exposure that outweigh the convenience.

  • Anything involving legal counsel. Confidentiality and privilege are questions for your attorney, and the safe default is no bot in the room.
  • Personnel matters. Discipline, terminations, complaints, compensation. A verbatim transcript of a difficult HR conversation is evidence, and it is rarely evidence in your favor.
  • Regulated client data. Health information, financial account details, and similar categories carry handling requirements that a general purpose transcription service may not meet.
  • Anything under a client confidentiality agreement. Check whether your contracts restrict recording or require notice. Plenty do, and plenty of people have never read that clause.
  • Strategy conversations you would not want quoted. Pricing, acquisitions, disputes. If you would not put it in an email, do not put it in a transcript.

Also worth naming: employees signing up for note-taking tools individually, with a personal account and a corporate calendar connection, is a textbook example of the problem we described in shadow IT. Nobody is doing anything malicious. They are trying to keep up. But your company data ends up on a platform you have no agreement with and no ability to delete from.

A Policy You Can Write This Week

This does not need to be a twelve page document. Six decisions, written down and shared, will cover the vast majority of the risk.

  1. Name the approved tool. One platform your company has actually reviewed. Outside bots do not get admitted to company meetings.
  2. State when recording is allowed, and when it is not. A short list of meeting types that are always off the record, using the categories above.
  3. Require an announcement and give people the ability to object. Scripted, every time, at the top of the call.
  4. Set a retention period on purpose. Pick a number that reflects how long you actually need meeting notes, then configure it rather than accepting the default.
  5. Decide who can access and share transcripts. Especially for external participants, who are handled differently by default in most platforms.
  6. Assign an owner. One person responsible for reviewing settings when the vendor changes them, which they will.

The Bottom Line

AI note-takers are helpful and they are a liability, and which one dominates depends entirely on whether you made decisions in advance. The tool is not the problem. Adopting it by accident is.

Treat the transcript the way you would treat any other business record: know where it lives, know who can read it, know how long you are keeping it, and know which conversations never get written down. That is a one afternoon exercise, and it ages well because it is about your process rather than any particular product. If you are working through AI adoption more broadly, we laid out an approach in how to actually prepare your team for AI without the hype.

We help businesses across Denton County configure meeting recording and retention properly, get unapproved bots out of company calls, and write policies people will actually follow. If meeting transcripts are piling up somewhere and nobody is sure where, that is worth an hour of our time and yours. Contact us today.


Sources:

Comments are closed

This website uses cookies and asks your personal data to enhance your browsing experience. We are committed to protecting your privacy and ensuring your data is handled in compliance with the General Data Protection Regulation (GDPR).