This week a video conferencing vendor spent several days explaining its own terms of service after users noticed language permitting customer content to be used for training machine learning models. Clarifications followed, then a revision. The specifics matter less than what the episode exposed: almost nobody, including the people who signed the agreement, knew what their existing terms said about the recordings sitting on that platform. And while the argument ran, the more immediate problem stayed where it has been all year — already in the meeting, already recording, and never procured by anyone in your organisation.
The AI in your meeting was not procured by you. It was invited by whoever sent the calendar invite
The governance discussion assumes the assistant is a feature you switch on. Increasingly it is a participant who arrives. A third-party notetaker joins through a guest link, appears in the participant list with a name like a colleague, records the audio of everyone present, produces a transcript and a summary, and files them in a workspace belonging to whoever connected it. That person may be your employee. It may equally be the counterparty's junior analyst, whose personal subscription now holds a verbatim record of your commercial negotiation. You have no contract with that vendor. You did not assess it. You cannot delete the recording. In many cases you cannot even establish which product it was.
Three categories, three different problems
The platform's own capability. Your conferencing vendor's recap and summary features. You have an agreement, administrative controls, retention settings and someone to ask about residency. This is the manageable case, and the one most governance effort is currently spent on. The third-party bot. No contract, no assessment, no administrative visibility, storage under an individual account, and a retention period set by a subscription you do not pay for. This is the category that matters, and it is almost entirely ungoverned. The personal recorder. A phone on the table running a transcription app. Invisible to every control you have, and increasingly common because the apps are good and free.
| Route | Custody question | Control question |
|---|---|---|
| Platform feature | Which agreement covers the recording? | Who sets retention and participant access? |
| Third-party bot | Whose account holds the transcript? | Can the organisation assess, restrict and delete it? |
| Personal recorder | Where does the recording go? | Was recording permitted and disclosed? |
Qualitative summary of this article's source text, not a measured outcome or performance estimate.
What the bot actually captures
Everything, including the parts you would never have put in writing. The five minutes before the agenda starts, when someone explains why the other supplier was dropped. The aside about a colleague's performance. The number the sales lead was not supposed to share yet. The client's frustration with their own management. Meeting recordings do not capture decisions; they capture conversations, and conversations contain material that nobody would have minuted. That record then sits in a searchable archive, indefinitely, under terms that vary by tier and that nobody in your organisation has read.
Consent, and why the notification banner is not it
A recording notice tells participants something is happening. It does not establish that they agreed, and it does not create a lawful basis for processing their personal data — which a transcript unambiguously is, for every person on the call, including your customer's employees who never accepted your privacy policy. In jurisdictions requiring all-party consent, a notification is specifically not sufficient. In European contexts, you need a basis, a retention period, a means of responding to access requests, and an answer to the question of who the controller is when the transcript lives in a third party's workspace. And the record is producible. A transcript of a meeting in which your team discussed a known defect, a competitor, or a customer's creditworthiness is exactly the document the other side will ask for in a dispute. Minutes were always a curated artefact. A transcript is not curated at all.
Three decisions to take this month
Can external notetakers join your meetings? Most platforms allow administrators to restrict unknown applications and control how guests join. The realistic answer for most organisations is allow with disclosure, block by default for defined meeting types. Can your people take notetakers into other organisations' meetings? This is the question nobody asks, and it is where you create exposure for someone else and reputational damage for yourself. How long is anything kept? The default across these tools is forever. An accumulating, searchable archive of every conversation your company has had is a liability that grows with time and delivers most of its value in the first fortnight. Ninety days covers almost every legitimate use.
The etiquette will settle within a year, and early adopters set it
Ask before the bot joins rather than announcing it once it has. Say how long the transcript is kept and who can see it. Make turning it off a one-sentence request that nobody has to justify. Do not let a tool that joins all your calls automatically walk into a meeting where its presence would be unwelcome. This costs nothing and is visible. Organisations that handle it gracefully will look considered. Organisations whose bot appears unannounced in a client's boardroom will look careless in a way that outlasts the meeting.
Practical Guidance for Meeting AI Governance Review
- Audit which recording tools are already joining your calls.
- Set platform controls for external applications and guest participants.
- Default external meetings to no recording, with explicit opt-in.
- Set a retention period of ninety days unless there is a reason.
- Write one paragraph of etiquette and circulate it to client-facing teams.
- Add recording and transcription terms to your standard confidentiality agreements.
- Check what your own vendors' bots do with your recordings.
- Tell people the transcript is discoverable in a dispute.
The Regional Angle
Three factors change the calculation here, and the first is not a compliance matter at all. Recording people without their consent is a criminal question in this region, not merely a regulatory one. Cybercrime legislation in the United Arab Emirates and comparable provisions elsewhere in the Gulf make unauthorised recording or photography of individuals and conversations an offence carrying fines and, in some formulations, custodial exposure. The framing matters because it changes who is at risk. A European privacy breach is an institutional problem handled by the company's counsel; an unconsented recording here can be a personal matter for the individual who ran the tool. An employee whose notetaker joins every calendar entry automatically, including a call with an external counterparty who was never asked, is not committing a policy violation that will be discussed at a governance forum. Brief your client-facing staff on that distinction specifically, because nobody reads it in the acceptable use document. The second concerns who you meet. A large share of consequential business here happens with government entities, sovereign and quasi-sovereign investors, family offices and family-owned groups, all of whom operate on discretion as a default rather than a preference. An unannounced AI participant in those meetings is not a technical breach; it is a signal that you do not understand how the relationship works, and the cost lands on the relationship rather than in a regulatory file. Automatic is not an excuse anyone will accept, and the explanation that the tool joins everything makes the impression worse rather than better. Maintain an explicit no-bot list by counterparty type, set external meetings to off by default, and make the affirmative decision to record a small deliberate act rather than a background setting. The third is a governance asymmetry inside multinational groups. Employee representative bodies, which in parts of Europe can stop workplace recording outright and routinely constrain it, do not exist in most Gulf workplaces. The practical result is that adoption here is faster and less contested, and the same group can end up recording freely in Dubai while being prohibited from doing so in Frankfurt. That produces an archive with strange gaps: the meetings you can most easily search are the ones in the jurisdictions with the weakest constraints, and any cross-border call inherits the strictest rule in the room whether or not anyone applied it. Set one group standard for calls with participants in multiple jurisdictions, pitched at the strictest applicable requirement, and accept the small loss of convenience. The alternative is an inconsistent record that is both operationally unhelpful and awkward to explain.
The objection worth taking seriously
The strongest objection is that this is an overreaction to something people genuinely like. Meeting assistants work. Attendees who used to spend the call typing now participate in it. People who missed a meeting can catch up in two minutes. Teams working across time zones finally have a usable record of a call they could not attend, and for staff working in a second language a transcript is a significant accessibility gain. Meanwhile the governance response — blocking tools, requiring approvals, shortening retention — is the familiar pattern of a security function removing something useful and offering nothing in return. All of that is true, and it is why the recommendation here is not to stop recording meetings. The distinction is between the sanctioned path and the unsanctioned one. Your platform's own capability, under your agreement, with your retention settings and your administrative controls, delivers nearly all of the benefit and almost none of the exposure. The target is the uncontracted third party holding a verbatim record of your commercial conversations in an account you cannot reach, on terms you have not read, for a period nobody has set. Deal with that category and you can be permissive everywhere else, which is the opposite of the usual outcome and considerably easier to defend.
Common Questions
Can we simply block all external recording bots?
Technically yes on most platforms, through controls on applications and guest participation. Whether you should depends on how often your counterparties bring their own, because blocking theirs creates friction in meetings you do not control.
Are transcripts personal data?
Yes, for every identifiable participant. That brings retention, access and lawful basis obligations, and it applies to the transcript held by a third-party tool as much as to the one in your own tenant.
What retention period is defensible?
Most organisations find that ninety days covers every genuine use. Anything longer should be a deliberate decision tied to a specific need, not a default nobody changed.
What should we expect over the next twelve months?
Expect more terms-of-service episodes like this week's, as vendors work out how to describe model training to customers who have suddenly started reading the agreement, and expect explicit opt-outs to become standard because the alternative is losing enterprise accounts. Expect platform administrative controls over external notetakers to improve quickly, since the demand is obvious. Expect the first prominent dispute in which a meeting transcript is produced as evidence, and expect it to change board attitudes faster than any policy. And expect recording and transcription clauses to appear in standard confidentiality agreements within the year, at which point this becomes a contract question rather than an etiquette one.
Meeting AI Governance Review — we find out which recording tools are already in your calls, set the platform controls and retention that make them safe, and give your client-facing teams a rule they can follow in the first thirty seconds of a meeting.
