AI meeting note-takers — the confidentiality problem nobody's talking about
Everyone's discussing whether staff should paste documents into ChatGPT. Meanwhile a note-taker bot is sitting in the meeting listening to everything, on somebody's personal account.
Published 26 July 2026
The AI conversation in most firms has focused on chat products — ChatGPT, Copilot, Claude and the like — and their handling of pasted documents. That focus is warranted, and this site has spent plenty of words on it.
Meanwhile, in almost every professional firm we speak with, a category of AI product has quietly gone from novelty to default without anyone assessing it: the meeting note-taker.
What has actually happened
Over the last eighteen months, tools like Otter, Fireflies, Read, Fathom, Grain and Sembly have become the standard way many professionals capture meetings. They join a Zoom, Teams or Google Meet meeting as a participant, record the audio, transcribe it, and produce a structured summary with action items and follow-ups. On top of those, the meeting platforms themselves — Zoom’s AI Companion, Microsoft Teams’ meeting intelligence, Google Meet’s transcription — have added similar native features.
For internal meetings this is a useful productivity tool. For meetings involving clients, patients, counterparties or witnesses, the analysis is quite different from what most firms have applied to it.
What actually happens to a meeting
Take a typical example. A senior lawyer joins a Teams call with a client to discuss a matter. Also joining the call is a note-taker bot — installed by the lawyer weeks ago, signed in with the lawyer’s personal Otter account, joining every meeting automatically.
Over the next 45 minutes:
- The audio of the meeting is transmitted to Otter’s infrastructure (US-based, unless a specific regional tier applies)
- A transcript is generated with speaker attribution
- A summary is produced, including “action items” the AI infers from the conversation
- The transcript and summary land in the lawyer’s Otter inbox, accessible from the app on personal devices
- The transcript is retained on Otter’s servers under whatever terms apply to the plan
The client’s confidential information — their commercial position, the legal issue, any concessions or admissions made during the discussion — is now stored on a third-party service, on a personal account the firm has no visibility of, indefinitely retained by default, and easily shareable via the app.
The client was not asked. The firm did not assess. The bot showed up as “Otter.ai” in the participant list and nobody thought about it.
The obligation lens
This is a disclosure to a third party in exactly the sense APP 8 and section 16C care about. The professional conduct implications for lawyers (confidentiality, arguably privilege), medical practitioners (health information), and financial advisers (client circumstances) are the same as for any other cross-border disclosure of client information — with the added feature that here you have also disclosed the entire tone, hesitation and unedited discussion of the client, in a way a document paste does not.
For meetings involving:
- Legal advice sessions — anything discussed may be privileged. The presence of a third-party transcription service could raise waiver questions.
- Clinical consultations — health information under the Privacy Act. Patient consent obligations are triggered.
- Investigation interviews — the highest-sensitivity workplace category. AI transcription in an HR investigation is a category error.
- Board and investment committee meetings — commercially sensitive discussion, sometimes market-moving, often with fiduciary implications.
- Negotiations — the party’s negotiating position captured in unedited detail.
…the “we use Otter for notes” line is not adequate as a compliance answer.
The counterarguments, honestly considered
There are two arguments people commonly make in defence of current practice, and both deserve a fair hearing.
“We use the enterprise tier, and it’s Australian-hosted”
Some of the major products offer enterprise tiers with regional data residency and stronger commitments on training, retention and data handling. Where a firm has properly deployed one of these — and where all staff are actually using it, not their personal accounts — this is a materially better position.
The caveats:
- The personal-account gap remains. Enterprise deployment does not stop staff signing in personal accounts.
- Australian hosting does not necessarily mean Australian inference. Some products host the transcript in Australia while sending the audio to overseas providers for the actual transcription and summarisation. Read each vendor’s technical documentation.
- Client consent obligations remain yours regardless of vendor tier.
“Everyone does this now — it’s a widely accepted practice”
Widely accepted is not the same as compliant, and “everyone does it” has never been a successful defence to a privacy or professional conduct complaint. The wide adoption reflects that the tool is useful, not that its data handling has been assessed by the professions.
Client consent
For any external meeting where AI transcription is used, informed consent is the minimum floor.
“Informed” is doing work in that sentence. A bot joining the meeting labelled “Otter.ai” is not consent. A verbal “hope you don’t mind if I take notes” is not consent for cloud AI transcription, because most clients hear “notes” and think of the lawyer typing.
Practical elements of proper consent:
- Told before the meeting starts (in the invite, or at the top of the call)
- Explicit that AI transcription is involved and what happens to the recording and transcript
- Recorded — either in the meeting notes themselves or in the engagement documentation
- Genuinely optional — the client can decline and the meeting proceeds without transcription
For matters involving vulnerable clients, family disputes, personal injury, criminal defence or any allegation-type material, our own view is that AI transcription should be off by default and used only where the client actively requests it. The productivity gain is not worth the exposure.
The on-premise version
The alternative that removes most of the analysis is capturing meetings on your own infrastructure. Audio is transcribed locally, summarisation happens locally, storage happens where you already store client material.
This is not a hypothetical: local speech-to-text and summarisation on modest hardware has become genuinely capable in the last two years, and it is now practical to run this pattern for a professional firm.
The productivity story is intact. The third-party disclosure is gone. Client consent conversations become straightforward because the honest answer is “the audio and transcript stay in our office, and are handled the same way as our written file notes”.
The action for the week
Look at the participant list from a recent client meeting. Is there a bot on it? Whose account signed it in? Where is the transcript now?
If you cannot answer those questions with certainty for your last five external meetings, that is the gap. It is a bigger and more common gap than the chat-AI-with-pasted-documents version most policies focus on, and it is largely uncovered by the safeguards firms have put in place for the more visible risk.
The good news: it is solvable. The step to solve it is a conversation about consent and about what infrastructure the transcription runs on. The step not to solve it is to leave a bot in every meeting and hope.
This article is general information about common obligations under Australian privacy and professional conduct rules. It is not legal, medical or financial advice and does not account for your circumstances. Obtain your own advice before acting on it.