The board call ends, everyone says goodnight, and the meeting keeps recording. Two directors stay on the line to work through a personnel matter they deliberately did not want minuted. What they do not know is that the AI notetaker one of them switched on weeks ago is still in the room, still transcribing, and that a tidy summary of the part they thought was private will land in someone's inbox within the hour. Nobody at the association decided to put that bot on the call. Nobody can tell you, right now, where the transcript of it lives.
This is the quietest AI story in the sector, precisely because it did not arrive as a purchase. While we argued about which copilot to buy and whether the agents at the door could read our data, a different kind of bot walked in through the calendar. Otter, Fireflies, Fathom, Read, the transcription baked into Zoom and Teams and Meet: staff turned them on one free account at a time, and now they auto-join meetings, transcribe whoever is present, and file the record in a place the organization does not administer and sometimes cannot even see.1 One security vendor watched a single customer sprout 800 new notetaker accounts in ninety days.2 None of it went through IT. Most of it did not go through anyone.
The people in the room never agreed
Here is what separates an association from the software company running the same tools. Our meetings are full of people who do not work for us. Board members who volunteer their evenings. Chapter leaders. Committee members hashing out a bylaw. A candidate you are interviewing, a donor, a member with a grievance. None of them clicked your acceptable-use policy, because they are not your staff. And the way most of these tools treat consent is that the one person who added the bot is deemed to have agreed on behalf of everyone. The host says yes for a room that was never asked.
That design is now being tested in court. Otter.ai is facing a consolidated federal class action, In re Otter.AI Privacy Litigation, brought by people who say they were recorded and transcribed without agreeing to it, and whose words, the complaint alleges, were fed back into training the product.34 A judge heard the company's motion to dismiss in the spring of 2026 and, as of this summer, has not ruled.5 No court has found the practice illegal, and this is one suit against one vendor. But the theory being argued is simple, and it is not going away: that a bot quietly transcribing a call is the very thing decades-old wiretap statutes were written to reach.5
And those statutes are not uniform. Roughly a dozen states require that everyone in a conversation consent before it can be recorded, not just one party. The lists differ at the margins, but they consistently include California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania, and Washington.6 Illinois, where a great many associations keep their headquarters, is one of them. The moment a director dials into your board call from one of these states, the law that governs the recording may not be the one your headquarters sits under. I am not your lawyer, and this is not a reason to panic. It is a reason to know, rather than assume, what is being recorded and who was told.
Where the words actually go
Consent is the half of this people can at least picture. The half they cannot see is where the transcript goes afterward. When a notetaker summarizes a meeting, the transcript usually leaves your environment entirely. It is sent off to a large language model to be condensed, and on the default commercial tiers of most of these tools, that content can be retained by the provider for a period, and in some products used to improve the model.78 The finished transcript then rests in whatever account the staffer signed up with, frequently a personal one, scattered across a set of tools nobody in the organization has an inventory of.2 Your members' words about a contested program, a personnel decision, a candidate for office, now sit in a service you do not control, cannot search, and could not delete on request if a member ever asked you to.
That last point is the one that should sting for anyone who thinks of the association's data as an asset. We have spent two years insisting that member data belongs in a system of record you own. A meeting transcript is member data too, some of the most sensitive you will ever hold, and it is being created and stored in precisely the ungoverned, un-owned way we would never tolerate for the membership database. We locked the front door and left this window open.
The afternoon audit
You do not need a policy project or a new product to get in front of this. You need one afternoon and three questions, and not one of them requires IT or a line of SQL.
First, find out what is already running. Ask each team, plainly, which notetaker or transcription tool joins their calls, and look at your own recurring meetings for a bot sitting in the attendee list. You are not auditing what was approved. You are auditing what is switched on, which is almost always more.
Second, trace where the transcripts live and who can read them. Take the most sensitive meeting you run, the board's executive session, and follow one transcript end to end. Which tool made it, which account holds it, who else can open it, and can you delete it. The answer you want is a specific place and a short list of names. The answer that tells you you have a problem is "that is just someone's personal productivity app, not one of our systems," because that sentence means your members' words are somewhere the association cannot reach.
Third, change the default from silent to announced. The bot does not join until a human says, out loud at the top of the call, that an AI notetaker is running and asks whether anyone objects, and that exchange goes in the minutes. It costs nothing. It is not a technical control. It converts the whole consent question from a standing legal exposure into a ten-second habit, and in an all-party-consent state it is also, not incidentally, the thing that keeps the recording lawful.
Notice who runs every step of that. The executive director. The chief of staff. The person who chairs the board call. Not the data team. The people who own the risk here, whose board just got transcribed into someone's free account, are exactly the people who can act on it without waiting for anyone, which is the reverse of most of what I write about. For once the fix is not architectural. It is a decision about who is allowed in the room, and it is yours to make on a Tuesday.
Quick takes
The tidy irony is that the notetaker vendors are now selling the governance back to you as a feature. Botless capture, admin-controlled recording, retention you can configure, "we never train on your data" as a paid tier.8 Some of it is genuinely useful and worth buying once you have decided this matters. But the first and cheapest control is not a SKU. It is the sentence someone says at the start of the call, and no upgrade is a substitute for having asked the room.
Regulators are circling the same drain, slowly. The EU AI Act already classes AI used to monitor workers as high-risk, and US privacy regulators, California's in particular, are tightening the rules on automated tools that process what people say.9 None of it is settled, and none of it should be what moves you. If the prospect of a member asking "where did the recording of our meeting go" does not concentrate the mind, a compliance memo two years from now will not either.
This is also the most widespread form of shadow AI in the sector, and the least dramatic, which is exactly why it slips the net. It does not look like the cyber-poor, target-rich exposure I wrote about a couple of weeks back, but it is a cousin of it: a steady, unmonitored path by which your most sensitive conversations leave the building. No one drew that arrow on the security diagram, because no one bought the thing that draws it.
Worth a read
Mayer Brown, “AI Notetakers: Productivity Tool or Emerging Legal Risk?” A clear-eyed legal walkthrough of the exposure, written for people who have to decide policy rather than win a case. The place to start if you want the risk framed soberly.
Recording Law, the two-party consent states reference. A plain state-by-state table of who requires all-party consent, with the nuances (and there are several) called out. Keep it handy before your next multi-state board call.
Nudge Security, “Shadow AI is taking notes.” The clearest account of how fast these tools spread through an organization on their own, and why the storage sprawl, not the transcript itself, is the part that should worry you.
My guess is that the AI notetaker becomes the first place a lot of associations are forced to reckon with the governance they skipped, and not because a regulator made them. It will be a board member asking a question no one on staff can answer: where did the recording of our last executive session go, and who else has it. The organizations that can answer will be the ones who spent a single afternoon this quarter finding out, before the question was pointed.
Quick answers
Do we need everyone's permission to use an AI notetaker in a meeting?
In about a dozen US states, including Illinois, every party to a conversation must consent before it can be legally recorded, and an AI notetaker is a recording. In the other states, one party's consent can be enough. Because virtual meetings routinely cross state lines, the simplest safe practice is to announce the notetaker at the start of every call and note in the minutes that no one objected.
Where do AI meeting transcripts get stored, and is that a problem?
Usually in whatever account the staff member who enabled the tool signed up with, often a personal one, and the transcript is typically sent to an external language model to be summarized. On default commercial tiers that content can be retained by the vendor for a period and, in some products, used to improve the model. For an association it means sensitive member and board discussions can end up in a system the organization does not own, control, or search.
What is the fastest way to get a handle on AI notetakers without a big project?
Spend one afternoon on three things: ask each team which notetaker tools auto-join their calls, trace where the transcript of your most sensitive recurring meeting is stored and who can access it, and make it standard to announce the notetaker at the start of every meeting. None of it requires IT, new budget, or technical skill, and it turns an invisible risk into a short list of decisions someone can own.
From the Mind of Ravi Rooprai is a weekly column on association tech, data, and AI. Read the perspectives for the longer arguments behind it.
Researched with AI assistance and fact-checked against primary sources. The analysis, judgment, and writing are mine. How this column is made →