An unfamiliar name appears in the meeting lobby.
Otter Notetaker wants to join.
Or Fireflies. Or another AI meeting assistant.
Nobody on the call remembers inviting it.
That does not necessarily mean something malicious has happened. Many AI meeting tools can be connected to a calendar and configured to join eligible meetings automatically. Otter's current documentation, for example, says its Notetaker can auto-join Zoom, Google Meet and Microsoft Teams meetings after a calendar is connected. Fireflies has similar auto-join controls.
The useful question is not "Why is there a robot in my meeting?"
It is:
Who connected it, what will it capture, where will the result go, and should it be here for this meeting?
For a small business, those four questions are usually enough to turn an awkward surprise into a sensible decision.
First: do not admit an unexpected bot automatically
If an AI notetaker is waiting in the lobby and nobody can explain why it is there, leave it there while you check.
If it has already joined, the host - or in some platforms a co-host - can usually remove it while the team works out what happened. If you are not the host, ask the host to remove or deny it rather than assuming an ordinary participant can control the lobby.
This is not about treating every meeting assistant as dangerous. It is about avoiding accidental recording or transcription of a conversation before anyone has decided whether that is appropriate.
Third-party meeting assistants often join as participants. Otter says its Notetaker appears as a visible guest participant. Fireflies similarly requires its Notetaker to be admitted before it begins capturing a meeting.
That visibility is useful, but visibility is not consent. Treat it as a prompt to check rather than a reason to click Admit automatically.
Work out who actually invited it
The person responsible may not have invited the bot during this meeting.
A common route is much less dramatic:
- someone created an account with an AI meeting service
- they connected Google Calendar or Microsoft Outlook
- they enabled an auto-join setting
- the service later found a calendar event with a meeting link
- the notetaker turned up
So ask the simple questions:
- Whose name or account is attached to the bot?
- Who on the team uses this meeting service?
- Has anyone connected their work calendar to it?
- Is it configured to join all meetings, only meetings they host, or some other category?
- Was this particular meeting deliberately selected?
If the answer is "I tried it last month and forgot about it", you have probably found the cause.
That is also a useful reminder from our guide to an employee connecting an AI tool to work: the important control is often the connection made earlier, not the surprise you notice today.
Decide what the bot would actually capture
"Taking notes" sounds harmless.
In practice, the service may be processing much more than a few bullet points.
Depending on the product and settings, a meeting assistant may capture or produce:
- audio
- a transcript
- speaker names
- meeting summaries
- action items
- shared slides, screen content or presented material in some products
- chat or meeting metadata
- searchable records kept after the call
- automatically shared notes or integrations with other systems
Do not rely on the friendly product name.
Check the current vendor settings and documentation for the exact service and plan you use.
Then ask a more useful question:
Would we be comfortable deliberately sending this meeting to that service?
If the answer is no, the bot should not be in the room.
Three different kinds of AI notetaker
"AI notes" can describe several different setups:
- platform-native AI, built into Zoom, Teams or Google Meet
- calendar-connected participant bots, such as Otter or Fireflies, that join the meeting as a guest
- local or device-based capture, where software records or transcribes without adding a visible participant tile
Those models do not create the same visibility, permissions or storage path. A visible participant is helpful when it exists, but you should not assume every AI note-taking tool will appear in the participant list.
Not every meeting deserves the same treatment
A routine internal project catch-up is different from:
- a disciplinary meeting
- an HR conversation
- a medical or wellbeing discussion
- a client call involving confidential information
- a legal discussion
- a board meeting
- a recruitment interview
- a conversation containing passwords, credentials or sensitive technical information
That does not mean AI note-taking can never be used for sensitive meetings.
It means the decision should be deliberate rather than inherited from a blanket calendar setting.
A small business can make this much easier by agreeing a few meeting types where automatic AI note-taking is simply off by default.
For everything else, the host can decide case by case.
Tell people clearly when a meeting is being captured
A bot sitting in the participant list is not a substitute for a clear explanation.
For UK organisations, the ICO's small-business guidance says that recording online meetings can involve people's images and voices. It says organisations should have a valid purpose and lawful basis, and should tell people why the meeting is being recorded, what the recording will be used for, and how long it will be kept.
That is a useful practical standard even before you get into the detail of which law applies in another country.
A simple introduction is usually better than a buried privacy policy:
"We use an AI notetaker on this call to create a transcript and action summary. The notes are kept in our company account and shared with the project team. Is anyone uncomfortable with that?"
Your exact wording and legal basis may differ, but the principle is straightforward: people should not have to discover afterwards that their conversation was sent to a third-party AI service.
If your organisation has legal, regulatory or contractual requirements around recording, follow those as well.
Do not assume the meeting platform has handled consent for you
Zoom, Teams and Google Meet all have their own recording, transcription and AI features.
Those controls can be useful, but they are not automatically the same thing as a third-party bot.
For example, Zoom says participants are notified when Zoom's own meeting recording is started. Microsoft Teams can be configured by administrators so participants must explicitly agree before they are included in recording and transcription. That agreement setting is a policy option, not a universal default for every Teams tenant.
That does not mean every separate AI notetaker that joins as a participant is covered by the same native recording workflow.
Treat the third-party tool as its own service with its own:
- account
- permissions
- recording behaviour
- storage
- retention
- sharing settings
- privacy terms
- integrations
The safest approach is to verify what the bot itself does rather than assuming the video-call platform has solved the problem. A third-party bot appearing in the participant list may make the capture more obvious, but it does not itself prove that participants have been properly informed or that the organisation's requirements have been met.
Check where the notes go after the meeting
The risk does not end when everyone hangs up.
Ask:
- Who owns the AI meeting account?
- Is it a personal account or a company-managed workspace?
- Who can see the transcript?
- Is the summary automatically emailed or shared?
- Can people outside the company receive it?
- How long are recordings and transcripts retained?
- Can users delete them?
- Is the tool connected to Slack, Teams, a CRM, Drive or other systems?
- Does it use meeting content for model improvement or other purposes under this plan?
This is the same broader issue covered in what happens to your data after you send it to an AI. "The bot left the meeting" does not mean the data disappeared.
Native tools can have their own sharing controls too. Google Workspace, for example, lets administrators control Gemini note-taking and set defaults for who receives meeting notes, including hosts only, invited guests in the organisation, or all invited guests.
That kind of explicit sharing control is worth looking for whatever product you use.
Be careful with automatic sharing
A useful transcript can become a problem if it is distributed more widely than the original conversation.
Imagine a client call where the AI summary is automatically:
- attached to a calendar event
- emailed to everyone invited
- posted into a shared Slack channel
- pushed into a CRM
- made searchable by a wider team
The meeting itself may have been appropriately restricted while the generated notes are not.
So review both sides:
Who could hear the meeting?
and
Who can read the resulting artefacts?
Those audiences should make sense together.
If the bot joined the wrong meeting
If a meeting assistant has already captured a conversation it should not have, do not panic.
Work through it methodically:
- Remove or stop the notetaker.
- Identify the account that caused it to join.
- Check exactly what was captured.
- Check who the recording, transcript or summary was shared with.
- Delete or restrict the artefacts where appropriate and where the service allows.
- Turn off or narrow the auto-join setting that caused the problem. Disconnecting a calendar or disabling future auto-join does not necessarily delete transcripts or recordings already stored in the meeting service.
- If sensitive, personal, regulated or client-confidential information was involved, follow your normal privacy, security or contractual incident process.
The seriousness depends on what was actually recorded and where it went. Personal meeting-assistant accounts can be harder for a company to govern because an administrator may not have the same visibility or deletion controls they would have in a managed company workspace.
A three-minute internal catch-up accidentally transcribed into an approved company workspace is not the same problem as a confidential client conversation recorded into an employee's personal account.
Respond to the real exposure, not just the presence of the bot.
Auto-join should be a choice, not a default nobody remembers
Auto-join is convenient because it removes friction.
That is also exactly why it deserves attention.
Fireflies' current documentation lets users turn automatic joining off or switch to a model where the notetaker joins only when explicitly invited. Otter also exposes controls over which calendar meetings its Notetaker joins.
For many small businesses, our suggested starting policy is:
- internal routine meetings: auto-join may be acceptable if everyone understands the rule
- external/client meetings: manual decision by the host
- sensitive meetings: no AI notetaker unless there is a clear reason and approved setup
You do not have to use those exact categories.
The point is to avoid one person's old calendar preference silently deciding the recording policy for every meeting they attend.
Native AI notes can be easier to govern
There can be an advantage to using the AI features already built into your main meeting platform rather than adding another external bot.
Google Workspace administrators can centrally turn Gemini note-taking on or off and control default note sharing. Microsoft Teams provides organisation-level recording and transcription policies, including an option to require participant agreement.
That does not make native AI automatically "safe", and you should still check your account, data and retention settings.
But central controls can make it easier to answer basic questions such as:
- who is allowed to use the feature
- whether participants are notified or asked to agree
- who receives the output
- where the artefacts are stored
- how the organisation can turn the feature off
A third-party tool may offer equally strong controls, but you need to configure and manage them separately.
Give your team one simple meeting-bot rule
You do not need a policy document every time a new note-taking app appears.
Start with one rule people can remember:
Do not add an AI notetaker to an external or sensitive meeting unless the host has approved it and participants know the meeting is being captured.
Then add one owner.
That could be a director, IT provider, operations person or security lead who can answer:
- which meeting tools are approved
- which account staff should use
- whether auto-join is allowed
- which meetings are excluded
- what to do when a bot appears unexpectedly
For a small business, that is already useful governance.
If the meeting tool can read files or email as part of its workflow, the same scoping principles apply as in our guides to limited Google Drive access and limited email access. If people are pasting meeting notes or transcripts into another AI service afterwards, use the same decision process as Can I paste this into AI?.
A 60-second check when a bot appears
If an AI meeting assistant unexpectedly joins your next call, use this:
- Do we know which service this is?
- Who connected or invited it?
- Is this meeting appropriate to record or transcribe?
- Have participants been clearly told?
- Do we know where the transcript and summary will be stored and shared?
- If any answer is unclear, leave the bot out until it is.
That is not anti-AI.
It is simply the meeting equivalent of checking who you are letting through the door.
AI meeting notes can be genuinely useful. They can save people from frantic typing, make actions easier to find and help teams remember what was agreed.
But convenience works best when everyone knows who invited the notetaker, what it is doing, and where the conversation goes next.
