White Paper

The Silent Attendee: How Safe Are AI Note-Takers?

An evidence-based examination of the AI meeting-assistant boom — who builds these tools, what they genuinely deliver, and what happens to your words after the meeting ends.

Published August 2026 Author K3i Research Team Reading time 17 min
Back to White Papers

Table of Contents

  1. Abstract
  2. The Rise of the Silent Attendee
  3. Who Builds Them: The Key Players
  4. The Productivity Case: Why Adoption Is Exploding
  5. Beyond Transcription: LLMs and the Conversational Knowledge Layer
  6. The Security Question: Who Else Hears Your Meeting?
  7. Can Your Ideas Leak Into Someone Else’s Model?
  8. Efficiency With Guardrails: A Balanced Path Forward
  9. Conclusion
  10. References

1. Abstract

In the space of three years, AI note-takers have gone from novelty to near-default. A 2025 survey commissioned by meeting-software vendor Fellow found that 75% of professionals now use an AI note-taker in work meetings [3]. The market behind them is scaling accordingly: analysts at Grand View Research value the global AI meeting assistant market at roughly USD 3.5 billion in 2025 and project it to exceed USD 21 billion by 2033 [1].

Yet the same tools that free people from note-taking also create a new class of risk. Every recorded meeting becomes a searchable, exportable, subpoenable file held by a third party — and in some cases, raw material for training that third party’s AI models. In August 2025, a federal class action was filed against Otter.ai alleging exactly that: recording meeting participants who never consented, and using their conversations to train its models without disclosure [4][5].

This paper maps the vendor landscape, quantifies the productivity benefits, explains how large language models (LLMs) turn transcripts into queryable knowledge, examines the security and confidentiality exposures with documented cases and statistics, and closes with a practical framework for capturing the efficiency while containing the risk.

75% of professionals use an AI note-taker in meetings (Fellow, 2025)
$3.5B AI meeting assistant market in 2025, heading to $21B+ by 2033
84% say they change what they say when they know AI is listening
12 US states require all-party consent before recording a meeting

2. The Rise of the Silent Attendee

The AI note-taker is a product of three converging forces: the normalisation of video meetings after 2020, automatic speech recognition (ASR) reaching near-human accuracy, and the arrival of LLMs capable of summarising an hour of conversation into a page of action items.

The numbers describe a category in full acceleration. Grand View Research estimates the AI meeting assistant market at USD 3.47 billion in 2025, growing at 25.8% annually to USD 21.48 billion by 2033, with North America accounting for over 33% of revenue [1]. The narrower AI note-taking segment was valued at USD 623.5 million in 2025 and is projected by Precedence Research to reach roughly USD 3.5 billion by 2035 [2]. Otter.ai alone reports more than one billion meetings transcribed and crossed USD 100 million in annual recurring revenue in March 2025 [9]. Fireflies.ai reports over 20 million users across 500,000+ organisations — including, by its own account, employees at 75% of the Fortune 500 [10].

Accuracy explains part of the surge. In benchmark testing published in JMIR Mental Health, the best commercial ASR engines achieved a median word error rate of 8.9%, approaching the 7.6% achieved by professional human transcribers [11]. But performance varies widely in the wild: a 2025 systematic review found word error rates ranging from 8.7% in controlled dictation to over 50% in noisy, multi-speaker conversation [12]. The transcript, in other words, is good enough to rely on — and imperfect enough to check.

3. Who Builds Them: The Key Players

The market splits into three tiers: dedicated note-taker startups, platform giants embedding AI directly into their meeting software, and privacy-first challengers differentiating on data handling.

3.1 The Dedicated Specialists

Otter.ai (founded 2016) is the category pioneer — its OtterPilot joins meetings as a visible participant, transcribes in real time, and answers questions about past conversations. Fireflies.ai takes a similar bot-based approach with deeper CRM and workflow integrations, and reports having processed more than two billion minutes of meetings [10]. Read.ai layers engagement analytics on top of transcription, while tl;dv and Grain target sales and product teams with clip-sharing workflows.

3.2 The Platform Giants

Microsoft ships Intelligent Recap and Copilot inside Teams, letting licensed users query a live meeting (“What did I miss?”) and receive AI-generated action items. Forrester’s Total Economic Impact analysis of Microsoft 365 Copilot projects an ROI between 112% and 457% for adopting organisations [13]. Google embeds Gemini in Meet with “take notes for me,” bundled into Workspace Business and Enterprise plans. Zoom offers AI Companion across its paid tiers. The strategic significance is bundling: for hundreds of millions of seats, the AI note-taker is no longer a purchase decision — it is a toggle.

3.3 The Privacy-First Challengers

A third wave differentiates on data handling. Fathom offers a free unlimited tier and holds SOC 2 Type II, HIPAA, and GDPR compliance, with training opt-outs for organisations [14]. Granola takes a different architectural route: it captures audio locally on the user’s device rather than joining the call as a bot — less visible to other participants, but also less dependent on cloud recording.

Vendor Product Reported scale (company figures) Stated position on training AI with customer content
Otter.ai OtterPilot / Otter Notetaker 25M+ users; 1B+ meetings; ~$100M ARR (2025) Trains on de-identified recordings and transcripts by default; account-level opt-out. Practice now contested in federal court [5][15]
Fireflies.ai Fireflies Notetaker 20M+ users; 500K+ organisations States it does not train models on customer data; zero-retention arrangements with its LLM sub-processors [10]
Fathom Fathom AI Notetaker Free unlimited tier; SOC 2 Type II, HIPAA, GDPR No third-party model training; de-identified internal improvement with opt-out [14]
Zoom AI Companion Bundled with paid Zoom plans After the 2023 terms-of-service backlash, states it does not use customer audio, video, or chat to train its or third-party AI models [7][8]
Microsoft Copilot in Teams / Intelligent Recap Bundled with Microsoft 365 Copilot licences Publicly commits that commercial-tenant prompts and content are not used to train foundation models [13]
Google Gemini in Meet (“Take notes for me”) Bundled with Workspace Business/Enterprise Publicly commits that Workspace content is not used to train models outside the customer’s domain without permission

4. The Productivity Case: Why Adoption Is Exploding

The benefits are real and measurable, which is precisely why blanket bans fail in practice.

4.1 Recovered Attention and Time

A human note-taker is a participant working at half capacity. Delegating capture to software returns that attention to the conversation. Fireflies claims its users saved 350 million minutes of meeting time in 2024 alone [10]; Otter estimates over USD 1.5 billion in cumulative time value across its user base [9]. Vendor figures deserve scepticism, but the direction is corroborated by independent adoption data: people do not adopt tools at a 75% rate unless the perceived payoff is immediate.

4.2 Institutional Memory

Decisions, commitments, and context that previously evaporated at the end of a call now persist as searchable records. For distributed teams across time zones, the asynchronous summary — not the live meeting — increasingly becomes the unit of organisational knowledge.

4.3 Accessibility and Inclusion

Real-time captioning serves deaf and hard-of-hearing colleagues; transcripts serve non-native speakers who process written language more comfortably than rapid conversation; and searchable records level the field for anyone who joined late, dropped off, or simply thinks better in review than in the room.

4.4 Downstream Automation

The transcript is becoming an input, not an output: CRM records update from sales calls, task managers ingest action items, and follow-up emails draft themselves. This workflow integration — not transcription itself — is where vendors now compete.

5. Beyond Transcription: LLMs and the Conversational Knowledge Layer

The pivotal shift of the past two years is from recording meetings to reasoning over them. Modern note-takers pipe transcripts through large language models to produce summaries, extract decisions and owners, detect sentiment, and — most consequentially — answer natural-language questions across an organisation’s entire meeting history: “What did we promise this client last quarter?” “Who owns the pricing decision?”

Vendors describe this as the “meeting knowledge engine.” Otter has begun positioning its accumulated conversation data as an enterprise knowledge layer, including integrations that expose meeting data to external AI assistants such as ChatGPT [9]. The trajectory is clear: agentic assistants that do not merely remember meetings but act on them — scheduling follow-ups, drafting documents, and briefing you before your next call.

Two caveats temper the enthusiasm. First, summarisation is not solved: research by Kirstein and colleagues found hallucinated content in 14–37% of AI-generated meeting summaries depending on the model [16]. An invented action item in a legal or clinical context is not a cosmetic bug. Second, the more valuable the aggregated corpus becomes, the more attractive it is — to attackers, to litigants, and to the vendor itself. That is the subject of the next two sections.

The moment your meetings become a queryable database, the question changes from “who was in the room?” to “who can query the room — forever?”

6. The Security Question: Who Else Hears Your Meeting?

6.1 The Consent Problem

Twelve US states — including California, Florida, Illinois, Pennsylvania, and Washington — require all-party consent before a conversation is recorded [17]. If even one participant sits in an all-party-consent state, the safe course is consent from everyone. Legal commentators broadly agree that a bot named “AI Notetaker” appearing in the participant list does not, by itself, constitute legally sufficient notice or consent — consent must be informed: what is recorded, how it is used, who can access it, and for how long [17][18]. In the EU, GDPR raises the bar further, treating meeting recordings as personal data processing that requires a lawful basis and data-subject rights.

6.2 The Case That Crystallised the Risk

In August 2025, Brewer v. Otter.ai was filed in the US District Court for the Northern District of California. The plaintiff, who had no Otter account, was recorded on a February 2025 sales call because another participant ran OtterPilot. The complaint alleges Otter recorded non-subscribers without prior consent and used their conversations to train its speech-recognition and machine-learning models without disclosure — asserting violations of the federal Electronic Communications Privacy Act, the Computer Fraud and Abuse Act, and California privacy statutes [4][5]. NPR’s reporting framed the core question plainly: when an AI assistant joins a call, who exactly has agreed to what [4]?

The case remains unresolved, but its lesson is already operational: the person who benefits from the note-taker (the account holder) and the people bearing the privacy cost (everyone else on the call) are not the same people. Employment lawyers at firms including Littler and Fisher Phillips now advise clients to treat every external meeting with an AI attendee as a consent event requiring explicit notice [18][19].

6.3 The Zoom Precedent: Terms of Service as Attack Surface

Security is not only about breaches; it is about what the contract quietly permits. In March 2023, Zoom updated its terms of service to grant itself rights to use customer content for “machine learning, artificial intelligence, training, testing” — language that went largely unnoticed until August 2023, when public reporting triggered a backlash severe enough that Zoom amended its terms within days, ultimately stating that it does not use customer audio, video, or chat content to train its own or third-party AI models [6][7][8]. The episode established a pattern the industry has internalised: data-use rights expand quietly in legal documents and contract only under public pressure.

6.4 The Behavioural Cost

Surveillance changes speech. In the 2025 Fellow survey, 84% of AI note-taker users said they change what they say once they know the tool is listening, and 47% reported that a note-taker had captured or shared content they did not intend to be recorded [3]. Half of non-adopters cited privacy and security as their primary reason for staying away [3]. The tool that promises perfect recall can, at the margin, make the conversation itself less candid — a real if unmeasured tax on the creative and dissenting speech that meetings exist to surface.

6.5 Shadow AI and the Expanding Attack Surface

Security teams report a further problem: employees connect note-takers to corporate calendars, email, and drives via OAuth grants that IT never reviewed — a phenomenon security vendors label “shadow AI” [20]. Each connected bot is a standing credential into the meeting stream of the organisation. Some organisations have responded with outright prohibitions — Derbyshire County Council in the UK, for example, bars external AI note-takers from its meetings [21] — but most analysts conclude bans are unenforceable in practice and that governed adoption beats prohibition [18][20].

7. Can Your Ideas Leak Into Someone Else’s Model?

The question executives actually ask is sharper than “is it secure?” It is: can the company providing the note-taker read, query, or learn from my meetings — and could my ideas end up benefiting someone else? The honest answer: it depends almost entirely on the vendor and the contract tier, and the differences are material.

7.1 Four Distinct Exposure Paths

  1. Model training. Some vendors train ASR and language models on customer conversations by default, typically “de-identified” — Otter’s default posture, per its own documentation and the allegations now in litigation [5][15]. De-identification removes names from metadata; it does not remove your product roadmap from the words themselves.
  2. Sub-processor exposure. Most note-takers do not run their own frontier LLMs; transcripts transit third-party model APIs. The protective standard is a zero-data-retention agreement with those sub-processors — Fireflies, for example, states it maintains exactly that [10]. Absent such terms, your transcript may persist in a second company’s logs.
  3. Vendor insider and breach risk. A meeting corpus is a concentrated archive of strategy, pricing, personnel, and IP. SOC 2 Type II certification, encryption at rest and in transit, and short default retention windows are the table stakes that separate enterprise-grade vendors from hobby tools.
  4. Legal process. Transcripts are discoverable. A record that once lived in fallible human memory is now a timestamped exhibit — retained, by default, indefinitely on someone else’s servers.

7.2 The Aggregation Question

Could a vendor build its own agent on the accumulated intelligence of millions of meetings? Contractually, most enterprise agreements now forbid it, and the major platforms — Microsoft, Google, Zoom — publicly commit not to train foundation models on commercial customer content [7][13]. But the commercial temptation is structural: conversation data is the scarcest, highest-value training resource left, and the vendors holding it are AI companies whose valuations depend on model quality. The Zoom episode demonstrated how quickly the boundary can move when no one is watching; the Otter litigation will test what happens when someone is. The prudent posture for a confidential organisation is to treat any vendor’s training right — present or future — as a negotiable, auditable contract term, not a settled default.

8. Efficiency With Guardrails: A Balanced Path Forward

The evidence supports neither uncritical adoption nor prohibition. Bans fail because the productivity gain is real and the tools arrive through individual OAuth grants; laissez-faire fails because consent law, confidentiality, and model-training exposure are genuine liabilities. K3i recommends a governed middle path.

For Organisations

  1. Standardise on one vetted tool. Choose a vendor on evidence: SOC 2 Type II, GDPR (and HIPAA where relevant), contractual no-training commitments, zero-retention terms with LLM sub-processors, and admin-controlled retention.
  2. Turn consent into a workflow, not an assumption. Meeting invites should disclose recording; the host confirms verbally when external parties join; all-party-consent rules apply whenever any participant may sit in one of the twelve all-party states [17][18].
  3. Set retention to the minimum that serves the use case. A 30–90 day default converts a permanent archive into a rolling working memory and shrinks both breach and discovery exposure.
  4. Segment by sensitivity. Legal, M&A, personnel, and security-incident meetings should be no-recording zones by policy. The 84% behavioural-change finding [3] is reason enough: some rooms must stay candid.
  5. Audit the OAuth surface. Inventory which note-takers already hold calendar and drive scopes across the organisation, and revoke what was never approved [20].

For Individuals

  1. Announce and ask — before the bot joins, not after.
  2. Check your vendor’s training default and opt out where offered; assume anything said on a recorded call may be quoted back verbatim.
  3. Review summaries before sharing — with hallucination rates of 14–37% in meeting summaries [16], the unreviewed AI recap is a liability in your name.

For Vendors and Policymakers

  1. No-training-by-default for business content, with training as an explicit, revocable, compensated opt-in.
  2. Active consent capture from every participant — a join-screen acknowledgement, not a name in the attendee list.
  3. Standardised disclosure of sub-processors, retention, and training use in a one-page, machine-readable format — the “nutrition label” the category currently lacks.

9. Conclusion

AI note-takers have crossed the adoption threshold from optional to ambient. The productivity case is genuine: recovered attention, institutional memory, and an emerging conversational knowledge layer that will shortly become agentic. The risk case is equally genuine: a consent regime the law has not settled, contracts that can quietly claim training rights, sub-processors the customer never sees, and a behavioural chill measurable in the data.

The organisations that win this transition will be neither the ones that ban the silent attendee nor the ones that ignore it, but the ones that govern it — one vetted tool, explicit consent, minimal retention, no-training contracts, and no-recording zones for the conversations that matter most. Efficiency and guardrails are not opposing forces; the guardrails are what make the efficiency safe to keep.

10. References

  1. Grand View Research (2025). AI Meeting Assistant Market Size & Share Report, 2026–2033.
  2. Precedence Research (2026). AI Note-Taking Market Size and Trends, 2026–2035.
  3. Fellow (2025). State of AI Note-Taking Survey (vendor-commissioned; as reported in Saner.ai, “AI Note-Taking Statistics 2026”).
  4. NPR (August 2025). “Class-action suit claims Otter AI secretly records private work conversations.”
  5. Brewer v. Otter.ai, Inc., US District Court, Northern District of California (filed August 2025); case commentary, National Law Review.
  6. TechCrunch (August 2023). “Zoom knots itself a legal tangle over use of customer data for training AI models.”
  7. The Record, Recorded Future News (August 2023). “Zoom revises terms again to say it doesn’t use customer data to train AI models.”
  8. ISACA (2023). “Lessons Learned From a Controversial Terms of Service Update.”
  9. Otter.ai (2023–2025). Company announcements: one billion meetings transcribed; USD 100M ARR milestone.
  10. Fireflies.ai (2025–2026). Company security documentation and published usage figures.
  11. JMIR Mental Health (2023). Benchmark study of automatic speech recognition word error rates.
  12. PMC systematic review (2025). Speech-recognition accuracy across clinical and conversational settings.
  13. Forrester Consulting (2024). The Total Economic Impact of Microsoft 365 Copilot.
  14. Fathom (2026). Security and compliance documentation.
  15. Voibe Resources (2026). “Is Otter.ai Safe? Class Action, Two-Party Consent & Verdict.”
  16. Kirstein, M., et al. (2024). Study of hallucination rates in AI-generated meeting summaries.
  17. Recording Law (2026). AI Meeting Recording Laws by State: Complete Guide.
  18. Littler Mendelson (2025). “AI Transcription and Note-Taking Technologies: Seven Points for Employers to Consider.”
  19. Fisher Phillips (2025). “New Lawsuit Highlights Concerns About AI Notetakers: 7 Steps Businesses Should Take.”
  20. Nudge Security (2025). “Shadow AI is taking notes: the growing risk of AI meeting assistants.”
  21. Derbyshire County Council (2025). Staff guidance: “Please be wary about AI notetakers in online meetings.”

Disclaimer: This paper is provided for general information only and is based on publicly available sources as of August 2026, cited in the References section. It does not constitute legal advice. Litigation referenced in this paper involves allegations that remain unproven unless and until decided by a court. Company practices, policies, and terms of service change frequently; readers should verify current terms directly with vendors before making decisions.