An evidence-based examination of the AI meeting-assistant boom — who builds these tools, what they genuinely deliver, and what happens to your words after the meeting ends.
In the space of three years, AI note-takers have gone from novelty to near-default. A 2025 survey commissioned by meeting-software vendor Fellow found that 75% of professionals now use an AI note-taker in work meetings [3]. The market behind them is scaling accordingly: analysts at Grand View Research value the global AI meeting assistant market at roughly USD 3.5 billion in 2025 and project it to exceed USD 21 billion by 2033 [1].
Yet the same tools that free people from note-taking also create a new class of risk. Every recorded meeting becomes a searchable, exportable, subpoenable file held by a third party — and in some cases, raw material for training that third party’s AI models. In August 2025, a federal class action was filed against Otter.ai alleging exactly that: recording meeting participants who never consented, and using their conversations to train its models without disclosure [4][5].
This paper maps the vendor landscape, quantifies the productivity benefits, explains how large language models (LLMs) turn transcripts into queryable knowledge, examines the security and confidentiality exposures with documented cases and statistics, and closes with a practical framework for capturing the efficiency while containing the risk.
The AI note-taker is a product of three converging forces: the normalisation of video meetings after 2020, automatic speech recognition (ASR) reaching near-human accuracy, and the arrival of LLMs capable of summarising an hour of conversation into a page of action items.
The numbers describe a category in full acceleration. Grand View Research estimates the AI meeting assistant market at USD 3.47 billion in 2025, growing at 25.8% annually to USD 21.48 billion by 2033, with North America accounting for over 33% of revenue [1]. The narrower AI note-taking segment was valued at USD 623.5 million in 2025 and is projected by Precedence Research to reach roughly USD 3.5 billion by 2035 [2]. Otter.ai alone reports more than one billion meetings transcribed and crossed USD 100 million in annual recurring revenue in March 2025 [9]. Fireflies.ai reports over 20 million users across 500,000+ organisations — including, by its own account, employees at 75% of the Fortune 500 [10].
Accuracy explains part of the surge. In benchmark testing published in JMIR Mental Health, the best commercial ASR engines achieved a median word error rate of 8.9%, approaching the 7.6% achieved by professional human transcribers [11]. But performance varies widely in the wild: a 2025 systematic review found word error rates ranging from 8.7% in controlled dictation to over 50% in noisy, multi-speaker conversation [12]. The transcript, in other words, is good enough to rely on — and imperfect enough to check.
The market splits into three tiers: dedicated note-taker startups, platform giants embedding AI directly into their meeting software, and privacy-first challengers differentiating on data handling.
Otter.ai (founded 2016) is the category pioneer — its OtterPilot joins meetings as a visible participant, transcribes in real time, and answers questions about past conversations. Fireflies.ai takes a similar bot-based approach with deeper CRM and workflow integrations, and reports having processed more than two billion minutes of meetings [10]. Read.ai layers engagement analytics on top of transcription, while tl;dv and Grain target sales and product teams with clip-sharing workflows.
Microsoft ships Intelligent Recap and Copilot inside Teams, letting licensed users query a live meeting (“What did I miss?”) and receive AI-generated action items. Forrester’s Total Economic Impact analysis of Microsoft 365 Copilot projects an ROI between 112% and 457% for adopting organisations [13]. Google embeds Gemini in Meet with “take notes for me,” bundled into Workspace Business and Enterprise plans. Zoom offers AI Companion across its paid tiers. The strategic significance is bundling: for hundreds of millions of seats, the AI note-taker is no longer a purchase decision — it is a toggle.
A third wave differentiates on data handling. Fathom offers a free unlimited tier and holds SOC 2 Type II, HIPAA, and GDPR compliance, with training opt-outs for organisations [14]. Granola takes a different architectural route: it captures audio locally on the user’s device rather than joining the call as a bot — less visible to other participants, but also less dependent on cloud recording.
| Vendor | Product | Reported scale (company figures) | Stated position on training AI with customer content |
|---|---|---|---|
| Otter.ai | OtterPilot / Otter Notetaker | 25M+ users; 1B+ meetings; ~$100M ARR (2025) | Trains on de-identified recordings and transcripts by default; account-level opt-out. Practice now contested in federal court [5][15] |
| Fireflies.ai | Fireflies Notetaker | 20M+ users; 500K+ organisations | States it does not train models on customer data; zero-retention arrangements with its LLM sub-processors [10] |
| Fathom | Fathom AI Notetaker | Free unlimited tier; SOC 2 Type II, HIPAA, GDPR | No third-party model training; de-identified internal improvement with opt-out [14] |
| Zoom | AI Companion | Bundled with paid Zoom plans | After the 2023 terms-of-service backlash, states it does not use customer audio, video, or chat to train its or third-party AI models [7][8] |
| Microsoft | Copilot in Teams / Intelligent Recap | Bundled with Microsoft 365 Copilot licences | Publicly commits that commercial-tenant prompts and content are not used to train foundation models [13] |
| Gemini in Meet (“Take notes for me”) | Bundled with Workspace Business/Enterprise | Publicly commits that Workspace content is not used to train models outside the customer’s domain without permission |
The benefits are real and measurable, which is precisely why blanket bans fail in practice.
A human note-taker is a participant working at half capacity. Delegating capture to software returns that attention to the conversation. Fireflies claims its users saved 350 million minutes of meeting time in 2024 alone [10]; Otter estimates over USD 1.5 billion in cumulative time value across its user base [9]. Vendor figures deserve scepticism, but the direction is corroborated by independent adoption data: people do not adopt tools at a 75% rate unless the perceived payoff is immediate.
Decisions, commitments, and context that previously evaporated at the end of a call now persist as searchable records. For distributed teams across time zones, the asynchronous summary — not the live meeting — increasingly becomes the unit of organisational knowledge.
Real-time captioning serves deaf and hard-of-hearing colleagues; transcripts serve non-native speakers who process written language more comfortably than rapid conversation; and searchable records level the field for anyone who joined late, dropped off, or simply thinks better in review than in the room.
The transcript is becoming an input, not an output: CRM records update from sales calls, task managers ingest action items, and follow-up emails draft themselves. This workflow integration — not transcription itself — is where vendors now compete.
The pivotal shift of the past two years is from recording meetings to reasoning over them. Modern note-takers pipe transcripts through large language models to produce summaries, extract decisions and owners, detect sentiment, and — most consequentially — answer natural-language questions across an organisation’s entire meeting history: “What did we promise this client last quarter?” “Who owns the pricing decision?”
Vendors describe this as the “meeting knowledge engine.” Otter has begun positioning its accumulated conversation data as an enterprise knowledge layer, including integrations that expose meeting data to external AI assistants such as ChatGPT [9]. The trajectory is clear: agentic assistants that do not merely remember meetings but act on them — scheduling follow-ups, drafting documents, and briefing you before your next call.
Two caveats temper the enthusiasm. First, summarisation is not solved: research by Kirstein and colleagues found hallucinated content in 14–37% of AI-generated meeting summaries depending on the model [16]. An invented action item in a legal or clinical context is not a cosmetic bug. Second, the more valuable the aggregated corpus becomes, the more attractive it is — to attackers, to litigants, and to the vendor itself. That is the subject of the next two sections.
The moment your meetings become a queryable database, the question changes from “who was in the room?” to “who can query the room — forever?”
Twelve US states — including California, Florida, Illinois, Pennsylvania, and Washington — require all-party consent before a conversation is recorded [17]. If even one participant sits in an all-party-consent state, the safe course is consent from everyone. Legal commentators broadly agree that a bot named “AI Notetaker” appearing in the participant list does not, by itself, constitute legally sufficient notice or consent — consent must be informed: what is recorded, how it is used, who can access it, and for how long [17][18]. In the EU, GDPR raises the bar further, treating meeting recordings as personal data processing that requires a lawful basis and data-subject rights.
In August 2025, Brewer v. Otter.ai was filed in the US District Court for the Northern District of California. The plaintiff, who had no Otter account, was recorded on a February 2025 sales call because another participant ran OtterPilot. The complaint alleges Otter recorded non-subscribers without prior consent and used their conversations to train its speech-recognition and machine-learning models without disclosure — asserting violations of the federal Electronic Communications Privacy Act, the Computer Fraud and Abuse Act, and California privacy statutes [4][5]. NPR’s reporting framed the core question plainly: when an AI assistant joins a call, who exactly has agreed to what [4]?
The case remains unresolved, but its lesson is already operational: the person who benefits from the note-taker (the account holder) and the people bearing the privacy cost (everyone else on the call) are not the same people. Employment lawyers at firms including Littler and Fisher Phillips now advise clients to treat every external meeting with an AI attendee as a consent event requiring explicit notice [18][19].
Security is not only about breaches; it is about what the contract quietly permits. In March 2023, Zoom updated its terms of service to grant itself rights to use customer content for “machine learning, artificial intelligence, training, testing” — language that went largely unnoticed until August 2023, when public reporting triggered a backlash severe enough that Zoom amended its terms within days, ultimately stating that it does not use customer audio, video, or chat content to train its own or third-party AI models [6][7][8]. The episode established a pattern the industry has internalised: data-use rights expand quietly in legal documents and contract only under public pressure.
Surveillance changes speech. In the 2025 Fellow survey, 84% of AI note-taker users said they change what they say once they know the tool is listening, and 47% reported that a note-taker had captured or shared content they did not intend to be recorded [3]. Half of non-adopters cited privacy and security as their primary reason for staying away [3]. The tool that promises perfect recall can, at the margin, make the conversation itself less candid — a real if unmeasured tax on the creative and dissenting speech that meetings exist to surface.
Security teams report a further problem: employees connect note-takers to corporate calendars, email, and drives via OAuth grants that IT never reviewed — a phenomenon security vendors label “shadow AI” [20]. Each connected bot is a standing credential into the meeting stream of the organisation. Some organisations have responded with outright prohibitions — Derbyshire County Council in the UK, for example, bars external AI note-takers from its meetings [21] — but most analysts conclude bans are unenforceable in practice and that governed adoption beats prohibition [18][20].
The question executives actually ask is sharper than “is it secure?” It is: can the company providing the note-taker read, query, or learn from my meetings — and could my ideas end up benefiting someone else? The honest answer: it depends almost entirely on the vendor and the contract tier, and the differences are material.
Could a vendor build its own agent on the accumulated intelligence of millions of meetings? Contractually, most enterprise agreements now forbid it, and the major platforms — Microsoft, Google, Zoom — publicly commit not to train foundation models on commercial customer content [7][13]. But the commercial temptation is structural: conversation data is the scarcest, highest-value training resource left, and the vendors holding it are AI companies whose valuations depend on model quality. The Zoom episode demonstrated how quickly the boundary can move when no one is watching; the Otter litigation will test what happens when someone is. The prudent posture for a confidential organisation is to treat any vendor’s training right — present or future — as a negotiable, auditable contract term, not a settled default.
The evidence supports neither uncritical adoption nor prohibition. Bans fail because the productivity gain is real and the tools arrive through individual OAuth grants; laissez-faire fails because consent law, confidentiality, and model-training exposure are genuine liabilities. K3i recommends a governed middle path.
AI note-takers have crossed the adoption threshold from optional to ambient. The productivity case is genuine: recovered attention, institutional memory, and an emerging conversational knowledge layer that will shortly become agentic. The risk case is equally genuine: a consent regime the law has not settled, contracts that can quietly claim training rights, sub-processors the customer never sees, and a behavioural chill measurable in the data.
The organisations that win this transition will be neither the ones that ban the silent attendee nor the ones that ignore it, but the ones that govern it — one vetted tool, explicit consent, minimal retention, no-training contracts, and no-recording zones for the conversations that matter most. Efficiency and guardrails are not opposing forces; the guardrails are what make the efficiency safe to keep.
Disclaimer: This paper is provided for general information only and is based on publicly available sources as of August 2026, cited in the References section. It does not constitute legal advice. Litigation referenced in this paper involves allegations that remain unproven unless and until decided by a court. Company practices, policies, and terms of service change frequently; readers should verify current terms directly with vendors before making decisions.