AI Note Taking Assistance - Security Considerations
Security, Assurance, and Governance Framework for AI Meeting Assistants in the UK Public Sector
Version: 01 Initial Draft for Comment
Date: 27th July 2026
This is an incomplete initial Draft guidance note please suggest additional contents required.
Background
The rapid integration of artificial intelligence (AI) meeting assistants across public sector organisations in the United Kingdom has created a complex intersection of productivity benefits and severe information security, assurance, and governance vulnerabilities.[1, 2] Tools such as Otter.ai, Fireflies.ai, and Read.ai utilise automated software bots that automatically connect to synchronized calendars, join virtual meetings, record audio, transcribe conversations, and generate summaries using cloud-hosted large language models (LLMs).[2, 3, 4]
While the productivity gains are documented—highlighted by a landmark UK government trial involving 20,000 civil servants across 50 departments where generative AI tools (such as Microsoft 365 Copilot) saved users an average of 26 minutes per day, equating to nearly two working weeks per person annually—the unmanaged deployment of these technologies introduces acute security risks.[5, 6, 7]
This organic, employee-led adoption occurs primarily as "Shadow AI," where staff authorize third-party calendar integrations or install browser extensions without corporate procurement, IT approval, or Data Protection Officer (DPO) oversight.[2] Consequently, highly sensitive, legally privileged, or protected public sector data is exfiltrated to external infrastructures, raising critical questions regarding data sovereignty, legal compliance, and network integrity.[1, 2, 4]
Technical Mechanisms and Information Assurance Vulnerabilities
The architectural design of third-party AI meeting assistants fundamentally alters the security perimeter of virtual communications.[4] Once authorized via a user’s calendar or invited via a meeting link, these bots act as unverified participants, capturing and streaming live media to external cloud servers.[4, 8] This ingestion process creates several primary technical and assurance vulnerabilities:
Creation of an External Corporate Memory: Spoken conversations regarding policy formulation, legal strategies, financial budgets, and personal health data are converted into highly structured, indexable, and searchable text databases hosted on servers outside the control of the hosting public body.[4] While raw audio files are computationally difficult to exploit at scale, structured text transcripts make it trivial for threat actors to identify strategic vulnerabilities, internal conflicts, or sensitive administrative plans if the third-party provider suffers a data breach.[4]
Agentic AI System Exposure: Many contemporary meeting tools are evolving into agentic AI systems that possess autonomous capabilities, such as scanning user calendars, reading corporate directories, sending automated summaries, and executing API-driven workflows across connected business applications.[9, 10, 11] If these agents are granted over-privileged access or interact with compromised external networks, a single point of failure can lead to cascading security incidents, such as unauthorized data manipulation or lateral movement within public sector tenants.[9]
Input Validation and Infrastructure Gaps: Unvetted meeting bots often bypass strict software risk assessments (SRAs), operating with default, insecure configurations.[1, 12] The NCSC highlights that organizations deploying unverified AI capabilities remain vulnerable to prompt injection attacks, where malicious instructions embedded in a participant's shared screen or chat messages are processed by the AI bot, causing unexpected behaviours or data exposure.[12]
NHS_mail and Shared Tenancy Risks: In shared cloud environments such as the NHS, where there are over 1.2 million active users on NHS_mail, improper configuration of video-conferencing files can have massive consequences.[13] For instance, if the privacy settings of a Microsoft Teams recording or transcript are changed from "Private" to "Public," the content immediately becomes accessible and editable to all NHSmail users, illustrating how easily automated outputs can scale human errors.[13]
UK Legal, Data Protection, and Regulatory Landscape
Public sector organizations must operate in strict compliance with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018 (DPA), and the Data (Use and Access) Act (DUAA).[14, 15, 16, 17] The deployment of AI meeting assistants creates distinct compliance challenges under these legislative frameworks:
Lawful Basis and Public Task
Under UK GDPR Article 6, public bodies typically process personal data under the lawful basis of "public task" to fulfil their statutory duties.[16, 18] Relying on an AI tool to transcribe a meeting does not require a new lawful basis if the underlying purpose of the processing remains unchanged.[16] However, a separate lawful basis is required if the data is shared with the AI vendor for secondary purposes, such as product improvement or model training.[16] Because many consumer-grade platforms reserve the contractual right to utilize customer transcripts to train their foundation models, public sector bodies are frequently in violation of UK GDPR when deploying unassured tools.[1, 2, 19]
The Data (Use and Access) Act
The Data (Use and Access) Act 2025 (DUAA)* reshapes how automated decision-making (ADM) and profiling are handled.[15, 20] While the Act stream-lines legitimate interests and reduces restrictions on purely automated decisions in standard B2B contexts, these flexibilities are strictly prohibited when processing "special category" data, such as health, racial origin, or biometric information.[15, 20] Because meeting discussions in public sectors (especially within the NHS, local authorities, or law enforcement) routinely touch upon special category details, any ADM or profiling driven by AI meeting transcripts remains subject to rigorous Article 22 restrictions, requiring human oversight, the right to contest decisions, and clear explanations of the logic involved.[15, 16, 21]
*(https://ico.org.uk/about-the-ico/what-we-do/legislation-we-cover/data-use-and-access-act-2025/the-data-use-and-access-act-2025-what-does-it-mean-for-organisations/)
Biometric Data and Voiceprints
Advanced speech diarisation models analyse vocal characteristics—such as pitch, tone, and pacing—to attribute spoken text to specific individuals.[21, 22] When these voice characteristics are processed to identify an individual, they constitute biometric data.[21] Under UK GDPR and international frameworks, the creation and storage of "voiceprints" require explicit, written consent.[21] The unauthorized generation of voiceprints by AI meeting bots has triggered substantial class action litigation under biometric privacy acts, highlighting a severe litigation risk for organizations that allow these bots to record meetings unchecked.[21, 23]
Wiretapping and Electronic Recording Laws
Under the post-Brexit regime, the legal requirement for consent remains a cornerstone of recording communications.[10, 24, 25] In jurisdictions requiring all-party consent, deploying a bot that automatically records a meeting without obtaining explicit, opt-in confirmation from every single participant violates electronic recording laws, exposing the hosting organization to civil and, in severe cases, criminal liabilities.[2, 10, 21]
Covert Device Capture and International Sub-processors
Tools like "Granola" operate on a "bot-free" model, meaning they do not join calls as visible participants.[26] Instead, they capture the host's microphone and system audio directly via device-level drivers.[26] While this model avoids the disruption of visible bots, it presents severe compliance hazards.[26] Because there is no visible bot in the meeting room, other participants receive no automatic notification that recording is occurring.[26] In many jurisdictions, such as Germany under § 201 StGB* (violation of the confidentiality of the spoken word), covert recording of non-public spoken words carries a criminal penalty of up to three years' imprisonment.[26] Furthermore, Granola relies on US-based sub-processors (such as Deepgram and AssemblyAI for transcription, and OpenAI and Anthropic for summaries), meaning transcripts are transferred to the United States.[26] This triggers the requirement for a complete Transfer Impact Assessment under UK GDPR Schrems II principles to evaluate the risks of US intelligence surveillance laws.[26]
*(https://www.gesetze-im-internet.de/englisch_stgb/englisch_stgb.html)
Case Studies and Institutional Responses
Institutional audits across the UK and internationally reveal a consistent pattern of restrictive actions against unassured AI transcription services for example:
Institution
Technical Measures Implemented
Policy and Enforcement Stance
Approved Alternatives
University of Oxford [8]
• Blocked Single Sign-On (SSO) registrations for unapproved AI bots.
•Revoked calendar access and Teams meeting permissions.
• Restricted automation on an individual app-by-app basis.
•Categorical ban on unapproved Teams meeting bots.
• Mandatory security assessments required before any enablement.
•Explicit warning that Otter.ai is not approved for personal data.
•Corporately managed, paid version of Microsoft 365 Copilot.
Bournemouth University [11]
• Configured Teams to prevent unapproved bots from joining automatically.
• Enforced the disablement of auto-join and calendar sync on personal tools.
• Compulsory IT team assessment required before using any assistant.
• Mandatory policy to decline proceeding with meetings if an external bot is active.
• None; cases evaluated individually by IT Services.
Loughborough University [1]
• Multi-stage Software Risk Assessment (SRA) process.
• Mandatory Data Protection Impact Assessment (DPIA) if sharing personal data.
• Formal prohibition of unvetted external transcription platforms.
• Compulsory review of vendor data-sharing and model-training clauses.
• Native Microsoft Teams and Microsoft Word transcription features.
US Universities(Washington, Chapman, UC Riverside) [23]
• Blocked Read AI, Otter.ai, and other non-native bots at the tenant level
• Restricting all non-native bots across their video conferencing estates.
• Strict institutional bans due to data privacy and corporate copyright risks.
• Platform-native enterprise transcription tools.
In the legal and corporate domain, the class action lawsuit Brewer v. Otter.ai (consolidated in the Northern District of California) serves as a benchmark.[2, 10, 23] The plaintiff, a non-user of Otter, alleged that the platform recorded, transcribed, and analysed his private conversations without his knowledge or consent when he attended meetings hosted by Otter users.[2, 10] The complaint asserts that Otter routinely ingested these private conversations to train its machine learning and speech-recognition models, violating wiretapping statutes and consumer protection laws.[2, 10, 27]
In clinical and healthcare settings, the reliability of AI transcription is of paramount concern.[1, 2, 28] A comparative study on the clinical accuracy of LLM-generated medical documentation evaluated transcription error rates across prominent models:
Platform / Model
Total Word Error Rate (% of Target Words)
Misattributed Speaker Word Error Rate (%)
Operational and Clinical Implications
NotebookLM[28]
4.0%
3.6%
Lowest overall error rate; demonstrates superior contextual language processing.
AssemblyAI[28]
10.4%
1.4%
Lowest speaker misattribution rate; highly effective for multi-speaker diarisation.
Otter.ai [28]
18.5%
8.9%
Highest error rates; significant risk of medical terminology errors and incorrect speaker turn-taking.
These clinical findings indicate that even modest transcription errors can distort patient documentation, introduce dangerous medical terminology hallucinations, and lead to incorrect clinical decisions, underscoring why fully autonomous note generation remains unsafe for clinical deployment.[1, 2, 28]
Public Sector Assurance Frameworks and Guidelines
The UK Government Digital Service (GDS) and the Department for Science, Innovation and Technology (DSIT) have established clear guardrails under the "AI Playbook for the UK Government," which updates and expands upon the 2024 Generative AI Framework.[29, 30, 31] The playbook defines ten core principles to guide the safe, responsible, and effective deployment of AI in government [29, 32]:
Principle 1: You know what AI is and what its limitations are.[29, 32] Public bodies must recognize that generative AI systems lack reasoning and contextual awareness, frequently introducing inaccuracies, biases, and hallucinations.[29, 32]
Principle 2: You use AI lawfully, ethically and responsibly.[29, 32] AI applications must align with the Civil Service Code and data protection legislation, ensuring that diverse participation is built into the project lifecycle.[29, 32, 33]
Principle 3: You know how to use AI securely.[29, 32] Organizations must enforce strict information security protocols to prevent data leakage and privacy violations.[12]
Principle 4: You have meaningful human control at the right stages.[29, 32] Fully autonomous AI operations that lead to irreversible actions (such as altering records or sending communications) are strictly prohibited; human verification is mandatory.[12]
Principle 5: You understand how to manage the full AI life cycle.[29, 32] Public sector entities must maintain end-to-end traceability, asset management, and secure decommissioning of AI models.[34]
These national standards are supported by the NCSC's Agentic AI security guidance, which warns that the autonomy and complexity of agentic systems make them particularly prone to unpredictable behaviour and over-privileged access.[9] The NCSC advises public sector bodies to apply the principle of least privilege, restrict agent capabilities to tightly bounded pilots, avoid long-lived credentials, and establish robust kill-switch mechanisms.[9]
Furthermore, public sector bodies must align with the international ETSI EN 304 223 standard for AI cybersecurity, which establishes a technical baseline for securing AI data supply chains, managing model dependencies, and mitigating model drift and prompt injection risks.[9, 14, 34]
Corporately Assured Implementations
To reconcile the demand for productivity with strict security requirements, the UK public sector has pursued two parallel, assured deployment tracks:
The i.AI "Minute" Tool: Developed by the Cabinet Office’s Incubator for AI (i.AI), "Minute" is a custom-built, secure meeting transcription, minuting, and summarization tool deployed within the government’s secure network boundaries.[7, 35] It eliminates external cloud exposure and ensures that government discussions remain protected under public sector sovereignty.[7, 35]
ICO's Secure Microsoft 365 Copilot Deployment: The Information Commissioner's Office (ICO) utilizes Microsoft 365 Copilot for summarizing Teams meetings, transcripts, and emails under the lawful basis of "public task".[18] To maintain compliance, the ICO enforces strict technical safeguards: all processed data remains within the ICO's secure UK Microsoft 365 and Azure tenants, ensuring that customer data is never utilized to train external foundation models.[18] Furthermore, audio recordings and generated transcripts are subjected to a mandatory auto-deletion policy after 21 days, and all outputs are verified by human operators to mitigate hallucinations.[18]
Technical Hardening of Virtual Meeting Platforms
To defend public sector communications against unauthorised AI bots, IT administrators must implement rigorous technical hardening across Microsoft Teams, Zoom, and Google Meet.[3, 36, 37]
Microsoft Teams Hardening
Microsoft Teams features native admin controls to intercept and block external bots before they enter a live session.[3, 23] Under Microsoft Message Centre notice MC1251206*, Teams automatically flags external third-party bots as "Unverified" in the meeting lobby, requiring explicit organiser approval.[23] To achieve absolute protection, administrators should configure the ExternalBotAccessMode attribute, which is managed via the Teams Admin Centre (TAC) or PowerShell [3]:
*(https://mc.merill.net/message/MC1251206)
Open the Teams Admin Center and navigate to Meetings -> Meeting Policies.
Locate the Meeting Join & Lobby section.
Under Manage external bots and their access to meetings, select the appropriate policy:
AllowAllBots: Admits all third-party bots without restriction.[3]
RequireApprovalWhenDetected: Sends detected bots to the lobby, where they await host admission (Default).[3]
BlockDetectedBots: Automatically turns unapproved bots away at the door, preventing them from entering the lobby or the meeting.[3]
Administrators can enforce this globally or target specific user groups using the PowerShell cmdlet [3]:
Set-CsTeamsMeetingPolicy -Identity "Global" -ExternalBotAccessMode BlockDetectedBots
This configuration ensures that standard guest access remains open to human participants, while uninvited third-party bots (such as Otter or Fireflies) are blocked.[3] Additionally, Teams default transcript retention should be audited; transcripts are stored in the host's OneDrive (for ad-hoc meetings) or the channel’s SharePoint folder (for channel meetings), with a default expiration period of 60 days that should be adjusted to align with organizational data retention policies.[1]
Zoom Hardening
To prevent unapproved bots from accessing Zoom meetings, administrators must implement multi-layered domain and application blocks.[36, 38, 39]
Domain-Level Blocking
Administrators can configure domain blocks via the Zoom Admin Portal [36, 38]:
Navigate to Account Management -> Account Settings -> Meeting.
Under Security, locate the setting Block users in specific domains from joining meetings and webinars and toggle it to On.[36, 38]
Click the edit icon and input known AI bot domains, separated by commas: otter.ai, read.ai, fireflies.ai, meetgeek.com, fathom.video.[36, 38]
Save the changes to apply the block across all scheduled and ad-hoc meetings.[36, 38]
App Marketplace Restricting
To prevent internal employees from authorizing integrations that bypass domain blocks, administrators must restrict the Zoom App Marketplace [39]:
Sign in as an administrator at marketplace.zoom.us.[39]
Click Manage in the upper-right corner and select Admin App Management -> Apps on Account.[39]
Locate third-party transcription apps (such as Otter.ai) and click Disable or Remove.[39]
Navigate to Admin App Management -> Permissions and disable App Requests.[39] This forces all application installations to undergo administrator review, preventing users from authorizing automatic calendar syncs with external services.[39]
In-Meeting Safeguards
Hosts should be trained to apply immediate in-meeting controls [38]:
Enable the Waiting Room feature to manually verify and admit every participant.[38]
Toggle on Only authenticated meeting participants can join, which forces attendees to sign in via verified Zoom accounts, blocking anonymous bot connections.[38]
Once all expected human participants have joined, click the Security icon and select Lock Meeting to prevent late-arriving bots from entering.[38]
Note on Zoom AI Companion: Unlike third-party bots, the native Zoom AI Companion is integrated directly into the Zoom platform.[23] Zoom’s terms of service guarantee that customer meeting content is not utilized to train its AI models without explicit, opt-in host consent, offering a compliant native alternative if authorized by the organization’s DPO.[23]
Google Meet Hardening
Google’s 2026 security screening update implements a risk-based classification model that automatically routes unverified external bots, anonymous joiners, and unfamiliar connection patterns into a high-risk queue.[40] These entities are flagged with a red "potential risk" warning banner in the lobby.[40] To secure Google Meet environments, administrators and hosts must apply both console and in-meeting configurations [40, 41, 42]:
Host Access Control and Knocking Disablement: During meeting scheduling in Google Calendar or inside an active session, hosts should access Host Controls and navigate to Meeting Access.[43] Choose the Restrictedaccess level (available for Workspace enterprise editions) and uncheck the box next to Anyone can ask to join.[43] This action disables "knocking" for the entire meeting.[43] Any anonymous user or external third-party bot attempting to join via "Ask to join" is automatically denied entry without requiring manual host rejection.[40, 43]
Google Admin Console Hardening: IT administrators must enforce domain-level restrictions by logging into the Google Admin Console and navigating to Menu -> Apps -> Google Workspace -> Google Meet -> Meet Safety Settings.[41, 42] Under Incoming Call Restrictions, set the switch to Only contacts & in-domain users.[41, 42] This prevents external Google accounts or automated dialers from directly calling internal users, severely restricting the lateral join path utilized by calendar-scraping bots.[40, 41]
Suggested Actions and Governance Framework
To establish a comprehensive posture against the threat of unassured AI meeting assistants, UK public sector organizations should implement a multi-tiered governance framework.[1, 2, 10]
Phase 1: Policy Formulation and Acceptable Use
Public sector bodies must draft and publish clear internal policies defining which recording and transcription services are authorized and the conditions under which they may operate.[10]
Mandatory SRA and DPIA: No transcription tool should be deployed without completing a Software Risk Assessment (SRA) to verify alignment with Cyber Essentials requirements, and a Data Protection Impact Assessment (DPIA) to evaluate privacy risks.[1]
Contractual Verification: Organizations must verify that vendor contracts include explicit "no training" commitments, ensuring that public data is never utilized to improve external models.[16, 19, 44]
Mandatory Human-in-the-Loop: Policy must mandate that all AI-generated meeting notes and transcripts undergo human verification for accuracy before being saved or distributed, mitigating the risks of transcription errors and hallucinations.[1, 2, 18]
Phase 2: Technical Enforcement and App Blocking
IT departments must execute domain blocks and SSO restrictions to eliminate the use of unassured consumer-grade tools.[8, 39]
SSO Access Revocation: Disable the ability for employees to sign up or log into services like Otter.ai, Read AI, or Fireflies.ai using their corporate Google Workspace or Microsoft Entra ID credentials.[8]
Active Endpoint and Network Scanning: Deploy network monitoring and endpoint controls to identify unauthorized browser extensions, local device capture tools (such as Granola), or active API connections to unapproved AI domains.[2, 45]
Tenant-Level Blocking: Enforce the platform-specific hardening steps outlined below to ensure that uninvited bots are turned away at the door.[3, 36, 43]
Platform
Recommended Administrative Configuration
Technical Verification Method
Microsoft Teams
• Set ExternalBotAccessModeto BlockDetectedBots.[3]
• Configure standard transcript retention to 21 days or less.[18]
• Execute PowerShell: Get-CsTeamsMeetingPolicy | Select Identity, ExternalBotAccessMode.[3]
Zoom
• Enforce manual domain blocklist for otter.ai, read.ai, fireflies.ai.[36, 38]
• Disable unapproved integrations in Zoom App Marketplace.[39]
• Audit marketplace logs at marketplace.zoom.usfor unauthorized user installs.[39]
Google Meet
• Enforce Restricted meeting access and disable external knocking.[43]
• Set Incoming Call Restrictions to "Only contacts & in-domain".[41]
• Verify Workspace Admin Console under Meet Safety Settings.[41, 42]
Phase 3: Employee Training and External Engagement Rules
Public sector employees must be trained to recognize and handle AI bots, particularly when participating in external meetings hosted by third parties.[11, 12, 24]
Lobby Verification: Meeting hosts must verify the identity of all attendees in the lobby before granting entry, stating clearly at the start of the call that the use of third-party AI transcription tools is prohibited.[12, 46]
Declining External Bot Participation: If an employee joins an external meeting and observes an active third-party AI bot, they should politely request its deactivation.[11] Bournemouth University suggests the following standard phrasing:
Enforcing Incident Reporting: If an unapproved AI bot silently joins a meeting or distributes an unauthorised summary containing sensitive public data, employees must report the incident to their DPO as a potential personal data breach under UK GDPR.[8, 11]
Bibliography
2026 | Data protection, information security and data privacy ..., https://www.lboro.ac.uk/data-privacy/announcements/listing/2026/news---26-02-06---ai-transcription-tools-a-time-saver-or-security-risk.html
AI Ethical Breaches: The Risks of Inviting AI into your Meeting Room - DPEX Network, https://www.dpexnetwork.org/articles/ai-ethical-breaches-the-risks-of-inviting-ai-into-your-meeting-room
Teams to Block External AI Bots - UC Today, https://www.uctoday.com/unified-communications/microsoft-teams-to-block-external-bots-automatically-as-ai-notetaker-crackdown-hardens/
Your AI Meeting Assistant Might Be the Biggest Security Risk in Your Office | by Len Noe, https://medium.com/@len213noe/your-ai-meeting-assistant-might-be-the-biggest-security-risk-in-your-office-4cf7c2f63edf
Landmark government trial shows AI could save civil servants nearly 2 weeks a year, https://www.gov.uk/government/news/landmark-government-trial-shows-ai-could-save-civil-servants-nearly-2-weeks-a-year
UK Public Sector AI Case Studies - Cube8, https://www.cube8.co.uk/case-studies.php
AI in UK government departments - UK Parliament, https://researchbriefings.files.parliament.uk/documents/CBP-10236/CBP-10236.pdf
Are your online meetings safe from third party AI bots? | Information ..., https://www.infosec.ox.ac.uk/article/are-your-online-meetings-safe-from-third-party-ai-bots
NCSC Publishes Guidance on Securing Agentic AI Use - Infosecurity Magazine, https://www.infosecurity-magazine.com/news/ncsc-publishes-guidance-securing/
AI Note-Takers at Work: The Silent Threat to Privacy and ..., https://www.socialeurope.eu/ai-note-takers-at-work-the-silent-threat-to-privacy-and-compliance
Use of AI meeting assistants at BU | Bournemouth University, https://www.bournemouth.ac.uk/news/2025-07-07/use-ai-meeting-assistants-bu
Security and risks - AI Knowledge Hub, https://ai.gov.uk/knowledge-hub/how-to/security
Using video conferencing and consultation tools guidance for IG professionals - NHS Digital, https://digital.nhs.uk/data-and-information/information-governance/guidance/using-video-conferencing-and-consultation-tools/guidance-for-ig-professionals
AI Security in the UK: The Cost of Getting It Wrong in 2026 - Appinventiv, https://appinventiv.com/blog/ai-security-in-uk/
Recent UK legal and regulatory developments on AI and automated decision-making, https://www.kennedyslaw.com/en/thought-leadership/article/recent-uk-legal-and-regulatory-developments-on-ai-and-automated-decision-making/
AI Note Taking Tools and GDPR: Do You Need a New Lawful Basis? - Measured Collective, https://measuredcollective.com/ai-note-taking-tools-and-gdpr-do-you-need-a-new-lawful-basis/
How do I work from home securely? | ICO - Information Commissioner's Office, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/security/working-from-home/how-do-i-work-from-home-securely/
Microsoft 365 Copilot | ICO - Information Commissioner's Office, https://ico.org.uk/global/privacy-notice/microsoft-365-copilot/?search=recording
Avoid These Security and Compliance Traps When Implementing a Notetaker - Read AI, https://www.read.ai/articles/avoid-these-security-and-compliance-traps-when-implementing-a-notetaker
AI marketing in the UK: 2026 guide to trends, tools & regulations, https://uk.cyberclick.net/digital-growth-playbook/ai-marketing-in-the-uk-guide-to-trends-tools-regulations
AI Transcription Tools Under Scrutiny: Navigating Privacy Risks and Practical Mitigation Strategies | Insights & Resources | Goodwin, https://www.goodwinlaw.com/en/insights/publications/2026/04/alerts-practices-dpc-ai-transcription-tools-under-scrutiny
AI Meeting Assistant Development Services | Neurotrack UK, https://neurotrack.uk/ai-meeting-assistant-development/
Microsoft, Zoom and Google Tighten Meeting Bot Controls as Otter Case Nears Hearing, https://www.uctoday.com/security-compliance-risk/ai-meeting-bots-controls-microsoft-zoom-google/
The rise of video conferencing – what the ICO And NCSC want you to watch out for, https://kempitlaw.com/insights/the-rise-of-video-conferencing-what-the-ico-and-ncsc-want-you-to-watch-out-for/
AI in Client Meetings: Helpful Assistant or Hidden Ethical Risk? - North Carolina Bar Association, https://www.ncbar.org/2026/01/30/ai-in-client-meetings-helpful-assistant-or-hidden-ethical-risk/
Granola Alternative: the GDPR Comparison - Sally AI, https://www.sally.io/blog/granola-alternative
AI notetakers: Legal privilege & data protection risks - Browne Jacobson LLP, https://www.brownejacobson.com/insights/otter-chaos-issues-with-using-ai-notetakers
Accuracy of large language model transcription of simulated physician-patient verbal interactions - PMC, https://pmc.ncbi.nlm.nih.gov/articles/PMC13088782/
Artificial Intelligence Playbook for the UK Government - GOV.UK, https://assets.publishing.service.gov.uk/media/67aca2f7e400ae62338324bd/AI_Playbook_for_the_UK_Government__12_02_.pdf
AI Playbook for the UK Government - GOV.UK, https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government
Artificial Intelligence Playbook for government published | Practical Law, https://uk.practicallaw.thomsonreuters.com/w-045-8067?transitionType=Default&contextData=(sc.Default)
Artificial Intelligence Playbook for the UK Government (HTML) - GOV.UK, https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government/artificial-intelligence-playbook-for-the-uk-government-html
Generative AI policy - GCS - Government Communication Service, https://www.communications.gov.uk/publications/gcs-generative-ai-policy/
Securing AI Adoption in the Public Sector - NCSC Ireland, https://www.ncsc.gov.ie/pdfs/NCSC_Secure_AI_Adoption_2026.pdf
UK Government calling on AI 'Humphrey' to fix outdated technology - OmniCyber Security, https://www.omnicybersecurity.com/uk-government-ai-outdated-tech/
Preventing 3rd Party AI Tools From Accessing Your Meetings, https://it.stonybrook.edu/help/kb/preventing-3rd-party-ai-tools-your-meetings
How to Block all Otter ai - Google Meet Community, https://support.google.com/meet/thread/369917295/how-to-block-all-otter-ai?hl=en
How to Prevent and Remove Unapproved AI bots from Zoom Meetings - Rice University KB, https://kb.rice.edu/149886
How do I disable AI Notetakers (otter.ai, read.ai, fireflies.ai, etc.) from joining our meetings - Zoom Community, https://community.zoom.com/meetings-2/how-do-i-disable-ai-notetakers-otter-ai-read-ai-fireflies-ai-etc-from-joining-our-meetings-17388
How to prevent custom Google Meet bot from being flagged as "Potential Risk"?, https://support.google.com/meet/thread/438497815/how-to-prevent-custom-google-meet-bot-from-being-flagged-as-potential-risk?hl=en
Restrict who can call my organization's users with Google Meet, https://knowledge.workspace.google.com/admin/meet/restrict-who-can-call-my-organizations-users-with-google-meet
Manage Meet settings (for admins) - Google Workspace Help, https://knowledge.workspace.google.com/admin/meet/manage-meet-settings
Tips to control meeting access and participation - Google Workspace Learning Centre, https://support.google.com/a/users/answer/11989526?hl=en
AI notetaker security and privacy checklist - Avoma, https://www.avoma.com/blog/ai-notetaker-security-features
Best AI Meeting Assistant for Enterprise 2026 - SOC2, HIPAA, SSO, Admin Controls, https://summarizemeeting.com/en/faq/best-ai-meeting-assistant-for-enterprise
Last updated
Was this helpful?