There’s an AI in Your Meeting. Who Let It In?
AI meeting assistants are becoming normal. Our meeting etiquette, cybersecurity and data governance haven’t caught up.
I recently heard someone talking about an experience they recently had with an online meeting they didn’t even attend. Their AI did.
It was an online educational session. The AI meeting assistant joined in their place, listened to the conversation, created a transcript and produced notes.
Nobody stopped it at the door.
Nobody apparently asked:
Who is this?
What is it recording?
Where is that recording going?
Who owns the account it’s being stored in?
Who will be able to see it afterwards?
The meeting happened and then, afterwards, the organisation contacted the person to say - ‘Please don’t let your AI attend again and if you have a recording, please don’t share it.’
Which got me thinking as I think it raises a rather more interesting question.
If you didn’t want the AI in the room, why did you let it in?
Imagine this happening in real life. Twenty people arrive for a private business meeting, one person walks through the door carrying recording equipment. Nobody recognises them or asks who they represent. Nobody checks what they’re recording or establishes where that recording will be stored. They sit through the entire meeting.
Afterwards, when everyone has gone home, somebody contacts the person who sent them and says: “Actually, we’d rather they hadn’t been there.”
We’d recognise immediately that something had gone wrong, action could have been immediate. Digitally, we’re doing versions of this every day and increasingly, the unfamiliar participant isn’t even a person.
It’s Otter. Fathom. Fireflies. Read AI. Copilot. Zoom AI Companion. Or another AI meeting assistant.
Welcome to the new meeting room.
The meeting room now has a digital door
This isn’t just our opinion. In March 2026, the UK’s National Cyber Security Centre published guidance specifically about securing online meetings. Its advice includes using a waiting area or lobby to verify participants before admitting them, challenging participants you don’t recognise and restricting meetings to authenticated users and invited guests where appropriate.
Organisations need to be aware of AI attendees because those tools may record, transcribe or analyse meeting content. Businesses should understand what information they collect, how it is used, who can access it and how long it is retained.
basically Someone needs to mind the door
Microsoft has already started designing this assumption into Teams. Teams can identify some external bots waiting in the lobby. A meeting organiser attempting to admit one can receive an explicit warning that they’re about to allow an external bot into the meeting that may record or transcribe it.
That’s fascinating because it tells us where this is heading.
AI admission is becoming a meeting-host decision.
is it legal to record a meeting with AI?
This is where conversations about AI meeting assistants can become misleadingly simple.
You’ll hear “You can’t record people without consent because of GDPR.” or “I was in the meeting, so I’m entitled to record it.” Neither is a particularly useful rule.
UK GDPR doesn’t simply say that every recording requires consent. Organisations processing personal information need an appropriate lawful basis. Consent is one possible lawful basis, but it isn’t the only one. The appropriate basis depends upon why the information is being processed and the relationship between the organisation and the people involved.
The ICO specifically says organisations can record online meetings containing people’s voices and images where there is a valid purpose and an appropriate lawful basis but organisations should consider whether the objective could be achieved in a less intrusive way and before recording, people should be told why the meeting is being recorded, what the recording will be used for and how long it will be retained.
then there’s the question nobody asks: where did the meeting go?
This is the bit that interests us most at Human First Digital.
A traditional meeting ends.
People leave.
Perhaps somebody wrote some minutes.
An AI-enabled meeting can create an entirely new digital asset.
There may now be:
Audio
Video
A transcript
An AI summary
Actions
Names and contact details
Chat messages
Files
Searchable conversational data
Potentially sitting inside somebody else’s software account and that changes the risk considerably.
Imagine you said something commercially sensitive
Let’s make this practical. You’re attending a networking or business-support meeting and during the conversation you say: “We’re planning to launch this in November. We haven’t announced it yet.” or perhaps somebody discusses an employee, customer, health issue or other personal information.
In an ordinary meeting, those words exist principally in the memories and handwritten notes of the people present.
With an AI meeting assistant, they could become searchable stored data.
So who controls that information now?
Being the person who said something doesn’t automatically mean you own every subsequent recording of it or have an unconditional right to delete every copy. Copyright, confidentiality, contractual rights and data-protection rights are different legal questions but where a recording or transcript identifies you or contains information about you, personal-data obligations and individual data rights may become relevant.
The organisation processing that personal information needs a lawful basis and must process it fairly and transparently and if that information is subsequently used for another purpose, another important principle appears purpose limitation.
Organisations should establish why personal information is being collected and shouldn’t simply reuse it for unrelated purposes without considering whether that new use is compatible and lawful.
That distinction becomes extremely important in the AI era.
Because “We recorded this meeting to produce minutes” is not necessarily the same proposition as “We have created a permanent corpus of organisational conversations that can subsequently be searched, analysed, summarised or fed into other systems.”
Who owns the Fathom account?
Here’s another scenario.
Five businesses have a meeting.
One participant’s Fathom account records it.
Whose information is it?
Who controls access?
What happens when that person’s employee leaves?
What if their account is compromised?
What if they share the transcript?
What if the software changes its terms?
What if the meeting contains confidential client information?
What if someone exercises a data-protection right?
What if somebody forwards the AI summary but not the context from which it was generated?
Most importantly…..
Does anyone in the meeting actually know the answers?
This is where AI literacy stops being about how to write a good prompt and starts becoming something much more important. It’s digital governance.
A transcript is not just a better set of minutes
A set of minutes might include - The board discussed financial performance and agreed to review expenditure, however a verbatim transcript might contain the entire discussion.
Who challenged whom
The actual financial figures
Speculation
Personal opinions
Customer names
Commercial vulnerabilities
Half-formed ideas
Statements that were never intended to become permanent organisational records
Those are fundamentally different information assets and AI adds another layer. The transcript isn’t merely stored, it becomes computable which means it can potentially be searched, summarised, categorised, compared and interrogated. That dramatically increases its usefulness but it can also dramatically increase its sensitivity.
“But everybody in the meeting got the notes”
That doesn’t automatically solve the problem either.
Access is part of governance. Microsoft Teams, for example, now allows organisers to decide whether recordings, transcripts and AI recaps are accessible to everyone, only organisers, or specific people.
The question isn’t simply: Should this meeting be recorded?
We now need to ask: Who should have access to which artifact afterwards and for how long?
The NCSC explicitly recommends knowing where recordings, transcripts, chat logs and shared files are stored, checking who has access and retaining personal information only as long as there is a clear reason to keep it.
The ticking time bomb isn’t AI. It’s governance.
AI meeting assistants are useful. The problem is that adoption is happening faster than organisational behavior is changing around it. We’ve normalised the tool before we’ve normalised the rules and that means thousands of organisations are potentially accumulating huge repositories of conversations without having consciously decided how we mitigate any risks they could generate.
This is what we mean by Human First Digital
We spend a lot of time talking to businesses about websites, AI, automation, CRM systems, data and digital skills but the technology is rarely the interesting bit.
The interesting bit is what happens between the systems and the humans using them.
Nobody deliberately decided:
“Let’s create an unmanaged database containing years of our commercially sensitive conversations.”
They decided:
“Fathom is brilliant. It saves me taking notes.”
That is precisely how digital risk often develops. One perfectly reasonable decision at a time.
Human First Digital helps organisations ask the question that comes next and how do we get the enormous benefits of new technology without accidentally building ourselves a completely different problem?
If AI has already arrived in your organisation and your policies, processes and people haven’t quite caught up yet, that’s exactly the sort of conversation we like having.

