Monitoring AI Meeting Assistants at Work

Security & Compliance
By eMonitor Editorial Team
9 min read

Otter, Fireflies, Zoom AI Companion, and Microsoft Copilot now join meetings by default in many organizations, quietly recording, transcribing, and sending conversations to third-party AI models. Almost none of it went through IT. Here is why it spreads unmanaged, the real risks it creates, and how to get visibility before a policy can work.

A sales call, a client kickoff, a performance conversation: a growing share of them now have a silent extra participant. AI meeting assistants have gone from a niche convenience to a default feature in the space of two years, built directly into Zoom, Teams, and Google Meet, and installed as independent bots by millions of individual employees who simply wanted better notes. Most of that adoption happened without a single conversation with IT, security, or legal. This guide covers what these tools actually do, why they spread the way they do, the consent and data-governance risks they create, and how to build a policy that starts with knowing which tools are already in use, something shadow AI usage tracking makes possible.

What AI meeting assistants actually do

An AI meeting assistant is software that joins a call, captures the audio, and turns it into a transcript, a summary, and often a list of action items, using a large language model to do the interpretation. Some, like Otter or Fireflies, join visibly as a named participant in the call. Others, like Zoom AI Companion or Microsoft Copilot in Teams, run inside a platform employees already use and can be turned on with a single toggle, with no separate bot ever appearing on screen.

The appeal is obvious and largely legitimate. Nobody has to take notes by hand, follow-up emails write themselves, and searchable transcripts make it easy to pull up what was actually agreed weeks later. For an individual employee trying to get through a day of back-to-back calls, an AI notetaker is an unambiguous productivity win, which is exactly why so many of them installed one without asking anyone first.

The part that gets less attention is where the recording goes afterward. Once a meeting assistant joins a call, the audio and transcript typically leave the company's own systems entirely and land on the vendor's infrastructure, processed by whichever AI model that vendor uses, retained under whatever policy that vendor sets, and in some cases used to improve the vendor's own models unless an employee happened to opt out in a settings page nobody reviewed.

It also helps to separate the two adoption paths, because they create different problems. A standalone bot, Otter, Fireflies, Fathom, is something an individual employee chose and installed, which at least leaves a trail: a calendar permission granted, an account created with a work email. A built-in assistant is different. It is a feature flag inside software the company already licensed, and it can be switched on for an entire workspace by a single admin setting or a vendor default, with no individual decision to point back to at all. Both end up in the same place, meeting content on a third-party model, but only one of them looks like a decision anyone made.

Why they proliferate unmanaged

AI meeting assistants spread the way most shadow IT spreads: through free tiers, single-click sign-in with a work email, and calendar integrations that ask for permission once and then run indefinitely. There is no purchase order, no vendor security review, and often no visible cost, so none of the usual gates that catch new software ever get triggered. Our guide to tracking ChatGPT usage covers the same underlying pattern for generative AI tools more broadly.

Platform defaults make it worse. When Zoom or Teams ships an AI companion switched on, or defaults a workspace admin setting to enabled, adoption stops being an individual employee's choice at all, it becomes ambient. A company can have hundreds of meetings a week being transcribed by a built-in AI feature that was never explicitly approved, simply because nobody changed the default.

And the incentive to disclose is backwards. An employee who finds a tool that makes their job easier has every reason to keep using it and very little reason to flag it to IT, since flagging it risks having it taken away. The tools that create the most governance exposure are, from the employee's point of view, working exactly as intended.

Remote and hybrid work accelerates the trend further. When most meetings already happen over video rather than in a conference room, adding a notetaker is a one-click extension of a workflow that was already digital, not a new category of tool that has to clear any bar of its own. A habit that might have prompted a second thought in person, inviting an unfamiliar assistant to sit in on a sensitive conversation, barely registers as a decision when it is just another checkbox in a video call interface.

The risks these tools create

The first risk is where sensitive information ends up. Sales calls discuss pricing and contract terms, client kickoffs cover confidential roadmaps, HR and performance conversations touch protected personal data, and legal calls can involve privileged discussion. An AI notetaker does not distinguish between a routine standup and a conversation that should never leave the building; it transcribes everything it hears and sends it to a third-party model with the same defaults either way. This is the same class of exposure covered in employee monitoring versus DLP, extended into a channel, live audio, that most data-loss-prevention tooling was never built to inspect.

The second risk is consent and legal exposure. Many jurisdictions require one-party or all-party consent before a conversation is recorded, and a bot silently joining a call, or a built-in feature nobody announced, can put a company on the wrong side of wiretapping or data protection law, especially when the other participant is a client, a candidate, or anyone outside the organization who never agreed to be recorded by a third-party AI service.

The third risk is the newest and least visible: uninvited bots. Calendar integrations and browser extensions increasingly let an AI assistant auto-join any meeting on a connected calendar, sometimes belonging to a guest rather than the host, so a company can end up with an unfamiliar AI notetaker sitting in a meeting that no one on the internal side installed or approved. Nobody owns that exposure because nobody decided to create it.

There is a fourth, quieter risk worth naming: accuracy and misattribution. AI transcripts and summaries are generated by a model, not verified by a human, and they can misquote a speaker, misattribute a comment to the wrong person, or summarize a hedge as a commitment. When that transcript is later forwarded, saved to a shared drive, or cited in a dispute, an error introduced by the AI can take on the authority of a verbatim record, which is a different and less obvious kind of exposure than a straightforward data leak.

Finding out which AI assistants employees already use

A policy written before anyone knows what is actually running is a policy written blind. The starting point is not a memo, it is visibility into which applications and websites are active across the organization, since that is where AI meeting assistants show up long before anyone reports them. Application and website usage analytics reports which desktop apps and web domains employees actively use during work hours, which surfaces Otter, Fireflies, Fathom, and similar tools running on managed devices, along with how widely each one has spread and which teams are driving adoption.

This works because discovery does not require reading what was said in any meeting. Usage visibility answers a narrower and more useful question, which application was open and active, not what was recorded inside it, so a company can find the governance gap and quantify it without ever touching meeting content. That is the distinction that keeps discovery from becoming the very problem it is meant to solve.

Once the picture exists, the next step is straightforward: compare what is actually running against what is approved, identify the teams with the heaviest unmanaged usage, and use that as the evidence base for the policy conversation, rather than guessing at adoption from anecdotes.

See which AI tools are already in your meetings

eMonitor's application and website usage analytics surface AI notetakers and other shadow AI tools running across your organization, so governance starts with facts instead of guesses.

Building an AI meeting assistant policy

Start by naming an approved tool, or a short list of them, chosen with input from security and legal on retention, training-data use, and data residency, rather than leaving the choice to whichever free extension an employee found first. A single approved option removes most of the incentive to reach for something unvetted.

Require disclosure as a non-negotiable rule: every participant in a meeting must be told, before it starts, that an AI assistant is recording and what happens to the transcript afterward. This is the simplest lever available for consent risk, and it costs nothing beyond a habit change, a line in the calendar invite or a spoken notice at the start of the call.

Name the meeting types that must never be recorded by a third-party AI at all, HR conversations, performance discussions, legal matters, anything covered by attorney-client privilege, and make that list specific rather than a vague appeal to good judgment. Vague guidance is what got most companies into this position in the first place.

Finally, treat discovery as ongoing rather than a one-time audit. New AI notetakers launch constantly, platform defaults change without notice, and a policy that is not paired with a way to see when unapproved tools reappear will quietly go stale within a quarter.

It is worth sequencing this deliberately rather than publishing a policy and hoping it sticks. Run discovery first, so the approved tool decision is grounded in what employees are actually reaching for rather than a guess. Pilot the approved tool with one or two teams before a company-wide rollout, so disclosure habits and retention settings get tested on a small scale. Then communicate the policy alongside the reason for it, since a policy that only says what is banned invites workarounds, while one that explains the consent and data-handling risk tends to get followed voluntarily.

Best practices

How to bring AI meeting assistants under control without banning useful tools:

  • Name an approved tool: give employees a sanctioned option instead of a policy vacuum.
  • Review vendor data handling first: retention, training use, and access controls before approval, not after.
  • Require disclosure to every participant: the simplest fix for consent risk.
  • Exclude HR, legal, and privileged calls: name the meeting types explicitly.
  • Get application and website usage visibility: you cannot govern tools you cannot see.
  • Watch for platform defaults: built-in AI companions can enable themselves silently.
  • Treat discovery as ongoing: new notetakers appear faster than annual audits catch them.
  • Avoid outright bans: they push the behavior underground rather than ending it.

AI meeting assistants are not going away, and for most employees they are a genuine improvement over handwritten notes. The risk was never the concept, it was the silence: tools adopted without review, running in conversations that were never meant to leave the room, with no one able to say which ones were even active.

Closing that gap starts with visibility, not a memo. Once a company can see which AI notetakers are actually running, the policy conversation becomes concrete instead of theoretical, and enforcement becomes possible instead of aspirational.

Surfacing AI meeting assistant usage with eMonitor

eMonitor does not join meetings, capture audio, or read transcripts, and it was never built to. What it does is report which applications and websites are active on managed devices during work hours, which is exactly the signal that reveals an AI notetaker spreading unmanaged across a team: Otter running on a laptop, Fireflies open in a browser tab, a Zoom AI Companion session active during a client call. That usage data turns a governance question nobody could previously answer, which AI meeting tools are we actually running, into a dashboard.

It is built for discovery and governance, not surveillance of what was said. Aggregate team trends rather than individual scoreboards, employee self-access to their own usage data, and work-hours-only tracking keep the focus on the tools in use, not the conversations themselves. Trusted by 1,000+ companies worldwide and rated 4.8/5 on Capterra, eMonitor starts at $3.90 per user with a 7-day free trial.

If you do not know how many AI meeting assistants are already running across your organization, that is the first question worth answering. Start a free trial and see the usage data for yourself.

Frequently Asked Questions

What is an AI meeting assistant?

An AI meeting assistant is a bot or built-in feature, such as Otter, Fireflies, Zoom AI Companion, or Microsoft Copilot, that joins a call, records or transcribes the audio, and generates notes and summaries using a third-party AI model. Some join as a visible participant in the call; others run silently inside a platform employees already use.

Why are AI meeting assistants a security risk?

They move meeting audio and transcripts, often including client names, financial figures, legal discussion, and personal data, onto a third-party vendor's servers where retention, training use, and access controls are outside the company's own security stack. Most are adopted without IT review, so no one has assessed what the vendor does with the data.

Is it legal to record a meeting with an AI notetaker?

It depends on jurisdiction. Many regions require one-party or all-party consent before recording a conversation, and dropping an AI bot into a call without telling participants can violate wiretapping or data protection law, particularly when a client or candidate outside the company is on the call and never agreed to be recorded.

What is shadow AI in the context of meetings?

Shadow AI is any AI tool employees adopt on their own, outside IT-approved software, and AI meeting assistants are one of the fastest-growing forms of it. A free browser extension or a personal account connected to a work calendar can start joining meetings company-wide within days, with no procurement, security review, or policy behind it.

How can a company tell which AI meeting assistants employees are using?

Application and website usage visibility is the most direct signal. Monitoring software that reports which desktop applications and web domains employees actively use surfaces Otter, Fireflies, Fathom, and similar tools running across the organization, even when no one requested or approved them, without needing access to what was recorded.

Should companies ban AI meeting assistants outright?

Usually not. Outright bans tend to push the behavior underground rather than stop it, since the tools are genuinely useful for notes and follow-up. A more durable approach is naming an approved tool with acceptable data handling, requiring disclosure to participants, and monitoring for unapproved alternatives.

What should an AI meeting assistant policy cover?

An approved tool or shortlist, a rule against recording without disclosing it to every participant, guidance on what meeting types must never be recorded by a third-party AI, such as legal or HR conversations, data retention and deletion expectations, and a stated method for discovering unapproved tools in use.

Does eMonitor record or transcribe meetings?

No. eMonitor does not join calls, capture audio, or read meeting content. It reports application and website usage, so a company can see that Otter or Fireflies is running on managed devices during work hours, which surfaces the governance gap without eMonitor itself accessing anything said in the meeting.

Know which AI tools are in your meetings

eMonitor surfaces the AI notetakers and shadow AI tools already running across your organization. Start a 7-day free trial.