TL;DR: AI Meeting Transcription Apps: The Data Risks Your Team May Not Know About, a practical compliance guide for enterprise and HR teams in 2026.
Your team is probably using AI meeting transcription tools. Possibly several of them. Some on free accounts you don't know about.
Otter.ai, Fireflies, Tactiq, Read.ai, Fathom, tl;dv, Avoma, and Krisp all work the same way at the infrastructure level: your meeting audio goes to their US-based servers for processing. There is no on-device transcription happening in your browser or on your laptop. When those meetings contain client names, financial projections, M&A discussions, employee performance conversations, or anything involving a patient's health, the compliance risks are real and often overlooked.
This guide covers what is actually happening to your meeting data, the specific regulatory obligations that apply, and what your AI meeting transcription policy needs to address before you have an incident rather than after.
How AI transcription tools actually work (and why it matters)
The mechanics are straightforward. When you click "record" in Otter or add a Fireflies bot to a Zoom call, the following happens in sequence:
- The audio stream from your meeting is sent to the vendor's cloud infrastructure.
- The vendor's servers run that audio through a speech-to-text model (usually a fine-tuned version of Whisper or a proprietary equivalent).
- The resulting transcript is stored in the vendor's database, linked to your account.
- You access the transcript through their web app, mobile app, or integration (Slack, Notion, CRM, etc.).
That process means the audio of your meeting, and the transcript derived from it, exists on a third party's infrastructure the moment recording starts. You don't own that infrastructure. You can't control what happens to it beyond the terms of service you agreed to when you created an account.
The free tier problem makes this worse. Most employees who start using these tools sign up on a personal free account, not a corporate account with negotiated terms. Free tiers typically have very different data handling rules than paid plans.
| Tool | Free tier transcript retention | Model training use | BAA available |
|---|---|---|---|
| Otter.ai | Indefinite (standard tier) | May use for product improvement | Enterprise plan only |
| Fireflies.ai | 800 minutes stored per seat | Not disclosed for free accounts | Business and Enterprise only |
| Read.ai | 5 meeting limit, then deleted | Not disclosed | Enterprise only |
| Tactiq | Limited exports on free | Not disclosed | Not advertised publicly |
| Fathom | Unlimited on free (check current ToS) | States "do not train on your data" | Not available as of mid-2026 |
| tl;dv | 10 meetings on free | Not disclosed | Business plan and above |
Verify each vendor's current terms before relying on this table. Terms change. The structural point stands regardless: free-tier data handling is materially different from enterprise plan data handling, and most employees start on free.
The shadow AI meeting bot problem
The specific scenario generating the most compliance exposure in 2026 is not an employee using an approved tool incorrectly. It is an employee adding a meeting bot to an external call that they were not authorized to record.
Here is how it happens. Many AI meeting tools let you invite the bot to any meeting by adding a bot email address to the calendar invite, or by pasting a meeting link into the tool's interface. The employee adds "[email protected]" to a client discovery call. The bot joins. It announces itself as "Fireflies Notetaker" in the Zoom waiting room. The client either clicks "admit" without reading, or the host admits it thinking it belongs to the client, or the meeting goes ahead before anyone notices.
The result: the audio from that client meeting is now stored in the employee's personal Fireflies account under whatever plan they signed up for, possibly free tier, with no DPA in place and no consent from the client.
The clients most at risk from this scenario are the ones you least want to expose:
- Law firm calls with clients discussing pending litigation or regulatory matters
- Medical practice calls with patients (potentially PHI under HIPAA)
- M&A discussions where the other party is evaluating a transaction
- HR conversations about a specific employee's performance or compensation
- Board meetings with non-public financial information
In 2025 and early 2026, multiple law firms discovered AI bots on client calls they had not authorized. Several medical practices found Otter.ai transcribing physician consultations conducted via Zoom. In most cases, the bot was added by a well-intentioned team member who wanted better notes, not someone trying to create a compliance violation.
Shadow AI, by definition, doesn't show up in your IT inventory until something goes wrong.
GDPR implications
GDPR applies whenever a meeting participant is an EU resident. It doesn't matter where your company is based or where the meeting is taking place.
Voice recordings are personal data. Transcripts that contain a person's name, their spoken opinions, or any information that identifies them are also personal data. If the transcript includes information about a person's health, political views, or trade union membership, it is special-category data with stricter protections.
Sending that data to a US-based vendor requires a valid international data transfer mechanism. The main options are Standard Contractual Clauses (SCCs) and adequacy decisions. The EU-US Data Privacy Framework provides a partial adequacy mechanism, but it only applies to vendors that have self-certified under the framework. Many smaller transcription tools have not.
Most enterprise-tier plans for major transcription tools include a Data Processing Agreement (DPA) that incorporates SCCs. Free-tier accounts do not. Using a free-tier transcription tool on meetings with EU participants, without a signed DPA and SCCs, is a GDPR violation. It's as simple as that.
Beyond the transfer rules, GDPR Article 13 requires you to inform data subjects about how their data is processed. In practice, this means:
- Tell every meeting participant, at the start of a recorded meeting, that AI transcription is active and who processes the data.
- Include AI transcription in your privacy notice if you use it for customer or external meetings.
- Allow participants to object. If an EU participant objects to being transcribed, you must either stop the recording or allow them to leave before it resumes.
HIPAA implications
The rule here is clear, even if it is often ignored in practice.
Any meeting that involves protected health information (PHI): a patient's condition, treatment plan, medication, test results, or anything that identifies the patient in connection with their health, is subject to HIPAA when your organization is a covered entity or business associate.
Voice recordings of those meetings are PHI. Transcripts of those meetings are PHI.
Using any third-party tool to process PHI requires a signed Business Associate Agreement (BAA) with that vendor. The BAA is not optional. It's the legal mechanism that makes the vendor accountable for handling your PHI in compliance with HIPAA's security and privacy rules.
Most AI transcription tools do not offer BAAs on free or starter plans. Several do not offer BAAs at all. Otter.ai, Read.ai, and Fireflies make BAAs available to enterprise customers only. Free and business-tier accounts are not covered.
If your medical practice, health system, or any team that discusses patients is using AI transcription: check whether you have a signed BAA with that vendor. If you don't, you have an active HIPAA compliance gap. Stop using the tool for any clinical call until you either sign a BAA or move to a HIPAA-compliant alternative. Your HIPAA compliance officer should be informed immediately.
Attorney-client privilege
Privilege protects confidential communications between an attorney and their client. It is one of the most valuable protections in the legal system, and it is not difficult to waive inadvertently.
The traditional privilege waiver analysis looks at whether the communication was kept confidential. When an AI transcription tool processes an attorney-client conversation, a third party (the vendor) holds a copy of that communication. That changes the confidentiality analysis.
In discovery proceedings, opposing counsel can subpoena the vendor for the transcript. Whether privilege holds in that scenario depends on the jurisdiction and the specific facts, but the argument that privilege was waived by voluntarily involving a third-party service has been raised in several cases in 2025. Some courts have found waiver. Others have not. The law is still developing.
The practical risk for law firms and in-house legal teams:
- Do not use AI transcription tools for any call with a client where you would normally assert privilege.
- If you use AI transcription for internal legal team meetings, ensure the vendor has signed a confidentiality agreement and that your engagement letters address AI tool use.
- If you want to use AI transcription for any legal work, consult with a legal ethics authority in your jurisdiction before deploying.
Your AI meeting transcription policy: what to cover
A policy that just says "don't use unapproved tools" will be ignored, because employees have already found tools that make their work easier. An effective policy names the approved tools, defines the acceptable conditions, and gives employees clear rules they can actually follow.
Eight things your policy needs to address:
1. Approved tools and plans. Name the specific tools that are approved, and which plan tier. "Fireflies.ai Business plan" is a policy. "AI transcription tools with a DPA on file" leaves too much room for interpretation.
2. Which meetings require explicit participant consent before recording. At minimum: any meeting with external participants (clients, vendors, candidates), and any meeting with EU residents.
3. Which meetings must never be recorded with AI tools. Attorney-client calls, patient consultations, board discussions of non-public information, M&A discussions, HR disciplinary proceedings, salary discussions, and any meeting where a participant objects.
4. Account requirements. No personal free accounts for business meetings. AI transcription tools must be used through the company's licensed account with a signed DPA.
5. Data retention. Employees must delete transcripts from the vendor platform after your defined retention period (30 days is a reasonable default for most teams). Transcripts should not accumulate indefinitely in a vendor's cloud.
6. New attendee notification. Anyone who joins a meeting in progress must be informed immediately if AI transcription is active, before they speak.
7. External participant consent. Require affirmative consent from all external participants before enabling AI transcription on any client, vendor, or partner call. A verbal "is it okay if we record and transcribe this call?" at the start, and a logged "yes," is a minimum.
8. Annual vendor review. Someone is responsible for reviewing the approved tool list, checking DPA status, and verifying BAA coverage for health-adjacent teams at least once per year.
Approved tool evaluation checklist
Before adding any AI transcription tool to your approved list, get answers to these questions. Vendors should be able to answer all of them. If they can't, or won't, that is the answer.
- Where are servers and data stored? Is EU-based hosting available?
- Is a signed Data Processing Agreement (DPA) available for this plan tier?
- Are Standard Contractual Clauses (SCCs) included in the DPA?
- Is a BAA available if you process any health information?
- What is the free-tier transcript retention policy? When are transcripts deleted?
- Can the organization opt out of audio or transcript use for model training?
- Is a list of subprocessors published and kept current?
- Can meeting hosts prevent unauthorized bots from joining their meetings? Is there an org-wide setting to block external meeting bots?
- What happens to data when the account is cancelled?
The last question matters more than most teams realize. Some tools retain transcripts for 30 to 90 days after account cancellation. Enterprise plans typically provide immediate deletion on request. Check the current ToS before you assume either way.
What to do right now
If your team is using AI transcription tools today and you haven't done any of this yet, a reasonable starting point:
Run a shadow IT audit for meeting tools. Ask employees which transcription tools they use, personally or through shared accounts. The actual list will be longer than your IT inventory shows. From that list, identify which tools process external or sensitive meetings, and which accounts are free tier.
Get DPAs in place. For any tool your team uses in meetings with external participants, get a signed DPA if you don't have one. Most vendors make this available on their website for paid plans. If the tool doesn't offer a DPA, it should not be used for external meetings.
Check HIPAA coverage. If your team handles any health information and uses AI transcription, confirm whether you have signed BAAs. If not, stop using those tools for clinical or patient-adjacent calls today.
Draft or update your meeting recording policy. Add the eight elements above. Make the approved tool list explicit. Put this in your employee handbook and your new hire onboarding.
The meeting recording problem is one of the easier shadow AI risks to address. The tools are well-known, the regulatory obligations are clear, and the fix (proper accounts, DPAs, and a written policy) is not technically complex. The hard part is discovering who is using what before something goes wrong.
For a broader view of shadow AI risk across your tools, see the shadow AI governance guide and the AI vendor due diligence checklist.
Related Reading
- Shadow AI governance, detection and visibility controls
- AI data privacy for small teams, GDPR and CCPA guide
- GDPR-compliant AI assistants comparison 2026
- AI vendor due diligence checklist 2026
- Privacy-first AI APIs that don't train on your data
- AI acceptable use policy template
- GDPR AI fines 2026 enforcement cases
- AI support chatbot account takeover risk 2026
- Vetting AI tools: avoid fake apps and malware
- CCPA and AI in 2026: what California's privacy law requires for AI tools
- Does your AI vendor train on your business data? 11 vendors compared
- ChatGPT Dreaming V3 memory governance: business privacy
- AI agent persistent memory and GDPR compliance
- Shadow AI Policy for Small Teams: 2026 Detection and Governance Guide
- AI Governance for Remote and Distributed Teams: The 2026 Playbook
- Anthropic vs OpenAI: GDPR Compliance Differences (2026)
- ChatGPT vs Claude vs Gemini enterprise compliance 2026: the complete compar
- GDPR Article 30 for AI Tools: Record of Processing Activities Template (202
- Microsoft Copilot data governance for small teams: what you actually need t
- Synthetic data governance and GDPR: what you need to document in 2026
