TL;DR: Consent to record is not the same as consent to have AI process your meeting for model training. These are separate questions with different legal requirements, and most meeting policies only address the first one.
Your team is almost certainly using at least one AI meeting tool. Zoom AI Companion is embedded in most paid Zoom accounts. Otter.ai and Fireflies.ai are popular third-party options that work across Zoom, Google Meet, and Microsoft Teams. They all do similar things: transcribe meetings, summarize discussions, generate action items.
But they handle your meeting data very differently. And the differences matter specifically when your meetings contain client information, personnel discussions, financial data, or anything that would be sensitive if it appeared in a vendor's training dataset.
This guide compares Zoom AI Companion, Otter.ai, and Fireflies.ai across eight compliance and privacy criteria. It also covers the shadow AI bot problem that most meeting policies miss entirely.
The consent gap most teams don't know about
Before getting into the tool comparison, there is a foundational issue worth naming clearly.
When someone clicks "record" in Zoom or adds an AI bot to a meeting, they are usually thinking about consent in one dimension: did participants agree to be recorded? That question is addressed by most corporate recording policies and by two-party or all-party consent laws in many US states.
But there is a second consent question that most teams have never asked: did participants agree to have the audio or transcript of this meeting used to train an AI model?
These are legally and practically separate questions. Recording consent is about whether a person agrees to have their speech captured. Model training consent is about whether a person agrees to have their speech used as training data to improve a commercial AI product.
Under GDPR, using personal data (which a meeting participant's speech clearly is) for a purpose not disclosed to the participant is a violation of the fairness and transparency principle. If your AI meeting tool's terms allow using transcripts for model training, and you have EU participants in your meetings, you need their specific, informed consent for that additional processing purpose, not just their general consent to the meeting being recorded.
Most meeting recording policies address neither question adequately.
The consent gap most IT teams miss
The specific problem is that AI meeting tools often activate recording and transcription without any per-participant opt-in, and the person who bears the legal risk for this is your organisation, not the vendor.
Zoom AI Companion requires a host or admin to activate it, but once active there is no mechanism asking each participant to individually consent. When AI Companion is running, Zoom shows a notification to participants that AI features are in use. Participants can see the notification. They cannot, in the standard product flow, click "decline" and continue in the meeting with their audio excluded from transcription. The practical choice is: accept or leave the call. Under GDPR Article 7, consent must be freely given, which the EU data protection authorities interpret as meaning that refusal must carry no penalty. Leaving a work meeting qualifies as a penalty.
Otter.ai joins meetings as a visible bot account, usually named "Otter.ai Notetaker" or a workspace-custom name. Participants can see the bot in the participant list. There is no automated verbal announcement, no in-meeting prompt to participants asking them to confirm they consent to AI transcription, and no per-participant opt-out mechanism in the standard product. The visibility of the bot name is treated by Otter as the consent mechanism. Whether that satisfies GDPR Article 7's "informed" and "freely given" requirements is contested, and most DPAs Otter issues do not resolve this question on the controller's behalf.
Fireflies operates identically to Otter in terms of consent mechanics. The bot appears in the participant list under its service name. No explicit per-participant consent prompt exists. The additional risk with Fireflies is the auto-join feature: if any participant has Fireflies connected to their calendar with auto-join enabled, the bot can enter a meeting the host did not invite it to, without any action by the host. The host may not notice. External guests definitely will not have been asked.
The legal exposure across all three tools:
GDPR Article 7 requires that consent is freely given, specific, informed, and unambiguous. A notification that AI is active, with no opt-out path other than leaving the call, does not clearly satisfy "freely given" or "unambiguous." Teams handling personal data about EU residents in meetings are carrying real Article 7 exposure when they rely on in-product notifications as the sole consent mechanism.
ECPA (Electronic Communications Privacy Act) governs recording in the US. For one-party-consent states, the host's consent is sufficient. For all-party-consent states - California, Florida, Illinois, Washington, and others - every participant must consent to being recorded. An AI bot that records and transcribes without each participant actively consenting may violate state wiretapping law in those jurisdictions, regardless of what the vendor's terms say.
Illinois BIPA (Biometric Information Privacy Act) applies when voice data is used to extract biometric identifiers. Tools that do speaker identification, voice fingerprinting, or similar analysis of audio to identify individual speakers may be collecting biometric data under BIPA. Fireflies and Otter both offer speaker identification features. BIPA requires written consent before collection, a retention schedule, and no sale of biometric data. The fines are substantial: $1,000 per negligent violation, $5,000 per intentional violation, per person.
| Tool | Configure this before your next external meeting |
|---|---|
| Zoom AI Companion | Disable AI Companion by default for external meetings: Admin settings → AI Companion → uncheck "Enable AI Companion for external meetings." Require a manual host activation for each external call. |
| Otter.ai | Require bot approval before joining. In workspace settings, set bot join behavior to "Ask before joining" rather than auto-accept, and train hosts to notify guests verbally at the start of any meeting the bot joins. |
| Fireflies | Set auto-join to "Ask before joining" in workspace settings (Settings → Fireflies Notetaker → Meeting preferences). Disable calendar auto-join entirely for accounts used in external client meetings. |
Tool-by-tool breakdown
Zoom AI Companion
Zoom AI Companion is integrated directly into Zoom's paid workplace plans. Unlike Otter and Fireflies, it does not require a third-party integration or a separate bot; it is part of the Zoom product itself.
Data training: Zoom states that for paid Zoom workplace accounts, it does not use customer audio, video, transcripts, or AI Companion-generated outputs to train its AI models without explicit opt-in. This applies to Business, Business Plus, and Enterprise plans. Free Zoom accounts have weaker terms.
Data residency: Zoom operates data centers in the US and EU. Paid customers can request that data processing occur in specific regions. EU customers with GDPR requirements should request EU data processing through their account settings or account representative.
DPA availability: Available for paid Zoom customers. Zoom provides a standard Data Processing Agreement accessible through their privacy documentation. Enterprise customers can negotiate custom terms.
Retention: Zoom meeting recordings and AI Companion summaries follow the retention settings configured by the account administrator. There is no mandatory indefinite retention. Retention can be set to specific periods and meetings can be deleted.
GDPR compliance: Zoom has published GDPR commitments and provides SCCs for international data transfers. The DPA covers Zoom AI Companion for paid accounts.
Consent mechanism: Zoom AI Companion is off by default and must be enabled by an account admin. When AI features are active, Zoom displays a notification to participants that AI features are in use. The visual indicator is the main consent mechanism in-product; organizations should supplement this with their own participant notice.
Pricing tier for privacy protections: Business plan or above. Free accounts do not have the same data protection commitments.
Otter.ai
Otter.ai is a standalone AI meeting notetaker that works across Zoom, Google Meet, Microsoft Teams, and in-person via mobile. It is widely used by individuals and teams, often on personal or self-service accounts.
Data training: Otter's privacy policy states that they may use de-identified and aggregated data to improve their services, which can include model training. Enterprise customers can negotiate DPAs that restrict this use more specifically. Free and Pro plan users are subject to the standard privacy policy, which is broader.
Data residency: Otter.ai's primary infrastructure is US-based. As of 2026, Otter does not offer EU data residency as a standard option. This is relevant for EU customers: using Otter without a DPA and SCCs for US data transfers may create GDPR transfer compliance issues.
DPA availability: Available at the Business and Enterprise plan levels. Free and Pro accounts do not have access to a formal DPA. For teams with GDPR obligations, this is a hard requirement before using Otter for any meetings involving EU participants.
Retention: Transcripts are retained as long as the account is active, with no automatic deletion on free or standard plans. Enterprise customers can negotiate retention limits. Deleted content may persist in backups for a period after deletion.
GDPR compliance: Otter makes general GDPR compliance claims on their website, but the specifics are plan-dependent. A DPA with SCCs is necessary for GDPR-compliant use with EU data. Free-tier accounts cannot achieve GDPR compliance for meetings involving EU residents.
Consent mechanism: Otter's bot joins meetings with a bot account name (usually "Otter.ai Notetaker" or similar). Participants can see the bot in the participant list. There is no automated verbal notification. Organizations using Otter must implement their own participant notice through calendar invites or verbal disclosure.
Pricing tier for privacy protections: Business plan at minimum; Enterprise for full DPA terms.
Fireflies.ai
Fireflies.ai is a meeting intelligence platform that offers automated meeting notes, action item extraction, and conversation analytics. It integrates with Zoom, Google Meet, Teams, Webex, and others.
Data training: Fireflies' terms state they use data to provide and improve the service. Business and Enterprise plan customers can request a DPA that addresses training restrictions. Standard and free plan terms are broader. Fireflies has published a GDPR-oriented privacy policy, but the operative terms for data use depend on the plan and whether a DPA is in place.
Data residency: Fireflies processes data primarily in US-based cloud infrastructure. EU data residency is not available as a standard option. EU customers need to rely on SCCs for transfer compliance.
DPA availability: Available at the Business plan level. This makes Fireflies slightly more accessible for small teams seeking GDPR compliance than some alternatives, as Business plan pricing is accessible to smaller organizations.
Retention: Meeting recordings and transcripts are retained in the Fireflies platform indefinitely by default. Users can delete individual meetings, and admins on Business/Enterprise plans can configure retention. Automatic deletion is not the default.
GDPR compliance: Fireflies publishes GDPR documentation and SCCs. DPA availability on the Business plan is a positive for small teams. Full GDPR-compliant use requires an active DPA and SCCs for international transfers.
Consent mechanism: Fireflies' bot appears in the participant list of meetings it joins. Like Otter, it does not automatically announce itself verbally. The auto-join feature is the main consent risk (see below). Organizations must build their own participant notice process.
Pricing tier for privacy protections: Business plan for DPA access.
Side-by-side comparison
| Criterion | Zoom AI Companion | Otter.ai | Fireflies.ai |
|---|---|---|---|
| Trains on your data? | No (paid plans, explicit) | Possibly (standard plans); DPA restricts on Enterprise | Possibly (standard plans); DPA restricts on Business+ |
| Data residency options | US + EU available | US only | US only |
| DPA available? | Yes (paid plans) | Yes (Business/Enterprise) | Yes (Business+) |
| GDPR coverage | Yes, with DPA | Yes, requires DPA + SCCs | Yes, requires DPA + SCCs |
| SOC 2 Type II | Yes | Yes | Yes |
| Retention default | Admin-configurable | Indefinite | Indefinite |
| Consent notification | In-product participant alert | Bot visible in participant list | Bot visible in participant list |
| Auto-join risk | No (requires user action) | Yes (calendar auto-join available) | Yes (calendar auto-join available) |
| Minimum plan for protections | Business | Business | Business |
The shadow AI bot problem
This is the governance issue that gets less attention than it deserves.
Otter.ai and Fireflies.ai both offer an auto-join feature. When enabled, the bot automatically joins any meeting that appears in the user's calendar. This means that if one person on a call has enabled Fireflies auto-join with their calendar connected, the Fireflies bot will show up in your meeting, even if you, as the host, did not invite it, do not have a Fireflies account, and did not consent to AI transcription.
The bot appears in the participant list under its service name, so it is technically visible. But participants who are not paying attention to the participant list will not notice it. And external guests on a call you are hosting have no way of knowing that one of your internal team members has an AI tool configured to auto-join their calendar meetings.
This creates a practical consent failure. The legal exposure depends on jurisdiction and the nature of the meeting, but the pattern is: AI bot joins meeting, transcribes a confidential conversation, stores it in a third-party platform, under terms that may allow training use, without all participants having been informed or having consented.
For a deeper look at how these bots create compliance exposure, see AI meeting transcription data leak compliance 2026, which covers the full range of AI transcription tools and their data handling practices.
Building a meeting AI policy
Before your team uses any of these tools for meetings that contain sensitive information, put the following in place:
Participant notice requirement. Any meeting that will be recorded or AI-transcribed should include a notice in the calendar invitation and a verbal disclosure at the start of the meeting. This is both good practice and, in many jurisdictions, legally required.
Approved tool list. Specify which meeting AI tools are approved for which types of meetings. A tool without a DPA should not be used for meetings involving EU participants, HR discussions, client confidential information, or financial data.
Auto-join restrictions. Require that team members disable auto-join features in Otter, Fireflies, or similar tools before using them for any external meetings or client calls. Auto-join is appropriate only for internal meetings where all participants have been informed.
Retention and deletion policy. Define how long AI meeting summaries and transcripts should be kept. Most tools do not auto-delete. Someone needs to own the periodic deletion of meeting records past your retention window.
Restricted data types. List categories of information that should not be discussed in AI-transcribed meetings (or that require extra controls). Examples: M&A discussions, personnel performance, attorney-client privileged conversations, patient health information.
Sample meeting recording notice
Copy and adapt this for use in calendar invites or email signatures when AI transcription will be active:
This meeting will be recorded and transcribed using [Tool Name]. The transcript and any AI-generated summaries will be accessible to [team members / list]. If you prefer not to have your audio captured, please let the organizer know before the meeting starts and alternative arrangements can be made. Transcripts are stored under [your organization's] retention policy and will be deleted after [X days/months]. For questions, contact [name or role].
Keep it short, specific, and include a genuine opt-out path. A notice with no real opt-out does not satisfy GDPR informed consent requirements.
For your AI tool governance framework more broadly, the shadow AI governance tools visibility tech teams guide covers how to detect which AI tools are actually in use across your organization. The AI acceptable use policy template small teams has a section on meeting AI tools that you can adapt directly.
If you need to track DPA status across multiple vendors including these meeting tools, the AI vendor DPA tracker 2026 covers the major tools in one place.
