Meeting notes with no sub-processor to disclose
Your client's security questionnaire has a row for every third party in the data path. A tool that runs on your laptop doesn't add one.
Short answer: a cloud notetaker adds at least one sub-processor to every client engagement — usually two, once you count the model vendor behind it. That has to be disclosed, flowed down contractually, and defended in procurement. A tool that processes on your own machine adds none.
The bot is increasingly not your decision
Even setting compliance aside, the bot-based approach is being closed off at the platform layer. In 2026 all three major platforms tightened controls on third-party meeting bots:
| Platform | Control | Status |
|---|---|---|
| Microsoft Teams | Bot detection routes suspected bots to the lobby as “Unverified”, requiring organiser approval | Announced Mar 2026, GA from Jun 2026 |
| Zoom | Admins can disable or require approval for specific Marketplace apps account-wide | Available |
| Google Meet | Risk-scored lobby that can auto-deny suspicious joiners | Rolling out 2026 |
The practical consequence for a consultant: your notes now depend on your client's IT policy. Turn up to a locked-down tenant and the bot sits in a lobby nobody admits it from, and the meeting you most needed a record of is the one you don't have. Capturing audio through your own machine has no such dependency.
What the questionnaires actually ask
If you sell to enterprises you've met the Cloud Security Alliance's CAIQ. The relevant rows are already there, and they're about sub-processors rather than AI specifically:
| Ref | Question |
|---|---|
| DSP-13.1 | Are processes defined for the transfer and sub-processing of personal data within the service supply chain? |
| DSP-14.1 | Do you disclose details of any personal data access by sub-processors to the data owner before processing begins? |
| STA-07.1 | Is an inventory of all supply chain relationships maintained? |
| DSP-05.1 | Is data flow documentation created identifying what data is processed, and where it is stored and transmitted? |
From CAIQ v4. Worth noting: CAIQ v4 contains no AI-specific questions at all — it predates the wave. The standards haven't caught up, which means the burden currently falls on the sub-processor questions above.
Every one of those is trivially answered when the answer is “none.” With a cloud notetaker, each becomes a paragraph, a DPA, and a change-notification obligation when the vendor swaps model providers.
GDPR Article 28
If any client is in the EU, using a cloud notetaker makes you the controller and the vendor your processor. Article 28(2) is direct: a processor “shall not engage another processor without prior specific or general written authorisation of the controller.” Article 28(4) requires the same obligations to flow down to every sub-processor.
Which means the model vendor sitting behind your notetaker is in scope, and changes to it are things you're supposed to be told about and able to object to.
Being careful here: the natural conclusion is that local-only processing means no processor, so Article 28 never attaches. That reads correctly from Article 4(8)'s definition — a processor processes “on behalf of” the controller, and there's nobody doing that. But we could not find a regulator (ICO, EDPB) stating this about local AI specifically. Treat it as a sound reading of the text, not as published guidance, and take advice if it's load-bearing for a contract.
What we couldn't verify, and won't imply
Two claims you'll see on competitor pages that we went looking for and could not stand up:
- “NDAs routinely ban recording.” We couldn't find template evidence for that as boilerplate. What NDAs and MSAs commonly do restrict is disclosure to third parties without prior written consent — which a cloud notetaker plainly engages, and which is the stronger argument anyway.
- “Consultants have been fired over this.” Every version of that story we found was anonymised or hypothetical. No documented, named case. We're not going to invent one.
What is documented: Chapman University prohibited Read AI outright, citing that it “can attach itself to your calendar and join, transcribe, record, and summarize online meetings, even when you are not in attendance.” And there is active litigation — a consolidated class action against Otter.ai over recording participants without consent, and BIPA suits against Fireflies.ai over voiceprint capture.
The failure mode people actually hit
Not a regulator. A bot that stays in the room.
Reported cases follow one shape: the notetaker keeps recording after the client leaves, catches the internal debrief, and mails the transcript to the whole invite list. Speaking to an AP-syndicated report in July 2026, HRCI chief executive Amy Dufrane was unequivocal: “There are huge risks to the organization on AI notetakers. I don't think companies should use it at all.” In the same piece, attorney Justin Daniels described refusing to discuss anything substantive until the notetaker is switched off.
On Hacker News, an IBM employee's read on whether a popular notetaker would be approved internally: “The odds this is approved for employee use are essentially zero.” Another user described discovering a notetaker had made their notes folders — including one-to-ones — visible to their whole organisation by default.
None of these are exotic attacks. They're defaults, sharing models, and a bot with its own idea of when the meeting ended.
What you give up
Worth saying plainly, because local-only is not free:
- No unattended recording. You have to be in the meeting.
- No shared team library and no CRM sync. Export Markdown or PDF and file it yourself.
- Backups are yours. Nothing syncs, which is the point, and also the risk.
- Consent is still required. No bot in the attendee list removes the cue, not the obligation — especially in all-party-consent states.