All posts
For consultants

Meeting notes with no sub-processor to disclose

Your client's security questionnaire has a row for every third party in the data path. A tool that runs on your laptop doesn't add one.

Short answer: a cloud notetaker adds at least one sub-processor to every client engagement — usually two, once you count the model vendor behind it. That has to be disclosed, flowed down contractually, and defended in procurement. A tool that processes on your own machine adds none.

The bot is increasingly not your decision

Even setting compliance aside, the bot-based approach is being closed off at the platform layer. In 2026 all three major platforms tightened controls on third-party meeting bots:

PlatformControlStatus
Microsoft Teams Bot detection routes suspected bots to the lobby as “Unverified”, requiring organiser approval Announced Mar 2026, GA from Jun 2026
Zoom Admins can disable or require approval for specific Marketplace apps account-wide Available
Google Meet Risk-scored lobby that can auto-deny suspicious joiners Rolling out 2026

The practical consequence for a consultant: your notes now depend on your client's IT policy. Turn up to a locked-down tenant and the bot sits in a lobby nobody admits it from, and the meeting you most needed a record of is the one you don't have. Capturing audio through your own machine has no such dependency.

What the questionnaires actually ask

If you sell to enterprises you've met the Cloud Security Alliance's CAIQ. The relevant rows are already there, and they're about sub-processors rather than AI specifically:

RefQuestion
DSP-13.1Are processes defined for the transfer and sub-processing of personal data within the service supply chain?
DSP-14.1Do you disclose details of any personal data access by sub-processors to the data owner before processing begins?
STA-07.1Is an inventory of all supply chain relationships maintained?
DSP-05.1Is data flow documentation created identifying what data is processed, and where it is stored and transmitted?

From CAIQ v4. Worth noting: CAIQ v4 contains no AI-specific questions at all — it predates the wave. The standards haven't caught up, which means the burden currently falls on the sub-processor questions above.

Every one of those is trivially answered when the answer is “none.” With a cloud notetaker, each becomes a paragraph, a DPA, and a change-notification obligation when the vendor swaps model providers.

GDPR Article 28

If any client is in the EU, using a cloud notetaker makes you the controller and the vendor your processor. Article 28(2) is direct: a processor “shall not engage another processor without prior specific or general written authorisation of the controller.” Article 28(4) requires the same obligations to flow down to every sub-processor.

Which means the model vendor sitting behind your notetaker is in scope, and changes to it are things you're supposed to be told about and able to object to.

Being careful here: the natural conclusion is that local-only processing means no processor, so Article 28 never attaches. That reads correctly from Article 4(8)'s definition — a processor processes “on behalf of” the controller, and there's nobody doing that. But we could not find a regulator (ICO, EDPB) stating this about local AI specifically. Treat it as a sound reading of the text, not as published guidance, and take advice if it's load-bearing for a contract.

What we couldn't verify, and won't imply

Two claims you'll see on competitor pages that we went looking for and could not stand up:

What is documented: Chapman University prohibited Read AI outright, citing that it “can attach itself to your calendar and join, transcribe, record, and summarize online meetings, even when you are not in attendance.” And there is active litigation — a consolidated class action against Otter.ai over recording participants without consent, and BIPA suits against Fireflies.ai over voiceprint capture.

The failure mode people actually hit

Not a regulator. A bot that stays in the room.

Reported cases follow one shape: the notetaker keeps recording after the client leaves, catches the internal debrief, and mails the transcript to the whole invite list. Speaking to an AP-syndicated report in July 2026, HRCI chief executive Amy Dufrane was unequivocal: “There are huge risks to the organization on AI notetakers. I don't think companies should use it at all.” In the same piece, attorney Justin Daniels described refusing to discuss anything substantive until the notetaker is switched off.

On Hacker News, an IBM employee's read on whether a popular notetaker would be approved internally: “The odds this is approved for employee use are essentially zero.” Another user described discovering a notetaker had made their notes folders — including one-to-ones — visible to their whole organisation by default.

None of these are exotic attacks. They're defaults, sharing models, and a bot with its own idea of when the meeting ended.

What you give up

Worth saying plainly, because local-only is not free:

Nothing to declare

Free forever. No account. Nothing leaves your Mac.

Download for Mac