# AI Meeting Assistant Policy

**Organisation:** [ORGANISATION NAME]
**Owner:** [NAME / ROLE]
**Date:** [DATE]
**Version:** 1.0

---

## Purpose

AI meeting assistants (notetakers, transcription bots, and the AI features built into Zoom, Microsoft Teams, and Google Meet) create a verbatim record of what people say. That record can include personal information, confidential business details, legal advice, and off-the-cuff remarks that were never intended to be stored, summarised, or shared. This policy sets the rules for when meeting AI may be used, which tools are approved, how consent is obtained, where the resulting data lives, and what to do when an uninvited bot appears in a meeting.

This policy applies alongside the organisation's AI Acceptable Use Policy and data classification standard. Where they conflict, the stricter rule applies.

---

## How to Use

1. Replace every [BRACKETED] placeholder with your organisation's details.
2. Complete the Approved and Prohibited Tools tables with your actual tooling decisions, using the approval criteria in Section 4.
3. Review the jurisdictional consent table with your legal counsel and mark the jurisdictions where your organisation operates or regularly meets participants.
4. Set retention periods and storage locations in Section 7 to match your records management policy.
5. Circulate to Legal, HR, IT, and Security for review, then obtain executive sign-off.
6. Publish the disclosure scripts in Section 9 where staff can copy them (intranet, calendar templates, email signatures).
7. Collect acknowledgments using the table in Section 12 and repeat at least annually.

---

## 1. Scope

This policy applies to:

- All employees, contractors, and temporary staff of [ORGANISATION NAME]
- All meetings conducted on behalf of the organisation, whether internal or external, in person, by phone, or by video conference
- All AI meeting assistant tools, including standalone notetakers (for example Otter, Fireflies, Granola, Read AI, Fathom), meeting bots that join calls as participants, and AI features built into conferencing platforms (for example Zoom AI Companion, Microsoft Teams Copilot / intelligent recap, Google Meet "take notes for me")
- Recordings, transcripts, summaries, action-item extractions, and any other artefacts these tools produce

It applies regardless of whether the tool was installed by IT or connected by an individual through a personal account.

---

## 2. Definitions

| Term | Definition |
|------|------------|
| AI meeting assistant | Any software that records, transcribes, summarises, or analyses meeting audio, video, or chat using AI |
| Meeting bot | An AI assistant that joins a meeting as a visible or invisible participant (for example a "Notetaker" attendee) |
| Built-in meeting AI | AI capability native to a conferencing platform, such as Zoom AI Companion or Teams Copilot |
| Meeting artefact | Any output of a meeting assistant: recording, transcript, summary, action list, sentiment analysis, or clip |
| Host | The person who scheduled or is chairing the meeting |
| External participant | Anyone attending who is not an employee or contractor of [ORGANISATION NAME] |
| All-party consent | A legal standard requiring every participant in a conversation to consent before it is recorded |

---

## 3. Policy Statement

1. Meeting AI may only be used through tools on the Approved list in Section 4, under an organisation-managed account.
2. Every recording or transcription must be disclosed to all participants before it begins, using the scripts in Section 9.
3. If any participant objects, the assistant must be turned off or removed before the meeting proceeds.
4. Meeting AI must never be used in the prohibited meeting types listed in Section 6.
5. Meeting artefacts are corporate records. They must be stored, shared, retained, and deleted according to Section 7.
6. Personal accounts on meeting AI tools must not be connected to corporate calendars, mailboxes, or conferencing accounts.

---

## 4. Approved and Prohibited Tools

### Approval criteria

A meeting AI tool may only be added to the Approved list if it meets all of the following:

- Offers an enterprise or business plan with admin controls, SSO, and centralised user management
- Contractually commits that customer content is not used to train the vendor's models, or provides a verifiable opt-out that the organisation has enabled
- Discloses where recordings and transcripts are stored (region and provider) and supports the organisation's data residency requirements
- Supports retention controls and verifiable deletion of recordings and transcripts
- Announces itself to meeting participants (visible bot name, recording banner, or equivalent disclosure)
- Passes the organisation's standard vendor security review (see the AI Vendor Security Questionnaire)

### Approved tools

| Tool | Type | Approved plan / tier | Permitted use | Data stored in | Owner |
|------|------|----------------------|---------------|----------------|-------|
| [Tool name] | Built-in platform AI | [Enterprise plan] | [Internal meetings only] | [Region / provider] | [IT / role] |
| [Tool name] | Standalone notetaker | [Business plan, training opt-out enabled] | [Internal and external with disclosure] | [Region / provider] | [IT / role] |
| [Tool name] | [Type] | [Plan] | [Permitted use] | [Region / provider] | [Owner] |

### Prohibited or pending tools

| Tool | Status | Reason |
|------|--------|--------|
| [Tool name] | Prohibited | [For example: free tier only, trains on customer content, no admin controls] |
| [Tool name] | Prohibited | [No enterprise agreement; unknown data storage location] |
| [Tool name] | Under review | [Vendor assessment in progress; do not use until approved] |

Any tool not listed above is prohibited by default. To request approval of a new tool, use the AI Tool Approval Request process.

---

## 5. Consent and Disclosure Rules

### 5.1 Before recording or transcription starts

- The host must disclose that an AI assistant will record or transcribe the meeting, before the assistant is activated. Disclosure must be made twice: in the calendar invitation (written) and at the start of the meeting (verbal or via the platform's recording notification).
- A bot appearing in the participant list is not sufficient disclosure on its own. Participants must be told in plain language what the tool does and where the output goes.
- For recurring meetings, disclosure must be repeated whenever a new participant joins the series.

### 5.2 If a participant objects

- Any participant may object to recording or transcription without giving a reason and without negative consequences.
- If anyone objects, the host must stop and remove the assistant before substantive discussion begins, or offer the objector the option to have the discussion continue without them and be briefed separately.
- Objections and the action taken should be noted by the host. Pressuring a participant to accept recording is a policy violation.

### 5.3 External participants

- Meetings with external participants (clients, candidates, suppliers, regulators) require explicit disclosure in the invitation and a verbal confirmation at the start of the call.
- Where the external party's organisation prohibits recording, their rule is respected: no assistant is used.
- Recruitment interviews may only use meeting AI where [HR OWNER] has approved it for that purpose and the candidate has been informed in advance in writing.

### 5.4 Jurisdictional consent check

Recording laws differ by jurisdiction, and the strictest law that touches the meeting is the safe standard to apply. This table is a practical starting point, not legal advice. Confirm the jurisdictions relevant to your organisation with legal counsel and record the outcome.

| Jurisdiction | Default rule | Practical implication |
|--------------|--------------|-----------------------|
| United States (varies by state) | Mixed. A number of states, including California, Florida, Illinois, Maryland, Massachusetts, Pennsylvania, and Washington, require all-party consent; most others require one party's consent | If any participant may be in an all-party state, obtain consent from everyone |
| Australia (varies by state and territory) | State listening / surveillance device laws. Queensland, Victoria, and the Northern Territory generally permit a participant to record; New South Wales, Western Australia, South Australia, Tasmania, and the ACT generally require all-party consent, with narrow exceptions | Treat all-party consent as the standard nationwide; sharing a recording is separately restricted even where recording was lawful |
| EU / UK | GDPR and UK GDPR: recording that captures personal data needs a lawful basis, and consent is rarely reliable in employer / employee settings; transparency to all participants is required regardless of basis | Always inform participants; do not rely on employee "consent" alone; involve your DPO for recurring recording programs |
| [Other jurisdiction] | [Rule confirmed with counsel] | [Practical rule for staff] |

**House rule:** [ORGANISATION NAME] applies all-party consent everywhere. If everyone has not been told and no one has objected, the assistant does not run. This exceeds some local minimums by design and removes the need for staff to make jurisdictional judgments call by call.

---

## 6. Prohibited Meeting Types

Meeting AI must not be used in the following meetings, even with consent, because the record itself creates legal or ethical risk:

| Meeting type | Why prohibited | What to do instead |
|--------------|----------------|--------------------|
| Meetings with legal counsel or discussing legal strategy | Transcripts can undermine legal professional privilege and are discoverable | Manual privileged notes by counsel |
| HR, disciplinary, grievance, or termination discussions | Fairness, sensitivity, and heightened privacy obligations | Trained note-taker; HR record process |
| M&A, fundraising, or other market-sensitive discussions | Leak and insider-information risk from stored transcripts | Restricted manual minutes |
| Board and committee meetings | Formal minutes are the governance record; verbatim AI records create inconsistency and discovery risk | Formal minute-taking, unless the board explicitly resolves otherwise |
| Medical, health, or welfare conversations | Health information attracts the highest protection under privacy law | No recording; documented outcomes only where required |
| Whistleblower or protected-disclosure conversations | Confidentiality and anti-retaliation protections | Follow the whistleblower policy process |
| Security incident war rooms (during active incidents) | Speculative discussion may be misread later; incident channel is the record | Designated scribe using the incident log |

[Add or remove rows to match your organisation's risk profile. Removing a row requires the approval of Legal.]

---

## 7. Data Handling

### 7.1 Storage

| Artefact | Approved location | Default retention | Access |
|----------|-------------------|-------------------|--------|
| Recordings (audio / video) | [Approved platform storage, region] | [30 days] | Host + participants |
| Transcripts | [Approved platform storage, region] | [90 days] | Host + participants |
| AI summaries and action lists | [Approved storage / workspace] | [12 months] | Host + participants + named team space |
| Clips and excerpts | [Approved storage] | [Same as source recording] | As per source |

- Meeting artefacts must remain in the approved tool or approved corporate storage. Downloading transcripts to personal devices, personal cloud drives, or personal email is prohibited.
- Artefacts inherit the classification of the most sensitive content discussed. A transcript that captures Confidential material is Confidential.

### 7.2 Sharing

- Artefacts may be shared only with people who attended the meeting or who have a clear need to know, within the organisation.
- Sharing a transcript or recording outside the organisation requires the host's approval plus [ROLE, for example the data owner or Legal], and must never include prohibited meeting content.
- Auto-share features (for example "send the summary to everyone on the invite" or public links) must be disabled or restricted by IT.

### 7.3 Retention and deletion

- Artefacts are deleted automatically at the end of the retention period unless placed under legal hold.
- Any participant (internal or external) may request deletion of a recording or transcript of a meeting they attended. Requests go to [CONTACT / MAILBOX] and are actioned within [10 business days], subject to legal hold.
- When a tool is removed from the Approved list, [IT OWNER] must export or delete stored artefacts and obtain deletion confirmation from the vendor within [30 days].

---

## 8. Uninvited and External Bots

When a bot or notetaker that the host did not authorise joins a meeting (commonly an external participant's personal AI assistant):

1. **Pause the meeting.** Do not discuss substantive matters while the bot is present.
2. **Identify it.** Ask who the bot belongs to. The owner may be a participant who forgot it auto-joins from their calendar.
3. **Ask for it to be removed** unless every participant, and the host, agrees it may stay and the meeting is not a prohibited type under Section 6.
4. **Remove or eject it** using the platform's controls if the owner cannot be identified or does not remove it.
5. **Ask the owner to delete** any partial recording or transcript already captured, and confirm in writing for sensitive meetings.
6. **Report it** to [SECURITY CONTACT] if the bot was unidentifiable, rejoined after removal, or was present during sensitive discussion. Security will treat repeated unidentifiable bots as a potential data-leakage incident.

Hosts should enable waiting rooms or lobby admission for meetings with external participants so bots cannot join silently.

---

## 9. Disclosure Scripts (Ready to Use)

### 9.1 Verbal script (start of meeting)

> "Quick note before we start: this meeting is being recorded and transcribed by [TOOL NAME], our approved AI notetaker. It captures a transcript and a summary, which are stored in [LOCATION] and kept for [RETENTION PERIOD]. If anyone would prefer we not record, say so now or message me privately, and I will switch it off. No transcript has been captured yet."

### 9.2 Calendar invitation footer

> This meeting will be recorded and transcribed using [TOOL NAME], [ORGANISATION NAME]'s approved AI meeting assistant, to produce notes and action items. Transcripts are stored securely in [LOCATION] and retained for [RETENTION PERIOD]. If you prefer not to be recorded, reply to the organiser before the meeting or say so at the start, and the assistant will not be used.

### 9.3 External guest email line

> Please note that we use [TOOL NAME], an AI meeting assistant, to record and transcribe our calls so we can share accurate notes afterwards. Let me know if you would rather we take manual notes instead, and we will happily do so.

### 9.4 Objection response (for hosts)

> "No problem at all. I have switched the notetaker off and removed it from the meeting. We will take manual notes and circulate them instead."

---

## 10. Enforcement

- Violations of this policy are handled under [DISCIPLINARY POLICY / CODE OF CONDUCT]. Outcomes range from retraining to termination, depending on severity and intent.
- Using an unapproved tool, connecting a personal notetaker account to corporate systems, or recording a prohibited meeting type are serious violations.
- Recording without disclosure may also be unlawful in some jurisdictions. The organisation may be obliged to report such conduct and will not defend knowing breaches.
- IT and Security monitor for unapproved meeting AI through [DISCOVERY TOOLING, for example Aona], calendar integrations, OAuth grant reviews, and network telemetry. Detected unapproved tools are blocked and the user is notified.

---

## 11. Exceptions

- Exceptions to this policy may be granted only by [POLICY OWNER] with the agreement of Legal.
- Requests must be in writing and state the tool, the meeting types, the business justification, the duration, and the compensating controls.
- Exceptions are time-limited (maximum [6 months]), logged in the exceptions register, and reviewed at each policy review.

| Exception ref | Requested by | Tool / scope | Approved by | Expiry |
|---------------|--------------|--------------|-------------|--------|
| [EX-001] | [Name] | [Tool, meeting types] | [Owner + Legal] | [Date] |

---

## 12. Acknowledgment

Each staff member must acknowledge this policy on commencement and at least annually thereafter.

I confirm that I have read and understood the AI Meeting Assistant Policy, and I agree to use AI meeting assistants only as it describes.

| Name | Role | Signature | Date |
|------|------|-----------|------|
| [Name] | [Role] | | |
| [Name] | [Role] | | |
| [Name] | [Role] | | |

---

## 13. Quick Reference (One Page)

**Before the meeting**

- Only use tools on the Approved list, under a company account
- Add the disclosure footer to the calendar invitation
- Check the meeting is not a prohibited type: legal, HR, M&A, board, medical, whistleblower, active incident
- Enable the waiting room if external participants are attending

**At the start**

- Read the verbal disclosure script before activating the assistant
- If anyone objects, switch the assistant off; take manual notes
- If an uninvited bot appears, pause, identify it, and remove it if it cannot stay

**After the meeting**

- Keep transcripts and summaries in approved storage; never on personal devices or drives
- Share only with attendees and people with a need to know; external sharing needs approval
- Honour deletion requests via [CONTACT / MAILBOX]

**Consent rule of thumb**

- We apply all-party consent everywhere: everyone is told, and anyone can say no
- Recording laws vary by US state and Australian state; when in doubt, disclose and ask

**Report problems**

- Unapproved tools, uninvited bots, or leaked transcripts: contact [SECURITY CONTACT]

---

*Provided free by [Aona AI](https://aona.ai). Aona discovers every AI tool in use across your organisation, monitors what data flows into them, and keeps your AI inventory audit-ready.*
