playbook
AI meeting bot consent and retention template for small teams
A practical notice, consent, retention, and sharing template for AI meeting bots, transcripts, summaries, and meeting recaps.
Bottom line
AI meeting bots should not join every meeting by default. They create recordings, transcripts, summaries, action items, and sometimes searchable recaps. That output can contain customer names, pricing, hiring discussions, legal issues, health details, security incidents, roadmap plans, and employee performance notes.
Use a written rule before inviting bots to customer, hiring, legal, support, or internal-sensitive meetings.
This template extends the broader AI meeting bots privacy and compliance risks playbook.
Meeting classification
| Meeting type | Bot default | Reason |
|---|---|---|
| Public webinar or public demo | Allow with notice | Content is intended for broad distribution. |
| Internal team standup | Allow if team agrees | Low sensitivity, but still may include customer or employee details. |
| Customer success call | Approval required | May include customer issues, account details, contracts, or roadmap expectations. |
| Sales call | Approval required | May include pricing, buying committee, contract, and personal data. |
| Hiring interview | Restrict by default | Candidate privacy and employment law risk. |
| Legal, HR, finance, security incident | Block by default | Sensitive and often privileged or regulated. |
| Board, acquisition, fundraising | Block by default | Strategic and confidential. |
Consent notice template
Use plain language at the start of a meeting and in the calendar invite:
This meeting may use an AI assistant to create a transcript, summary, and action items.
The output may be stored in our company workspace and shared with meeting participants or relevant internal owners.
Please say before we begin if you do not want the meeting recorded, transcribed, or summarized.
Do not share passwords, payment details, health information, private keys, or other restricted data during recorded parts of the call.
For external meetings, do not rely only on a small bot notification. Say it out loud or put it in the invite.
Retention settings
Decide retention before rollout:
| Output | Default retention | Owner |
|---|---|---|
| Audio/video recording | Off by default unless needed | Meeting owner |
| Transcript | 30-90 days for normal business calls | Team lead |
| AI summary | Same as transcript unless copied to CRM or project tool | Team lead |
| Action items | Keep in task system, not only in bot app | Functional owner |
| Sensitive call output | Delete or restrict quickly | Founder, legal, or security owner |
Microsoft documents Teams recording and transcript policy controls, including storage and permissions in OneDrive or SharePoint. Zoom documents AI Companion privacy, retention, and access controls, including admin-managed sharing behavior and zero data retention options for some temporary transcript inputs.
The practical point: choose a default retention period instead of letting every employee decide.
Sharing rules
Use these defaults:
- Summaries from external customer calls can be shared with the account team, not the whole company.
- Hiring summaries stay with the hiring team.
- Incident summaries stay with incident owners.
- Do not forward raw transcripts to vendors unless approved.
- Do not paste transcripts into unrelated AI tools without a separate approval.
- Do not use bot summaries as final legal, HR, financial, or security decisions.
If the bot cannot enforce sharing rules, enforce them in the workflow and audit access periodically.
Vendor approval checklist
Before approving a meeting bot, collect:
- Which meeting platforms it joins.
- Whether it records audio/video or only generates notes.
- Whether it stores transcripts, summaries, chat, screen content, or metadata.
- Whether admins can set retention.
- Whether admins can disable email delivery or public summary links.
- Whether summaries can be downloaded, copied, or forwarded.
- Whether legal hold, eDiscovery, or export features apply.
- Whether the vendor uses meeting content for model training.
- Whether the bot can join external meetings automatically.
- How offboarding removes bot access.
Rollout policy
AI meeting assistants are allowed only for approved meeting types.
Meeting owners must notify participants when AI recording, transcription, or summarization is used.
Employees may not invite AI meeting bots to legal, HR, finance, board, acquisition, security incident, regulated-data, or highly sensitive customer meetings unless leadership approves the specific use case.
Meeting summaries and transcripts must follow the team's retention and sharing rules.
If restricted information is captured, notify the meeting owner and delete or restrict the output where possible.
Evidence checked
- Microsoft Teams recording policy
- Microsoft Teams transcript and recording access controls
- Zoom Support: AI Companion
- AI meeting bots: privacy and compliance risks
- Small Team AI Security Checklist
FAQ
Is a calendar bot notice enough?
Not for sensitive external meetings. Put the notice in the invite and say it at the start. Give participants a clear chance to object.
Should transcripts be retained forever?
No. Default to a short retention period unless there is a business, legal, or contractual reason to keep them longer.
Should bots join hiring calls?
Restrict by default. If the team uses a bot for hiring, make the notice explicit, limit access, and define retention before the first interview.
Recommended next step
Add the notice template to your meeting invite policy, then run the AI Tool Risk Checker for the first meeting bot workflow.