← Back to the blog AI Consulting · Toledo, Ohio

Is Your AI Notetaker Safe on Client Calls?

Jayson Hines · August 14, 2026 · 4 min read

I was on a call with a contractor last week and watched three different AI notetakers join the meeting before we even got past hello. His, mine, and one his estimator forgot he still had running from a different tool. Nobody blinked. That's just what meetings look like now, a room full of humans and a handful of bots quietly transcribing everything anyone says.

Earlier this month a security researcher found a hole in one of the popular ones, a tool called tl;dv, that let any signed up user pull meeting records for basically anyone else on the platform. Over 180,000 meetings. Government agencies, universities, companies you'd recognize. Mostly it exposed metadata, who created the meeting and whether it was recording right then, but in a chunk of cases that was enough to just walk into someone's live call uninvited. The company had known about it since January and still hadn't fixed it when this became public.

I'm not writing this to scare anybody off AI notetakers. I run one on almost every client call I have and it saves me real time. I'm writing it because most people treat these tools like they're invisible furniture, and they're not. It's a piece of software sitting inside your sales calls, your pricing conversations, every meeting where somebody says a number they wouldn't want a competitor to hear.

What actually changes for you

Nothing about whether you should use one. What should change is how much you trust it by default. A few things worth checking this week if your team runs any kind of AI notetaker, Otter, Fireflies, Fathom, Zoom's built in one, Google's, or tl;dv itself:

Look at who's actually in the call before you start talking numbers. If there's a notetaker bot sitting in the participant list that nobody on your team invited, that's not normal. The researcher who found the tl;dv hole walked straight into a government meeting with 157 people in it that way, and not one of them said anything.

Check your notetaker's sharing settings. Most of these tools default a recording to private, which is the right call, but people flip that to shareable at some point and forget about it. Anything set to shareable is one link away from anyone who has it.

And just think about what you actually say once the bot is running. If it's pricing you haven't offered anybody else, a client's financials, anything under an NDA, treat it the same way you'd treat email. Don't put it somewhere you don't control.

Small doesn't mean skipped

I hear a version of this in almost every workshop I run. Someone says we're a five person shop, nobody's coming after us. That's backwards. The tl;dv exposure didn't happen because a hacker went looking for a specific small business to target. It happened because a piece of software a lot of companies trust had a hole in it, and everybody using that software, big or small, was sitting in the same spot the whole time. You don't get skipped for being small. You get caught in whatever net was already out there.

This is part of what I walk through in the AI policy work I do with businesses around Toledo and Northwest Ohio, which tools are actually safe to run in a client meeting and which ones need a second look before your team keeps using them on autopilot. If you want a set of eyes on what your team's running right now, I'm happy to take a look.

Email Jayson