top of page
CETech 20 year logo.png
CETech 20 year logo.png

Before You Let AI Sit In on Your Meetings: The One-Page Policy Your Business Needs

  • 21 minutes ago
  • 5 min read

Somebody on your team is already using an AI meeting assistant. Maybe you know about it, maybe you don't. It joined a call last week, took notes, wrote a summary, and emailed it around, and everyone thought it was great. That is exactly when a business needs a short, plain-English policy — before the tool ends up sitting in a conversation it had no business hearing.




This Showed Up Faster Than Most Technology Does



Most workplace technology arrives through the front door. Someone budgets for it, somebody signs a contract, IT sets it up, staff get trained.


AI note-takers did not arrive that way. They arrived through a free trial, a browser extension, or a checkbox that was already on inside a platform your team was using anyway. One employee turns it on because it saves them twenty minutes of typing after every call. It works. Two weeks later, three other people are using different tools, and nobody in leadership has approved any of it.


We are not going to tell you to ban them. Honestly, they are useful, and the businesses we work with across manufacturing, engineering, construction, and healthcare are getting real value out of AI summaries and transcripts. But there is a gap between "useful" and "governed," and right now most small and mid-sized businesses in Western New York are sitting squarely in that gap.





What Actually Happens to the Recording



Here is the part worth understanding, because it drives every decision that follows.


When an AI assistant joins your meeting, it typically captures audio, converts it to a written transcript, generates a summary, and stores all of it on the vendor's servers. That storage may last thirty days or indefinitely, depending on the plan. Some vendors keep transcripts to improve their models unless you specifically opt out. Some make that setting easy to find. Some don't.


So the practical question is not "did the AI help." It is: who else can read this, for how long, and under what terms.


Most of the time the answer is fine. A weekly team huddle about project timelines is not sensitive. But run the same tool through a few other conversations and the picture changes fast.


An employee performance discussion. A call about an acquisition. A conversation where a client shares customer records or engineering drawings. A meeting where a patient's name comes up. A discussion with your attorney. In each case a permanent transcript now exists on a third-party platform that was never reviewed, never contracted with, and possibly never disclosed to the other people on the call.





The Consent Question, and Why New York Matters Here



New York is a one-party consent state for recording conversations, which means that generally one participant's awareness is enough for the recording itself to be lawful. That is the legal floor, and it is a bad place to build a policy.


Two reasons. First, the moment a call crosses a state line — and half your calls do — you may be dealing with a state that requires everyone on the call to consent. Second, and more practically: clients and employees find out. When a customer learns after the fact that their conversation was transcribed and stored by a service they never heard of, the reaction is rarely about legality. It is about trust, and that is much harder to repair than a settings change.


The simple standard that avoids all of it: tell people. "I've got a notetaker on this call, is that alright with you?" Ten words. It has never once cost anyone a deal, and it eliminates the entire category of problem.





Where Compliance Gets Real





If you handle regulated information, the stakes move up a level.


For a practice covered by HIPAA, an AI service that processes conversations containing patient information is handling protected health information, and that generally requires a business associate agreement with the vendor. Most free-tier consumer AI tools will not sign one. Which means a well-intentioned staff member turning on a free notetaker before a clinical or billing discussion has created a compliance exposure without anyone deciding anything.


For contractors working toward or holding CMMC certification, the same logic applies with sharper edges. Controlled unclassified information discussed on a call and transcribed to an unapproved cloud service is a control failure, and it is exactly the kind of thing that surfaces during an assessment when someone asks how you monitor for unauthorized cloud applications.


For businesses under SOC 2 obligations or contractual confidentiality terms, an unreviewed processor of company conversations is a vendor management problem regardless of what the tool costs.


None of this makes AI unusable. It just means the tool has to be chosen deliberately, with an agreement in place, rather than adopted accidentally.





A Policy You Can Actually Write This Month



The good news: this does not need to be a twenty-page document. Most of our clients get real protection from about one page that answers six questions.


Which tools are approved. Name them. One or two is plenty. If your business already runs Microsoft 365, the AI features built into the platform you have already contracted with are usually the easiest place to start, because the data stays inside an environment you have already vetted.


Which meetings are off limits. Be specific. HR matters, legal conversations, anything involving patient information, anything involving controlled or client-confidential technical data.


How consent works. One sentence spoken at the top of the call, every time, on external meetings.


Where the notes are allowed to live. If AI summaries end up in a personal account or a random consumer app, you have lost custody of your own records. They belong in company storage.


Who reviews the output. AI summaries get things wrong. They mishear names, invert decisions, and occasionally invent an action item nobody agreed to. Whoever ran the meeting reads the summary before it goes out.


Who to ask. Give people a name. Most shadow AI use is not defiance — it is an employee solving a real problem because nobody told them the approved way to solve it.





Two Things to Do Before You Write Anything



First, find out what is already in use. Ask your team directly, and look at what has been authorized to connect to your Microsoft 365 or Google Workspace environment. The list is usually longer than leadership expects, and part of what we do for clients is inventory those connected applications and flag the ones with broad permissions.


Second, check the settings on the tools you decide to keep. Two in particular: whether your data is used to train the vendor's models, and how long transcripts are retained. Both are usually adjustable. Both are usually set to the vendor's preference by default, not yours.





The Upside of Getting Ahead of It



Businesses that write this down early end up in a much better position than the ones who wait for an incident. Their teams use AI more, not less, because people are not quietly hiding a tool they suspect might be against the rules. Their clients hear a clear answer when they ask how their information is handled. And when an auditor, an insurer, or a large customer asks about AI governance — which is happening more and more in contract reviews — there is a document to hand over instead of a scramble.


That last one is worth noting. AI usage questions are showing up in cyber insurance renewals and vendor security questionnaires now. Having a policy is starting to be table stakes.





Not Sure What Is Running in Your Environment?



CETech has been helping New York businesses make technology decisions for more than twenty years, and this is one of the most common questions we are getting right now. We can inventory the AI and cloud applications already connected to your environment, tell you which ones raise a compliance flag for your industry, help you pick a tool that fits your obligations, and help draft the one-page policy your team will actually follow.


Call us at 585-441-0055, email [email protected], or reach out through CETechno.com to set up a conversation. It is a much easier discussion to have now than after a transcript ends up somewhere it shouldn't.


Comments


bottom of page