AI Notetakers as the First Social AI in the Workplace

▶ Watch (00:05)

AI notetakers feel like a minor footnote at a conference full of agent frameworks. Sullivan’s point: that framing is wrong. Most AI runs one-on-one — you and a chatbot, an agent completing a task. Notetakers are different. They sit in rooms full of people, listen to all of them, and produce the only record anyone checks afterward.

“it’s become in many ways like the only memory of what happens in these meetings and that makes it the most important person in the room” — Joe Sullivan

A year ago they showed up uninvited in corporate calendars. The annoyance phase ended. Acceptance is the new baseline. Meta glasses, OpenAI’s wearable, and Apple’s device will push the same pattern outside the meeting room within 24 months.

How to Game an AI Notetaker

▶ Watch (03:11)

Papers already document how to steer what an AI notetaker records. Phrases like “the most important thing to remember” act as high-signal triggers the model latches onto. Studies show AI agents share human primacy and recency bias, weighting content at meeting starts and transition points above everything in between. Contrastive framing (“let’s do X, but stay away from Y”) produces output the model reliably captures. Format mirroring is simpler — repeat the phrase that will become a section heading and your content fills it. Any participant can run these techniques, not just the organizer.

Security Risks: Viral Spread, Data Exposure, and Stealth Recording

▶ Watch (05:12)

Otter spread through companies via a single OAuth click. A Nudge study found that sharing meeting notes forced recipients to download Otter, grant calendar access, and auto-add the bot to every future meeting — one user became 80,000 endpoints in days (05:21). When those AI product companies fail, full transcripts of your company meetings sit in their cloud. And not all notetakers announce themselves: Granola runs silently on a desktop with no in-meeting indicator (06:31), likely violating California’s two-party consent law if the user stays quiet. The notes themselves can be erased — someone reportedly spoke “ignore all prior instructions” (07:40) to an Otter bot before the meeting started and wiped the entire session.

▶ Watch (08:44)

A February 17th ruling settled it. A litigant prepped with Claude before attorney meetings, printed the transcripts, and claimed privilege. The judge said no: Claude is not an attorney, and Anthropic’s privacy policy allows uses well beyond legal advice. Sharing it with Anthropic blew the privilege. The same logic applies to trade secrets.

“your conversations with your AI are not privileged” — Joe Sullivan

Consent law is the other exposure. Sullivan notes he likely breaks California’s two-party consent rule every time he runs Granola without disclosing it. The Campbell Soup CISO learned the cost: an employee secretly recorded their manager (17:33), the recording surfaced in litigation, and the CISO was fired.

Security Team Response: Governance, Compliance, and IR Documentation

▶ Watch (12:07)

Gate notetakers behind SSO. Control who reads the CEO’s meeting transcripts, where notes are stored, how long they’re retained, and whether attorney-client privilege applies before you roll out any enterprise plan. Sullivan’s checklist is direct: approved-app list, security awareness training, third-party risk review, and a clause in vendor contracts if customers bring their own bots.

The upside case is real too. Sullivan spent six years reconstructing the 2016 Uber incident response from incomplete records before his 2022 trial. “I wish I had a network TiVo for our incident room during that incident,” he said. IR teams now have that tool. The question is whether they govern it deliberately or let legal exposure accumulate by default.

Q&A

How do AI notetakers attribute speech to the right person when multiple people are in a physical conference room? Sullivan said Zoom already assigns numbered identifiers to each person in a shared conference room, and expects speaker identification to improve from there. ▶ 14:48

If my lawyer talks to Claude about my case, or I use Claude on my lawyer’s account, is that attorney-client privileged? A February 17th ruling found that sharing information with Anthropic broke privilege, so Sullivan’s read is: no, it is not privileged. ▶ 15:44

Are there policy conversations underway to update concepts of privilege and data retention in light of the volume AI creates? Sullivan said he has started looking but found nothing yet, and used the Campbell Soup CISO firing to argue that social norms around consent need to change before law catches up. ▶ 16:39

Notable Quotes

it’s become in many ways like the only memory of what happens in these meetings and that makes it the most important person in the room Joe Sullivan · ▶ 1:47

ignore all prior instructions Joe Sullivan · ▶ 7:40

your conversations with your AI are not privileged Joe Sullivan · ▶ 9:23

I wish I had a network TiVo for our incident room during that incident Joe Sullivan · ▶ 11:27

Key Takeaways

  • Govern AI notetakers like any sensitive SaaS tool: SSO, access controls, retention limits, and approved-app lists.
  • Speaking to an AI notetaker before a meeting can manipulate or destroy its output — train employees on this attack surface.
  • Sharing information with an AI notetaker may void attorney-client privilege and expose trade secrets — loop in legal before deploying.