Portable AI notetakers - small devices that attach to phones or fit in a pocket - can now record workplace conversations, store them offline, and generate searchable transcripts and summaries without ever touching a company network. That means employees can capture conference-room discussions, job interviews, and customer calls using tools their organizations never approved, exposing employers to privacy violations, security breaches, and litigation risks.
These devices no longer need to appear in a videoconference participant list or be installed on an organization-issued computer. An employee can record a meeting, upload the audio through a personal device, and send it to a third-party AI service - all without the employer's knowledge. This practice, known as "shadow AI," bypasses the security controls many organizations have built to block unapproved AI tools.
Consent laws and third-party sharing
Recording laws vary widely by jurisdiction. Most states require only one party's consent to record a conversation, but others require all parties to agree. The analysis becomes more complicated when participants are in different states or countries, and portable devices expand the settings where the issue arises - including job interviews, workplace investigations, accommodation meetings, and conversations with patients or visitors.
Even when participants consent to being recorded, that consent may not cover what happens next. "Participants may not understand that the service will receive their voices and statements and use that information to create a transcript, identify speakers, summarize the discussion, and generate additional records."
What conversations are exposed
Workplace discussions often contain information that should never leave the organization: medical conditions, workplace complaints, customer data, business strategy, or trade secrets. A portable recorder can also capture incidental details that would never appear in formal meeting notes - an employee discussing a family member's health, a personal matter, or a conversation with legal counsel.
Outside the workplace, employees may record discussions with customers, auditors, government regulators, or lawyers. These third parties may have confidentiality expectations or legal protections that an undisclosed recording undermines.
AI recorders capture what participants say, not just what the organization decides should be memorialized. People speculate, raise concerns that later prove unfounded, or change their minds during a discussion. An AI-generated summary can preserve those statements as a searchable - and potentially incomplete - record.
Policies and approval processes
Organizations should not wait until they discover an unauthorized recording to act. A workplace recording policy should generally prohibit recording conversations without prior organizational approval and the knowledge and express consent of all participants. The policy should apply to audio and video recordings made through electronic devices, including personal ones, and identify categories of conversations that may not be recorded even with consent - such as discussions involving trade secrets, personal data, or privileged communications. Employers must also ensure the policy does not restrict employee activity protected by labor and employment laws.
An AI workplace usage policy should address AI tools by function, not just by brand name or software format. It should require approval of both the specific tool and the proposed use, prohibit conducting organization business through personal AI accounts or unapproved devices, and make clear that information submitted to an AI service counts as a disclosure to a third party.
An approval process should evaluate the specific tool, the proposed use, the people whose conversations may be recorded, and the categories of information likely to be captured. Approval for routine internal meetings should not automatically authorize recording workplace investigations, accommodation discussions, privileged communications, patient interactions, or customer calls.
Written policies alone are insufficient. Training should explain the risks of portable AI notetakers, the organization's approval process, when notice and consent are required, and which conversations may not be recorded. Managers, HR personnel, and meeting leaders should also know how to respond when they spot an unauthorized recording device.
Why this matters for management
Managers sit at the intersection of these risks. They lead the meetings being recorded, they approve tools, and they are often the first to notice a device on the conference table. A manager who understands what to look for - and what to do when they find it - can prevent a single employee's shortcut from becoming a privacy lawsuit, a regulatory investigation, or a leaked trade secret. For practical guidance on building these guardrails into HR and leadership practices, see AI for Human Resources and AI for Management.
Your membership also unlocks: