At some point, you’ve invited or were asked to allow an AI meeting assistant into a meeting. These AI-enabled tools are useful, but are they lawful, safe, secure and in line with your organisation’s compliance requirements?

Would you let a stranger record your meetings?

An AI meeting assistant is AI-enabled software that joins meetings, records what happens and creates transcripts. During this process, it processes personal information, confidential information, and other sensitive business information.

You need to have a policy position on AI meeting assistants, along with the correct procedure to follow based on that position.

AI meeting assistants are like strangers who aren’t part of your organisation but sit in on all your meetings and record what is being discussed and by whom. Would you let a stranger on the street sit in all your meetings? It’s unlikely, especially without proper due diligence. In this case, AI meeting tools are no different. They may even be worse. Yes, they are useful productivity tools, but they also introduce risks that need to be managed.

AI meeting assistants raise some GRC questions

AI meeting assistants present risks that traditional software does not. For example, unlike a traditional note-taking app, with voice-to-text transcription happening locally, an AI meeting assistant may involve a third-party vendor processing attendees’ personal and confidential information.

The third party can retain this information and, depending on the terms and settings, use it to train or improve AI models. And, because AI systems are not always reliable, the AI meeting assistant may at some point hallucinate and produce inaccurate discussion summaries. This opens your organisation up to a loss of control, an increased risk of inappropriate distribution, unauthorised access and exposure of your meeting minutes to a legal discovery process. 

Make a decision about AI meeting assistants

Do you want to integrate AI meeting assistants into your organisation? If the answer is no, you can prohibit their use and block the tools from accessing your systems. If you want to leverage AI meeting assistants, you should decide how you want to use them, document it in a policy, and establish a procedure. This process can also help you choose AI meeting assistants that align with your organisational values and compliance requirements.

A policy sets your position, and the procedure supports it by saying how to follow and achieve those outcomes.

Make sure you understand the difference between policies and procedures. To have a practical policy and procedure, workshop the issue and decide your organisation’s policy before documenting it. It’s also important to train your employees on the policy after the board issues it. 

Have your organisational controls in place

You can record your policy statements in a new policy or incorporate them in your AI Acceptable Use Policy (AI AUP). Either way can work, but you need a separate procedure to support your policy position.

The procedure lays out, step by step, what employees must do before, during and after using an AI meeting assistant. For example, your procedure may require employees to first check the AI register to confirm that it is approved for organisational use.

Conduct third-party risk management

Organisations should review any AI-specific clauses, intellectual property provisions, de-identification language and sub-processor models in vendor contracts.

Retaining control over your information and digital assets is about managing third-party relationships.

For example, contracts sometimes distinguish between customer data, such as recordings, transcripts and summaries, and usage data. Usage data includes information about who uses the tool, when they use it and how the tool performs. A customer may own the meeting transcript, but the vendor can be licensed to use the same material or retain de-identified information.

Many provisions can materially affect your confidentiality obligations, competitive position, regulatory compliance, and long-term control over your information and digital assets.

We enable you to leverage AI

No single AI governance approach works for all organisations. If that were the case, we would have shared it in this post. Different organisations have different types of meetings, risk profiles, information and reasons for using AI. If you want to use AI meeting assistants lawfully, securely and responsibly, we can help you work through the relevant issues.

Frequently asked questions about AI meeting assistants

  1. Should I allow an AI meeting assistant into my meetings? You can, but you should put measures in place to mitigate the risks posed by the AI meeting assistant.
  2. Do we need a separate AI meeting assistant policy? A separate policy can be useful, but it may also be appropriate to include the rules in your AI AUP and have a supporting procedure that details the practical instructions for recording meetings and using the tool.
  3. What is the biggest issue with AI meeting assistants? AI meeting assistants are third-party tools that can process and retain large amounts of personal, confidential and business information.

Actions to take

  • Have oversight over your AI tools by creating and maintaining an AI register using software.
  • Work through the relevant issues and develop policy statements and a procedure that is appropriate for your organisation by asking for our help.
  • Progress your AI governance by finding the right next steps for your organisation.
  • Fulfil your legal requirement to raise awareness about POPIA and PAIA by having an awareness session.