Artificial intelligence meeting assistant's guideline
Overview
Artificial intelligence (AI) meeting assistants are becoming increasingly common in online meetings. While these tools can improve productivity by transcribing, summarising or note-taking, they can also introduce privacy, security and governance risks, particularly where meeting information is stored or processed outside the entity.
This guideline provides considerations and good practices for hosting, joining and supporting meetings where AI meeting assistants may be present.
This guideline is for all staff, regardless of their role or entity.
Key takeaway
AI meeting tools that record, transcribe, summarise or analyse meetings and capture information should only be used where approved by the entity and meeting participants are aware of its use.
AI meeting assistants
AI meeting assistants such as ReadAI, Otter.ai, Fireflies.ai, Fathom and Microsoft Copilot are designed to make meetings efficient by:
- recording and transcribing conversations in real time using speech-to-text and speaker recognition
- summarising discussions into key points or action items
- generating reports, notes or follow-up emails automatically
- integrating with major platforms like Microsoft Teams, Zoom and Google Meet.
Typically, one participant invites the tool, but once active, it can capture everything said and typed in chat – even if others in the meeting didn’t give their consent. Some AI meeting assistants request access to a user’s calendar and may automatically join scheduled meetings. In some cases, these tools send automated follow-up emails to all meeting participants offering access to meeting transcripts or summaries, which can lead to wider sharing and unintended sign-ups.
What are the risks?
AI meeting assistants may be helpful, but if they operate outside an entity’s control, entities can lose track of where information goes, who has access to it and how it might be used. This creates risks that are easy to overlook in everyday meetings:
- Loss of privacy: Anything said or typed, by anyone in the meeting, can be recorded and stored. AI meeting assistants often also access all calendar information. Under the terms and conditions of some AI meeting assistants, information captured during meetings may not be treated as confidential and may be retained, analysed or otherwise used by the provider. Entities using AI meeting assistants will need to comply with the Queensland Privacy Principles (QPPs) set out in the Information Privacy Act 2009 (Qld) (IP Act).
- Recordkeeping and AI tools: The recordkeeping requirements for AI meeting assistants are the same recordkeeping requirements public authorities have for all their business activities. See Artificial Intelligence and public records for more information.
- Data sovereignty: AI meeting assistants often save data on the AI provider’s platforms, which are commonly located outside of Australia.
- Sensitive information exposure: Business plans, personal information, data or decisions could end up outside of the entity’s control.
- Reliability risks of AI: AI systems can introduce bias, summarise decisions and outcomes incorrectly/without transparency, and operate in ways that are difficult to challenge or explain. This can lead to unfair outcomes, reduced accountability, and loss of trust, particularly when decisions impact individuals or sensitive government functions.
- Record accuracy and legal risk: AI-generated transcripts or summaries may be incomplete, inaccurate or lack context. Where meeting records inform decisions, compliance activities or legal processes, this may create risks if the information is relied upon without verification.
- Information access considerations: Notes, transcripts and summaries created by AI meeting assistants that are documents of an entity or Minister are subject to the Right to Information Act 2009 (RTI Act). Documents subject to an access application must be released unless disclosure would, on balance, be contrary to the public interest. If entities cannot easily find and redact information, the time and effort saved by AI tools may be lost when responding to information access requests.
Agencies are expected to apply a consistent, evidence-based approach to identifying and managing AI risks across the lifecycle in line with the Artificial intelligence governance policy.
AI meeting assistant hygiene
Technical controls alone may not prevent AI meeting assistants joining meetings. Good meeting practices can help reduce risk regardless of the technical environment.
Types of meetings where guidance should be applied
Hosts should consider implementing AI meeting assistant guidance in meetings where there is a higher likelihood of sensitive information being discussed, including:
- cross-organisation meetings (multiple entities within Queensland Government or external parties)
- formal governance or decision-making meetings
- meetings involving sensitive or protected information
- meetings that are formally recorded or minuted.
For routine internal working meetings not listed above, organisational AI policies still apply but a formal AI notice is usually not required. Hosts and participants should use judgement and consider whether additional risks may be present, such as cultural norms around open conversation or frequent use of AI meeting assistants without participant awareness.
Recommended entity position
Entities are encouraged to determine their own position on the use of AI meeting assistants. The following recommendations outline the suggested approach and what to communicate:
- multi-entity meeting and external parties: ‘AI meeting assistants are not permitted’
- internal meeting:
- no approved AI meeting assistants: ‘AI meeting assistants are not permitted’
- approved AI meeting assistants: ‘Only approved AI meeting assistants may be used in this meeting. Approved tools: [approved tool name]’. It is highly recommended that participants inform the host before enabling an AI meeting assistant.
Completing a Foundational artificial intelligence risk assessment (FAIRA) aligned with the Artificial intelligence governance policy is a precondition of entity approval for use (to be conducted as per entity’s governance structure, not intended for individual meeting hosts).
Guidance for meeting hosts
Before and at the start of the meeting: hosts should set expectations at the beginning of the meeting inform participants of the entity’s position on AI meeting assistants using suggested wording above (see Recommended entity position).
During the meeting: monitor the participant list, noting that meeting assistants may still join meetings despite the business implementing technical controls trying to prevent unauthorised access.
If an AI meeting assistant appears unexpectedly, the host may wish to:
- avoid discussing sensitive information until the issue is resolved
- remove the AI meeting assistant from the meeting if it is not authorised by the entity or agreed upon by the meeting participants
- notifying the appropriate technical or cyber security team.
If using an AI meeting assistant, clearly label AI-generated meeting records, including the AI tool used, to support record keeping and retrieval.
Technical teams
Technical teams should support safe meeting practices where possible.
Potential measures include:
- blocking website access to known problematic AI meeting assistants to reduce staff sign up
- hardening EntraID application permissions to restrict users’ abilities to grant access to various cloud applications
- reviewing the entity’s environment to identify which users have enabled AI meeting assistants (and other apps) access to corporate information and remove access if needed
- utilising the meeting platform’s specific technical guidance on AI meeting assistants.
Contact cybersecurityunit@qld.gov.au for more detailed technical guidance.
Cyber security teams
Cyber security teams play a role in supporting safe adoption of AI tools by:
- providing guidance and education on the risks of AI use in meetings
- identifying risks related to meeting recording, transcription and data storage
- ensuring alignment with Queensland Government policies and entity ISMS controls
- supporting entities to assess and approve appropriate tools.