Which AI Notetaker Should You Use for Your China Team?

Earlier this month, an independent security researcher going by “Bobdahacker” disclosed a flaw in tl;dv, a popular AI meeting assistant with more than 2 million users. Its database contained an error that allowed anyone to see every live call the assistant was on.

Four out of five times the researcher was able to join those meetings as an AI notetaker by simply requesting entry, according to Nate Nelson at Dark Reading. Affected organisations included government agencies in 23 countries, HubSpot, Mitsui Fudosan, the University of Tokyo and UC Berkeley.

AI notetakers are so ubiquitous that we tend to overlook the high degree of trust we give to them. This is third-party software that processes the names, voices and other personal information of your employees and clients, turning meetings into searchable corporate data. Many of them usually require access to company calendars, email and contact lists as well.

Despite this, I’ve yet to be in a meeting where somebody asked for the bot to be removed. Like with passwords and two-factor authentication, it’s probably going to take a few more years (and a few more high-profile incidents) before we become more careful.

Cross-Border Regulations

For companies with teams in China, the problem is as much as an HR/data security compliance issue as it is a cyber security issue.

First, there’s the obvious issue that many popular Western choices (Zoom AI, Otter, Fireflies) don’t work in China without a VPN. Plenty of people use these platforms inside China, but they’re usually foreigners with permanent VPN access, and not ideal for local employees.

The more serious consideration is the law, because China treats cross-border data transfer seriously. But not everything is treated the same way.

Most data a business moves in and out of the country is not restricted at all. Price lists, product specifications, factory schedules and marketing material leave freely, with no filing and no approval.

The problem is that popular Western cloud AI notetakers such as Otter, Fireflies and tl;dv process or store meeting data outside the Chinese mainland. If a China-based employee uses one of these services to record a meeting, personal information contained in that meeting may therefore be transferred across China’s borders.

Thankfully, the exemption most likely to help you is the one for transfers necessary to human resources management, which can cover recording your own staff, but only if your China labour rules and employment policies actually document it.

If a China-based client is on the line, however, their personal information would not fall within this HR-specific exemption.

Having said all that, we could not find a publicly reported Chinese enforcement action specifically involving a foreign company using an AI meeting notetaker. So, you might want to take this as our overly cautious reading of the law. Or you might take the view that the rules exist and simply haven’t been tested yet.

Recommendations

So, what would our advice be for cross-border teams?

1. Use Copilot on Microsoft Teams for Cross-Border Meetings

For anything cross-border, use the global version of Microsoft Teams. Most companies with employees in China are on Teams already, so use Copilot to transcribe your meetings. It doesn’t remove the legal grey zone around AI notetaking, but it doesn’t complicate things either: Microsoft is already your processor, and there is no new vendor in the chain.

Microsoft stores Teams and Copilot data based on your company’s Microsoft 365 setup, but different types of meeting data can be stored in different places. Check your data location before relying on Copilot for China-related meetings.

If you are using Teams, we would also suggest blocking third-party notetakers at tenant level, in Entra ID and the Teams admin centre. This prevents staff and clients from bringing their own notetakers into your meetings.

Also note that we mean the global Microsoft 365 tenant, not a 21Vianet-operated one. The China-operated version lacks an AI notetaker.

Western tools

2. Use Chinese Software for China Only Meetings

For meetings conducted entirely within China, consider China-based services such as Tencent Meeting AI Assistant, Feishu Miaoji, DingTalk AI, iFlytek Tingjian and Tongyi Tingwu.

It would also be wise to use one of these tools if you need an AI notetaker for a meeting with a Chinese client.

It is worth noting, though, that while this solves your China compliance problem, using the same tools for cross-border meetings risks running you into another country’s rules by putting data onto Chinese servers. If a China-based AI notetaker records a meeting involving U.K. employees, you also need to consider U.K. rules on sending personal data to China.

Chinese tools

3. Set Up a Tiered Meeting Rule

International law firm Mayer Brown also suggests implementing a tiered meeting rule. Routine meetings can be recorded using your approved tools. Legal advice, HR investigations, performance conversations, trade secrets and board deliberations get no AI notetaker at all.

This is clearly sensible for data security generally, but particularly so for staying in compliance with cross-border data rules. A voice print is one thing, but conversations that include employees sharing personal information such as ID card numbers are another area entirely.

If you really do need a record of a sensitive meeting, use a transcription tool configured to process the audio locally on the device, such as MacWhisper with an appropriate local model.

Local-only tools

For meetings that should not touch anyone’s cloud.

Finally, put in place a one-page policy, in English and Chinese, naming your approved tools, the retention period, your no-AI zones, and giving every employee explicit permission to remove an uninvited bot from a meeting.