{"id":4396,"date":"2024-07-10T09:00:00","date_gmt":"2024-07-10T14:00:00","guid":{"rendered":"https:\/\/www.darkreading.com\/vulnerabilities-threats\/privacy-security-concerns-with-ai-meeting-tools"},"modified":"2024-07-10T09:00:00","modified_gmt":"2024-07-10T14:00:00","slug":"privacy-security-concerns-with-ai-meeting-tools","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/07\/10\/privacy-security-concerns-with-ai-meeting-tools\/","title":{"rendered":"Privacy &amp; Security Concerns With AI Meeting Tools"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt64510604f28d23a3\/668e8692c28f033e350574e8\/Meeting_room%281800%29_Federico_Caputo_Alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">AI-powered meeting assistants like Otter.ai, Zoom AI Companion, and Microsoft 365 Copilot promise increased employee productivity and a reliable record of discussions by attending online meetings alongside or instead of participants. AI assistants can record video and transcribe audio, summarize notes and actions, provide analytics, and even coach speakers on more effective communication. But do the benefits outweigh the associated security and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/data-privacy\" rel=\"noopener\">privacy<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> risks?<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Consider this: If a stranger appeared in a meeting room, intent on recording the conversation and using that information for unknown purposes, would that person be allowed to proceed unchallenged? Would the same conversation with the same level of candor occur? The answer, of course, is no. So why are businesses allowing AI meeting assistants to eavesdrop on conversations and collect potentially sensitive data?&nbsp;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Content Privacy\">Content Privacy<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These applications pose a significant privacy and security risk to corporate information and those being recorded. The potential for misuse is a pressing concern that many organizations still need to consider how best to manage. This technology is spreading faster than awareness of its risks, underscoring the need for immediate action.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The first victim of AI eavesdropping might be the quality of the conversation. Employees who speak candidly about co-workers, managers, the company and its customers, or investors might find themselves disciplined based on the assistant&#8217;s transcript, which could easily be taken out of context. In turn, the fear of how recordings might be used could also stymy innovation and transparency.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Other risks include employees feeling obliged to consent against their will because a more senior colleague wants to use an assistant, and an overreliance on the veracity of transcriptions, which may contain mistakes that, unchecked, become a record of fact.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Online meetings frequently also include discussion of personal data, intellectual property, business strategy, unreleased information about a public company, or information about security vulnerabilities, all of which could cause legal, financial, and reputational headaches, if leaked. Existing tools to stop leaks, such as data loss prevention systems, would not prevent the data from leaving the organization&#8217;s control.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">There is considerable potential for unauthorized access to or misuse of recorded conversations. Though enterprise solutions might offer some control through administrative safeguards, third-party applications often have fewer protections, and it may not always be clear how or where a provider will store data, for how long, who will have access to it, or how the service provider might use it.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Privacy and Security Often an Afterthought\">Privacy and Security Often an Afterthought<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Some transcription tools may\u200c allow the provider to ingest and use the data for other purposes, such as training the algorithm. Users of virtual meeting provider Zoom complained last year, after an&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cybersecurity-analytics\/following-pushback-zoom-says-it-won-t-use-customer-data-to-train-ai-models\" rel=\"noopener\">update to Zoom&#8217;s terms of service led to concerns<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;that customer data would be used to train the company&#8217;s AI algorithm. Zoom was forced to update its terms and clarify how and when customer data would be used for product improvement purposes.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Zoom&#8217;s past data privacy issues serve as a stark reminder of the potential consequences. A&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.ftc.gov\/system\/files\/documents\/cases\/1923167_c-4731_zoom_final_order.pdf\" rel=\"noopener\">settled Federal Trade Commission investigation<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;Federal Trade Commission investigation and a&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.bbc.com\/news\/business-58050391\" rel=\"noopener\">settled $86 million class-action privacy lawsuit<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;demonstrated that fast-growing startups can overlook data privacy and security.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Companies in this space may also end up inadvertently making themselves a target for hackers intent on getting access to thousands of hours of corporate meetings. Any leak, regardless of content, would be reputationally damaging for both the provider and customer.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The AI revolution does not stop in online meetings though. Gadgets, such as&nbsp;<\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.nytimes.com\/2024\/06\/06\/technology\/humane-ai-pin.html\" rel=\"noopener\">Humane&#8217;s wearable AI Pin<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, take the assistant concept a step further and can record any interaction throughout the day and process the content. In such cases, it seems even less likely that users of the pin will continually ask other parties for consent each time, easily exposing sensitive conversations.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Legal Considerations\">Legal Considerations<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The key legal consideration with regards to AI assistants is consent. Most AI assistants include a clear and conspicuous recording consent mechanism to comply with laws like the&nbsp;California Invasion of Privacy Act, which makes it a crime to record a person&#8217;s voice without their knowledge or consent. However, legal requirements vary: 11 states in the US, including California, have &#8220;all-party&#8221; consent laws, requiring all participants to consent to be recorded, while the remainder have &#8220;one-party&#8221; consent laws, where only one participant \u2014 typically the one doing the recording \u2014 needs to consent.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_center\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">Map of All-Party and One-Party Consent States<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><img data-recalc-dims=\"1\" decoding=\"async\" data-component=\"image\" class=\"ContentParagraph-Image\" data-src=\"https:\/\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.png\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.png?w=640&#038;ssl=1\" loading=\"lazy\" alt=\"Map of all-party and one-party consent states\" title=\"Map of all-party and one-party consent states\"><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">By taking these proactive steps, businesses can harness the benefits of AI assistants, while safeguarding their sensitive information and maintaining trust with employees and clients. By preventing incidents before they occur and ensuring that the integration of AI in meetings enhances productivity without compromising privacy and security, we can improve and revolutionize team collaboration.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Participants in online work meetings might assume <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/cyber-risk\/data-privacy\" rel=\"noopener\">privacy<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, but this often depends on the company&#8217;s policies and the jurisdiction. In the US, workplace privacy typically is limited by company policies. In contrast, the European Union and its member states, particularly Germany and France, offer stronger privacy protections in the workplace.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Noncompliance with recording laws can lead to criminal liability, which is rarely enforced, and civil damages and penalties, which are often litigated. More than 400 cases related to unlawful recordings have been filed in California alone this year, with thousands more in arbitration, though none are thought to be related to AI assistants \u2014 yet.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"Managing \u200cRisk\">Managing \u200cRisk<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">As AI assistants become increasingly integrated into both professional and personal spheres, leaders cannot overstate the urgency to address privacy and security concerns. To manage the risks, companies must quickly assemble dedicated teams to assess emerging technologies, and document policies and socialize them across the organization.&nbsp;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A comprehensive policy should outline the authorized use of AI assistants, consent requirements, data management and data protection protocols, and clear consequences for violations. Continuous updates to these policies are essential as technology evolves, and in parallel, there is a critical need to educate employees about potential risks and encourage a culture of vigilance.&nbsp;<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/vulnerabilities-threats\/privacy-security-concerns-with-ai-meeting-tools\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY AI-powered meeting assistants like Otter.ai, Zoom AI Companion, and<\/p>\n","protected":false},"author":12,"featured_media":4397,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-4396","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?fit=1800%2C1013&ssl=1",1800,1013,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?fit=1800%2C1013&ssl=1",1800,1013,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/07\/privacy-security-concerns-with-ai-meeting-tools.jpg?fit=1800%2C1013&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4396","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=4396"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/4396\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/4397"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=4396"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=4396"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=4396"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}