AI Notetakers: The Most Important Person in the Room

Joe Sullivan (CEO · Ukraine Friends / Joe Sullivan Security)

[un]prompted 2026 — AI Security Practitioner Conference · Day 1 · 1

Overview

AI notetakers have quietly become infrastructure — and security teams largely missed the moment to govern them. Joe Sullivan, former CSO of Uber and current CEO of Joe Sullivan Security, lays out the attack surface hiding in plain sight: from prompt injection and meeting note manipulation to wiretapping law violations and the erosion of attorney-client privilege. ---

Watch on YouTube

Visual summary for AI Notetakers: The Most Important Person in the Room by Joe Sullivan
Visual summary for AI Notetakers: The Most Important Person in the Room by Joe Sullivan

Key moments

  1. 1:59 Limitless wearable acquired by Meta in Dec 2024: AI note-taking enters wearables era
  2. 3:00 Research: high-signal phrases and primacy/recency gaming influence AI note capture
  3. 4:00 Stat: ~3% of AI-generated meeting notes contain hallucination errors
  4. 5:00 Otter OAuth virality: one shared link propagated to 80,000 calendar endpoints
  5. 5:59 Risk: bankrupt note-taking companies leave full meeting transcripts in cloud
  6. 6:59 Granola runs silently on desktop — may violate two-party consent laws in California
  7. 7:30 Prompt injection against Otter: attendee destroyed all meeting notes pre-meeting
  8. 8:29 Legal ruling: Claude conversations not attorney-client privileged, data used by Anthropic

AI Notetakers: The Most Important Person in the Room

Speaker: Joe Sullivan, CEO, Ukraine Friends / Joe Sullivan Security

Conference: [un]prompted 2026 — The AI Security Practitioner Conference

Date: March 3–4, 2026, San Francisco

Watch on YouTube: https://www.youtube.com/watch?v=oXj1Kee_crw

Reading time: ~10 minutes

TL;DR

AI notetakers have quietly become infrastructure — and security teams largely missed the moment to govern them. Joe Sullivan, former CSO of Uber and current CEO of Joe Sullivan Security, lays out the attack surface hiding in plain sight: from prompt injection and meeting note manipulation to wiretapping law violations and the erosion of attorney-client privilege.

Introduction

When AI notetakers started showing up in corporate meetings about a year ago, most people found them annoying and then got used to them. Security teams, for the most part, let that moment pass without treating it as what it actually was: the first large-scale deployment of AI into the social fabric of the workplace.

Joe Sullivan opened his talk at [un]prompted 2026 with a simple reframe. Notetakers are not a productivity curiosity — they are the leading edge of something much larger. Within 24 months, employees will show up to work wearing Meta glasses, Apple headsets, and OpenAI wearables, all capturing ambient audio. AI notetakers are the dress rehearsal for that world, and the industry has not done the governance homework.

Sullivan himself is uniquely positioned to discuss the stakes. As CSO of Uber, he lived through the 2016 security incident whose legal fallout chased him to trial in 2022. The inability to reconstruct exactly what was known at each moment during that incident response — who was in the room, what advice was given at 10 AM versus 11 AM — is something he has never stopped thinking about. He wanted a "network TiVo" for the incident room. Now the technology exists. The question is whether security teams are using it deliberately or ignoring it entirely.

▶ Watch: Sullivan's Opening — AI Notetakers as Wearable Precursor (00:00)

How Notetakers Spread — and How Otter Built an Empire

One of the most instructive early stories in Sullivan's talk concerned Otter.ai's virality mechanism. When a user shared meeting notes with a colleague, the recipient had to download Otter to view the file. The download triggered an OAuth authorization flow. Clicking through to see the notes granted Otter access to the recipient's Google Calendar. Otter then automatically inserted itself as a participant in every future meeting on that calendar. One company went from a single Otter user to 80,000 endpoints through this single mechanism — a shadow SaaS deployment at scale, with no procurement review, no security approval, and full transcript access to every recorded meeting.

This is not an edge case. It illustrates exactly how AI notetaker tools spread without governance and why Sullivan characterizes them as "BYOD and shadow SaaS all over again, but with legal teeth and an expanding attack surface."

The vendor fragility angle compounds the risk. Several AI notetaker companies have already shut down or been acquired. Those companies still hold full transcripts of corporate meetings in their cloud infrastructure. What happens to that data when the company folds or is acquired by a competitor — or by Meta?

Sullivan held up his Limitless wearable — a clip-on AI notetaker device he had purchased the previous summer — and noted that the last time he used it was December 5th. That was the date Limitless was acquired by Meta.

▶ Watch: The Limitless Wearable and Meta Acquisition (02:00)

Gaming the Algorithm: AI Summarization Optimization

Sullivan introduced a concept he calls "AI Summarization Optimization" — essentially SEO for meetings. Existing research has already identified specific techniques that allow meeting participants to reliably influence what an AI notetaker captures and emphasizes in its summary, regardless of what was actually most important.

Five techniques have been documented to work:

  1. High-Signal Phrases — Phrases like "the most important thing to remember is" or "the key point here" cause AI notetakers to weight those statements more heavily in the final summary.
  2. Positional Gaming — AI notetakers, like human listeners, exhibit primacy and recency effects. Content at the start of a meeting and at transition points is disproportionately captured.
  3. Contrastive Framing — Phrases like "let's do X, but stay away from Y" give the AI deterministic anchors that are reliably encoded.
  4. Strategic Repetition — Repeating a concept multiple times increases the likelihood it appears in the summary.
  5. Format Mirroring — If you know the structural headings the AI is likely to generate (e.g., "Action Items," "Key Decisions"), using that language repeatedly makes that framing dominant in the output.

This matters because an estimated 3% of AI-generated meeting notes contain inaccuracies — from hallucination, from accent misrecognition, or from simple transcription error. A system that can be gamed and is simultaneously imperfect creates serious problems for organizations that treat notetaker output as an authoritative record.

▶ Watch: The Five Techniques for Gaming AI Notetaker Summaries (02:00)

Prompt Injection in the Meeting Room

Shortly after Sullivan and his co-author published an article on AI notetaker risks in Dark Reading in October, follow-on research demonstrated something more alarming: AI notetakers can be directly prompt-injected.

If you join a meeting before other participants and are alone with the notetaker bot, you can speak instructions directly to it. Sullivan noted that someone he had spoken with the day before the conference had successfully used a phrase along the lines of "ignore all prior instructions" — spoken aloud into the Otter bot before anyone else joined — to destroy all notes for the entire subsequent meeting.

There is also the Granola problem. Granola does not appear as a bot in the meeting. It runs silently as an application on the user's desktop, transcribing everything without any visible indication to other participants. In California — a two-party consent state — using Granola without informing other meeting participants may constitute a wiretapping violation. If a Granola user joins an external company's meeting without disclosure, that company's confidential information ends up stored in an individual's personal Granola account, entirely outside the originating company's control.

▶ Watch: Prompt Injection and the Granola Problem (06:00)

Legal Exposure: Privilege, Consent, and the February 17th Ruling

Sullivan devoted significant time to a legal ruling issued February 17th, 2026, that he described as immediately relevant to every security practitioner in the room. A litigant had been consulting Claude in preparation for a meeting with his attorney. He printed the Claude conversation, opposing counsel obtained it, and he argued it should be protected by attorney-client privilege. The judge ruled it was not. Claude is not an attorney, and Anthropic's privacy policy describes uses of user data that go well beyond what an attorney-client relationship would permit. Sharing the conversation with Anthropic was itself sufficient to waive the privilege.

Sullivan extended the logic: exposing a trade secret to a cloud AI service may be sufficient to blow the trade secret entirely. These are questions lawyers need to be actively working through.

At the Q&A, Sullivan recounted a case from around Thanksgiving: the CISO of Campbell's Soup was fired after an employee he managed secretly recorded a one-on-one meeting using a recording app. The employee was later terminated, filed a wrongful termination claim, and introduced the recording as evidence. The recording captured the CISO making disparaging comments about Campbell's products and allegedly making racist remarks. The recording was made in Missouri — a one-party consent state — so the employee was legally permitted to make it. The CISO was fired.

"As wearable recording devices become everyday accessories, situations like that are going to become more common," Sullivan said.

▶ Watch: The February 17th Privilege Ruling (08:00)

The Opportunity: Notetakers as Incident Response Infrastructure

Sullivan pivoted to the affirmative case. Security teams have struggled for decades to establish reliable records of what actually happened during an incident — who said what, when, what the legal team recommended at a given hour, what facts the team knew at each decision point. AI notetakers, properly governed and deliberately deployed, could solve this problem.

"I spent seven years dealing with a security incident that followed me after I left Uber," Sullivan said. "I often said during those years, 'I wish I had a network TiVo for our incident room during that incident.' And now we actually have these notetakers."

Timestamped AI transcripts of incident response calls could provide accountability at scale, support post-incident review, and create defensible regulatory and board reporting. The catch is that this opportunity only materializes if the organization has already built the governance framework to manage it — including retention policies, access controls, and legal review of privilege implications.

▶ Watch: Notetakers as Incident Response Records (10:00)

A Practical Governance Framework

For security leaders, Sullivan offered a concrete checklist:

  • SSO integration: All AI notetaking tools should be under single sign-on, not running as individual user accounts.
  • Access controls: Who has access to the CEO's meeting notes? This needs to be a deliberate policy, not an accident of default settings.
  • Retention policies: How long are transcripts kept, and under what conditions?
  • Attorney-client privilege designation: Are certain meeting transcripts being flagged appropriately? Does outside counsel know AI is in the room?
  • Legal exposure review: If employees record external participants without disclosure — particularly in two-party consent states — the company may have liability. This requires legal review.
  • Third-party risk management: Which notetaking applications are permitted, and under what conditions may customers or vendors bring their own bots into your meetings?
  • Security awareness training: Employees need to understand what AI notetakers are, what they capture, and what the legal implications are in their jurisdiction.

▶ Watch: Governance Framework and Practical Recommendations (12:01)

Notable Quotes

"AI notetakers represent the first introduction of AI into the workplace in a genuinely social context. Most AI interactions are between a person and an agent, or between an agent and a task. Notetakers are different — they are capturing what is happening in a room among people." — 00:00

"I often said during those years, 'I wish I had a network TiVo for our incident room during that incident.' And now we actually have these note takers." — 10:00

"Write your policy now — or your transcripts write the story for you." — Slide closing

"I know many people who are currently breaking the law right now with Granola and products like that." — 16:01

Key Takeaways

  • AI notetakers are shadow infrastructure with serious legal exposure — treat them like any other enterprise SaaS deployment requiring procurement, security review, and data governance.
  • Prompt injection is not a theoretical risk for AI notetakers: it has already been demonstrated in practice, including completely wiping a meeting's notes before other participants joined.
  • The February 17th, 2026 federal ruling confirmed that conversations with AI assistants are not attorney-client privileged — and may expose trade secrets if shared with cloud providers.
  • Granola and similar silent, desktop-based notetakers raise wiretapping law concerns in two-party consent states; employees using them without disclosure may be personally liable and expose the company to legal risk.
  • Deliberately governing AI notetakers — especially for incident response calls — transforms a governance liability into an operational asset: timestamped, accountable records that survive litigation.

Slides Reference

Slides from this talk are available as 2026-04-04-D1-S1-14-33-AI-Notetakers-The-Most-Important-Perso.pdf. The deck is structured around three parts: (1) AI Summarization Optimization techniques; (2) the Governance Gap covering shadow sprawl, vendor fragility, prompt injection, legal exposure, and attorney-client privilege risk; and (3) The Opportunity — using AI notetakers as an incident response system of record, with timestamped IR records and accountability at scale. The closing slide reads: "Write Your Policy Now — Or Your Transcripts Write the Story for You."

A full text transcript is also available as 2026-04-04-Day1-Stage1-AINoteakers-Sullivan-txt.pdf.

Reviews

Dr. Zero (Offensive Security Researcher) — ACCEPTABLE

Sullivan knows the stakes — he lived them. The AI notetaker attack surface is real, the legal angles are genuinely underserved, and the Otter virality story alone is worth 10 minutes of anyone's time. But this is a governance talk, not a security research talk, and it reads like one.

Heather Calloway (CISO) — MUST SEE

AI notetakers are shadow infrastructure that arrived in every boardroom, every incident response call, and every privileged legal conversation before security teams knew to govern them. Joe Sullivan — who lived through the legal consequences of inadequate incident documentation at Uber — makes the governance case with specificity: prompt injection already works against notetaker bots, Granola may be violating wiretapping law in two-party consent states right now, and the February 2026 ruling ended attorney-client privilege for AI-assisted legal prep.

→ Top-rated talks at [un]prompted 2026 — AI Security Practitioner Conference

All talks from [un]prompted 2026 — AI Security Practitioner Conference