Bot-Free vs Bot-Based AI Notetakers: Which Is Right for Client-Facing Meetings?
Published September 26, 2026
- Bot-based notetakers join calls as a visible participant; bot-free tools capture audio at the device layer with no participant added.
- Since March 2026, Google Meet flags third-party notetaker bots as 'potential risk' and defaults to deny — every bot now requires an extra host click.
- Bot-free removes the meeting-participant problem, but most bot-free apps still upload audio to a vendor cloud (Granola, Jamie, Fireflies desktop).
- Only fully on-device capture — like Basil AI on Apple Neural Engine — eliminates both the visible-bot friction AND the vendor-cloud breach surface.
- For client-facing, legal, or compliance-sensitive meetings, bot-free on-device is the default in 2026; bot-based still fits unattended, server-side capture.
Quick answer: Bot-based AI notetakers join your call as a visible participant and stream audio to a vendor cloud; bot-free tools capture audio on the device itself. For client-facing meetings — sales, legal, consulting, board — bot-free is now the default because a visible bot signals surveillance, Google Meet flags third-party bots as 'potential risk' since March 2026, and on-device capture eliminates the vendor breach surface.
Every AI meeting assistant has to decide one thing before it does anything else: how does it get the audio? That single choice — join the call as a visible participant, or capture from the device itself — is now the most consequential decision in the category. It shapes what your client sees, whether Google Meet will let the tool in at all, whether a breach of the vendor's cloud exposes your privileged conversations, and whether the meeting can even happen when the room is a conference table instead of a Zoom link.
This guide explains the two capture models, why the industry tipped toward bot-free in 2026, where bot-based still wins, and how a fully on-device architecture takes the bot-free idea one step further by removing the vendor cloud entirely.
What is a bot-based AI notetaker?
A bot-based notetaker sends a virtual participant into your Zoom, Google Meet, or Microsoft Teams call. It authenticates against your calendar, dials in at the scheduled start time, and appears in the attendee grid with a name like "Otter Notetaker" or "Fireflies.ai." As AICentralResources' 2026 comparison summarizes, bot-based tools like Otter.ai, Fireflies.ai, Fathom, Zoom AI Companion, Avoma, Fellow.ai, and Notta "send a virtual participant into your meeting" that "sits in the participant list, records everything, and leaves when the call ends."
The bot streams audio to the vendor's cloud in real time. Transcription, speaker diarization, and summarization happen server-side. The finished notes land in your inbox — and a copy stays on the vendor's servers for as long as the retention policy allows.
What is a bot-free AI notetaker?
Bot-free tools skip the meeting-participant step entirely. As Fathom's 2026 bot-free explainer puts it, the recording agent "lives on the laptop or phone, not inside the meeting — so nothing joins, nothing needs admission, and the tool works whether you're on Zoom or sitting across a conference" room table. Capture happens at the operating-system audio layer: microphone input plus, on desktop, the system audio stream the meeting client is playing.
From the meeting's perspective, nothing is different. No extra tile in the grid, no "Notetaker has joined the meeting" chime, no admission from the waiting room, no awkward first minute explaining what the branded robot is doing on the call.
Why the industry tipped toward bot-free in 2026
1. Google Meet started flagging bots as 'potential risk'
The biggest structural change of the year came from Google. In March 2026, Google Meet rolled out a risk-based join queue for third-party bots. UC Today reported that the update was released on the Rapid Release track first, with Scheduled Release organizations expected to receive it in early April 2026. The mechanics are simple and unforgiving: as notes.so's post-policy roundup explains, Meet now flags third-party notetaker bots as "potential risk" and defaults to deny their entry, directly affecting Fireflies, Otter, Fathom, and any other bot-based tool.
Even bot vendors acknowledge it. The Airspeed (Glyphic) knowledge base tells its own customers that Google "recently updated how it handles third-party bots in Google Meet," that all bots "may be flagged as 'with potential risk' by default," and that Meet "now defaults to 'Deny' for bots flagged as potential risks." This is not a targeted crackdown on one vendor; it is a category-wide friction tax.
2. The tl;dv incident showed the cloud-vendor breach surface is real
In August 2026, Dark Reading disclosed a vulnerability in tl;dv — the popular "Too Long; Didn't View" meeting assistant that automatically joins, records, and transcribes video calls — that allowed hackers to spy on government and corporate video calls. A follow-up Business Explainer analysis reported that the vulnerability "put more than 180,000 meeting records across 80,000 or more users at risk" — a scale that would not exist if the recordings had never left participants' devices in the first place. For a deeper walkthrough of what went wrong in that architecture, see our tl;dv Firestore breach post-mortem.
3. Otter's class action showed how the visible bot invites lawsuits
Meanwhile, the Hintze Law analysis of In re: Otter.ai Privacy Litigation notes that on August 13, 2026, the U.S. District Court for the Northern District of California allowed significant portions of the proposed class action to proceed. The complaint alleges that Otter's "meeting assistant joined virtual meetings, recorded and transcribed conversations in real time, collected voice-related information, retained meeting content, and used that information to improve its products and machine-learning systems." As Social Europe reported, the underlying case (Brewer v. Otter.ai, Inc., Case No. 5:25-cv-06911) alleges Otter records non-users "without their knowledge or consent, and uses this data to train its machine learning models." The visible bot is the exhibit A in the plaintiffs' theory of the case.
Bot-based vs bot-free: side-by-side
| Dimension | Bot-based (Otter, Fireflies, Zoom AI, Fathom) | Bot-free / cloud (Granola, Jamie, Fireflies desktop) | Bot-free / on-device (Basil AI) |
|---|---|---|---|
| Appears in participant list | Yes — visible name | No | No |
| Requires host admission | Yes; flagged "potential risk" on Meet since March 2026 | No | No |
| Works for in-person / phone calls | No — needs a video-conference link | Yes | Yes |
| Audio uploaded to vendor cloud | Yes | Yes (for AI processing) | No — stays on device |
| Vendor breach exposes your recording | Yes (see tl;dv, Aug 2026) | Yes | No |
| Used to train vendor's AI models | Often (see Otter litigation) | Depends on policy | No |
| Works fully offline | No | No | Yes |
| Unattended / server-side capture | Yes | No — needs your device | No — needs your device |
When does a bot-based tool still make sense?
Bot-based capture is not going away, and for some jobs it is still the right choice. If you need a meeting recorded whether or not you personally attend, or if you want centralized server-side video recording across an entire organization, the bot is doing something a device-side agent cannot. Anarlog's 2026 Google Meet roundup puts it well: a visible bot "earns its place when unattended attendance, video recording, or consistent server-side capture matters."
Just budget for two things: participants seeing the bot in the list, and — on Google Meet — a host having to clear the "potential risk" prompt every single time.
Where bot-free stumbles: it usually still means "cloud"
Here is the part most bot-free comparison posts skip. "No bot in the meeting" is not the same as "no data in the cloud." Most bot-free tools capture on the device and then immediately upload the audio to their servers for transcription and summarization. Granola, Jamie, the Fireflies desktop app, and the tl;dv desktop app all follow that pattern — the recording agent is local, but the AI pipeline is not.
That distinction matters the moment you evaluate the breach surface. In the tl;dv incident, the bot vs no-bot mode did not protect anyone; the meeting records existed on the vendor's backend because that is where the AI ran. The Mayer Brown analysis of AI notetaker legal risk warns that "inputting privileged information into an AI tool operated by a third-party vendor may amount to disclosure to a third party, thereby waiving the privilege that would otherwise attach to those communications." The court in United States v. Heppner, No. 25 CR. 503 (JSR), 2026 WL 436479 (S.D.N.Y. Feb. 17, 2026), declined to extend attorney-client privilege to materials a defendant prepared using a consumer-grade generative AI platform.
If your risk register cares about vendor cloud storage — and for legal, healthcare, financial services, and board work, it does — bot-free is a necessary but not sufficient condition.
Compliance dimensions that survive the bot-vs-no-bot choice
Removing the visible bot does not remove any of the underlying obligations. A few of the big ones:
Consent to record
Many U.S. states require all-party consent for recording. Smith Anderson's legal analysis warns that "automatic recording by an AI note-taker may inadvertently violate wiretapping or privacy laws if participants are not properly informed." Bot-free tools quietly do the same recording — with the same disclosure duty. Your General Counsel decides the disclosure mechanism (verbal at top of call, calendar-invite note, written consent) for your jurisdiction.
GDPR: lawful basis, DPA, transfers
Under Article 6 of the GDPR, every recording needs a lawful basis, and legitimate interest requires a documented balancing test. Article 28 requires a written data processing agreement with any cloud vendor that touches the audio. And under Article 32, appropriate technical measures include limiting who can access the data. On-device processing collapses several of these questions at once — there is no processor to sign a DPA with, and there is no transatlantic transfer to justify — but your DPO makes the call.
Attorney-client privilege
For law firms, the Mayer Brown analysis is direct: for meetings involving privileged communications, organizations "should evaluate whether the use of third-party AI notetakers creates an unacceptable risk of privilege waiver." For a deeper walkthrough written for solo and small-firm attorneys, see our best AI meeting assistant for lawyers guide.
MNPI in financial services
For asset managers and broker-dealers, material non-public information in a meeting recording that sits on a vendor server becomes discoverable, subpoenable, and breach-exposable. Our MNPI-aware AI meeting notes guide and compliance-officer procurement guide walk through the architecture questions in detail.
Who should choose which?
Choose bot-free (on-device) if...
- You take client-facing sales, discovery, or kickoff calls where a visible bot signals surveillance and kills trust
- You are a consultant, lawyer, therapist, financial advisor, or executive whose meetings routinely include privileged, MNPI, or PHI-adjacent content
- You meet with enterprise or government clients whose IT departments already block third-party bots
- Your meetings often happen in a conference room, on a phone call, or on a random browser-based tool where no bot could join
- Your risk register treats vendor cloud copies of the audio as a material breach surface
Choose bot-based if...
- You need meetings recorded whether or not any specific person attends
- You want organization-wide, server-side coverage that does not depend on individual laptops
- You need video recording, not just an audio transcript
- Your meetings are internal-only, participants have signed off on the bot, and your platform is not primarily Google Meet
How Basil AI solves this — on-device, not just bot-free
Basil AI is a bot-free notetaker that goes one step further: the entire AI pipeline runs on your Mac or iPhone. There is no participant in your Zoom, Meet, or Teams call. There is also no vendor server holding a copy of the recording. Basil uses Apple's Speech framework and the Apple Neural Engine to transcribe in real time on the device, consistent with the on-device principles Apple describes in its privacy overview.
Concretely, that means:
- No bot in the participant list. Your client sees a normal, private conversation — not a branded robot.
- No Google Meet "potential risk" prompt. Nothing is trying to join the call, so there is nothing to flag.
- No vendor cloud to breach. The tl;dv-style incident is architecturally impossible because we never receive the audio.
- No training on your recordings. The Otter class action theory does not attach to a vendor that never sees the data.
- Works in the room and on the plane. Conference-table meetings, phone calls, offline flights — all captured, because we don't need a video-call link or a network connection.
- Notes live in Apple Notes. Your workflow stays inside the Apple ecosystem you already trust.
To be clear on the guardrails: on-device processing is an architecture fact — no vendor server is holding your recording. Whether that architecture is sufficient for your specific compliance regime is a determination your CCO, GC, or DPO makes.
The 5-question decision framework
- Do participants outside my org join my meetings? If yes, bot-free is the default.
- Do my meetings run on Google Meet? If yes, bot-based means the "potential risk" prompt on every call.
- Would a breach of the vendor's server be a material incident for my organization? If yes, on-device beats cloud bot-free.
- Do I need unattended, server-side recording of meetings I don't attend? If yes, bot-based still fits.
- Do I meet in person, on the phone, or on niche platforms? If yes, only device-level capture works at all.
The bottom line
The bot-vs-bot-free debate was cosmetic in 2024. In 2026, it is a procurement decision. Google Meet flags bots as "potential risk." Cornell and Oxford restrict them by policy. The Otter class action is proceeding. tl;dv leaked 180,000+ meeting records. The visible bot is no longer a neutral UI choice — it is a signal to your clients, a friction point on your platform, and a compliance exhibit if things go wrong.
Bot-free is now the default for client-facing meetings. Bot-free and on-device is the default for anything that would ever appear in a risk register.
Try the fully on-device notetaker
Basil AI captures every meeting on your Mac or iPhone with zero cloud upload. No bot in your call. No vendor server holding your recording. Just private, accurate notes that stay yours.
Frequently Asked Questions
What is a bot-free AI notetaker?
A bot-free (or 'botless') AI notetaker captures meeting audio directly from your device's microphone or system audio instead of joining the call as a visible participant. Nothing appears in the attendee list, no host has to admit a bot from the waiting room, and the tool works across any platform — Zoom, Teams, Meet, Slack huddles, phone calls, or in-person conversations — because it never touches the meeting infrastructure at all.
Why did Google Meet start flagging notetaker bots in 2026?
In March 2026, Google Meet began screening third-party bots and flagging them as 'potential risk' in the join queue, defaulting to deny entry. Google's stated rationale is that unauthorized bots recording corporate meetings raise legitimate security and compliance questions. The practical effect: every bot-based notetaker — Otter, Fireflies, Fathom, tl;dv — now requires an explicit extra click from the host on every Meet call.
Are bot-free notetakers actually more private?
It depends on the tool. Bot-free eliminates the vendor participant, but most bot-free apps (Granola, Fireflies desktop, Jamie) still upload audio or transcripts to a vendor cloud for AI processing. Only fully on-device tools like Basil AI keep the recording, transcription, and summarization on your Mac or iPhone with zero cloud upload. Your Chief Compliance Officer or GC determines whether that architecture matters for your data.
When does a bot-based notetaker still make sense?
Bot-based tools shine for unattended capture — recording a meeting you cannot attend, server-side video recording, or organization-wide coverage that does not depend on any one participant's laptop. If your workflow depends on a call being recorded whether or not you personally show up, a bot is the reliable path. Just expect the Google Meet 'potential risk' prompt and clear it with participants first.
Does a bot-free notetaker need consent to record?
Yes. Removing the visible bot does not remove the legal duty to disclose recording. Many U.S. states are two-party (all-party) consent jurisdictions, GDPR requires a documented lawful basis, and professional codes of conduct in law and healthcare add their own duties. Your General Counsel decides whether verbal disclosure at the top of the call, a calendar-invite note, or a written consent form is sufficient for your jurisdiction.
Which bot-free notetaker is best for compliance-sensitive work?
For attorney-client privilege, MNPI, PHI, or board discussions, the only architecture that removes the vendor-cloud breach surface is fully on-device processing. Basil AI transcribes locally on Apple Neural Engine with no cloud upload; other bot-free tools still transmit audio to vendor servers for AI. Your CCO or GC decides which architecture the risk register requires.