The next time you host a Zoom meeting or webinar, be mindful of AI notetaker bots that can scrape your meeting for content without your consent. This poses a security issue for faculty, staff, and students who may be presenting research or displaying institutional data over Zoom. While there is no fool-proof solution to prevent these types of unauthorized recordings, there are steps you can take to protect your meeting from notetaking bots.
What are notetaker bots?
Notetaker bots are third-party automated services that can join Zoom meetings as participants, and silently record audio and video, generate transcripts, or even redistribute a meeting’s contents outside of the host’s control. Some services, like WebinarTV, find publicly-posted webinar registration links, register a bot attendee under a fabricated human name, and screen-record the session outside Zoom's environment so it can be posted on their own site without the meeting host’s permission.
Before your Zoom meeting
Reinforce your meeting registration: Enable registration in Zoom to prevent unauthorized users from accessing your meeting. You can enhance security by limiting registration to WCM users and affiliates, like NYP and MSKCC, when possible. Look for the Require authentication to join option when scheduling your meeting and view the pre-loaded options for affiliates in the dropdown menu. This will require attendees to log in with an email address the matches a domain (e.g., med.cornell.edu, nyp.org) that you select:
Restrict registration approval and look for common bot aliases: Elect to manually approve all registrants who sign up for your meeting. Reject registrants with generic display names, throwaway email domains (e.g., johnsmith@companymail.website), or emails associated with known scraping services (e.g., Otter.ai, Read.ai, Fireflies.ai, etc.).
Take care when sharing your meeting link: Never post your meeting’s join/registration link on a public-facing website.
During your Zoom meeting
Spot the bots
If you see any attendees matching these attributes, boot them out of your meeting:
- Attendee name is “[Name] Notetaker/Notes” or matches an AI tool
- Does not engage with the meeting (e.g., never speaks, doesn’t respond to polls/Q&A)
- Has a persistent recording indicator or visible transcription icon next to their name
- Joins immediately when meeting starts with a placeholder display name or a domain you don’t recognize
If your meeting was captured
If you discover your meeting was scraped by an AI notetaker:
- Collect info: Note the bot/service name, the registrant name/email that was used to join (if identifiable via registration data), and the time it joined.
- Look for vendor takedown process: If content was redistributed publicly, check the specific vendor's terms of service or contact them directly to remove the unauthorized material.
- Contact the Privacy Office: If a WCM webinar shows up on WebinarTV or a similar site, and included patient or health-related content, contact privacy@med.cornell.edu.
- Contact ITS Support: Create a ticket regarding the incident so account-wide protections can be reviewed and updated as needed.
Review our Zoom AI Notetaker Bot guide for more details on protecting your meetings.
