Across California, city managers, department heads, and public officials are discovering the convenience of AI meeting transcription. Record a city council session, upload it to an app, and within minutes receive a summary, action items, and a searchable transcript. The technology works. The problem is where your recording goes after you hit upload — and what happens to it there.

For private businesses, the data risks of consumer AI meeting tools are manageable. For government agencies, those same risks carry legal, reputational, and public accountability dimensions that most IT departments have not fully considered.

This article is written for California city managers, county administrators, department heads, and IT directors who are evaluating or already using AI meeting transcription tools. Our goal is to help you ask the right questions — not to alarm you, but to ensure the tools you adopt are appropriate for the level of accountability your organization operates under.

How consumer AI meeting transcription actually works

Most popular AI meeting transcription services — the ones with app store downloads, free tiers, and consumer-friendly interfaces — operate on a shared cloud infrastructure model. When you upload a recording or connect a meeting bot, your audio is transmitted to the company's servers, processed by their AI model, and the transcript is returned to you.

What many users do not fully appreciate is what happens to that audio and transcript data after processing. Consumer AI companies often retain recordings to improve their transcription accuracy. This is how their AI gets better — by training on real recordings from real meetings. Your recordings may become part of that training dataset.

⚠ Legal Alert

A class-action lawsuit was recently filed against a major consumer meeting transcription service, alleging that the company used user recordings to train its AI models without obtaining sufficient informed consent — potentially violating federal wiretapping statutes and California privacy law. The lawsuit alleges that meeting participants, many of whom never agreed to any terms of service, had their voices and words used as AI training data without their knowledge.

For a private individual or a small business, this may be an acceptable risk tradeoff in exchange for a convenient, low-cost tool. For a government agency, the calculus is entirely different.

Why government agencies face unique exposure

Government agencies in California operate under a set of legal obligations that do not apply to private organizations. These obligations affect how you can handle data — including meeting recordings — in ways that most consumer AI companies have not designed their products to accommodate.

The California Public Records Act (CPRA)

Under the CPRA, records created or maintained by a public agency may be subject to public disclosure. This includes digital records — and potentially includes any records held by third parties on behalf of the agency. When your meeting recordings are processed and potentially stored by a consumer AI company, the question of whether those records are subject to a CPRA request becomes legally complex.

The critical question: If a journalist or member of the public files a CPRA request for your meeting recordings, can you account for every copy — including copies held by your transcription service provider?

The Brown Act

California's Brown Act governs how local government bodies conduct public meetings. It does not specifically address where meeting recordings may be processed or stored — but it creates a framework of public accountability around local government deliberations that is difficult to reconcile with recordings being sent to consumer AI companies for processing and potential training use.

Closed session meetings — which cover personnel matters, litigation strategy, real estate negotiations, and other sensitive deliberations — are specifically exempted from public disclosure under the Brown Act. Sending closed session recordings to a consumer AI service for transcription creates a data handling situation that is, at minimum, inconsistent with the spirit of that exemption.

"The question is not whether your meeting was recorded. The question is where that recording went, who processed it, and whether your agency can account for it under a public records request."

Personnel and legal proceedings

Many government meetings touch on topics that carry specific confidentiality requirements — personnel evaluations, disciplinary proceedings, legal strategy discussions, labor negotiations. When these discussions are captured in a recording and sent to a consumer AI service, the confidentiality protections that apply to the meeting itself may not follow the recording to the third-party processor.

What to look for in a meeting transcription tool — and what to avoid

Not all AI meeting transcription tools carry the same risks. The key is to understand how any tool you evaluate handles your data before, during, and after processing. Here is a framework for evaluating your options.

Evaluation checklist for government agencies

Where is the data processed? Recordings should be processed on infrastructure that the vendor controls and can specifically account for. "Cloud processing" without specifics is not an acceptable answer.
Are recordings used for AI training? Any tool that uses your recordings to train or improve its AI models is not appropriate for government use. This should be a hard contractual commitment, not a policy subject to future terms-of-service changes.
Is there a complete audit trail? Every access, upload, download, and administrative action involving your recordings should be logged with timestamps and user attribution.
What happens to audio after transcription? Raw audio files should be deleted after transcription is complete. Indefinite retention of audio creates unnecessary data liability.
Is the vendor a consumer app company? Tools designed for consumer convenience may not have the data handling, security practices, or contractual commitments appropriate for government use.
Does the vendor have documented security practices? Look for formal security audits, documented infrastructure controls, and a clear security contact. Not a help desk — a security team.
Can the vendor support a CPRA response? If your agency receives a public records request that touches meeting recordings, can the vendor confirm what data they hold and provide it or confirm deletion?

The specific risks of closed session recordings

Closed session meetings present the highest risk category for AI transcription tool misuse. These sessions cover the most sensitive deliberations your agency conducts — and they are specifically protected from public disclosure under the Brown Act for good reason.

The risk scenario is straightforward: a closed session recording is uploaded to a consumer AI transcription service. The service processes the recording on shared cloud infrastructure. The recording is retained for model training purposes. A future data breach, legal discovery request, or regulatory inquiry surfaces the recording in a context your agency cannot control.

AXIOM's assessment is direct: closed session recordings should never be processed by consumer AI tools. If you need AI transcription for closed sessions, the processing must happen on infrastructure your agency controls or that a trusted security partner controls on your behalf under a documented data processing agreement.

What responsible AI meeting transcription looks like for government

The good news is that AI meeting transcription can be done responsibly for government agencies. The technology itself is not the problem — it is how and where that technology is deployed.

A responsible implementation for government agencies has the following characteristics:

Practical steps for California government agencies

If your agency is currently using consumer AI meeting transcription tools, here are the immediate steps we recommend:

  1. Inventory your current tools. Identify every AI meeting transcription tool in use across your agency — including tools adopted by individual departments without central IT approval.
  2. Review the terms of service for each tool. Specifically look for language about data retention, AI training, and third-party data sharing.
  3. Stop using consumer tools for closed sessions immediately. The risk is not theoretical — it is a documented liability that your agency can eliminate today at no cost.
  4. Establish an approved tool policy. Define which meeting transcription tools are approved for use, under what circumstances, and with what data handling requirements.
  5. Evaluate purpose-built alternatives. There are tools designed specifically for organizations that handle sensitive information. Evaluate them against the checklist above.
  6. Document your decision. Whatever tools your agency approves, document the evaluation process and the data handling commitments you received. This protects your agency in the event of a future records request or audit.
💡 From the Field

NSAG has advised Northern California municipal clients on AI tool adoption since 2025. The most common situation we encounter is a department that adopted a consumer meeting tool without IT involvement — often through a free tier — and has been using it for months without any data handling review. The good news is that this is correctable. The important thing is to identify it and address it before it becomes a liability.

A note on the Otter.ai lawsuit and what it means for public agencies

In 2025, a class-action lawsuit was filed against Otter.ai — one of the most widely used consumer meeting transcription services — alleging that the company recorded and processed meeting conversations without adequate participant consent and used those recordings to train machine learning models in potential violation of federal and California law.

We are not in a position to adjudicate that lawsuit, and we encourage agencies to review the publicly available filings and consult their legal counsel. What we can say is this: the lawsuit illustrates exactly the data handling risk that government agencies should be evaluating when they adopt consumer meeting tools.

The question for your agency is not whether Otter.ai specifically is appropriate for government use. The question is whether any consumer meeting tool — operating under consumer-facing terms of service, designed for convenience rather than compliance — is appropriate for an agency with public accountability obligations.

Our view is that it is not. And the lawsuit demonstrates that this is not a hypothetical concern.

Conclusion

AI meeting transcription is a genuinely useful technology for government agencies. The ability to generate accurate transcripts, summaries, and action items from recorded meetings can improve accountability, reduce administrative burden, and create better records of public deliberations.

The technology is not the problem. The deployment model is the problem. Consumer tools designed for convenience were not built for the accountability standards that government agencies operate under in California.

The path forward is to adopt AI meeting transcription tools that match your accountability obligations — tools built and operated by vendors who understand security, who make hard commitments about your data, and who can support your agency if your data handling practices are ever scrutinized.

That is what NSAG Meeting Intelligence was built to be.

Built for organizations that handle sensitive information

NSAG Meeting Intelligence processes all data on NSAG-controlled infrastructure in California. Your recordings are never used to train AI models. Audio is deleted after transcription. Full audit log included.

Start Free — No Card Required

Questions? Call 707.452.3015 or email support@nsag.ai

Frequently Asked Questions

Can government agencies use Otter.ai for meeting transcription?
Government agencies should carefully evaluate consumer transcription tools before use. Consumer tools may use recordings to train AI models, creating CPRA, FOIA, and data sovereignty concerns for public agencies. A class-action lawsuit was recently filed against a major consumer transcription service alleging unauthorized use of recordings for AI training. We recommend agencies use tools that process data on controlled infrastructure and provide hard contractual commitments against AI training use.
What are the Brown Act requirements for meeting recordings?
California's Brown Act requires local government bodies to allow public meetings to be recorded and sets rules around meeting conduct and public access. It does not specifically regulate where recordings may be processed or stored — but agencies should ensure their data handling practices comply with CPRA and their own IT security policies, particularly for closed session recordings.
Are closed session recordings subject to CPRA requests?
Closed session recordings are generally exempt from public disclosure under the Brown Act. However, using consumer AI services to process those recordings creates data handling complexity. If recordings are held by a third-party vendor, the agency's ability to fully account for and control those records may be compromised. We recommend closed session recordings only be processed on controlled infrastructure.
What is the safest AI meeting transcription tool for government agencies?
Government agencies should choose tools that process data on controlled infrastructure, never use recordings for AI model training, provide full audit trails, delete audio after transcription, and are operated by organizations with documented security practices. NSAG Meeting Intelligence was built specifically for these requirements by a Network Security Assessment Group operating a 24/7 Security Operations Center.