
Security measures for conversation intelligence face a new test this year: federal court. In 2026, multiple AI meeting notetakers and conversation intelligence platforms are facing lawsuits over recording consent, biometric voice data, and unauthorized use of customer recordings to train AI models- the exact violations call recording laws exist to prevent.
This blog breaks down those four measures, using real buyer evaluations instead of a hypothetical checklist, so you know what to verify before you sign.
These four measures focus more on accessibility and security nuances of the conversation intelligence platforms. Avoma's broader security checklist covers additional questions to raise with any AI notetaker and conversation intelligence platform before a contract review.
A pop-up notification that says a meeting is being recorded notifies participants. It does not ask them anything. More legal teams now treat that difference as the line between compliant and non-compliant recording.
One of our customers, an enterprise leader evaluating a conversation intelligence platform, said during initial evaluations,
The only disclosure (mentions competitor) provided was a little banner that pops up when it's in the meeting. We can't just have a passive participant that's informing them that they're being recorded. They need to actually click something to say, "I am giving you my permission.
Their legal team pushed back and did not choose the competitor tool, as the legislation is moving toward requiring meeting recordings to be dynamic.
Consent gets more complicated when someone outside your company joins a call your company did not organize. Another leader of a mid-sized company flagged this gap:
A lot of the tools will seek consent if you're the meeting organizer. But if you're not the meeting organizer, you don't get that big benefit.
This matters whenever a call includes someone from outside the host company. A consent system that only activates for the host misses those calls, including ones where a prospect or partner company sent the invite.
Avoma differentiator
Avoma's conversation intelligence platform runs a four-tier consent model: disabled, notification-only, acknowledgment required, and permission required. The permission-required tier presents a join-time screen with accept or decline options, and declining stops the recording. This tier addresses the gap both leaders raised, since it requires active permission regardless of who organized the meeting.
Disclosure: The consent still depends on which of the four tiers the host's organization sets as its default. If the host's organization defaults to the notification-only tier, a guest still sees only a pop-up. The guest sees the join-time permission screen only if their organization requires the permission tier or if Avoma's meeting policy settings enforce it. Organizations should confirm which tier applies by default rather than assume the strongest option is active.
Consent controls who gets recorded. Access control decides who can open that recording later. Most conversation intelligence tools handle this with a single toggle: it sets sharing as public or private for all recordings in the account. That one setting breaks down in three ways. It treats a routine standup the same as a sensitive legal call. It cannot stop a rep from sharing a link outside the deal team. It gives an admin no way to lock down one recording without changing the rule for the whole account.
Annother organization switched to Avoma from a (known AI notetaker) owing to the lack of governance over who could access recorded content.
Avoma differentiator
Avoma applies four layers of control to its recordings:
A prospect asking who else can see a recording gets an answer built from four checkpoints, not from a single shared setting.
Hosting location and processing rights are two distinct questions, and conversation intelligence platforms sometimes address only one. A security page can specify one hosting region, while a separate clause in the privacy policy permits processing at other global sites for support, analytics, or model training.
Buyers who read only the security page miss that second clause, and legal teams that catch it after signing have little room to renegotiate. The gap becomes a compliance problem the moment a contract or regulation requires data to remain within a designated region.
A prospect did not choose (a known Avoma competitor) due to this gap. GDPR friction and unreliable recording and compliance showed up as critical pains in their evaluation.
Avoma differentiator
Avoma hosts customer data on AWS infrastructure in the United States, inside an isolated Virtual Private Cloud, with encryption at rest and in transit. It holds SOC 2 Type II certification and is ISO/IEC 42001 certified fir Artificial Management System.
Avoma's privacy policy also permits processing at other global sites its cloud providers operate. Avoma governs that transfer under the EU-US, UK, and Swiss Data Privacy Frameworks and provides buyers with a direct opt-out via email.
Organizations that need data to remain within one region can request EU residency directly from Avoma's enterprise team, as this option is available on request.
For GDPR-covered meetings, Avoma recommends enabling the meeting reminder and the recording consent disclaimer for external participants, regardless of their location, since data residency alone does not satisfy consent requirements under the GDPR.
A conversation intelligence platform can get consent right and still expose a customer if it uses recordings to train shared AI models or shares data with undisclosed third parties. That risk sits on top of the consent question, not underneath it.
In August 2025, a plaintiff sued Otter.ai in a federal class action, alleging Otter recorded private conversations without consent and trained its AI models on them, even without a direct Otter account.
Many privacy policies give a vendor the right to train AI models on customer recordings unless the contract says otherwise. That clause sits in the privacy policy, not the security page a buyer checks first, so it can pass a security review unnoticed.
An AI governance framework asks this exact question of tools before adoption, and a conversation intelligence platform deserves the same scrutiny as any other AI tool using customer data.
Avoma differentiator
Avoma does not use customer meeting data to train its AI models, and that commitment is contractual in enterprise agreements, not merely a policy statement. It also shares its full sub-processor list, the third parties that touch customer data for hosting, transcription, and analytics.
Retention follows the same transparency standard. Admins set retention periods for recordings and transcripts, and any meeting owner or admin can delete a recording at any time. Avoma's Data Processing Addendum commits to deleting customer data within 30 days of contract termination, or sooner on request.
A compliance badge indicates that a vendor has passed an audit. It says nothing about how that vendor handles consent, where it processes data, who can open a recording after a call ends, or whether it trains AI models on customer conversations. Only a direct answer from the provider covers that.
Evaluate a conversation intelligence platform by how it answers those questions, not by how many compliance badges it lists on a website.
Book a demo with Avoma's team to walk through our privacy, security, and compliance.
A conversation intelligence platform must be compliant with SOC 2 Type II, ISO/IEC 42001 certified and support GDPR, HIPAA requirements where applicable. Beyond compliance certifications, companies should verify how the platform handles recording consent, access to sensitive conversations, data residency and processing, and AI training. Strong platforms should also provide encryption at rest and in transit, independent security testing, and clear controls over retention and deletion.
Not necessarily. A recording notification tells participants that a meeting is being recorded, while active consent requires participants to take an affirmative action before recording begins. The right approach depends on applicable laws, company policies, and participant location. Avoma supports multiple consent options so organizations can configure recording workflows based on their requirements.
Access to meeting recordings and transcripts should be governed at multiple levels rather than through a single public-or-private setting. Organizations may need different access rules depending on the meeting, user, team, or sensitivity of the conversation. Avoma provides four layers of control: organization-level policies, user-level settings, automation rules based on conditions such as meeting type or CRM stage, and manual admin overrides for individual recordings.
Data residency matters because companies may have contractual, regulatory, or internal requirements governing where customer conversation data is stored and processed. Organizations should verify both the vendor’s primary hosting location and whether subprocessors or cloud providers can process data in other regions. Avoma hosts customer data on AWS infrastructure in the United States and offers EU data residency on request. It also governs applicable international transfers under the EU-U.S., UK, and Swiss Data Privacy Frameworks.
Companies should explicitly verify whether recordings, transcripts, or other customer meeting data can be used to train the vendor’s or a third party’s AI models. They should also review the vendor’s subprocessor list and contractual terms rather than relying only on a security page. Avoma does not use customer meeting data to train its AI models, and this commitment is included contractually in its enterprise agreements. Avoma also publishes the subprocessors that handle customer data for services such as hosting, transcription, and analytics.


