AI Notetaker Blocked? Why Microsoft Teams and Google Meet Are Quarantining Bots — and What Still Works
Microsoft Teams now routes third-party AI notetaker bots to a quarantine lobby. Google Meet flags them as risks. Here's what changed and what still works.

AI Notetaker Blocked? Why Microsoft Teams and Google Meet Are Quarantining Bots — and What Still Works
You open Zoom at 9 a.m. and notice your Otter or Fireflies bot is sitting in the lobby — again — waiting for someone to let it in. You let it in, the call ends, and next week the same thing happens.
If you're on Teams, you may have seen it labeled "Unverified." If you're on Google Meet, there was a "potential risk" warning. If you work at a university or a security-conscious enterprise, the bot may have been turned away entirely.
This isn't a bug. It's policy. In 2026, the three platforms that handle the majority of video meetings in the world changed how they treat third-party AI notetaker bots — and the net effect is that bots many people rely on for recording and transcription have become significantly less automatic.
Here's what changed, why, and what you can actually use when a bot isn't an option.
What Changed: The Platform-by-Platform Breakdown
Microsoft Teams: Quarantine Lobby, July 2026
The most significant policy change came from Microsoft. Starting in June 2026 and rolling out to all worldwide datacenters by July 31, 2026, Teams introduced mandatory bot detection and quarantine.
The default behavior: Teams identifies external third-party meeting bots based on their joining pattern, tenant origin, and application identity, then routes them to a lobby labeled "Suspected threats" and marked "Unverified." Organizers must manually admit them before the meeting can proceed.
This policy applies to every third-party AI tool that joins meetings as a participant bot — which is how Otter, Fireflies, Gong, Read.ai, Fathom, and most similar note-taking tools work. Under the new default setting (RequireApprovalWhenDetected), none of them auto-joins anymore. Every admission is logged in the meeting audit trail with timestamp, organizer identity, and the bot's claimed application ID.
Administrators can switch the setting to AllowBots to restore the old behavior, but Microsoft's default is quarantine — and many enterprise IT teams are leaving it there. In August 2026, Microsoft is adding a stricter option: the ability to automatically block all detected external AI bots outright, with no lobby admission possible.
Google Meet: Flagged as "Potential Risk"
Google moved earlier. Starting in late March 2026, Google Meet began routing third-party notetaker bots to the waiting room with a "potential risks" label, defaulting to denying entry. Hosts can manually admit them, but the flag stays visible to every participant in the call — which creates its own friction in professional and client-facing contexts.
The change came as Google updated Meet's security posture in response to the broader legal and regulatory pressure building around AI recording tools. The "potential risk" label is intentionally visible: it's designed to prompt hosts to think about consent before allowing external recording software into the call.
Zoom: Admin Controls, Institutional Bans
Zoom's official policy is more permissive at the platform level — it gives administrators controls for third-party apps but doesn't quarantine bots by default. The real change has happened at the institutional level. Cornell University blocked Read.ai and Fireflies.ai from all Zoom meetings on their tenant. The University of Washington blocked Read AI from both Zoom and Teams. Several large enterprises have taken similar action through their own admin consoles.
Why Platforms Changed
The immediate trigger was a cluster of lawsuits against AI notetaker companies. The most prominent: a class action against Otter.ai, consolidated as In re Otter.AI Privacy Litigation in the Northern District of California, which alleges that OtterPilot joined meetings and recorded participants who never consented to be recorded by a third-party service. A motion to dismiss was heard on May 20, 2026; as of this writing, the court has not yet ruled.
A parallel suit filed in Illinois federal court (Cruz v. Fireflies.AI Corp.) alleges that Fireflies violated the Biometric Information Privacy Act by using its speaker recognition feature to create and retain biometric voiceprints without the required notice or written consent.
These cases put AI notetaker companies on every IT department's risk register. Once the liability calculus changed, platforms faced pressure to give administrators the tools to control what's happening inside their meetings. The Teams quarantine lobby and Google's "potential risk" label are both responses to that pressure.
The underlying concern isn't hypothetical. When a meeting bot joins a call, it records every participant — not just the person who authorized the tool. Participants who never signed up for Otter, Fireflies, or any other service are captured and transcribed. Their biometric voice data may be retained. In two-party consent states, recording without all-party consent is a separate legal issue entirely.
The Architecture Problem Nobody Talked About
To understand why bots are getting blocked — and why they're difficult to adapt — it helps to understand what a meeting bot actually is.
Most AI note-taking services work by sending a software agent into your meeting as a visible participant. This is why they appear in the lobby, show up in the participant list under a service account name ("Otter.ai," "Fireflies Notetaker," "Gong"), and need to be admitted by the host. The bot joins the meeting the same way a human would, then records the audio stream from inside.
This architecture creates three specific problems in the current environment:
It's visible to other participants. Every person on the call can see the bot's name. In a client meeting, an investor conversation, or a negotiation, "Fireflies Notetaker is in the meeting" is a disclosure whether you intended it to be or not.
It requires platform permission. Since the bot joins as a participant, it goes through the same admission flow that humans do — including the new quarantine lobbies on Teams and Google Meet.
It creates consent exposure. Since the bot is recording all participants, not just the person who invited it, the company running the service becomes liable for what those participants said.
Local overlay tools work completely differently. Instead of joining your meeting as a participant, they run on the same device you're using for the call — capturing your audio, your screen, and the meeting context from the outside, without ever touching the meeting platform's participant list. No bot in the lobby. No name in the participant list. No platform admission required.
Which Use Cases Are Most Affected
Not all AI meeting tool use is the same. The new bot restrictions hit some use cases harder than others.
Post-meeting records and shared transcripts depend heavily on bot-based tools, because the whole point is producing a shareable artifact that goes to the team. If you use Otter or Fireflies primarily to generate meeting notes that get distributed to people who weren't on the call, you need the platform to produce a transcript — and that means you need the bot admitted. The new admission requirements add friction but don't break this use case entirely; they just mean you can no longer count on the bot auto-joining.
Enterprise compliance recording (call centers, financial services, healthcare) has its own class of tools with tighter integration into platform APIs. These are affected differently from consumer note-takers and generally have compliance exceptions.
High-stakes private meetings — job interviews, salary negotiations, one-on-one sales calls, investor conversations — are the use cases most sensitive to a visible bot in the room. For these meetings, bot-based tools were already a poor fit. A candidate arriving for a job interview with an Otter bot in the lobby creates a specific kind of impression. So does a sales rep who starts a discovery call with a notetaker joining before the prospect has said anything.
For these meetings, local overlay approaches were always more appropriate. The restriction on bots doesn't change the use case — it just makes the alternative more obvious.
What to Actually Use
If your primary use of Otter, Fireflies, or a similar tool is team-internal recording and transcripts, your best path forward is adapting to the new admission flow. Make sure whoever hosts recurring meetings knows to admit the bot; some tools offer workarounds like calendar-based pre-authorization that reduce (but don't eliminate) the friction.
If you're using an AI meeting tool for live support during the meeting itself — to catch something you missed, remember context from earlier in the call, or help you respond under pressure — a bot-based note-taker was always solving the wrong problem. These tools summarize what happened; they don't help you with what's happening right now.
That's the gap Meeting Copilot fills. It runs as an invisible desktop overlay that listens through your mic and the system audio without joining the meeting as a bot, which means it's unaffected by Teams' quarantine rules, Google Meet's "potential risk" flag, and any enterprise IT policy that blocks third-party bots. It doesn't appear in the participant list, doesn't show up in meeting audit logs, and doesn't require host admission. The AI is running on your side of the call, not inside it.
This distinction matters most in the moments where the stakes of a conversation are highest. Interviews, negotiations, and sales calls are all meetings where what you say next matters more than what the transcript looks like afterward — and where a visible bot in the lobby changes the room before you've said a word.
The Broader Shift
What Microsoft, Google, and an increasing number of enterprise IT administrators are doing is forcing a distinction that the market blurred for two years: there's a difference between recording a meeting and having AI support during it. The bot-based architecture served both use cases, which is why it grew so fast. The platform crackdowns are splitting them apart.
For recording and post-meeting artifacts, the bot tools are adapting — admission flows, explicit consent features, platform API integrations. The friction has increased, but the use case persists.
For real-time assistance during meetings, the trajectory is away from bots entirely. The tools built on local overlay architectures — the ones that never touched the platform's participant list to begin with — are simply unaffected by every policy change announced so far. They weren't designed to be sneaky; they were designed to help the person using them, not to be another participant in the call.
The quarantine lobby is new. The distinction between these two approaches isn't.
Sources: Microsoft Teams bot detection rollout (Microsoft 365 roadmap, Windows News, VoIP Review); Google Meet "potential risk" flag (UC Today); Cornell AI bot block (IT@Cornell); Otter.ai class action and Fireflies BIPA suit (National Law Review).