Why Read: AI notetakers are everywhere. In this week's issue, we lay out the space through a cybersecurity lens, dig in on a few of the top players, and suggest a framework for personal and company policies around them.
Earlier this year, Meta - a company not particularly known for its ethics - made a few blunders that were so bad, even it had to backstep.
In April, it had launched the rather Brave New World-y Model Capability Initiative, a tool that tracked employee keystrokes and mouse clicks as well as the content displayed on their computer screens in order to collect data for training AI models. More than 1,600 employees signed a petition against it. But it wasn't until a massive internal security breach that the company announced it was pausing the initiative indefinitely.
According to documents viewed by WIRED, as it reported in early June:
The security notice sent out Monday indicated that "employee data across 45,000 hive tables" had been exposed. Those tables included employee activity such as "full prompts and transcriptions, private conversations, people and performance data."
Ironically, at exactly the same time, VCs and founders were diving headfirst into a new category of devices and software that run exactly the same risks, exposing the details of internal business processes and intellectual property and cataloguing sensitive business decisions - as well as those of their partners and clients - to malign actors.
The only difference is that, in contrast to Meta's employees, they're actually paying for it. Often monthly.
I'm talking about the sudden explosion of AI notetaking devices and software, which have recently rounded a corner of privacy impropriety, making them even subtler - sometimes undetectable - to those being recorded.
They've also rounded a popularity corner: Silicon Valley can't stop talking about Granola and its AI notetaking app and Plaud, the company behind an AI wearable notetaking pin and a magnetic credit card that attaches to the back of your phone. (Zoom now asks me if I'd like it to take notes every time I open a Teams meeting. Yes, that's right. Not a Zoom meeting. A Teams meeting.)
And while Firefly and Otter bots still pepper the attendee lists at virtual meetings, they're beginning to look awkward and bumbling by comparison.
There are two key product areas here: software that runs on your laptop and devices, recording in the background of meetings, and a set of spylike physical recording devices that capture all the audio around them.
Of course, these devices are extremely convenient and useful. They record your calls without your having to lift a finger, take notes on your behalf, automatically surface to-dos, and draft followup emails so you don't lose track of important tasks in a growing nightmare of notifications.
They also introduce massive cybersecurity risk into your business, often without your awareness or consent.
That's partially because they're the perfect Trojan Horse of a listening device for nation-state actors. (And there are companies in this group likely to be used in this way. More on that later.)
It's also because new approaches that skip the meeting bot make surveillance even less conspicuous, allowing attendees to record one another without the knowledge or consent of others. (This is illegal in some states, but legal in the majority.
The core business model for many of these, even when deployed by trusted businesses, is not necessarily the sale of the software or devices themselves. It is the data derived from following the rhythms and patterns of your day - the way you talk, negotiate, and otherwise handle your business interactions - which is being used to train a model with the same goal that Meta had for its Model Capability Initiative.
In other words, they're training agents in human-to-human context using your and your company's data.
The risk is akin to employees entering sensitive internal information into public instances of Claude and ChatGPT - which then shows up in searches by people outside the company.
Plaud claims over 2 million users, primarily in the medical and business industries, across 170 countries. TechCrunch reports that AI assistant Pocket has 130,000.
The takeaway here is that if you don't have one already, the time has come to create and publicize an AI notetaker policy at your company. Your team or employees may be using their personal devices to augment their workflow, as people do with public Claude and Chat instances, including to get around tricky and constraining internal LLM policies.
Why Chinese Ownership Is a Threat
Plaud makes tiny AI recording devices with a technology originally designed to catch cheating spouses. Its devices include Plaud Note, which attaches magnetically to your phone and records your conversations, both in person and on calls. It works like magic, transcribes entire meetings in minutes, and has every security accreditation possible.
There's just one problem. It was founded by a Chinese national named Nathan Xu, who got his bachelor's degree from Wuhan University. Nathan was living in Beijing, working as a director at FZ Capital until July of 2021, when he moved to San Francisco to launch Plaud.
So, what's wrong with a nice success story?
A few years ago, we hosted a private briefing for our SNS members in which a national security representative laid out the Chinese Communist Party's strategy for undermining US businesses. The individual involved, speaking under Chatham House Rule, explained that state-sponsored surveillance and IP theft often targeted US business practices and processes - a relatively unsexy field, all things considered, but one that is instrumental to China's overall practice of rebuilding stolen IP as new entities that undercut the pricing of their originating Western counterparts.
Combine this idea with China's National Security Law, which requires PRC citizens to assist in intelligence-gathering activities. Violation of this law is punishable by life in prison. Many Chinese nationals and dissidents living outside the country have reported threats to, or detention of, their friends and family members just for sharing true details of their former lives in China. China also maintains shadow police departments throughout the United States to help intimidate and enforce policies like these among foreign nationals living abroad.
As a result of all these factors, it is not possible for a Chinese national to found a company that is not a security risk to US businesses. Any documentation of your internal business structure, strategy, processes, or intellectual property should be considered vulnerable if conducted using an AI tool owned and run by a Chinese national. You are, in effect, handing over everything to the CCP.
Even if you don't care about putting your own IP at risk, your business partners may, which would limit your future potential to sell into any critical infrastructure areas. This is especially true if you're building a technology that may be used by the US government or in any defense capabilities.
We also know that the CCP is aggressively pursuing information-gathering about US citizens and their relationships to one another. I've previously reported on its internal database of digital dossiers on US citizens, specially focused on journalists and activists. Just last week, the New York Timesreleased a report on an unsecured internal police dashboard found to be tracking foreigners' locations and travel associates using private data.

Source: The New York Times
We also know that the CCP has a history of using listening devices for surveillance in its products. Chinese-made cars have been widely found to include listening devices and have therefore been banned from use in the US. Huawei devices have also been banned in much of the West, for fear of back-door access to critical systems.
But the CCP is nothing if not persistent, smart, and extremely strategic. So let's play one of my favorite games: If I Were Xi Jinping.
If I Were Xi
If I were Xi Jinping, how would I optimize my surveillance of the US innovation ecosystem?
For one, I would be extremely supportive of any Chinese national who wanted to start a business recording the internal, private conversations of US founders and investors. Money? Clout? What do you need? We'll make sure you get it.
Of course, we wouldn't want the US to know that we were supporting the company, so we'd need to do things a little differently than the average Chinese company.
In this completely imaginary scenario, I would probably encourage the company to incorporate in the US - Delaware, of course! - and move its office directly into San Francisco, where eavesdropping on founders and investors in coffeeshops is pretty much a local pastime.
I'd minimize or deny any ties with Chinese investors, which have come under greater scrutiny in the Valley. The company would, of course, host all cloud compute in the US to avoid drawing attention, but the devices would be manufactured in Shenzhen. (It's nearly impossible for US companies not to do this anyway.)
I would also encourage this company to start by infiltrating investor communities, because they have the broadest overall exposure to particularly innovative new IP. I might even encourage an investor from a major Chinese firm to found this company - you know, just to make sure they really click with others when they move to Silicon Valley.
The founding team would be composed of almost entirely Chinese nationals. We wouldn't want to worry about any pesky Americans whistleblowing on privacy or surveillance breaches. (Learned our lesson on that one with TikTok.) Not to mention any back doors I might have insisted on building in.
To further maximize the appearance of this being a US firm, it wouldn't have any offices in China, despite its founder having lived until recently in Beijing.
But we would want an Asian presence, so our next step after raising money from some key US investors would be to launch an Asian office somewhere "independent." Singapore would be a good option.
Then, if I were Xi, I would do anything in my power - including using TikTok, misinformation, and AI influencers - to pump the media story around this company and boost sales among US companies.
I, Berit, am of course not intimating that this is what actually happened. But the above strategy list does sound an awful lot like Plaud.
It's perfectly possible that Nathan Xu (formerly Xu Gao) is a kind-hearted innovator, who pivoted from building a failed educational platform and serving as an investor to suddenly launching a billion-dollar hardware startup with three flawless product lines in a country he's never lived in before, all on his own hard work and merit.
But if Xi Jinping had wet dreams, Nathan and Plaud would be the stars.
Plaud was bootstrapped by Nathan and his co-founder, Charles Liu, a Shenzhen factory owner, before the pair turned to Kickstarter to raise an additional million. So no early investors with outsized influence. Its offices are in SF, Amsterdam, and Singapore. Data is hosted wherever the customer is.
Neither Plaud Note nor Plaud NotePin notifies other parties audibly when it's recording. There is only a small flashing light that may or may not be noticeable, depending on where the Plaud device is being stored.
Right on cue, rumors of Tencent having invested in Plaud have been denied by both parties. Perhaps they're just rumors. But it certainly wouldn't be in the CCP's interest to spread them.
As stated to Forbes by Dan Weirich, a Bay Area-based partner with Carbide Ventures who invested around $5 million in Plaud earlier this year: "I'd like to be on the front page of the newspaper for having a big IPO, not for recording all of America's conversations with Chinese technology."
Oopsie, Dan.
Assuming that Nathan Xu and Charles Liu didn't build Plaud for the purposes of spying on Silicon Valley's best new ideas, it would be very out of character for the Chinese Communist Party not to insist on it being used that way.
Ethics & the Impossibility of Opting Out
The safest option you can take from a cybersecurity perspective is not to use an AI notetaker at all. Even notetakers with great privacy policies and strong corporate ethics behind their parent companies can be hacked, potentially exposing transcripts or recordings of your personal and professional interactions and IP.
Granola, for example, makes meeting notes available to anyone with the link, unless you change the default setting. And it requires users with individual accounts to opt out of training its models.
But even abstaining entirely won't protect you from unwanted recording. It's very likely, especially in the types of tech-forward rooms where our members live (both real and virtual), that you may be recorded without your knowledge or awareness. Many people who own these devices for convenience's sake are not aware of recording laws or security vulnerabilities and may have a recording device on their phone or person that you don't spot or can't see.
This happened to me just last week. I was talking with someone who stated that they had a Plaud, showed it to me, and then implied that because I was now aware of it, they could legally record our conversation. Unfortunately, even in Washington - a two-party-consent state - there's enough legal gray area around recording that they may be right.
These devices have become so pervasive that if you're discussing a sensitive subject or proprietary information with others, it would be wise to clearly state your own recording boundaries at the beginning of your calls.
Hi, Bob - so great to see you, and thank you so much for taking the time to chat with me. I want to make sure we can speak as openly as possible today, so I have a quick request: if you normally use an AI notetaking device or any other recording method, would you please take a minute to turn it off?
Then wait in silence for them to do so.
The Least Bad Options
All that being said, I am a realist who appreciates new technology. I want these devices myself, even as I deeply distrust some of them and the generally omnipresent surveillance culture they facilitate. My days are full of meetings that I desperately need help following up with, and I legitimately believe that this specific application is probably one of AI's best uses.
So, if you know that you will be using AI notetaking no matter what you've learned in these pages, please use one of the least bad options. (I wouldn't trust Plaud, Zoom, or Otter.ai farther than I can throw them.)
If you have to have a device, YC-born Pocket is generally well-reviewed and praised for its unlimited transcription plan, although lag times can be quite high. Limitless and Bee have been acquired by Meta and Amazon, which counts them out in my book, from a privacy perspective.
My top pick among all the options, for a combination of clean design, high functionality, and ease of use, would be Granola.
Based in London and founded by designer Sam Stephenson and entrepreneur Christopher Pedregal, Granola transcribes your meetings in real time and uses your own notes and meeting templates to optimize those notes. It does not keep audio recordings. It works across Zoom, Teams, Webex, Google Meet, and Slack and integrates with CRMs, Slack, and other organizational tools.
Here's a followup email I asked it to generate from the sample meeting it uses to train new users:

It also seems to have a legitimately nuanced approach to privacy and its importance. When it's taking notes, Granola displays a watermark in the corner of your screen to notify others that an AI notetaker is present - a feature the company did not have to build in (although its marketing team probably doesn't hate having its logo everywhere).
It does not allow enterprise accounts to read individuals' private notes, unless they are deliberately shared - a fact that sets them well apart from Meta's ham-handed, top-down approach.
"Companies hate us for this - they're like, hey, there's all this content; why am I paying you money?" Pedregal explained in a Platformer interview. He continued:
And we're like, no. We're capturing context, but context can be very private, very sensitive, very nuanced. So even though your company's paying for it, those notes are private. Legally, if the company gets sued, we have to hand those notes over - it's the same thing with Gmail. But it's not like your manager, or your manager's manager, can look at those notes or run an agent on them. There are some real trade-offs for us as a company in doing that, and it's something we believe in.
All enterprise accounts in Granola have model training turned off by default. And all individual users can opt out of having their anonymized data used to train Granola's model. (Make sure you do that. Anonymous data is a misnomer.)
Granola also has apps for iOS and Apple Watch, so you can use its services on the fly.
It is a venture-backed company, so it could be sold or acquired or enshittified later, as Google has done to itself with the G-suite, or as happened with 23andMe's genetic database.
For the moment, though, with Pedregal and Stephenson at the helm, you just might find it boosts your productivity without providing a direct funnel from your company's most sensitive IP directly into the hungry, waiting mouths of the CCP.
Even so, I'll be keeping my IP development calls off the record.
Your comments are always welcome.
Sincerely,
Berit Anderson
ETHERMAIL
Dear Mark,
Gee, that was fun as a .... fun as a metaphor.
Then there is the opportunity cost. $1 trillion would pay for about 50 new Intel factories, or all the manufacturing rebuild and upgrade that Trump talks about but that the U.S. is currently not doing to any great degree outside data centers and semiconductors. And, of course, most of the high-bandwidth memory and AI processors are made in South Korea and Taiwan.
In Japan, Korea and China, most AI is linked to manufacturing, logistics or something else practical.
Scott Foster
Journalist & Research Analyst, Asia Times
Quarterly Columnist, SNS Asia Letter
Author, Stealth Japan
Tokyo, Japan
Mark,

Luke Winkenhofer
2026 FiReFellow
Biomedical Engineering Student
Cal Poly-San Luis Obispo
Carlsbad, CA
RE: 2 Things
Hi Sally,
1) See editorial below July 23:
2) Were you able to fix the copyright assignment for the Harris / Mackey Ireland book? [...]
THANK YOU....
William C. Harris
MRIA (Member Royal Irish Academy)
Co-Founder & Board Chair,
Innovation Advisory Partners |
Founding President & CEO (fmr.)
Science Foundation Arizona |
Co-Author (with Pete Mackey),
How to Change the Future: Lessons from Ireland
Phoenix, AZ
Bill,
On the first - thank you to (you and) H. Holden Thorp for this clarion call, for not mincing words about the state of science today in the US and what it signifies for students, academe in general, and the world at large. Would that many others were standing up as clearly.
And thank you for your continuing commitment to effect change, as you and Science Foundation Arizona did to irrefutable impact in Ireland. It's an honor that FiReBooks was able to bring to the public eye your book, with co-author Pete Mackey, about the process and lessons therein that can be applied to other countries and states. (The change of copyright assignment is in the works.)
Sally Anderson

