Over the past year or two, a small note-taking bot has been showing up in more and more Teams meetings. It carries the name of a well-known app, it records, it transcribes, and often nobody around the table really knows who let it in or where the data ends up. These automatic assistants (Otter.ai, Fireflies, Gong, and a whole crowd of others) have become regulars on business calls, sometimes without half the participants even noticing.
Microsoft just tightened things up. The company rolled out a new safeguard in Teams that detects these external bots, holds them in the waiting room, and requires the organizer to confirm their entry before they can join the meeting. The full rollout is set for the end of July 2026, with an option to block these bots outright arriving in August. For a small or mid-sized business in Trois-Rivières or the Mauricie region holding confidential meetings, this is good news worth paying attention to.
Quick answer: Microsoft Teams now detects external note-taking bots, holds them in the waiting room, and requires the organizer to approve them before they can join. It’s on by default, it’s managed from the admin center, and starting in August 2026 admins will even be able to block them automatically. The result: fewer unauthorized recordings in your meetings and better control over your data.
1. What Microsoft just changed in Teams
The new feature has a clear name in the Teams admin center: a policy called “Manage external bots and their access to meetings.” Once enabled, Teams analyzes participants using behavior and infrastructure signals to spot bots. As soon as it detects one coming from outside your organization, it holds it in the waiting room, flags it visually, and asks the organizer to confirm its entry.
Here’s the key detail: even in a meeting where you’ve allowed participants to bypass the waiting room, a bot flagged by this policy stays blocked until the organizer approves it. In other words, the rule that applies to humans and the one that applies to bots are no longer the same.
- Automatic detection of external bots when they attempt to join a meeting.
- Waiting room placement with a visual marker that sets them apart from real participants.
- Mandatory manual confirmation from the organizer before admission.
- Adjustable scope: the policy can apply to the whole organization, specific groups, or individual users.

2. Why these note-taking bots are a real problem
An assistant that transcribes a meeting sounds handy. The catch is what happens afterward. These tools capture everything that’s said, send it to servers often located abroad, and sometimes feed the content of your conversations into AI models. In a meeting where you’re discussing a contract, an employee file, financial figures, or a client, that turns into a potential data leak.
In Quebec, this isn’t just a matter of best practice. Law 25 governs the collection and circulation of personal information. If a third-party bot records a meeting where clients or employees are named, without clear consent and without anyone knowing where the data goes, your business is exposed. The problem isn’t the bot itself, it’s that until now it could walk in without anyone really giving the green light.
- Recording and transcribing confidential conversations without explicit consent.
- Data hosted outside Quebec, sometimes outside Canada.
- Meeting content potentially reused to train AI models.
- No clear record of who invited the bot or what it kept.
3. How the safeguard works in practice
Everything is managed from the Teams admin center. An administrator assigns the policy to the whole organization, a specific department, or a handful of people. By default, Microsoft’s recommended behavior is straightforward: detect bots, send them to the waiting room, and require the organizer’s confirmation.
Microsoft also recommends limiting who can admit someone from the waiting room to organizers and co-organizers, so a regular participant doesn’t accidentally let a bot in. A “Do not detect bots” option exists for organizations that prefer to let assistants join freely, but that’s not the setting to choose if confidentiality matters to you.
The roadmap goes further. Starting in August 2026, administrators will be able to choose between three behaviors: allow everything, require approval when a bot is detected (the default setting), or automatically block detected bots. Microsoft also plans allow lists for approved tools, organization-wide blocking, and reporting and audit logs on bot activity. If you want these settings configured right the first time, our managed IT services cover exactly this kind of hardening.

4. What this means for your business in Quebec
In practical terms, if your teams use Teams for internal or client meetings, you’ll want this setting turned on and properly scoped. It stops a supplier, a partner, or even a well-meaning employee from letting a recording bot into a sensitive call. It also gives you a clear answer the day a client asks who’s listening in and who’s keeping the conversation.
Here’s what we recommend doing right now.
- Check that the bot detection policy is active in your Teams admin center.
- Restrict the right to admit participants to organizers and co-organizers.
- Decide which note-taking tools are acceptable, and which aren’t.
- Plan for the August 2026 rollout to choose between mandatory approval and automatic blocking.
- Document all of it, to stay aligned with Law 25.
For a small business in Trois-Rivières, the Mauricie, or the Quebec City area without a full-time IT team, this kind of configuration can be sorted out quickly with the right support. It’s a good moment to tidy up your Teams settings while Microsoft rolls out the feature.

Frequently asked questions
Does this also block Microsoft 365 Copilot meeting notes?
No. Detection targets bots external to your organization, such as third-party note-taking assistants. Microsoft 365’s own tools, including Copilot, aren’t treated as external bots. That said, Microsoft plans to later extend a unified way of managing AI participants.
Do I need to do anything, or is it automatic?
The safeguard is on by default, but it’s worth checking. You’ll want to confirm it’s active, decide who it applies to, and restrict who can admit a participant from the waiting room. These choices are made in the Teams admin center, not in the user-facing app.
Are note-taking bots illegal in Quebec?
No, they aren’t illegal on their own. The risk comes from recording personal information without clear consent and without knowing where the data goes. Law 25 requires you to govern this kind of collection, and that’s exactly what this new control helps you do.
Take back control of your meetings
This Teams update is a good example of a simple setting that protects your data with little effort once it’s properly configured. If you’re not sure where your Microsoft 365 environment stands, our team can review your policies, turn on the right safeguard, and document it for compliance. Check out our managed IT services or reach out through our contact page to talk it through.
Sources: Microsoft Learn · Help Net Security · OKTO Solutions