“Does anyone mind if we record?”
During lockdown, this question became part of the opening ceremony for a meeting. We checked whether everyone could hear us, admired someone’s pet and/or bookshelf, established that somebody was still on mute, then asked permission to press the record button.
It was understandable. Having your face and voice preserved by your colleague’s computer still felt weird. Asking first was polite, and it gave people a chance to mention that they were about to discuss something they would rather not have available to watch on catch-up. But the habit has stayed with us even as recording and transcription have become pretty standard. And now an AI tool is increasingly likely to produce the notes, identify the actions and save someone the considerable effort of remembering what we all agreed before the next meeting.
But I think we sometimes still ask the question without knowing quite what we are asking. Is this permission we actually need? Are we explaining something we are entitled to do? Is it an organisational rule, a legal requirement or just a show of good manners? If someone says no, do we know what happens next? I suspect quite a few of us are hoping nobody says no so we don’t have to find out.
When the notebook becomes an app
If I arrive at a meeting with a notebook, I generally don’t ask anyone for consent before I start writing in it. I might explain what the notes are for and what I’ll do with them, particularly if I’m interviewing someone. There might be ground rules about attribution or sharing, but making a record is usually part of the activity. Somebody needs to remember the decisions. Introduce an AI transcription tool, though, and suddenly keeping notes can feel like it requires a fresh negotiation. Sometimes there is a new issue: a handwritten summary and a recording of every word are different things. So are notes in an approved system and a transcript sent to a service someone found on the internet that morning. But “AI is involved” does not, by itself, mean fresh consent is required.
For UK readers, the Information Commissioner’s Office has guidance on this specific point. If AI supports existing activities without changing the purposes or processing activities, an organisation may be able to use its existing lawful bases. But that assumes the AI tool provider isn’t also using the information for its own purposes, such as model training. We need to understand how their information is used, and outputs need checking. That needs a bit of effort, but it’s rather more useful than assuming a general murmur of agreement has sorted everything out.
A record and a recording are different things
Imagine a family telling their social worker that they don’t want any notes taken. They might have had bad experiences with records, worry about who will see them or feel misunderstood – and those concerns deserve a proper conversation. But a social worker cannot just agree that there will be no record. Social Work England’s standards, for example, require clear, accurate and up-to-date records, including how decisions are reached. Of course they do.
There is also a difference between capturing the words and capturing what happened. We humans know that “I’m fine” can be a cheerful reassurance or a fairly clear indication that someone is absolutely not fine. Tone is everything, but a transcript may give you the same sentence for both. It won’t necessarily capture that moment when everyone looked cross or sceptical. Maybe they all crossed their arms and rolled their eyes at the same time. Maybe the AI didn’t notice.
A good meeting note will include that nuance, distinguishing what was said from what you can legitimately interpret. It needs checking and should be open to challenge, but more words don’t automatically make a more meaningful record.
Nor does the duty to document a conversation justify using any recording tool you fancy. The ICO’s recording advice asks whether less intrusive methods could achieve the purpose, and requires a justified lawful basis and information about use and retention. Professionals need to understand their recording responsibilities and how their tools handle the information. “Everyone else uses this app — the first 45 minutes are free” is unlikely to be the reassurance everyone is hoping for.
We have been confused about this before
If you’ve worked in safeguarding, you’ll recognise the parallel: people can become so worried about data protection that they hesitate to share information about a risk. Information sitting safely in separate organisations can leave those protecting a child without the picture they need. That’s why the ICO’s safeguarding guidance is clear that consent isn’t required where an appropriate lawful basis supports sharing. Requirements still apply, including for handling sensitive information, but withholding consent does not prevent legitimate data sharing.
Sometimes sharing is permitted; sometimes a separate legal duty requires it. Professionals need to know which applies. We sometimes reach for “data protection” when we mean “I’m not sure what I’m allowed to do”. That uncertainty needs guidance and good organisational support.
Good manners still matter
People might talk differently when every word is recorded, or have good reasons to ask for another approach. Listening matters when you need to build trust. And where an approved tool is appropriate, and secure, putting down the pen and making eye contact while an AI creates a record that you check afterwards might improve the conversation. But where consent is the basis, the choice must be genuine. Asking someone to agree to something they cannot meaningfully decline doesn’t create a useful choice – it’s just a notification dressed up to look like a request for permission.
You need to know when agreement is really required. If the answer is “our policy says so”, we should also be able to explain what the policy protects, who made that decision and whether it still makes sense.
The questions behind the button
We have had quite a lot of practice clicking permission buttons, but I’m not convinced it made us particularly well informed. Cookie banners can turn a simple choice into a small administrative obstacle course. By the time I have worked out whether rejecting something requires opening seven separate menus, I have usually forgotten why I visited the website. It is hardly surprising that people have become suspicious of being tricked into giving information away. But I suspect some of us will painstakingly reject website cookies and then cheerfully tell a friendly chatbot about our work, our children and our difficult colleague, without checking the settings.
A conspicuous permission screen attracts our attention; a helpful conversation can make us forget to ask questions at all. For organisations using AI, those questions need answering before staff start improvising. Where does the information go? Can the supplier reuse it? Who can access it? When is it deleted? Who checks the notes before they become the official record? And how can someone see their information or challenge an error?
Access doesn’t necessarily mean receiving an unedited transcript containing everyone else’s information, but the record shouldn’t become the private possession of whoever pressed the button. The ICO’s subject access guidance explains those rights and limits. “Does anyone mind?” is an easy question to ask, but we should all be able to explain what happens to someone’s information.
If your organisation’s policy seems excessive
Here’s a thing, though. You might now be worried that we’ve just suggested your compliance team doubles down on checks and balances and you won’t know how to navigate it all. That’s okay; I’ve never met a compliance team that wasn’t open to a conversation as long as you ask questions and don’t just bang your fists on the desk.
Healthy challenge is your friend. If you think you’ve got too much or too little grip on permissions, start by asking how the policy was reached. We like to be useful, so hopefully these questions can help:
- Which requirement is this implementing: law, a professional duty, an organisational decision or customary practice?
- What specific risk does the restriction address?
- Does the policy distinguish between recording, transcription and a checked written summary?
- If consent is required, what happens when someone refuses or withdraws it?
- Could an approved tool with clear access, deletion and checking arrangements address the concern?
- Who owns the policy, and when will it be reviewed?
First, let’s admit we’re not really sure what we’re asking permission for, before we regret asking the question at all. If it helps, I’ve learnt this lesson asking the kids what they want for tea. If I ask an open question, I can hardly be surprised when the answer is ice cream. If the options are sausages or nuggets, I should probably say that.
The stakes are obviously rather higher with someone’s personal information, but the principle holds: be clear about what’s decided, what’s genuinely open to discussion and why. And before we ask “Does anyone mind?”, we should know what we’ll do if someone does.