SNS: A SECURITY SKEPTIC'S GUIDE TO GRANOLA, PLAUD & AI NOTETAKING
 

 

"Next Year's News This Week"

A Security Skeptic's Guide to Granola, Plaud & AI Notetaking

By Berit Anderson

_________

Why Read: AI notetakers are everywhere. In this week's issue, we lay out the space through a cybersecurity lens, dig in on a few of the top players, and suggest a framework for personal and company policies around them.

_________

 

Earlier this year, Meta - a company not particularly known for its ethics - made a few blunders that were so bad, even it had to backstep. 

In April, it had launched the rather Brave New World-y Model Capability Initiative, a tool that tracked employee keystrokes and mouse clicks as well as the content displayed on their computer screens in order to collect data for training AI models. More than 1,600 employees signed a petition against it. But it wasn't until a massive internal security breach that the company announced it was pausing the initiative indefinitely.  

According to documents viewed by WIRED, as it reported in early June:

The security notice sent out Monday indicated that "employee data across 45,000 hive tables" had been exposed. Those tables included employee activity such as "full prompts and transcriptions, private conversations, people and performance data."

Ironically, at exactly the same time, VCs and founders were diving headfirst into a new category of devices and software that run exactly the same risks, exposing the details of internal business processes and intellectual property and cataloguing sensitive business decisions - as well as those of their partners and clients - to malign actors.  

The only difference is that, in contrast to Meta's employees, they're actually paying for it. Often monthly. 

I'm talking about the sudden explosion of AI notetaking devices and software, which have recently rounded a corner of privacy impropriety, making them even subtler - sometimes undetectable - to those being recorded. 

They've also rounded a popularity corner: Silicon Valley can't stop talking about Granola and its AI notetaking app and Plaud, the company behind an AI wearable notetaking pin and a magnetic credit card that attaches to the back of your phone. (Zoom now asks me if I'd like it to take notes every time I open a Teams meeting. Yes, that's right. Not a Zoom meeting. A Teams meeting.) 

And while Firefly and Otter bots still pepper the attendee lists at virtual meetings, they're beginning to look awkward and bumbling by comparison. 

There are two key product areas here: software that runs on your laptop and devices, recording in the background of meetings, and a set of spylike physical recording devices that capture all the audio around them. 

Of course, these devices are extremely convenient and useful. They record your calls without your having to lift a finger, take notes on your behalf, automatically surface to-dos, and draft followup emails so you don't lose track of important tasks in a growing nightmare of notifications.

They also introduce massive cybersecurity risk into your business, often without your awareness or consent. 

That's partially because they're the perfect Trojan Horse of a listening device for nation-state actors. (And there are companies in this group likely to be used in this way. More on that later.)