Research

The EU AI Act when an AI is taking your notes

Dylan de Heer, Co-Founder & CPO

Dylan de Heer

The EU AI Act when an AI is taking your notes

Most of the EU AI Act started applying on 2 August 2026, and the chapter everyone is asking about is the one on transparency. If you run meetings in Europe and software writes the notes, the question landing in your inbox is some version of the same thing: do you now have to announce it, and to whom.

The honest answer is that the AI Act asks less of your notetaker than the current wave of vendor explainers implies, and the obligation that genuinely falls on you was mostly already there. What the Act does add is one flat prohibition that some meeting tools walk straight into, and a training duty that has been live since February 2025 and gets almost no attention.

This is general information about what the regulation says. It is not legal advice, and it does not replace asking someone who gives legal advice for a living. Weeve holds no compliance certifications, and no notetaker, including this one, can make you compliant with the AI Act.

The short answer

The AI Act's transparency article is aimed at systems that talk to people, systems that generate synthetic media, and systems that read emotions. A notetaker that sits quietly on a laptop and writes down what was said is a poor fit for all three, so the disclosure you owe the room comes from data protection law and from recording-consent law rather than from the AI Act. The AI Act's real bite for meetings is Article 5(1)(f), which has prohibited inferring emotions in the workplace since 2 February 2025, and Article 4, which has required AI literacy among your staff since the same date.

What actually changed on 2 August 2026

Article 113 of the Regulation sets the dates. It says the Act "shall apply from 2 August 2026", then lists four carve-outs. Point (a) pulls Chapters I and II forward to 2 February 2025. Point (b) pulls governance and general-purpose AI rules forward to 2 August 2025. Points (c) and (d) push most high-risk obligations out to 2027 and 2028.

Chapter IV, which is Article 50, the transparency article, appears in none of those carve-outs. It therefore lands on the general date. The European Commission states it directly on its own regulatory framework page: "The transparency rules of the AI Act will come into effect in August 2026."

So the duty is live. The useful question is what it actually says.

What Article 50 asks for, and what it does not


Article 50 is titled "Transparency obligations for providers and deployers of certain AI systems". The word carrying the weight is "certain". There are four duties in it, and they point at four different problems.

The first binds providers. Systems "intended to interact directly with natural persons" have to be built so that people are "informed that they are interacting with an AI system", unless that is obvious from the context.

The second also binds providers. Systems generating synthetic audio, image, video or text must mark their output "in a machine-readable format and detectable as artificially generated or manipulated".

The third binds deployers, which is you. Deployers of an emotion recognition system or a biometric categorisation system "shall inform the natural persons exposed thereto of the operation of the system".

The fourth binds deployers of deepfakes, who must "disclose that the content has been artificially generated or manipulated".

Now hold a meeting notetaker against those. It does not speak to anyone in the meeting, so the first is a stretch. Its summary is a compressed account of a real conversation rather than a fabricated audio or video of a person, so the second and the fourth do not describe it. The third fires only if the tool infers emotion, and most do not.

Recital 132 explains the thinking behind the article, and it is about "specific risks of impersonation or deception". Nobody is deceived by a transcript of what they said.

That gap matters, because the market is currently selling the opposite reading. If you buy a tool on the promise that it discharges an Article 50 duty for you, you have bought a solution to a duty that may not have applied, while the duty that does apply sits somewhere else entirely.

The part that is a flat prohibition, and it has been live since February 2025

Article 5 is the list of practices the AI Act bans outright. Point (f) of Article 5(1) prohibits putting on the market, putting into service, or using "AI systems to infer emotions of a natural person in the areas of workplace and education institutions, except where the use of the AI system is intended to be put in place or into the market for medical or safety reasons".

Two things about that. It is a prohibition, not a disclosure obligation, so there is no version of it you can consent your way out of. And under Article 113(a) it has applied since 2 February 2025, which is eighteen months before the transparency rules people are currently worrying about.

The definition matters for whether a meeting tool is caught. Article 3(39) defines an emotion recognition system as one "for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data". Recital 18 spells out what counts, and voice is explicitly in scope: it names "characteristics of a person's voice, such as a raised voice or whispering". The same recital carves out physical states, giving pain and fatigue as its examples.

So a meeting tool that scores mood, sentiment or engagement from how somebody sounded, used in a work meeting, is in prohibited territory rather than disclose-it territory. A tool that reads the words and reports what was decided is not.

Weeve's own feature list is recording, transcription, projects, speaker identification and marking a moment. There is no sentiment score, no engagement metric and no inference of emotion from voice anywhere in it. That is a statement about what the software does, not a compliance credential, and it is the sort of thing worth checking on any tool you are evaluating rather than taking from a marketing page.

The duty nobody is writing about

Article 4 requires that providers and deployers "take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf". Under Article 113(a) it has applied since 2 February 2025.

If you roll a notetaker out across a practice, a small firm or a clinic, you are a deployer. Article 3(4) defines that as anyone "using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity". Article 2(10) confirms the other side of it: the Regulation "does not apply to obligations of deployers who are natural persons using AI systems in the course of a purely personal non-professional activity".

Article 4 has no prescribed form. It does not demand a course or a certificate. It asks that the people operating the tool understand what it does. For a five-person firm that is a written page explaining where recordings live, who can reach them, what the summary is and is not reliable for, and what to say to a client. It is closer to an induction note than a compliance programme, and it is the item most likely to be missing when somebody asks.

The AI Act sits on top of the law you already had

Article 2(7) is short and load-bearing: "Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation."

Nothing in the AI Act relieves you of GDPR. The lawful basis for recording a client, the retention period, the subject access request when someone asks for their transcript, all of that continues exactly as before. We covered that ground in why Weeve is GDPR compliant by default.

Consent law for recording a conversation is a third body of law again, mostly national rather than European, and the rules genuinely differ by country and by whether every party has to agree. That is the guide to whether it is legal to record a meeting, and it remains the one that decides whether you may press record at all. The AI Act does not touch it.

Where Weeve makes your disclosure harder


This is the awkward part, and skipping it would be dishonest.

A cloud notetaker that joins the call as a bot appears in the participant list with a name on it. That is clumsy, and people complain about it, but it does disclose something. Anyone glancing at the participant list can see that a piece of software is in the room.

Weeve does not join the call. It captures audio on the Mac itself, so no participant appears, nothing announces itself, and the meeting looks exactly like a meeting with no software in it. Every bit of the disclosure therefore falls on the person running the meeting. If you say nothing, nothing gets said.

There is more. Weeve has no admin console, no team seats and no audit log, so an organisation that wants disclosure enforced centrally, logged and reportable will not get that here. The discipline below is something a person does, not something the software makes them do. Weeve is also Mac only, needs Apple Silicon, and needs macOS 14 or later, so anyone in your organisation on Windows is outside this entirely.

What to say, and where to record that you said it

None of this is complicated. It is just easy to forget.

  1. Put it in the calendar invite, in one line, before the meeting exists. "This session will be recorded and transcribed on my machine for my notes." People who object then object in advance, which is far better for everybody than an objection at minute three.

  2. Say it out loud before you press record, not after. Name what is being captured, where it goes, and how long you keep it.

  3. Say it again when somebody joins late. They missed it, and they are the person most likely to raise it afterwards.

  4. Type it into the chat as well on a video call. The spoken line is missed by anyone who dialled in with their attention elsewhere.

  5. Write down that you did it. A line at the top of the notes reading "recording disclosed at the start, no objections" takes three seconds and is the only evidence you will have in a year.

  6. Have an answer ready for no. Somebody will decline, and the answer has to be that you stop recording and take notes as normal, without any friction attached to their saying so.

Step 6 is the one that decides whether the rest is real. A disclosure that cannot be refused is an announcement.

Common questions

Do I have to tell people an AI is taking notes?

Under the AI Act, probably not on the basis of Article 50, because a notetaker that only listens and writes is unlikely to be a system "intended to interact directly with natural persons". Under data protection law and under national recording-consent rules, you very likely do have to tell them you are recording. The practical answer is the same either way: tell them.

Does the AI Act apply to me if I only record my own meetings?

Article 2(10) excludes natural persons using AI systems "in the course of a purely personal non-professional activity". Recording your book club is outside it. Recording client sessions in your own practice is professional activity, so you are a deployer and Articles 4 and 5 apply to you.

Is sentiment or engagement scoring in a meeting tool allowed?

If it infers emotions from biometric data, including voice characteristics, and it is used in a workplace or an education setting, Article 5(1)(f) prohibits it, and has done since 2 February 2025. The exception is narrow and covers medical or safety reasons. Sentiment drawn purely from the text of what was said is a different question and turns on whether biometric data is involved.

Does an on-device notetaker change what the AI Act asks of me?

Not for the transparency duties. Where the processing happens does not alter whether you have to tell people. It changes the data protection picture underneath, because content that never leaves your Mac has no transfer, no subprocessor and no vendor retention period attached to it. Those are GDPR questions rather than AI Act questions, and they are worth keeping separate in your head.

Does the AI Act replace consent law for recording?

No. It sits alongside it. Article 2(7) keeps privacy and confidentiality-of-communications law fully in force, and consent rules for recording conversations are national law that the AI Act does not amend.

The regulation everyone is reading about asks you to be honest with the people in the room. That was true before August 2026, and the sentence you say out loud is the same one.

If your reason for recording is that the conversation is confidential, Weeve keeps the audio, the transcript and the summary on your Mac and asks you to do the telling yourself.