Streamline ISO Consultants

  • Home
  • Security & AI
    • ISO 27001 Information Security
    • ISO 42001 AI Management
    • Cyber & Information Security Advisory
    • Essential Eight
    • SOC 2
    • TISAX
  • ISO Consulting Services
    • ISO Consultants Australia
    • ISO 9001 for US Companies
    • ISO Mentoring
    • Independent ISO Internal Audit Services Australia (Clause 9.2)
    • ISO Gap Analysis Audits: Know Where You Stand Before Stage 1
    • ISO Certification Auditors
    • ISO System Development
    • ISO Management System Maintenance & Ongoing Support
  • ISO Standards
    • ISO 9001 Quality Management
    • ISO 45001 Occupational Health and Safety
    • ISO 14001 Environmental Management
    • ISO 17025 Testing and Calibration
    • HACCP Food Safety
    • ISO 19443 Nuclear Supply Chain
  • Resources
    • All Articles
    • ISO Clause Guides
    • Quality Quotes
  • About
    • ISO FAQs
    • Quality Policy
    • Client Testimonials
    • ISO 9001 Certificate
  • Contact
    • Business Info
    • Privacy Policy

By Streamline ISO Consultants

The Uninvited Guest: Why You Should Never Let Bots Auto-Join Your Meetings

Tilt-shift miniature of an operations desk with alerts, illustrating monitoring who and what joins your meetings
A misaddressed invite goes to the wrong external address, and an uninvited AI notetaker joins the meeting. No hacker required.

Here is a scenario that is far more common than most organisations realise, and it requires no hacker, no malware and no sophistication whatsoever.

Someone sets up a meeting and starts typing a colleague’s name into the invite. Outlook autocompletes it, helpfully, instantly, from its cached list of addresses it has seen before. The name looks right. The invite goes out.

Except the address Outlook offered was scott@unwanted.com, not scott@mycompany.com, an external address from some old thread, sitting in the cache, one row above or below the one that was wanted. Same first name. Same shape. Wrong company.

The external recipient does not attend. But their AI notetaker does, because it is configured to join every meeting on their calendar automatically. It arrives in the participant list with a perfectly ordinary-looking name. Nobody challenges it. The meeting runs for an hour, and every word is transcribed into a third party’s system.

The organisation finds out when the bot politely emails a summary of the meeting to all attendees.

Nobody was hacked. No control was bypassed. Every system worked exactly as designed. That is precisely what makes this failure mode so dangerous, and why it will not show up in a penetration test.

The root cause is autocomplete, and it is not user error

It is tempting to file this under “someone was careless”. Resist that, because it is both unfair and useless, and if that is your conclusion, your corrective action will be “remind staff to check addresses”, which fixes nothing.

Outlook maintains a cached list of every address you have ever sent to or received from: the auto-complete list. It is not your address book. It is not curated. Nobody approved what went into it. A supplier you emailed once in 2021, a recruiter, a person at a conference, someone on a long-forgotten CC chain: they are all in there, and they all surface as suggestions the moment you start typing.

Now consider how a meeting invite is actually created. You type three letters of a name. A dropdown appears. You pick, or you press Enter and it picks for you. You are looking at the display name, not the address behind it. And two entries reading “Scott” sit one row apart. One is internal. One is scott@unwanted.com, an external address cached years ago. The wrong one is selected in about a fifth of a second, by muscle memory, while the person is already thinking about the agenda.

The invite then looks completely normal. Nobody re-reads a sent invitation. And unlike an email (where a wrong recipient might reply “I think you meant someone else”), a calendar invite to the wrong person often produces no human response at all. It just quietly lands in a stranger’s calendar. Their bot does the rest.

This is a system design problem wearing a human-error costume. The interface offers an unvetted external address with the same visual weight as a colleague, at the exact moment the user’s attention is elsewhere. Told that way, the control set writes itself:

  • Turn on external-recipient warnings. Microsoft 365 can flag external recipients before an item is sent, and can tag external senders on arrival. If your people cannot see at a glance that an address is outside the organisation, they cannot catch it.
  • Clear the auto-complete cache periodically, or teach people to delete individual stale entries from the dropdown with the small ‘x’. Every dead external address you remove is a landmine taken out of the field.
  • Use distribution lists and calendar groups for recurring or sensitive meetings, so the invitee list is a controlled object rather than something retyped from memory each time.
  • Check the address, not the name. The display name is what deceives you; the domain is what tells you the truth. For any meeting that matters, expand the invitee list and read the domains before you send.
  • Treat invite accuracy as a control, with an owner, not as a personality trait of whoever happens to be organising.

None of this is exotic. It is the same principle as any other access control: the system should make the safe thing easy and the dangerous thing visible. Right now, for meeting invitations, most organisations have it precisely the wrong way round.

Why nobody notices the bot

This is the part that surprises people. Surely someone would spot an unexpected attendee?

In practice, almost never. AI notetakers appear in the participant list under names that read like people or like a product nobody questions. Attendees arrive late and leave early, so the list is never stable. In a meeting of eight or ten, nobody audits the roster. If the meeting has external participants by design (a client, a supplier, a contractor), then one more external name is entirely unremarkable. And critically, most people have simply never been told that this is a thing that can happen.

Microsoft’s own guidance is blunt about the risk. External meeting assistant tools, it says, may “record or transcribe meetings without participant awareness”, “store meeting data in third-party systems outside of the organization’s compliance boundaries”, and “introduce compliance, privacy, and data leakage risks”.

Why this is worse than an ordinary mis-sent email

A mis-sent email discloses one document. A mis-sent meeting invitation can disclose an hour of unguarded conversation. And meetings are where people say the things they would never put in writing. Commercial positions. What a client is really like. Names, health information, salaries, security weaknesses, the state of a deal. The unguarded aside is the whole point of a meeting, and it is now a transcript.

Worse, that transcript now lives in someone else’s AI platform, in their tenancy, subject to their retention settings and their terms, possibly offshore, possibly used to improve a model. You cannot recall it. You may not even know precisely what was said, because you were not taking minutes. And you have no visibility of who in that third-party organisation can now read it.

Which raises the question most organisations have never asked themselves: if personal information was discussed in that meeting, is this a notifiable data breach? Under the NDB scheme you must notify if a breach is likely to result in serious harm. Personal information has been disclosed to an unauthorised third party and stored in a system you do not control. That is a serious question, and “we hadn’t thought about it” is not an answer you want to be forming at 6pm on a Friday.

It is also a textbook example of the point I made about the OAIC’s 2025 breach statistics: of 1,205 notifiable breaches last year, 716 were malicious or criminal, and 489 were not attacks at all. Human error and process failure. This is exactly that category, and no security product on the market prevents it.

The Microsoft Teams setting that stops it

The good news is that Microsoft has built a control for precisely this, and most organisations do not know it exists. In the Teams Admin Center, under Meeting policies → Meeting Join and Lobby, there is a setting called “Manage external bots and their access to meetings”. It can be applied at the tenant level through the org-wide policy, or targeted at a specific group or user. Microsoft’s documentation on it is worth reading in full: it is short, and unusually candid.

It has two options:

  • Do not detect bots: bots are not identified at all, and appear like any other external participant. This is the state most people assume they are not in.
  • When detected, require approval before joining: this is the default. Detected bots are held in the lobby regardless of your lobby configuration, and an organiser must explicitly admit them. Teams warns the organiser about the risk before they do.

Microsoft also makes a recommendation that matters as much as the setting itself: configure your meetings so that only organisers and co-organisers can admit people from the lobby. If any presenter can wave a participant through, your bot control is only as strong as the least attentive person in the meeting, and in the scenario above, that person is distracted, mid-sentence, and clicking “admit” without reading. The same Microsoft page covers anonymous join settings, which are worth reviewing at the same time.

For anyone managing this at scale, the policy is exposed through PowerShell via the ExternalBotAccessMode attribute on Set-CsTeamsMeetingPolicy. One practitioner’s warning: Microsoft’s own documentation is currently inconsistent on the cmdlet. The prose refers to Set-CsTeamsMeetingPolicy while the code examples show Set-CsTeamsEventsPolicy. Verify against your own tenant rather than trusting the copy-paste.

Why the setting alone is not a control

Here is where I put my auditor’s hat on, because this is the part that gets organisations into trouble.

“It’s on by default” is not evidence. I have lost count of the number of times a client has told me a control was enabled because it ships enabled, and we have then discovered a legacy policy, an inherited configuration, or a well-meaning admin who turned it off for a specific business case three years ago and never turned it back on. Defaults drift. If you cannot show me the current policy setting on your tenant, you do not have a control; you have an assumption.

And Microsoft is refreshingly candid about the limits: it states plainly that some external bots may not be detected, and that human participants are occasionally misclassified as bots. So the technical control reduces the risk; it does not eliminate it. Which means the process control still has to exist:

  • Someone owns the participant list. For any meeting where something sensitive will be discussed, the chair checks who is in the room (out loud) before the substance starts. It takes ten seconds and it is the single highest-value habit in this entire article.
  • Unknown attendee, no discussion. If a name in the list is not recognised, the meeting stops until it is explained. Nobody has ever regretted being the person who asked.
  • Invite accuracy is a control. Autocomplete is the villain here. Distribution lists and calendar groups for recurring sensitive meetings beat typing an address every time.
  • Your own people’s bots count too. If your staff have notetakers auto-joining their calendars, your recordings are flowing into whatever tool they signed up for, which is shadow AI with a microphone.

Would you even know if it had already happened?

That is the uncomfortable question. Most organisations have no way of telling whether an external bot has ever sat in one of their meetings, and no process for deciding whether it would be notifiable if one had. A gap analysis answers both.

Book a gap analysis →

Where this sits in ISO 27001 and ISO 42001

If you hold, or are pursuing, ISO 27001, this is not an exotic edge case: it lands squarely in territory the standard already requires you to think about. Access to information. Third parties and suppliers processing your data. Incident management: would you detect it, who assesses it, who decides whether to notify. And awareness training, because none of the process controls above work if your people have never been told that AI notetakers exist and can turn up uninvited.

ISO 42001 adds the other half: governing AI as a category rather than chasing individual tools. Which AI systems are permitted to touch your information? Who approved them? What happens to the data afterwards? An AI notetaker is an AI system operating on some of your most sensitive unstructured data, and in most organisations, nobody has ever assessed it, because nobody ever procured it. It just appeared, one calendar invite at a time.

What I would do this week

  1. Open the Teams Admin Center and look. Meeting policies → Meeting Join and Lobby → “Manage external bots and their access to meetings”. Confirm it is set to require approval, on the org-wide policy and on any targeted policies. Screenshot it: that screenshot is your evidence.
  2. Restrict lobby admission to organisers and co-organisers only, so a distracted presenter cannot admit a bot on your behalf.
  3. Tell your people this is possible. Ten minutes in a team meeting. Most staff have genuinely never considered it, and awareness costs you nothing.
  4. Decide your position on notetakers generally (yours and other people’s) and write it down. That is your AI acceptable-use policy earning its keep.
  5. Check the same question on your other platforms. Teams is not the only place you meet, and the other platforms have their own settings and their own gaps.

Frequently asked questions

Can an AI notetaker really join a meeting I did not invite it to?

It does not need to be invited directly. It joins on behalf of a person who was invited, and if that invitation went to the wrong address, the bot follows it there. Many notetakers are configured to auto-join everything on their user’s calendar without the user doing anything at all.

Isn’t bot detection on by default in Teams?

Yes: “when detected, require approval before joining” is the default. But defaults drift, policies get overridden, and Microsoft states that some bots may not be detected at all. Verify the setting on your tenant rather than assuming, and keep the human check as well.

Is a bot recording our meeting a notifiable data breach?

It may well be, and that call has to be made on the facts. If personal information was disclosed to an unauthorised third party and the disclosure is likely to result in serious harm, the NDB scheme is engaged. The mistake is not having a process to make that assessment: the OAIC has published a quick reference guide precisely because organisations struggle with this decision under pressure. Work it out before you need it, not during.

Should we just ban AI notetakers?

Blanket bans tend to push tools into the shadows rather than remove them, and notetakers are genuinely useful. The better answer is governance: approve a tool, configure it, tell people what may and may not be recorded, and control what enters your meetings from outside. That is exactly what an AI management system is for.

The physical equivalent arrived in August 2026, when the Privacy Commissioner put surveillance wearables on the record. Same failure mode, different room: your visitor policy says no cameras, and your visitors are wearing them.

Speak with an experienced ISO 27001 auditor

If reading this made you want to go and check a setting, that is the right instinct, but the setting is the easy part. The harder question is whether you would detect this, assess it and act on it if it happened tomorrow, and that is a management system question rather than a Teams question.

Start with a gap analysis, or read more on cyber and information security advisory and security and AI governance. Email hello@streamline.business or call us. You will deal directly with an experienced ISO auditor, not a salesperson.

  • Brisbane 07 3667 8280
  • Sydney 02 8315 7780
  • Melbourne 03 9034 3990

Microsoft references: hand these to whoever administers your tenant

  • Manage external bots and their access to meetings hosted in your organization. The core article. Covers how Teams detects bots, the admin policy, the two options, and Microsoft’s own list of known limitations.
  • Control who can bypass the meeting lobby. The companion setting. Restricting lobby admission to organisers and co-organisers is what stops a distracted presenter admitting the bot anyway. Also covers anonymous join.
  • Set-CsTeamsMeetingPolicy. The PowerShell cmdlet reference, for applying ExternalBotAccessMode across the tenant or to targeted groups rather than clicking through the admin centre.

Read them in that order. The first tells you the risk exists, the second closes the gap the first leaves open, and the third lets you prove it is applied consistently, which is the bit an auditor will ask you for.

Source: Microsoft Learn, “Manage external bots and their access to meetings hosted in your organization” (updated 11 June 2026). The scenario described in this article is a generic, illustrative pattern, not an account of any particular organisation.

General guidance only. This article is general information, not legal, financial, safety or compliance advice, and it does not take account of your specific circumstances. Streamline ISO Consultants are ISO management-system consultants, not lawyers or licensed advisers. Standards, laws and regulator guidance change, and details were correct only at the time of writing. Always seek professional advice before acting. See our full Disclaimer.

Stay in the Loop

Get an email when we post an article. Your email address will not be used for marketing, and you can unsubscribe at any time.

We handle your details in line with our privacy policy.

More ISO Certification Information

  • ISO Frequently Asked Questions
    Frequently Asked Questions: ISO FAQs
  • ISO 14001 environmental management
    ISO 14001 Consulting, Environmental Audits and Mentoring
  • Consultant guiding a business owner through their ISO management system at a laptop
    ISO Mentoring: Expert Guidance for DIY ISO Systems
  • ISO 45001 workplace safety inspection
    ISO 45001 Consulting, Safety Audits and Mentoring
  • ISO 27001 information security risk analysis
    ISO 27001 Consulting, Internal Audits & Mentoring
  • Tilt-shift miniature of a collapsed bridge with engineers at a drawing board tracing the failure back to the design
    ISO 9001 Clause 8.3: Design Inputs, Outputs, Review,…
  • ISO certification bodies in Australia
    How to Choose an ISO Certification Body in Australia
  • Tilt-shift miniature of a submarine periscope casting a narrow cone of light onto one small island of activity in a vast dark ocean
    ISO Clause 4.3: Determining Your Scope (Inside Your…
  • Miniature industrial yard with a mobile crane on outriggers and timber packing inside a taped exclusion zone, and a worker in hi-vis at a table with a lift plan
    Your Plant Risk Assessment Is a Document. Is It a Control?

Filed Under: Articles Tagged With: #informationsecurity, #iso27001

Quick Information Request

Brisbane ISO Consultants

Level 14, 167 Eagle St
Brisbane Queensland 4000
Phone: 07 3667 8280
Email: hello@streamline.business

Sydney ISO Consultants

Level 5, 20 Bond Street,
Sydney NSW 2000
Phone: 02 8315 7780
Email: hello@streamline.business

Melbourne ISO Consultants

Level 8, 350 Collins Street
Melbourne, Victoria 3000
Phone: 03 9034 3990
Email: hello@streamline.business

Client and partner logos

KEY ISO ARTICLES

Articles, Deep Dives & More
Frequently Asked Questions
Quality Quotes
Funding Grants for ISO Certification
ISO Consultants
Strategic Planning - Mystical Art?
ISO Certification Auditors
How to get ISO 9001 Certification
ISO Certification Cost
How to tell if your ISO Cert is fake
4-year-olds and Root Cause Analysis
Fast ISO 9001 Certification
The Ultimate Guide to ISO 9001 Audit
ISO 45001 Certification Cost
Who's Interested in a Party?
How to use Smartsheet for ISO
Smarter Quality Objectives
Local Government QMS
Quality Assurance, Quality Control or QMS
ISO Certification in Sydney
ISO Certification in Melbourne
ISO Certification in Brisbane
SAI Global Consultant Affiliate Program

QUICKLINKS TO ISO INFO

ISO Consultants Australia
ISO Mentoring
ISO 27001 Certification Cost
ISO 9001 Quality Management
ISO 45001 Health & Safety
ISO 14001 Environment
ISO 17025 Testing & Calibration
ISO 27001 Information Security
ISO 42001 AI Management
ISO 22000 HACCP Food Safety

Search

FOLLOW OR GET IN TOUCH

linkedinmail
Smartsheet Platinum Partner

Copyright © 2026 Streamline · Log in

Privacy Policy · Terms of Use · Disclaimer

Call us Enquire