For most of the past year, if you worked anywhere near legal, HR, or IT procurement in Europe, you had a date circled: 2 August 2026. That was the day the EU AI Act's obligations for high-risk systems were supposed to bite, and a whole industry of readiness webinars, vendor questionnaires, and slightly panicked Slack threads grew up around it. A recurring question in those threads: what do we do about the AI notetaker?
The date is gone. On 24 July 2026, Regulation (EU) 2026/1744 — the "Digital Omnibus on AI" — was published in the Official Journal; it entered into force on 27 July. It pushes the application of the AI Act's high-risk obligations for Annex III systems from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products from 2 August 2027 to 2 August 2028. Sixteen extra months, handed over with two weeks' notice.
The obvious reaction is relief, followed by putting the file back in the drawer. Here is the contrarian case: if that deadline was the reason your organisation was thinking carefully about meeting recording, you were already thinking about the wrong law. Almost nothing that actually governs the AI notetaker in your Tuesday standup changed last week — and a good deal of it has been in force since 1978.
Point one: your notetaker probably was never high-risk
The single most common misconception in those readiness threads was that "AI in the workplace" equals "high-risk under the AI Act." It doesn't. Annex III is a closed list of use cases, and the employment entry covers a specific set: systems used for recruitment and candidate selection, for allocating tasks, for making decisions about promotion or termination, and for monitoring and evaluating the performance and behaviour of workers.
A tool that writes down what was said in a meeting and produces a summary is, on its own, none of those things. It's a transcription tool. The classification in the AI Act follows the purpose the system is put to, not the cleverness of the model inside it. This is the part worth internalising, because it cuts both ways: the same notetaker becomes a genuinely different regulatory object the moment someone in your company decides to run sentiment analysis across sales calls, score who talks the most in standups, or feed transcripts into a performance-review pipeline. Nobody procures that. It gets built on a Thursday by someone with API access and a good idea.
Point two: the rules that actually bite didn't move an inch
Here's what the deferral did not touch, all of which applies to a meeting recording made this afternoon.
Data protection law. A recording of a meeting is personal data about everyone audible in it, and often special-category data the moment someone mentions a health issue, a union, or a grievance. That means you need a lawful basis, a defined purpose, a retention period, and an answer to a subject access request — not in December 2027, but now. GDPR has applied to your transcripts since the day you started making them. In practice this is where most organisations are actually non-compliant, and no AI Act timetable was ever going to fix it.
Criminal law on recording. In Germany, recording a confidential spoken word without consent is a criminal offence under § 201 StGB — a fact that predates machine learning by several decades and is completely indifferent to what the EU decided last week. In the United States, roughly eleven states require all-party consent, and California's Invasion of Privacy Act has become the workhorse statute for AI recording claims. A single video call with participants in three jurisdictions can pull in three inconsistent consent rules at once.
Collective employment law. In Germany, introducing a system capable of monitoring employee performance or behaviour triggers works-council codetermination under § 87(1)(6) BetrVG — and the case law reads "capable of" generously. A transcription tool rolled out across an organisation lands in that category whether or not anyone intends to monitor anyone. Similar consultation duties exist across much of the EU. None of this was deferred; none of it was ever in the AI Act to begin with.
Transparency duties. The AI Act's Article 50 transparency obligations — the ones about people knowing when they are interacting with an AI system and about marking synthetic content — kept their original schedule. The Omnibus moved the heavy high-risk compliance machinery, not the basic duty to be upfront.
Point three: the real legal risk right now is a lawsuit, not a regulator
While Brussels was rescheduling, a federal judge in California was reading briefs. In re Otter.AI Privacy Litigation (No. 5:25-cv-06911, N.D. Cal.) consolidates claims that the OtterPilot notetaker recorded meetings without the consent of everyone in them, brought under the federal Wiretap Act and California's Invasion of Privacy Act. The motion to dismiss was argued on 20 May 2026 and, as of this writing, no ruling has issued — meaning no court has yet held Otter's practices lawful or unlawful.
That ruling is the first serious federal test of whether wiretap statutes written for alligator clips and telephone lines reach an AI participant sitting quietly in a video call. Whichever way it goes, it will shape notetaker deployment far faster than a 2027 compliance date will — and it arrives on a docket schedule nobody gets to defer. If you want one date in your calendar to replace 2 August 2026, that's the one.
The compliance that doesn't expire
Strip out the deadline anxiety and what's left is a short list that would have been correct in 2024 and will still be correct in 2028. Ask before you record, out loud, every time — the social convention around consent is doing more legal work than most people realise. Know where the audio physically goes and who can subpoena it there. Set a retention period and actually enforce it, because an indefinite archive of everything anyone ever said is a liability that compounds. Write down, in one sentence, that transcripts will not be used for performance evaluation — and mean it, because that sentence is the line between an ordinary tool and an Annex III system. And be especially careful in the conversations where recording is most useful and most sensitive: one-on-ones, grievances, client calls under privilege.
Notice how many items on that list are really questions about architecture rather than paperwork. Where does the audio live? Who else's servers has it touched? What happens to it if the vendor is acquired, breached, or served with a discovery request? A compliance programme built on vendor questionnaires answers none of those. A different technical choice answers most of them at once.
The simplest way to shrink your legal surface: don't send the audio anywhere
Meetly records, transcribes, and summarises entirely on your iPhone. No meeting bot joins the call, no audio is uploaded, no account is created — which means there is no vendor archive to breach, subpoena, retain past its purpose, or explain to a works council. You still get an accurate transcript and summary in 90+ languages; the recording just never leaves the device that made it. Most of the hard questions above stop being hard when the answer is "it's on my phone."
Download MeetlyWhat sixteen extra months are actually for
There's a version of the next year and a half where nothing happens, the file stays in the drawer, and in mid-2027 the same organisations run the same panicked readiness sprint with the same vendor questionnaires. That's the default outcome of any deferral, and it's the one to plan against.
The better version treats the deferral as time to fix things that a deadline would have forced you to paper over. Sixteen months is enough to inventory which teams are recording what, and why. It's enough to kill the three shadow deployments nobody approved. It's enough to move the sensitive categories of conversation — legal, medical, HR, client-privileged — onto tooling where the audio never leaves the endpoint, so the retention question answers itself. And it's enough to write the one-page policy that says which meetings get recorded, who can read the transcript, how long it lives, and what it will never be used for.
- Inventory: list every AI notetaker in active use, including the ones on personal accounts. This is always longer than the IT list.
- Purpose test: for each one, write the sentence "the output is used to ___." If that sentence involves evaluating a person, you have an Annex III problem due 2 December 2027.
- Consent: standardise how recording is announced, and make declining genuinely easy — a consent nobody can refuse is not a consent.
- Location: for each tool, answer where the audio is processed and stored. Move the sensitive categories to on-device processing.
- Retention: pick a number of days, automate the deletion, and stop archiving everything forever by default.
- Watch the docket: the Otter.ai ruling will move faster than the regulation did.
The AI Act deferral is genuinely good news for anyone who was building a compliance programme in a hurry. It is not news at all for the person who has to decide, at 10:03 tomorrow morning, whether it's acceptable to hit record. That decision was always governed by older, duller, more stubborn law — and by whether the people in the room know what's happening to their voices.
Private by architecture, not by policy
Meetly is a meeting recorder built the way the compliance questions want it built: on-device transcription with WhisperKit, on-device summaries, 90+ languages, no bot in the call, no cloud upload, no account. Free to start. The safest recording is the one that never travels.
Download MeetlyFrequently asked questions
Has the EU AI Act been delayed in 2026?
Partly. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers the application of the AI Act's high-risk obligations for Annex III systems from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products from 2 August 2027 to 2 August 2028. The Act itself is not repealed, and other parts of it — including the Article 50 transparency duties — keep their original schedule.
Is an AI notetaker a high-risk AI system under the EU AI Act?
Usually not by itself. Annex III's employment category covers systems used for recruitment, task allocation, promotion and termination decisions, and monitoring or evaluating worker performance and behaviour. A tool that transcribes a meeting and summarises it does none of those. It becomes high-risk when the organisation uses its output to evaluate or rank people — for example, scoring participation, running sentiment analysis on employees, or feeding transcripts into performance reviews. Classification follows the use, not the technology.
Do I still need consent to record a meeting after the AI Act delay?
Yes, and that never depended on the AI Act. In Germany, recording a confidential spoken conversation without consent is a criminal offence under § 201 StGB. In the US, about eleven states require all-party consent and California's Invasion of Privacy Act is frequently used in AI recording claims. Separately, GDPR requires a lawful basis, a defined purpose, and a retention period for the recording and transcript. None of this was deferred.
Does a works council have to approve an AI meeting recorder in Germany?
In most cases yes. Under § 87(1)(6) BetrVG, introducing a technical system that is capable of monitoring employee performance or behaviour requires works-council codetermination, and German case law reads "capable of" broadly — the employer's intention to monitor is not the test. A company-wide transcription rollout typically needs a works agreement covering which meetings are recorded, who can access transcripts, how long they are retained, and an explicit exclusion of performance monitoring.
What is the Otter.ai lawsuit about and has it been decided?
In re Otter.AI Privacy Litigation (No. 5:25-cv-06911, N.D. Cal.) alleges that the OtterPilot notetaker recorded meetings without the consent of all participants, under the federal Wiretap Act and California's Invasion of Privacy Act. Otter's motion to dismiss was argued on 20 May 2026 and no ruling has been issued, so no court has yet held the practice lawful or unlawful. It is the first significant federal test of whether wiretap statutes reach an AI notetaker in a video call.
