A woman monitors a secure AI-assisted video conference and data workflow across multiple screens.
Organisations using Microsoft 365 Copilot in Teams should distinguish AI disclosure, meeting transcription and retention of Copilot conversations when reviewing their compliance controls. A September 21 report from FinTech Global, relaying guidance from Theta Lake, warns that inconsistent manual disclosures and indiscriminate retention policies leave workplace AI deployments poorly prepared for EU AI Act scrutiny. That is a governance warning, rather than a reported regulatory ruling that manual disclaimers are inherently unlawful.

For IT administrators, there is a concrete configuration issue behind the warning: Microsoft documents that Teams can discard the temporary speech-to-text data used by meeting Copilot while Copilot prompts and responses may still be retained under Microsoft Purview policies. “No saved transcript” does not necessarily mean “no retained AI interaction.”

What the disclosure warning establishes​

Theta Lake’s recommendations, as reported by FinTech Global, cover AI assistants embedded in Microsoft Teams, Zoom and Webex. They propose four connected measures: inventory deployed AI tools, deliver consistent and logged disclosures, selectively capture AI interactions with personal-information redaction, and maintain logs that support investigations and legal holds.

These are operational recommendations. The report does not identify an enforcement decision, a failed compliance inspection or a regulator’s finding that a manually delivered notice cannot satisfy an applicable obligation. Its categorical prediction that manual disclaimers “won’t survive” scrutiny should therefore not be treated as a legal finding.

Automation can make a disclosure process more repeatable, but organisations still need to establish what must be disclosed, to whom and at which point in a workflow. A notice shown to the employee operating an assistant and a notice shown to someone communicating with that assistant serve different audiences.

Nor should administrators assume that a platform-generated label settles every disclosure question. Greenberg Traurig’s analysis of the European Commission’s AI Act transparency guidance explains that platform-side labels may complement, but cannot replace, an operator’s own applicable disclosure. That supports assessing responsibility across the workflow rather than treating the presence of a label as a complete compliance check.

The useful conclusion is narrower than the headline: organisations need a reliable way to deliver required notices and establish that their controls worked. Purchasing an automated disclaimer mechanism, by itself, does not establish that the correct obligation has been addressed.

Teams separates transcription from retained Copilot conversations​

Microsoft’s Teams administration documentation describes two meeting Copilot modes with different data-handling consequences. Understanding that distinction is a practical starting point for the retention review Theta Lake recommends.

Teams meeting optionDocumented behaviourGovernance consequence
Only during the meetingCopilot uses temporary speech-to-text processing data that is not saved after the meeting or event ends.Administrators must still assess retention of Copilot prompts and responses separately.
During and after the meetingCopilot becomes available when transcription starts, supporting use during and after the meeting or event.The saved transcript is an additional record to account for.
OffMeeting participants cannot use Copilot, and recording and transcription are also disabled.Turning off Copilot at the meeting level also affects those other meeting capabilities.

Microsoft explicitly states that, depending on an organisation’s Purview retention policies, Copilot prompts and responses during meetings might be retained even when recording and transcription are turned off. Its documentation limits that statement to the Commercial cloud, excluding GCC and DoD environments. It also states that meeting Copilot is unavailable in end-to-end encrypted meetings and is not currently available for GCC High. These boundaries should remain visible in any internal guidance. Microsoft Learn

The practical implication is that a retention inventory should distinguish temporary processing data, saved transcripts and Copilot prompt-response records. Treating them as one category can produce an inaccurate explanation of what the organisation keeps—or deletes.

Review the policy without accidentally changing meeting controls​

For organisations already licensed to use meeting Copilot, Microsoft documents the following administrative path:

  1. In the Teams admin center, open Meetings > Meeting policies.
  2. Select the relevant existing policy, or create a new one.
  3. Open the Recording & transcription section and inspect the Copilot setting.
  4. Before saving a change, establish whether the intended behaviour is an enforced requirement or an organiser-changeable default.
  5. Save the selected policy and apply it to the intended groups or individual users.

The distinction in step four is important. Microsoft documents four policy choices:

  • “On” defaults meetings to “Only during the meeting,” but organisers can select another Copilot mode.
  • “On with saved transcript required” enforces “During and after the meeting”; organisers cannot change that value.
  • “On with transcript saved by default” initially selects “During and after the meeting,” while allowing organisers to change it.
  • “Off” defaults Copilot to off, but organisers can change the meeting option to enable it.

Consequently, the administrative “Off” policy is an organiser-changeable default, not an absolute prohibition on meeting Copilot. Separately, when an organiser sets Copilot to Off for an individual meeting, recording and transcription are disabled for that meeting. Microsoft Learn

These settings establish Copilot and transcription behaviour. They do not, by themselves, establish that a legally sufficient disclosure was delivered or that a particular retention schedule is appropriate.

Retention needs a business purpose, not a blanket rule​

FinTech Global presents AI transcripts, summaries and Copilot outputs as regulatory records and points to GDPR, SEC Rule 17a-4, FCA COBS and MiFID II as overlapping considerations. The report does not establish that every generated output falls within each of those regimes, or provide a retention schedule for a particular organisation. Its wording should not be used as a universal instruction to archive everything.

The operational response is to document the purpose and treatment of each relevant record category. For a Teams deployment, that means identifying which meetings produce saved transcripts, whether Purview policies retain Copilot interactions, and which business workflows require preservation or deletion. An organisation should also distinguish evidence that a disclosure control operated from the full content of the conversation.

Theta Lake’s proposed personal-information redaction at ingestion belongs in that same assessment. The report does not specify which records may be redacted or how that recommendation interacts with preservation obligations. It therefore provides no basis for enabling blanket redaction across all regulated communications.

Recruitment screening and performance evaluation also deserve a separate assessment rather than inheriting the classification of an ordinary meeting-summary workflow. FinTech Global identifies those uses as higher-risk applications; the presence of a familiar collaboration product does not answer the deployment-specific compliance question.

The immediate, supported action for Teams administrators is to map actual meeting-policy behaviour alongside Purview retention handling, then give compliance teams that configuration record. This turns a broad warning about AI governance into a specific decision about what users are told, what the service processes and what the organisation actually retains.