Update: Third-party AI Assistant Bots Joining UW-Madison Zoom Meetings
Posted: 2024-03-22 13:16:48 Expiration: 2026-03-29 13:16:48
UW-Madison Zoom user settings will be updated to block a series of third-party AI bot domains from joining UW-Madison Zoom meetings. Learn more.
Update:
Starting October 23, 2024, UW-Madison Zoom user settings will be updated to block a series of third-party AI bot domains from joining UW-Madison Zoom meetings. This update aims to reduce the security risks associated with sharing data with unapproved third-party applications.
What is changing?
-
Affected user setting: Block users in specific domains from joining meetings and webinars.
-
Blocked third-party AI bot domains: otter.ai, read.ai, fireflies.ai, meetrecord.com, sembly.ai, hal.ai
We recognize the list of domains is not comprehensive and will need to be reviewed periodically. If you’d like to recommend additional third-party AI bot domains to be added to this list, please submit your feedback using the comment feature here: https://kb.wisc.edu/139097 .
Keep in mind
-
Individuals who already modified the default setting will not receive this update. The keyword ‘modified’ will appear next to the modified setting. You can still add these domains to your personalized setting.
-
This setting is not locked and can still be modified to add or remove domains as desired.
-
View tips on how to reduce the risk of a third-party AI bot from joining your UW-Madison Zoom meeting.
If you have any questions, please contact the DoIT Help Desk.
*********************************************************************************************
Original post:
Individuals have reported random AI assistant bots such as otter.ai, read.ai, and fireflies.ai, joining and recording their UW-Madison Zoom meetings without approval, which has been a concern for Secure Zoom accounts.
What is an AI Assistant Bot?
AI assistant bots such as otter.ai, read.ai, fireflies.ai, and similar bots offer to streamline virtual meetings by taking notes on behalf of the attendee/host and organize content to include a list of action items, meeting highlights, and more.
What is happening?
Individuals are integrating their UW-Madison Office 365 calendar with the otter.ai, read.ai, or similar apps by signing up for an account. Once the AI assistant bot is given permission to read the account’s calendar, the bot will attempt to auto-join every video conference meeting (including MS Teams and Webex) the individual is invited to.
Most hosts are unaware if an attendee integrated an AI assistant bot with their account and may accidentally allow the AI assistant bot to join their meeting. The bot will then record the meeting, create a transcript, and more, without the host’s awareness, until the meeting is done and the bot notifies the host and attendees a recording of the meeting is completed and is now available.
Why shouldn’t I use them?
UW-Madison does not have a contract with otter.ai, read.ai, or fireflies.ai . Individuals integrating these apps with their UW-Madison Microsoft 365 calendar are assuming risk in exposing university content such as protected or sensitive data.
Can AI assistant bots be blocked?
See update above.
How can I delete the integration from my UW-Madison Microsoft 365 account?
If your UW-Madison Microsoft 365 calendar is integrated with an AI assistant bot, you’ll need to go to the AI assistant application and delete your account from there. Zoom admins do not have the ability to revoke access on behalf of a UW-Madison Zoom user.
Resources:
- Read.ai - Delete your read.ai account
- Otter.ai - Disconnect your calendar and delete your otter.ai account
- Fireflies.ai - Delete your fireflies.ai account
How can I protect my meetings from AI assistant bots?
There are a few security options that can prevent the AI assistant bots from joining your meeting.
1. Enable waiting room
The waiting room requires that each of your attendees be reviewed and admitted to the room. “Bot” accounts can be rejected before they join your meeting. Learn more: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0059359 . Please go to the User section for steps.
- For internal meetings: UW-Madison host and UW-Madison attendees only
If your meeting is only UW-Madison faculty, staff, and students, you may require authentication using a UW-Madison account to join your meeting. The AI assistant bots do not have UW-Madison Zoom accounts, and should not be able to join.
- For external meetings: UW-Madison host and non- UW-Madison attendees combination
If you're invited non-UW-Madison attendees to your meeting, you can still use a Waiting Room or you can add them as exceptions to the authentication requirement. Learn more: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0063837#h_01F13CMJ47ERFJ9Y9WEKEW8W59 .
2. Enable captcha:
- Learn more: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0067293 .
- Please go to the User section in this article and view step 6.
3. Block the AI assistant bot's domain
- Learn more: https://support.zoom.com/hc/en/article?id=zm_kb&sysparm_article=KB0063852 .
- Please go to the User section in this article and follow the User steps to learn how to add otter.ai, read.ai, and fireflies.ai in the domain section.
Additional resources:
- Managing third-party meeting bots KnowledgeBase: https://kb.wisc.edu/136072
- Generative AI services at UW–Madison: https://it.wisc.edu/generative-ai-services-uw-madison/
-- UW-Madison Zoom