Since June 2026, Teams detects external AI notetakers and holds them in the lobby. In October 2026, a new policy lets you block them automatically. What it really covers, where it falls short, and the decisions to make before turning it on.
One more participant nobody invited
A supplier joins your Teams meeting. Thirty seconds later, a notetaker along the lines of Otter, Fireflies or Read.ai shows up in the participant list. Nobody invited it: the tool latched onto the external guest's calendar, and it is now recording, transcribing and summarizing the meeting into a third-party service. Your internal discussions, your numbers, your employees' words end up stored outside your tenant, without the organizer ever saying yes.
Microsoft describes the problem in its own documentation: these bots may "record or transcribe meetings without participant awareness", "store meeting data in third-party systems outside of the organization's compliance boundaries" and introduce data leakage risks. Blocking AI bots in Teams meetings is therefore a governance file, not an admin's whim.
What has been in place since June 2026
Do not confuse October's new feature with what is already running. Announced on March 13, 2026 (MC1251206) and rolled out between June and mid-September 2026, external bot detection is on by default in every tenant. Teams identifies bots from infrastructure and behavioural signals collected during the join process, labels them as unverified and forces them into the lobby, even when the meeting lets everyone else bypass it. The organizer has to admit them explicitly, with a reminder of the risk.
That is the default mode, "When detected, require approval before joining" (RequireApprovalWhenDetected in the meeting policy). The other existing option, "Do not detect bots", switches everything off. Between the two, the simplest reflex was missing: refusing outright.
What changes in October 2026
Message MC1459141, published on August 21 and updated on September 9, 2026, adds a third option to the "Manage external bots and their access to meetings" policy: automatically block identified external bots, with no organizer intervention. Targeted Release runs from mid to late September, with general availability in October 2026. The original timeline aimed for August; it slipped.
Three things to keep in mind:
- The option is off by default. Nothing changes in your tenant until an administrator selects it.
- It is set at the meeting policy level, so you can roll it out by user group if you want to go gradually (leadership and HR first, for example).
- It targets external bots. Microsoft 365 Copilot, which runs inside your tenant, is not affected.
The limits Microsoft admits itself
Microsoft states in plain words that "some external bots may not be detected" and that detection may occasionally classify a human as a bot. In that case, the organizer admits the person and ticks "This is not a bot". A bot that joins with a real user account, or that mimics a human participant well enough, can get through. Automatic blocking cuts the exposure sharply; it does not bring it to zero.
Two complements are worth the effort. First, restrict lobby admission to organizers and co-organizers, as Microsoft recommends, so a distracted presenter does not admit everyone with one click. Second, require a verification check (CAPTCHA) for anonymous users and untrusted organizations: according to a Microsoft support answer citing Read.ai's own documentation, that tool cannot pass this check. Microsoft is also preparing a Teams Bot Identification Program, in public preview, so legitimate vendors can self-identify.
Law 25: the question is not technical
A third-party notetaker collects personal information: the voice, name and words of every participant, your employees included. Quebec's Commission d'accès à l'information reminds organizations that consent must be "manifest, free, informed and given for specific purposes", that people must be told at the time of collection what the purposes and means are and which third parties receive the information, and that any communication outside Quebec requires a privacy impact assessment beforehand. A bot that invites itself through a supplier's calendar ticks none of those boxes.
This applies to you as an organizer, but also to your own employees using these tools in other people's meetings. The question to settle with your privacy officer: which transcription tools are authorized, for whom, and where the data goes.
What to do before pressing the button
Five moves, in this order.
- Inventory: which AI notetaking tools are already circulating in the organization, officially or not. Teams audit logs and lobby admissions give a good picture.
- Decide your stance: block for everyone, block for sensitive groups, or organizer approval with training. A written policy beats a silent setting.
- Offer the alternative: if teams adopted a notetaker, they needed one. Native Teams transcription and Copilot recaps keep the data inside the tenant.
- Configure: meeting policy, admission restricted to organizers, verification for anonymous users. Test on a pilot group before the global rollout.
- Communicate: warn organizers, and warn your partners that their assistants will be turned away from your meetings.
The button arrives in October
The decision is yours right now. A clear policy on AI notetakers, written and communicated before activation, is worth more than the setting itself.
Want to talk it through?
Let's spend 30 minutes on your situation.
A free assessment with an io4 architect. No commitment, no pressure.
Book my assessment
