Case Study · July 16, 2026 · 7 min read

The 72-Hour Transcript

Everyone wanted AI meeting transcripts, and everyone feared them, the wrong details and the permanent discoverable record. The fix was to make the transcript delete itself in 72 hours, and to make downloading it the moment you became its author.

ScopeThe Workflow InterventionGovernance OutcomeRisk reduction FunctionGovernance EvidenceFirsthand operator account

Everyone wants AI meeting transcripts. Nobody wants to type notes, and a good transcript hands back an hour of attention in every meeting. And everyone is right to be nervous about them, for two different reasons that get tangled together. The first is accuracy: the AI mishears a number, a name, a “not,” and now there is a confident, wrong sentence in a record. The second is quieter and worse: retention. An imperfect transcript that sticks around forever is a permanent, discoverable record of things that may never have been said.

The wrong response is to ban the tool. The right one is to govern it, starting from a single principle the rest of this site keeps returning to, and stated the careful way a records policy has to state it: under this company’s own approved records policy, an AI transcript was treated as an ephemeral draft, not the official record, until a person deliberately made it one. That is a designation a company chooses, not a fact about the world, and, as we will get to, a legal hold or a required regulated record always overrides it.

The rule

At a company I worked with, we turned that principle into two mechanisms.

First, every AI transcript auto-deleted after 72 hours. Not “should be deleted.” Deleted, by the system, on a timer, unless someone acted. The default state of an AI transcript was gone, because AI output is not work product and an ephemeral draft cannot quietly harden into a permanent record. The timer had one hard exception, wired in from the start: a legal hold, or a record a regulation requires you to keep, always overrode the deletion and stopped the clock, because a company’s convenience does not get to delete what the law says to preserve.

Second, keeping one was an act with a name attached. The policy said that the moment a person downloaded a transcript, that person became the human author of record, and owned everything that follows from it: the accuracy, the cleaning, the verification, the finalization into real meeting minutes, exactly as any good program-management process already demands. To be precise, this was an internal accountability rule the company adopted, not legal alchemy. Downloading did not change the legal nature of the underlying information. It named the person answerable for turning it into a real record. The AI expanded your attention during the meeting so you were not heads-down typing. It did not do your job after it. The final minutes were human-owned, human-reviewed, and human-approved, and now they had a specific human’s name on them.

An AI transcript is ephemeral until a human takes ownership An AI transcript has two paths. By default, if no one downloads it, it is auto-deleted at 72 hours and no record is kept. If someone downloads it, that person becomes the author of record, cleans and verifies and finalizes it, and it becomes human-owned minutes. AI transcript ephemeral by default no one keeps it Deleted at 72 hours no record kept DOWNLOAD You are the author of record clean, verify, finalize Human-owned minutes
The AI transcript is ephemeral by default under the policy. Keeping it is a human act, and that act is what assigns accountability. There is no AI work product, only the record a person chose to author.

Why the two mechanisms need each other

Either one alone is weak. Auto-delete without an ownership rule just loses useful notes and teaches people to hoard screenshots. An ownership rule without auto-delete leaves a swamp of half-verified transcripts that everyone assumes someone else is responsible for. Together they make the accountability physical: the record does not exist unless a named person reached out and took it, and the taking is the acceptance of responsibility. Attention expanded, accountability intact. That is the whole point of the standard, and this is what it looks like when it is wired into a tool instead of written on a poster.

The tool you pick is a data decision

There was a second, quieter choice underneath the policy, and it is the part most companies get wrong by treating it as an IT convenience.

We ran two tiers of meeting. For Tier 1, the confidential ones, we used Zoom AI, because, as we evaluated it then, it could restrict auto-sharing of the transcript to just the meeting owner. That mattered: a confidential transcript that auto-broadcasts to every attendee is a data-classification problem wearing a productivity costume. For Tier 2, the meetings where it was fine for every attendee to get the transcript automatically, either tool was allowed. The AI feature we chose was decided by the sensitivity of the data in the room, not by which vendor the company already paid for. That is the Permission pillar in one decision: data sensitivity decides the environment, and it decides the sharing model too.

What does not transfer

Take the pattern, not the parts.

The specific tools will change, and the specific feature difference may already have. Treat “Zoom for Tier 1, either for Tier 2” as an example of the question to ask, which is “does this tool’s default sharing match the sensitivity of this meeting,” not as a standing recommendation about two products.

The 72 hours is a policy choice, not a magic number, and it never overrides the law. Once litigation is reasonably anticipated, a duty to preserve can attach to electronically stored information regardless of your deletion timer (Federal Rule of Civil Procedure 37(e)), and some regulated records carry their own affirmative retention requirements (FDA’s guidance on IRB meeting minutes is one example). Your number depends on how your teams actually work and, far more, on what your own legal, compliance, and records-retention functions require. Retention and discoverability are genuinely legal questions, and this is a worked operating example, not legal advice. Set the number with the people who own that risk, and check it against your own regulatory and quality obligations if your meetings touch regulated work.

And it only holds if it is enforced, not announced. The auto-delete has to be configured in the system, on a timer, or it is a suggestion. The ownership rule has to be one everyone has actually read, and the people who download have to actually do the cleaning, or you have simply relabeled an unverified transcript as “minutes” and made things worse. A governance mechanism that depends on everyone remembering to be careful is not a mechanism. It is a hope.

Monday morning

Pick your meeting-transcript tool by data tier, not by habit: for your confidential meetings, does the default sharing keep the transcript with the owner, or spray it to the room? Set a default auto-delete on the raw transcripts. Then write the single sentence that does the real work: the moment you download it, you are the author of record. And before any of it goes live, walk it past legal and records.

It is a small, workflow-level change, one tool and one policy. But it is the whole no-AI-work-product principle made real, and a company that gets this one right has learned the habit every larger rung on the ladder is going to require.

Cheers,
-Titus

The next one

Get it in your inbox.

New Issues, FAQs, and Case Studies as they go out. Each one names something, explains something, or hands you something you can use on Monday. Subscribe, and I will send each as it goes out.

Prefer the tool you already think in? Here is how to read it in your chatbot.