AI Notetakers on the Jobsite: What Legal Will Ask
Your field teams already adopted them. The open question is who governs the record.
Alena Tuttle

Almost everything that gets decided on a jobsite gets decided verbally. A sliver of that ever reaches writing. And the sliver that does usually gets typed up at 8pm from memory.
We know what that gap costs. The PlanGrid and FMI research put $177.5 billion a year into non productive activity in US construction, traced 48% of rework back to poor communication and project data nobody could find, and clocked the average worker losing 5.1 hours a week just looking for information.
So field teams did what capable people do when nobody solves their problem. They solved it themselves. They started carrying AI notetakers and pocket recorders onto projects, and they didn't ask.
In the National Cybersecurity Alliance and CybSafe "Oh, Behave!" study, 38% of employees who use AI said they'd put sensitive work information into AI tools without their employer knowing. Okta's 2026 research runs higher: two thirds of US employees using AI tools their company never approved.
If you're an exec at a GC, or you run ops, or you sit in legal or IT, that should get your attention. Probably not for the reason you're expecting.
Your people already found the value
The easy version of this article is a scare piece. I don't think the scare piece is right.
Your super carrying an AI recorder isn't a rogue actor. He's a good field leader who got tired of writing the daily log at 8pm and found something that gave him his evening back. The tool works. That's why it spread.
Follow what he actually got out of it. He's off the job at 5:30 instead of 8. Two weeks later the architect asks what they settled on for the field fab, and he has the answer in ten seconds from the seat of his truck.
But it stops with him. It's on his phone, in his account, in his format. It never turns into the daily log that holds up when the claim comes, or the change order backed by what the architect said on Tuesday, or the forty job pattern that tells you which subs really slip. And when he leaves for a competitor in March, it goes with him.
The obligations don't. That recording is a business record about your project, and those follow the company.
Which is where "well, if he's paying for it himself, that's one less thing I have to buy" stops being true. He kept the benefit. You kept the liability, on a record you can't see, can't search and can't preserve.
The records already exist. We just finish them.
Let's get the obvious objection out of the way: Recordings and transcripts of jobsite conversations are discoverable. That's true of a consumer recorder and it's also true of your email, your texts and your Procore comments.
So the real question is what shape that record is in when somebody reaches for it. An unmanaged consumer tool answers that badly. The record sits on a device you didn't issue, in an account you can't audit, under a retention setting you didn't choose.
Hardline doesn't create a new category of record. Look at what comes out the other side of a call: an updated daily log, a Procore observation, an RFI to the architect, a calendar invite that moves the pour, a confirmation email to the sub. Every one of those already lives in your workflow. Every one is already discoverable. Every one already shows up in claims today, on projects where nobody has ever heard of us.
The record exists either way. What's in question is whether it gets finished, in enough detail, by the person who was on the call, on the day it happened.
Right now it usually doesn't, and that's not a knock on your supers. They're choosing between running the job and writing about running the job, and they pick the job, correctly.
Closing that loop is the whole product. Same records you were already keeping, finished in time to count.
A notetaker hands you a transcript.Hardline turns the conversation into the documents that run the job.
Consent isn't a formality in about a dozen states
The second exposure has nothing to do with litigation strategy. It's the recording itself.
Federal law sets a one party consent baseline, but it doesn't preempt stricter state law. Roughly a dozen states require every party to consent before you record. Depending on how you count the mixed jurisdictions, the list generally runs California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Montana, New Hampshire, Oregon, Pennsylvania and Washington. California is $5,000 per violation or treble damages. Several states stack criminal exposure on top.
Now run that against a real day. Your super is on the phone with a sub, then the architect, then an owner's rep, then a supplier, and the recorder in his pocket has no idea which of them is sitting in an all party consent state. If you run work across state lines (and you do), somebody is getting recorded without being asked.
It's not theoretical enforcement anymore either. The class action filed against Otter.ai in August 2025 alleges violations of the federal Electronic Communications Privacy Act and the California Invasion of Privacy Act, and it survived its motion to dismiss on the core privacy claims. However it shakes out, the plaintiffs' bar has found this category.
This is the one place a company level setting beats a personal device outright. Disclosure configured once by an admin is how you handle all party consent across state lines. Fifty individual judgment calls a day is not.
Why banning it backfires
The instinct at this point is a policy prohibiting recording devices on company projects. Reasonable instinct. Harder execution.
Employment counsel has been warning for a while that blanket no recording rules are legally vulnerable. Under Section 7 of the National Labor Relations Act, the NLRB can invalidate rules that would reasonably tend to chill employees documenting workplace safety concerns or working conditions. A flat ban, applied to everybody for every purpose, is the kind of overbroad rule that's been struck down before. That holds in non union shops too, which surprises people.
And underneath the legal problem is a practical one. Your supers picked up these tools because the documentation burden is real and nobody solved it for them. A ban doesn't remove the burden. It removes the sanctioned tool and pushes the behavior somewhere you can't see it, which is the worst outcome available to the company holding the liability.
This is the settled view in enterprise AI governance too. The guidance behind frameworks your IT team may already know, like ISO/IEC 42001 and the NIST AI Risk Management Framework, is that you govern AI by taking inventory of what's already in use and giving people a sanctioned path. Not by prohibition. You make the approved option the easy one.
The standard to hold us to
Here's the governance checklist I'd run at any vendor in this category, us included.
Ownership. The company owns the account and the data, not the individual. When your super leaves in March, the record stays with you.
Retention you control. You set how long transcripts live. The vendor's default is not your policy.
Legal hold. When counsel issues a preservation notice, you need a way to suspend deletion for specific projects or people. Make them show you.
Consent handling. Disclosure configurable at the org level and owned by an admin, not left to whoever is holding the phone. Ask specifically who can turn it off.
Auditability. Somebody at your company should be able to say what got captured, when, by whom, and on which project.
Training data and subprocessors. Ask plainly whether your conversations train the vendor's models and who else touches the transcripts. Get it in the contract, not a marketing FAQ.
A consumer recorder bought on a personal card fails every one of these. Not because those products are bad, several are excellent at what they were built for, which is one professional taking notes in his own meetings. They were never meant to sit inside a company's records program.
So run the list at us. Retention windows are yours to set. Disclosure is an organization wide setting an admin controls, not a checkbox on your super's phone.
None of that is special to notetakers. It's the same ownership, retention and auditability questions ISO 42001 and the NIST framework ask about any AI system, and your IT team is probably already working through them for the software sitting in the office. The notetaker is just the first one that showed up on the field, in somebody's pocket, without a PO. Whatever standard you set here is the one you'll be applying to the next five.
Your field teams were right about the problem. They were right that the answer is voice. The one thing they couldn't do from the field is make it the company's record instead of their own.
The recorders are already on your projects. The only question left is whether the record they're making belongs to you.
Ready to capture every conversation?
Hardline turns your calls and site conversations into daily logs, RFIs, tasks, and more, automatically.
Get started
