Surely you'd also have to ban phones and other devices with microphones? All these devices can trivially be set up to record, so if your goal is full security, you should be a no phones workplace.
This is the part where you repeat the same comment and substitute in modifying the software, opening the device and putting in listening hardware, putting a microphone under your skin, attaching a microcontroller to their outside walls to analyze vibration patterns, etc. Luckily, the world doesn't operate on pedantry. They care about removing 99% of attack vectors, the remaining 1% is covered by you being on the line. If your office permits outside recording hardware, someone 'forgetting' that their device was recording is a mishap. But if it only approves certain devices and finds out you did James Bond-level gadgetry to circumvent their measures, guess what image that'll paint on you.
I imagine this is why Apple has kept the mic array and camera as separate removeable components in their devices when pretty much everything else is integrated.
If it’s an Apple device, it’s pretty easy to verify, if you’re not getting into the realm of spycraft. Open the stock recording app from the store and try to record after verifying the preferences allow recording. This is sufficient for catching bad actors who don’t have immense resources behind them. Even easier if it’s a managed device.
If you’re worried about legit espionage, you hold the meeting or do the work in a SCIF, zero devices go in or out period, metal detectors and patdowns on both entry and exit.
So to enforce "to ban phones and other devices with microphones" you'd require the user hand over this phone and you grant access to operate it. I can imagine difficulties.
> If you’re worried about legit espionage, you hold the meeting or do the work in a SCIF, zero devices go in or out period
Well the problem with that is it would bar required phones and other devices.
Many workplaces already require MDM for devices. Some don’t allow unmanaged onsite devices at all. It just depends on the sensitivity of the work. Maybe you haven’t been onsite at a defense contractor or a large financial firm, it can get very restrictive and you basically sign over a lot of your rights to work there.
> Well the problem with that is it would bar required phones and other devices.
That’s the point. Nothing goes in or out except through tightly controlled channels. SCIFs aren’t theoretical, they are in frequent use especially for anyone touching classified info. Large enterprises sometimes use similar facilities as needed for highly sensitive meetings where they can’t afford for anything to be leaked.
I imagine that some workplaces will have to become more security conscious, and others (in two-party states) will have to make it clear to employees that recording without permission from others is illegal and the company will both sue and file charges.