ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

AI Meeting Notetakers in Law Firms: Risks to Check First

AI notetakers can record privileged calls and store transcripts on vendor servers. Here is what to evaluate before one joins your client meetings.

3 min readBy Counsel Cyber Team

AI notetakers are easy to adopt and hard to unwind. A lawyer installs one to save time on a client call, it joins every meeting on the calendar, and suddenly a transcript of a privileged conversation lives on a vendor's server that no one at the firm vetted. The convenience is real, and so are the risks.

Before one joins your meetings, work through the questions below.

Where the Risk Comes From

Privilege and confidentiality

A notetaker produces a recording, a transcript and often an AI summary. Each is a new copy of confidential information. Rule 1.6(c) asks lawyers to make reasonable efforts to prevent unauthorized disclosure of client information, and ABA Formal Opinion 512 on generative AI discusses confidentiality when client information is put into these tools. The vendor's terms determine who can see that content, how long it is kept, and whether it can be used to train models.

Consent and recording laws

Recording rules differ by state. Some states require only one party's consent while others require all parties to agree, and a call can cross state lines. A bot that silently joins a meeting is a poor way to handle consent. Check the rules that apply to your calls, and when in doubt, announce the recording and ask.

Third-party participants

Opposing counsel, experts, witnesses and clients on other organizations' calls may not welcome a bot. Some organizations ban them outright. A surprise notetaker can damage trust.

Accuracy

Summaries can misattribute statements, drop qualifiers or invent action items. A transcript that reads cleanly may still be wrong. Errors in a file note can cause real problems later.

Discovery and retention

Transcripts and recordings may be discoverable, and they can complicate your retention policy. If the firm keeps everything forever by default, you have created a large archive that is also a target.

Vendor Questions to Ask

  1. Is there a business or enterprise plan with a written data processing agreement?
  2. Is customer content used to train models? Can that be disabled by contract?
  3. Where is data stored, and how is it encrypted in transit and at rest?
  4. Who at the vendor can access recordings and transcripts?
  5. How long is data retained, and can we delete it on demand and verify deletion?
  6. Does the tool support single sign-on and multi-factor authentication?
  7. How does the vendor notify customers of a security incident?
  8. Are administrators able to control sharing, integrations and bot behavior centrally?

Free consumer accounts rarely answer these questions well.

Policy Settings That Help

  • Approve one tool and block the rest on firm devices and accounts.
  • Disable auto-join. Require the person hosting the meeting to start the notetaker deliberately.
  • Restrict by meeting type. Many firms allow it for internal administrative meetings and prohibit it for privileged client calls unless the client agrees.
  • Control sharing. Turn off public links and automatic emailing of summaries to all attendees.
  • Set retention. Delete recordings after a short window and keep only the reviewed notes that belong in the file.
  • Review the output. A lawyer should read and correct any summary before it is filed.

Alternatives

If the real need is accurate notes, consider a staff member taking notes, or the transcription features built into platforms the firm already licenses, which may fall under existing agreements. Those can be simpler to govern than a new vendor.

Talking With Clients

Some clients will welcome the efficiency and others will object. Mention it in your engagement letter or ask before the call. Large corporate clients may already have outside counsel guidelines that restrict AI tools, so read them.

A Final Check

Ask your staff, without blame, whether anyone is already using a notetaker. Check calendar integrations and connected apps in your Microsoft 365 or Google environment, since users often authorize these tools themselves.

Counsel Cyber can help your firm audit connected apps, set up a vetted tool and put guardrails around it. This post is general information, not legal advice, so confirm requirements with your state bar and counsel.