Attorney–client privilege does not survive a third party on the line.
By Kyle Nelson, Founder, Fazit
For a lawyer, the risk of a cloud AI notetaker is not only whether you may record the call. It is what recording does to the privilege. Streaming a client conversation to a vendor and its subprocessors is a disclosure to third parties — which invites a waiver argument and leaves a discoverable record. On-device transcription avoids the disclosure by never sending the audio. It does not, however, remove your duty to tell your client.
This is general information for practicing attorneys, not legal advice, and it does not create an attorney–client relationship. Privilege and ethics rules vary by jurisdiction and are fact-specific; rely on your own bar’s current rules and opinions.
Three duties a notetaker touches at once
A meeting-notes tool sits directly on top of three overlapping obligations, and cloud transcription strains all three:
- Confidentiality (Model Rule 1.6). You must make reasonable efforts to prevent unauthorized disclosure of information relating to the representation. Routing that information through a third-party pipeline is exactly the kind of choice the rule asks you to make deliberately.
- Technological competence (Rule 1.1, comment 8). The duty of competence now includes understanding the benefits and risks of the technology you use. “I didn’t know it uploaded the audio” is not a defense the comment leaves open.
- The privilege itself. Distinct from your ethical duties, the attorney–client privilege is an evidentiary protection that can be waived — and waiver is where the notetaker does its real damage.
The waiver problem
The general rule is stark: voluntarily disclosing a privileged communication to a third party can waive the privilege as to that communication. A cloud notetaker is, by construction, a set of third parties — the vendor, plus whatever ASR and LLM subprocessors it streams your audio to. The moment your client’s privileged words reach those servers, you have created a disclosure you then have to defend.
There is a counter-argument, and it is worth stating fairly: disclosures to agents who facilitate the representation — interpreters, e-discovery vendors, experts under Kovel — often do not waive privilege. A notetaker vendor might be characterized the same way. But notice what that costs you: you have turned a settled protection into a fact-specific argument you now have to win, one that a confidentiality agreement papers over but does not eliminate, and that says nothing about audio swept into a training set. Cloud transcription trades a clean privilege for a defensible one. On-device transcription lets you keep the clean one, because there is no third-party disclosure to characterize.
The discovery problem
Even set privilege aside. A recording or transcript on a vendor’s server is an artifact, and artifacts are discoverable. Opposing counsel can seek it. It can surface in a matter unrelated to the one it was made for. It falls within litigation holds. It can be breached. And the metadata — which client, which date, which duration — can itself be sensitive in a way that survives deletion of the content.
WHERE THE PRIVILEGED AUDIO ENDS UP WHO CAN REACH IT
Cloud recorder + bot (Otter, Fireflies) Vendor, subprocessors, subpoena,
breach, sometimes training sets
Bot-free cloud transcription (Granola) ASR/LLM subprocessors, then deleted
On-device transcription (Fazit) No one — the audio never leaves
the machine, no file is createdThe ladder is the whole argument in three rows. Each step down removes a category of party who can reach your client’s words. The bottom row removes all of them — not by policy, but because the audio was never written or sent.
What the bar has actually said
This is no longer abstract. In December 2025 the New York City Bar’s Formal Opinion 2025-6 took up AI tools that record, transcribe, and summarize client conversations directly. Its conclusions track the analysis above: a lawyer should obtain the client’s consent before the tool records — undisclosed recording can be deceptive under Rule 8.4 even when only a summary is kept, because people speak differently once a verbatim record is being made — should weigh whether recording is tactically advisable given confidentiality and privilege, must understand how the tool generates and stores its transcripts and summaries, and should check the output for accuracy where it may be preserved and relied on.
The Boston Bar Association arrives at the same place from a different angle, framing four duties — consent, security, confidentiality and privilege, and file retention — and stating plainly that a firm should keep the tool’s inputs and outputs on its own systems, without third-party disclosure. Read together, both opinions reduce to one instruction: know where the audio and its derivatives go, and keep them off third parties. On-device transcription is the version of that instruction that needs no vendor vetting, no data-processing agreement, and no retention policy, because the third party the opinions worry about is never in the pipeline. What neither opinion lets you skip is the consent conversation — that duty attaches to the act of recording, not to where the recording ends up.
And now a federal court has ruled
On February 10, 2026, this stopped being hypothetical. In United States v. Heppner, Judge Jed Rakoff of the Southern District of New York held that 31 documents a criminal defendant had produced by feeding information from his lawyers into a consumer version of Anthropic’s Claude were protected by neither the attorney–client privilege nor the work-product doctrine. As far as the firms tracking it can tell, it is the first ruling that prompts containing privileged information, and the outputs they produce, are not themselves privileged.
What the court actually ran was a terms-of-service analysis. The privilege failed because the tool’s own terms let the provider collect inputs and outputs, use them to train the model, and disclose them to third parties including government authorities. On terms like that there is no reasonable expectation of confidentiality, so using the tool was treated as a disclosure to a third party. Work product failed on a separate ground: the defendant went to the tool on his own, without counsel directing him, so the material was not prepared at an attorney’s direction.
Be fair about the limits, because they are real. Heppner was a client using a general-purpose chatbot for legal research, not a lawyer using a meeting notetaker, and the decision expressly leaves open whether an enterprise tier with contractual confidentiality and no training on customer data would come out differently. A cloud notetaker vendor with business terms and a signed DPA has a genuine argument that it is not the tool the court was describing.
But look at what that argument is. It is a fact-specific fight about a vendor’s contract, its subprocessors, and its retention, conducted after your client’s words are already on someone else’s servers, and now with a published decision showing what it looks like when a judge runs it. That is the same trade the waiver section describes, and the same artifact the discovery and wiretap exposure attaches to. On-device processing does not win the argument. It removes the party whose terms would have to be argued about.
The bot problem
Bot-based tools add a second liability on top of the first. A visible “notetaker has joined” bot records everyone on the call — including opposing parties, witnesses, and third parties whose consent you do not have and whose words you may have no right to capture. In an all-party-consent jurisdiction, that bot can create exposure before anything is transcribed. The consent map is here, and the argument that a notetaker should not attend as a participant at all is in An AI Notetaker Should Not Be a Participant in Your Call.
What on-device changes — and what it does not
Be precise about the boundary. On-device transcription does not excuse you from the consent and disclosure duties covered in the consent guide. If your jurisdiction or your client relationship requires notice, you still give it.
What it removes is the third-party disclosure and the discoverable artifact. Fazit holds call audio in a RAM ring buffer, transcribes it with an on-device model on Apple Silicon, and writes the note to your own vault as Markdown. No audio file is created, no subprocessor receives the conversation, and the note carries audio_retained: false in its frontmatter because that line describes the execution path, not a promise. There is no recording to subpoena, no vendor to compel, and no disclosure to characterize as a waiver — because the privileged audio never left your machine. The mechanism is documented in Why “Never Records” Is Not Marketing, the architecture-level comparison in On-Device vs. Cloud AI Notetakers, and the GDPR controller/processor exposure in A GDPR-Compliant AI Notetaker Is One That Never Creates the Data.
Evaluating a notetaker as a lawyer: five questions
- Does the client’s audio leave my device? If yes, you have a third-party disclosure to justify.
- Is there a subprocessor list? Every name on it is a party who receives privileged material.
- Is a recording or transcript stored where a subpoena can reach it? If so, it is discoverable — plan for the litigation hold now.
- Does a bot join and record everyone? If so, you are capturing non-clients whose consent you may lack.
- Can the vendor use my audio to train models? Find the answer before the call, not in the terms after.
A tool that answers no / none / no / no / no is doing on-device transcription. For a practice built on privilege, that row is not a nicety — it is the difference between a note-taking tool and a future discovery target.
Lawyers are not the only profession where the analysis runs this way. The recordkeeping version of the same argument, for SEC and FINRA registrants, is in An AI Notetaker for Financial Advisors, the contract version, for consultants bound by an NDA, is in An AI Notetaker for Consultants, and the BAA version, for therapists holding the most privileged conversations of all, is in An AI Notetaker for Therapists and Coaches.
FAQ
Can lawyers use AI notetakers?
Yes, but the analysis is about privilege before it is about consent. Sending client-call audio to a vendor and its subprocessors is a disclosure to third parties, which is what invites a waiver argument. On-device capture avoids the disclosure because no third party receives the content. The duty to tell the client you are transcribing does not go away.
Does using an AI notetaker waive attorney-client privilege?
No court has held that it does. The risk is that privilege protects confidential communications, and routing them through a third party can undercut the expectation of confidentiality that the protection rests on. In February 2026 a federal court held that documents a party produced by feeding privileged information into a consumer AI chatbot were protected by neither privilege nor work product, on a terms-of-service theory. That is not a ruling about notetakers, but it is the analysis on-device processing makes unnecessary.
What have bar associations said about AI notetakers?
The NYC City Bar issued Formal Opinion 2025-6 in December 2025 and the Boston Bar Association has published four-duty guidance. Both treat confidentiality, competence, supervision and client communication as engaged by these tools. Neither bans them. Both expect you to understand where the data goes.
Is an on-device notetaker enough for client confidentiality?
It removes the third-party disclosure, which is the part a tool can fix. It does not remove your own duties: informing the client, complying with recording-consent law in your jurisdiction, and applying your firm’s retention policy to the note that results. This page describes architecture, not legal advice.