Are AI Meeting Notes Discoverable in Litigation? What Warner, Heppner, and the 2026 Rulings Mean for Your Transcripts

Key takeaways
  • AI meeting transcripts are electronically stored information under FRCP 26(b)(1) and are presumptively discoverable in litigation.
  • Two federal courts split on February 10, 2026: Warner v. Gilbarco protected AI-generated work product; United States v. Heppner destroyed privilege for AI documents.
  • Cloud AI vendors like Otter and Fireflies retain server-side copies that can be subpoenaed directly from the vendor — even if you delete your account.
  • Corporate lawyers are now ejecting AI notetakers from sensitive meetings because automated transcripts turn routine conversations into permanent, discoverable records.
  • On-device transcription eliminates the vendor-server subpoena target, though on-device transcripts remain discoverable if relevant.

Quick answer: Yes. AI meeting notes, transcripts, and summaries are electronically stored information under FRCP 26(b)(1) and are presumptively discoverable in civil and criminal litigation. Two February 2026 federal rulings — Warner v. Gilbarco and United States v. Heppner — reached opposite results on whether AI-generated materials are privileged, and neither eliminates the discovery obligation to preserve and produce them.

Two federal courts split on the same day. Corporate lawyers are already ejecting AI bots from meetings. Here's the discovery reality every professional needs to understand — and why on-device transcription changes the calculus.

Yes — AI meeting notes, transcripts, and automated summaries are almost always discoverable in litigation. Under Federal Rule of Civil Procedure 26(b)(1), any non-privileged material that is relevant and proportional to the needs of a case is fair game for discovery — and AI transcripts fit squarely within that definition of electronically stored information (ESI). The complication in 2026 is not whether these records can be reached, but whether privilege or work product will shield them. Two federal courts issued conflicting rulings on the same day, and the discovery calculus has never been messier.

This is not a theoretical concern. In June 2026, PYMNTS reported that corporate lawyers have begun actively ejecting AI notetakers from meetings before they start, citing the risk that automated transcripts turn routine business conversations into discoverable evidence. A 2025 Fellow.ai survey cited in that reporting found three out of four professionals were already using an AI notetaker in work meetings. The category exploded before the law caught up.

The two February 10, 2026 rulings that split federal courts

On the same day — February 10, 2026 — two federal courts confronted the same fundamental question: are materials a party generates using consumer AI tools protected from discovery? They reached opposite conclusions.

United States v. Heppner (S.D.N.Y.): privilege destroyed

In United States v. Heppner, Judge Jed S. Rakoff of the Southern District of New York ruled on a question of first impression: whether a criminal defendant's exchanges with a public generative AI platform were protected by attorney-client privilege or the work product doctrine. Bradley Heppner, indicted in October 2025 on securities and wire fraud charges tied to a scheme that allegedly defrauded investors of more than $150 million, had used the consumer version of Claude to prepare 31 documents outlining defense strategies. FBI agents seized those documents during a search of his home.

Judge Rakoff granted the government's motion to compel from the bench on February 10, 2026, issuing a written opinion on February 17. As Covington's Inside Privacy analysis summarized, the court's reasoning rested on three pillars: Claude is not a lawyer, Heppner did not communicate with the tool at counsel's direction, and even if the underlying information had been privileged, sharing it with a third-party AI platform waived that privilege. As the Washington Legal Foundation characterized the ruling, Claude "is not a lawyer, a 'trusting human,' or a 'licensed professional who owes fiduciary duties and is subject to discipline.'"

Warner v. Gilbarco (E.D. Mich.): work product preserved

The same day, Magistrate Judge Anthony P. Patti of the Eastern District of Michigan ruled in Warner v. Gilbarco, Inc. that a pro se employment discrimination plaintiff's ChatGPT-assisted drafting was protected work product. The defendants had sought discovery of "all documents and information" concerning the plaintiff's use of third-party AI tools. Judge Patti denied the motion, reasoning that generative AI programs are "tools, not persons" — and that treating every AI query as a privilege-destroying disclosure "would nullify work-product protection in nearly every modern drafting environment, a result no court has endorsed."

The International Bar Association flagged the split as the opening chapter of a much longer story: federal courts are now openly divided on how privilege and work product apply to AI-generated litigation materials, with outcomes turning heavily on facts like whether counsel directed the use of AI and whether the tool was a public consumer product or an enterprise-grade platform with confidentiality terms.

Why AI meeting notes are worse than email for discovery

Email discovery is bad. AI meeting notes are worse, and for structural reasons that Bloomberg Law laid out in a January 2026 analysis. AI notetaking has created "an entirely new category of documents in the discovery process," and their existence raises novel questions about possession, custody, and control — particularly when vendors retain data on their own servers.

Traditional email lives in your company's control. AI transcripts often do not. When Otter's OtterPilot bot joins a Zoom call, the audio is streamed to Otter's servers and stored there. The Otter.ai privacy policy grants the company broad rights to process that content. Even if you delete your Otter account, the copy retained by the vendor — and the metadata around it — may still exist and remain reachable via subpoena served directly on the vendor.

Verbatim capture creates statements you never made

AI transcripts capture verbatim what participants said in a way handwritten notes never do. As Duane Morris attorneys Sharon Caffrey and Seth Dawicki observed in a February 2026 analysis, third-party AI transcription services often involve calendar access, automated AI participation in virtual meetings, and "potential data storage on and disclosure to external servers — typically for purposes of training newer AI models." Casual comments become permanent, searchable, and potentially damaging exhibits.

Inaccurate summaries still become exhibits

Even flawed transcripts can hurt. As Long Island Business News explained in June 2026, AI "may misattribute speakers, miss nuance, or convert casual comments into formal-looking statements" — and even inaccurate materials can become "exhibits, deposition topics, or leverage in discovery disputes." Once the transcript exists, its accuracy becomes a fact question, not a shield against production.

Cloud vs on-device: the discovery surface area compared

The single most useful lens for thinking about AI notetakers and discovery is the surface area they create. Every server, every retention window, every subprocessor, every training corpus is another place where your meeting content can be reached by a subpoena, a breach, or a regulator.

Discovery dimension Cloud AI notetakers (Otter, Fireflies, Zoom AI Companion) On-device transcription (Basil AI)
Where audio is processed Vendor servers Your device (Apple Neural Engine)
Where transcript is stored Vendor cloud + your app Your device (and iCloud if you choose)
Can vendor be subpoenaed directly? Yes — vendor holds the records No vendor-side copy exists
Retention after account deletion Often retained per policy / backups Deleted when you delete
Training-data reuse Often on by default No — nothing leaves the device
Third-party subprocessors Multiple (analytics, storage, ML) None
Metadata trail (join logs, distribution) Vendor-side, discoverable None external
Privilege waiver risk from vendor disclosure Real (per Heppner) No third-party disclosure to trigger it

The preservation problem: what FRCP 37(e) means for AI transcripts

Once litigation is reasonably anticipated, the duty to preserve attaches — and it now covers AI-generated data. K&L Gates' February 2026 litigation guidance advises custodians to disable auto-delete settings, export chat histories, save key exchanges in document repositories, and coordinate with IT to understand "retention of logs and metadata" for AI platforms. K&L Gates also flags the December 2025 ruling in In re OpenAI, Inc., Copyright Infringement Litigation, where Magistrate Judge Ona Wang compelled production of millions of GenAI logs including user prompts and model responses — establishing that AI logs are neither categorically private nor exempt from proportional discovery.

Under FRCP 37(e), failure to preserve ESI that should have been preserved in anticipation of litigation can result in curative measures, adverse-inference instructions, or terminating sanctions. If your organization uses cloud AI notetakers, the preservation obligation extends not just to the transcripts in your inbox but to vendor-side copies, distribution logs, and any metadata the vendor retains — a scope most companies have not budgeted for.

Why corporate lawyers are ejecting AI notetakers from meetings

The market response has been swift. PYMNTS, drawing on New York Times reporting in June 2026, documented that corporate lawyers are now removing AI notetakers from meetings before they begin. The reasoning is straightforward: automated transcripts turn routine business conversations into discoverable evidence in lawsuits and investigations, and the cost-benefit shifted the moment courts started treating AI outputs as ordinary ESI.

Mayer Brown's June 2026 analysis put it bluntly: organizations should "consider limiting access to the privileged output of an AI notetaker, as broad access beyond need-to-know personnel can undermine claims of confidentiality." The firm noted that whether disclosure to an AI vendor waives work product "turns on the vendor's data retention and third-party sharing practices, making vendor due diligence essential." Cloud vendors that retain audio, use it for training, or share with subprocessors face a much steeper waiver argument than tools that never send data off-device.

The GDPR and CCPA overlay

Discovery is not the only pressure point. Article 5 of the GDPR mandates data minimization and purpose limitation, meaning meeting recordings that are indefinitely retained by a vendor for potential model training arguably exceed what is "necessary in relation to the purposes" of the original processing. The California Consumer Privacy Act gives California residents the right to know what personal information is collected and to demand deletion — rights that become practically difficult to enforce when your voice is training a cloud AI model.

These regimes intersect uncomfortably with discovery obligations. A litigant in California may have a CCPA deletion right but a federal preservation duty — and the vendor holding the records is caught between the two. On-device processing avoids the collision entirely because the vendor is never in possession of the record.

How Basil AI solves this: on-device transcription and the disappearing subpoena target

Basil AI takes the vendor-server subpoena target off the board. Transcription runs on your Mac or iPhone using Apple's on-device Speech framework and the Neural Engine described on Apple's privacy page. Audio does not stream to a Basil server because there is no Basil server processing your meetings. There is nothing for opposing counsel to subpoena from us, because we do not have the recording.

This does not make on-device transcripts undiscoverable — if your transcript is relevant to a lawsuit, it is still ESI subject to preservation and production. What it does is collapse the discovery surface to a single custodian: you. No vendor-side backup. No training-corpus derivative. No third-party subprocessor. No metadata log kept for account analytics. As Debevoise's data blog emphasized when analyzing Heppner, the privilege analysis pivoted on the third-party nature of the AI platform. Remove the third party and one of the two key Heppner waiver arguments disappears.

For a deeper look at how the local processing pipeline actually works, see our technical write-up on on-device transcription on iOS 26, and our compliance-officer breakdown of keeping recordings off the cloud for financial services. For the broader vendor-comparison view, our compliant AI meeting notes buyer checklist maps the dimensions that matter for regulated work.

A checklist for meetings that might become exhibits

Before you hit record on a sensitive conversation, run this checklist:

What comes next: the represented-client, enterprise-AI case

The unresolved question — as Jones Walker's AI Law Blog pointed out — is what happens when a represented party uses enterprise AI at counsel's direction. Neither Heppner nor Warner squarely answered that. Expect the next wave of decisions to grapple with confidentiality contracts, zero-retention enterprise tiers, and the question of whether an AI vendor bound by a strict DPA is meaningfully different from a copy service or an outside consultant historically treated as a privileged agent.

Until then, the safest posture for sensitive meetings is the one that eliminates the question altogether: keep the audio on the device, keep the transcript in your control, and never create a vendor-side copy that discovery can reach.

Keep sensitive meetings off cloud servers

Basil AI records and transcribes meetings 100% on-device. No vendor copy. No training corpus. No subpoena target where none needs to exist.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

Can opposing counsel subpoena my Otter or Fireflies transcripts?

Yes. Under Federal Rule of Civil Procedure 26(b)(1), any non-privileged, relevant, and proportional electronically stored information — including AI transcripts, summaries, action items, and vendor-side metadata — can be subpoenaed. Because vendors like Otter and Fireflies retain copies on their servers, subpoenas can be served on both your company and the vendor, expanding the surface area for discovery.

Does using an AI notetaker waive attorney-client privilege?

It can. In United States v. Heppner (S.D.N.Y. Feb. 17, 2026), Judge Rakoff held that sharing information with a public AI platform waived any privilege that might have attached, because the AI provider is a third party outside the attorney-client relationship. Enterprise tools with confidentiality contracts may fare differently, but the risk is real and jurisdiction-specific.

Are AI-generated notes considered work product?

It depends on the facts. In Warner v. Gilbarco (E.D. Mich. Feb. 10, 2026), Magistrate Judge Patti held that a pro se litigant's ChatGPT-assisted drafting qualified as work product, calling generative AI 'tools, not persons.' But work product protection can still be lost if disclosure to the vendor materially increases the likelihood an adversary will obtain the materials — which turns on the vendor's retention and sharing practices.

Do I have to preserve AI meeting transcripts once litigation is anticipated?

Yes. K&L Gates and other litigation firms advise that once litigation is reasonably anticipated, custodians must preserve AI-generated data that relates to claims or defenses. That includes disabling auto-delete, exporting chat histories, and coordinating with IT to capture vendor-retained logs. Failure to preserve can result in sanctions under FRCP 37(e).

Can on-device transcription reduce discovery exposure?

It reduces the third-party surface. When transcription runs locally on your Mac or iPhone and no vendor server holds a copy, subpoenas to a cloud provider cannot reach recordings that were never uploaded. The transcript on your device is still discoverable if relevant, but the vendor-side duplicate — the target of many recent subpoenas — does not exist.

Are AI meeting notes admissible as evidence at trial?

Increasingly, yes — but with authentication challenges. As Bloomberg Law and Mayer Brown have noted, courts are beginning to face admissibility questions around AI transcript accuracy, speaker misattribution, and hallucinated summaries. Parties can be deposed on AI-generated summaries, and inaccurate transcripts have been used as exhibits in discovery disputes even when the underlying summary was flawed.

Get Weekly Privacy Insights

On-device AI tips, privacy news, and Basil AI updates. No spam.

Unsubscribe anytime. Privacy Policy