AI Client Intake Notes for Lawyers: A Privilege-Safe Workflow
Client intake is where a matter is won or lost, and it is also where the most sensitive facts of a representation first hit the record. A prospective client walks in (or dials in) and, within twenty minutes, hands you the emotional core of the case: the affair, the tax position, the trade secret, the arrest, the acquisition. If you are a solo attorney, you are also the one taking notes, running the conflicts check, quoting a fee, and trying to remember whether the caller actually said "my business partner" or "my former business partner."
It is no surprise that solo and small-firm lawyers are reaching for AI notetakers to handle the transcription and summarization burden. The problem is that most consumer AI tools were not built with Rule 1.6 in mind. Uploading an intake call to a cloud service — even one with a friendly privacy page — creates a set of ethics and privilege questions that most solos have not been trained to answer. This article lays out a workflow for using AI on intake notes that reduces those risks by design, anchored to the ethics guidance that actually exists today.
This article is for information only and is not legal advice.
Why Intake Is the Highest-Risk Moment for AI Use
Three things are true about a first client meeting that are not true about most other work product.
First, privilege is fragile at intake. The attorney-client relationship may not yet be formed, but the prospective-client privilege under Model Rule 1.18 already attaches to the information disclosed. That protection exists whether or not you take the case, and it exists whether or not you take notes on a legal pad or through a SaaS platform.
Second, intake conversations are dense with the exact categories of information that create waiver exposure if disclosed to a third party. The third-party doctrine is not a new problem, but AI vendors have made it a live one at a scale that did not previously exist.
Third, intake happens fast and repeatedly. A solo attorney may run five intake calls a week. Every one of those is a decision point about which tools touch privileged content. A workflow that requires case-by-case judgment about whether to "turn on the recording" is a workflow that will fail on a Thursday afternoon when the phone will not stop ringing.
What the Ethics Guidance Actually Says
The relevant guidance for AI use in intake is more developed than many practitioners realize.
ABA Formal Opinion 512 (July 2024) is the anchor document. It sets out that a lawyer using a generative AI tool must (i) understand the tool's capabilities and limitations, (ii) protect confidential information under Rule 1.6, (iii) communicate with the client about material AI use, (iv) supervise the tool as if it were a nonlawyer assistant under Rules 5.1 and 5.3, and (v) charge reasonable fees. Opinion 512 is explicit that inputting client information into a self-learning or third-party-hosted GAI tool implicates the duty of confidentiality even if the vendor promises not to train on the data.
NYC Bar Formal Opinion 2025-6 (December 2025) sharpens the point for New York practitioners and, by influence, for the broader bar. It treats the choice of AI vendor as itself an ethical decision requiring diligence into where data is processed, who can access it, and whether the vendor's terms permit any secondary use.
The case law is starting to catch up. In US v. Heppner (S.D.N.Y. Feb 2026), Judge Rakoff held that a litigant's chats with a public AI platform were not privileged, reasoning by analogy to the third-party doctrine. The holding was not about lawyers, but the logic transfers directly: content shared with an AI vendor is content shared with a third party unless something about the architecture makes it otherwise. West Technology Group v. Sundstrom (D. Conn. 2024) is a reminder that the mechanics of who touched a document matter to privilege analysis. And Brewer v. Otter.ai (2025) has focused attention on the specific question of AI notetakers and the consent, recording, and data-handling posture around them.
Read together, the guidance points in one direction: the safest place for privileged intake content is a place where no third party has access to it.
The Four Failure Modes of Cloud AI Notetakers at Intake
Before laying out a workflow, it is worth naming the specific ways cloud-based AI notetakers create risk at the intake stage.
Failure mode one: the bot in the room. Notetakers that join a Zoom or Teams call as a participant create a visible third party on the recording. Every attendee sees "Otter.ai" or "Fireflies" in the participant list. In an intake context, that is a disclosure moment. The prospective client sees the bot and either consents implicitly (weak record) or objects (awkward and disruptive). Neither is ideal.
Failure mode two: server-side storage of privileged content. Once the transcript is generated in the vendor's cloud, it lives there. It is subject to the vendor's retention policy, their subprocessors, their subpoena response practices, and their breach exposure. A subpoena to the vendor is a subpoena you may never see.
Failure mode three: training and secondary use ambiguity. Vendor terms change. A tool that does not train on your data today may reserve the right to do so tomorrow, or to use "aggregated" or "de-identified" outputs in ways that Opinion 512 would treat as material.
Failure mode four: consent theater. Some tools push all the consent burden onto the user with a checkbox, but the substantive disclosure to the client — that a third-party vendor will process the recording — often never happens. That is a Rule 1.4 problem as much as a Rule 1.6 problem.
A Privilege-Safe Intake Workflow, Step by Step
The workflow below is designed for a solo attorney running intake calls in person, by phone, or on video. It assumes you want AI help with transcription and summarization but do not want to import third-party risk into every new matter.
Step 1: Decide the tool question once, not per call
Pick one intake tool and commit to it. The decision criteria should be: does this tool process audio and transcripts on-device, or does it upload them? If it uploads, what is the vendor's contractual and technical posture on access, retention, and training? A tool that runs entirely on your Mac's Neural Engine removes most of the third-party-doctrine analysis before it starts.
Step 2: Build a standing consent script
Whether or not your jurisdiction requires two-party consent to record, your ethics obligations require you to be transparent about material AI use. A 15-second script at the top of every intake call solves this. Something like: "I use an AI tool that runs on my own computer to help me take notes on our call. Nothing is uploaded to a server. Is that all right with you?" Log the answer.
Step 3: Separate the conflicts check from the substantive intake
Get names and adverse parties on the record early, run the conflicts check, and only then proceed to the substantive facts. This is good practice regardless of AI, but it also means your AI-generated notes for the substantive portion of the call are cleanly scoped to a matter that has cleared conflicts.
Step 4: Label everything as Privileged and Confidential at creation
The intake note, the transcript, and any AI-generated summary should carry a Privileged & Confidential header from the moment they exist. This matters if the document is ever produced in discovery or reviewed by a special master.
Step 5: Store on the same machine, in the matter folder
Do not export intake transcripts to a general-purpose cloud drive. Keep them in your matter management system or in an encrypted folder on the same device that generated them. The fewer copies in the fewer places, the smaller the surface.
Step 6: Review, edit, and delete the raw transcript on a schedule
Opinion 512's supervision duty means the AI output is a draft, not a final work product. Read the summary against your memory of the call, correct it, and set a deletion policy for the raw audio and transcript once the edited summary is finalized. Retention creep is a privilege risk.
Comparing Intake Tool Architectures
The table below compares the architectural postures of common categories of AI notetakers as applied to intake work. It is not a product-by-product review; it is a framing device for the diligence Opinion 512 and NYC Bar Opinion 2025-6 contemplate.
| Architecture | Where audio is processed | Third-party access risk | Subpoena exposure to vendor | Fit for intake |
|---|---|---|---|---|
| Bot-joins-call SaaS (Otter, Fireflies, Read) | Vendor cloud | Vendor staff, subprocessors, breach exposure | Yes — vendor holds the content | Poor |
| Platform-native AI (Teams Copilot, Zoom AI Companion) | Platform cloud | Platform staff, platform subprocessors | Yes — platform holds the content | Mixed; depends on tenant configuration |
| Generic cloud LLM used for summarization | Vendor cloud | Vendor staff, model providers | Yes | Poor unless enterprise-grade DPA is in place |
| On-device notetaker (Apple Neural Engine) | Attorney's Mac | None outside the device | No vendor to subpoena for content | Strong |
Documenting the Intake File
A defensible intake file for a matter where AI was used to assist with notes should contain, at minimum: the consent record (client's answer to the AI-use question), the edited AI-generated summary marked Privileged & Confidential, a note reflecting the conflicts check outcome, and a retention note stating when the raw transcript and audio were deleted. If you ever need to defend the workflow — to a client, a court, or a disciplinary body — those four artifacts do most of the work.
For a broader treatment of the ethics posture, see our companion piece on Basil for Law, which walks through Rule 1.6 diligence for AI vendors.
What Solos Should Not Do
A few practices are worth flagging as clear risk creators at intake.
Do not paste intake notes into a general-purpose consumer chatbot to "clean them up." The Heppner reasoning applies with force: content sent to a public AI platform is content shared with a third party, and there is no reason to think a court would treat a lawyer's intake summary differently.
Do not rely on vendor marketing language as your diligence. "Bank-grade encryption" and "we do not train on your data" are not answers to the questions Opinion 512 asks. The questions are architectural: where does the data go, who can access it, and what is the retention posture.
Do not use bot-joining notetakers on intake calls without explicit, logged consent. The Brewer v. Otter.ai litigation has drawn attention to exactly this pattern, and the reputational risk is meaningful even where the legal exposure is contested.
Do not skip the deletion step. Retention is a decision, not an accident. If your tool defaults to keeping transcripts indefinitely, change the default or work around it.
How Basil Approaches This
Basil was built by a practicing lawyer for the intake problem specifically. Audio, transcription, and summarization all run on-device on the Apple Neural Engine. Nothing is uploaded. There is no Basil server that holds your intake content, no subprocessor chain, and no vendor cloud to subpoena. In-person and virtual calls are both captured through on-device capture on macOS, so no bot joins the Zoom, Teams, or Meet call and no third participant appears on the recording. This is what we mean by privilege-safe by architecture: the risk reduction comes from the design, not from a promise.
The general Basil app is available today with a free tier of 60 minutes per month. The Basil for Law edition — with privilege attestation, a consent log, matter organization, and automatic Privileged & Confidential labeling — launches in August 2026 for solo attorneys at $19.99/month or $199.99/year, with a 3-day trial on the monthly plan and a 7-day trial on the annual plan. Basil signs DPAs and NDAs on request.
This article is for information only and is not legal advice.
Frequently asked questions
Can I ethically use an AI notetaker for client intake calls?
Yes, provided you comply with ABA Formal Opinion 512: understand the tool, protect confidentiality under Rule 1.6, disclose material AI use to the client, supervise the output, and charge reasonable fees. The safest architecture is one where the audio and transcript never leave your device, because that removes most of the third-party-doctrine analysis.
Do I need client consent to use AI on an intake call?
You should get it, and you should log it. Even where recording consent is not legally required in your jurisdiction, Rule 1.4 and Opinion 512 point toward affirmative disclosure of material AI use. A short standing script at the top of every intake call is the cleanest approach.
What is the risk of using a cloud AI notetaker for intake?
Cloud notetakers store privileged content on vendor servers, which creates third-party access, subpoena exposure to the vendor, and potential secondary-use ambiguity. The reasoning in US v. Heppner (S.D.N.Y. Feb 2026) — that content shared with a public AI platform is not privileged — illustrates why architecture matters.
How long should I keep AI-generated intake transcripts?
Only as long as you need them. Once you have finalized an edited summary in the matter file, set a retention policy for the raw audio and transcript. Indefinite retention creates unnecessary risk and complicates any future privilege review.
Does an on-device AI notetaker eliminate all privilege risk?
No tool eliminates all risk. On-device processing reduces the third-party exposure that cloud tools create and removes the vendor as a subpoena target for content, but the lawyer's supervision, consent, and retention obligations still apply.
When will Basil for Law be available?
The Basil for Law edition launches in August 2026 for solo attorneys at $19.99/month or $199.99/year, with a 3-day monthly trial and a 7-day annual trial. The general Basil app is available today with a 60-minute-per-month free tier.
Keep client conversations on your device
Basil transcribes and summarizes entirely on-device — no cloud, no bot, no server to subpoena. See Basil for Law → · Legal-tool reviews →
This article is for information only and is not legal advice.