How to Record a Zoom Call Without a Bot Joining (and Why Lawyers Should)
If you have taken a deposition prep call, a client intake, or a settlement discussion over Zoom in the last two years, you have almost certainly seen a small rectangle slide into the participant list with a name like Otter.ai Notetaker, Fireflies Notetaker, or Read AI. Sometimes it belongs to you. Sometimes it belongs to opposing counsel. Sometimes nobody in the meeting knows whose calendar invited it.
For a lawyer, that little rectangle is not a convenience. It is a third participant in a conversation that was supposed to be privileged, and it is streaming audio to a server you do not control, under a terms-of-service you did not negotiate, subject to subpoena you cannot quash on the vendor's behalf. The good news is that you do not have to accept the bot as the price of AI notes. You can record a Zoom call without a bot joining, and for attorneys there are strong reasons to do exactly that.
This article walks through the mechanics — the built-in Zoom options, the operating-system-level options, and the on-device capture approach — and then explains why the architecture matters under ABA Formal Opinion 512, NYC Bar Formal Opinion 2025-6, and the emerging case law on AI tools and privilege.
What a meeting bot actually is
A meeting bot — the technical term is a "recall bot" or "notetaker bot" — is a headless participant. When you (or the vendor, using calendar access you granted at signup) drop it into a Zoom link, the vendor's server spins up a virtual attendee that joins the call as a real participant. It receives the same audio and video stream every human participant receives. That stream is transmitted to the vendor's cloud, transcribed there, summarized there, and stored there.
Three things follow from that architecture, and they are the reason bots are the wrong default for legal work:
- The bot is a person, legally speaking, for consent purposes. Every participant can see it. In two-party consent jurisdictions, its presence has to be disclosed and consented to like any other attendee, and Zoom's own recording indicator does not always fire when a third-party bot is capturing.
- The audio leaves the room. Once the stream hits the vendor's server, you have created a subpoena target that is not you and not your client. You have also arguably introduced a third party to the communication, which is the classical way to break privilege.
- You inherit the vendor's security posture. Their subprocessors, their retention defaults, their breach history, their employees' access to raw transcripts — all of it is now part of your matter file.
Judge Rakoff's February 2026 decision in US v. Heppner (S.D.N.Y.) is the clearest recent signal on the direction of travel here. The court held that a litigant's chats with a public AI platform were not privileged, applying a third-party doctrine analogy: once you voluntarily hand the content of a communication to a third-party service, the expectation of confidentiality that underpins privilege is difficult to reconstruct. The opinion was about chatbot conversations, not meeting bots, but the reasoning is portable. A cloud transcription vendor that receives the raw audio of a privileged call is, structurally, the same third party.
The Brewer v. Otter.ai litigation (2025) put the operational risk in plain view: a putative class action alleging that Otter's notetaker recorded and processed conversations without adequate consent from all participants. Whatever the ultimate merits, the case is a preview of the discovery you do not want to be on the receiving end of when your notetaker vendor is the defendant and your client's call is in the training set.
Option 1: Zoom's built-in local recording
The simplest way to record a Zoom call without a bot joining is the feature Zoom shipped in 2013: local recording. As host (or as a participant granted recording permission), you click Record and choose Record on this Computer. Zoom writes an .mp4 and an .m4a to your local drive when the meeting ends. No third-party attendee. No vendor cloud. Zoom itself is of course still in the middle of the call — it has to be, it is the conferencing layer — but you are not adding a fourth party on top of it.
What local recording does not give you is a transcript or a summary. Zoom's AI Companion feature does produce summaries, but it runs on Zoom's servers and, depending on your account configuration, may be governed by terms that permit product improvement uses. For a privileged conversation, most attorneys who look carefully at the settings turn AI Companion off and either transcribe manually or run the file through an on-device transcription tool afterward.
Option 2: Operating-system-level capture
On macOS, you can capture the audio of any application — including Zoom — at the OS level, without Zoom needing to cooperate and without any bot in the participant list. The mechanism is a virtual audio device (Apple's ScreenCaptureKit APIs, introduced in macOS Ventura and expanded in Sonoma, make this a first-class capability) that routes system audio into a recording process running locally.
This is the same class of capture that QuickTime uses when you record a screen with audio. The distinguishing feature, for privilege purposes, is that the audio never leaves the machine. It is captured, processed, and stored locally. There is no server-side leg of the journey, so there is no vendor to subpoena and no subprocessor to add to your matter's data map.
The tradeoff historically was that OS-level capture gave you a file, not notes. Doing anything useful with the file — transcription, speaker labels, summary — meant uploading it somewhere. That is the gap on-device AI closes.
Option 3: On-device capture with on-device AI
The current generation of Apple silicon (M1 through M4) ships a Neural Engine capable of running speech-to-text and summarization models locally, at usable speed, on the same machine that captured the audio. That means the full pipeline — capture, transcription, summary — can happen without any network call.
This is the architecture Basil uses. In Computer mode on macOS, Basil captures the system audio of a Zoom, Teams, or Google Meet call the same way QuickTime would, and runs transcription and summarization on the Apple Neural Engine. No bot joins the call. No audio, transcript, or summary leaves the device. Basil operates no server that receives user data, so there is nothing on our side to subpoena and no subprocessors to disclose in a DPA.
The point is not that Basil is the only tool that can do this — the OS primitives are available to anyone. The point is that the combination (OS-level capture plus on-device AI) is what makes the bot-free workflow actually productive for a lawyer. Without on-device AI, you are back to transcribing by hand or uploading the file.
Comparison: four ways to get notes from a Zoom call
| Approach | Bot in the call? | Audio leaves the device? | Transcript / summary? | Privilege risk profile |
|---|---|---|---|---|
| Third-party notetaker bot (Otter, Fireflies, Read, Fathom cloud tier) | Yes | Yes — to vendor cloud | Yes, on vendor servers | Highest: added third party, vendor subpoena target, consent exposure |
| Zoom local recording + Zoom AI Companion | No | Yes for the summary (Zoom cloud) | Yes, on Zoom's servers | Moderate: fewer parties than a bot, but summary content still leaves |
| Zoom local recording, no AI Companion | No | No | No — file only | Low, but no notes to work from |
| On-device capture with on-device AI (e.g., Basil in Computer mode) | No | No | Yes, generated locally | Lowest: no third party added, no vendor server in the loop |
Why the architecture matters under ABA Formal Opinion 512
ABA Formal Opinion 512 (July 2024) is the ABA's guidance on generative AI in law practice. It does not ban cloud AI, and it does not require any particular architecture. What it does is impose a set of duties that get progressively harder to satisfy the more third parties you add to a privileged communication: competence (Model Rule 1.1), confidentiality (Model Rule 1.6), communication with the client about how their information is being handled (Rule 1.4), and supervision of nonlawyer assistance including vendors (Rules 5.1 and 5.3).
Under Model Rule 1.6(c), a lawyer must make reasonable efforts to prevent inadvertent or unauthorized disclosure of client information. The comment to 1.6 lists factors including the sensitivity of the information, the likelihood of disclosure absent safeguards, and the cost and difficulty of additional safeguards. When the additional safeguard is "do not add a bot," the cost is roughly zero and the risk reduction is meaningful.
NYC Bar Formal Opinion 2025-6 (December 2025) reinforces the same architectural point in a New York-specific frame: the more you can keep client data under your own custody rather than a vendor's, the shorter your disclosure and diligence obligations get.
Consent, two-party jurisdictions, and the bot problem
Eleven US states require all-party consent to record a conversation. California is the one that matters most for AI-notetaker litigation right now, because that is where the Brewer v. Otter.ai case is proceeding. The theory in these cases is straightforward: a bot that joins a call and streams audio to a vendor is a recording device, and every participant has to consent, not just the host.
Removing the bot does not remove the consent question — if you are recording, you still need consent — but it collapses the question back to a familiar one. You are recording your own call, on your own machine, the way lawyers have recorded phone calls (with appropriate consent) for decades. You are not also disclosing the content of the call to a third-party vendor as a condition of getting notes.
The West Technology Group v. Sundstrom (D. Conn. 2024) matter is worth reading here for the adjacent point about vendor-mediated data flows and the discoverability of what sits on those vendor servers. The general lesson: data you have handed to a vendor is data a court can reach through the vendor, on a timeline you do not control.
A practical workflow for bot-free Zoom recording
Assuming you have decided to move to a bot-free setup, here is what the workflow looks like in practice:
- Turn off calendar integrations for any notetaker vendor you previously authorized. This is the step most people skip. Otter, Fireflies, Read, and similar tools typically have persistent calendar access and will auto-join future meetings unless you revoke it in the vendor dashboard and in Google/Microsoft's connected-apps settings.
- Decide on your capture layer. Zoom local recording is the minimum viable option. OS-level capture with an on-device tool is the option that also gives you searchable notes.
- Handle consent explicitly. A short verbal notice at the start of the call — "I am recording this for my own notes; is that alright with everyone?" — plus a written follow-up covers most jurisdictions. For matters where consent is contested, a written consent log matters. (Basil's forthcoming Basil for Law edition, launching August 2026, includes a per-matter consent log for exactly this reason.)
- Label the output. Transcripts and summaries of privileged calls should be labeled as such — Privileged & Confidential — Attorney Work Product — from the moment they are created, not retroactively.
- Set a retention policy. On-device recordings are still recordings. Decide, per matter, how long you keep them and where.
For a longer treatment of the vendor-diligence side of this, see our note on AI notetakers and privilege risk.
What about Teams and Google Meet?
The same three options exist. Teams has its own local recording and its own cloud transcription (via Copilot); Google Meet has cloud recording tied to Workspace and "Take notes with Gemini" as the cloud AI layer. In both cases, the bot-free path is OS-level capture on the participant's own machine, and the on-device AI layer sits on top of that capture rather than on top of the conferencing vendor's API.
One caveat: on Windows, OS-level system-audio capture is more fragmented than on macOS, and the driver-level solutions historically used (VB-Cable, Stereo Mix) are not always deployable in managed-firm environments. Basil is macOS-only for that reason — the Apple Neural Engine plus ScreenCaptureKit is the stack the on-device workflow was built for.
How Basil approaches this
Basil is a fully on-device notetaker built by a practicing lawyer. In Computer mode on macOS, Basil captures Zoom, Teams, and Google Meet audio at the OS level — no bot joins the call — and runs transcription and summarization on the Apple Neural Engine. No audio, transcript, or summary is uploaded. Basil operates no server that receives user data and has no subprocessors handling client content, so there is nothing on our side to subpoena and nothing to disclose in a client DPA beyond the app itself.
The general Basil app is available today with a free 60 minutes per month. The Basil for Law edition — adding privilege attestation, a per-matter consent log, matter organization, and automatic Privileged & Confidential labeling — launches in August 2026 at $19.99/month or $199.99/year for solos, with a 3-day trial on the monthly plan and a 7-day trial on the annual plan. Basil signs DPAs and NDAs on request.
This is a risk-reduction posture, not a guarantee. No architecture removes a lawyer's underlying obligations under Rule 1.6 or the duty to obtain informed client consent where required. What on-device capture does is shorten the list of third parties who have your client's audio, which is the shortest and cheapest safeguard available.
This article is for information only and is not legal advice.
Frequently asked questions
Can I record a Zoom call without a bot joining?
Yes. Zoom's built-in local recording writes the file to your own machine with no third-party attendee. On macOS, you can also capture Zoom audio at the operating-system level using a tool like Basil, which adds on-device transcription and summary without uploading anything.
Does Zoom's local recording notify other participants?
Yes. Zoom shows a recording indicator to all participants when a host or permitted participant records locally. That indicator is a feature, not a bug — it satisfies the basic notice component of consent in most jurisdictions, though you should still confirm consent verbally, especially in all-party-consent states.
Are AI notetaker bots a privilege problem?
They can be. A bot that joins a call streams audio to a vendor's server, which introduces a third party to a privileged communication and creates a subpoena target you do not control. The Otter.ai litigation and Judge Rakoff's US v. Heppner ruling both illustrate the direction courts are taking on cloud AI and confidentiality.
Is on-device capture the same as end-to-end encryption?
No. End-to-end encryption protects data in transit between endpoints. On-device capture means the data never leaves the endpoint in the first place — capture, transcription, and summarization all happen locally, so there is no transit leg to protect and no vendor server holding a copy.
What should I tell clients about how I record calls?
Tell them what you use, where the audio and transcript live, and who else has access. Under ABA Formal Opinion 512 and Model Rule 1.4, informed client communication about AI tools is increasingly expected. If your tool runs on-device with no vendor server, that disclosure is short; if it uses a cloud notetaker, it is longer and typically requires an updated engagement letter.
Does Basil work with Teams and Google Meet?
Yes. In Computer mode on macOS, Basil captures system audio for Zoom, Microsoft Teams, and Google Meet the same way — at the OS level, with no bot joining the call. Transcription and summarization run on the Apple Neural Engine on the same machine.
Keep client conversations on your device
Basil transcribes and summarizes entirely on-device — no cloud, no bot, no server to subpoena. See Basil for Law → · Legal-tool reviews →
This article is for information only and is not legal advice.