AI Meeting Notes and the Work-Product Doctrine: A Different Standard Than Privilege
Most lawyer-facing writing about AI notetakers collapses two very different doctrines into one word: privilege. That collapse is convenient shorthand and terrible risk management. Attorney-client privilege and the work-product doctrine protect different things, arise at different moments, waive under different rules, and interact with third-party AI tools in different ways. If you use — or are evaluating — an AI meeting notetaker, you need to understand both, because a decision that is safe under one doctrine can be catastrophic under the other.
This article walks through the work-product doctrine as it applies to AI-generated meeting notes: what it covers, what it does not, how disclosure to a vendor is analyzed, and how the architecture of your notetaker changes the analysis. It is written for practicing lawyers, not IT buyers, and it draws on the ethics opinions and cases that actually matter right now.
Why Privilege and Work Product Are Not the Same Test
Attorney-client privilege protects confidential communications between a lawyer and a client made for the purpose of obtaining or giving legal advice. It is a communications rule. It is waived, in most jurisdictions, by voluntary disclosure to a third party who is not within the circle of confidentiality.
The work-product doctrine, codified for federal practice at Federal Rule of Civil Procedure 26(b)(3) and rooted in Hickman v. Taylor, 329 U.S. 495 (1947), protects materials prepared in anticipation of litigation or for trial by or for a party or its representative. It is a materials rule. It protects things — memos, notes, mental impressions, interview summaries — not communications as such.
The two overlap constantly in practice. A memo summarizing a client interview may be both a privileged communication and opinion work product. But the tests are independent, and losing one does not necessarily lose the other. Just as important, gaining one does not gain the other.
The core differences that matter for AI notes
| Dimension | Attorney-Client Privilege | Work-Product Doctrine |
|---|---|---|
| What it protects | Confidential communications for legal advice | Materials prepared in anticipation of litigation |
| Who must be involved | Lawyer and client (plus agents within the circle) | Party or its representative (lawyer, consultant, agent) |
| Trigger | Legal advice sought or given | Reasonable anticipation of litigation |
| Waiver by third-party disclosure | Generally waives, subject to agency and common-interest exceptions | Only waives if disclosure substantially increases the likelihood an adversary obtains the material |
| Opinion vs. fact | No such distinction | Opinion work product gets near-absolute protection; fact work product yields on substantial need |
| Applies to AI-generated summary? | Only if the underlying communication was privileged and confidentiality is preserved | Yes, if the notes reflect a lawyer's mental impressions or trial preparation |
When AI Meeting Notes Become Work Product
An AI-generated summary of a meeting can qualify as work product when three things line up: the meeting occurred in anticipation of litigation or for trial preparation, the lawyer directed the creation or curation of the notes, and the notes reflect the lawyer's selection, emphasis, or mental impressions of what mattered.
Raw transcripts sit closer to the fact end of the spectrum. They are a mechanical record of what was said. Courts have historically been reluctant to extend robust work-product protection to purely mechanical recordings that involve no lawyer judgment. A witness interview transcript that captures everything spoken is more vulnerable than a lawyer's selective memo drawn from that transcript.
AI summaries occupy an interesting middle ground. A one-page summary that highlights admissions, flags open issues, and identifies follow-up questions reflects something resembling judgment — but the judgment was exercised by a model, on a template, not by the lawyer. That distinction matters when opposing counsel argues that an AI summary is not really opinion work product because no attorney mind ever engaged with it.
The practical answer is that AI-generated summaries are most defensible as work product when the lawyer directs their creation for a litigation-related purpose, reviews and adopts them, and can articulate why the summary format itself reflects the case theory (for example, a template built around the elements of a claim or defense).
The Third-Party Problem: Vendor Disclosure and the Waiver Question
Here is where AI notetakers diverge sharply from a legal pad. Every cloud-based notetaker involves disclosing meeting audio and transcripts to a vendor — often to several subprocessors — for processing. That disclosure raises different questions under each doctrine.
Under privilege law, disclosure to a vendor is typically analyzed through the Kovel agency framework: a third party who assists the lawyer in rendering legal advice can be within the circle of confidentiality if properly engaged. Ethics opinions have applied that logic to technology vendors, but only when the engagement includes real confidentiality obligations and the vendor's role is limited.
Under work-product law, the analysis is different and, in many respects, more forgiving. The Advisory Committee note to Rule 26 and a long line of federal decisions hold that work product is waived by third-party disclosure only when the disclosure substantially increases the likelihood that an adversary will obtain the material. Disclosure to a friendly consultant working on the case does not waive. Disclosure to a random contractor with no confidentiality obligation might.
So when you send meeting audio to a cloud notetaker, the work-product question is: does the vendor's handling of that data substantially increase the odds that an adversary — through subpoena, breach, litigation involving the vendor, or the vendor's own use of the data — gets a copy?
What increases that risk
- Vendor retention of audio or transcripts after processing
- Use of client data to train models, whether the vendor's or a subprocessor's
- A subpoena-able business relationship: the vendor has your data and can be served
- Broad rights in the terms of service to disclose data in response to legal process without notice
- Multiple subprocessors, each of which introduces its own subpoena surface
- Recording bots that join the call and create records the other side's platform also retains
The Otter.ai class action, Brewer v. Otter.ai (2025), illustrates the point. The complaint alleges that the service recorded and processed conversations, including those of non-consenting participants, and used that data in ways users did not expect. Whatever the merits, the case is a live demonstration that a notetaker vendor can become a party in its own litigation, with your recordings as evidence.
The Heppner Signal: AI Interactions and the Third-Party Doctrine Analogy
In United States v. Heppner, decided by Judge Rakoff in the Southern District of New York in February 2026, the court held that a litigant's chats with a public AI platform were not privileged. The reasoning drew on a third-party doctrine analogy: a user who feeds material into a service operated by an outside company has disclosed that material to a third party. Whatever the user believed about confidentiality, the architecture of the interaction did not support a privilege claim.
Heppner is a privilege case, not a work-product case, and its facts involved a party's own use of a consumer chatbot rather than a lawyer's use of a professional tool. But its logic is transferable. If the mere act of typing something into a third-party AI service is treated, by analogy to the third-party doctrine, as disclosure, then the work-product waiver question — does this disclosure substantially increase the risk an adversary obtains the material — becomes more concrete. The answer depends heavily on which third party, under what contract, with what retention.
West Technology Group v. Sundstrom and the Duty to Preserve
West Technology Group v. Sundstrom (D. Conn. 2024) is worth reading alongside the doctrinal cases because it addresses what happens when litigation-related electronic records disappear or are handled carelessly. The case reinforces a point that AI-notetaker adopters underappreciate: work-product materials, once created, become subject to preservation obligations. A notetaker that auto-deletes recordings, or a vendor that quietly rotates data out of its systems, can create spoliation exposure independent of any waiver question.
The takeaway is architectural. Whatever tool you use, you need to know exactly where the audio lives, where the transcript lives, where the summary lives, and for how long. Vague answers from a vendor are not a substitute for that knowledge.
What ABA Formal Opinion 512 and NYC Bar 2025-6 Add
ABA Formal Opinion 512 (July 2024) addressed generative AI and lawyer ethics directly. It emphasized competence under Model Rule 1.1, confidentiality under Model Rule 1.6, and the lawyer's obligation to understand how a tool handles client information before using it. The opinion does not draw a bright line between privilege and work product, but its confidentiality framework covers both: a lawyer who does not know where client data goes is not competent to use the tool.
NYC Bar Formal Opinion 2025-6 (December 2025) built on that foundation with more specificity around AI tools that process client communications. The opinion reinforces that vendor selection, contract terms, and technical architecture are all part of the confidentiality analysis — not add-ons to it.
Neither opinion says "do not use AI notetakers." Both say, in effect, that if you use them, you are responsible for understanding what happens to the data, and you cannot outsource that understanding to marketing materials.
A Practical Framework for AI Notes and Work Product
The doctrinal analysis converges on a set of practical questions you can apply to any notetaker you are evaluating or using now.
1. Where does the audio go?
If audio leaves the device — to a vendor's servers, to a transcription subprocessor, to a model host — you have created a disclosure. Whether that disclosure risks work-product waiver depends on the answers below. If audio never leaves the device, the question largely disappears.
2. What is the retention posture?
Zero retention is not the same as short retention. A vendor that processes and immediately discards raw audio has a different subpoena surface than one that stores it for 30 days "for quality purposes." Read the actual data-handling documentation, not the summary page.
3. Who are the subprocessors?
Each subprocessor is another party that can be subpoenaed, breached, or acquired. A tool that lists no subprocessors — because the processing happens locally — has a materially smaller attack surface than one that lists a dozen.
4. Does the vendor train on your data?
Training use is disclosure with amplification: the material does not just sit in a vendor's storage, it is absorbed into model weights that other users interact with. Even where training clauses are opt-out, the default and the auditability of the opt-out matter.
5. Does a bot join the call?
Bot-based notetakers create a record on the platform (Zoom, Teams, Meet) that the platform itself may retain. They also announce their presence to participants, which is good for consent but bad for candor. On-device capture that does not appear on the call preserves the meeting's natural dynamics while still recording.
6. Can you produce a defensible chain of custody?
If a court asks where a recording came from, how it was processed, and who else touched it, can you answer? Work-product protection depends in part on your ability to describe how materials were created and preserved.
How Basil Approaches This
Basil is built by a practicing lawyer, and the architecture reflects the doctrinal analysis above rather than working around it. Audio, transcription, and summarization run entirely on-device on the Apple Neural Engine. There is no server that receives your recordings, no subprocessor chain, and no training use of your data — because Basil never receives your data in the first place. In-person meetings and virtual calls (Zoom, Teams, Meet) are captured in Computer mode on macOS, without a bot joining the call.
The practical effect for work-product analysis is architectural, not promissory. Third-party disclosure is not part of the equation when there is no third party. That does not by itself make any particular note privileged or shielded — doctrine still has to do its work — but it removes an entire category of waiver risk from the analysis.
The Basil for Law edition, launching August 2026, adds privilege attestation, a consent log, matter organization, and Privileged & Confidential labeling to the on-device foundation. Pricing for the Solo tier is $19.99/month or $199.99/year, with a 3-day trial on the monthly plan and a 7-day trial on the annual plan. The general Basil app, with a 60-minute monthly free tier, is available today. Basil signs DPAs and NDAs on request.
If you want to go deeper on the related privilege analysis, see our companion pieces on AI notetakers and attorney-client privilege and vendor diligence for on-device AI.
This article is for information only and is not legal advice.
Frequently asked questions
Is a raw AI transcript of a meeting work product?
Not usually on its own. Work-product protection typically requires that the material be prepared in anticipation of litigation and reflect some element of lawyer judgment or selection. A mechanical transcript that captures everything said, without lawyer direction or curation, sits at the fact end of the spectrum and is more vulnerable to disclosure than a selective summary or memo the lawyer directs and adopts.
Does sending audio to a cloud AI notetaker waive work-product protection?
It can, depending on the vendor. Work product is waived by third-party disclosure when the disclosure substantially increases the likelihood an adversary will obtain the material. A vendor that retains audio, uses data for training, has many subprocessors, or has broad rights to disclose in response to legal process raises that risk. On-device processing, where audio never leaves your machine, avoids that disclosure entirely.
How is the work-product doctrine different from attorney-client privilege?
Privilege protects confidential communications between lawyer and client made for legal advice. Work product protects materials prepared in anticipation of litigation. Privilege is generally waived by any voluntary third-party disclosure. Work product is only waived by disclosures that substantially increase the risk an adversary gets the material. The two often overlap but are analyzed independently.
What does US v. Heppner mean for AI notetakers used by lawyers?
Heppner held that a litigant's chats with a public AI platform were not privileged, reasoning by analogy to the third-party doctrine. Although it involved a party using a consumer chatbot rather than a lawyer using a professional tool, the case signals that courts view submitting material to a third-party AI service as disclosure. That framing pressures both privilege and work-product analyses when vendors receive client data.
What should I ask an AI notetaker vendor before using it on litigation matters?
Ask where audio and transcripts are stored, how long they are retained, who the subprocessors are, whether the vendor or any subprocessor trains models on user data, whether a bot joins the call, what the response to subpoenas looks like, and whether the vendor will sign a DPA. Vague answers to any of these should be treated as a red flag for both confidentiality and work-product purposes.
Does on-device processing eliminate all work-product risk?
No single architecture eliminates all risk, but on-device processing removes the third-party disclosure vector that drives most vendor-related waiver analysis. If audio never leaves your device, there is no vendor server to subpoena, no subprocessor chain, and no training use of your data. Doctrine still governs whether any particular note qualifies as work product, but the disclosure question largely disappears.
Keep client conversations on your device
Basil transcribes and summarizes entirely on-device — no cloud, no bot, no server to subpoena. See Basil for Law → · Legal-tool reviews →
This article is for information only and is not legal advice.