Legal Malpractice Insurance and AI Notetaker Disclosure

Renewal season for legal malpractice policies has quietly become an AI audit. Over the past eighteen months, carriers writing lawyers professional liability (LPL) coverage in the United States have added, expanded, or sharpened questions about generative AI use, third-party vendors, and confidentiality controls. The AI notetaker sitting in your Zoom sidebar is now a line item on your application, whether you noticed or not.

This piece walks through what carriers are starting to ask, why the questions are showing up now, how the answers interact with your duties under ABA Model Rule 1.6 and the newer AI-specific guidance, and what a defensible disclosure looks like. It is written for solos and small firms who do not have a dedicated risk officer reading the fine print of every SaaS contract.

Why carriers started asking about AI notetakers specifically

Three things happened in close succession. First, the ABA issued Formal Opinion 512 in July 2024, telling lawyers that generative AI tools implicate the duties of competence, confidentiality, communication, and supervision, and that lawyers must evaluate the vendor's data handling before use. Second, the New York City Bar followed in December 2025 with Formal Opinion 2025-6, sharpening the confidentiality analysis for cloud-based AI. Third, courts began treating AI tools as discoverable and, in some configurations, not privileged. The Brewer v. Otter.ai litigation (2025) put a spotlight on background transcription capture and the questions it raises about consent and vendor data handling.

For an underwriter, that combination is a claim vector. If a firm is using an AI notetaker that stores transcripts on a vendor server, the carrier's exposure now includes: subpoena of that vendor by an adversary, an inadvertent-waiver claim, a client complaint about undisclosed recording, a data breach at the vendor, and a bar grievance under Rule 1.6 or its state analog. So the applications changed.

The questions showing up on 2025 and 2026 renewal applications

Carriers do not use a single form, but the pattern across the major LPL writers is consistent. Expect some subset of the following:

Some carriers now ask a follow-up specifically about meeting bots, phrased as "any tool that joins or records video conferences." That question exists because bot-based notetakers (the ones that show up as a participant named "Notetaker" in a Zoom call) create a discoverable third-party record and a consent problem in two-party-consent jurisdictions.

What a bad answer looks like

The two failure modes on the application are opposite and equally dangerous. The first is a blanket "no" when associates or the lawyer themselves are quietly using a consumer AI tool. The application is signed under penalty of rescission. If a claim later reveals that a paralegal was pasting deposition excerpts into a public chatbot, the carrier can deny coverage for material misrepresentation. The second failure is over-listing: naming every browser extension anyone ever installed, without knowing whether the vendor retains data. That gives the carrier a menu of things to exclude.

The defensible answer is a short, accurate inventory with a one-line data-handling note for each tool, plus a copy of the firm's written AI policy. If you do not have a written policy, that is the first thing to fix before the next renewal.

How the disclosure interacts with Rule 1.6 and privilege

Model Rule 1.6(c) requires lawyers to make reasonable efforts to prevent unauthorized disclosure of client information. Formal Opinion 512 makes clear that using a third-party AI vendor is a disclosure event that has to be evaluated: what does the vendor see, what do they retain, who at the vendor can access it, and what happens on subpoena. The Rule 1.6 comments already contemplate this analysis for cloud vendors generally; AI just makes the stakes higher because the data is processed, not just stored.

The privilege overlay is separate. Attorney-client privilege can be waived by disclosure to a third party unless the third party is a necessary agent of the lawyer. Whether an AI vendor qualifies as a Kovel-style agent is unsettled and jurisdiction-specific. Courts can look at a cloud AI relationship and decide it looks more like third-party doctrine than agency. The same logic reaches transcription vendors that retain and process meeting content on their own servers.

Carriers know this. That is why the disclosure question is really a proxy for two underlying risks: waiver and unauthorized disclosure. If your answer to the application makes clear that the tool never sends data off the device, both risks drop meaningfully. If the answer is "cloud vendor, standard DPA," the carrier will price accordingly, and in some cases exclude AI-related claims by endorsement.

What carriers are quietly excluding by endorsement

A handful of LPL writers have begun attaching endorsements that carve out coverage for claims arising from the firm's use of generative AI, or that condition coverage on the firm having a written AI policy and executed vendor agreements. The endorsements are not standardized and are easy to miss because they sit in the policy schedule rather than the declarations page. Read them.

The practical exclusions to watch for:

Endorsement patternWhat it doesHow to respond
Blanket AI exclusionExcludes any claim arising from generative AI usePush back; ask for policy-language carveouts for on-device tools
Vendor-conditional coverageCoverage only if a written DPA is on file for each AI vendorMaintain a DPA folder; request signed DPAs from every vendor
Consent-conditional coverageCoverage only if client consent to AI use is documentedAdd an AI clause to the engagement letter
Cloud-transcription carveoutExcludes claims from meeting-bot or cloud transcription toolsMove to on-device capture or disclose and price accordingly
Training-data exclusionExcludes claims where client data was used to train a modelConfirm in writing that no vendor uses your data for training

Building an answer set you can defend

The application answer is downstream of firm hygiene. Before you touch the form, do four things.

1. Inventory. Ask every timekeeper, in writing, what AI tools they use for client work. Include browser extensions, mobile apps, transcription tools, and anything that touches email drafting or document review. Do not rely on IT logs alone; consumer AI is often used on personal devices.

2. Classify by data path. For each tool, note where the data goes. On-device (never leaves the machine) is the lowest-risk classification. Cloud with a signed DPA and no training use is the middle. Cloud with no DPA, or consumer tier with data-training defaults, is the top of the risk stack and should be shut down before you sign the application.

3. Paper the vendors. Request a DPA from every remaining vendor. If a vendor will not sign one, that is a data point for the application and, arguably, for whether the tool is Rule 1.6 compliant at all. Keep copies.

4. Write the policy. A one-to-two page written AI policy is table stakes now. It should cover approved tools, prohibited tools, client consent, supervision of AI output, and what to do when a client asks whether AI was used. The ABA Center for Professional Responsibility has published materials that can serve as a starting point.

Client consent and the engagement letter

Formal Opinion 512 does not require client consent for every AI use, but it does require the lawyer to consider whether the specific use rises to a level that triggers the duty to communicate under Rule 1.4. Recording, transcription, and summarization of client meetings almost always do. Two-party-consent states raise the stakes further: recording without consent is a criminal statute problem, not just an ethics problem.

The cleanest fix is a paragraph in the engagement letter that (a) describes the AI tools the firm uses in general terms, (b) confirms that client-confidential information will only be processed by tools the firm has vetted, and (c) obtains consent to on-device capture and summarization of client meetings. If the firm uses a cloud-based tool, the paragraph should say so and identify the vendor. Vague "we may use technology" language is not enough for a carrier and probably not enough for a bar counsel either.

For more on the underlying consent analysis, see our internal note on Basil for Law and the privilege-waiver cluster.

What the answer sounds like when it is done right

A defensible application response, in plain English, reads something like this: "The firm uses an on-device AI notetaker that processes meeting audio locally on the attorney's Mac and does not transmit audio, transcripts, or summaries to any third-party server. The vendor has executed a DPA. No client data is used for model training. The firm maintains a written AI use policy dated [X], and the engagement letter includes a consent paragraph covering AI-assisted notetaking."

That answer does three things at once. It identifies the tool, it disposes of the third-party disclosure question, and it papers the Rule 1.6 reasonable-efforts analysis. An underwriter reading it does not need to ask a follow-up. Compare that to "Yes, we use [popular cloud transcription tool], standard terms," which invites the follow-up and often the endorsement.

Where the market is heading

Two trends are worth watching. First, carriers are beginning to differentiate premium based on tool architecture, not just presence. On-device tools with no server-side retention are being treated as a lower-risk profile in some quoting engines. Second, bar authorities are converging on the view that lawyers must be able to explain, in specific terms, what happens to client data inside any AI tool they use. The days of "it's just a notetaker" as an answer are ending.

The lawyers who will have the easiest renewal conversations in 2026 and 2027 are the ones who can point to an architecture that removes the disclosure question rather than answering it. If nothing leaves the device, there is no vendor to subpoena, no DPA to argue about, and no training-data question to answer.

How Basil approaches this

Basil is a fully on-device AI meeting notetaker for attorneys. Audio, transcription, and summaries are processed on the Apple Neural Engine on the lawyer's own Mac. Nothing is uploaded. There is no Basil server that receives user content, and there are no subprocessors handling matter data. That architecture is the point: on a malpractice application, the honest answer about data path is "none, it stays on the device," which is a materially different answer than the cloud vendors can give.

Basil captures both in-person meetings and virtual calls (Zoom, Teams, Meet) through on-device capture on macOS in Computer mode, so no bot joins the call as a third participant. Basil signs DPAs and NDAs on request. The Basil for Law edition, which adds privilege attestation, a consent log, matter organization, and Privileged & Confidential labeling, is launching in August 2026 at $19.99 per month or $199.99 per year for solo attorneys, with a 3-day monthly trial and a 7-day annual trial. The general Basil app, with a 60-minute-per-month free tier, is available today. See Basil for Law for the full feature list.

Basil's architecture reduces the risk by removing the third party from the data path, which is the specific risk carriers are underwriting when they add AI questions to the application. Coverage outcomes remain a matter for the carrier and the facts of any given claim.

This article is for information only and is not legal advice.

Frequently asked questions

Do I have to disclose AI notetaker use on my malpractice application?

If the application asks, yes. LPL applications are signed under penalty of rescission, so a blanket 'no' when the firm or any timekeeper uses AI tools can void coverage for material misrepresentation. Inventory the tools first, then answer accurately.

Will using an AI notetaker raise my malpractice premium?

It depends on the tool's architecture. Some carriers are differentiating between on-device tools with no server-side retention and cloud vendors that store transcripts. The presence of a written AI policy, signed DPAs, and client-consent language in the engagement letter also affects underwriting.

What is the difference between on-device and cloud AI for privilege purposes?

An on-device tool processes data locally and never transmits it to a vendor server, which means there is no third-party recipient of the client-confidential content. Cloud tools route the content to a vendor, which raises third-party disclosure and potential waiver questions.

Do I need client consent to use an AI notetaker?

For meeting recording and transcription, in most cases yes, both under Rule 1.4 communication duties and under state recording-consent statutes. The cleanest approach is a consent paragraph in the engagement letter that identifies the tools and their data path.

What if my carrier attaches an AI exclusion endorsement?

Read it carefully. Some endorsements are blanket exclusions; others are conditional on having a written policy and signed DPAs. Push back where you can, and ask whether on-device tools are treated separately from cloud vendors.

Does Basil sign a DPA?

Yes. Basil signs DPAs and NDAs on request, even though Basil never receives user content, because carriers and clients often require the paperwork regardless of architecture.

Keep client conversations on your device

Basil transcribes and summarizes entirely on-device โ€” no cloud, no bot, no server to subpoena. See Basil for Law โ†’ ยท Legal-tool reviews โ†’

This article is for information only and is not legal advice.