ABA Formal Opinion 477R and AI Meeting Tools: Securing Client Communications in Practice

When the ABA Standing Committee on Ethics and Professional Responsibility issued Formal Opinion 477R in 2017, most lawyers were still emailing clients from desktops and dictating memos into handhelds. The opinion updated Formal Opinion 99-413 to reflect a world where confidential information routinely moves across cloud services, mobile devices, and public networks. Almost a decade later, the same framework is doing new work: it is the baseline test that lawyers must apply before turning on an AI meeting notetaker for a client call.

This article walks through what 477R actually requires, why AI notetakers are the new stress test for the opinion, and what a defensible workflow looks like in 2026. It draws on later authority — ABA Formal Opinion 512 on generative AI, NYC Bar Formal Opinion 2025-6, and recent decisions including US v. Heppner and Brewer v. Otter.ai — that together give 477R sharper edges when applied to AI tools.

What ABA Formal Opinion 477R Actually Says

Formal Opinion 477R interprets Model Rule 1.6(c), which requires a lawyer to make "reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to, information relating to the representation of a client." The opinion rejects a one-size-fits-all rule. Instead it lays out a fact-specific analysis, drawing on the seven factors in Comment [18] to Rule 1.6, including the sensitivity of the information, the likelihood of disclosure absent safeguards, the cost of additional safeguards, the difficulty of implementing them, and the extent to which safeguards adversely affect the lawyer's ability to represent clients.

Practically, 477R told lawyers to do seven things when handling electronic communications: understand the nature of the threat, understand how client confidential information is transmitted and where it is stored, understand and use reasonable electronic security measures, determine how electronic communications about client matters should be protected, label client confidential information, train lawyers and nonlawyer assistants in technology and information security, and conduct due diligence on vendors providing communication technology.

That last point — vendor due diligence — is where AI meeting tools live. The opinion recognized that lawyers routinely rely on outside providers for email, storage, and collaboration. It required lawyers to evaluate the provider's security policies, its recoverable data, and its history of breaches, and to consider the terms of service that govern how the provider may use client data. In 2017 that meant Dropbox and Gmail. In 2026 it means transcription services, meeting bots, and AI summarizers.

Why AI Meeting Notetakers Are the New Test Case

An AI notetaker touches every category 477R was designed to address. It captures audio of live conversations with clients. It generates transcripts that are, by definition, verbatim records of privileged discussions. It usually stores those transcripts on a vendor's servers. Many services train models on customer data unless the customer opts out. And the entire pipeline typically depends on a chain of subprocessors that the lawyer has no direct relationship with.

The risk is not theoretical. In Brewer v. Otter.ai (2025), a putative class action filed in the Northern District of California, plaintiffs alleged that the popular transcription service recorded and processed conversations without adequate consent from all participants and used the resulting data to train its models. Whatever the ultimate outcome, the case is a warning shot: the vendor terms most lawyers scroll past can convert a privileged conversation into training data or, worse, into evidence a third party can subpoena from the vendor.

The privilege risk is compounded by cases like US v. Heppner (S.D.N.Y. Feb. 2026), in which Judge Rakoff held that a litigant's chats with a public AI platform were not privileged, reasoning by analogy to the third-party doctrine: sharing content with a commercial AI provider is, for privilege purposes, sharing it with a third party. If a lawyer feeds a client transcript into a cloud AI service, the same logic can reach the transcript.

ABA Formal Opinion 512 and NYC Bar 2025-6: The Modern Overlay

ABA Formal Opinion 512 (July 2024) applied Rules 1.1, 1.6, 1.9, 5.1, 5.3, and 1.5 to generative AI tools. It reinforces the 477R vendor-diligence duty and adds an explicit competence obligation: lawyers must understand, at least at a functional level, how the AI tool processes inputs and outputs, where data is stored, whether it is used to train models, and who else can see it.

NYC Bar Formal Opinion 2025-6 (December 2025) then focused on AI notetakers specifically. It emphasizes informed consent from all participants, careful evaluation of whether recording is even permissible under the applicable wiretap statute, and heightened caution when the meeting involves privileged content. Read together, 477R, 512, and 2025-6 form a stacked test: is the tool competent and secure (477R and 512), and have you obtained the consents and adopted the workflow rules that apply specifically to recording and AI transcription (2025-6)?

The Seven 477R Steps Applied to an AI Notetaker

Here is how the 477R checklist maps onto a modern AI meeting workflow.

477R StepApplied to AI Meeting Tools
Understand the threatInterception during capture, vendor breach, subpoena to vendor, model training on client data, inadvertent sharing of transcripts.
Map data flow and storageIdentify where audio is captured, where it is transcribed, where transcripts are stored, and every subprocessor in the chain.
Use reasonable securityPrefer on-device processing where available; otherwise require encryption in transit and at rest, SSO, and access controls.
Determine protection levelClient-matter conversations should sit at the highest protection tier your firm supports.
Label confidential informationMark transcripts and summaries as Privileged & Confidential; segregate by matter.
Train personnelWritten policy on when notetakers may be used, consent scripts, and retention rules.
Vendor due diligenceReview DPAs, subprocessor lists, training-data terms, breach history, and jurisdiction of storage.

The Vendor Due Diligence Problem

Vendor diligence is where most firms fall short, and it is where the risk is highest with AI notetakers. A typical cloud transcription service involves the audio capture layer, a cloud transcription model, a cloud summarization model, storage, and often a separate integrations layer (calendar, CRM, matter management). Each hop is a subprocessor. Each subprocessor is a party your client did not choose.

Under 477R, the lawyer's obligation is to actually read the terms. Key questions include: Does the vendor use customer content to train models? What is the default, and how do you turn it off? Does the vendor sign a DPA and, if applicable, a BAA? What is the subprocessor list, and how are changes to that list disclosed? Where is data stored, and under what jurisdiction's law? What is the response protocol for a subpoena served on the vendor? How long is data retained, and can you configure retention or force deletion?

A helpful outside reference is the ISO/IEC 27001 family and the SOC 2 framework, both of which give lawyers a common vocabulary for evaluating vendor security posture. Neither is a substitute for reading the actual contract, but both help a non-technical reviewer ask the right questions.

Consent, Recording, and the Wiretap Overlay

Vendor diligence gets you halfway. The other half is consent. Most jurisdictions require at least one-party consent to record a conversation, and roughly a dozen require all-party consent. New York, for example, is a one-party state, but Rule 8.4 and the NYC Bar's guidance still push lawyers toward disclosure when recording clients or opposing counsel. California is an all-party state, and secret recording exposes the lawyer to both criminal and civil liability under Penal Code section 632.

For AI notetakers, the analysis is more layered. A bot that joins a Zoom call as a visible participant makes disclosure easier — everyone can see it. A silent, on-device capture makes disclosure a workflow question: the lawyer has to say, on the record, that a notetaker is running. NYC Bar 2025-6 treats this as a threshold requirement, not a nicety.

Even where recording is lawful, informed consent under Rule 1.6 is a separate question. The client should understand that a transcript will exist, where it will live, who will have access, and how it will be retained. That is a short conversation to have at the start of a matter, and a memorializable one.

Litigation Risk: When the Transcript Becomes Evidence

Once a transcript exists, it can be subpoenaed, produced, and used against your client. West Technology Group v. Sundstrom (D. Conn. 2024) is a useful reminder that courts will grapple with the discoverability of AI-generated records and the metadata around them. If your notetaker stores transcripts on a vendor's cloud, that vendor is a subpoena target. If the vendor is compelled to produce, your client's privileged conversation may leave your control before you even see the subpoena.

Architectural choices matter here. A tool that never sends data off the device removes the vendor-subpoena vector entirely. A tool that stores encrypted transcripts on the firm's own infrastructure keeps the subpoena inside the attorney-client relationship, where you can litigate privilege. A tool that quietly ships everything to a third-party cloud gives you the least control.

A Practical 477R-Compliant Workflow for AI Notetakers

Putting the pieces together, a defensible workflow looks something like this:

  1. Adopt a written firm policy that specifies which AI notetakers are approved and what matter types they may be used for.
  2. Prefer tools that process audio and transcripts on-device or on firm-controlled infrastructure. If you use a cloud tool, insist on a DPA that disables model training on your data.
  3. Obtain and document client consent at the start of the engagement, and again at the start of any recorded meeting.
  4. Announce the notetaker at the top of every call, and note the announcement in the transcript.
  5. Label transcripts and summaries as Privileged & Confidential and store them within your matter file, not in a separate cloud silo.
  6. Set a retention schedule that matches your document-retention policy, and enforce it.
  7. Train lawyers and staff on the policy annually and on any material vendor changes.

For a deeper walk-through of consent scripting, see our internal note on Basil for Law, which collects the consent, labeling, and matter-organization features designed for this workflow.

How Basil Approaches This

Basil was built by a practicing lawyer around one architectural choice: audio, transcription, and summaries are processed entirely on-device using the Apple Neural Engine. Nothing is uploaded. There is no Basil server in the loop and no subprocessor chain — Basil never receives user data. That structure is not a promise about outcomes; it is a fact about where the bytes live. For 477R purposes, it removes the vendor-subpoena vector, eliminates the model-training question, and shortens the vendor diligence conversation to a much simpler review.

Basil captures in-person meetings and virtual calls on macOS (Zoom, Teams, Meet) via on-device capture, so no bot joins the call. The general Basil app is available today with a free 60-minute monthly tier. The Basil for Law edition — with privilege attestation, a consent log, matter organization, and Privileged & Confidential labeling — arrives in August 2026 at $19.99/month or $199.99/year for solos, with a 3-day monthly trial or 7-day annual trial. Basil signs DPAs and NDAs on request.

If 477R is the baseline, the goal is architectural: choose tools where the reasonable-efforts analysis is short because the exposure surface is small. That is the approach Basil takes.

This article is for information only and is not legal advice.

Frequently asked questions

Does ABA Formal Opinion 477R specifically address AI meeting tools?

No. 477R was issued in 2017 and addresses electronic client communications generally under Model Rule 1.6(c). It is applied to AI meeting tools by analogy, and is now supplemented by ABA Formal Opinion 512 (2024) on generative AI and NYC Bar Formal Opinion 2025-6 (December 2025) on AI notetakers specifically.

What is the single most important 477R factor for choosing an AI notetaker?

Vendor due diligence. Under 477R, the lawyer must understand where client data goes, who processes it, and how it may be used. Tools that process data on-device drastically shorten this analysis by removing the vendor and subprocessor chain from the picture.

Do I need client consent to use an AI notetaker on a client call?

In most cases yes. Even in one-party consent states, Rule 1.6 and current ethics guidance, including NYC Bar 2025-6, treat informed client consent as a threshold requirement when a recording or transcript will be created. All-party consent states require consent from every participant.

Can a subpoena reach the transcript stored by my AI vendor?

Yes. If a third-party vendor stores your transcripts, that vendor can be served with a subpoena, and your client may not learn of it in time to move to quash. On-device or firm-controlled storage keeps the transcript inside the attorney-client relationship where privilege can be litigated.

Does using a public AI tool waive privilege?

It can raise a serious risk. In US v. Heppner (S.D.N.Y. Feb. 2026), Judge Rakoff held that a litigant's chats with a public AI platform were not privileged, reasoning by analogy to the third-party doctrine. Feeding client transcripts into a public AI chatbot is best avoided.

How does Basil fit into a 477R workflow?

Basil processes audio, transcripts, and summaries entirely on-device on macOS, with no server and no subprocessors. That architecture removes the vendor-subpoena vector and simplifies the reasonable-efforts analysis under 477R. The Basil for Law edition, arriving August 2026, adds a consent log, matter organization, and Privileged & Confidential labeling.

Keep client conversations on your device

Basil transcribes and summarizes entirely on-device — no cloud, no bot, no server to subpoena. See Basil for Law → · Legal-tool reviews →

This article is for information only and is not legal advice.