Microsoft Copilot in Teams: Law Firm Confidentiality Risks

Microsoft Copilot is now embedded across the Microsoft 365 stack, including Teams meetings, where it can transcribe conversations, generate summaries, surface action items, and answer questions about what was said. For law firms already standardized on Teams, the temptation is obvious: turn it on, and every client call comes with an AI notetaker attached.

The confidentiality analysis is more complicated than the marketing suggests. Copilot for Microsoft 365 is a cloud service. Meeting audio, transcripts, and the prompts a lawyer types into Copilot chat all flow through Microsoft's infrastructure under the terms of the customer's tenant agreement. That is a defensible posture for many business use cases. For attorneys bound by ABA Model Rule 1.6 and the growing body of ethics guidance on generative AI, it is worth working through carefully before the first privileged conversation is captured.

This article walks through what Copilot in Teams actually does with meeting data, where the confidentiality pressure points are, how recent ethics opinions and case law frame the question, and what a lower-risk architecture looks like.

What Copilot in Teams Actually Does During a Meeting

When a Teams meeting is scheduled with transcription enabled and Copilot licensed for the participants, Copilot can operate in two overlapping modes. First, it can generate a recap after the meeting: a summary, a list of decisions and action items, and follow-up suggestions. Second, during the meeting, participants with a Copilot license can open the Copilot pane and ask questions like "what has been decided so far" or "summarize the last ten minutes."

Under the hood, this requires two things: a live transcript of the meeting, and a large language model with access to that transcript. Microsoft's documentation confirms that Copilot in Teams runs on top of the meeting transcript, and that transcript is stored in the meeting organizer's OneDrive or in Exchange, depending on configuration. Microsoft describes the enterprise data protection commitments applicable to Copilot in its Microsoft 365 Copilot data, privacy, and security documentation, including statements that prompts and responses are not used to train the foundation models when used within a Microsoft 365 tenant.

Those commitments matter. They are also not the same as saying nothing leaves the device. The transcript exists. The summary exists. Both are stored in cloud tenants that Microsoft operates, that Microsoft can be compelled to produce under lawful process, and that are governed by whatever retention, eDiscovery, and administrator access controls the firm has configured, or failed to configure.

Where the Confidentiality Pressure Points Are

For a lawyer, the interesting questions are not whether Microsoft is a reputable vendor. They are structural.

None of these are unique to Copilot. They apply to any cloud meeting product. Copilot changes the picture because it converts spoken conversation into structured, searchable text by default, and it invites lawyers to type substantive questions about privileged discussions into a chat interface whose logs live in the same cloud.

What the Ethics Opinions Say

Two opinions are worth reading closely.

ABA Formal Opinion 512 (July 2024) addresses generative AI tools generally. Its core teachings for meeting AI are that lawyers must understand how the tool handles inputs and outputs, must evaluate confidentiality risks under Rule 1.6, must consider whether informed client consent is needed before inputting client information, and must supervise the tool's output. The opinion does not prohibit cloud AI. It requires competent, informed use.

NYC Bar Formal Opinion 2025-6 (December 2025) is more pointed on meeting-capture tools specifically, focusing on notice, consent, and the confidentiality analysis when a third-party AI vendor is in the loop. Read together with Opinion 512, the direction of travel is clear: lawyers can use these tools, but the burden is on the lawyer to understand the data path and to make an informed judgment about whether client confidentiality is adequately protected.

Case law is starting to fill in the edges. In U.S. v. Heppner (S.D.N.Y. Feb. 2026), Judge Rakoff held that a litigant's chats with a public AI platform were not privileged, drawing a third-party doctrine analogy. The holding involved a consumer product, not an enterprise tenant with contractual protections, so it does not translate directly to Copilot use inside a firm's Microsoft 365 tenant. It does illustrate the direction courts are heading: sending substantive content to an AI service can matter for privilege and work-product analysis, and the terms under which the service holds that content are going to be litigated.

Separately, Brewer v. Otter.ai (2025) is a live reminder that meeting-transcription vendors themselves face claims tied to how they capture and process call audio. The case involves a consumer-oriented transcription product, but the underlying question, who consented to what and where the audio went, is the same question that applies to any AI notetaker.

Copilot in Teams vs. Alternative Architectures

The table below summarizes how three common approaches differ on the axes lawyers actually care about. It is not a scorecard; it is a way to see the trade-offs.

DimensionCopilot in TeamsThird-party bot notetakerOn-device notetaker (Basil)
Where audio is processedMicrosoft cloud (tenant)Vendor cloudLocal Mac (Apple Neural Engine)
Where transcript is storedOneDrive/Exchange of organizerVendor accountLocal device
Bot visibly joins callNo (native)Yes, typicallyNo (on-device capture)
Third-party subprocessor for AIMicrosoft (contractual EDP)Vendor plus its subprocessorsNone
Subpoena surface outside firmMicrosoft tenant recordsVendor recordsNone held by a third party
Works for in-person meetingsNoLimitedYes
Requires client to be on TeamsYesDependsNo

The point of the comparison is not that cloud AI is disqualifying. It is that the confidentiality analysis changes depending on where the data lives and who can be compelled to produce it. For some matters, the Microsoft tenant path is entirely appropriate. For others, particularly high-sensitivity investigations, deal work, or matters where the client has expressed reservations about cloud AI, an architecture with no third-party data holder may be the more defensible choice.

Vendor Diligence Questions Worth Asking

Whether the firm is evaluating Copilot, another cloud AI notetaker, or an on-device tool, the diligence questions look similar. Guidance from the International Legal Technology Association and standard cloud-vendor questionnaires cover most of them. A short list:

Microsoft publishes answers to most of these for Copilot in its documentation and in the Microsoft Products and Services Data Protection Addendum. The point of the exercise is not to catch a vendor out. It is to build a written record that the firm asked the questions, which is what Opinion 512 essentially requires.

Third-Party Attendance and Waiver Risk

One issue that gets less attention than it should is what happens when a Teams meeting includes a third party who is not covered by privilege. The West Technology Group v. Sundstrom line of cases (D. Conn. 2024) and similar authorities remind us that presence of a non-privileged third party can defeat privilege regardless of what technology is in the room. Copilot does not create this problem, but it does make the record of the meeting substantially more complete and searchable, which changes the practical calculus in later discovery.

If the firm's practice is to allow AI capture on any Teams call with clients, it is worth pairing that practice with a clear protocol on who may attend, when Copilot should be paused, and how transcripts of mixed-attendance meetings are labeled and retained.

Practical Guardrails If You Use Copilot in Teams

For firms that decide Copilot is the right fit for some or all of their Teams meetings, a few guardrails reduce the risk without giving up the productivity benefits:

These are the same guardrails any competent legal-tech policy would apply to a cloud AI tool. They do not eliminate the underlying architectural fact that content is being processed in a third-party cloud. They reduce the risk that a lapse in configuration or usage turns into a confidentiality problem.

When On-Device Makes More Sense

For a subset of a lawyer's work, the cleanest answer to "what data went to a third party" is "none." On-device notetakers process audio and generate transcripts and summaries on the lawyer's own machine, using local models, with no upload step. There is no vendor tenant holding the transcript, no vendor administrator with theoretical access, and no third-party record to be subpoenaed.

This architecture is not a fit for every workflow. It requires capable hardware, it does not integrate with a firm's Teams governance in the way Copilot does, and it puts responsibility for backup and retention on the individual attorney or the firm's own systems. For matters where the marginal confidentiality value is high, though, it is a meaningfully different posture.

If you are weighing options across the market, our Basil for Law pillar page walks through how an on-device architecture maps to the confidentiality analysis under Rule 1.6 and the recent ethics guidance.

How Basil Approaches This

Basil is built on a single architectural choice: audio, transcription, and summaries are processed on-device using the Apple Neural Engine. Nothing is uploaded. There is no Basil server that receives client content, and there are no subprocessors in the AI path. For virtual meetings on Teams, Zoom, or Meet, Basil captures on-device in Computer mode, so no bot joins the call and no third-party service holds the recording.

The general Basil app is available today with a free tier of 60 minutes per month. The Basil for Law edition, which adds privilege attestation, a consent log, matter organization, and Privileged & Confidential labeling, launches in August 2026 at $19.99 per month or $199.99 per year for solo attorneys, with a 3-day trial on monthly and a 7-day trial on annual. Basil signs DPAs and NDAs on request.

None of this eliminates a lawyer's judgment. It changes the architecture that judgment is exercised on top of. For a fuller comparison, see our writeup on Basil for Law.

This article is for information only and is not legal advice.

Frequently asked questions

Does Microsoft train its AI models on my Teams meeting content when I use Copilot?

Microsoft states in its Copilot for Microsoft 365 documentation that prompts, responses, and data accessed through Microsoft Graph are not used to train the foundation models when Copilot is used within a Microsoft 365 tenant. That commitment is contractual and applies to enterprise use, but the transcripts and Copilot chat logs still exist in the tenant and are governed by whatever retention and access controls the firm configures.

Is a Teams meeting transcript generated by Copilot privileged?

Privilege attaches to communications, not to the medium that records them. A transcript of a privileged conversation is generally covered by the same privilege as the underlying conversation, but the presence of a third-party AI service in the data path, and the presence of any non-privileged third-party attendees in the meeting, can complicate the analysis. Recent authorities including U.S. v. Heppner illustrate that courts are beginning to scrutinize AI data flows in privilege disputes.

Do I need client consent to use Copilot on a call with the client?

ABA Formal Opinion 512 and NYC Bar Formal Opinion 2025-6 both point toward obtaining informed client consent when client information will be processed by a generative AI tool, particularly where the tool involves a third-party vendor holding client content. The safer practice is to disclose, obtain consent, and document it in the file.

How is Copilot in Teams different from a bot-based notetaker like Otter or Fireflies?

Copilot runs natively inside Microsoft's own infrastructure under the customer's tenant, so no external bot joins the call. Third-party notetakers typically join as a participant and route audio to their own cloud. Both approaches involve a third-party data holder, but the contractual, retention, and access controls differ. The Brewer v. Otter.ai litigation is a reminder that bot-based tools face their own set of consent and capture questions.

Can Copilot transcripts be subpoenaed from Microsoft?

Content stored in a Microsoft 365 tenant is potentially subject to lawful process served on Microsoft, subject to the Stored Communications Act and Microsoft's own challenge posture. In practice, most legal process for tenant content is served on the customer, not on Microsoft, but the surface area exists. A tool that stores no content with a third party removes that surface area.

Is there a way to get AI meeting notes without sending client data to a cloud vendor?

Yes. On-device notetakers process audio and generate summaries locally on the lawyer's own machine, with no upload. Basil is built on this architecture, using the Apple Neural Engine on macOS. It is not a fit for every workflow, but it is a materially different posture for matters where the confidentiality analysis is tight.

Keep client conversations on your device

Basil transcribes and summarizes entirely on-device โ€” no cloud, no bot, no server to subpoena. See Basil for Law โ†’ ยท Legal-tool reviews โ†’

This article is for information only and is not legal advice.