Best AI Meeting Assistant for Lawyers and Solo Attorneys: Attorney-Client Privilege in the AI Era

Published September 13, 2026

Key takeaways

Quick answer: The best AI meeting assistant for lawyers is one that never sends client audio to a vendor cloud. On-device transcription (like Basil AI) avoids the privilege, subpoena, and vendor-breach exposure that cloud tools like Otter.ai, Fireflies, and Zoom AI Companion create. Evaluate every tool on four axes: processing location, retention default, model-training use, and DPA scope — then measure against ABA Formal Opinion 512.

September 13, 2026 · 11 min read · Legal & Compliance

If you are a lawyer or solo attorney searching for the best AI meeting assistant in 2026, the honest answer has changed in the last twelve months. It is no longer about which tool has the cleanest summary or the smoothest Zoom integration. It is about which tool does not turn every privileged client conversation into a third-party data asset — one that can be subpoenaed, breached, or, as recent litigation now alleges, used to train a vendor's models. This guide walks through the ethics rules that changed the calculus, the litigation that made the risk concrete, and the specific criteria a legal buyer should apply before installing any notetaker.

Why the "best AI notetaker for lawyers" question is different in 2026

For most professions, choosing an AI notetaker is a productivity decision. For lawyers, it is an ethics decision and, increasingly, a litigation-risk decision. Three developments in 2024–2026 permanently changed the buyer analysis.

First, on July 29, 2024, the American Bar Association issued its first formal ethics opinion on generative AI. ABA Formal Opinion 512 tells lawyers that when they use generative AI tools they must "fully consider their applicable ethical obligations," including duties of competence, confidentiality, client communication, and reasonable fees. It is not binding law, but state bars in California, Florida, New Jersey, New York, and Pennsylvania have issued substantially similar guidance, and disciplinary counsel now treat Opinion 512 as a benchmark.

Second, the plaintiffs' bar started testing wiretap theories against AI notetakers. As Morrison & Foerster summarized in early 2026, plaintiffs in In re Otter.AI Privacy Litigation allege that Otter unlawfully intercepted meeting participants' communications by capturing their voices, storing the recordings, and using them to train AI models without the consent of all parties.

Third — and this is the one that changed procurement calendars — on August 13, 2026, a federal judge in the Northern District of California let the core claims against Otter proceed past a motion to dismiss. That single ruling reframed AI notetakers from productivity software to litigation exposure.

The August 13, 2026 Otter ruling and what it means for law firms

According to Recording Law's analysis of the ruling, the federal Wiretap Act claim survived because the court held that the statute's "party exception" could fall away where plaintiffs allege Otter "tortiously used their conversational data without their knowledge or consent to train its 'machine learning systems for its own pecuniary gain.'" The California Invasion of Privacy Act section 631 claim survived for all three California plaintiffs.

The practical takeaway for legal buyers is more important than the doctrinal one. As the analysis Humla published on the ruling put it, wiretap claims proceeded not because a bot joined a call, but because the vendor independently collects, retains, and uses conversations for its own commercial purposes. That distinction matters because eleven days earlier, Granola — a bot-free tool that captures audio directly on the user's laptop — was sued on essentially the same theory. The bot was never the real problem. The vendor's independent use of the recording was.

For a law firm, this means the traditional "just don't let the bot in" heuristic no longer protects you. What matters is where the audio goes after capture. If it leaves the attorney's device for a vendor's servers, every downstream use of that audio is arguably a third-party act on privileged material.

Why this matters more for solo and small-firm attorneys

Solo and small-firm attorneys often make individual tool decisions without a procurement team or a general counsel to backstop them. The result, documented across multiple HR Executive and industry analyses, is that consumer AI notetakers enter law firms through individual sign-ups, not vendor evaluations. That shadow-IT path — sign up with a work email, click through the terms, hit record on the next client call — is exactly what turned the Otter litigation into a class action worth watching.

What ABA Formal Opinion 512 actually requires

Opinion 512 organizes ethical duties around six existing Model Rules. For AI meeting tools specifically, the three that bite hardest are:

Formal Opinion 512 covers six key areas where generative AI use intersects with existing ethical duties: competence, confidentiality, communication with clients, supervision, candor toward the tribunal, and fees. Every one of those touches AI meeting notes. Confidentiality is the sharpest edge — a tool that stores verbatim transcripts of privileged conversations on a vendor server has already made the disclosure that Rule 1.6 asks you to think twice about.

The four criteria that actually matter for legal buyers

Cut through the vendor marketing. Every AI meeting tool should be evaluated on the same four dimensions, in this order:

1. Processing location

Where does the audio actually get transcribed? A cloud vendor's servers, or the attorney's device? This is the single most consequential answer because it determines the entire downstream risk surface — subpoena exposure, breach exposure, subprocessor sprawl, DPA complexity.

2. Retention default

What happens to audio and transcripts by default? Many cloud notetakers retain both indefinitely unless an admin changes a setting. Otter.ai's privacy policy illustrates the norm: broad retention rights, broad use rights, and configuration burdens placed on the customer.

3. Model-training use

Are your conversations used to train the vendor's models? The Otter and Granola complaints allege this happens by default in many tools. A no-training contractual commitment is table stakes for legal work — and it should cover not just transcripts but audio and derived embeddings too.

4. DPA scope

Is there a Data Processing Agreement, and what does it actually commit? Named subprocessors, change notification, breach timelines, deletion rights, and data residency all belong in a legal-grade DPA. Marketing pages don't count.

Cloud vs on-device: the comparison that decides most legal procurements

Here's how the two dominant architectures compare across the criteria that matter to a law firm buyer:

Criterion Cloud AI notetaker (Otter, Fireflies, Zoom AI Companion) On-device notetaker (Basil AI)
Where audio is processedVendor cloud serversAttorney's Mac or iPhone
Third-party copy of privileged audioYes — created at ingestionNo vendor server holds the recording
Default retentionOften indefinite unless changedAttorney controls; deletes with the file
Model training on your audioContested in current litigationNot possible — audio never leaves device
Subpoena / discovery surfaceVendor can be subpoenaed for contentNo vendor holds the content to produce
Works without internetNoYes — fully offline
Compliance postureSOC 2 + DPA covers controls, not architectureArchitecture removes the third party; firm's CCO/GC still determines fit

The critical row is the second one. Cloud transcription creates a third-party copy of privileged audio at the moment of ingestion. That copy is what plaintiffs are litigating over, what future subpoenas can reach, and what vendor breaches will expose. On-device processing simply never creates it.

Does SOC 2 Type II solve the problem?

SOC 2 Type II is the enterprise procurement baseline for cloud vendors and, increasingly, it is a hard gate for law firm procurement teams. As Layer9's SOC 2 checklist for law firms puts it, buyers should demand the Type II report, encryption in transit and at rest, documented access controls, data residency answers, and "a contractual guarantee that your proprietary data will never be used to train their foundational models."

That is a good checklist. It is also incomplete for legal work. SOC 2 attests that a vendor's controls operate effectively — it does not eliminate the vendor's server itself. If the underlying architecture requires shipping client audio to a third party, SOC 2 makes that shipment better-controlled but not absent. On-device tools sidestep that question entirely.

The HAQQ 45-point evaluation framework for legal AI vendors makes a similar point: missing SOC 2 or ISO 27001 is a red flag, but reliance on subprocessor certifications rather than the vendor's own controls is a bigger one. The deeper a cloud stack goes, the more parties end up handling privileged material.

Consent, CIPA, and the states where the risk is highest

Federal wiretap law needs only one-party consent, so the attorney recording can technically be that party under federal law alone. But roughly a dozen states — including California, Illinois, Florida, Pennsylvania, Massachusetts, and Washington — require all-party consent, and the penalties are meaningful: California's Invasion of Privacy Act carries $5,000 per violation, and Pennsylvania treats unlawful recording as a felony punishable by up to seven years.

The consent obligation sits with the person running the meeting, not the software vendor. If you are a California-licensed attorney on a call with an out-of-state client and an in-state witness, an AI notetaker that captures without announcing itself is your exposure, not the vendor's. This is one of the reasons a bot-based tool that visibly joins a Zoom call is sometimes cleaner than a silent botless capture — but only when consent is explicitly obtained on the record.

For deeper background on how these consent regimes are colliding with the AI notetaker business model, see our earlier analysis of the Otter.ai August 13 ruling and vendor-as-eavesdropper theory and the underlying CIPA and phone-interception theories now being tested in federal court.

Bot-based vs bot-free vs on-device: which does what

There are three capture models in the market. Each has legal trade-offs.

Bot-based cloud tools (Otter, Fireflies, Zoom AI Companion). A visible bot joins the call, captures audio and video, and processes everything in the vendor's cloud. As Shadow's bot-free legal picks point out, deposition prep, client intake, and matter strategy calls generally should not have "Otter.ai Notetaker has joined" on the participant list — even when consent is technically obtained, a visible third-party participant raises privilege concerns and puts audio on a vendor cloud nobody in the firm vetted.

Bot-free cloud tools (Granola, and increasingly Fathom's bot-free mode). No bot appears in the call, but audio is still captured from the desktop and typically shipped to a vendor cloud for transcription. The August 2026 Granola suit shows this architecture faces the same wiretap theory as bot-based tools.

On-device tools (Basil AI). Audio is captured and transcribed on the attorney's Mac or iPhone using Apple's built-in speech frameworks. Nothing goes to a vendor server unless the attorney explicitly exports it. This is the only architecture that eliminates the third-party copy problem at the source.

How Basil AI solves this for lawyers and solo attorneys

Basil AI is a fully on-device AI meeting recorder for Mac and iPhone. The architecture matters more than any feature comparison:

To be clear about what Basil AI is and is not: on-device processing is an architecture fact, not a compliance guarantee. It removes the third-party server. It does not remove the attorney's independent obligations under Rule 1.6, ABA Formal Opinion 512, or state all-party consent statutes. The firm's general counsel or ethics partner still owns the compliance determination. What on-device processing does is shrink the surface area those obligations have to cover — from a shared cloud stack to a single device the attorney already owns.

For a deeper technical walkthrough of the underlying platform, see how iOS 26's SpeechAnalyzer powers on-device transcription, and for a workflow-oriented comparison against cloud alternatives, see the bot vs bot-free vs on-device breakdown.

What to do Monday morning: a practical checklist for solo attorneys and small firms

If you are a solo attorney or small-firm partner and you already have an AI notetaker installed, here is the concrete sequence:

  1. Inventory. List every AI meeting tool currently installed on firm devices — including personal accounts used for firm calls. Consumer sign-ups are the shadow-IT path most law firm evaluations miss.
  2. Check training defaults. Log into each tool and confirm whether meeting content is used to improve the vendor's models. If the toggle is on, turn it off — and check whether the setting applies retroactively.
  3. Read the retention policy. Confirm the default retention window for audio and transcripts. Change it to the minimum the tool allows.
  4. Update engagement letters. If you use AI meeting tools on client matters, disclose it in your engagement letter and get written client consent. Formal Opinion 512 makes this a competence-and-communication issue.
  5. Segment by matter sensitivity. If you retain a cloud tool for non-privileged operations meetings — vendor calls, firm admin, CLEs — that is defensible. Use an on-device tool for anything privileged.
  6. Verify all-party consent. In every meeting, if any participant is in an all-party state (California, Illinois, Florida, Pennsylvania, Massachusetts, Washington and others), get explicit consent on the record before recording.

The bottom line for lawyers evaluating AI meeting tools

The best AI meeting assistant for a lawyer or solo attorney in 2026 is not the one with the smartest summaries. It is the one that never turns a privileged conversation into a vendor's data asset. The Otter litigation, the Granola suit, and ABA Formal Opinion 512 have converged on the same conclusion: architecture matters more than marketing. On-device processing is the only capture model that eliminates the third-party server at the source. Cloud tools with SOC 2 and no-training DPAs can be defensible for non-privileged work. For depositions, intake, matter strategy, and any conversation you would not want the vendor's litigation team to read three years from now, the answer is local capture.

Try Basil AI — the on-device AI meeting recorder built for privileged work

100% on-device transcription. No cloud servers. No training on your audio. Your client conversations never leave your Mac or iPhone.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

Does using an AI notetaker waive attorney-client privilege?

Not automatically, but it can. Privilege depends on whether a third party is present and the firm's intent. When a cloud AI vendor independently retains, processes, or uses the audio for its own purposes — as plaintiffs allege in the Otter.ai litigation — that vendor arguably becomes a third-party listener. On-device processing keeps the transcript inside the attorney's device, closing that gap.

Is Otter.ai safe for law firms?

In August 2026, a federal judge let core wiretap and California Invasion of Privacy Act claims against Otter proceed past a motion to dismiss. Otter's own terms allow use of content to improve the service. For privileged client work — depositions, intake, matter strategy — most legal-tech analysts now recommend against Otter's consumer tiers and toward tools that never transmit audio to a vendor server.

What does ABA Formal Opinion 512 say about AI meeting tools?

Formal Opinion 512, issued July 29, 2024, tells lawyers that Model Rules on competence (1.1), confidentiality (1.6), communication (1.4), supervision (5.1/5.3), candor (3.3), and fees (1.5) all apply to generative AI. Lawyers must understand how a tool processes and retains client data before using it, and get informed consent when confidential information will be disclosed to a third party.

Do I need SOC 2 Type II for an AI notetaker used in legal work?

SOC 2 Type II is the enterprise procurement baseline for cloud vendors handling client data, and many firms make it a gate. But SOC 2 attests to controls — it does not eliminate the third-party server itself. A tool that processes audio entirely on the attorney's device sidesteps the underlying vendor-server question that SOC 2 controls are trying to mitigate.

Can a solo attorney legally use an AI notetaker in California?

California is an all-party consent state under Penal Code §632 (CIPA), carrying $5,000 per violation. Every meeting participant must consent before recording. That obligation sits with the attorney, not the vendor. A bot that joins silently — or a botless tool that never announces itself — creates exposure regardless of how strong the vendor's privacy policy is.

What should be in an AI notetaker DPA for a law firm?

At minimum: (1) explicit no-training clause covering audio, transcripts, and derived embeddings; (2) named subprocessors with change notification; (3) data residency; (4) configurable retention with default off; (5) breach notification timelines; (6) audit and deletion rights. If a vendor cannot commit to these in writing, the tool is not procurement-ready for privileged work.