Best AI Meeting Assistant for Lawyers and Solo Attorneys: Attorney-Client Privilege in the AI Era
Published September 13, 2026
- The August 13, 2026 Otter.ai ruling let wiretap and CIPA claims proceed — cloud AI notetakers are now an active legal risk for firms, not a theoretical one.
- ABA Formal Opinion 512 makes competence, confidentiality, and informed consent about AI tools an ethical obligation, not a best practice.
- SOC 2 Type II and no-training DPAs help, but on-device processing is the only architecture that eliminates the third-party server entirely.
- Evaluate every AI meeting tool on four axes: processing location, retention default, training-data use, and DPA scope — not marketing claims.
- For depositions, intake, and matter strategy, choose bot-free, on-device capture. Save cloud tools (if any) for non-privileged operations work.
Quick answer: The best AI meeting assistant for lawyers is one that never sends client audio to a vendor cloud. On-device transcription (like Basil AI) avoids the privilege, subpoena, and vendor-breach exposure that cloud tools like Otter.ai, Fireflies, and Zoom AI Companion create. Evaluate every tool on four axes: processing location, retention default, model-training use, and DPA scope — then measure against ABA Formal Opinion 512.
If you are a lawyer or solo attorney searching for the best AI meeting assistant in 2026, the honest answer has changed in the last twelve months. It is no longer about which tool has the cleanest summary or the smoothest Zoom integration. It is about which tool does not turn every privileged client conversation into a third-party data asset — one that can be subpoenaed, breached, or, as recent litigation now alleges, used to train a vendor's models. This guide walks through the ethics rules that changed the calculus, the litigation that made the risk concrete, and the specific criteria a legal buyer should apply before installing any notetaker.
Why the "best AI notetaker for lawyers" question is different in 2026
For most professions, choosing an AI notetaker is a productivity decision. For lawyers, it is an ethics decision and, increasingly, a litigation-risk decision. Three developments in 2024–2026 permanently changed the buyer analysis.
First, on July 29, 2024, the American Bar Association issued its first formal ethics opinion on generative AI. ABA Formal Opinion 512 tells lawyers that when they use generative AI tools they must "fully consider their applicable ethical obligations," including duties of competence, confidentiality, client communication, and reasonable fees. It is not binding law, but state bars in California, Florida, New Jersey, New York, and Pennsylvania have issued substantially similar guidance, and disciplinary counsel now treat Opinion 512 as a benchmark.
Second, the plaintiffs' bar started testing wiretap theories against AI notetakers. As Morrison & Foerster summarized in early 2026, plaintiffs in In re Otter.AI Privacy Litigation allege that Otter unlawfully intercepted meeting participants' communications by capturing their voices, storing the recordings, and using them to train AI models without the consent of all parties.
Third — and this is the one that changed procurement calendars — on August 13, 2026, a federal judge in the Northern District of California let the core claims against Otter proceed past a motion to dismiss. That single ruling reframed AI notetakers from productivity software to litigation exposure.
The August 13, 2026 Otter ruling and what it means for law firms
According to Recording Law's analysis of the ruling, the federal Wiretap Act claim survived because the court held that the statute's "party exception" could fall away where plaintiffs allege Otter "tortiously used their conversational data without their knowledge or consent to train its 'machine learning systems for its own pecuniary gain.'" The California Invasion of Privacy Act section 631 claim survived for all three California plaintiffs.
The practical takeaway for legal buyers is more important than the doctrinal one. As the analysis Humla published on the ruling put it, wiretap claims proceeded not because a bot joined a call, but because the vendor independently collects, retains, and uses conversations for its own commercial purposes. That distinction matters because eleven days earlier, Granola — a bot-free tool that captures audio directly on the user's laptop — was sued on essentially the same theory. The bot was never the real problem. The vendor's independent use of the recording was.
For a law firm, this means the traditional "just don't let the bot in" heuristic no longer protects you. What matters is where the audio goes after capture. If it leaves the attorney's device for a vendor's servers, every downstream use of that audio is arguably a third-party act on privileged material.
Why this matters more for solo and small-firm attorneys
Solo and small-firm attorneys often make individual tool decisions without a procurement team or a general counsel to backstop them. The result, documented across multiple HR Executive and industry analyses, is that consumer AI notetakers enter law firms through individual sign-ups, not vendor evaluations. That shadow-IT path — sign up with a work email, click through the terms, hit record on the next client call — is exactly what turned the Otter litigation into a class action worth watching.
What ABA Formal Opinion 512 actually requires
Opinion 512 organizes ethical duties around six existing Model Rules. For AI meeting tools specifically, the three that bite hardest are:
- Rule 1.1 (Competence) — a lawyer must reasonably understand the benefits and risks of technology they use, including how a GAI tool processes and retains data.
- Rule 1.6 (Confidentiality) — a lawyer must not reveal information relating to representation without informed consent. Sending client audio to a third-party vendor arguably "reveals" that information.
- Rule 1.4 (Communication) — clients may need to be informed that AI tools are being used on their matter, particularly where confidential information is at stake.
Formal Opinion 512 covers six key areas where generative AI use intersects with existing ethical duties: competence, confidentiality, communication with clients, supervision, candor toward the tribunal, and fees. Every one of those touches AI meeting notes. Confidentiality is the sharpest edge — a tool that stores verbatim transcripts of privileged conversations on a vendor server has already made the disclosure that Rule 1.6 asks you to think twice about.
The four criteria that actually matter for legal buyers
Cut through the vendor marketing. Every AI meeting tool should be evaluated on the same four dimensions, in this order:
1. Processing location
Where does the audio actually get transcribed? A cloud vendor's servers, or the attorney's device? This is the single most consequential answer because it determines the entire downstream risk surface — subpoena exposure, breach exposure, subprocessor sprawl, DPA complexity.
2. Retention default
What happens to audio and transcripts by default? Many cloud notetakers retain both indefinitely unless an admin changes a setting. Otter.ai's privacy policy illustrates the norm: broad retention rights, broad use rights, and configuration burdens placed on the customer.
3. Model-training use
Are your conversations used to train the vendor's models? The Otter and Granola complaints allege this happens by default in many tools. A no-training contractual commitment is table stakes for legal work — and it should cover not just transcripts but audio and derived embeddings too.
4. DPA scope
Is there a Data Processing Agreement, and what does it actually commit? Named subprocessors, change notification, breach timelines, deletion rights, and data residency all belong in a legal-grade DPA. Marketing pages don't count.
Cloud vs on-device: the comparison that decides most legal procurements
Here's how the two dominant architectures compare across the criteria that matter to a law firm buyer:
| Criterion | Cloud AI notetaker (Otter, Fireflies, Zoom AI Companion) | On-device notetaker (Basil AI) |
|---|---|---|
| Where audio is processed | Vendor cloud servers | Attorney's Mac or iPhone |
| Third-party copy of privileged audio | Yes — created at ingestion | No vendor server holds the recording |
| Default retention | Often indefinite unless changed | Attorney controls; deletes with the file |
| Model training on your audio | Contested in current litigation | Not possible — audio never leaves device |
| Subpoena / discovery surface | Vendor can be subpoenaed for content | No vendor holds the content to produce |
| Works without internet | No | Yes — fully offline |
| Compliance posture | SOC 2 + DPA covers controls, not architecture | Architecture removes the third party; firm's CCO/GC still determines fit |
The critical row is the second one. Cloud transcription creates a third-party copy of privileged audio at the moment of ingestion. That copy is what plaintiffs are litigating over, what future subpoenas can reach, and what vendor breaches will expose. On-device processing simply never creates it.
Does SOC 2 Type II solve the problem?
SOC 2 Type II is the enterprise procurement baseline for cloud vendors and, increasingly, it is a hard gate for law firm procurement teams. As Layer9's SOC 2 checklist for law firms puts it, buyers should demand the Type II report, encryption in transit and at rest, documented access controls, data residency answers, and "a contractual guarantee that your proprietary data will never be used to train their foundational models."
That is a good checklist. It is also incomplete for legal work. SOC 2 attests that a vendor's controls operate effectively — it does not eliminate the vendor's server itself. If the underlying architecture requires shipping client audio to a third party, SOC 2 makes that shipment better-controlled but not absent. On-device tools sidestep that question entirely.
The HAQQ 45-point evaluation framework for legal AI vendors makes a similar point: missing SOC 2 or ISO 27001 is a red flag, but reliance on subprocessor certifications rather than the vendor's own controls is a bigger one. The deeper a cloud stack goes, the more parties end up handling privileged material.
Consent, CIPA, and the states where the risk is highest
Federal wiretap law needs only one-party consent, so the attorney recording can technically be that party under federal law alone. But roughly a dozen states — including California, Illinois, Florida, Pennsylvania, Massachusetts, and Washington — require all-party consent, and the penalties are meaningful: California's Invasion of Privacy Act carries $5,000 per violation, and Pennsylvania treats unlawful recording as a felony punishable by up to seven years.
The consent obligation sits with the person running the meeting, not the software vendor. If you are a California-licensed attorney on a call with an out-of-state client and an in-state witness, an AI notetaker that captures without announcing itself is your exposure, not the vendor's. This is one of the reasons a bot-based tool that visibly joins a Zoom call is sometimes cleaner than a silent botless capture — but only when consent is explicitly obtained on the record.
For deeper background on how these consent regimes are colliding with the AI notetaker business model, see our earlier analysis of the Otter.ai August 13 ruling and vendor-as-eavesdropper theory and the underlying CIPA and phone-interception theories now being tested in federal court.
Bot-based vs bot-free vs on-device: which does what
There are three capture models in the market. Each has legal trade-offs.
Bot-based cloud tools (Otter, Fireflies, Zoom AI Companion). A visible bot joins the call, captures audio and video, and processes everything in the vendor's cloud. As Shadow's bot-free legal picks point out, deposition prep, client intake, and matter strategy calls generally should not have "Otter.ai Notetaker has joined" on the participant list — even when consent is technically obtained, a visible third-party participant raises privilege concerns and puts audio on a vendor cloud nobody in the firm vetted.
Bot-free cloud tools (Granola, and increasingly Fathom's bot-free mode). No bot appears in the call, but audio is still captured from the desktop and typically shipped to a vendor cloud for transcription. The August 2026 Granola suit shows this architecture faces the same wiretap theory as bot-based tools.
On-device tools (Basil AI). Audio is captured and transcribed on the attorney's Mac or iPhone using Apple's built-in speech frameworks. Nothing goes to a vendor server unless the attorney explicitly exports it. This is the only architecture that eliminates the third-party copy problem at the source.
How Basil AI solves this for lawyers and solo attorneys
Basil AI is a fully on-device AI meeting recorder for Mac and iPhone. The architecture matters more than any feature comparison:
- Local capture. Audio never leaves the device. Transcription happens on the Apple Neural Engine using Apple's Speech framework, the same on-device engine Apple's privacy program is built around.
- No vendor server. There is no Basil cloud holding your client recordings to subpoena or breach. The third-party-copy problem simply does not exist.
- No training on your data. Because we never receive your audio, we cannot train on it — and cannot be sued for having done so.
- Attorney controls retention. Files live on the attorney's device. Delete the file, and the record is gone; there is no vendor mirror to worry about.
- Works offline. Confidential conversations in a courthouse hallway, a client's kitchen, or an airplane still get captured — no internet required.
To be clear about what Basil AI is and is not: on-device processing is an architecture fact, not a compliance guarantee. It removes the third-party server. It does not remove the attorney's independent obligations under Rule 1.6, ABA Formal Opinion 512, or state all-party consent statutes. The firm's general counsel or ethics partner still owns the compliance determination. What on-device processing does is shrink the surface area those obligations have to cover — from a shared cloud stack to a single device the attorney already owns.
For a deeper technical walkthrough of the underlying platform, see how iOS 26's SpeechAnalyzer powers on-device transcription, and for a workflow-oriented comparison against cloud alternatives, see the bot vs bot-free vs on-device breakdown.
What to do Monday morning: a practical checklist for solo attorneys and small firms
If you are a solo attorney or small-firm partner and you already have an AI notetaker installed, here is the concrete sequence:
- Inventory. List every AI meeting tool currently installed on firm devices — including personal accounts used for firm calls. Consumer sign-ups are the shadow-IT path most law firm evaluations miss.
- Check training defaults. Log into each tool and confirm whether meeting content is used to improve the vendor's models. If the toggle is on, turn it off — and check whether the setting applies retroactively.
- Read the retention policy. Confirm the default retention window for audio and transcripts. Change it to the minimum the tool allows.
- Update engagement letters. If you use AI meeting tools on client matters, disclose it in your engagement letter and get written client consent. Formal Opinion 512 makes this a competence-and-communication issue.
- Segment by matter sensitivity. If you retain a cloud tool for non-privileged operations meetings — vendor calls, firm admin, CLEs — that is defensible. Use an on-device tool for anything privileged.
- Verify all-party consent. In every meeting, if any participant is in an all-party state (California, Illinois, Florida, Pennsylvania, Massachusetts, Washington and others), get explicit consent on the record before recording.
The bottom line for lawyers evaluating AI meeting tools
The best AI meeting assistant for a lawyer or solo attorney in 2026 is not the one with the smartest summaries. It is the one that never turns a privileged conversation into a vendor's data asset. The Otter litigation, the Granola suit, and ABA Formal Opinion 512 have converged on the same conclusion: architecture matters more than marketing. On-device processing is the only capture model that eliminates the third-party server at the source. Cloud tools with SOC 2 and no-training DPAs can be defensible for non-privileged work. For depositions, intake, matter strategy, and any conversation you would not want the vendor's litigation team to read three years from now, the answer is local capture.
Try Basil AI — the on-device AI meeting recorder built for privileged work
100% on-device transcription. No cloud servers. No training on your audio. Your client conversations never leave your Mac or iPhone.
Frequently Asked Questions
Does using an AI notetaker waive attorney-client privilege?
Not automatically, but it can. Privilege depends on whether a third party is present and the firm's intent. When a cloud AI vendor independently retains, processes, or uses the audio for its own purposes — as plaintiffs allege in the Otter.ai litigation — that vendor arguably becomes a third-party listener. On-device processing keeps the transcript inside the attorney's device, closing that gap.
Is Otter.ai safe for law firms?
In August 2026, a federal judge let core wiretap and California Invasion of Privacy Act claims against Otter proceed past a motion to dismiss. Otter's own terms allow use of content to improve the service. For privileged client work — depositions, intake, matter strategy — most legal-tech analysts now recommend against Otter's consumer tiers and toward tools that never transmit audio to a vendor server.
What does ABA Formal Opinion 512 say about AI meeting tools?
Formal Opinion 512, issued July 29, 2024, tells lawyers that Model Rules on competence (1.1), confidentiality (1.6), communication (1.4), supervision (5.1/5.3), candor (3.3), and fees (1.5) all apply to generative AI. Lawyers must understand how a tool processes and retains client data before using it, and get informed consent when confidential information will be disclosed to a third party.
Do I need SOC 2 Type II for an AI notetaker used in legal work?
SOC 2 Type II is the enterprise procurement baseline for cloud vendors handling client data, and many firms make it a gate. But SOC 2 attests to controls — it does not eliminate the third-party server itself. A tool that processes audio entirely on the attorney's device sidesteps the underlying vendor-server question that SOC 2 controls are trying to mitigate.
Can a solo attorney legally use an AI notetaker in California?
California is an all-party consent state under Penal Code §632 (CIPA), carrying $5,000 per violation. Every meeting participant must consent before recording. That obligation sits with the attorney, not the vendor. A bot that joins silently — or a botless tool that never announces itself — creates exposure regardless of how strong the vendor's privacy policy is.
What should be in an AI notetaker DPA for a law firm?
At minimum: (1) explicit no-training clause covering audio, transcripts, and derived embeddings; (2) named subprocessors with change notification; (3) data residency; (4) configurable retention with default off; (5) breach notification timelines; (6) audit and deletion rights. If a vendor cannot commit to these in writing, the tool is not procurement-ready for privileged work.