AI Notetakers for Lawyers: What Works for Client Intake, Depositions, and Privileged Calls

Published October 09, 2026

Key takeaways

Quick answer: For privileged client meetings, lawyers should avoid cloud notetakers whose terms let the vendor retain, train on, or disclose inputs — a federal court held in United States v. Heppner (S.D.N.Y., Feb. 2026) that such use can waive privilege. Safer options are fully on-device tools (like Basil AI on iPhone/Mac) paired with written client consent, per NYC Bar Formal Opinion 2026-2 and ABA Formal Opinion 512.

Published October 9, 2026 · Buyer Intent · Legal Technology

On February 10, 2026, Judge Jed S. Rakoff of the Southern District of New York issued the first federal ruling of its kind: documents a criminal defendant had generated using a consumer AI tool, and later shared with his attorneys, were not protected by attorney-client privilege or the work-product doctrine. The decision in United States v. Heppner turned on a boring but devastating fact — the tool's terms let the vendor retain inputs and disclose them in response to legal process — which the court treated as sharing privileged material with a third party. For lawyers evaluating an AI notetaker for client intake, depositions, or any privileged call, Heppner is now the baseline test every vendor has to pass.

This guide is written for solo attorneys and small-firm lawyers who already use (or are about to use) an AI meeting notetaker. We'll map the three practice contexts that matter most — intake, depositions, and privileged client calls — against the architecture of the leading tools, the ABA's Formal Opinion 512, and NYC Bar Formal Opinion 2026-2. The goal is a clean, defensible answer to the question your malpractice carrier is about to start asking: which AI tool, in which room, with what consent?

Why the Standard Shifted in 2026

Three things changed the risk calculus for lawyers using AI notetakers this year, and all three happened within six months.

First, the Heppner ruling. According to the Chapman and Cutler analysis of the case (docket 25-cr-00503-JSR), Judge Rakoff found that communications with public AI tools may not satisfy the attorney-client privilege because the tools are not attorneys, do not provide legal advice, and the inputs are not confidential. The BakerHostetler summary adds the crucial point: simply forwarding the AI's output to counsel does not retroactively cloak the materials with privilege.

Second, the NYC Bar's two-opinion sequence on AI recording. The 2Civility summary of NYC Bar Formal Opinion 2025-6 is blunt: an attorney should not secretly activate an AI notetaker during a client conversation, and informed consent is required before recording. Formal Opinion 2026-2 extended the same logic to non-client calls and recommended that lawyers avoid recording as a default practice absent a good reason.

Third, the architecture of the tools themselves became an issue. As our complete guide to bot-free notetakers documented, "bot-free" is not the same as "on-device" — Granola captures audio locally but still ships transcripts to an AWS Virtual Private Cloud for processing, which puts a vendor back in the chain of custody. That matters because the specific thing that killed privilege in Heppner was the vendor's ability to retain and disclose inputs.

The Three Practice Contexts, and What Each Demands

Not every lawyer-client interaction has the same risk profile. The practical question is which tool fits which room.

1. Client Intake

Intake is where most firms want AI help the most — a 45-minute consult turning into a clean matter summary, conflicts check, and engagement letter draft. It is also the most sensitive conversation in the entire representation, because everything said is presumptively covered by prospective-client confidentiality under Model Rule 1.18. The ABA's own summary of Opinion 512 notes that confidentiality duties under Rule 1.6 extend to prospective and former clients via Rules 1.18(b) and 1.9(c).

What this means in practice: if your intake notetaker uploads audio or transcripts to a vendor cloud, that vendor is in the chain of custody for information you may ultimately be unable to represent on. The on-device alternative keeps the audio off any server you don't control.

2. Depositions

Depositions are different. There's already a certified stenographic record, so an AI notetaker is a work-product aid, not the record. The relevant risks are (a) duplicate recording consent under state wiretap statutes and (b) the chain of custody for your own notes if they later get subpoenaed. The Harris Beach Murtha analysis of Heppner explains the pattern: non-privileged materials do not become privileged merely because they are later shared with counsel, so an AI-generated deposition summary that lived in a vendor cloud may be fair game for discovery.

3. Ongoing Privileged Client Calls

This is the daily reality — the strategy call, the settlement discussion, the Zoom with the general counsel. These are the calls where Heppner hits hardest. The STACK Cybersecurity breakdown of the ruling notes that the court found "not remotely any basis" for a privilege claim once the vendor's terms allowed retention and disclosure. Any tool that joins the call as a visible bot, or that uploads the transcript to a cloud whose terms let the vendor process it, inherits that exact risk.

The Honest Vendor Scorecard

Here's how the leading tools actually sit against the three practice contexts, based on their own policies and architecture.

Tool Capture Where audio/transcript lives Vendor can retain/train on inputs? Fit for privileged calls
Otter.ai Bot joins call Otter cloud Per Otter.ai privacy policy, broad processing rights Poor — visible bot, vendor cloud
Fireflies.ai Bot joins call Fireflies cloud Per Fireflies privacy policy, cloud storage & integrations Poor — visible bot, vendor cloud
Zoom AI Companion Native in call Zoom cloud Per Zoom privacy statement, processed by Zoom Poor — vendor in chain of custody
Granola (bot-free) System audio, no bot Transcript uploaded to AWS VPC (US) Varies; vendors in processing chain include OpenAI/Anthropic/Deepgram Weak — no bot, but vendor cloud remains
Rev (human-reviewed) Upload Rev cloud; human transcribers Humans see audio Poor for privileged content
Basil AI Device microphone, no bot Device + your iCloud only No vendor server ever receives audio or transcript Strong — no third-party chain of custody

The column that matters for Heppner is the third one. The ruling turned on whether the vendor's position in the chain made the input a third-party disclosure. For a bot-based or cloud-processed tool, it does.

What NYC Bar Formal Opinion 2026-2 Actually Requires

Opinion 2026-2 — the sequel to 2025-6, now covering non-client calls — is the single most important document for any lawyer picking an AI notetaker right now. According to the official opinion text, the committee concluded that an attorney should obtain consent of all other parties to a call before recording, should consider whether recording is tactically well-advised, and should default to not recording absent a good reason.

For client-facing calls, the MyShingle Ethics Opinion 2026-2 analysis flags an additional wrinkle: undisclosed recording is deceptive under Rule 8.4 and inconsistent with the duty of loyalty — even if only a summary is ultimately retained — because clients speak differently when a verbatim record is being made. The ethical floor is not "delete the audio afterward." It is "get consent first, understand where the data flows, and explain it in terms the client actually comprehends."

What ABA Formal Opinion 512 Requires

The ABA's Formal Opinion 512, issued July 29, 2024, remains the anchor document. Six duties apply.

Rule 1.6 is the one that forces the architectural question. If you can't answer "where does the audio go and who processes it," you can't satisfy Rule 1.6 with a straight face.

The Six Questions to Put to Any Vendor Before Procurement

Copy-paste these into your vendor questionnaire. If a vendor can't answer in writing, that is itself the answer.

  1. Where is the audio processed — on my device, on your servers, or on a sub-processor's servers (OpenAI, Anthropic, Deepgram, AssemblyAI, AWS)?
  2. What is the retention policy for audio, transcripts, and summaries, and how do I prove deletion on request?
  3. Do you use any customer input — audio, transcript, or summary — to train or improve any model, including sub-processors' models?
  4. What happens on a subpoena? Will you contest? Will you notify me before producing?
  5. What is your SOC 2 / ISO 27001 / HITRUST status, and when was the most recent audit?
  6. Do you offer a DPA with contractual guarantees that match the above, and is it signable at my firm's size?

For a bot-based cloud tool, the answers to #1 and #3 will usually disqualify the tool for privileged work no matter how good the DPA is. The exposure the Heppner court cared about was not the DPA — it was the fact that the vendor was in the chain at all.

The Consent Script That Actually Works

Both the NYC Bar and the ABA agree that consent must be specific. Here is a template that satisfies both opinions when you are using an on-device tool like Basil AI:

"To take better notes, I'd like to use an AI transcription app on my iPhone/Mac during our calls. The app runs entirely on my device — Apple's on-device speech framework handles the transcription locally, so no vendor server ever receives our conversation. I'll keep the transcript on my device and in my firm's iCloud, retain it for the life of the matter plus seven years, and delete it on your request. Does that work for you? If you'd rather I not record, I'll take written notes instead."

For a cloud tool, the honest version of the same script has to name the vendor, name the sub-processors, and admit that a vendor server will hold the recording. Clients who understand the difference tend to prefer the first version.

Depositions: A Narrower, More Specific Workflow

The North Carolina Bar's analysis of multi-party AI recording identifies the specific risk: a lawyer-side AI summary of a deposition becomes a non-privileged document that a vendor holds and that opposing counsel can subpoena from the vendor. The deposition itself is on the record; your summary is work product only if you can keep it in confidence.

Practically, this argues for one of two patterns. Either use the certified transcript the court reporter will deliver (and nothing else), or use an on-device tool so that any AI-assisted summary lives on your device and inherits normal work-product protections. Avoid the middle ground where a vendor cloud holds the only AI-enhanced version — that is the posture Heppner explicitly rejected.

How Basil AI Solves This

Basil AI is built for the exact scenario this article is about: a lawyer who wants real transcription, action items, and summaries for client meetings without putting a vendor in the chain of custody.

The architecture is simple. Audio is captured by the device microphone (or Mac system audio). Transcription runs locally via Apple's iOS 26 Speech framework, specifically the new SpeechAnalyzer / SpeechTranscriber modules. Summaries are generated by Apple Foundation Models on-device. Nothing routes through Basil's servers, OpenAI, Anthropic, Deepgram, or AssemblyAI. The transcript lives on the device and, if the user chooses, in the user's own iCloud via Apple Notes integration.

In Heppner terms, there is no third-party vendor to "share" with — a design that aligns with the specific defect the court identified in consumer cloud AI tools. For deeper detail on the architecture, see our breakdown of why bot-free isn't the same as on-device and our analysis of the Heppner / Warner privilege split.

This is an architecture claim, not a legal-ethics guarantee. Whether a specific use of Basil AI meets your state bar's rules is still your call — but the one question that was fatal in Heppner ("did a vendor get the inputs?") has a straight answer: no.

A Decision Matrix for the Three Rooms

Context Default answer Why
New-client intake call On-device only (Basil AI) + written consent Prospective-client confidentiality under Rule 1.18 is maximal; vendor in chain = disqualifying
Standing privileged client call (strategy, settlement) On-device only (Basil AI) + consent recorded in engagement letter addendum Heppner directly on point; cloud/bot tools create third-party exposure
Deposition Rely on certified transcript; if AI used, on-device only for personal work product Avoid vendor-held AI summaries that could be subpoenaed
Opposing counsel / negotiation call (non-privileged) Consent of all parties required; on-device still preferred NYC Bar 2026-2 requires all-party consent; architecture reduces downstream risk
Internal firm meeting Any tool with firm-approved DPA No client confidentiality duty if no client content discussed

What This Means for Your Malpractice Carrier

As Freeman Mathis & Gary's professional-liability analysis of Opinion 512 notes, carriers are increasingly asking about AI tool use at renewal — and undisclosed use can affect coverage. The clean answer at renewal is: "We use an on-device AI notetaker for client meetings; audio never leaves the attorney's device; we obtain informed consent per our state bar's current opinion; we document consent in the matter file." That is a defensible position. "We use Otter and the DPA is fine" is harder to sell to the carrier if Heppner gets cited back at you after a privilege dispute.

Final Call: Pick the Architecture, Then the Workflow

The decade-long debate about AI notetakers in legal practice collapsed in February 2026 into one question: does a vendor hold your client's words? If yes, you've inherited the third-party problem the Heppner court punished. If no, you have an architecture a bar grievance panel can actually evaluate on its merits — and a consent conversation with your client that is honest rather than evasive.

For solo and small-firm lawyers who already live on iPhone and Mac, the practical answer in October 2026 is a fully on-device notetaker paired with the consent script above and a written AI-use policy mirroring the template circulating from The Legal Prompts and similar sources. The decision authority stays with you — your state bar sets the rule and your professional judgment applies it — but the architecture decision is binary and clear.

Try Basil AI for your next client meeting

100% on-device transcription on iPhone and Mac. No vendor cloud. No bot in the call. Download free.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

Can lawyers use AI notetakers during client meetings?

Yes, but with conditions. NYC Bar Formal Opinion 2025-6 and Formal Opinion 2026-2 require informed client consent before recording. ABA Formal Opinion 512 requires lawyers to understand how the tool handles data (Rule 1.1), protect confidentiality (Rule 1.6), and obtain informed consent before inputting client confidences into self-learning tools. Boilerplate engagement-letter language does not satisfy the consent requirement.

Does using an AI notetaker waive attorney-client privilege?

It can. In United States v. Heppner (S.D.N.Y., Feb. 10, 2026), Judge Rakoff held that documents a defendant generated using a consumer AI tool were not protected by attorney-client privilege or the work-product doctrine because the vendor could retain and disclose inputs. The court treated this as sharing with a third party. On-device tools where no vendor sees the data materially reduce this third-party problem.

Which AI notetakers are safe for depositions?

Depositions have their own stenographic record, so most AI notetakers duplicate rather than replace it. If used, prefer tools that run fully on-device (Basil AI) or vendor-reviewed services with no training on inputs. Avoid consumer-grade cloud tools whose terms permit retention and model training. Always confirm with opposing counsel and the court reporter before recording.

What should a lawyer's AI-notetaker consent clause say?

Per NYC Bar guidance, consent should name the tool, explain where audio and transcripts are processed and stored, state whether the vendor retains or trains on inputs, describe retention and deletion, and give the client a meaningful ability to decline. ABA Opinion 512 is explicit that boilerplate 'we may use technology' language is not enough — the lawyer must explain the specific risk.

Is Otter.ai or Fireflies.ai appropriate for privileged client calls?

Both are cloud services that store transcripts on vendor infrastructure, which creates the exact third-party disclosure problem flagged in Heppner. Otter.ai's privacy policy and Fireflies.ai's privacy policy grant broad rights to process and retain content. For privileged conversations, most state-bar guidance pushes lawyers toward tools where the vendor never receives the audio — i.e., fully on-device capture.

Does running the notetaker on-device solve the privilege problem?

It removes the vendor as a third-party recipient of the audio and transcript, which is the specific defect the Heppner court identified in consumer cloud tools. Privilege still depends on confidentiality in practice (don't share the transcript loosely) and on obtaining consent under your state bar's rules. On-device processing is an architecture fact; whether your use meets professional-conduct rules is still your call.