The efficiency argument for AI meeting transcription is compelling for any busy law firm. Client intake calls, deposition preparation sessions, strategy meetings, partner discussions — all of them generate information that needs to be captured, organized, and acted on. AI transcription tools promise to do that automatically, saving hours of manual note-taking and reducing the risk of missed action items.
The problem is that the most convenient AI meeting tools — the ones with free tiers, browser plugins, and consumer-friendly interfaces — were not designed with attorney-client privilege in mind. And in the legal profession, where confidentiality is not just a best practice but a professional obligation, using the wrong tool is not just a security risk. It is an ethics exposure.
This article is for managing partners, general counsel, and legal IT directors who are evaluating or already using AI meeting transcription tools. Our goal is to give you the framework to make a defensible decision — one you can stand behind if a client, a bar association, or a court ever asks about it.
The attorney-client privilege problem
Attorney-client privilege protects confidential communications between a lawyer and client made for the purpose of obtaining legal advice. It is one of the oldest and most fundamental protections in the legal system. And it can be waived — including by disclosing privileged communications to third parties who are not within the circle of privilege.
When a law firm uses a consumer AI meeting tool to transcribe a client call, that recording is sent to the tool's servers for processing. The AI company receives the content of privileged communications. Whether this constitutes a waiver of privilege is a complex legal question that courts have not fully resolved in the context of AI tools — which is exactly why it is a risk law firms should not be taking unnecessarily.
Voluntary disclosure of privileged communications to a third party can constitute a waiver of attorney-client privilege. The question of whether using a consumer AI transcription service constitutes such a disclosure has not been definitively resolved by courts. Law firms that use consumer tools for privileged client communications are accepting an unquantified legal risk — one that could affect their clients' ability to assert privilege in litigation.
The traditional doctrine on third-party disclosures has carved out exceptions for agents and assistants who are necessary to the legal representation — court reporters, legal secretaries, paralegals. Whether a consumer AI company qualifies as such an agent depends on the nature of the relationship and the contractual terms governing it. Most consumer AI tool terms of service were not written with this analysis in mind.
The ABA ethics framework
The American Bar Association's Model Rules of Professional Conduct provide the ethical framework for evaluating AI tool use in legal practice. Three rules are particularly relevant:
Rule 1.1 — Competence
ABA Model Rule 1.1 requires lawyers to provide competent representation, which includes the legal knowledge, skill, thoroughness, and preparation reasonably necessary for the representation. Comment 8 to Rule 1.1 specifically addresses technology: lawyers should keep abreast of changes in the law and its practice, including the benefits and risks associated with relevant technology.
This means lawyers have an ethical obligation to understand the tools they use — including where their data goes, how it is protected, and what risks it creates. Using a consumer AI tool without understanding its data handling practices is not competent practice.
Rule 1.6 — Confidentiality of Information
ABA Model Rule 1.6 requires lawyers to make reasonable efforts to prevent the inadvertent or unauthorized disclosure of client information. Comment 18 states that lawyers must act competently to safeguard information relating to the representation of a client against inadvertent disclosure or unauthorized access.
What constitutes "reasonable efforts" in the context of AI tools is still being defined by state bar ethics opinions. But the general principle is clear: using a tool that sends client communications to a consumer AI company's servers without adequate safeguards is not a reasonable effort to protect client information.
Rule 5.3 — Responsibilities Regarding Nonlawyer Assistance
When lawyers use third-party vendors — including technology vendors — they retain responsibility for ensuring those vendors protect client confidentiality. Rule 5.3 requires that lawyers make reasonable efforts to ensure that the conduct of those assisting them is compatible with the lawyer's professional obligations.
Applied to AI meeting tools, this means law firms must evaluate their vendors' data practices and ensure they meet the confidentiality standards required by the legal profession — not just the adequacy standards required for general business use.
"The ethics obligation is not to avoid AI tools — it is to use them competently, which means understanding where your client communications go and what happens to them."
State bar ethics opinions on AI
State bars across the country have been issuing formal ethics opinions on AI tool use in legal practice. While the specifics vary by jurisdiction, several consistent themes have emerged:
- Supervision requirement: Lawyers remain responsible for work product generated with AI assistance and must review AI outputs for accuracy
- Confidentiality requirement: Client information must not be shared with AI tools in ways that create disclosure risks without client consent
- Competence requirement: Lawyers must understand the AI tools they use, including their data handling practices
- Disclosure considerations: Some opinions suggest that using AI tools for client matters may require client disclosure or consent, particularly where sensitive information is involved
California attorneys are subject to the California Rules of Professional Conduct, which similarly require competence and confidentiality. The California State Bar has been active in evaluating AI ethics issues, and guidance continues to evolve. California firms should monitor developments from the State Bar and consult their professional responsibility counsel when evaluating new AI tools.
Ethics rules vary by jurisdiction and are evolving rapidly in response to AI. This article provides general guidance and does not constitute legal advice. Law firms should consult with professional responsibility counsel in their jurisdiction before implementing AI meeting tools for client matters.
The AI training problem for legal work
Beyond the privilege and ethics issues, law firms face a specific concern about AI training that goes beyond what most other organizations confront: the risk that privileged client communications could become part of an AI company's training dataset.
If a consumer AI tool uses your client meeting recordings to train its models, those communications — which may include litigation strategy, settlement positions, client admissions, and other highly sensitive information — could in theory influence the outputs the AI provides to other users, including opposing counsel.
This is not a theoretical risk. A class-action lawsuit filed in 2025 against a major consumer meeting transcription service alleged that the company used customer recordings to train AI models without adequate consent. Law firms that used that service during the relevant period may have exposed privileged client communications to AI training without their knowledge or their clients' consent.
If a consumer transcription service uses your meeting recordings to train AI models, privileged client communications could become part of a training dataset accessible to the AI company and potentially influencing outputs to other users. Most consumer tools' terms of service do not provide the contractual protections law firms need to prevent this. A hard contractual commitment against AI training — not just a policy statement — is required.
What a law firm evaluation framework looks like
Given the privilege, ethics, and AI training concerns, law firms evaluating meeting transcription tools need a more rigorous framework than most other organizations. Here is what that framework should cover:
Law firm evaluation checklist for AI meeting transcription
Practical guidance for law firm implementation
If your firm is evaluating or already using AI meeting transcription, here is a practical action plan:
- Inventory current tool use. Survey your firm — including individual attorneys and practice groups — to identify every AI meeting tool in current use. Shadow IT adoption of AI tools is common in law firms, particularly among younger attorneys.
- Conduct a privilege analysis. For each tool identified, evaluate whether its use for client meetings creates privilege risk under your jurisdiction's rules. This analysis should involve your professional responsibility counsel.
- Establish a firm policy. Define which tools are approved for use in client matters, which are approved for internal matters only, and which are not approved at all. Make the approved tools easy to access — if the compliant option is harder to use than the consumer alternative, shadow IT will continue.
- Consider client disclosure. For ongoing matters where AI tools will be used for client-related meetings, consider whether your jurisdiction's ethics guidance requires disclosure to or consent from clients. Proactive disclosure is far better than reactive explanation.
- Review vendor contracts. For any tool approved for client matters, review the vendor agreement carefully. Ensure it includes confidentiality protections, a commitment against AI training use, and data deletion procedures appropriate for legal work.
- Document your due diligence. Maintain records of your tool evaluation process and the basis for your decisions. If a privilege issue ever arises, your documented due diligence is your first line of defense.
NSAG has worked with Northern California law firms and legal departments on security assessments. The pattern we see most often is individual attorneys adopting consumer AI tools for efficiency without firm IT or compliance involvement. In legal practice, unlike most industries, this creates not just security risk but professional responsibility exposure. A firm-wide policy with an approved compliant alternative is the most effective solution.
Internal meetings vs. client meetings
It is worth distinguishing between two categories of law firm meetings with different risk profiles:
Internal meetings — partner meetings, firm administrative discussions, business development calls, internal strategy sessions that do not involve client matters. These meetings do not involve privileged client communications, and the risk profile is closer to that of a standard business organization. Consumer AI tools may be acceptable for these meetings depending on the firm's data policies, though the AI training concern remains relevant.
Client meetings — intake calls, matter strategy sessions, deposition preparation, settlement discussions, any meeting where client information or legal strategy is discussed. These meetings involve potentially privileged communications and require the full evaluation framework described above. Consumer AI tools are generally not appropriate for these meetings without significant contractual protections.
A tiered approach — approved tools for client matters, broader options for internal use — is often the most practical implementation for law firms.
The competitive advantage of doing this right
It is worth noting that law firms that implement AI tools responsibly — with documented processes, appropriate vendor agreements, and clear client communication — have a competitive advantage over firms that do not.
Clients, particularly sophisticated corporate clients and government agencies, are increasingly asking their outside counsel about AI tool use. A firm that can demonstrate a thoughtful, documented approach to AI adoption — including how it protects client communications — is a more attractive partner than one that cannot answer the question.
Doing this right is not just about risk management. It is a differentiator.
Conclusion
AI meeting transcription can deliver genuine efficiency gains for law firms — faster note capture, better follow-through on action items, more accessible meeting records. None of that value requires accepting privilege risk or ethics exposure.
The path forward is to use tools that were designed for organizations that handle sensitive information — tools with appropriate contractual protections, controlled infrastructure, documented security practices, and a hard commitment against using your recordings for AI training.
NSAG Meeting Intelligence was built for exactly this requirement. Contact us to discuss your firm's specific needs, including the contractual protections required for legal use.
Built for organizations that handle confidential information
NSAG Meeting Intelligence processes all data on NSAG-controlled infrastructure in California. Your recordings are never used to train AI models. Audio deleted after transcription. Full audit log. Contact us to discuss the contractual protections your firm requires.
Start Free — No Card RequiredLegal inquiry? Call 707.452.3015 or email support@nsag.ai