Table of Contents
  • Privilege exposure in AI meeting transcription comes from four checkable properties of the tool: how it captures the conversation, whether it processes recordings for model training, where it stores the audio, and who receives the transcript.

  • Of the three failures people call a “privilege problem” (confidentiality breach, waiver, and admissibility), only waiver is permanent.

  • Training rights depend on plan tier: Otter’s free and Pro tiers permit de-identified conversation data to improve its models with an opt-out in settings, while its Enterprise plan carries a no-training-on-customer-data policy.

  • Fireflies defaults to joining every meeting with a web-conference link, so a note-taker can attend client calls without anyone deciding to invite it.

  • An AI transcript converts an otherwise ephemeral conversation into a durable record that can be requested in discovery.

An AI note-taker probably sat in on one of your client meetings this month. Someone turned it on because it saved them an hour, and nobody asked what the tool agreed to on your behalf.

That’s the actual risk with AI transcription tools for law firms, and it comes down to four things every tool does with what it hears: how it captures the conversation, whether it processes your recordings to train a model, where it stores the audio, and who it automatically sends the transcript to.

The answers change by tool and by plan tier, and the consumer tiers most people sign up for are where the rights get reserved. But most of them are settings you can change this afternoon.

We run this review for firms without internal IT, and the same four answers decide it nearly every time.

Table of Contents

The Bot in Your Client Meeting Already Agreed to Something

When an AI note-taker joins a client meeting, the terms it operates under were accepted by whoever installed it, and those terms govern what happens to the conversation. Nobody at your firm negotiated them. In most cases nobody read them.

These tools arrive through individual adoption, which is why the review never happened.

How an AI Note-Taker Ends up in a Privileged Meeting

These tools enter your firm through one person’s decision rather than a firm-wide one, which is exactly why nobody reviewed the terms. The pattern is consistent:

  • One person installs it. An associate connects Otter, Fireflies, or the AI assistant built into Zoom or Microsoft Teams to their own calendar.

  • It works. They stop taking notes during depositions prep and client calls, and they get an hour back.

  • It spreads. Two colleagues ask what they’re using. Now it’s on three calendars.

  • It auto-joins. Fireflies, for example, defaults to joining every meeting with a web-conference link, which includes the ones with clients on them.

  • Nobody escalates it. It never looked like a technology decision, so it never reached anyone who would have asked about confidentiality.

Every step is reasonable on its own, and the result is a third-party service sitting in privileged conversations under terms your firm never evaluated.

What Accepting the Terms Actually Committed Your Firm To

Clicking through a consumer-tier agreement typically grants the vendor rights your firm would never grant in a signed engagement letter. Free and individual plans commonly permit the vendor to use your recordings to improve its models, with the opt-out buried in settings rather than presented at signup.

Otter’s free and Pro tiers work this way. Its policy also reserves the right to keep recordings after you delete them, where the vendor decides that serves a legitimate business purpose.

The gap between what your firm assumes and what the agreement says is where the exposure lives.

Client security questionnaires and cyber-insurance renewals both ask how your firm handles confidential material, and they’re usually what forces a real law firm cybersecurity conversation.

I’ve seen a lot of firm administrators give to the best of their knowledge answers.

— Aaron Eittreim, EVP Sales, Uptime Legal

Answering from assumption carries real consequences: a client who concludes they were misled ends the relationship, and an inaccurate answer on an insurance questionnaire can undermine a claim when you need it most.

Three Different Problems Everyone Calls “Privilege”

A privilege problem with an AI transcription tool is actually one of three distinct failures: a confidentiality breach, a waiver of privilege, or a question of admissibility. They carry different consequences and different remedies, and collapsing them into one worry is why most guidance on this topic is impossible to act on.

The three sections below separate them.

Comparison of confidentiality breach, privilege waiver, and admissibility, showing only waiver is irreversible.

Only one of the three is permanent, and that’s the one worth organizing your policy around.

Confidentiality Breach: A Duty Violation

A confidentiality breach means client information reached someone it shouldn’t have, which implicates your duty under ABA Model Rule 1.6 to protect information relating to the representation. Rule 1.6(c) asks you to make reasonable efforts to prevent inadvertent or unauthorized disclosure.

A breach is serious and often remediable. You can notify the client, close the gap, document what changed, and continue the representation.

Privilege Waiver: The One You Can’t Undo

Waiver means disclosure to a third party destroyed the protection itself, and no vendor remediation restores it. Where a confidentiality breach damages trust, waiver removes a legal shield.

If privilege is waived over a conversation, opposing counsel may be entitled to its substance. There’s no notification process that reverses that, and no apology from a transcription vendor that puts it back.

Admissibility: A Separate Question Entirely

Admissibility asks whether a transcript can be entered as evidence, which is a different question from whether creating it compromised confidentiality. Most vendor content that touches legal risk at all addresses this one, usually framed as whether a transcript is court-admissible.

Admissibility matters, and it isn’t your first concern here. A transcript can be perfectly inadmissible and still have cost you the privilege.

The Four Places a Privileged Conversation Can Leak

An AI transcription tool is safe for privileged meetings only when your firm can answer what happens at all four exposure points:

  • What captured the conversation

  • Whether the vendor processes it to train a model

  • Where the audio and transcript live

  • Who receives them automatically

Standalone note-takers like Otter and Fireflies reserve training rights on their free and individual tiers. Zoom AI Companion and Microsoft 365 Copilot contractually exclude training. The difference is the plan you’re on, not the logo.

These four points are the whole evaluation. Each one maps to a specific setting or contract term you can check, and the four sections below give you the question that tests each.

Four-stage flow of AI transcription exposure: capture, processing, storage, and distribution.

Treat the framework as a sequence. A conversation passes through all four stages in order, and a tool is only as safe as its weakest one.

Capture: What Joined the Meeting

Capture covers what started listening and who was on the invite when it did. The question that tests it: did anyone outside the privilege receive an invitation, and did the tool join without an explicit decision?

An auto-join setting means the tool attends meetings nobody cleared it for. A forwarded calendar invite means a participant you didn’t plan for.

Processing: Whether Your Recordings Train Someone’s Model

Processing determines whether your client conversations become training data that can surface in another user’s results. This is the highest-stakes item in the framework, and the one most often buried in terms rather than exposed as a setting.

The ABA addressed this directly in Formal Opinion 512, its first formal ethics guidance on generative AI, issued in July 2024.

The opinion concludes that a lawyer needs informed client consent before entering information relating to the representation into a self-learning AI tool. It also holds that boilerplate language in an engagement letter doesn’t count: the client has to hear why you’re using the tool, what the specific risks are, and what information gets disclosed.

A transcription tool that trains on your recordings is exactly that kind of tool.

Storage: Where the Audio Lives, and for How Long

Storage is a legal data management question: where the recording physically lives, who can retrieve it, and when it’s actually deleted. Deleting a transcript in the interface removes it from your view, not necessarily from the vendor’s systems.

Otter’s privacy policy reserves the right to keep recordings and transcripts after you delete them, where Otter determines that serves a legitimate business purpose.

Ask where the data resides, which sub-processors touch it, and what the retention window is once you’ve asked for deletion.

Distribution: Who Gets the Transcript Automatically

Distribution is the least-known exposure point, because transcript sharing is usually left to whoever set the tool up. Fireflies defaults to letting each teammate choose their own email settings, which means the answer at your firm depends on a decision no partner made.

If opposing counsel, a client’s accountant, or a third party sat on that invite, the transcript reaches them without anyone deciding to send it.

Automatic sharing to connected cloud drives and note apps creates the same problem one step removed. Check both.

Mapping each stage to the obligation it implicates makes the review concrete:

Exposure Point What It Controls The Duty It Implicates The Question That Tests It
Capture What started listening, and who was present Reasonable efforts to prevent unauthorized disclosure (Rule 1.6(c)) Did anyone outside the privilege get an invite?
Processing Whether recordings train the vendor’s models Confidentiality of information relating to the representation (Rule 1.6) Are our recordings used for model training?
Storage Location, access, and retention of audio and transcripts Reasonable efforts, plus technology competence (Rule 1.1, Comment 8) Where does it live, and when is it truly deleted?
Distribution Who automatically receives the transcript Risk of third-party disclosure and privilege waiver Does this send to everyone on the invite?

Bar rules vary by state, and what counts as a reasonable effort isn’t settled the same way everywhere. Use the four questions to establish the facts, then apply your own jurisdiction’s standard to them.

Not sure how your firm’s access is currently configured?

An IT Health Check maps what you have, flags where access is misconfigured, and gives you a clear picture of where your firm actually stands.

What to Ask a Vendor, and What Their Answers Actually Mean

The four questions worth asking a transcription vendor map directly to the four exposure points, and a real answer names one of them specifically. Most vendor security pages answer a question you didn’t ask.

The two sections below cover the questions that work and the reassurances that only sound like answers.

The Questions That Get Real Answers

Asking what happens at a named stage forces a specific answer that a compliance-page summary can’t satisfy. Put all four in writing:

  • Do you use our recordings or transcripts to train your models? Ask for the answer for your specific plan tier, in writing. Otter’s free and Pro tiers permit de-identified conversation data to improve its models, while its Enterprise plan carries a no-training policy, so the tier is the answer.

  • Where is our audio stored, and which sub-processors have access? A named region and a named list, not “secure cloud infrastructure.”

  • What happens when we delete a transcript, and how long until the audio is gone? Deletion in the interface and deletion from their systems are different events.

  • What does the tool send automatically, and to whom? Ask about participant emails, connected drives, and integrations separately.

Any vendor selling to regulated buyers can answer all four. A vendor that won’t answer in writing has given you your answer.

Reassurances That Aren’t Answers

SOC 2 compliance, encryption at rest, and “we don’t sell your data” are each true statements that leave the training and retention questions untouched. They describe real controls and they answer a different question.

Four common vendor security reassurances paired with the question each one fails to answer.

The pattern is consistent: each statement is accurate, and none of them tells you what happens at a named stage. Safe tools exist, and identifying them takes more than reading the security page.

Some tools treat the data you include in a prompt as private and confidential, and by contract ensure it’s not included in the large language model. But it’s not easy to determine that.

— Mike Dewdney, Director of Cloud & IT, Uptime Legal

That difficulty is the reason to run the four questions rather than trust a summary. The answers exist, and they’re usually not on the marketing page.

The Settings to Change Before the Next Recorded Client Call

Before the next recorded client call, turn off auto-join, disable model training, set the shortest available retention period, and stop automatic transcript distribution. Most of the exposure across all four points is controlled by settings you can change in an afternoon.

The two sections below cover what to change now and what to write down afterward.

Checklist of AI transcription settings to change, grouped by capture, processing, storage, and distribution.

Work through it once per tool your firm allows, and treat anything you can’t change as a reason to reconsider the tool.

Defaults Worth Turning Off Immediately

Auto-join, model training, indefinite retention, and automatic transcript sharing are the four defaults that create the most exposure with the least awareness. Each one has a direct fix.

Move your firm to a business or enterprise tier if you’re on a consumer plan, since that’s often where the training rights actually change. Then require explicit approval before any tool joins a client meeting, cut retention to the minimum the tool offers, and treat the absence of a retention setting as its own answer.

In Otter, configurable retention starts at the Business tier, so a firm on a consumer plan has no retention control at all.

What to Write into Firm Policy

A workable policy names which meetings may be recorded, who approves a new tool, and where transcripts are allowed to live. Keep it short enough that people follow it.

Write down the four answers for every approved tool and date them. Vendor terms change, and a dated record is what lets you answer a client questionnaire without guessing.

FREE GUIDE · THE GAP MAP

Is your firm actually protected — or just assuming it is?

The 8 cybersecurity assumptions most law firms get wrong — and what real protection actually looks like.

The Meetings You Shouldn’t Record at All

Configuration doesn’t make every meeting safe to record, because a transcript converts an otherwise ephemeral conversation into a durable record that can be requested later. That’s the part most guidance on this topic misses entirely.

Some conversations are better left unrecorded regardless of how well the tool is configured:

  • Early case assessment, where candid discussion of weaknesses is the point

  • Settlement strategy and valuation discussions

  • Conversations touching a client’s potential exposure or wrongdoing

  • Internal discussions of a firm conflict or a malpractice concern

  • Any meeting where a participant hasn’t been told a tool is listening

A well-configured tool still leaves you with a permanent record of the conversation.

Security Risk

A transcript doesn’t just risk exposing a privileged conversation. It creates a discoverable record of a discussion that would otherwise have left none.

How Do You Review This Without a Compliance Team?

Reviewing an AI transcription tool without a compliance team means getting someone outside the vendor to verify the four exposure-point answers in writing. A firm of fifteen attorneys with no in-house IT can do this, and reading vendor marketing isn’t how.

Send the four questions to the vendor and keep the response. Have someone technical read the answers against the tool’s actual settings, because the two don’t always agree. Then record what you found with a date on it.

For a firm with no internal IT function, this review is part of what managed IT for law firms covers. Uptime Legal does it alongside the policy work that follows. Firms that want to handle it themselves can, as long as the answers end up written down rather than assumed.

Your Firm Doesn’t Need to Ban AI Transcription

The firms that handle this well answer four questions about every tool they allow: what joined the meeting, whether the vendor trains on the recording, where the audio lives, and who receives the transcript. Then they change the settings whose answers don’t hold up.

Do that once per tool and write down what you found. The next time a client sends a security questionnaire or an insurer asks how you handle confidential material, you’ll have a real answer ready.

Some conversations still shouldn’t be recorded. Knowing which ones is part of the same judgment.

Not sure how your firm’s access is currently configured?

An IT Health Check maps what you have, flags where access is misconfigured, and gives you a clear picture of where your firm actually stands.

WHAT’S NEXT

ARTICLE
How to Utilize the 2026 Legal Software Report

FREE ASSESSMENT
Get a Free IT Health Check for Your Firm

GET HELP
See How Uptime Legal Supports Law Firms Day to Day

Frequently Asked Questions

It can, if the tool puts a third party in possession of the conversation. Whether it does depends on the vendor’s terms and your configuration, which is why the four exposure-point answers matter more than the tool’s name.

Not inherently. It breaks confidentiality when recordings are retained, processed for training, or distributed to people outside the representation without your firm deciding to allow it.

Twelve states require all-party consent, including California, Illinois, Florida, Massachusetts, and Pennsylvania. Federal law sets a one-party floor, so your obligation depends on where the participants are, not where your firm is.

Yes. Once a transcript exists it’s a record like any other, which is the strongest argument for not recording conversations you wouldn’t want produced.

Rarely. Free and consumer tiers are where vendors most often reserve rights to retain recordings and use them for model training.

It should name which meetings can be recorded, who approves a new tool, where transcripts are stored, and how long they’re kept. Keep it to one page so people actually follow it.

Published On: August 5th, 2026 / Categories: Cybersecurity for Law Firms /
Curran Walia, Content Marketer at Uptime Legal, briefs law firms on legal technology with articles that don’t bury the lead. His work helps firms make sense of the systems, security, and software decisions behind a better-run practice.

Uptime Legal’s Technology Solutions

Cloud, software, IT, and document management built for today’s law firms.

  • Uptime Manage

Managed IT & Help Desk Solutions

  • Uptime Cloud

Cloud & Legal Application Hosting

  • Uptime Applications

Application Configuration & Support

  • LexWorkplace

Document Management For Law Firms