AI Meeting Notes for Law Firms: What Privilege Compliance Actually Requires (2026)

Published March 13, 2026 · Updated September 2026 · By The Crossing Report · 12 min read

The Compliance Question No One Warned You About

The managing partner at a 12-attorney immigration firm in Illinois figured out Fathom six months ago. She joined a client call, the AI notetaker joined automatically, and the transcript was ready before she'd finished reviewing the action items in her head.

What she hadn't figured out: Illinois is an all-party consent state. The call was recorded before any disclosure was made. The bot's name in the participant list — "Fathom" — did not constitute informed consent under Illinois law or ABA Formal Opinion 512.

She got lucky. The client never complained. But she changed her intake process the next morning.

This is the compliance question at the center of AI meeting notes for law firms in 2026: not whether the tools work (they do), but whether your firm is using them in a way that protects attorney-client privilege, satisfies bar ethics rules, and doesn't expose you to state wiretapping liability. This guide answers that question definitively.


Does AI Transcription Breach Attorney-Client Privilege?

Not automatically — but it creates conditions where privilege can be waived.

Attorney-client privilege is a legal protection that depends on how confidential information is handled, not what tool captured it. The risk with AI meeting notes at law firms is specific: when a transcript of a privileged client conversation is transmitted to a third-party AI vendor's servers, that transmission can be treated as a disclosure to a third party — which may waive privilege if the vendor relationship isn't structured correctly.

Condition 1: The vendor relationship.

If your AI notetaker transmits audio or transcript data to the vendor's servers for processing, and there is no data processing agreement (DPA) in place establishing confidentiality obligations, you have disclosed privileged information to a third party without a formal confidentiality structure. Courts have found waiver in similar circumstances — not frequently, but often enough that your malpractice carrier has an opinion about it.

The fix: before using any AI meeting tool with privileged client communications, obtain and sign the vendor's DPA. Both Fathom and Otter.ai make DPAs available. Some tools process audio locally (Granola does this for Mac; a few others are emerging in 2026). Local processing eliminates the third-party transmission problem entirely — though local tools have fewer features and won't suit every firm.

Condition 2: Engagement letter authorization.

If a client has not been informed that AI tools may process the content of their confidential communications, and a privileged transcript is generated and handled by a third party, the argument for waiver is stronger. ABA Formal Opinion 512 requires disclosure of AI use where material to the representation — and using AI to transcribe every word of a privileged client meeting is, by any reading, material.

The rule here is simple: add AI notetaker disclosure to your engagement letter. One paragraph, signed by the client at intake, authorizes the use and documents informed consent. Sample language is at the end of this guide.


State Bar Guidance on AI Notetakers: What We Know in 2026

Formal bar ethics opinions on AI meeting tools are still catching up with the technology, but the pattern as of September 2026 is consistent on three points:

The bot name is not a disclosure. Multiple bar ethics analyses — from Florida, California, and the ABA — have concluded that an AI notetaker appearing in a call's participant list, even with a recognizable name like "OtterPilot" or "Fathom," does not constitute informed consent for purposes of ethics rules on confidentiality. The bot's presence is not a disclosure; an explicit verbal or written notice is.

Supervision is required. ABA Formal Opinion 512 and subsequent state bar guidance consistently require attorneys to supervise AI tools used in client representation. For meeting notes specifically, that means reviewing AI-generated summaries and action items for accuracy before relying on them or sharing them — not rubber-stamping the output.

Rule 1.6 applies to the vendor relationship. Sharing client confidential information with an AI vendor is a disclosure that must be authorized by client consent or protected by a formal confidentiality structure. The vendor's privacy policy alone is not sufficient. A data processing agreement that imposes confidentiality obligations on the vendor is the standard.

State recording law compounds the ethics exposure. Twelve US states require all-party consent before a call can be recorded. AI notetakers that auto-join calls before consent is established may violate state wiretapping law in those jurisdictions — in addition to bar ethics rules. The states with all-party consent requirements as of 2026:

State Statute Exposure
California Penal Code § 632 Up to $5,000/violation, civil liability
Florida § 934.03 Felony charge possible
Illinois Eavesdropping Act Criminal and civil exposure
Washington RCW 9.73.030 Criminal and civil
Pennsylvania Wiretapping and Electronic Surveillance Control Act Criminal and civil
Massachusetts M.G.L. c. 272, § 99 Criminal misdemeanor
Connecticut § 52-570d Civil liability
Maryland § 10-402 Civil liability
Michigan § 750.539c Civil liability
Montana § 45-8-213 Civil liability
New Hampshire § 570-A:2 Civil liability
Oregon § 165.540 Civil liability

If your firm practices in any of these states, or your clients are regularly located in them, verbal consent before recording is not optional — it is the law.


Tool Comparison: Which AI Meeting Tools Meet Law Firm Confidentiality Standards

For law firms, the evaluation criteria differ from what general businesses use. SOC 2 compliance, DPA availability, local versus cloud processing, and consent workflow features matter more than UI preference or price.

Fathom

Fathom is the most commonly recommended AI meeting notetaker for law firms in 2026. Its team plans ($32/user/month) include SOC 2 Type 2 compliance, explicit data privacy controls, and a data processing agreement available on request. Fathom processes calls via its servers, but with a signed DPA in place, that transmission is covered by a formal confidentiality structure.

Fathom also has an optional consent notification that plays at the start of the recording — the only major meeting AI with this feature built in. Enable it in team settings. It doesn't substitute for engagement letter disclosure, but it satisfies the verbal consent requirement on recorded calls.

Privacy infrastructure: SOC 2 Type 2 ✓ | DPA available ✓ | Optional consent prompt ✓ | Video-only (Zoom, Google Meet, Microsoft Teams)

Best for: Law firms where most meetings happen via video call, and firms that want the clearest compliance posture without custom configuration.

Limitation: Video calls only. No in-person or phone call support.

Otter.ai

Otter.ai is the market leader by adoption across professional services. The Business plan ($40/user/month) adds SOC 2 Type 2 compliance, admin controls, and a DPA. For law firms, the Business plan is not optional — the standard and individual plans lack the data governance features required for privileged communications.

Otter.ai does not have automatic consent prompts. The verbal opener your team uses at the start of every recorded call is the consent workflow, and that means it must be firm policy, not individual discretion.

Privacy infrastructure: SOC 2 Type 2 (Business plan only) ✓ | DPA available ✓ | Consent prompt: manual only | Supports video, phone, and in-person

Best for: Firms that conduct client meetings across multiple formats and need one tool that handles all of them.

Limitation: Business plan required for compliance features. No built-in consent workflow.

tl;dv

tl;dv is a European-based AI meeting platform with strong GDPR compliance infrastructure — which in practice translates to solid data privacy controls for US firms as well. Data can be stored in EU regions. It integrates with Salesforce, HubSpot, and Notion, making it popular at consulting and agency firms that need CRM integration.

For law firms, tl;dv's GDPR framework provides a strong international data protection baseline, but you'll still need to review its DPA for attorney-client communications. It does not have built-in consent prompts.

Privacy infrastructure: GDPR compliant ✓ | EU data residency available ✓ | DPA available ✓ | Consent prompt: No

Best for: Firms with international clients or European operations. Consulting and agency firms that need CRM integration.

Limitation: Less common in domestic US legal settings. Consent workflow is entirely manual.

Read.ai

Read.ai is an enterprise-focused meeting intelligence platform with SOC 2 Type 2, HIPAA-eligible infrastructure, and SSO/SCIM support. Pricing runs $29.75–$49.75/user/month. Law firms with formal data security programs and existing enterprise vendor management processes will find it integrates cleanly into existing compliance structures.

Read.ai offers analytics beyond transcription — meeting quality scores, engagement metrics, and manager summaries — features that mid-size firms may find useful but solo and small practices generally won't need.

Privacy infrastructure: SOC 2 Type 2 ✓ | HIPAA eligible ✓ | SSO/SCIM ✓ | DPA available ✓ | Consent prompt: No

Best for: Law firms with 20+ attorneys and existing enterprise data security programs.

Limitation: Priced and featured for enterprise. More infrastructure than most small firms need.


If you're an accounting firm, bar ethics rules don't apply — but state wiretapping law does. Recording a client call in Illinois without all-party consent is a wiretapping exposure whether you're an attorney or a CPA.

There's an additional consideration for accounting firms: transcript content. If your AI meeting transcripts include tax strategy, financial projections, account details, or client earnings, those transcripts may implicate GLBA privacy obligations depending on how they're stored, retained, and who has access to them.

The standard practice that protects accounting firms:

Engagement letter addition: Add one sentence to your standard engagement agreement: "[Firm Name] may use AI-assisted meeting transcription tools to accurately capture notes from client meetings and calls. Transcription data is retained under our firm's data security policies and with service providers under data processing agreements."

Verbal opener for tax calls: For calls involving tax advice, add: "I'm using an AI note-taking tool on this call. The transcript stays within our firm and our note-taking provider — it won't be used for any other purpose. Is that acceptable?"

Data retention policy: AI meeting transcripts are client data. Your existing document retention policies apply. Define how long transcripts are kept, where they're stored, and who has access — and make sure that policy is documented in writing.


The Three-Sentence Disclosure You Add to Every Client Intake

You don't need a page of legal disclaimers. Three sentences satisfy informed consent, establish the confidentiality framework, and give the client a genuine opt-out.

Use this as your starting point. Have your professional liability insurer and bar counsel review before finalizing:

Engagement letter addition:

"[Firm Name] uses AI-assisted meeting transcription tools to capture and summarize client meetings and calls. Transcription data is retained with [vendor name] under a data processing agreement and subject to our firm's confidentiality obligations. If you prefer that transcription tools not be used in our meetings, please notify us at any time."

Three things this accomplishes:

  1. Discloses AI use — satisfies ABA Opinion 512's materiality requirement
  2. Names the data handling structure (DPA + confidentiality obligations) — covers Rule 1.6
  3. Provides an opt-out — establishes informed consent with a genuine choice

Verbal call opener (for all-party consent state compliance):

"Before we start — I'm using an AI transcription tool to take notes. Is that okay with you?"

Clients almost never say no. The disclosure creates goodwill, not friction. And the documentation that consent was obtained is the transcript itself, which includes the opener and the client's audible agreement.


Practical Setup: Deploying AI Meeting Notes Compliantly at Your Firm

Here's the implementation checklist for a small law or accounting firm deploying AI meeting notes for the first time:

Week 1 — Tool selection and vendor compliance:

  • Choose your tool: Fathom (video, best default privacy settings), Otter.ai Business (multi-format), or Read.ai (enterprise)
  • Obtain and sign the vendor's DPA before any client calls are recorded — this step cannot be skipped
  • Enable the consent notification feature if your tool offers one (Fathom does; turn it on)

Week 2 — Policy and intake:

  • Add the three-sentence disclosure to your engagement letter template
  • Brief every attorney and paralegal on the verbal call opener — one sentence, consistent across the firm
  • Map the states where your attorneys practice and where your regular clients are located; flag all-party consent states for your team

Week 3 — Workflow:

  • Run the tool on internal meetings first — get comfortable with output quality and accuracy
  • Move to non-sensitive external calls (vendor meetings, co-counsel calls)
  • Deploy on client calls under the consent framework after a week of clean testing

Ongoing:

  • Review AI-generated summaries before relying on them or sharing them — the supervision obligation under ABA Opinion 512 is not a formality
  • Retain meeting transcripts under your existing document retention policy
  • Check vendor DPA terms annually — platforms update their data handling policies, and your DPA coverage may need renewal

Your Next Step

If your firm already uses an AI meeting notetaker, do one thing today: log into the tool's settings and confirm whether a consent notification is enabled. If it isn't, write the verbal call opener and make it firm-wide policy by end of week.

If you're about to deploy for the first time, start with Fathom's free individual plan on internal calls this week. Get the DPA signed before using it on client calls. Add the three-sentence disclosure to your next engagement letter template.

The tools work. The compliance framework is not complicated. The firms that run into trouble are the ones who adopted the tool without thinking through the consent workflow — and discovered the problem months later when a client complained or a transcript surfaced somewhere it shouldn't have.

The Crossing Report covers AI compliance updates for professional services firms weekly. Subscribe free.

This is the kind of intelligence premium subscribers get every week.

Deep analysis, cross-sector patterns, and the frameworks that help professional services firms make the crossing.

Related Reading

See all 56 articles →

This is a sample issue — new ones go to subscribers

New issues of The Crossing Report ship exclusively to subscribers every week. Free in your inbox.