AI meeting notes that never leave your office
The ethics opinions all ask the same question: who else gets access to your client's information? Local processing gives that question a short answer.
Not legal advice, and we're obviously not a neutral party — we make one of these tools. Every rule and opinion below is linked so you can read the primary source rather than take our summary for it.
Short answer: the bar opinions don't mandate a particular architecture. They ask whether a third party can access information relating to the representation, whether it's retained, and whether it trains a model. A tool that runs entirely on your machine answers all three at once — but it doesn't remove your duty to tell the client you're recording.
What the rules actually say
| Source | Date | What it requires |
|---|---|---|
| Model Rule 1.6(c) | 2012 | “Reasonable efforts to prevent the inadvertent or unauthorized disclosure of, or unauthorized access to,” client information |
| Model Rule 1.1, cmt. 8 | 2012 | Keep abreast of “the benefits and risks associated with relevant technology” |
| ABA Formal Op. 512 | Jul 2024 | Evaluate disclosure risk before inputting client information; informed consent required for self-learning tools |
| DC Bar Op. 388 | Apr 2024 | Determine whether the provider or third parties access inputs, and whether your inputs affect other users' outputs |
| Florida Op. 24-1 | Jan 2024 | Vet retention, sharing and self-learning policies; no improper billing for AI-saved time |
| Texas Op. 705 | Feb 2025 | Vendor vetting plus mandatory independent verification of AI output |
| NYC Bar Formal Op. 2025-6 | Dec 2025 | The one squarely about AI notetakers — see below |
Note that the ABA and state opinions are advisory. The binding text is your own jurisdiction's rules.
You still have to tell the client
This is the part a privacy-first tool cannot do for you, and it's worth being blunt about.
NYC Bar Formal Opinion 2025-6 is the most on-point guidance anyone has issued: clients must be notified and their consent obtained whenever an AI system records their calls. The reasoning is that undisclosed recording deprives the client of the chance to choose their words with care, and hands an advantage to the recording party.
The striking detail: New York is a one-party-consent state. Recording your own client call is lawful there. The opinion holds that your ethical duties run ahead of the wiretap statute anyway, and that secret recording can implicate Rule 8.4's prohibition on deception. Lawful and ethical are not the same test.
So: no bot in the attendee list removes an awkward object from the call. It does not remove the sentence you have to say. See our guide to recording consent laws for the statutory side.
Where on-device processing actually helps
Read DC Opinion 388's test again — does the provider or a third party access the inputs? — and notice that it's phrased as a question about outcomes, not architecture. A local tool answers it in one word. There is no provider, no sub-processor, no retention window, and nothing held by anyone who could be served with a subpoena naming them instead of you.
The same goes for ABA 512's self-learning trigger. Informed consent attaches where the tool retains and learns from what you feed it. A model running on your own hardware, that sends nothing back, has nothing to learn from at scale.
What we are not going to claim
Three things, because the vendor pitch in this space routinely overreaches:
- No bar has blessed local AI as categorically compliant. The opinions are architecture-agnostic. NYC Bar 2025-6 doesn't distinguish on-device from cloud at all. Local processing answers the questions they ask — that is a good argument, not a safe harbour.
- No court has held that a cloud notetaker waives attorney-client privilege. Courts are actively working through AI and privilege and the results have split. Anyone telling you the question is settled is selling something.
- Local storage is not automatically secure storage. An unencrypted laptop is a worse custodian than a competent vendor. Turn on FileVault, use a strong device password, and keep a backup. Rule 1.6(c) says reasonable efforts — that obligation is now yours rather than a vendor's.
The cautionary tale
The reason this stopped being theoretical: an AI researcher reported receiving an Otter.ai transcript of a Zoom meeting that kept recording after he left the call, capturing investors discussing their firm's strategic failures and metrics. It was reported by NPR alongside a class action over recording non-subscribers without consent.
Nothing about that requires bad intent by the vendor. It requires only that a recording exists somewhere you don't control, governed by logic you didn't write. Substitute a privileged conversation for the investor call and the consequence changes considerably.
Practical setup
- Say it at the top of the call. “I use an AI notetaker for my own notes. It runs on this machine and nothing is uploaded. Any objection?” Note that you got a yes.
- Put it in the engagement letter if AI notes are part of how you work.
- Encrypt the device. FileVault, strong password, automatic lock.
- Review before you rely. Texas Opinion 705 makes independent verification explicit, and every other opinion implies it. Transcription errors on names, numbers and dates are exactly where it matters.
- Check your own jurisdiction. The opinions above are advisory and they don't agree with each other on everything.