Imagine a Tuesday call. Your client’s general counsel joins, then her deputy, then a third participant: “GC’s Notetaker”. Nobody mentions it. Forty minutes later you have said, informally, that a claim “probably would not survive a strike-out application” and that the board “should not worry too much yet”. That afternoon a summary of the call, with your words in it, sits in a vendor’s cloud under terms neither of you has read.
That hypothetical is the ethics problem with AI note takers for lawyers, and it took until December 2025 for a bar to write it down. The New York City Bar’s Formal Opinion 2025-6 is, as far as I can find, the first bar opinion devoted to the subject, and its central warning is precise: an AI transcript “could effectively formalize everything that was said, including informal legal advice that an attorney might have offered to the client ‘off the cuff’”.
What NYC Bar Opinion 2025-6 requires
Formal Opinion 2025-6 (22 December 2025) gives four instructions. First, “an attorney should obtain client consent before recording the call.” Second, consider whether recording “is tactically well-advised… including issues of confidentiality and privilege”. Third, “check the work product for accuracy”. Fourth, “if an attorney knows that a client is recording a call with an AI tool, the lawyer should advise the client of the disadvantages of doing so.”
It sits on Formal Opinion 2024-5 (7 August 2024): “Without client consent, a lawyer must not input confidential client information into any Generative AI system that will share the inputted confidential information with third parties.” And ABA Formal Opinion 512 requires informed consent, not a boilerplate clause, before client information enters a self-learning tool.
Consent: one-party and all-party rules, and the GDPR angle
Consent has two layers, and the ethics layer is the stricter one. US recording statutes split between states where one party’s consent suffices and states where every participant must agree. The ethics duty applies regardless: the client’s consent is required before recording. A spoken consent line at the start, acknowledged by everyone and noted in the file, satisfies both.
In Europe the recording is personal data, the vendor is a processor, and professional secrecy adds a criminal-law layer. The CCBE’s 2025 guide allows client data into a generative AI tool only with “appropriate safeguards in place”; ÖRAK’s Austrian guidance requires an Art 28 GDPR agreement and a § 40 Abs 3 RL-BA undertaking from the provider first, failing which the input is “standesrechtlich unzulässig”. A consumer-plan bot fails those tests; AI ethics rules for lawyers by jurisdiction has the full map.
Privilege: the third party in the room and the transcript that outlives the call
Privilege follows the terms of service. In United States v. Heppner (S.D.N.Y., memorandum 17 February 2026) Judge Rakoff held that a defendant’s roughly 31 documents of exchanges with consumer Claude were protected by neither privilege nor work product: “Because Claude is not an attorney, that alone disposes of Heppner’s claim of privilege”, and the exchanges were not confidential because the privacy policy allowed third-party access. He left open that a tool used at counsel’s direction “might arguably” act as a lawyer’s agent. A note-taker is the same analysis with a microphone: terms that permit training, retention or disclosure end the expectation of confidentiality; enterprise terms plus counsel’s direction preserve an argument. Does using ChatGPT waive privilege? covers the case law.
The vendor test courts now use comes from Morgan v. V2X (D. Colo., 30 March 2026): no confidential information in an AI platform unless the provider is contractually prohibited from “(1) storing or using inputs to train or improve its model; and (2) disclosing inputs to third parties except where essential”. Apply it to the bot before it joins the call.
Copilot meeting recaps: what is stored and where
Copilot in a Microsoft 365 work tenant is the recorder most firms already own. Microsoft’s enterprise data protection documentation states that “prompts, responses, and data accessed through Microsoft Graph aren’t used to train foundation models” and that Copilot inherits the tenant’s sensitivity labels, retention policies and audit. One carve-out matters for European firms: “Anthropic models are currently excluded from the EU Data Boundary.” Consumer Copilot on a personal account is a different product that trains unless the user opts out.
The real Copilot risk is your own permissions. As the ABA’s Law Technology Today put it, “permissions set years ago and never revisited now define what an AI tool will surface on demand.” A recap of a privileged call is a document in the tenant, readable by anyone who can open the folder. Microsoft Copilot for lawyers covers the pre-deployment checks.
Gemini, Otter and Zoom: check the tier before the call
| Tool and tier | Training default | Before a client call |
|---|---|---|
| Copilot, work tenant with enterprise data protection | Not used to train foundation models; tenant retention and labels apply | Check who can see the recap and the retention setting |
| Copilot, personal account | Trains unless “Training on conversation activity” is off | Do not use |
| Gemini, consumer account | Trains with “Keep Activity” on; Google: “Please don’t enter confidential information that you wouldn’t want a reviewer to see” | Do not use |
| Gemini for Google Workspace | “Not human reviewed or otherwise used for Generative AI model training outside your domain without permission” | Confirm the meeting runs on the Workspace tenant, not a personal account |
| Standalone bots (Otter, Zoom’s AI Companion and similar) | Not verified for this page; terms vary by plan and change | Run the vendor questions first |
For the standalone bots, the CCBE’s technical guide supplies the questions: will the provider train on uploaded data, can its staff access recordings, will you be told of law-enforcement disclosure, where is the data centre? A recording is a prompt: what happens to it depends on the contract, not the technology.
Opposing counsel’s note-taker in your negotiation
Suppose the other side’s associate joins a settlement call with a bot in tow. Nothing in 2025-6 stops them, but the transcript formalises your off-the-cuff remarks as much as theirs. Say you see the bot, ask whether the call is being recorded and summarised, state what you are content to have recorded, and keep anything sensitive for a call without it.
The opening script and the firm policy
The consent line is the cheapest control on this page.
Draft (1) a two-sentence consent statement I can read at the start of a recorded client call stating that the call is recorded and summarised by [tool], where the transcript is stored and for how long, and asking each participant to confirm; (2) an instruction to the note-taker to produce only decisions, action items, owners and dates, and to exclude verbatim quotation of legal advice; (3) the two sentences I say if a participant objects. Jurisdiction: [state / country]. Cite any ethics guidance as [VERIFY] rather than asserting it.From this meeting recap and transcript, list every decision, every action item with owner and due date, every open question and every commitment made to the client, quoting the speaker for each commitment. Exclude anything that was legal advice to the client; where advice was given, write only "advice given on [topic]" so the lawyer records it separately. Flag any mis-heard name, number or date. Then draft a five-line follow-up email containing no advice.Review this AI-generated summary of a client call <summary>...</summary> against the transcript <transcript>...</transcript>. Report: (1) statements in the summary not supported by the transcript; (2) informal or hedged advice the summary has stated as a conclusion; (3) names, figures and dates to verify; (4) passages to mark privileged or remove before filing; (5) the retention period under our policy <policy>...</policy>. Do not rewrite; list the edits.The firm policy needs six lines: approved recording tools and tiers; recording off by default for external calls; the consent line and who reads it; where transcripts are stored, for how long, and who can access them; a lawyer’s review before any summary is filed; and no bot that the firm has not approved. The law firm AI policy template has a slot for it.
Safe uses: internal meetings, dictation, CLE
Internal meetings inside a tenant with enterprise data protection, with no client on the line, are where recaps earn their keep. Webinars, CLE sessions and public talks are the ideal case. Two categories stay off the list whatever the tool: board deliberations, for the reasons Skadden gave, and privileged strategy calls whose value depends on never being written down. The free bot someone installed is the subject of shadow AI in law firms.
Where to go next: the state-by-state view is in the state bar AI ethics opinions map; the ethics and regulation cluster hub indexes the rest; and the three prompts above sit with the client-communication prompts in the prompt library. Which recap tool is safe for which call is a ten-minute settings question, and AI Lab for Lawyers answers it live, in the tools, with a meeting-recording policy to take home.
Frequently asked questions
Can lawyers use AI note-takers on client calls?
Yes, with conditions. NYC Bar Formal Opinion 2025-6 says a lawyer should obtain the client's consent before recording, consider whether recording is tactically well-advised given confidentiality and privilege, and check the AI's summary for accuracy. The tool must also pass the confidentiality test in ABA Opinion 512 and NYC 2024-5: no client information into a system that shares it with third parties or learns from it without informed consent. That rules out consumer tiers.
Does an AI transcription bot waive privilege?
It can. Privilege depends on a reasonable expectation of confidentiality, and in United States v. Heppner (S.D.N.Y., February 2026) Judge Rakoff held a defendant's exchanges with consumer Claude were not confidential because the platform's privacy policy allowed third-party access. A bot whose terms permit training, retention or disclosure puts the transcript in the same position. Use a tool under enterprise terms that prohibit training and third-party disclosure, and keep counsel directing its use.
Do I need consent to record a client meeting with AI?
Two layers. Ethically, NYC Bar 2025-6 says obtain client consent before recording, and ABA Opinion 512 requires informed consent before client information enters a self-learning tool. Legally, recording statutes differ: some US states require one party's consent, others require every participant's, and in the EU the recording is personal data processed by a vendor under a data processing agreement. The safe practice is a spoken consent line at the start, from everyone on the call.
What does NYC Bar Opinion 2025-6 say?
Issued 22 December 2025, it addresses AI tools that record, transcribe and summarise client conversations. An attorney 'should obtain client consent before recording the call', should consider whether recording 'is tactically well-advised' including 'issues of confidentiality and privilege', and 'should check the work product for accuracy'. If a client is recording with an AI tool, the lawyer 'should advise the client of the disadvantages'. Transcripts may 'formalize' advice given 'off the cuff'.
Is Copilot's meeting recap confidential?
In a work tenant with enterprise data protection, Microsoft says prompts, responses and data accessed through Microsoft Graph 'aren't used to train foundation models', and recaps inherit your tenant's retention policies and sensitivity labels. The risk is internal: the recap is a document visible to anyone with permission, so permissions debt decides who can read it. Consumer Copilot on a personal account trains on conversations unless the user opts out, and is not suitable for client calls.