← Back to blog

AI Meeting Notetakers Without Breaching Client Confidentiality

30 August 2026·5 min read
Quick answer: AI meeting notetakers like Otter, Fireflies and Fathom can save a law, accounting or financial planning practice real hours — but the confidentiality risk isn't the transcript itself, it's where that transcript goes afterwards: whose servers, whose AI training pipeline, and who else at the vendor can technically access it. Vet the vendor before the meeting, disclose the tool to the client at the start of the call, and know which meetings should never be recorded at all. ✨

Every practice we work with is either already using an AI notetaker or quietly wondering if they should be. Fair enough — nobody misses typing up file notes by hand. But "is this compliant" gets asked a lot less than it should, and the answer isn't a flat no, it's "depends entirely on which tool, which settings, and which meeting." Here's how to work that out instead of guessing. 💖

What most firms get wrong when adopting AI notetakers

  • Picking a tool based on the free trial, not the data terms — the easiest app to install is rarely the one with the most defensible confidentiality settings.
  • Never checking whether the vendor trains its AI on your recordings — some do by default unless you opt out, meaning privileged conversations could feed a third party's model.
  • Not telling the client the meeting is transcribed by third-party AI — a passive "recording" banner isn't genuine informed consent for privileged conversations.
  • Using the same notetaker for every meeting, no exceptions — settlement strategy and anything covered by legal professional privilege shouldn't be recorded by a third-party tool, full stop.
  • Assuming IT "sorted the settings" — retention periods and training opt-outs are usually left on vendor defaults unless someone specifically changes them.

The vendor-vetting checklist

Run any AI notetaker through this before it touches a client meeting:

☐ Does the vendor train its AI on your meeting content, and can that be switched off?
☐ Where is data stored, and does that matter for your privilege or privacy obligations?
☐ What's the retention period, and can a transcript be permanently deleted on demand?
☐ Who are the vendor's subprocessors, and are they listed publicly?
☐ Does the vendor hold SOC 2 or equivalent independent security certification?
☐ Can access be restricted to specific staff, with an audit log of who's viewed a transcript?
☐ Does your professional body or PI insurer have a stated position on AI notetaker use?

Three real examples

Family law firm: Uses an AI notetaker for routine update calls and initial consults, but manually switches it off for anything touching settlement strategy or legal professional privilege — those get handwritten file notes instead.
Accounting firm: Confirmed AI training is opted out at the account level before rolling the tool out firm-wide, and added a line to their engagement letter disclosing meetings may be transcribed by AI. 📈
Financial planning practice: Uses AI transcription for annual reviews, but says out loud at the start of every call — "I'm using an AI tool to transcribe this, is that okay?" — and skips it for conversations involving undisclosed family or estate matters.

Where the actual risk lives

The transcript itself isn't usually the problem — it's the pipeline behind it. Most notetakers record audio, send it to a cloud service for transcription, then run that transcript through a language model to generate a summary. Each step is a point where data leaves your control: it sits on the vendor's servers, may be retained indefinitely by default, and depending on the terms, could be used to train their AI unless you've opted out. None of that is necessarily disqualifying — but "is this tool safe" has a real, checkable answer for each vendor, not a vibe-based one.

💡 Say it out loud, every time: a quick verbal disclosure at the start of the call — "I'm using an AI tool to take notes on this, are you comfortable with that?" — is worth more than a clause buried in an engagement letter nobody reads twice. It's also simply the more respectful version of consent for a client who might not know what "AI transcription" means in practice.

Mistakes to avoid

  • Recording privileged strategy discussions by default — treat privilege, settlement discussions and anything similarly protected as an automatic "notetaker off" situation, not a mid-conversation judgement call.
  • Skipping the engagement letter update — if AI transcription is now part of how you run meetings, your standard client agreement should say so.
  • Never asking who else at the vendor can see the data — "stored securely" on a marketing page isn't the same as a documented subprocessor list.
  • Forgetting the transcript is a discoverable document — an AI-generated summary can be requested the same as any other file note; write and store it with that in mind.

Please note: general information, not legal or financial advice — check current guidance from your professional body and your professional indemnity insurer before relying on it.


Frequently asked questions

Is it ever safe to use an AI notetaker for privileged legal conversations?

Being honest: the safest position for genuinely privileged strategy discussions is not to use a third-party AI tool at all, regardless of the vendor's assurances — the risk of an unintended waiver of privilege isn't worth the time saved. Save AI notetakers for administrative and update-style meetings.

Do we need explicit written client consent to use an AI notetaker?

A line in your engagement letter plus a verbal heads-up at the start of the call covers most situations, but check your professional body's current guidance — requirements are still evolving as these tools become mainstream.

What should we do with old transcripts we don't need anymore?

Set a retention period and actually delete transcripts once it passes, the same way you'd manage any other client file — most vendors let you configure this, but it's rarely switched on by default.

Are free versions of these tools riskier than paid ones?

Often, yes — free tiers are more likely to use your data for model training, and typically offer fewer admin controls. If you're using one for client work, the paid tier with training opted out is usually worth the cost.


Keep reading 🤍

Share
Written by
Kate, founder of Chronically Online

I help Gold Coast and Brisbane businesses grow with branding, websites and marketing that actually works.

Work with me ✦