Legal
OPINION OF THE WEEK: Beware Of AI Notetaking Threat To Confidentiality

Lawyers can put confidentiality and privilege at risk if AI notetakers are used in meetings – one of the risks of this burgeoning technology that HNW individuals need to understand.
In thinking about all the use cases and risks that attend AI in
today’s private client advisory sector, one term that ought to
stick in the mind right now is “confidentiality.”
For those who don’t follow the twists and turns of AI closely, as
well as legal cases, it might not appear obvious that one of the
dangers of AI if not used properly is the destruction of
lawyer-client privilege. In an industry where HNW and UHNW
individuals and families understandably value their privacy, this
is a big problem.
Many of us who go on Zoom, Teams and other platforms for business
meetings might be told in advance – as we should – that “this
meeting is being recorded” – usually in a cheerful voice. For
journalists who haven’t mastered the grinding skill of shorthand
– as I did decades ago – all these recording tools are a
godsend.
But there is a downside.
As noted by the law firm White & Case in an April 23 report,
entitled Attorney-client privilege and work product in the
age of generative AI, two cases illustrate the risks –
with very different results.
On 10 February this year, the US District Court for the Eastern
District of Michigan in Warner v. Gilbarco,
Inc denied a motion to compel production of documents
that a self-represented litigant had prepared using a public AI
chatbot. The court found that work product protection
applied.
A week later, on 17 February, the US District Court for the
Southern District of New York in United States vs.
Heppner reached the opposite result, ordering a criminal
defendant to produce documents he had generated using another
public AI chatbot while seeking legal advice.
The Heppner case was also mentioned at a recent media webinar,
which I attended. The event was hosted by law firm ArentFox Schiff.
Sarah Severson, a partner, explained the risks of AI in meetings
where there are not clear understandings about what is
involved.
Notes taken via AI could be “discoverable,” she continued.
Automated transcripts and summaries are classed as digital
documents that opposing counsel can subpoena in civil or criminal
cases.
Severson said lawyers should always disclose their use of AI to
clients in their engagement letters.
“AI does not owe clients a duty of confidentiality or
accountability,” she said.
The root of the problem is that cloud-based processing,
third-party vendor data access, and terms of service permitting
model training eliminate the legal expectation of
confidentiality.
This is a global issue.
The UK is an example, as recent cases demonstrate. In the case of
UK v Secretary of State for the Home Department [2026] UKUT
81 (Hamid), the Upper Tribunal (Immigration and Asylum
Chamber) delivered the first decision by an English court or
tribunal to directly address what the legal professional
privilege risks when confidential and privileged material is
uploaded to open-source AI tools.
It is important to remember that jurisdictions such as
Singapore share the common law traditions of the UK and US, for
example. As case law builds up around the world, the AI
notetaking issue will become a global one.
One of the points coming out of all this is that – as Severson
said in the webinar – AI is a valuable tool. The ability to
summarize and collect data is useful, to give just one
example. The arrival of AI is, it should be said, also a
reason why the grunt work that junior lawyers used to do is being
replaced. These recent cases are also a reminder that large
AI models, which rely on vast amounts of data, are, in a
way, a sort of “public” field.
Fintechs are starting to address the problem of how public AI can
be. In
early June, Custodia, a Swiss privacy-first AI startup, said
it had launched Sentinel, a “physical AI thinking appliance
developed and designed from the ground up for executives, family
offices, scientific researchers, and any professional whose
intellectual property is too valuable and too sensitive to trust
to the cloud.”
Perhaps it is not a coincidence that Custodia is Swiss – the land
of bank secrecy (albeit no longer on cross-border matters),
where privacy is still highly prized, as it should
be.
In its press release about the launch, Custodia said: “Rather
than relying on pre-trained knowledge, Sentinel ingests your
documents, understands their context, and retrieves precisely the
right information to ground every answer it gives. Load thousands
of files – financial records, research papers, legal
documents, corporate history, correspondence – and Sentinel
draws only from that store of knowledge. No hallucination from
unrelated internet data.”
Well, that is the sales pitch, and this news service is looking
into this area about private AI to see just how thick the walls
of privacy really are. What is clear, however, is that if
you are a lawyer or a client, or indeed a professional wealth
manager, investor or professional figure having a confidential
discussion, the AI recording gizmo should be turned off.
Or, at the very least, the use of these devices must be
clearly disclosed ahead of time, giving affected parties a chance
to refuse.