Legal
OPINION OF THE WEEK: Beware Of AI Notetakers' Threat To Confidentiality

Lawyers can put confidentiality and privilege at risk if AI notetakers are used in meetings – one of the risks of this burgeoning technology that HNW individuals need to understand.
In thinking about all the use cases and risks that attend AI in today’s private client advisory sector, one term that ought to stick in the mind right now is “confidentiality.”
For those who don’t follow the twists and turns of AI closely, as well as legal cases, it might not appear obvious that one of the dangers of AI if not used properly is the destruction of lawyer-client privilege. In an industry where HNW and UHNW individuals and families understandably value their privacy, this is a big problem.
Many of us who go on Zoom, Teams and other platforms for business meetings might be told in advance – as we should – that “this meeting is being recorded” – usually in a cheerful voice. For journalists who haven’t mastered the grinding skill of shorthand – as I did decades ago – all these recording tools are a godsend.
But there is a downside.
As noted by the law firm White & Case in an April 23 report, entitled Attorney-client privilege and work product in the age of generative AI, two cases illustrate the risks – with very different results.
On February 10 this year, the US District Court for the Eastern District of Michigan in Warner v. Gilbarco, Inc denied a motion to compel production of documents that a self-represented litigant had prepared using a public AI chatbot. The court found that work product protection applied.
A week later, on February 17, the US District Court for the Southern District of New York in United States vs. Heppner reached the opposite result, ordering a criminal defendant to produce documents he had generated using another public AI chatbot while seeking legal advice.
The Heppner case was also mentioned at a recent media webinar, which I attended. The event was hosted by law firm ArentFox Schiff. Sarah Severson, a partner, explained the risks of AI in meetings where there are not clear understandings about what is involved.
Notes taken via AI could be “discoverable,” she continued. Automated transcripts and summaries are classed as digital documents that opposing counsel can subpoena in civil or criminal cases.
Severson said lawyers should always disclose their use of AI to clients in their engagement letters.
“AI does not owe clients a duty of confidentiality or accountability,” she said.
The root of the problem is that cloud-based processing, third-party vendor data access, and terms of service permitting model training eliminate the legal expectation of confidentiality.
This is a global issue.
The UK is an example, as recent cases demonstrate. In the case of UK v Secretary of State for the Home Department [2026] UKUT 81 (Hamid), the Upper Tribunal (Immigration and Asylum Chamber) delivered the first decision by an English court or tribunal to directly address what the legal professional privilege risks when confidential and privileged material is uploaded to open-source AI tools.
It is important to remember that jurisdictions such as Singapore share the common law traditions of the UK and US, for example. As case law builds up around the world, the AI notetaking issue will become a global one.
One of the points coming out of all this is that – as Severson said in the webinar – AI is a valuable tool. The ability to summarize and collect data is useful, to give just one example. The arrival of AI is, it should be said, also a reason why the grunt work that junior lawyers used to do is being replaced. These recent cases are also a reminder that large AI models, which rely on vast amounts of data, are, in a way, a sort of “public” field.
Fintechs are starting to address the problem of how public AI can
be. In
early June, Custodia, a Swiss privacy-first AI startup, said
it had launched Sentinel, a “physical AI thinking appliance
developed and designed from the ground up for executives, family
offices, scientific researchers, and any professional whose
intellectual property is too valuable and too sensitive to trust
to the cloud.”
Perhaps it is not a coincidence that Custodia is Swiss – the land
of bank secrecy (albeit no longer on cross-border matters),
where privacy is still highly prized, as it should be.
In its press release about the launch, Custodia said: “Rather than relying on pre-trained knowledge, Sentinel ingests your documents, understands their context, and retrieves precisely the right information to ground every answer it gives. Load thousands of files – financial records, research papers, legal documents, corporate history, correspondence – and Sentinel draws only from that store of knowledge. No hallucination from unrelated internet data.”
Well, that is the sales pitch, and this news service is looking into this area about private AI to see just how thick the walls of privacy really are. What is clear, however, is that if you are a lawyer or a client, or indeed a professional wealth manager, investor or professional figure having a confidential discussion, the AI recording gizmo should be turned off. Or, at the very least, the use of these devices must be clearly disclosed ahead of time, giving affected parties a chance to refuse