A.I. note takers are making lawyers nervous
nytimes.com
nytimes.com
But the real danger with these IMO is that they're turning casual conversations into a permanent record, and one that will be completely discoverable in court, should the company get into trouble later.
The problems start when using conference room audio or someone is on their laptop mic. If they miss a word they never do unintelligible, they just start playing madlibs based on the rest of the sentence.
We just went through a round of 100+ (non-sensitive) VoC interviews and they really cut down the workload of compiling all of the feedback. If the audio was a little shaky though, we pretty much had to throw away the transcripts and do them from scratch like we used to.
Imo this is the single biggest flaw of LLMs. They're great at a lot of things, but knowing when they're wrong (or don't have enough information to actually work on) is a critical flaw.
IMO there's nothing structural about why they shouldn't be able to spot this and correct themselves - I suspect it's a training issue. But presumably bots that infer context/fill in the dots rank better on what people like... at the cost of accuracy.
Not always though. Let’s say that someone is saying ”1 2 3 4 <unintelligible> 6 7 8” then it will happily write 5 in the middle and give it good confidence as based on the context, it is the only likely word. Varies between TTS providers though.
Basically, why they are so good in average is that they estimate what is said most often based on the context. The context being then not only the audio but what was transcribed previously.
And if you don’t want it to be based on what is most likely to be said in context and only based on the audio around 1 word it is going to be awfully wrong most of the time.
Add accents, and half the words would be indistinguishable from each other (note that word "indistinguishable", ironically, would be quite distinguishable).
People parse things like that in so much context, based in their own understanding of a situation, their grasp on speakers accent or speech impairments, etc.
Add to that that most native english speakers blur words together. The pause that in some languages is used to separate words, is used in english to separate sentences. English language as spoken doesn't separate words natively.
The text-to-speech before LLMs was meh. I think it's the ability to generate filler for uncertain words that makes it feel magic compared to before.
Lots of tools in our toolbelts to do better uncertainty calibration but it trades off against other capabilities and actually can be rather frustrating to interact with in agentic contexts since it will constantly need input from you or otherwise be indecisive and overly cautious. It’s not technically a limitation of transformer architecture but it is more challenging to deal with than other architectures/statistical paradigms.
Like you can maintain a belief state and generate conditional on this and train to ensure belief state is stable and performant. But evals reward guessing at this point, and it’s very very hard to evaluate the calibration in these open ended contexts. But we’re slowly getting there, just not nearly as fast as other capabilities.
The confidence level can be any, as long as it's reported accurately often enough. "This is my conjecture, but", "I'm not completely sure, but", and "most historians agree that" are all perfectly valid ways to start a sentence, which LLMs never use. They state mathematical truth, general consensus, hotly debated stances, and total fabrication, with the exact same assertiveness.
> ways to start a sentence, which LLMs never use
A huge part of the problem is we've invented a document-generator setup which exploits human cognitive illusions, and even the smartest person can't constantly override the instinctive brain-bits that "sees" fictional entities and infers the intent of a mind. That makes it weirdly-hard to discuss the setup's shortfalls or how to improve it.
To wit: The machine does not possess any kind of confidence about how Rome fell. Or even whether Rome fell. It has "confidence" about which word/token will next in a "typical" document given the document-so-far has text like "How did Rome fall?" It may be straightforward to burn money training the system so that its "typical" story never has a computer-character with confident words about Roman history, but that's just papering over the underlying problem.
TLDR: We can't fix the thinking-habits or beliefs inside the mind of an entity that doesn't actually exist. Changing the story-generator to contain a tee-totaling Dracula dispensing life-advice doesn't mean we "cured the disease of vampirism."
(Which is intensely depressing to a human that doesn’t.)
If you ask a good model something that makes no sense, it will tell you it makes no sense and it can't answer the question; so I know it's possible.
The reason AI companies won’t do this of course is it would completely ruin the illusion of confident confidence these machines project.
That's why I'm still cautiously optimistic about LLMs somewhere being good enough. I don't know if or when someone will manage to do it, but I'm hopeful.
Do stochastic parrots dream of the number of 'e's in "electric sheep"?
Of course there's a secondary problem that the model may then overuse the unintelligible option, but that's something that's a matter of training them properly against that eval.
You could also try thresholding the output based on perplexity to remove the parts that the model is less sure about, but that's not going to be super accurate I think.
AA-Omniscience is a knowledge and hallucination benchmark that rewards accuracy, punishes bad guesses and provides a comprehensive view of which models produce factually reliable outputs across different domains. The benchmark contains 6,000 questions across 6 major domains, derived from authoritative academic and industry sources and generated automatically using an LLM-based question generation agent to ensure unambiguity, scalability and factual precision
Which reminds me that that's another big issue with LLMs - they'll blindly do whatever you ask them to, without pushback. (Again, I miss 3.5/3.6 era Sonnet which actually had half a spine. Fuck anthropic for blindly chasing coding benchmarks at the cost of everything else.)
I've engaged in several "CMVs" (or "tell me why X is bad") with LLMs, and very often it's clear it's just saying stuff to say it, giving very terrible points on unjustifiable positions that collapse the moment I counter argue even slightly rationally.
The point isn't that it's unexpected. It's that prior text-to-speech systems were much better about this particular failure mode, prone to spitting out entirely incorrect words but not rephrasing entire sentences.
This is a particularly bad failure mode because people don't notice it.
> What we need are tools that embrace that and ping the agent to validate what it just said or double check.
This is not a problem that can be fixed by throwing more AI at it. It's a shared problem to all such systems, whether they're audio-text transformers or LLMs. Agentic review would just further push the system towards creating output that looks correct, but is not.
LLM translation does the same, yielding more natural text, but generally not better translation. In several cases, especially the "easy" translation between similar languages (e.g. within a language group like Germanic or Nordic) LLM-powered translation is notably worse than more primitive "word & phrase book" systems, tending to change the meaning of the text in order to have good grammar whereas these older systems would give crude or grammatically incorrect translations that still retained the core meaning.
Maybe it depends on topics or length, for me it's usually 1-2 paragraphs of a German article to share online.
Are you native in both languages? If you are only native in one of them, it would be insightful to find if people with your skillset but native in the language you are not have the same opinion as you.
Sadly there are no examples here to compare.
Same languages, same use case. My experience is different. On both google translate and others. ¯\_(ツ)_/¯
This is a solvable issue, the current model and harnesses just aren't made with that assumption - hence they're doing "best effort while guessing if unsure".
Give it a few more months to years and things will likely settle how he pitched - at least in the context of note taking: only let it become "lore" if it didn't have to guess a word.
Currently there is basically only one mode - and it's optimized for conversation. The note taking is just glued on with that functionality as the backbone, and that's probably not going to stay.
I'm hesitant to admit even that. Like any computational linguistics problem, accuracy relies on coverages of all levels: form morphology, through syntax and semantics to speech act and world knowledge.
I worked with state of art speech recognition in healthcare setting. The model was specifically trained on small set of languages with emphasis on covering medical terminology.
It worked great for conversations most of the time, but sometimes messed up very badly. For instance when patient would mention the name of a relative, a street address or phone number. Spelling out an email address would mess it up completely.
It's just like when you're a horrible typist and rely on spell checking: The red squibles are gone, but the story no longer makes sense. Or when you "autofix" a syntax error, but the meaning diverges from your intention.
As the technology improved the number of words decreases, but the mistakes get more severe.
If the prediction strength is below X, put an indicator that it couldn't make a valid prediction?
Someone tell Altman
- the person said 8 to 10
- LLM transcribed as 18
Granted, the person had a foreign accent and didn't enunciate very clearly. But I knew they meant 8-10 if for no other reason than 18 didn't make sense given the context. But the AI isn't smart enough, and then 18 goes into the record.
But key in my prompt is asking 1) for it to flag any low confidence or context-nonsensical statements in the transcript, with the timestamp, so then I can listen to the original audio and either clarify, correct, or say "I couldn't understand that either, here's my best guess and mark it low confidence", then 2) which I see as critical: Claude also is told to create a "context" document that it maintains based on my answers, so it starts to gather ASR things like "transcript commonly hears A B and C as variants of name X", who is who, internal product and project names and context info on them. 3) Claude is told specifically to read this prior to summarizing the transcript, and to consult it as it is doing so, and to ask me on anything it's not confident on.
What is then starting to get quite powerful for me is moving from full text search of my meeting notes in Obsidian (I'm a PM in a lot of meetings), but I can point Cowork to the Obsidian notes folder (because they're all Markdown) and start doing rich "querying" of it. "When did [stakeholder] first mention [feature] as a release blocker?" and it can point to the meeting.
My system works well, and I've done a bit to fine tune the automation and friction reduction, and it's a bit easier to manage because I'm not generally creating summaries for broader consumption but as my second brain (I have a separate prompt that utilizes some of that "knowledge" to build those).
One thing I've found helpful with this is moving the summarization itself into something with "context/memory". Krisp is capable of generating summaries but can't/doesn't review prior transcripts. Its role is just "give me the transcript as you heard it".
Or mostly just confirm what you half-remembered?
Trying to figure out whether the value of the loop is rediscovery or just precise lookup.
Got a team with Indian, Chinese, Texan, British, and Australian? Your A.I.-powered translation tool is going to get 80% of your conversation wrong.
Half- vs. full duplex. Headphones is all you really need, though of course a directional mic and/or one closer to your mouth will yield a clearer audio recording as well.
Isn't that what people do?
Nixon tapes for example: https://kagi.com/search?q=site%3Anixonlibrary.gov+%22unintel...
RTO problems
But the summarization feature is where the most ridiculous errors and omissions happens.
I sincerely hope these aren't used in court.
Potentially sinister due to the biases of the model, as the model may have been trained using internet content that has a lot more fictional titillating evil overlord board meetings than the actual mind-numbing real thing. Training that included extremist anti-corporate dogma might even bias the language models towards hallucinating the worst possible misinterpretation.
I've seen whisper hallucinate whole legal arguments whole cloth when the AGC was broken in it and the audio went quiet-- so I think the language models in it are more than powerful enough to politically load a transcript.
Good practice should be to minimize any unnecessary stored records because ANY record just means more processing costs in discovery and god knows how much extra cost in litigation should it happen to have an unfavorable interpretation in light of some impossible to anticipate future litigation.
But if AI transcription must be used it would be might be prudent to save a copy of the original audio along with it.
Ironic use of “sinister” when you probably mean “nefarious” and don't mean to perpetuate silly old superstitions about “left-handed” people being evil :p
I’ve been saying it since the mid-10s, but it’s worth repeating: data isn’t gold, it’s more like oxygen in a room in that the higher the concentration, the more likely it is to poison the inhabitants or explode with an errant spark (lawsuit).
Collect only what’s needed to perform the function, and store it only as long as necessary for compliance. Anything else is going to spool counsel.
Limiting data retention doesn't mean hiding bad things, it means limiting exposure in general. The more of a thing - anything - that you have, the bigger a target you are to bad actors. By extension, companies holding vast sums of data beyond what's needed to process a given transaction or remain compliant with the law end up placing themselves at risk of being targeted and said data used as leverage against them.
You don't limit data to hide bad shit you're doing, you limit it to avoid others using it to do bad shit against you or your customers. If someone or something is engaged in bad shit, there will always be evidence somewhere regardless of data retention policies.
I would add that their is no guarantee their are correct as well.
“At timestamp X, person Y said Z” says the robot, and then you dutifully scrub the audio to timestamp X to verify.
I’m overall an AI optimist but this is going to blow up in people’s faces very quickly. (I would explain this to my manager but he has AI note taking turned on in all his meetings!)
And that’s not even getting into the use of it for sensitive clinical notes in eg. mental health…
Also social settings will change, when everything you say stays on record forever in every meeting...
The parts that aren’t privileged. On the other hand, perhaps the truth-seeking function of the justice system will be better equipped than before when we had to rely on (more) faulty human recollection.
I have a friend who works at a large-ish company that imports and manufactures things (in one of the clerical/quantitative professions). A few years back, they had the IT department go on a kind of "inquisition", wherein they forced employees to disable the summarization function that came with MS Teams, and threatened to fire them if they did not. The resistance to this demand was surprising -- most people are clueless about the cost of their own convenience. Worst of all, people would zone out of meetings, because the AI was producing summaries, which they would then never read.
The effect of the technology was that it made meetings infinitely more expensive, because the supposed benefit of meetings was nullified by complacency, _and_ it made the meetings a liability (incorrectly summarized meetings, that could be used in the discovery process, sure, but could also be sold by MSFT as a kind of market-research-data to competitors in the space).
Nothing illegal has to happen in these meetings at all, for this tech to cause an infinity of problems for the corporation. Every employee that uses these is effectively an unwitting spy. And if that is the case, then the meetings might as well be recorded and uploaded to YouTube (or whatever people watch these days)[1].
[1]: Maybe this is the future. Which I am okay with, but only if the entire planet has to do it, and the penalties for not doing it are irrecoverably severe.
Be careful what you wish for. Particularly when it involves tech that often gets it very, very wrong.
It is true accusation and potential for success of it.
The only question is whether everyone gets a slice, or it ends up locked down so only governments and corporations have access to it. Obivously I come down on the sousveillence side of the fence - it's the lesser of two evils. If it exists I want everyone to have it, and you can't stop it existing.
Modernized. Industrial AI scale.
I’ll be honest, this is something that I hope AI note taking tools capture and incorporate into summaries of the company’s status. Especially if they act as an intermediary without revealing the specific person who said it. There’s a lot of information latent within organizations that doesn’t get properly shared due to concerns of retaliation or simply embarrassment that would benefit everyone by being communicated sooner.
Maybe some smaller shops are not like this, but the bigger your company is, the more you'll find this type of thinking to persist.
In theory, I do like your idea - anonymously cascading feedback upstream. I just see no avenue for this to succeed in practice.
"It seems that starting in 2025 one of your employees began spreading many bigly unfair and hateful lies about Dear Leader in team meetings. We at the Department of Truth would hate to see your operating license revoked for encouraging such unpatriotic behavior..."
Even today, I generally assume that my phone could be tapped; even when talking with my trusted work colleagues, friends, and family. I'm extra careful about dirty jokes or "grey morality" in video conferences and email.
The same applies to speaking with lawyers. You never know when some motivated asshole wants to twist your words out of context, and the possibility of a recording just enables that behavior.
---
I know enough about security and encryption to know that unless I've exchanged keys physically with someone else, there really is no guarantee that someone hasn't compromised a certificate somewhere. (IE, a "secure" connection on the internet is secure enough for a credit card.)
This is horrifying. Why do you feel the necessity to self-censor? What consequences do you anticipate?
And then add to that how easy it is to record phone conversations with today's phones (I've done it), it's easier on the brain to assume it's being recorded as opposed to wondering if it is.
But yes, I don't care about my dirty jokes being recorded :-) Illegal activity? Sure. But I solve that problem by not doing illegal things.
And yet, we still see comments of people horrified when you said you assume as default that someone (or more likley, something) is listening.
The normalcy bias is too strong.
My primary worry would be things being taken out of context when circumstances change later. Maybe there's lawsuit discovery, or maybe you have a falling out with a coworker who tries to defame you. The last thing you want is a motivated adversary to be given access to a wide trove of things that could be reframed to be used against you.
And it's not just off-color jokes or insensitive comments. At one job, we had a project that involved "fudging" billable numbers for a completely legitimate purpose. I was the one insisting that we don't use that term in writing at all to avoid any potential future misunderstandings. Call it an "adjustment" or "algorithmic modification" or something, but not "fudging" or "fabricating." Same kind of reasoning.
And I make a point of seeing the people I care about face to face.
That's a good policy when interacting with any human or device in a work context.
Adding to that: If you live in a one-party consent state assume you're being recorded by any of the parties in a face-to-face conversation, too.
Yeah-- it sucks that the world is this way. I deal with it. What I don't want to see are draconian controls on technology (which will ultimately be ineffective) in an attempt to put the genie back in the bottle.
Even if you don't live in a one-party consent state, assume you're being (perhaps illegally) recorded by any of the parties in a face-to-face conversation too.
Maybe AI agents that work in our personal best interests?
Total oversimplification. The fact is the privilege is a rule totally in the hands of the court. Every time a new communications technology come up, someone shouts about privilege but the courts still accept it. (Telephones, cell phones, emails, IMs, zoom court, each have had their day in the A-C privilege debate and been accepted.) What matters is that the parties intended and expected communications to be privileged.
As an example. I had a crim law prof who had been a NYC public defender in the 70s/80s. She had regularly interviewed clients at Rikers Island. All interviews were listened to by guards and she said you could even pay to get a copy of the recording. But these interviews were still covered by attorney-client privilege. No court would allow such evidence, but that doesn't mean that the prison could not use it for jail safety. Why does this matter: Because the presence of a third party doesn't mean anything. This isn't magic. An eavesdropper does not nullify the spell. Whether something is or is not privileged depends on the rules followed in the local jurisdiction, and no jurisdiction has ever followed a simplistic "presence of a third part" rule.
Until someone demonstrates an example of an AI actually leaking privileged information, courts are going to chalk it up as just another electronic tool for recording communications.
> In February 2026, Judge Jed S. Rakoff of the U.S. District Court for the Southern District of New York ruled that a defendant who pasted information—including details conveyed by his lawyers—into a public, consumer-grade AI chatbot (specifically Anthropic's Claude) completely waived his attorney-client privilege.
But maybe if you are using a transcription tool that happens to send your audio through the Anthropic APIs, the ruling would be different?
> What matters is that the parties intended and expected communications to be privileged.
I would contend that your summary, not theirs, is a oversimplification. Jurisdictions will obviously differ, but privilege does not attach merely because of the intent and beliefs of the lawyer and client.
IMHO we should just assume the R word before every verb in every legal discussion. That is how reality works. These are not spells. If I express that I intend something to be private, then announce it using a megaphone at a basketball game, my intention is no longer reasonable regardless of what magic words I have thrown into my communication. Act like an idiot and a court will treat you like an idiot.
The whole point should be that the people in the meeting can actually focus on the conversation rather than half listening while trying to write down enough notes to remember it later. If you're paying people good money to be in a meeting, having them spend half of it doing low quality note taking is a bit mad.
This is basically the reason I've been building Whistle Enterprise (https://whistle-enterprise.com). I'd much rather have something where I choose to record a meeting, process it locally, generate the document and then decide what to keep or delete. I mean yea, it still creates a record so it doesn't solve the legal / discovery side, but at least you're not also adding a random third party into the middle of every conversation.
I've had doctors write horribly-incorrect notes in my digital chart after appointments, so please don't think I'm trying to be a Luddite.
I found the legal profession to be a prime candidate to disruption using LLMs, especially the initial consultation phase (Do I have a claim?). One of the things that's protecting the status-quo, for the time being, is the law - for example in the UK you can't actually offer any sort of legal services without being SRA-accredited. There's also lots of secrecy within the profession, and lots of procedural tricks that lay people are not aware of. AI could make all of these more accessible for the lay person.
How can AI learn the secret procedural tricks? Where's the training data?
And is there a legal consequence for AI giving bad/incorrect legal advice? Can they get disbarred?
Can you be sure the AI tool even read an entire piece of legislation (inb4 "you can't with lawyers either" : I thought we're aiming for better)?
How will they understand the inner workings of courts, CPS etc? How will they network with other lawyers for advice and learning (how will the LLM train on that)?
Of course not :) but unfortunately I've received half-truths and outright lies from actual solicitors, while AI has mostly given reliable advice, even if not procedurally perfect.
There's lots of guarding and unwritten rules in the legal profession so this is not something that will be straightforward to train on, but once done, even if imperfect, will bring legal access to the masses.
"2028 – A Dystopian Story By Jack Ganssle":
http://www.ganssle.com/articles/2028adystopianstory.htm
Known as ’The Rule of 26’, which is sometimes given as a reason NOT to keep engineering notebooks etc. By Federal Rule 26 you are guilty if you did not volunteer the records before they are requested. Including any backups.
From Cornel Law:
LII Federal Rules of Civil Procedure Rule 26. Duty to Disclose; General Provisions Governing Discovery
Rule 26. Duty to Disclose; General Provisions Governing Discovery
(a) Required Disclosures.
(1) Initial Disclosure.
(A) In General. Except as exempted by Rule 26(a)(1)(B) or as otherwise stipulated or ordered by the court, a party must, without awaiting a discovery request, provide to the other parties:
(i) the name and, if known, the address and telephone number of each individual likely to have discoverable information—along with the subjects of that information—that the disclosing party may use to support its claims or defenses, unless the use would be solely for impeachment;
(ii) a copy—or a description by category and location—of all documents, electronically stored information, and tangible things that the disclosing party has in its possession, custody, or control and may use to support its claims or defenses, unless the use would be solely for impeachment; …
[1] There's actually a subset of this, which includes "...until you are legally allowed to delete it, then delete everything". This is driven by regulation (e.g. SOX in the US).
General conclusion:
Corporate litigation is mostly just a series of self-investigations so that both sides can learn what both sides actually know, given that neither side knows much about themselves OR the other side. At the same time both sides are trying to stop the other side from getting the judge to order them to do more investigating.
If Mark Z was exactly himself but not successful and filled with resentment, he would write something like this. The smugness, the egotism of that story. It's so obvious that engineer types, like almost all middle class variations, are part of the problem and somehow think they are the solution. Bleh.
Do these systems not share data with the AI servers? Or are they all local (on-site, not on-computer)?
I am totally baffled by the trust people put on these systems, sharing with them the most obviously private data.
- we promise not to share PII (defined as narrowly as possible)
- we promise not to share payment information except with our payment system
- if you pay us, we promise not to train LLMs on your data
- you agree that everything else can be used for any business purpose, including marketing, intelligence gathering, and "sharing with our 1735 trusted partners".
The average person doesn't care about online privacy.
https://www.pewresearch.org/internet/2019/11/15/americans-an...
To me, that says the average person doesn’t care enough (they care, just not enough) to do anything about it.
They might care enough to spend 5 seconds signing a petition, but not enough to spend 5 minutes installing an ad blocker, and definitely not enough to spend 5 hours doing anything more extreme like de-googling their life.
Especially real-time transcription where the AI actually takes notes (instead of just recording every word and has a dump of it somewhere) can be appealing. Then there isn't any record of the raw sentences, and things that aren't relevant are immediately discarded without any written record.
OpenAI's realtime whisper and other such models will become the default over time.
A lawyer may just accept it, believing the summary accurately represents the transcription. When AI summarizes a meeting, it does not catch the nuances of what actually happened. An offhand or dissenting comment may be critical but not caught in the summary. The AI compresses but can easily miss important details that matter. The consequences of only using the AI summary are potentially catastrophic. Context could be easily misunderstood, critical details may be left out, things that weren't actually said could be accepted as fact.
[1] https://www.findlaw.com/criminal/criminal-legal-help/what-ar...
That feels hinky to me...
Seems to have had a good reception so far within the legal world who was my original target market for this.
Is it as powerful as the services using insane compute? No. Does it do a pretty decent job without using a third party? Yes.
No Javascript, no CAPTCHA, no geoblocking, no DDoS directed at blog
https://static.nytimes.com/narrated-articles/synthetic/artic...
Works where archive.is is blocked
Text-only, no DDoS directed at blog
view-source:https://www.nytimes.com/2026/05/09/business/dealbook/ai-notetakers-legal-risk.html
Save as 1.htm
Something like egrep -o "(\"text\":\"[^\"]+)|(\"textAlign\":\"LEFT\")|(\"url\":\"[^\"]+)|(\"__typename\":\"TextInline\")" 1.htm \
|sed '/\"url\":\"/{s/??.*//;s/$/\">/;s/.\{7\}/<a href=\"/;};
/\"__typename\":\"TextInline\"/{s/\"$/<\/a>/;s/.\{24\}//;};
s/\"textAlign\":\"LEFT\"/<p>/g;/\"text\":\"/s/.\{8\}//' \
|sed '1s/^/<meta charset=utf-8><meta name=viewport content=width=device-width>/' > 2.htm
rm 1.htm
firefox ./2.htm
NB. Javascript and CSS interpreters are needed only for Datadome challenge. The following DNS data, e.g., A RRs, are required ct.captcha-delivery.com
geo.captcha-delivery.com
www.nytimes.com
g1.nyt.com
No other DNS data is requiredWould you be willing to license this code as GPL-3.0-or-later, or some other free license? I'd like to include a JavaScript derivative of this for Haketilo (a userscript manager). I would add it to a collection of scripts that aim to replace proprietary JavaScript here: https://codeberg.org/JacobK/unfinished-site-fixes/
Apparently not everyone listens to audio at the same speed
Although I definitely think that any alternative approach would be fraught with legal peril, I strongly disagree that this SHOULD be the state of the law. AI note-keeping tools, chatbots, and other AI-generated services are not sentient beings, but most importantly, they are not natural or even artificial persons. The whole principle of waiver in the area of privilege is based on the notion that an otherwise private attorney-client communication, or document created that is covered by the attorney work-product doctrine, has been copied to or shared with a THIRD PARTY. A third party is a party, which at minimum is a legal or natural person -- perhaps a corporation or LLC, but not a computer, dolphin, chimpanzee, or chair. AI note-keeping tools, models, chatbots, etc., are obviously not natural persons (human beings), but they are also not even artificial persons. They cannot sue or be sued, own property, enter judgments or be held liable, or have any legally enforceable obligations. Legally, chatbots have no "standing" or personhood, even of the artificial sort assigned to corporations and LLCs (which, although not human, can sue or be sued, own property, obtain judgments, have legally enforceable obligations, etc.). There simply is no logical theory of waiver due to copying a third party that gets triggered by "conversing" with a chatbot.
The stronger argument I have seen, which Judge Rakoff cited about 6 weeks ago in an SDNY ruling, and that perhaps makes more sense (at least on its face), is to point to the ChatGPT or Claude Terms of Service. Those Terms make the contents of any chat histories between users and the AI service capable of being copied and utilized for training or other purposes. However, those terms of service are also quite similar to the same provisions often found in email and SMS text message providers, and for Zoom, Teams, WhatsApp, and plenty of other channels used by attorneys to communicate with clients. I haven't had the opportunity yet to contrast them, but I would be surprised if the software products routinely used to facilitate attorney-client conversations don't contain substantively similar if not identical provisions to the ones that Judge Rakoff found persuasive to deem privilege waived with respect to client-ChatGPT conversations. I've been trying cases for nearly 20 years across multiple jurisdictions and have never even seen anyone argue, at least not since the dawn of the email era at the very beginning of my career, that attorneys and clients who share privileged communications via email have waived the privilege because of Outlook's or Gmail's terms of service that say that the service can train on the contents of the emails for whatever reasons. In fact, I do recall that argument being made a long time ago, and I can say that it has been squarely rejected out of hand in every jurisdiction and court I have ever appeared. I don't know anyone who would even make such an argument today. (I'll distinguish the different case of an employee suing their employer but using the employer-issued email account to communicate with outside counsel about their employment claims; that scenario really is a waiver because the employee's contract with the employer typically includes a provision that the emails are owned by the employer and may be reviewed by them, which is very different than having an automated Gmail or Outlook script processing metadata or even data from massive numbers of emails.) In every jurisdiction I have ever appeared, the waiver of privilege only arises from copying a third party, not from using email, or text, or Teams, or Zoom, to communicate with a client in a manner that otherwise would be considered privileged but for the medium of communication. It is possible that under particular terms of service, a different result might be warranted, such as if the model also includes terms that say the engineers might read the actual contents of chat histories, but otherwise, the OpenAI or Claude Terms of Service seem like an awfully thin reed upon which to stack the entire weight of this theory of waiver.
This is not legal advice, and no attorney-client relationship is formed; I'm just stating my opinion while indicating that this is not the way I think the law should be headed.
If you receive even just limited legal liability protections ... you are receiving a public benefit and you should be required to record every single conversation, including if you involve your personal devices, every single personal conversation you had on your personal devices of any kind, short of reporting accidental contamination.
It seems people are way too ok with all the abuse and criminality of our politicians and executives at all levels and accountability really needs to be reintroduced into the system. Or are we simply going to wait for a coulee more Luigi events and the ruling class then just dropping the mask on the prison system surveillance state they have constructed around even the USA?
But I realize that is probably wishful thinking because it seems we long crossed the threshold of accountability, where the citizens had enough power to actually affect a requirement that all meetings and communications of any and all politicians, bureaucrats, and executives be recorded and even made public in most cases.
Inaccuracy in meeting minutes?
Leaking private info, re security of notes?
I have never used them (don't trust them to accurately capture what is important in a meeting vs just noting what's mentioned), but the concept seems very useful to me.
> A trendy productivity hack, A.I. note takers are capturing every joke and offhand comment in many meetings. They could also potentially waive attorney-client privilege.
By now everyone knows that AI notes that aren't curated by a human will catch every silly thing that was said in the meeting while omitting the context of the tone or body language. Something as simple as "yeah, right" has vastly different meanings depending on how it was said. In a different context it's already been established that using AI breaks client attorney privilege [0] and this concern has been raised before by law firms [1][2] or the American Bar Association [3] (you can just hit escape before the paywall loads to see the full content). A judge will have to weigh in on this one too.
I don't know what's with the wave of paywalled articles that keep making it to the front page without any workaround included in the submission. Even when you coax the text out of the page source, they're not very insightful to begin with.
[0] https://perkinscoie.com/insights/update/federal-court-rules-...
[1] https://www.smithlaw.com/newsroom/publications/the-silent-gu...
[2] https://natlawreview.com/article/when-ai-takes-notes-protect...
[3] https://www.americanbar.org/groups/gpsolo/resources/ereport/...
Not for me - there was no viewable text.
To be fair, the attorney-client privilege should be completely technology/medium agnostic. If the intention is to have that info stay between client and attorney, nothing should change this.
I suspect what isn't being said by the lawyers is they want to keep attorney client privilege so they can outright lie.
As a trial attorney for over 40 years, that is an incredibly offensive take. Attorney/client privilege is usually litigation related and a prime example of the nature of conversations involve our advising our client of the prospects of prevailing at trial and whether to engage in settlement discussions with money amounts involved. If some day you are sued and you have a conversation with your lawyer about your financial worth as well as how much you are willing to pay to the person suing you - and that information ends up being turned over to the person suing you - you won't be so snide about the importance of attorney client privilege.