Direct answer — Is AI voice dictation protected by attorney-client privilege? Not automatically. Privilege protects confidential lawyer-client communications, and it is generally destroyed by voluntary disclosure to a third party. Sending audio or transcripts to a cloud AI vendor can be that disclosure. Whether a given vendor breaks privilege is an unsettled question of law and depends on contract, configuration and jurisdiction. Dictation processed entirely on your own device never creates the disclosure in the first place.

This article is general information, not legal advice. Privilege is jurisdiction-specific: what follows describes US attorney-client privilege, legal professional privilege in England and Wales, and the professional secrecy regimes of civil law countries as three related but distinct systems. Take advice from qualified counsel in your own jurisdiction before changing how your practice handles privileged material.

Through the first half of 2026, a wave of law firm alerts converged on the same warning: attorney-client privilege AI transcription risk is no longer theoretical. Goodwin, Duane Morris, Ogletree Deakins and Norton Rose Fulbright all published on it, and two courts — one federal in New York, one tribunal in England — reached decisions that point the same way.

Software vendors have been quiet on this. The dictation category sells accuracy, speed and integrations, and stops short of the question a litigator actually asks. This guide covers the mechanism of waiver, what the 2026 decisions did and did not hold, the questions to put to a vendor, and the architectural answer that removes the exposure. For the practical setup side, our guide to voice dictation for lawyers and barristers covers workflow, vocabulary and hardware.

What destroys attorney-client privilege, and does AI transcription trigger it?

Voluntary disclosure to a third party. That is the mechanism, and it is much older than AI. Goodwin’s April 2026 alert puts it in one line: “Attorney-client privilege is generally destroyed by voluntary disclosure of privileged communications to third parties.”

Two features of the doctrine matter for tooling decisions. Privilege attaches to the communication at the moment it is made, and it belongs to the client rather than the lawyer.

The consequence is unforgiving. Norton Rose Fulbright states it plainly for the UK equivalent: if privilege is waived by the use of an open-source AI tool, “there is no mechanism by which privilege can be retrospectively asserted or recovered.” A confidentiality policy written after the audio has left the building does not recover anything.

Whether a transcription vendor counts as that third party is the open question of 2026. Goodwin frames it as unresolved: “Whether an AI transcription vendor qualifies as a functional equivalent of a legal assistant or stenographer, thereby preserving privilege, is an unsettled question of law.”

That comparison is the crux. Courts have long allowed privilege to survive contact with necessary intermediaries — the line of authority running from United States v. Kovel covers accountants, translators and experts brought in at counsel’s direction. Whether a subscription transcription service sits inside that line has not been resolved.

Goodwin also notes the exposure is wider than outside counsel: in-house legal teams, companies under investigation, and board strategy discussions attended by counsel are all equally at risk.

Duane Morris adds the operational failure mode that firms actually hit. Its February 2026 piece warns that automatic recording of meetings where legal strategy is discussed risks exposure to third-party vendors, and tells attorneys to check that AI transcription is not switched on by default in their conferencing platform.

What did courts say about AI and privilege in 2026?

Two decisions landed within eight weeks of each other, on two continents, and neither was a sweeping ban. Both turned on the same fact: a public, consumer-grade AI tool whose terms permitted the provider to keep and reuse the input.

United States v. HeppnerHamid [2026] UKUT 81
Forum reportedSouthern District of New YorkUpper Tribunal (Immigration and Asylum Chamber), England
Dates reportedOral ruling 10 Feb 2026; written opinion 17 Feb 2026Reported by Norton Rose Fulbright, April 2026
QuestionDid privilege ever attach?Was existing privilege waived?
Reported outcomeDocuments drafted with a public AI platform protected by neither privilege nor work productUploading privileged documents to an open-source AI tool waives legal professional privilege
WeightOne district court decision — persuasive, not bindingNot binding on other courts, likely persuasive
Carve-out notedEnterprise or counsel-directed use might be decided differentlyClosed systems inside a secure network distinguished

As reported by Ogletree Deakins, the New York court found confidentiality fatally compromised because the platform’s terms of service expressly permitted data collection, retention and use for model training. Ogletree also reports the court rejected the argument that privilege could attach retroactively once the material was later shared with counsel.

Norton Rose Fulbright reports the English tribunal’s language as: “uploading confidential documents into an open source AI tool such as ChatGPT is to place this information on the internet in the public domain and […] waive legal privilege.”

That is consistent with guidance already published by the Courts and Tribunals Judiciary of England and Wales in October 2025, which instructs judicial office holders that “any information that you input into a public AI chatbot should be seen as being published to all the world.”

Read the carve-outs as carefully as the holdings. Ogletree stresses that Heppner did not hold that all AI use waives privilege, and reports the judge acknowledged the outcome might differ with an enterprise-grade tool carrying contractual confidentiality, no training on inputs, or zero-retention policies.

Does attorney-client privilege mean the same thing outside the United States?

No, and treating the world as one regime is how compliance work goes wrong. “Attorney-client privilege” and the “work product doctrine” are US concepts.

England and Wales protect legal professional privilege, made up of legal advice privilege and litigation privilege. Civil law jurisdictions across Europe generally frame the same territory as professional secrecy, an obligation on the lawyer with its own scope and its own exceptions.

Goodwin flags the practical consequence for anyone using cloud tooling: “In cross-border contexts, privilege standards may differ, further complicating risk assessments where transcripts are stored or processed outside the United States.”

So the location of the server is not only a data protection question. It can change which privilege regime a court applies to the transcript. The same reasoning drives sector rules elsewhere — see HIPAA-compliant voice dictation for medical professionals, where the analysis concerns protected health information rather than privilege but the architecture question is identical.

What should you ask an AI dictation or transcription vendor?

Ask about possession and permissions, not features. Goodwin’s due diligence list translates directly into procurement questions:

Duane Morris adds the ones that come from practice: confirm client data is not stored on external servers or used to train newer models, disclose the tool’s use to clients, and set transcription to off by default until consent is obtained and documented.

Goodwin’s governance section goes further, recommending categories of meeting where AI transcription is prohibited outright: “privileged discussions with legal counsel, sensitive negotiations, or other high-risk contexts.”

One question collapses most of that list: does any audio or text leave the device? If the answer is no, the retention policy, the training clause, the cross-border transfer and the subpoena-the-vendor scenario stop being live issues — no vendor holds a copy. Weesper Neon Flow is designed to answer that one with a no: the speech model runs on your own machine, so there is no vendor in the chain to serve a subpoena on.

Which technical criterion removes the third-party disclosure risk?

On-device processing. A dictation tool that runs the speech model locally never transmits the recording, so the voluntary disclosure that destroys privilege does not occur.

That is a narrow, verifiable claim about one failure mode, not a compliance guarantee. Here is what it does and does not change:

Question a court or an opponent may askCloud AI transcriptionOn-device dictation
Did the audio leave the device?YesNo
Does a third-party vendor hold the content?YesNo
Do the terms permit retention or model training?Depends on plan and contractNothing transmitted, so nothing to retain
Can the vendor be subpoenaed for the recording?Yes — it holds a copyNo copy exists outside your machine
Is a voiceprint created and stored by a third party?Sometimes, for speaker labellingNo
Is the resulting transcript discoverable?YesYes
Do consent-to-record laws still apply?YesYes

The last two rows are the point. Local processing changes who holds your client’s words. It does not change what those words are, or your obligations once they exist as a file.

Weesper Neon Flow runs a Whisper model locally on macOS and Windows, with no audio upload. The architecture is described in more depth in our guide to offline voice dictation and privacy, and the organisational controls around it in our enterprise security and encryption guide.

What does on-device dictation not solve?

Quite a lot, and any vendor who tells you otherwise should worry you. Local processing removes a disclosure vector; it is not a privilege shield, a compliance programme or a records policy.

Still on you after switching to a local tool:

The defensible claim is narrow and worth stating exactly: on-device dictation removes the third-party disclosure vector. It does not remove the file, the duty or the jurisdiction.

Conclusion: architecture narrows the argument you have to win

Privilege will keep being litigated tool by tool. The 2026 decisions were fact-specific, non-binding and explicitly left room for enterprise-grade AI used under counsel’s direction — as Ogletree, Goodwin and Norton Rose Fulbright all take care to say.

But there is a difference between a position you defend with contracts, configuration screenshots and a vendor’s privacy policy, and a position where the disclosure never happened. The second argument is shorter.

If your practice handles privileged material and you want dictation that keeps the audio on your own machine, download it for macOS or Windows. Weesper Neon Flow costs €5/month and includes a 15-day free trial. Setup, model choice and offline behaviour are documented in the Weesper Help Center.