Rise in Popularity of AI Transcription Services Brings Litigation and Disclosure Risks
But this convenience comes with novel litigation and disclosure risks that businesses must assess and manage as they roll out these tools.
Popular remote conferencing and collaboration platforms offer real-time voice-to-text transcriptions and summarized notes created by generative AI applications. The settings and options for how participants are notified of the use of these tools can vary. Businesses should consider the implications of automatically generated written records of videoconferences for their records retention and disclosure policies and in litigation.
AI transcription records may increase a business's logistical burdens in several ways, including:
AI transcription services create a written record that can be saved by any attendee. In these written records, it is possible that AI may misinterpret or misattribute words, especially in complex or overlapping conversations. This risk increases the more meeting participants there are and the more they interrupt or speak over each other. Inaccuracies may only be discovered later, if or when the transcript is implicated in litigation. By then, it is too late to correct the document, and it may be difficult to obtain compelling human testimony of what was discussed in the conference. In addition to these accuracy considerations, an additional set of issues may arise if one participant enables the transcription service in a way that other participants are not aware of.
Implementing internal policies regarding AI transcription services can be an important way to mitigate risks and ensure compliance with legal and privacy standards. Here are some options for businesses to consider:
Define usage guidelines. Consider setting clear guidelines on when and how AI transcription services can be used. For example, guidelines may specify which meetings or types of discussions are appropriate for transcription.
Consent requirements. Requiring explicit consent from all meeting participants before enabling transcription services may serve as a risk mitigator. This can be done through verbal consent at the beginning of the meeting or through written consent before the meeting, for example, as part of a broader acceptable-use policy for technology (if all meeting participants are from the same business).
Training programs. Consider developing and conducting regular training sessions to educate employees about the risks and proper use of AI transcription services. These training sessions might, for example, teach employees the importance of obtaining consent and the potential legal implications of recorded transcriptions.
Awareness campaigns. Broader awareness campaigns to remind employees to treat all virtual meetings as if they are being recorded and encourage professional communication during meetings may help minimize litigation risk. Humor and attempts at humor often fall flat in a transcript.
Data retention policies. Businesses may consider defining policies for the retention and deletion of transcription records. For example, these policies might define how long transcriptions should be stored and the process for securely deleting them when they are no longer needed.
Access controls. Imposing access controls to ensure that only authorized personnel can access transcription records can be a useful compliance measure and risk mitigator. These access controls might involve encryption and other security measures to protect stored data.
Confidentiality agreements. Consider assessing the business's incoming and outgoing confidentiality agreements to include provisions related to AI transcription services. In this context, it may be valuable to remind employees that they may have obligations to protect third parties' sensitive information discussed during transcribed meetings.
Privacy impact assessments. Businesses might benefit from implementing privacy impact assessments to identify and mitigate potential privacy risks associated with the use of AI transcription services.
Policy documentation. Internal policies related to AI transcription services should be readily accessible to employees and written in clear, understandable language.
Regular updates. Policies should be subject to regular review and updates. Technology in this space is developing rapidly, and the law may change quickly. It is advisable to communicate any changes to employees promptly.
The information provided is not intended to be a comprehensive review of all developments in the law and practice, or to cover all aspects of those referred to.
Readers should take legal advice before applying it to specific issues or transactions.
Editorial Disclaimer
Originally published before the Ashurst Perkins Coie combination. See disclaimer.