
Your firm ran a security review on the document management system, and another on the practice management platform. Nobody ran one on the thing that sits in client calls taking notes. A researcher found one of those vendors leaving 180,000 call records open in January. It was still open yesterday.
THE LEAD PLAY
Nobody at Your Firm Bought the Bot in the Room

Dark Reading published a researcher's findings on tl;dv yesterday. tl;dv is a meeting notetaker: it sits in your Zoom, Meet, and Teams calls and turns them into transcripts and summaries. The company behind it is a small outfit in Aachen, Germany, and it says more than two million people use the product. The researcher, who goes by BobDaHacker, found the flaw back in late January.
The product runs on Google Firebase. Tenant isolation held for the obvious things, so one customer couldn't read another's transcripts, recordings, or chats. But the database has a collection called meetings, and nobody ever scoped that one to the organization. Any signed-in user could query the whole thing.
What came back was more than 180,000 completed call records across more than 80,000 users: timestamps, whether a call was recording, and the email address of whoever convened it. Domain analysis put the governments of 23 countries in the set, including domains belonging to Ukraine's Ministry of Digital Transformation, the São Paulo state government, and a Malaysian Ministry of Education training institute, alongside HubSpot, Mitsui Fudosan, Berkeley, and the University of Tokyo. Out of a sample of 27,000 meeting IDs, more than a thousand had invitee emails and full transcripts sitting on the open internet.
Then, knowing which calls were live, the researcher impersonated a notetaker bot and asked to join the private ones. By their own count, they got in about 80 percent of the time.
They tried to report it, got nowhere, and took it to Dark Reading instead. Dark Reading tried the press and marketing contacts and got no reply either. The issue was still live when the story ran, six months after it was found.
Your security review process is triggered by a purchase order, and there was never a purchase order. It isn't on the software spend and it never went through procurement. An associate signed up with a work email on a free plan, or the client's business development lead did, and now there's a bot with a recording light sitting in the call.
Your people have been trained to let it in, too. Two years of notetakers in every vendor demo and every client call have made Admit the reflex. That reflex is what the 80 percent is measuring.
The transcripts were the smaller exposure. The metadata is a map: which of your matters convened a call, when, how often, and who called it. A litigation team's call cadence spiking the week before a filing tells somebody something. So does an address at your firm convening recurring calls with an address at a company that hasn't announced anything yet.
The recording itself is becoming its own exposure. On July 30 a plaintiff filed Chamberlain v. Granola in the Northern District of California over a bot-free notetaker, the kind that captures audio off the user's own machine with no participant visible in the call. The complaint quotes Granola's marketing back at it: "Other people in the room won't know it's there." Seven counts, among them the federal Wiretap Act, CIPA sections 631 and 632, and intrusion upon seclusion, plus an allegation that model training is switched on by default. The consolidated Otter.ai privacy litigation has been running in the same district since August 2025 on the same theories, fully briefed since April with no ruling yet.
The Play this week: Pull the inventory before you write anything. Your Microsoft 365 or Google Workspace admin can produce two lists in an afternoon: every third-party app an individual user has granted calendar or meeting permissions to, and every external participant that has joined your meetings more than a handful of times in the last ninety days. Notetakers show up on both, and you'll recognize names nobody ever put in front of you.
Then write one rule, and make it about procurement rather than brand. No recording bot joins a call with a client or opposing counsel unless the firm holds a contract with the company that runs it. Not an approved-tools list. A contract. The point isn't the security review you'd get out of it. It's that when something like this happens, somebody has a phone number that gets answered.
SECOND CHAIR
ChatGPT broke the citations after the lawyer had already checked them

The Connecticut Supreme Court sanctioned Ian Gottlieb of GLG Law on July 31, in a per curiam order covering TOV Realty, LLC v. Suarez and Kosel Equity, LLC v. MacGregor. What he did wrong isn't the usual thing. He researched on Lexis. He Shepardized. Then he pasted the verified drafts into ChatGPT to clean up the prose, and the model added and altered citations on the way through. Seven of them were wrong in what he filed. He and the firm each pay $1,000 to the CT Bar Institute, he takes six CLE hours beyond the annual twelve with three on generative AI, and both file a compliance report with the Office of the Appellate Clerk within six months. The Statewide Grievance Committee got a courtesy copy, and the court said plainly that it wasn't a referral. From the order: "The oversight in submitting fake citations is more than just sloppy lawyering: it imperils the integrity of our judicial process."
The read: Every AI policy written in the last two years governs research and drafting. This lawyer did both correctly. The failure was at the editing step, which most policies don't classify as an AI use at all, and the firm paid separately from the lawyer who filed.
Thomson Reuters says its own model beats the frontier labs

Thomson Reuters announced on July 31 that it has built its own model. It's called Thomson, trained on Westlaw, Practical Law, Checkpoint and Reuters content, and it ships this month as the default behind Tabular Analysis in CoCounsel Legal. The company's line: "The most capable AI models no longer come only from frontier AI labs. One now comes from Thomson Reuters." Bob Ambrogi went through the benchmark table on August 4 and found Thomson won three rows out of seven. It lost Stanford LegalBench to both Gemini 3.1 Pro and GPT-5.5, lost the Harvey Legal Agent benchmark to Claude Opus 4.8, and finished last on coding. GPT-5.5 was run in non-reasoning mode while Gemini and Opus ran in reasoning mode. And the research comparison put Thomson-plus-Westlaw against frontier models with web search, which as Ambrogi put it is "less a test of the models than of the retrieval sources behind them." All self-reported, no independent verification.
The read: The comparison that would settle this is the one the deck doesn't run. What do the frontier models score with Westlaw behind them?
STILL WATCHING
Thomson Reuters v. ROSS Intelligence was argued in the Third Circuit on June 11 before Judges Restrepo, Montgomery-Reeves and Bove. Eight weeks, no opinion. Whenever it lands, it will be the first appellate word on AI training and fair use in legal research.
In Cole v. Hobby Town Unlimited (C.D. Ill.), the response to Judge Darrow's show-cause order is due Friday.
The hallucination tracker sits at 1,845 decisions, up 29 from the figure in Monday's issue. Pro se filers account for 1,080 and attorneys 717. The attorney number moved by ten in five days.
The pricing split. Align Research went live on August 3 at $100 per research job, no subscription, three free jobs a month; founder Sam Davidoff, formerly a litigation partner at Williams & Connolly, says per-job pricing is what the tokens actually cost. Meanwhile DeepSeek shipped V4-Flash on July 31 at $0.28 per million output tokens against $25 for Claude Opus 4.8.
QUICK HITS
The GAO got one too. In The JAAW Group, LLC, B-424433.22, decided July 31, protest counsel cited a GAO decision that doesn't exist and misused a Federal Circuit case, conceding that it "addresses a contractor responsibility determination, not solicitation ambiguity." Counsel blamed "inadequate verification prior to filing." Warning, no sanctions, and this: AI "must only be used with close, careful supervision, fact-checking, and citation-checking." That's not an Article III court. If your government contracts group has been treating this as litigation's problem, the gap just closed.
Two labs published what their models did during security testing. Anthropic's account came July 30, OpenAI's on August 4, and Anthropic drew the line between them: OpenAI's models "exploited a novel vulnerability to escape isolation," while the Claude models "accessed the internet via an open path" that a misconfiguration at an evaluation partner had left open. What came through that path: a model reached a live company's production infrastructure after a fictional target name collided with a real domain and pulled several hundred rows of production data, and a separate run published a malicious Python package to PyPI that got downloaded and executed on 15 real systems.
PwC put a number on how much of the work is actually automatable. From a report covered August 3: 80% of legal work carries "meaningful barriers" to full automation. Firms expect AI efficiency worth 16% of chargeable hours this year, up from 11%. That second number is the one to build a budget against.
Somebody catalogued what law schools actually permit. Suffolk Law dean Andrew Perlman published an archive on August 3 covering 128 of the 196 US law schools. Prohibition is the default for graded work, with instructors opting in rather than students opting out. Twenty-six schools now require AI literacy training. It's the clearest read available on what your incoming associates were and weren't taught to do.
Ask your Workspace or M365 admin for the list of third-party apps holding calendar permissions before anybody drafts a policy about notetakers. The list takes an afternoon to pull.
See you in the next one.
