July 27, 2026 · 11 min read
Data-Privacy-Aware AI Meeting Notes for Asset Managers: Keeping MNPI Off Third-Party Servers
Published July 27, 2026
- FINRA's 2026 Annual Regulatory Oversight Report added a dedicated GenAI section and flagged recordkeeping lapses more than 50 times — supervision, not the tool, is what examiners test.
- Skadden's July 2026 MNPI-and-AI guidance says firms can face scrutiny when AI tools foreseeably could misuse nonpublic information, even absent a trade.
- A 2026 Journal of Finance study of 4,700 asset-manager meetings found only ~0.4% touched MNPI — but every meeting sits in the same containment architecture.
- Cloud transcription creates a third-party copy of the recording; on-device processing keeps audio on the analyst's Mac or iPhone with no vendor server holding it.
- 'On-device' is an architecture fact, not a compliance guarantee — the firm's CCO still determines fit against Rule 17a-4, Rule 204-2, and Advisers Act policies.
Quick answer: Asset managers evaluating AI meeting notes should judge tools by where audio is processed, retention defaults, training-data use, and DPA language — not marketing claims. Cloud transcription creates a third-party copy of MNPI-adjacent conversations that expands discovery, subpoena, and vendor-breach exposure. On-device processing avoids the vendor server entirely; compliance remains the firm's determination.
A management call. An LP update. An expert-network interview. Any one of these conversations can touch material nonpublic information — and the AI notetaker sitting in the meeting is now part of your MNPI containment perimeter.
On July 21, 2026, Skadden, Arps, Slate, Meagher & Flom published a client alert warning that broker-dealers and investment advisers “must maintain policies reasonably designed to prevent misuse of MNPI, and firms risk scrutiny if AI tools foreseeably could use restricted data improperly, even absent actual trades.” That sentence quietly reframes every AI meeting notetaker sitting in an investment-committee call, a management-team research call, or a portfolio-company diligence session. The tool is no longer neutral productivity software. It is now a data path that the SEC and FINRA expect the firm to govern.
This article is for the CCO, COO, or portfolio manager evaluating an AI meeting notes tool for an asset-management workflow where MNPI can enter the room. It is not compliance advice, and Basil AI is not “compliant” — compliance is a determination only your firm and counsel can make. What we can offer is a clear map of the dimensions that matter: where audio is processed, what the vendor retains, whether transcripts train models, and what the DPA actually says. Then we’ll be honest about where on-device architecture helps and where it doesn’t.
Why asset management is different from other AI-notetaker use cases
Consumer productivity vendors built AI notetakers for software sales teams and marketing standups. Asset managers are a different problem entirely. As a 2026 Meeting Notes review of AI notetakers for asset managers put it, an LP update call, an investment-committee review, or a management-team research call “may touch on material non-public information, investment theses not yet public, or confidential counterparty discussions. The stakes for using the wrong recording tool are not merely operational. They’re legal.”
How often does that actually happen? A 2026 study published in The Journal of Finance analyzed 4,700 private meetings between a large active asset manager and its portfolio firms and found that only about 0.4% of meetings discussed material nonpublic information. Low base rate — but any single one of those meetings can create insider-trading exposure. And critically, you cannot know in advance which meetings will land in the 0.4%. That means the containment architecture around every meeting is what matters, not just the ones you flag ex ante.
What FINRA and the SEC are actually looking at in 2026
On December 9, 2025, FINRA published its 2026 Annual Regulatory Oversight Report. For the first time, the report included a dedicated section on generative AI. As Risk Management Magazine observed, “the top generative AI use case” FINRA has seen at member firms is “summarization and information extraction” — exactly what a meeting notetaker does.
Smarsh’s analysis of the 2026 report notes that FINRA has sharpened its focus on individual accountability and vendor risk: “Even if firms outsource a function, they’re not outsourcing accountability” — firms must ensure their vendors do what they say. And as Corporate Compliance Insights reported after reviewing the same document, FINRA “flags recordkeeping lapses more than 50 times across the report,” emphasizing whether written procedures reflect actual practice.
The SEC posture is similar. Comply’s 2026 regulatory priorities briefing summarizes the direction: “regulators are looking for evidence that compliance is happening in real time, not just on paper.” The through-line for asset managers is that the question examiners will ask about your AI notetaker is not “is it certified?” but “can you produce every record it generated, prove where the audio was processed, and show the supervision procedures around it?”
The MNPI question: what happens when a transcript leaves the firm
The Skadden alert is worth reading in full. Its core observation: AI tools can now “access and analyze nonpublic information at scale,” which “raises questions of how existing insider trading and MNPI-handling rules apply.” A cloud-based meeting notetaker is one such tool. When a portfolio manager takes a call with a CFO and a bot uploads the audio to a vendor, the firm has just created a copy of a potentially-MNPI-adjacent recording that sits on infrastructure the firm does not control.
That’s not automatically a violation. But it does three things worth naming:
- It expands the subpoena surface. Any recording the vendor holds is subject to lawful process directed at the vendor, not just the firm.
- It creates a vendor-breach exposure. If the vendor is compromised, so is that recording.
- It complicates the MNPI walls. If a vendor uses aggregated transcripts to train models, is your issuer discussion now a training input? The answer depends entirely on the DPA, not on the marketing page.
A separate June 2026 analysis in Mondaq covering AI, MNPI, and the SEC makes the point directly: “When an AI system is trained on material nonpublic information, MNPI, and then used to inform or execute trades, the firm deploying that system may face insider trading liability, even if no human trader ever directly reviewed the underlying data.” The legal theory is not fully tested, but the direction of travel is unambiguous.
SEC Rule 17a-4: does an AI transcript become a book and record?
This is where practitioners get tangled. The clearest guidance is Skadden’s 2024 recordkeeping analysis, which explains that if a record “simply exists or is stored in the application or the cloud, Rule 17a-4(b)(4) and Rule 204-2(a)(7) are likely not implicated, as those rules apply to written communications that are sent and received.” But the moment that transcript is emailed, pasted into a chat, or exported into a client memo, “SEC recordkeeping requirements may apply to that written transmission.”
Translation: the same AI summary can be outside the recordkeeping perimeter one minute and inside it the next, depending purely on whether an analyst hits “send.” That’s a nightmare to govern with a cloud tool where you can’t see, control, or delete the source copy. It’s much more tractable when the source recording and transcript live on a device you already manage and can wipe.
The 2022 amendments to Rule 17a-4 also matter. As ACA Global summarized, the amendments “allow third parties (e.g., cloud service providers), which are unable to provide the undertaking required in the Rule, to use an alternative undertaking” — but only if the broker-dealer can access records without needing the third party to intervene (for example, to decrypt them). This is one reason firms want to keep the primary copy of sensitive recordings under their own control.
Off-channel enforcement didn’t die — it moved to FINRA
Between 2021 and 2024, the SEC brought recordkeeping actions against dozens of firms for off-channel communications violations. FINRA’s own May 2025 blog post counted 77 FINRA member firms settling with the SEC for OCC-related failures during that window.
Some firms concluded that with the change in administration and the SEC dialing back, the risk was gone. It wasn’t. Advisor Perspectives reported that into 2026 “FINRA barred an individual from associating with any member firm for off-channel communications use entirely. Where the SEC sweep largely targeted institutions, FINRA is increasingly holding individuals personally accountable.” A January 30, 2026 $750,000 FINRA fine against a broker-dealer for recordkeeping and supervisory failures, and a March 2026 $600,000 fine against BTIG covering thousands of off-channel messages including “substantive discussions regarding the firm’s investment banking business,” both underline the point.
Why does this matter for AI meeting notes? Because the compliance question examiners will apply to an AI notetaker is exactly the one they applied to WhatsApp and personal email: is this a business communication or record you can produce, and is it inside your supervision program? A cloud AI notetaker that generates business summaries outside your archival system is a modern echo of a personal iMessage thread with a client.
The four dimensions to actually evaluate
Cutting through the vendor marketing, here are the dimensions that determine whether an AI meeting notes tool is defensible in front of a FINRA examiner or an SEC staff attorney.
1. Processing location
Where is the audio decoded into text? A vendor server (Otter, Fireflies, Zoom AI Companion), a hyperscaler tenant (Microsoft, Google), or the endpoint device? For MNPI-adjacent conversations, endpoint processing avoids creating a vendor-held copy in the first place.
2. Retention defaults and controls
How long does the vendor keep audio and transcripts by default? Can you configure zero-day deletion? Is there a WORM or audit-trail option that satisfies SEC Rule 17a-4’s WORM or audit-trail requirement? Indefinite retention on a vendor server is a discovery magnet.
3. Training-data policy in the DPA
The question is not whether the marketing page says “we don’t train on your data.” The question is whether that promise is in the Data Processing Agreement or Master Services Agreement, where it creates legal accountability. If it isn’t, it isn’t a control.
4. Access, breach, and subpoena posture
Who at the vendor can see your recordings? What is the breach-notification SLA? How does the vendor respond to third-party legal process directed at your data on their servers? Every additional copy is another surface.
Cloud AI notetakers vs. on-device: a side-by-side view
This is a directional comparison, not a compliance certification. Verify current terms with each vendor and your counsel.
| Dimension | Typical cloud AI notetaker | On-device (e.g., Basil AI) |
|---|---|---|
| Audio processing location | Vendor servers (or hyperscaler tenant) | User’s Mac / iPhone (Apple Speech Recognition + Neural Engine) |
| Vendor copy of raw audio | Yes, by default | No — audio never leaves the device |
| Default retention | Days to indefinite | User-controlled; deletable at any time |
| Training on your content | Depends on DPA; often opt-out only | N/A — content doesn’t reach a vendor to train on |
| Discovery surface at vendor | Vendor holds recordings + transcripts | No vendor-held copy of the recording |
| Meeting-participant disclosure (bot in list) | Often yes (bot joins call) | No — device-level capture, no bot participant |
| Works offline (airplane mode, SCIF-adjacent) | No — requires cloud | Yes — fully offline |
| Firm’s recordkeeping obligation | Firm still responsible | Firm still responsible |
Read the last row carefully. On-device processing removes a category of vendor risk. It does not remove the firm’s obligation under FINRA’s AI guidance, Rule 4511, or SEC Rule 17a-4/204-2 to capture and supervise business communications through the firm’s approved system. Basil AI is a capture layer that keeps audio off vendor infrastructure; your books-and-records archive still handles retention.
Bots in the meeting: the counterparty-signaling problem
One under-discussed issue for asset managers: many cloud notetakers join meetings as a visible participant. On a management-team research call, a portfolio company sees a “[Vendor] Notetaker” entry in the participant list. That silently communicates that the call is being recorded on a third-party platform.
For investor-relations calls where the issuer’s counsel is careful about MNPI, that participant-list entry can chill exactly the discussion you called the meeting to have. It can also trigger the issuer’s own compliance protocols. Device-level capture avoids the visible bot: the microphone on the user’s Mac or iPhone captures the audio locally, and no additional identity joins the call.
How Basil AI solves this: on-device transcription for MNPI-adjacent workflows
Basil AI runs entirely on Apple silicon. Audio is captured and transcribed on the user’s iPhone, iPad, or Mac using Apple’s Speech framework, which supports on-device recognition; summarization runs against Apple’s on-device foundation models via the Apple Intelligence privacy architecture. There is no Basil server that receives, stores, or analyzes your meeting audio — because there is no Basil server in that data path at all.
Concretely, that means:
- No vendor-side copy of the audio to be subpoenaed, breached, or reviewed by employees of the transcription vendor.
- No bot in the participant list — the counterparty sees only the analyst.
- Works offline: the tool functions on a plane, in a Faraday-shielded room, or in a portfolio-company boardroom with no guest Wi-Fi.
- Files export to Apple Notes, PDF, or your archival system so the firm’s books-and-records process still owns the retention decision.
What we are explicitly not saying: Basil is not certified as SEC- or FINRA-compliant. Compliance is a determination your CCO makes about your firm’s program, not a badge a vendor can wear. What we can say is that the architecture removes an entire category of third-party-server risk that cloud tools inherently carry.
A practical evaluation checklist for CCOs
If you’re evaluating any AI meeting notes tool for an asset-management workflow, this is the short list:
- Read the DPA, not the marketing page. Is the non-training commitment contractual?
- Get retention defaults in writing. Include zero-day options where they exist.
- Map processing location. Vendor server, hyperscaler, or device?
- Ask about breach notification SLAs and how the vendor handles subpoenas directed at your data.
- Verify recordkeeping integration. Can the tool export in a format your archival system ingests?
- Test the meeting-participant view. Is a bot visible to counterparties? Is that acceptable for issuer calls?
- Document supervision. Written procedures should reflect actual practice — the point Corporate Compliance Insights emphasized about FINRA’s 2026 exam posture.
Where this is heading
The Skadden alert’s closing recommendation is worth repeating: firms should “consider inventorying data restrictions, segregating and permissioning AI access to nonpublic information, using explainability and audit trails, and asking key governance questions before granting AI tools such access.” That’s the direction of travel for every regulated financial services firm through the rest of 2026 and into 2027.
For asset managers, the honest reading is that a cloud AI meeting notetaker is not automatically disqualifying — but it is a decision that has to be made with eyes open about vendor-side copies, DPA language, and the fact that FINRA is now actively examining exactly this class of tool. On-device processing narrows the surface area of that decision. It doesn’t eliminate the firm’s work.
For related reading on how these dynamics play out in adjacent regulated workflows, see our pieces on AI meeting notes for compliance officers in financial services, AI notetaker discovery and privilege in corporate meetings, and how Otter’s de-identification default handles training data.
Try Basil AI — on-device meeting notes for regulated workflows
Capture management calls, investment-committee meetings, and LP updates without a third-party server ever seeing the audio.
Frequently Asked Questions
Are AI meeting notes considered books and records under SEC Rule 17a-4?
It depends on how the output is used. Skadden's 2024 analysis notes that if an AI transcript or summary is transmitted internally (e.g., emailed or posted in chat), Rule 17a-4(b)(4) and Rule 204-2(a)(7) can apply to that written transmission. Information that merely sits inside an application may not be captured, but firms should still track datasets the AI touches.
Can a cloud AI notetaker create MNPI exposure even if no one trades?
Yes. Skadden's July 2026 client alert warns that broker-dealers and investment advisers must maintain policies reasonably designed to prevent MNPI misuse, and firms risk scrutiny if AI tools foreseeably could use restricted data improperly — even absent actual trades. A cloud transcript of an issuer call is a copy of restricted data outside firm walls.
What percentage of asset-manager meetings actually touch MNPI?
A 2026 Journal of Finance study of 4,700 private meetings between a large active asset manager and its portfolio firms found that roughly 0.4% of meetings discussed material nonpublic information. The frequency is low, but any single meeting can create insider-trading exposure — which is why the containment architecture around every meeting matters.
Does on-device transcription satisfy FINRA recordkeeping?
On-device processing is an architectural fact — audio and transcripts stay on the user's Mac or iPhone rather than a vendor server. It does not itself satisfy FINRA Rule 4511 or SEC Rule 17a-4; the firm is still responsible for capturing, retaining, and supervising business communications in an approved system. On-device tools reduce the third-party surface area of that program.
What should a DPA say about training data for asset managers?
Look for a contractual — not just marketing-page — commitment that firm audio, transcripts, and derived metadata will not be used to train the vendor's models or any third-party model. If that language sits only in a blog post rather than the DPA or MSA, it is not a compliance control. Zero-day retention options and SOC 2 Type II add further assurance.
Why do bots-in-the-meeting notetakers create counterparty risk?
A visible recording bot in the participant list signals to a portfolio company or counterparty that the call is being captured on a third-party platform. That can chill the very disclosure the meeting was called to produce and, for MNPI-adjacent discussions, creates optics and DPA questions the meeting host may not want to answer. Device-level capture avoids the participant-list disclosure question.