If you supervise books-and-records at a registered investment adviser or broker-dealer, one document that landed on Chair Paul Atkins's desk last fall probably matters more to your AI meeting-notetaker policy than anything the SEC itself has published in 2026. On October 15, 2025, SIFMA and SIFMA AMG formally petitioned the SEC to modernize the communications-retention rules that govern broker-dealers, investment advisers, and security-based swap dealers — and to explicitly exclude AI-generated meeting transcripts from mandatory retention under Rules 17a-4, 18a-6, and 204-2(a)(7).

The SEC has not acted on that petition. Which means as of August 2026, the question "do I have to retain the AI transcript from Tuesday's investment-committee call?" still has to be answered under a 1997-vintage framework that Kitces notes still references microfilm and microfiche in its statutory text. This article walks through what SIFMA actually asked for, what current law says while the petition sits, and how the physical architecture of your notetaker — cloud vs. on-device — changes what records exist to be retained in the first place.

The SIFMA Petition, in Plain Language

SIFMA's October 15, 2025 letter was addressed personally to Chair Paul Atkins and co-signed by SIFMA's Asset Management Group. Its central complaint: the current recordkeeping regime is "outdated, overly broad, and applied under a strict liability standard" that no longer matches how firms and clients actually communicate.

Four specific asks matter for AI notetakers:

An analysis from Archive Intel summarized the practical effect this way: meeting transcripts or Slack messages used for internal collaboration would no longer have to be archived unless they meet the proposed threshold of client-facing, substantive communication. The petition is not a rule change — it's a request. The SEC does not have to respond, though Chair Atkins has publicly signaled interest in rolling back Gensler-era compliance expansions.

What Current Law Actually Says About AI Transcripts

Until the SEC acts, the operative framework is the one Skadden laid out in September 2024. Rule 204-2(a) requires investment advisers to maintain "written communications sent by such investment adviser" relating to four enumerated subjects: (i) any recommendation made or proposed to be made and any advice given or proposed to be given; (ii) any receipt, disbursement or delivery of funds or securities; (iii) the placing or execution of any order to purchase or sell any security; and (iv) predecessor performance and the performance or rate of return of managed accounts or securities recommendations.

The key words are "sent" and "received." Cooley's fund lawyers and SteelEye's SEC-registered adviser guide land in the same place: an emerging consensus that internal-only AI-generated content likely is not a "communication" record — but becomes one the instant it is shared externally. A Zoom transcript sitting in the cloud is closer to personal notes; the moment an adviser emails an AI-generated meeting summary to a client, forwards it to a colleague, or pastes an excerpt into chat, it becomes a written communication subject to Rule 204-2(a)(7) if it touches the enumerated topics.

The Retention Window

For content that does fall in scope, the retention period is five years, with the first two years required to be maintained in an easily accessible location. Time2Accelerate's analysis for private equity firms emphasizes there is no WORM format requirement for investment advisers under Rule 204-2 — that WORM requirement lives in Rule 17a-4 for broker-dealers.

Why This Debate Exists Now: The Off-Channel Enforcement Legacy

Cooley notes that the wave of off-channel communications enforcement actions over the past several years conditioned firms to think about recordkeeping as a communications problem — who sent what, over what channel, and whether it was retained and supervised. When WhatsApp threads with clients cost broker-dealers billions in penalties, compliance teams overcorrected. Everything is now "maybe a record," and AI notetakers create a new class of "maybe records" sitting in vendor clouds outside the firm's supervisory perimeter.

SIFMA's argument is that this overcorrection captures too much. Their October 15 letter asks the SEC to "exclude categories of communications that provide no investor protection benefit, such as emojis, unsolicited inbound messages, or ministerial messages ... and also, for the avoidance of doubt, exclude categories of materials that are not communications at all, such as AI-generated meeting transcripts and collaborative platform inputs."

What FINRA and the SEC Have Actually Said in 2026

While the petition sits, examiners are not sitting. The 2026 exam priorities emphasize evidence over documentation — regulators want proof that compliance is happening in real time, that AI decisions are explainable, and that firms can trace the connection between what they've documented and what they can actually produce. A separate summary of FINRA's 2026 Annual Regulatory Oversight Report notes that FINRA now expects documented AI supervision, not just human oversight in principle, and points to the SEC's March 2024 enforcement action fining two investment advisers a combined $400,000 for false and misleading statements about their AI capabilities under the Marketing Rule.

The takeaway for compliance officers: the SEC and FINRA have not narrowed anything in the AI-transcript space. If anything, exam priorities have tightened around AI governance frameworks and the ability to substantiate representations firms make about their AI use.

Cloud AI Notetakers vs. On-Device: How Architecture Changes the Record

Every recordkeeping conversation eventually collapses into a physical question: where does the audio and transcript actually live? Here's how the two architectures compare against the specific concerns compliance officers are asking about in 2026:

DimensionCloud AI Notetaker (Otter, Fireflies, Zoom AI Companion)On-Device AI Notetaker (Basil AI)
Where audio is processedVendor servers (typically AWS/GCP)The analyst's Mac or iPhone; Apple Neural Engine
Third-party copy of the recordingYes — a vendor server holds itNo vendor server holds the audio
Retention defaultVendor-controlled (often indefinite; see Otter.ai's policy)Firm-controlled on device; no vendor retention
Discovery / subpoena surfaceVendor may be subpoenaed for records the firm never seesNo third-party surface to subpoena
Visible bot in participant listTypically yes (chills counterparty disclosure)No bot; device-level capture
Training-data riskDepends on DPA; check contract, not marketingNo data leaves device to train on
"Sent or received" under Rule 204-2Not automatically, but the vendor-cloud copy is a shadow record examiners can flagNot applicable until the transcript is actually transmitted by the adviser

To be clear about the compliance framing: on-device processing is an architecture fact — no vendor server holds the recording. It is not a compliance guarantee. Your CCO still determines Rule 204-2, Rule 17a-4, and Advisers Act fit. But architecture shapes what records exist to be retained. A cloud transcript that no one at the firm knows exists is exactly the kind of "shadow record" SteelEye flagged: compliance officers might not know staff are using tools like Otter or receiving automatic Zoom summaries, resulting in written client discussion records existing unnoticed in AI tools.

The Practical Compliance Playbook While the Petition Sits

Assuming the SEC does not act on SIFMA's petition in your budget cycle, here's what firms are actually doing in 2026:

1. Inventory the shadow-record surface

Ask, for each conferencing platform in use: which AI notetakers are enabled by default? Which are enabled by individual users? Where does the resulting transcript live, and for how long? If a compliance officer cannot answer that question for Zoom, Teams, and Google Meet in a single dashboard, the firm has a supervision gap, not a technology problem.

2. Decide the perimeter

Layer3Labs's MNPI-and-AI guidance puts it bluntly: an AI tool that sees MNPI must sit inside the barrier, meaning a no-training endpoint, an access-controlled workspace, and logs limited to walled staff. On-device tools meet this test structurally — there is no external logging surface.

3. Write the policy to the physical facts

Do not write "Basil AI is compliant with Rule 204-2." Write: "Our sanctioned meeting-capture tool processes audio on the device, does not transmit audio or transcript to a vendor server, and produces artifacts the analyst chooses to retain within the firm's supervised systems." That statement is verifiable. "Compliant" is a determination, not a product feature.

4. Address the transmission trigger

The moment an analyst emails a summary to a client, or pastes an excerpt into a client-facing chat, the artifact enters Rule 204-2 scope on its normal terms. Route that transmission through the firm's archived channels — the same as any other client communication.

How Basil AI Solves This

Basil AI is a fully on-device AI meeting notetaker for iPhone and Mac. Audio is captured and transcribed on-device using Apple's Speech Recognition and Neural Engine. No audio and no transcript is uploaded to a Basil server — because Basil does not operate a server that holds meeting audio.

For a compliance officer evaluating the SIFMA petition landscape, that architecture answers several questions at once:

For a longer treatment of how this architecture maps to MNPI-sensitive workflows, see our companion piece on AI meeting notes for asset managers. For the compliance-officer framing across financial services more broadly, see AI meeting notes for compliance officers in financial services. And for the buyer-side definitional piece, see what "compliant AI meeting notes" actually means.

What to Watch: Signals That the Petition Is Moving

Chair Atkins has publicly signaled interest in rolling back several Gensler-era compliance expansions. Concrete signals that the SIFMA petition is progressing would include: (1) an SEC concept release soliciting comment on modernizing Rules 17a-4 and 204-2; (2) inclusion of the retention framework in the SEC's rulemaking agenda; or (3) Division of Examinations FAQ language narrowing what counts as a "written communication" when it originates from an AI notetaker.

None of those had occurred as of August 2026. The prudent planning assumption is that the current framework governs your 2026 exam cycle, and that the physical architecture of your notetaker — whether a vendor cloud holds the audio, or your Mac does — remains the single biggest determinant of your shadow-record surface.

The Bottom Line

SIFMA has asked the SEC to explicitly exempt AI meeting transcripts from Rules 17a-4 and 204-2(a)(7) retention. That request, if granted, would narrow the recordkeeping surface for every registered adviser and broker-dealer running AI notetakers today. Until the SEC acts, current law applies: transcripts sitting in a vendor cloud are likely not "sent or received" communications, but they become records the moment they are transmitted. And they remain shadow records — findable in a vendor system the firm doesn't fully supervise — for as long as the vendor holds them.

On-device architecture is not a substitute for compliance judgment. But it is the one variable a firm can change today that eliminates the shadow-record surface entirely, without waiting for the SEC to act on a petition it may never grant.

Try Basil AI — Private, On-Device Meeting Notes

Basil AI captures and transcribes meetings 100% on-device on iPhone and Mac. No vendor cloud. No bot in the participant list. No shadow record for examiners to find later.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

Does SEC Rule 204-2 require investment advisers to retain AI meeting transcripts?

Not automatically. Rule 204-2(a)(7) covers written communications sent or received relating to four enumerated categories: advice/recommendations, funds/securities, orders, and performance. A Skadden analysis and Cooley's fund lawyers agree that a transcript merely sitting in a vendor cloud is likely not a 'sent or received' communication — but the moment it is emailed, pasted into chat, or shared with a client, retention obligations attach.

What did SIFMA ask the SEC to change in October 2025?

In an October 15, 2025 letter to Chair Paul Atkins, SIFMA and SIFMA AMG asked the SEC to modernize Exchange Act Rules 17a-4 and 18a-6 and Advisers Act Rule 204-2(a)(7). Specifically, SIFMA wants the rules to exclude AI-generated meeting transcripts and collaborative platform inputs, refocus retention on 'client-facing' substantive communications, and add a safe harbor for firms with reasonable policies.

Has the SEC acted on SIFMA's petition yet?

No. As of August 2026, the SEC has not amended Rules 17a-4 or 204-2 in response to the October 15, 2025 SIFMA petition. Firms should assume the current strict-liability framework still applies and that AI transcripts, once transmitted, remain within scope. Compliance officers should not treat the petition as a change in law.

How does on-device transcription change the recordkeeping analysis?

On-device processing means the raw audio and transcript never leave the analyst's Mac or iPhone — there is no vendor cloud copy. That eliminates one class of 'shadow record' that examiners have flagged: transcripts sitting in third-party systems outside the firm's archival supervision. The firm's CCO still determines what to retain; architecture doesn't create or waive Rule 204-2 obligations.

What's the difference between Rule 17a-4 and Rule 204-2(a)(7) for AI transcripts?

Rule 17a-4 applies to broker-dealers and imposes WORM-format retention on required records. Rule 204-2(a)(7) applies to registered investment advisers, requires five-year retention (first two easily accessible) but has no WORM mandate. Both cover written communications 'sent or received' on enumerated topics — SIFMA's October 2025 petition targets both rules for the same modernization.

Can compliance officers block AI notetakers from joining meetings?

Yes, and many do. FINRA's 2026 Annual Regulatory Oversight Report expects documented AI supervision. Blocking third-party bots from Zoom/Teams and providing staff a sanctioned alternative — including device-level capture that never routes audio to an external vendor — is a common control. The goal is eliminating unsupervised 'shadow' transcripts sitting in personal accounts.