Regulation S-P and AI Notetakers: Vendor Due Diligence After the June 3, 2026 Deadline

Published August 19, 2026

Key takeaways

Quick answer: The SEC's amended Regulation S-P — enforceable for smaller RIAs since June 3, 2026 — requires investment advisers to document vendor due diligence for any third party (including AI meeting notetakers like Otter or Fireflies) that touches customer information, contract for 72-hour breach notice, and notify affected customers within 30 days. On-device notetakers keep audio off any vendor server and shrink the Reg S-P vendor perimeter.

August 19, 2026 · 11 min read

For the compliance officer at a mid-sized RIA, June 3, 2026 was not just a calendar date. It was the moment the SEC's amended Regulation S-P became enforceable for smaller entities — RIAs under $1.5 billion in AUM, smaller funds, and smaller broker-dealers. Larger firms had already been living under the rule since December 3, 2025. The amendments do not mention artificial intelligence anywhere in the text, but they quietly reshape the compliance analysis for every AI meeting notetaker running on a portfolio manager's Mac.

This article is for the CCO, general counsel, or operations lead trying to answer a specific question: does the AI notetaker my analysts have been using since 2024 create a Regulation S-P problem, and what do I need to change now that the smaller-entity deadline has passed?

What Amended Regulation S-P Actually Requires

Regulation S-P was first adopted in 2000 to implement the Gramm-Leach-Bliley Act's privacy provisions. The May 2024 amendments published in the Federal Register modernized the rule around four operational requirements: a written incident response program, mandatory customer breach notification, formal service provider oversight, and expanded recordkeeping. The FINRA Cybersecurity Advisory summarized the scope: broker-dealers (including funding portals), investment companies, registered investment advisers, and transfer agents are all covered institutions.

The compliance timeline created two waves. According to Holland & Knight's May 2026 client alert, smaller entities had to be in compliance by June 3, 2026 — a deadline that has now passed. The Investment Adviser Association pushed for more time; the SEC did not extend it.

The four moving parts

Every covered institution must now maintain: (1) a written incident response program that detects, responds to, and recovers from unauthorized access to customer information; (2) customer notification within 30 days of becoming aware of a qualifying incident; (3) written policies for overseeing service providers, including a 72-hour vendor breach notification standard; and (4) records of all of the above retained for five years. Nothing in that list is AI-specific. Everything in that list applies to AI notetakers.

Why AI Notetakers Fall Inside the Perimeter

The threshold question under Reg S-P is whether a vendor is a "service provider" with access to "customer information." The amended rule broadened both definitions. As Skadden's analysis of the final rule noted, the definition of covered customer information now sweeps in records the covered institution holds and records "a service provider maintains on its behalf."

An AI meeting notetaker sitting in a client onboarding call, an investment committee session, or an advisory review captures a live stream of exactly the material Reg S-P is trying to protect: client names, account holdings, financial situations, risk tolerances, sometimes Social Security numbers, and — in an asset-management context — often material non-public information. If the recording, the transcript, or the summary lives on the vendor's server, that vendor is holding customer information on the firm's behalf. That is a Reg S-P service provider relationship, whether or not anyone in procurement processed it as one.

The consumer-tier trap

The most common enforcement scenario is not a sophisticated attack on an enterprise SaaS vendor. It is an analyst using a personal-account AI tool for convenience. The Layer3Labs MNPI guide notes that most incidents come from convenience — someone uses a personal account because it is fast — and that consumer-tier AI tools typically retain inputs and may train on them. Under amended Reg S-P, a consumer-tier tool that trains on customer data is not just a policy problem; it is a documented vendor-oversight failure the moment an examiner asks for the vendor register.

The 72-Hour Vendor Breach Notice, in Practice

The most operationally consequential change is the 72-hour vendor notification requirement. As the Davis Wright Tremaine reminder put it, covered institutions must have written policies "reasonably designed" to require service providers to notify them of a breach within 72 hours. The RadarFirst analysis is blunt: vendor incidents are not separate events; they are part of the firm's own privacy incident management obligation.

This creates a hard contract-negotiation problem. Consumer-tier AI notetakers do not offer 72-hour breach notification in their standard terms. Enterprise tiers may — but the burden is on the firm to obtain that commitment in writing, document it, and monitor for compliance. According to guidance from Kroll's Reg S-P analysis, service provider due diligence is one of the four new pillars, alongside the incident response program, customer notification, and recordkeeping. Firms that cannot demonstrate they obtained 72-hour commitments from every vendor with access to customer information have a compliance gap.

The Vendor Perimeter Problem

Amended Reg S-P forces firms to inventory their vendors. Davis Wright Tremaine's guidance is that covered institutions "should inventory the customer information in their possession and the customer information maintained on their behalf by vendors" to scope compliance. That sounds procedural until you realize how many AI tools have quietly crept into workflows since 2023 — often without procurement, security review, or a signed DPA.

The LeGaye Law analysis of the amendments makes the same point: firms remain accountable for the security and confidentiality of customer information even when technology is outsourced. Delegation does not diminish responsibility. Every AI notetaker adopted through a personal Apple ID, a free trial, or an individual credit-card subscription is a phantom vendor relationship that the SEC now expects the firm to have documented.

Cloud AI Notetakers vs. On-Device Processing: A Side-by-Side

The architecture choice determines what shows up on the vendor register. Here is how the two models compare across the Reg S-P dimensions that matter.

Reg S-P dimension Cloud AI notetaker (Otter, Fireflies, Zoom AI Companion) On-device notetaker (Basil AI)
Vendor holds customer information? Yes — recording, transcript, and summary stored on vendor servers No — audio processed on the Mac/iPhone, no vendor server holds a copy
Service provider under Reg S-P? Yes — triggers written vendor oversight policies Not for the recording pipeline; standard software-vendor analysis only
72-hour breach notice needed in contract? Yes — must be negotiated and documented Not applicable to audio (nothing on vendor side to breach)
Vendor training on customer data? Consumer tiers: often yes. Enterprise: contractual opt-out required N/A — content never leaves device
Subpoena/discovery target? Vendor server is discoverable Only firm-held records are discoverable
Firm's Rule 204-2 obligations? Still owned by the firm Still owned by the firm

The last row is the honest disclosure that vendors often skip: whichever architecture you pick, Beach Street Legal's Advisers Act analysis is right that the recordkeeping obligation under Rule 204-2 sits with the adviser, not the tool. On-device processing removes one specific compliance risk — the vendor server — not all of them.

What the SEC's 2026 Exam Priorities Signal

Reg S-P does not sit alone on the exam sheet. On November 17, 2025, the SEC released its 2026 Division of Examinations priorities, and per WealthManagement.com's summary, AI supervision and compliance program effectiveness were called out across multiple sections. Notably, the priorities do not name specific communication channels — no mention of Teams, WhatsApp, or Zoom — which reinforces that recordkeeping obligations are channel-agnostic. A recording made by an AI notetaker is treated no differently from an email.

The Silver Regulatory Associates analysis ties it together: the Reg S-P amendments and the 2026 AI examination focus form "a single examination focus" for smaller advisers. Firms are being asked to demonstrate deliberate, documented, and monitored use of AI tools that touch client data. That is a governance posture, not a technology purchase.

The joint IAA/ICI comment letter

Even the industry's own trade associations are pushing for regulatory clarity. On May 1, 2026, the Investment Company Institute and Investment Adviser Association submitted a joint letter to the SEC urging modernization of the Investment Advisers Act books-and-records rule — as noted in the Troutman Pepper Locke Law360 republication. The letter cites the off-channel enforcement actions of 2022 through 2025 as evidence that the existing rule is a poor fit for modern communication technologies. Until the SEC acts, firms are stuck applying rules written for a paper-and-email world to real-time on-device inference.

Mapping the AI Notetaker Landscape to Reg S-P

Not every AI notetaker sits in the same architectural bucket. The vendor-perimeter analysis depends heavily on where the audio actually goes.

Cloud-first tools

Otter.ai's privacy policy and Fireflies.ai's privacy policy both describe cloud pipelines where audio and transcripts are stored on vendor infrastructure. For an RIA, both are Reg S-P service providers the moment they touch a client meeting, requiring vendor due diligence, 72-hour breach commitments, and inclusion in the firm's incident response tabletop exercises. Zoom's privacy notice covers the Zoom AI Companion feature in the same posture.

Hybrid tools

Some "botless" tools capture audio locally but still upload the file for cloud transcription — a common architecture in 2026. From a Reg S-P perspective the analysis is identical to the fully cloud tools: the vendor still holds a copy of the customer information. The absence of a visible meeting bot is a client-experience win, not a Reg S-P architectural change.

On-device tools

A genuinely on-device notetaker performs speech recognition and summarization locally, using the operating system's speech APIs and the device's neural engine. Apple's Speech framework documentation exposes on-device recognition that runs without an internet connection. In that architecture there is no vendor server to add to the Reg S-P register for the transcription pipeline itself.

How Basil AI Solves This

Apple's privacy architecture is the foundation Basil AI builds on. Basil runs entirely on-device: audio is captured, transcribed, and summarized on the analyst's Mac or iPhone using Apple's Speech framework and, where available, Apple Intelligence. The recording never touches a Basil server because there is no Basil server in the recording path. Files live in the user's device storage and, at their discretion, in the user's own Apple Notes via iCloud.

For Reg S-P purposes, this changes what shows up on the vendor register. Basil is a software vendor the firm licenses — that is a normal SaaS relationship — but Basil is not a service provider that maintains a customer information system in the Reg S-P sense, because Basil holds no customer audio, transcripts, or summaries. There is no server to breach and no dataset to subpoena. The 72-hour vendor breach notification requirement does not attach to a pipeline where the vendor is architecturally excluded from the data path.

To be explicit about what this does not do: on-device architecture does not make a firm Reg S-P compliant. The firm still needs a written incident response program, still owes 30-day customer notification if anything in its own infrastructure is breached, and still owns its recordkeeping determination under Advisers Act Rule 204-2. What the architecture does is shrink the vendor perimeter — one fewer third party that needs a signed 72-hour breach commitment and an annual security review. For a small compliance team that already has too many vendors to monitor, that reduction is the point.

For related background, see our deep dive on AI meeting notes for asset managers and MNPI containment, our compliance-officer explainer on SEC and FINRA recordkeeping for AI meeting notes, and our definitional piece on what "compliant AI meeting notes" actually means.

A CCO's Post-June-3 Checklist

If you did not close every item before the deadline, here is the practical work that most compliance teams are still doing in August 2026:

The Bottom Line for Investment Advisers

Regulation S-P did not create AI-specific rules. It did not have to. The amended rule created a documented, examinable vendor-oversight process that applies to every third party holding customer information — a category that quietly includes the AI notetakers most firms adopted in the last two years without procurement review. The June 3, 2026 deadline for smaller entities has now passed; the SEC's 2026 examination priorities have already flagged both Reg S-P readiness and AI supervision. Firms that treated the AI notetaker as consumer productivity software are the firms most likely to have a gap.

The architectural response is not the only response — a well-negotiated enterprise contract with a Reg S-P-appropriate cloud vendor is a defensible posture. But the smaller the vendor perimeter, the smaller the ongoing oversight burden. On-device transcription is one of the few ways to reduce that perimeter to zero for the recording pipeline, which is why compliance-conscious teams are increasingly evaluating it as an architectural default rather than an edge case.

Shrink Your Reg S-P Vendor Perimeter

Basil AI transcribes meetings on-device. No vendor server holds your audio, transcripts, or summaries. One fewer service-provider row on your Reg S-P register.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

Does Regulation S-P apply to AI meeting notetakers used by RIAs?

If the notetaker records, transcribes, or summarizes conversations that include customer nonpublic personal information (NPI) — client names, account details, financial situations — and the vendor stores that content on its servers, the vendor is a 'service provider' under amended Regulation S-P. That triggers written vendor due diligence, contractual 72-hour breach notification, and recordkeeping obligations for the firm.

What is the June 3, 2026 Reg S-P deadline?

June 3, 2026 was the compliance date for 'smaller entities' — RIAs with less than $1.5 billion AUM, smaller funds, and smaller broker-dealers. Larger firms have been subject to the amended rule since December 3, 2025. Both tiers must now have a written incident response program, service provider oversight policies, and customer notification procedures in place.

Do I need a signed DPA with my AI notetaker vendor under Reg S-P?

The SEC didn't strictly require a signed separate agreement, but examiners expect firms to show their policies are 'reasonably designed' to obtain 72-hour breach notice from vendors — which in practice means either amended contract language, a written attestation, or, for consumer-tier tools, replacing them with an enterprise agreement or an architecture that avoids vendor storage entirely.

How does on-device transcription change the Reg S-P analysis?

If audio is processed locally on the analyst's Mac or iPhone and never uploaded to a vendor server, the transcription tool is not a 'service provider' with access to a 'customer information system' in the Reg S-P sense — there is nothing on the vendor side to breach. This narrows the vendor due diligence perimeter, but the firm still owns the resulting file and any recordkeeping determination under Rule 204-2.

Is 'on-device AI' automatically Regulation S-P compliant?

No. On-device processing is an architecture fact, not a compliance certification. A firm's CCO still has to evaluate the tool against Reg S-P, Advisers Act Rule 204-2 recordkeeping, Rule 206(4)-7 compliance policies, and internal MNPI controls. The architecture removes one specific risk — a vendor holding a copy of the recording — but does not answer every question a Reg S-P examiner will ask.

What happens if my notetaker vendor is breached and doesn't tell me for a week?

The firm is still on the hook for the 30-day customer notification clock from the point of 'awareness.' Under the amended rule, delayed vendor notice does not extend the firm's obligation, which is why the SEC expects firms to negotiate 72-hour vendor breach notice up front. Firms whose vendors cannot commit to that timeline should reassess the relationship.

Get Weekly Privacy Insights

On-device AI tips, privacy news, and Basil AI updates. No spam.

Unsubscribe anytime. Privacy Policy