Published September 9, 2026 · 11 min read

FINRA's 2026 GenAI Rules for Broker-Dealers: What the New Oversight Report Means for AI Meeting Notes

Published September 09, 2026

Key takeaways

Quick answer: FINRA's 2026 Annual Regulatory Oversight Report, released December 9, 2025, added a dedicated GenAI section warning that generative AI tools — including AI meeting notetakers — implicate Rule 3110 supervision, Rule 4511 recordkeeping, and SEC Rule 17a-4. Broker-dealers must govern where audio is processed, retention defaults, and vendor training use. On-device transcription is an architecture choice that removes the third-party server from that supervisory chain; compliance remains the firm's determination.

The new standalone GenAI section, autonomous-agent language, and what it changes for AI notetakers sitting in your IC meetings.

On December 9, 2025, FINRA released its 2026 Annual Regulatory Oversight Report. It is roughly 90 pages long, arrives earlier in the year than any prior edition, and — for compliance officers evaluating AI meeting notetakers — contains one of the most consequential paragraphs FINRA has published in a decade: a standalone Generative AI section explicitly noting that GenAI tools can implicate the rules broker-dealers already live under for supervision, communications, recordkeeping, and fair dealing.

If a botted meeting recorder is joining your investment-committee call, your management-team diligence session, or your LP update, the 2026 Report has just quietly reframed how examiners will look at it in 2026. This article walks through what actually changed, what didn't, and what it means for the architecture — not the branding — of the AI tools sitting in your sensitive conversations.

What the 2026 Report Actually Adds

FINRA's 2025 report referenced only three GenAI use cases that firms had implemented. In 12 months that has changed dramatically. According to Debevoise & Plimpton's analysis, the 2026 Report "contains a standalone section on Generative AI ('GenAI') that substantially expands upon the topic from last year's publication" and, for the first time, addresses AI agents that take autonomous action rather than merely generate content.

Sidley Austin's client alert notes that FINRA expects firms to assess regulatory compliance obligations before deploying GenAI and to establish governance frameworks to supervise its use, with controls addressing hallucinations, bias, cybersecurity risks, and threat-actor use of AI. Ongoing human monitoring of model outputs is characterized as essential, and autonomous AI agents may require novel oversight — including tracking actions and restricting system access.

The framing that matters most, though, is technology-neutrality. Existing rules apply in full when firms deploy AI tools. Nothing was rewritten. Everything was extended.

The Four Rules the Report Says GenAI Implicates

Reading directly from the report and its analysts, four rule sets are called out repeatedly:

1. FINRA Rule 3110 (Supervision)

The 2026 Report states that pursuant to FINRA Rule 3110, a member firm must have a reasonably designed supervisory system tailored to its business, and that if a firm is relying on GenAI tools as part of that supervisory system, its policies and procedures may need to consider the integrity, reliability, and accuracy of the AI model. In plain English: if an AI notetaker is drafting the summary that a supervisor reviews, that summary is now part of the supervisory system, and the model behind it is in scope.

2. FINRA Rule 4511 & SEC Rules 17a-4 / 204-2 (Recordkeeping)

McGuireWoods' analysis flags that FINRA's 2026 themes on communications include sharpened emphasis on retention of GenAI chatbot communications. The obligation to capture business communications is technology-agnostic — the same 2018-era rules apply to a 2026 AI transcript.

3. Communications with the Public

The report reminds firms using GenAI to "generate or otherwise assist in creating communications to customers" to ensure those communications comply with relevant rules, per Global Relay's summary. AI-drafted follow-up emails from meeting summaries fall squarely inside this expectation.

4. Vendor & Third-Party Risk

Third-party operational resilience is one of the 2026 Report's headline risk areas. Any AI notetaker that stores audio, transcripts, or embeddings on vendor infrastructure now has to survive vendor due diligence documentation that the firm can produce to an examiner.

What Changed for AI Meeting Notetakers Specifically

Most "AI meeting assistants" — Otter, Fireflies, Zoom AI Companion, Fathom, and their competitors — operate on a cloud-transcription model. Audio moves from the meeting to a vendor server; transcripts and summaries are generated there and stored there for some retention window. Under a 2018 supervisory framework, that model was permissible with a DPA and a WSP paragraph. Under the 2026 Report, three specific pressure points get harder to ignore:

Off-Channel History Is About to Repeat Itself

Compliance analysts have started to draw a straight line between the 2021–2025 off-channel enforcement wave and the AI copilot boom. Global Relay's compliance hub reports that between December 2021 and early 2025, U.S. regulators charged more than 100 firms and collected over $3 billion in penalties for failures to capture business communications on approved channels. The lesson landed: WhatsApp compliance became a permanent line item.

The same publication warns that "the same logic that applied to WhatsApp in 2021 applies to internal AI copilots and collaboration tools in 2026." A business communication that happens through an AI tool needs to be captured, retained, and supervised — before a regulator arrives. If an AI notetaker is drafting client-follow-up emails or IC-meeting minutes, its outputs are business communications the moment a supervisor relies on them.

Meanwhile, on the deletion side of the ledger, MirrorWeb's July 2026 analysis notes that Rule 17a-4 and Rule 204-2 require the same records in 2026 that they required in 2018, and state securities regulators retain independent authority to request them regardless of federal enforcement priorities. Slower federal enforcement is not the same as vanished obligation.

What the Buy-Side Trade Groups Are Saying

Not every industry voice agrees on the scope. On May 1, 2026, the Investment Company Institute, in a joint letter with the Investment Adviser Association, urged the SEC to modernize the Recordkeeping Rule under the Investment Advisers Act of 1940, noting the rule was originally drafted in 1961 and does not account for modern communications technologies or cybersecurity realities. ICI's letter recommended a framework that can adapt as technologies evolve and that strikes a better balance between investor protection and retention burden.

The petition and its predecessors — including a February 2023 SIFMA joint letter and an October 2025 SIFMA follow-up analyzed by Time2Accelerate — argue that the adviser recordkeeping standard under Rule 204-2(a)(7) covers only external communications within four enumerated categories, not all AI-generated content. Whatever comes of that petition, the practical reality for a broker-dealer in September 2026 is that the rules on the books today are the ones examiners will apply.

Cloud AI Notetakers vs. On-Device: A Side-by-Side

The 2026 Report doesn't prescribe an architecture. But when compliance teams work backward from its supervisory expectations, the differences between architectures become sharper:

Dimension Cloud AI Notetakers (Otter, Fireflies, Zoom AI Companion) On-Device Transcription (Basil AI)
Where audio is processed Uploaded to vendor servers for transcription Transcribed on the user's Mac or iPhone using Apple Speech
Third-party server holds the recording? Yes — retention windows vary by plan/DPA No — no vendor server ever holds the audio
Training-data use Varies by vendor; check DPA and privacy policy carefully Not applicable — audio never leaves the device
Subpoena / discovery surface Vendor infrastructure is discoverable Only the firm's own devices are in scope
Bot in the meeting Often joins as a visible participant Botless — captures device audio without joining the call
Offline / air-gapped use Requires network connection Works fully offline
Rule 3110 supervisory chain Extends to vendor's model, ops, and access controls Contained within firm-issued devices and MDM

This is an architectural comparison, not a compliance claim. On-device processing narrows the surface area a CCO has to govern; it does not replace the CCO's determination.

How Basil AI Solves This

Basil AI is built on Apple's Speech framework, running transcription locally using the Apple Neural Engine. That architecture means the audio from an IC meeting, a diligence call, or an LP update never traverses a Basil server. There is no vendor-held recording to produce in discovery, no vendor breach vector to add to your incident-response playbook, and no third-party model training on your customer communications.

What Basil AI does not do — and what no vendor should claim to do for you — is make your firm compliant with FINRA Rule 3110 or SEC Rule 17a-4. Those determinations belong to your CCO. What Basil AI does is remove the third-party vendor server from the supervisory chain, so the question your CCO has to answer becomes narrower: how are we capturing, retaining, and supervising the transcripts that live on our firm-issued devices, under our existing MDM and WSPs?

For a broader breakdown of how architectural choices map to compliance-officer workflows, see our companion piece on AI meeting notes for compliance officers in financial services. For the buy-side lens on MNPI, see Regulation SP and AI notetaker vendor due diligence.

The New Agentic AI Wrinkle

The 2026 Report's most novel section covers AI agents — systems that don't just generate content but execute multi-step operational tasks. Snell & Wilmer's analysis observes that once an AI system can take action rather than merely generate content, the firm's supervisory, books-and-records, and governance obligations shift materially — moving AI "from the realm of communications oversight into the core of Rule 3110 (Supervision), Rule 3120 (Supervisory Control Systems), and books-and-records preservation."

This matters for AI notetakers because the roadmap for every major vendor is agentic: the tool won't just summarize the call, it will schedule follow-ups, update CRM entries, and send draft emails. The moment an AI notetaker takes an action outside the meeting, it enters the Rule 3110 core. An on-device model that hands the transcript back to the user for a human decision is a fundamentally different supervisory posture than a cloud agent making outbound moves on the firm's behalf.

What to Do Monday Morning

A five-item checklist tied to the 2026 Report's specific expectations:

  1. Inventory every AI notetaker in use — approved and shadow. Include free/personal accounts staff may be running on their own laptops.
  2. Map each tool to a Rule 3110 supervisory owner. If nobody owns supervision of the summaries, the tool doesn't clear the 2026 Report's expectation for reasonably designed supervision.
  3. Document where audio, transcripts, and embeddings are stored for each tool. Cross-reference each vendor's DPA against your firm's retention schedule for Rule 4511 / 17a-4 records.
  4. Decide which meeting types default to on-device capture or no capture — LP calls, IC sessions, cross-wall discussions, deal negotiations. Codify this in WSPs before your next exam.
  5. Add an AI-notetaker line to vendor due diligence, including model-training-data terms, retention defaults, subprocessor list, and breach-notification timing.

Bottom Line

The FINRA 2026 Annual Regulatory Oversight Report didn't invent new rules. It applied the ones broker-dealers already live under to a class of tools — AI notetakers — that quietly became infrastructure while nobody was writing WSPs about them. Architecture is now a compliance variable. A cloud transcript on a vendor server is a different Rule 3110 problem than a transcript that never left a firm-issued Mac. For further reading on how these architectural choices intersect with other 2026 developments, see our analysis of what "compliant AI meeting notes" actually means and our overview of bot vs. botless AI notetakers.

Try Basil AI — On-Device Meeting Transcription

8-hour recording. 100% on-device processing. No vendor server holds your audio.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

What did FINRA's 2026 Annual Regulatory Oversight Report add on generative AI?

The report, released December 9, 2025, introduced a standalone GenAI section that substantially expands prior guidance. It reminds firms that GenAI can implicate FINRA rules on supervision, communications, recordkeeping, and fair dealing, articulates governance and testing expectations, and — for the first time — discusses risks from autonomous AI agents. It does not create new rules but signals examination focus for 2026.

Does FINRA require broker-dealers to retain AI meeting transcripts?

FINRA's technology-neutral framework means existing recordkeeping obligations under FINRA Rule 4511 and SEC Rule 17a-4 apply when AI-generated content constitutes a business communication. The 2026 Report flags retention of GenAI chatbot communications specifically. Whether a particular AI transcript falls in scope depends on content and use; firms should have written policies addressing retention, supervision, and vendor governance for any AI notetaker they deploy.

Are AI meeting notetakers considered off-channel communications risk?

Potentially, yes. Global Relay and other compliance analysts have warned that AI copilots and meeting tools are the next off-channel communications frontier. Between December 2021 and early 2025, U.S. regulators collected over $3 billion in penalties for firms failing to capture business communications on approved channels. The same capture-retain-supervise logic applies to AI-generated summaries and transcripts.

How does on-device AI transcription change the compliance analysis?

On-device processing means audio is transcribed on the analyst's Mac or iPhone using Apple's Speech framework, so no vendor server holds the recording. That removes a third-party discovery surface, eliminates a vendor breach vector, and simplifies vendor due-diligence documentation. It does not, by itself, make a firm compliant — the CCO still decides how transcripts are captured, retained, reviewed, and produced under FINRA Rule 3110 and SEC Rule 17a-4.

What should broker-dealer compliance teams do about AI notetakers in 2026?

Inventory every AI notetaker in use (approved and shadow), map each to a supervisory owner under Rule 3110, document where audio and transcripts are processed and stored, review vendor DPAs for training-data use and retention defaults, and decide which meeting types (LP calls, IC sessions, cross-wall discussions) should default to on-device capture or no capture. Update WSPs to reflect the answers before your next FINRA examination.