SEC 2026 Exam Priorities and AI Meeting Notetakers: What Investment Advisers Should Have in Writing
Published September 10, 2026
- SEC's November 17, 2025 exam priorities make AI a focus area across virtually all adviser exams — including meeting notetakers.
- Existing rules apply: Rule 206(4)-7 (policies), Rule 204-2 (records), Regulation S-P (vendor DD), and the Marketing Rule.
- The June 3, 2026 Reg S-P deadline extended vendor due diligence and 72-hour breach notice obligations to smaller RIAs under $1.5B AUM.
- On-device transcription shrinks the vendor/subpoena/breach surface by keeping audio off third-party servers — but is an architecture choice, not a compliance guarantee.
- Written policies must match actual practice; the SEC's December 2025 Marketing Rule risk alert flagged firms whose P&Ps didn't reflect real workflows.
Quick answer: The SEC's 2026 examination priorities, released November 17, 2025, elevated AI to a focus area across virtually all adviser exams. For AI meeting notetakers, examiners will test written Rule 206(4)-7 policies covering where audio is processed, retention, training-data use, and Reg S-P vendor due diligence — a set of controls that becomes simpler when the recording never leaves the analyst's device.
On November 17, 2025, the SEC's Division of Examinations released its 2026 Examination Priorities, and the message for registered investment advisers running AI meeting notetakers is direct: examiners will assess AI use through the lens of existing rules — Rule 206(4)-7 policies, Advisers Act Rule 204-2 recordkeeping, Regulation S-P vendor oversight, and the Marketing Rule — during virtually every exam this fiscal year. The tool that sits silently in an investment-committee call or a client review is now inside that perimeter. This piece walks through what changed on November 17, what changed on June 3, 2026 with amended Reg S-P, and what a written policy for AI meeting notes should actually cover — with a comparison of cloud versus on-device architecture that shapes how big your vendor-oversight lift becomes.
What Changed on November 17, 2025
The Division of Examinations publishes its priorities annually to flag risks it plans to focus on. The Foley & Lardner summary of the 2026 priorities notes that the Division "unsurprisingly remains focused on how firms use emerging technologies" including automated investing tools and AI. A more consequential framing comes from Goodwin's analysis: the Division has integrated AI into cybersecurity, emerging technology, automated investment tools, and operational resiliency — meaning AI oversight will be a component of virtually all examinations going forward, not merely examinations of firms specifically marketing AI capabilities.
Cleary Enforcement Watch reads the 2026 Priorities as signaling less (but still present) focus on private fund advisers and more focus on retail advisers and emerging technologies such as AI and algorithmic advice. That framing matters for the AI-notetaker question: a retail-facing wealth manager whose advisers use an AI notetaker in every client review is now squarely inside the examination narrative.
The 'AI in every exam' shift
The practical takeaway from the PKF O'Connor Davies review is that emerging financial technologies — including AI, trading algorithms, and automated tools — will face increased scrutiny regarding supervisory and governance protocols, while cybersecurity, information security controls, and vendor oversight remain top regulatory concerns under Regulation S-P and Regulation S-ID. For a compliance officer, that translates into a single question examiners will pose: show me your written AI policy, and show me it matches what your advisers actually do.
What Changed on June 3, 2026: Amended Regulation S-P
The other 2026 date that reshapes AI notetaker vendor oversight is the amended Regulation S-P compliance deadline for smaller RIAs. Troutman's privacy team summarized the timeline: firms over $1.5B AUM had a December 3, 2025 deadline, and smaller firms had until June 3, 2026 to update their privacy and safeguards programs under the Gramm-Leach-Bliley Act framework.
The SWK Technologies summary is precise about the vendor-oversight lift: written policies must be reasonably designed to require oversight of service providers through both initial due diligence and ongoing monitoring, and service providers must notify the covered institution "as soon as possible, but no later than 72 hours" after becoming aware of a breach affecting a customer information system. The STP Investment Services analysis summarizes the customer-facing side: notice to affected individuals as soon as practicable, but no later than 30 days after becoming aware of certain unauthorized access to or use of sensitive customer information.
Every AI meeting notetaker vendor that receives customer audio, transcript, or metadata falls inside that framework. The Ncontracts June 2026 vendor management update flagged that the SEC has signaled Reg S-P compliance will be a priority in examinations conducted later this year — precisely the window firms are now in.
Rule 206(4)-7: The Written Policy Requirement
Under Rule 206(4)-7, every SEC-registered adviser must adopt written compliance policies reasonably designed to prevent violations. Ncontracts' 2026 AI compliance overview notes that 40% of investment adviser firms have implemented AI tools internally, but 44% of those firms have no formal testing or validation of their outputs — a gap examiners are actively looking for.
An AI-notetaker-specific policy under Rule 206(4)-7 should answer, at minimum, six questions:
- Processing location — Where does audio get processed? On the analyst's device? On a vendor cloud? In which region?
- Retention defaults — Is a recording persisted at all? For how long? Where?
- Training data — Does the vendor use customer content to train models? Is that commitment in the DPA, not just a marketing page?
- Vendor due diligence — Have you completed a Reg S-P vendor assessment, with 72-hour incident notification in the contract?
- Human oversight — Who reviews AI-generated summaries before they enter the client file?
- Marketing Rule alignment — If AI content ever touches prospect-facing materials, does it satisfy Rule 206(4)-1?
The 'policies vs. practice' trap
In December 2025, the SEC issued a Marketing Rule risk alert flagging advisers whose policies reflected the rule but whose practices didn't, per Ncontracts' analysis. The lesson generalizes: examiners are testing whether written AI policies are operating in practice, not just on paper. A firm with an on-paper prohibition on cloud AI notetakers whose advisers actually run Otter or Fireflies on the side has a policies-vs.-practice deficiency waiting to happen.
Rule 204-2: When AI Notes Become 'Books and Records'
Advisers Act Rule 204-2 is the recordkeeping rule that determines what AI-generated content firms must preserve. The Kitces analysis of SEC frameworks identifies the primary RIA AI use cases as "general research to aid in the investment advisory and financial planning process, the recording, transcription, note-taking, and summaries of client meetings, reviewing draft email communications, preparing initial marketing content." Each of those interactions can trigger Rule 204-2.
The dual-registrant analysis at Time2Accelerate puts the stakes in dollar terms: since 2021, the SEC has assessed more than $2.2 billion in combined penalties against financial firms for recordkeeping failures related to off-channel communications, and FINRA's 2026 Annual Regulatory Oversight Report introduced a dedicated generative AI section for the first time.
For AI meeting notes specifically, the Beach Street Legal write-up observes that recording, transcription, and summarization capabilities can be "particularly useful for capturing adviser and client action items, evidencing the verbal transmission of information or disclosures, and generally memorializing the discussion for future reference" — and each of those uses triggers a distinct set of compliance considerations.
The MNPI Angle: When Notetakers Sit in Deal Calls
For advisers whose meetings touch material nonpublic information, the 2026 priorities need to be read alongside the July 2026 Skadden analysis of SEC recordkeeping and AI. The concern is not only recordkeeping but MNPI containment: broker-dealers and investment advisers must maintain policies reasonably designed to prevent the misuse of MNPI, and firms risk scrutiny if AI tools foreseeably could use restricted data improperly, even absent an actual trade.
That's why the architecture of the AI notetaker matters. Cloud transcription creates a third-party copy of an investment-committee call. On-device transcription does not. Our companion piece on MNPI-aware AI meeting notes for asset managers walks through the containment logic in depth.
Cloud vs. On-Device: Vendor Oversight in Two Architectures
The examination-readiness lift for a cloud AI notetaker and an on-device AI notetaker differ materially. The table below maps them across the specific rule dimensions examiners will test in 2026.
| Dimension | Cloud AI notetaker | On-device AI notetaker |
|---|---|---|
| Where audio is processed | Vendor servers (often multi-region) | Analyst's Mac or iPhone; Apple Neural Engine |
| Reg S-P vendor DD required | Yes — full vendor questionnaire, DPA, 72-hour breach clause | No vendor server holds the recording; the app itself still requires app-vetting |
| Third-party breach exposure | Vendor breach = customer notification obligation | No vendor holds the data to be breached |
| Subpoena / discovery surface | Vendor can be subpoenaed for stored audio/transcripts | Firm remains sole custodian; standard document custody rules apply |
| Training-data risk | Must confirm in DPA that customer content isn't used to train models | Content never leaves device; no training pathway exists |
| Rule 204-2 retention | Firm must reconcile vendor retention with 204-2 obligations | Firm controls retention directly on device / firm storage |
| Compliance determination | CCO evaluates vendor + workflow | CCO evaluates workflow; vendor surface is materially smaller |
Neither row is "compliant" or "non-compliant" in the abstract — the CCO's fit determination is what matters. But the on-device row starts with fewer moving parts to document, fewer vendor contracts to renegotiate for 72-hour breach clauses, and no third-party server holding the recording of an LP call or a client review.
How Basil AI Solves This
Basil AI runs transcription 100% on-device using Apple's Speech framework and, on Apple Silicon, the Apple Neural Engine. The audio of an investment committee meeting is captured, transcribed, and summarized on the analyst's Mac or iPhone. No vendor server holds a copy. No third-party DPA is renegotiated for the 72-hour Reg S-P breach clause because no third party receives the recording in the first place.
That is an architecture fact, not a compliance guarantee. The firm's CCO still owns the Rule 206(4)-7 determination, still writes the Rule 204-2 retention policy, and still decides how AI-generated summaries flow into the client file. What changes is the size of the vendor-oversight lift and the scope of third-party breach exposure. For a related walk-through of that architectural distinction, see our Reg S-P vendor due diligence guide and our overview of AI meeting notes for compliance officers in financial services.
What To Do Monday Morning
A practical five-step checklist for advisers preparing for a 2026 exam that will touch AI notetakers:
- Inventory every AI notetaker in use. Include personal-account tools employees run without IT approval — the SEC does not care whose account signed up.
- Map each tool to Rule 206(4)-7 policy language. If the policy says "advisers may use approved AI transcription tools," define "approved" and list them.
- Audit Reg S-P vendor files. Confirm every cloud notetaker vendor has a signed DPA with a 72-hour incident notification clause per the amended rule.
- Reconcile retention with Rule 204-2. Where do transcripts and summaries live? For how long? Can you produce them on examiner request?
- Test the policies-vs.-practice gap. Ask three advisers what notetaker they used on their last client call. If the answer doesn't match your inventory, you have a December-2025-Marketing-Rule-alert-style problem.
For deeper reading on the definitional questions examiners actually probe, see our piece on what 'compliant AI meeting notes' actually means.
Bottom Line
The SEC did not write new AI rules in the 2026 priorities. It made clear that existing rules — Rule 206(4)-7, Rule 204-2, Regulation S-P, and the Marketing Rule — will be applied to AI tools including meeting notetakers across virtually every adviser exam this fiscal year. The June 3, 2026 Reg S-P deadline extended the vendor-oversight framework to smaller RIAs, and the July 2026 Skadden MNPI guidance sharpened the deal-context stakes. The architecture of your AI notetaker doesn't determine compliance — but it does determine how large your written policy, vendor file, and breach-notification surface need to be. On-device processing shrinks all three.
Try Basil AI: 100% On-Device Meeting Notes
Audio stays on your Mac or iPhone. No vendor server. No cloud copy.
Frequently Asked Questions
Did the SEC issue AI-specific rules in the 2026 exam priorities?
No. The SEC has taken a technology-neutral approach — existing rules like Rule 206(4)-7, Advisers Act Rule 204-2, Regulation S-P, and the Marketing Rule apply to AI use. The 2026 priorities, released November 17, 2025, signal that examiners will apply those existing frameworks to AI tools including meeting notetakers, not that new AI regulations are being enacted.
Are AI meeting notes considered 'books and records' under Rule 204-2?
They can be. Under Advisers Act Rule 204-2, records that memorialize advice, recommendations, or communications with clients may be required records. If an AI notetaker produces summaries, action items, or transcripts that document advice, firms need retention, indexing, and reproducibility policies that satisfy the rule — regardless of whether the tool is cloud or on-device.
Does the June 3, 2026 Regulation S-P deadline apply to AI notetaker vendors?
Yes, when the vendor receives customer information. Amended Reg S-P requires written vendor due diligence, 72-hour breach notification from service providers, and 30-day customer notification. On-device processing avoids sending audio to a vendor at all, materially shrinking the S-P surface — though the CCO still owns the compliance determination.
What should a written AI policy include for meeting notetakers?
At minimum: where audio and transcripts are processed, retention defaults, whether content is used for model training, DPA and BAA scope, incident-notification SLAs, human-oversight procedures for AI output, and Marketing Rule guardrails when AI summaries touch prospect-facing materials. The SEC expects policies to reflect what firms actually do, not aspirational language.
Is on-device transcription automatically compliant?
No. 'On-device' is an architecture fact — the audio and transcript stay on the analyst's Mac or iPhone with no vendor server holding the file. That materially shrinks vendor, subpoena, and breach exposure, but Rule 204-2 retention, Rule 206(4)-7 supervision, Marketing Rule guardrails, and MNPI containment obligations are still the firm's determination.
How do the 2026 priorities treat AI vendor oversight?
The 2026 priorities integrate AI into cybersecurity, emerging tech, automated tools, and operational resiliency, meaning AI oversight will feature in virtually all exams. Examiners will test whether Reg S-P vendor due diligence, incident response programs, and Rule 206(4)-7 policies actually cover AI tools that touch client data — including meeting notetakers.