FINRA's 2026 GenAI Guidance: What It Means for AI Meeting Notes at Broker-Dealers

Key takeaways
  • FINRA's 2026 Report expanded its GenAI section into standalone guidance — existing Rule 3110, communications, and recordkeeping obligations apply to AI meeting notetakers.
  • Summarization is the #1 GenAI use case FINRA has observed at member firms; that is literally what AI notetakers do.
  • Regulation S-P amendments (30-day customer notice, incident response plan) apply to breaches of sensitive customer info — including at your cloud transcription vendor.
  • On-device capture removes the vendor-server copy, shrinking third-party risk and Regulation S-P notification surface, but does not by itself satisfy Rule 3110 supervision.
  • Your CCO decides whether AI meeting notes are official firm records; if yes, they must live in your supervised archive under SEA Rule 17a-4.

Quick answer: FINRA's 2026 Annual Regulatory Oversight Report treats generative AI tools — including AI meeting notetakers — as subject to existing Rule 3110 supervision, communications, and recordkeeping obligations. Broker-dealers must assess GenAI risks (privacy, hallucinations, bias) before deployment, supervise outputs, log AI use, and update vendor DPAs to cover cloud transcription copies, especially given the June 3, 2026 Regulation S-P breach-notification deadline for smaller entities.

If your broker-dealer is running — or considering — an AI notetaker for internal meetings, client calls, or investment-committee sessions, FINRA's 2026 Annual Regulatory Oversight Report just gave you a compliance baseline. Released on December 9, 2025, the report added a standalone section on generative AI, and its guidance maps almost perfectly onto how AI meeting notetakers actually work. This article walks through what the 2026 Report says, which existing rules apply, how Regulation S-P intersects with cloud transcription vendors, and where an on-device architecture changes the risk math.

What the 2026 FINRA Report Actually Says About GenAI

On December 9, 2025, FINRA published its 2026 Annual Regulatory Oversight Report, and among the topics it covers are generative AI (GenAI), cybersecurity and cyber-enabled fraud, manipulative trading in small-cap equities, and third-party risk. According to Sidley Austin's summary, the nearly 90-page report highlights emerging risks including cybersecurity, data privacy, and GenAI, and reemphasizes perennial focus areas like Reg BI, third-party vendor management, and financial responsibility rules.

The most important shift is structural: this is the first year the Report contains a dedicated, standalone GenAI section. As Baker Donelson put it, the 2026 Report marks a notable escalation in the regulator's attention to generative AI. The foundational principle: FINRA's rules apply to GenAI tools just as they apply to any other technology.

Why This Matters for AI Meeting Notetakers Specifically

FINRA didn't publish this guidance thinking about note-taking apps. But two details in the Report make the connection unavoidable.

First, McGuireWoods notes that FINRA observed several member use cases for GenAI, with the most common being “summarization and information extraction” from large volumes of data. That is precisely what an AI meeting notetaker does — it takes hours of spoken audio, transcribes it, and extracts summaries and action items.

Second, the FINRA GenAI page explicitly reminds firms that using GenAI can implicate rules regarding supervision, communications, recordkeeping and fair dealing. For notetakers, all four dimensions apply: the tool is part of your supervisory system (or should be), it produces communications (summaries shared internally), those communications must be retained, and hallucinated action items in a client-facing recap raise fair-dealing concerns.

Rule 3110: Supervision Applies to AI Meeting Notes

The rule that does most of the work here is FINRA Rule 3110. FINRA's GenAI guidance is explicit: pursuant to Rule 3110 (Supervision), a member firm must have a reasonably designed supervisory system tailored to its business, and if a firm is relying on GenAI tools as part of that system, its policies and procedures may need to consider the integrity, reliability and accuracy of the AI model.

Rule 3110(b)(4) and internal communications review

Rule 3110(b)(4) requires firms to establish, maintain, and enforce written procedures for the review of incoming and outgoing written (including electronic) correspondence relating to the firm's investment banking or securities business. MoFo's Free Writings & Perspectives notes that FINRA has already confirmed firms are responsible for all communications, including AI-generated communications, and must ensure they comply with supervision, recordkeeping, and content standards.

Practically: if your AI notetaker generates a summary of a research call and it gets emailed to five people internally, that summary is an internal communication of a subject matter that may require principal review. Merely opening a communication is not sufficient review — the FINRA rulebook is clear that evidence of review must clearly identify the reviewer, the content reviewed, the date of review, and the actions taken.

Written supervisory procedures need a GenAI update

As ComplianceHub's analysis of the 2026 Report put it, the guidance is not legally binding in the same way a rule is, but FINRA examination findings are drawn directly from the Oversight Report's expectations. Firms that cannot demonstrate compliance with those expectations face findings, corrective action, and potential disciplinary proceedings. Translation: your WSPs need a GenAI section, and if AI meeting notetakers are in use anywhere at the firm, they belong in it.

Recordkeeping: Are AI Meeting Notes Official Firm Records?

This is the question most compliance officers ask us second (right after “is it discoverable?”). The 2026 Report doesn't answer it directly, but the underlying rules do. If a transcript or summary relates to the firm's securities business, it is a business record. SEA Rule 17a-4 and FINRA Rule 4511 require broker-dealers to preserve business communications for prescribed periods.

You have three defensible postures, and your CCO decides which:

What you cannot do is leave the question unanswered while the tool is running.

Third-Party Risk: The Vendor Surface Behind Every Cloud Notetaker

The 2026 Report treats third-party risk as a priority topic. McGuireWoods observed that FINRA stresses firms must maintain a reasonably designed supervisory system covering all outsourced activities, warning that a single incident at a critical service provider can affect large segments of the industry. To mitigate this, firms should conduct initial and ongoing due diligence of vendors supporting mission-critical systems (including those using or integrating GenAI tools), maintain detailed inventories of vendor services, and ensure that contracts contain robust data-protection, confidentiality and GenAI-related restrictions.

For an AI meeting notetaker, “the vendor” usually means: the transcription vendor, its cloud infrastructure provider, its LLM subprocessor for summarization, and possibly a foundation-model API. Each hop is a place customer meeting audio can be stored, logged, or — in a bad-actor scenario — accessed. If you're evaluating one, our AI notetaker procurement checklist walks through the vendor questions to ask.

Regulation S-P: The June 3, 2026 Deadline and What It Means for Vendor Breaches

Overlaid on the GenAI guidance is the amended Regulation S-P. On May 16, 2024, the SEC announced amendments to modernize the rules that govern the treatment of consumers' nonpublic personal information by broker-dealers, registered investment companies, registered investment advisers, and transfer agents.

The compliance timeline matters. Per Holland & Knight, larger entities — investment companies with more than $1 billion in assets, RIAs with more than $1.5 billion in AUM, and most broker-dealers with capital of more than $500,000 — have been required to comply since December 3, 2025, and all other Covered Institutions had a June 3, 2026 deadline. FINRA reminded member firms of that June 3 deadline in the 2026 Oversight Report itself.

Goodwin's analysis summarizes the key changes: a written incident response plan, customer breach notification, additional service provider oversight, and new recordkeeping requirements — including a 72-hour notification requirement for breaches involving customer information systems in service-provider contracts, and generally 30-day notice to affected individuals.

Here's why that matters for AI notetakers: if a cloud transcription vendor holding your customer meeting audio is breached, and that audio contains sensitive customer information (account numbers, financial positions, investment strategy), your firm — not the vendor — owes the 30-day customer notification. Regulation S-P's expanded service-provider oversight is not a paperwork exercise; it is a live obligation. This is one of the reasons our recent piece on the tl;dv Firestore breach resonated with compliance teams.

Cloud vs On-Device AI Meeting Notes: The Compliance-Relevant Differences

The 2026 Report doesn't prefer one architecture over another. But when you map the obligations to how the two architectures actually work, the operational implications differ materially.

Dimension Cloud AI Notetaker On-Device AI Notetaker
Where audio is processed Uploaded to vendor cloud + LLM subprocessors Processed locally on Apple Silicon (Mac/iPhone/iPad)
Vendor server copy of recording Yes, typically retained per vendor policy No — vendor never receives the audio
Regulation S-P vendor breach surface Vendor breach can trigger firm's 30-day notice No vendor-held customer meeting audio to breach
Rule 3110 third-party due diligence Full DDQ, DPA, subprocessor inventory required Materially reduced scope (no cloud data flow)
Rule 3110(b)(4) principal review Required for outputs Required for outputs
Rule 17a-4 / 4511 recordkeeping Firm must ingest outputs into archive Firm must ingest outputs into archive
Model-training use of audio Depends on vendor DPA / TOS N/A — audio never leaves device
Subpoena / third-party production risk Vendor may hold data subject to subpoena No vendor holding to subpoena

Both architectures still require Rule 3110 supervision and Rule 4511 recordkeeping — that's the firm's obligation and it doesn't disappear. What changes is the vendor surface: on-device processing eliminates the cloud vendor as a breach vector for the audio itself, which is what Regulation S-P's expanded service-provider oversight is designed to address.

Unique GenAI Risks FINRA Called Out — Applied to Notetakers

FINRA's GenAI page names three unique risks that remain present for all GenAI agents and their outputs: bias, hallucinations, and privacy. All three show up in AI notetakers:

How Basil AI Solves This

Basil AI is a privacy-first meeting notetaker for Mac and iPhone that performs transcription and summarization 100% on-device using Apple Silicon and Apple's Speech Recognition framework. From a FINRA compliance perspective, that architecture changes a few specific things:

For a deeper look at how this architecture applies to specific broker-dealer scenarios, see our companion pieces on expert-network calls and MNPI segregation and compliance-officer buyer guidance under Regulation S-P. And if you want the definitional framing, see our explainer on what “compliant AI meeting notes” actually means.

A Practical GenAI-Meeting-Notes Checklist for Broker-Dealers

If your firm hasn't yet done a GenAI review of notetaker use, here is a minimum starting list drawn from the 2026 Report and adjacent guidance:

  1. Inventory every AI notetaker in use — including shadow deployments on personal Zoom accounts. Theta Lake's read of the report emphasizes that off-channel communications supervision is a continuing FINRA priority.
  2. Decide, in writing, whether AI-generated transcripts and summaries are firm records under Rule 4511 and Rule 17a-4.
  3. Update WSPs to designate a supervisor for the AI notetaker, define review cadence for outputs, and specify meeting types where the tool is prohibited.
  4. Perform vendor due diligence per Rule 3110 third-party guidance — including subprocessor inventory, training-data clauses, and encryption at rest and in transit.
  5. Update service-provider contracts to include the 72-hour breach-notification obligation aligned with Regulation S-P.
  6. Establish an incident response plan that specifically contemplates a breach at the AI notetaker vendor.
  7. Log AI use — who ran it, on which meeting, with which participants and consent status.
  8. Train registered persons on hallucination review before any AI summary is acted on.

What This Doesn't Change

Two things worth stating plainly. First, on-device processing is an architecture fact, not a compliance guarantee. Basil AI is not a legal opinion, and no vendor's marketing page substitutes for your CCO's determination. Second, FINRA's 2026 Report is guidance, not a rule; the source of authority remains Rules 3110, 4511, Regulation S-P, and the securities laws they implement. What the 2026 Report does is tell you what FINRA examiners will look for, and how they will interpret existing rules when they walk into your firm and ask about GenAI.

The direction of travel is clear: GenAI oversight has moved, in FINRA's phrasing, from a theoretical concern to a regulatory expectation. AI meeting notetakers are one of the most visible surfaces where that expectation lands. Choosing an architecture that reduces the vendor risk surface — while keeping the firm's supervisory and recordkeeping obligations intact — is a defensible starting point.

Try Basil AI — On-Device Meeting Notes for Regulated Teams

Transcription and summarization run 100% on your Mac or iPhone. No vendor cloud copy of your meetings.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

Does FINRA's 2026 report create new rules for AI notetakers?

No. FINRA has said the 2026 Report is guidance, not new rules, but examination findings are drawn from its expectations. Existing rules — Rule 3110 (Supervision), 3110(b)(4) (correspondence review), 4511 (recordkeeping), and SEC Regulation S-P — already apply to GenAI meeting notetakers just as they do to any other communication or supervisory technology deployed by a member firm.

Are AI meeting notes subject to FINRA recordkeeping rules?

If the meeting relates to the firm's securities business and the AI notetaker generates a written record — a transcript, summary, or action list — that output is a business communication subject to Rule 3110(b)(4) review and SEA Rule 17a-4 retention. Firms should decide before deployment whether AI-generated meeting notes are official records, and if so, capture them in their supervised archive.

What's the SEC Regulation S-P deadline broker-dealers keep hearing about?

Larger entities have been required to comply with the amended Regulation S-P since December 3, 2025, and smaller entities faced a June 3, 2026 deadline. The amendments require a written incident response program and, generally, notification to affected individuals within 30 days of unauthorized access to sensitive customer information — including breaches at cloud AI vendors that hold customer meeting data.

Can a cloud AI notetaker satisfy FINRA supervision requirements?

Cloud tools can, if the firm treats the vendor as a third-party service provider under Rule 3110 and Regulation S-P: due diligence, contracts with confidentiality and GenAI restrictions, output review by a registered principal, and an inventory of firm data the vendor accesses. The question your CCO decides is whether that vendor surface — plus DPAs, subpoena risk, and training-data clauses — is worth it versus on-device capture.

Does using an on-device AI notetaker eliminate FINRA obligations?

No. On-device processing means the vendor never receives a cloud copy of the audio, which shrinks third-party risk and simplifies vendor oversight — but the firm still owns Rule 3110 supervision, Rule 4511 recordkeeping, and content-standards obligations for anything the tool produces. On-device is an architecture fact; compliance remains the firm's determination.

What did FINRA identify as the most common GenAI use case?

FINRA observed that summarization and information extraction from large volumes of data is the most common GenAI use case among member firms — exactly what an AI meeting notetaker does. The 2026 Report specifically calls out unique GenAI risks of bias, hallucinations, and privacy, and advises firms to test, log, and monitor outputs continuously.

Get Weekly Privacy Insights

On-device AI tips, privacy news, and Basil AI updates. No spam.

Unsubscribe anytime. Privacy Policy