Data-Privacy-Aware AI Meeting Notes for Asset Managers: Keeping MNPI Off Third-Party Servers
Published September 24, 2026
- The SEC's 2022 MNPI Risk Alert put alternative data, expert networks, and access-person controls squarely under Section 204A — AI notetakers that ingest deal calls now fall in the same policy perimeter.
- May 2026's SEC action against 21 individuals in a decade-long insider trading scheme built on leaked M&A information underscores how quickly misappropriated deal data becomes an enforcement matter.
- 'No training on your data' on a marketing page is not a compliance control; it must live in the executed DPA to create legal accountability.
- Zero-day retention still means the vendor received your audio. On-device transcription means there was never a vendor copy to subpoena, breach, or leak.
- Basil AI's on-device architecture is an architectural fact — compliance is your CCO's determination, not a vendor claim.
Quick answer: For asset managers, data-privacy-aware AI meeting notes means audio and transcripts of MNPI-sensitive conversations never touch a vendor's cloud. That rules out any tool whose default architecture uploads recordings to a third-party server for processing, retention, or model training. On-device transcription — where audio is processed on the analyst's Mac or iPhone — is the only architecture that eliminates the vendor-server copy entirely.
For an asset manager, "data-privacy-aware AI meeting notes" is not a marketing phrase — it is an architecture question. Every investment committee call, expert-network interview, LP update, and management-meeting readout that runs through an AI notetaker is either processed inside your information barrier or shipped to a vendor's server for transcription, summarization, and retention. The April 26, 2022 SEC Division of Examinations Risk Alert on Investment Adviser MNPI Compliance Issues put alternative data, expert-network calls, and access-person controls squarely inside Section 204A of the Advisers Act — and the AI meeting tool that ingests those calls is now the same policy problem.
This piece walks through what asset managers should actually check before an AI notetaker touches a call that could contain material nonpublic information. It is a technical and procurement checklist, not a compliance opinion; every decision below belongs to your Chief Compliance Officer and General Counsel.
Why AI Meeting Notes Became an MNPI Question
Five years ago, AI notetakers were a productivity story. In 2026 they are a policy story, because they now sit on the calls where MNPI actually gets discussed. As the Layer3 MNPI-and-AI compliance guide puts it bluntly, an AI notetaker on a deal call records MNPI and then stores that data wherever the tool stores data — which may be outside your wall and in a system that retains or trains on inputs.
The SEC has made it clear that this is not abstract. In a May 6, 2026 press release, the Commission charged 21 individuals in a decade-long insider trading scheme built on M&A information misappropriated from multiple global law firms and tied to more than a dozen pending corporate transactions. Morgan Lewis's May 2026 Securities Enforcement Roundup described it as one of the most significant market-abuse actions of the year, with parallel criminal charges filed in the District of Massachusetts. The lesson for asset managers is not that AI caused this scheme — it did not. The lesson is that the enforcement appetite for MNPI-adjacent conduct is high, and the surface area of "where does deal-relevant audio live" now includes every AI meeting tool your analysts have installed.
What the SEC's 2022 MNPI Risk Alert Actually Says
The 2022 Risk Alert was issued by the Division of Examinations to flag deficiencies related to Section 204A of the Investment Advisers Act of 1940 and Rule 204A-1 (the Code of Ethics Rule). It called out three areas that map almost perfectly onto how AI notetakers enter a firm:
- Alternative data. The alert defined alternative data broadly to include non-traditional information sources used in financial analysis. Paul Hastings's analysis noted that the alert highlighted for the first time deficiencies and weaknesses related to alternative data policies. A transcript archive of your PMs' calls is exactly the kind of non-traditional data source examiners now expect you to govern.
- Expert networks. The alert flagged that firms should track and log communications with expert networks and review detailed call notes — which is precisely what an AI notetaker automates, and precisely why the tool's retention posture matters.
- Access persons and personal-device tools. Rule 204A-1 requires advisers to identify access persons and monitor their conduct. When an analyst installs a consumer AI notetaker on a personal laptop, the firm's ability to monitor and log that access is meaningfully weakened.
The COMPLY adviser's guide to MNPI summarizes the same alert as highlighting poor documentation of MNPI policies, lack of controls around alternative data and expert networks, and untrained access persons. Any firm that lets AI notetakers into its meeting stack without documenting those three things is inviting a deficiency letter.
Where Your Audio Actually Goes: Three Architectures
The core question your CCO and CISO have to answer is where the audio of an MNPI-sensitive conversation is transcribed. There are only three real answers, and they carry very different discovery, breach, and training-data profiles.
| Dimension | Cloud AI Notetaker (default) | Cloud + "Zero-Day Retention" | On-Device (Basil AI) |
|---|---|---|---|
| Where audio is processed | Vendor servers | Vendor servers (deleted after processing) | Analyst's Mac / iPhone via Apple Neural Engine |
| Vendor copy of raw audio | Yes, retained | Yes, transient | None |
| Discovery/subpoena surface | Vendor + firm | Vendor logs + firm | Firm device only |
| Model-training exposure | Depends on ToS | Depends on DPA | N/A — no server ingestion |
| Works offline | No | No | Yes |
| Third-party sub-processor list | Multiple | Multiple | None for transcription |
| Compliance determination | Your CCO decides | Your CCO decides | Your CCO decides |
The MeetingNotes 2026 review of AI notetakers for asset managers makes the same point about cloud tools: raw recordings and transcripts stored indefinitely on a third-party server expand your discovery exposure and create ongoing regulatory risk. Configurable retention helps, but the fundamental architectural question — does the vendor ever have the audio at all — is only answered "no" by on-device processing.
Why "Zero-Day Retention" Is Not the Same as On-Device
Zero-day retention is a real control, and it is better than indefinite storage. But it is a policy control on top of an ingestion architecture, not a replacement for one. The vendor still received your audio. Their logs, their sub-processors, their incident-response team, and any subpoena served on them all still touch your calls. On-device processing removes the vendor from the data flow entirely for the transcription step, which is a structurally different risk profile.
What to Check in the DPA, Not the Marketing Site
The MeetingNotes review draws a distinction that every asset-manager procurement team should internalize: "We don't train on your data" on a marketing page is not a compliance control. What matters is whether that commitment appears in the executed Data Processing Agreement and vendor contract, where it creates legal accountability. The same review notes that SOC 2 Type II is the baseline expectation for any vendor handling sensitive financial data, because Type II means controls were independently audited over a sustained period, not just assessed at a point in time.
Concretely, before an AI notetaker is approved for MNPI-sensitive use, procurement should be able to point to contract language covering:
- Explicit no-training commitment on customer inputs, transcripts, and derived data.
- Retention schedule for audio, transcripts, and summaries — with named defaults and configurable overrides.
- Sub-processor list and change-notification obligations.
- Breach notification timelines aligned with the firm's own SEC-facing obligations, including any 8-K disclosure timing the firm may be subject to under the SEC cybersecurity disclosure rules.
- Deletion-on-request workflow with attestation.
- Jurisdiction of processing and data-transfer safeguards (relevant if your DPA references GDPR Article 28 processor obligations).
For a fuller procurement checklist tuned to the post-Otter environment, see our AI notetaker procurement checklist for enterprise buyers.
The Expert-Network and Alternative-Data Angle
Asset managers rely heavily on expert networks and alternative data providers. The 2022 Risk Alert singled these out. If an AI notetaker sits on a specialist call, the transcript is now a piece of alternative data your firm has ingested, and the same due-diligence expectations attach. That means documented policies on what topics the transcript can cover, how it is stored, who inside the firm can access it, and how it is disposed of. It also means the same information-barrier discipline you apply to human note-takers has to apply to the AI — the tool must sit inside the barrier, not straddle it.
Our related deep-dive on expert-network calls, hedge funds, and MNPI segregation unpacks how that plays out for fundamental-strategy funds specifically.
The Broker-Dealer and Adviser Recordkeeping Overlay
Asset managers that are also registered as broker-dealers, or that share affiliates that are, sit under SEC Rule 17a-4 and FINRA recordkeeping supervision on top of Advisers Act obligations. That does not change the on-device-vs-cloud question, but it does change what happens after transcription: outputs deemed "business communications" may need to route through an archiving system such as Global Relay. On-device capture does not preclude this — the analyst can still export a finalized transcript into the firm's supervised archive — but it does mean the raw audio never becomes a discovery artifact sitting on a vendor's server. Our companion piece on FINRA's 2026 GenAI guidance and broker-dealer recordkeeping covers that side of the map.
How Basil AI Solves This: On-Device, No Vendor Server
Basil AI is architected so that the vendor-server question has a simple answer: there is no vendor server in the transcription path. Recording, transcription, speaker attribution, and summarization all run on the analyst's iPhone, iPad, or Mac using Apple's on-device Speech Recognition framework and the Apple Neural Engine described in Apple's privacy documentation. Apple's own January 2025 statement on Siri privacy underscores the same architectural principle: on capable devices, audio is processed entirely on device using the Neural Engine.
Concretely, that architecture means:
- No Basil server receives the audio of an IC meeting, LP call, or expert-network interview.
- No Basil transcript is stored in a shared multi-tenant database.
- No customer audio or transcript is ever available to train a model — not because we have promised not to look, but because we never ingest it.
- The information barrier your firm draws around a walled team also contains Basil, because the tool runs inside each walled analyst's device.
That is an architectural fact about how the app runs on Apple Silicon. Whether that architecture meets your firm's specific MNPI, Section 204A, or Rule 17a-4 obligations is your CCO's determination, not a claim Basil makes. For the underlying technical picture, see our deep dive on model training, absorption, and the right-to-be-forgotten problem, which explains why "we deleted your data" is much harder to guarantee once audio has been ingested into a training pipeline.
Comparing Basil to Cloud-Native Alternatives
Cloud-native AI notetakers — the category that includes tools like Otter.ai, whose privacy policy governs how uploaded audio may be used, and Fireflies, whose privacy policy documents its cloud processing model — are built around the assumption that audio uploads to the vendor. Even for tools with strong enterprise controls, the discovery and breach surface is different. A recent example is the tldv Firestore misconfiguration incident, which we cover in our piece on why SOC 2 is not the same as security. The point is not that cloud tools cannot be used; many firms do use them under strict retention and DPA controls. The point is that on-device processing removes a category of risk rather than mitigating it.
A Practical Rollout for a Mid-Sized Asset Manager
For a fundamental-strategy fund with 20–80 investment professionals, a realistic phased rollout looks like this:
- Inventory. Map every AI notetaker currently installed on firm and BYOD devices — including personal accounts. The Layer3 guide makes the same point: most MNPI-and-AI incidents come from convenience, when someone uses a personal account because it is fast.
- Segment meeting types. Distinguish general team syncs from MNPI-sensitive calls (IC, deal diligence, expert networks, LP updates on non-public performance).
- Set a default. For MNPI-sensitive calls, the default should be on-device processing with no vendor server in the path.
- Contract the rest. For non-sensitive meetings where a cloud tool is used, make sure the DPA carries an explicit no-training clause, a named retention schedule, and SOC 2 Type II evidence.
- Train access persons. Rule 204A-1 requires it; document the training and repeat it annually.
- Log and supervise. Include AI notetaker outputs in your normal supervisory review scope.
Frequently Overlooked Gotchas
Three things trip up asset managers most often when they evaluate AI notetakers:
- Bot-based capture on Zoom/Teams. A visible bot on a management-meeting Zoom is disclosure to the counterparty that the call is being recorded and processed by a third party. That may be fine; it may not be. On-device capture avoids the visible-bot signaling issue entirely.
- Cross-tenant summary features. Some tools generate cross-meeting insights by embedding transcripts into a vector store. Confirm whether that store is single-tenant. If not, the abstraction leaks.
- Personal-account creep. Analysts who install a personal-tier version of a cloud notetaker are outside your DPA. This is the single most common source of the MNPI-and-AI incidents described in the Layer3 guide.
The Bottom Line for Asset Managers
Data-privacy-aware AI meeting notes is not a certification you buy; it is an architecture you choose. For asset managers, the choice that eliminates the vendor-server copy of MNPI-sensitive audio is on-device transcription. That does not make any single tool "compliant" — compliance is your CCO's determination against your firm's specific policies and the SEC's expectations under Section 204A. But it does mean the discovery surface, the breach surface, and the model-training surface for the underlying audio are structurally smaller.
Basil AI is built for exactly that architectural choice. If your firm is evaluating how to bring AI meeting notes inside your information barrier without expanding your MNPI exposure, the app is available on iPhone and Mac.
Try Basil AI — Private, On-Device Meeting Notes
Your recordings never leave your device. No cloud, no training, no vendor copy.
Frequently Asked Questions
Is it legal for asset managers to use AI meeting notetakers on calls that could contain MNPI?
Yes, using AI on calls that could contain MNPI is not itself illegal, but the SEC expects advisers to have reasonably designed policies under Section 204A of the Advisers Act. The risk is architectural: if the tool trains on inputs, retains recordings on a third-party server, or exposes logs outside your information barrier, you have created MNPI exposure. Your CCO decides which architectures pass that test.
What did the SEC's 2022 MNPI Risk Alert actually require?
The April 26, 2022 Division of Examinations Risk Alert flagged deficiencies under Section 204A of the Investment Advisers Act and Rule 204A-1, specifically calling out inadequate policies around alternative data, expert networks, and access-person monitoring. It expects written policies covering how information enters the firm — which now includes AI notetakers that ingest deal calls. Your compliance officer determines how those policies apply to specific tools.
Does 'no training on your data' in a marketing page satisfy an SEC examiner?
No. What matters is whether that commitment appears in the executed Data Processing Agreement and vendor contract, where it creates legal accountability. A marketing-page promise is not a compliance control. Examiners will ask for the DPA, the retention schedule, and evidence of vendor diligence — the same standard the 2022 Risk Alert applied to alternative data providers. Your general counsel makes the final call on contract sufficiency.
How is on-device transcription different from a 'zero-day retention' cloud tool?
Zero-day retention means a vendor still receives your audio, processes it on their servers, and then deletes it — you are trusting their deletion policy, their access logs, and their subpoena response. On-device transcription means the audio never leaves the analyst's Mac or iPhone in the first place. There is no vendor copy to subpoena, breach, or accidentally retain. Your CISO decides whether that architectural difference matters for your firm.
What about SOC 2 Type II — isn't that enough?
SOC 2 Type II is a baseline expectation, but it audits the vendor's controls, not whether the vendor has your MNPI-laden recording in the first place. A SOC 2 report tells you the vendor manages their environment well; it does not eliminate the discovery surface, the training-data question, or the risk that a future breach exposes an indefinite archive of your investment committee calls. Your CCO determines whether SOC 2 alone is sufficient.
Can Basil AI be used inside an information barrier at an asset manager?
Basil AI processes audio on-device using Apple's Speech Recognition and the Apple Neural Engine, so no recording or transcript is sent to a Basil server. That architecture keeps the AI inside the same device perimeter as the walled staff who took the call. Whether that satisfies your specific information-barrier policy is your CCO's determination, not a claim Basil makes.