Reg S-P guide › AI notetakers and service providers
Most small advisory firms have added at least one AI tool in the last two years: a meeting notetaker that joins client calls, a transcription app, an email drafting assistant, or a chatbot someone pastes client details into. These are usually adopted by one person, quickly, without a compliance review. Amended Regulation S-P has applied to smaller advisers since June 3, 2026, and its service-provider clause is written broadly enough that it is worth checking these tools against it.
The definitions are in 17 CFR 248.30(d) (Cornell LII copy, showing the rule as adopted at 89 FR 47786). Three matter here:
| Term | Definition (verbatim from the rule) |
|---|---|
| Service provider | "any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution." |
| Customer information | "any record containing nonpublic personal information as defined in § 248.3(t) about a customer of a financial institution, whether in paper, electronic or other form…" |
| Sensitive customer information | "any component of customer information alone or in conjunction with any other information, the compromise of which could create a reasonably likely risk of substantial harm or inconvenience to an individual identified with the information." |
The service-provider requirement in 248.30(a)(5) has two parts that matter for tools like these. First, your written policies must require providers to notify you "as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider." Second, the rule allows a written agreement under which the provider notifies affected individuals on your behalf, but "the obligation to ensure that affected individuals are notified" stays with the firm. The wider oversight duty, due diligence and monitoring, is covered on our service-provider oversight page.
Take the definition one clause at a time. A client meeting transcript can include names, account details, financial goals and health or family circumstances, so the recording or transcript is plausibly a record containing nonpublic personal information about a customer. The tool "receives" and "maintains" that record when it captures the call and stores the transcript. It does so "through its provision of services directly to" your firm. Reading it clause by clause, nothing in the definition excludes a vendor because the product is new, free, or categorized as AI. Whether a particular tool falls in still depends on what it actually captures, so check the vendor's data flow rather than assuming.
Two cases are less clear, and we do not claim to resolve them. A general-purpose chatbot that an employee pastes client details into is a service provider only if the firm is "permitted access" in the sense the rule uses, which the text does not spell out for consumer accounts. And a tool that only ever sees text you have fully de-identified may never touch customer information at all. If your firm relies on either point, that is a judgment to document with your compliance counsel, not one this page can make for you.
The Division of Examinations' Fiscal Year 2026 Examination Priorities mentions AI in two places, both outside the investment-adviser section:
We read those as two separate exposures. One is data handling (what your staff feed into AI tools and what controls surround them). The other is accuracy of what you tell clients about your own AI use, which is a marketing and disclosure topic, not a Reg S-P one. The priorities document is not a rule and does not say any specific tool is a service provider. See our exam-readiness page for how the cybersecurity items fit together.
It does not say any named AI product is or is not compliant. It does not say the SEC has brought or will bring enforcement over AI notetakers. It does not address state law, client-consent rules for recording calls, or the FTC Safeguards Rule that applies to state-registered advisers. Whether Reg S-P applies to you at all is covered on the coverage page.
Keep the AI-tool inventory and vendor evidence in one place. AdviserLedger helps a small RIA track vendors, contract terms and review dates for Reg S-P.
Get Reg S-P ready →