Get Reg S-P ready →

Reg S-P guide › AI notetakers and service providers

Is your AI notetaker a Reg S-P service provider? A short reading of the rule for small RIAs

Published September 30, 2026 · rule text linked below

Most small advisory firms have added at least one AI tool in the last two years: a meeting notetaker that joins client calls, a transcription app, an email drafting assistant, or a chatbot someone pastes client details into. These are usually adopted by one person, quickly, without a compliance review. Amended Regulation S-P has applied to smaller advisers since June 3, 2026, and its service-provider clause is written broadly enough that it is worth checking these tools against it.

In one sentence: if an AI tool receives, maintains, processes or is permitted access to your clients' information through services it provides to your firm, the rule's definition of "service provider" reads as if it covers that tool. That is our reading of the text, not SEC guidance, and the SEC has not published anything we could find that applies the definition to AI notetakers specifically.

What the rule text says

The definitions are in 17 CFR 248.30(d) (Cornell LII copy, showing the rule as adopted at 89 FR 47786). Three matter here:

TermDefinition (verbatim from the rule)
Service provider"any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution."
Customer information"any record containing nonpublic personal information as defined in § 248.3(t) about a customer of a financial institution, whether in paper, electronic or other form…"
Sensitive customer information"any component of customer information alone or in conjunction with any other information, the compromise of which could create a reasonably likely risk of substantial harm or inconvenience to an individual identified with the information."

The service-provider requirement in 248.30(a)(5) has two parts that matter for tools like these. First, your written policies must require providers to notify you "as soon as possible, but no later than 72 hours after becoming aware that a breach in security has occurred resulting in unauthorized access to a customer information system maintained by the service provider." Second, the rule allows a written agreement under which the provider notifies affected individuals on your behalf, but "the obligation to ensure that affected individuals are notified" stays with the firm. The wider oversight duty, due diligence and monitoring, is covered on our service-provider oversight page.

Why an AI notetaker is a plausible fit [our reading]

Take the definition one clause at a time. A client meeting transcript can include names, account details, financial goals and health or family circumstances, so the recording or transcript is plausibly a record containing nonpublic personal information about a customer. The tool "receives" and "maintains" that record when it captures the call and stores the transcript. It does so "through its provision of services directly to" your firm. Reading it clause by clause, nothing in the definition excludes a vendor because the product is new, free, or categorized as AI. Whether a particular tool falls in still depends on what it actually captures, so check the vendor's data flow rather than assuming.

Two cases are less clear, and we do not claim to resolve them. A general-purpose chatbot that an employee pastes client details into is a service provider only if the firm is "permitted access" in the sense the rule uses, which the text does not spell out for consumer accounts. And a tool that only ever sees text you have fully de-identified may never touch customer information at all. If your firm relies on either point, that is a judgment to document with your compliance counsel, not one this page can make for you.

What the SEC has said about AI (and what it has not)

The Division of Examinations' Fiscal Year 2026 Examination Priorities mentions AI in two places, both outside the investment-adviser section:

We read those as two separate exposures. One is data handling (what your staff feed into AI tools and what controls surround them). The other is accuracy of what you tell clients about your own AI use, which is a marketing and disclosure topic, not a Reg S-P one. The priorities document is not a rule and does not say any specific tool is a service provider. See our exam-readiness page for how the cybersecurity items fit together.

A short checklist for each AI tool [our suggestion]

  1. Inventory it. List every AI tool anyone at the firm uses with client data, including free accounts and browser extensions. A tool nobody listed cannot be overseen. The vendor due diligence checklist lists AI notetakers as a Tier 2 category.
  2. Find out what it captures. Audio, transcript, screen share, calendar attendees, connected CRM fields. The definition turns on what the tool actually receives.
  3. Ask where the data goes. Retention period, whether recordings or transcripts are used to train models, subprocessors, and how you delete data on request or when you end the contract.
  4. Get the 72-hour clause in writing. Check the vendor's terms for breach notice timing. Many click-through terms are silent or promise less. If the terms do not meet your written policy, decide whether to negotiate, restrict the tool, or drop it, and record which.
  5. Decide who can use it and for what. A written rule such as "approved notetaker only, no client names in consumer chatbots" is easier to defend than an unwritten habit. Tell staff and keep the acknowledgement.
  6. Update your incident response plan. If the tool is in scope, a breach at the vendor is an incident you may have to assess and give notice about. See writing an incident response program and the customer notice requirements.
  7. Check client-facing statements. If your brochure, website or client communications describe your use of AI, confirm they are accurate, given the exam priority quoted above.

What this page does not say

It does not say any named AI product is or is not compliant. It does not say the SEC has brought or will bring enforcement over AI notetakers. It does not address state law, client-consent rules for recording calls, or the FTC Safeguards Rule that applies to state-registered advisers. Whether Reg S-P applies to you at all is covered on the coverage page.

Keep the AI-tool inventory and vendor evidence in one place. AdviserLedger helps a small RIA track vendors, contract terms and review dates for Reg S-P.

Get Reg S-P ready →

Sources