Books and Records and AI Meeting Notes: Where the Line Is
•
8
MIN READ
AI Summary by Fellow
Ask five compliance officers whether an AI-generated meeting summary counts as a book and record, and you will get five different answers. That is not a knock on any of them. It is the actual state of the regulation right now.
On a recent webinar hosted by Global Relay and Fellow, Ryan Sheridan, Director of Regulatory Intelligence at Global Relay, was asked directly how firms are handling this. His answer was blunt about the ambiguity:
"I would say predominantly they're saying they're not part of books and records. I think that we also have clients that are taking a very conservative approach that are actually archiving them, because they view the material could potentially become client-facing, and they want to have the story to tell around decisions that were made."
Sheridan has more than two decades of experience leading e-comms, trade, and control room surveillance teams, with prior roles at Star Compliance, Barclays, Capital One, JPMorgan Chase & Co., and FINRA. He was joined on the call by Aydin Mirzaee, CEO and co-founder of Fellow, and moderated by Ben Hall, Head of Partner Marketing at Global Relay. What follows is drawn directly from that conversation.
Why "meeting notes" is not one category
The first mistake firms make is treating "AI meeting notes" as a single record type. It isn't. Mirzaee laid out the distinction:
"As you mentioned, there's video, audio, transcript, and AI-generated notes. And if you think about it, each one of these things is valuable in their own right... these two things, video and audio, are much more close to being biometric in their own right. And so it's, it's definitely a certain classification... So you might assume that the transcript on its own is, it's the same as the audio recording, but it's really not."
The transcript specifically carries its own risk, separate from the recording it came from:
"There's a lot of things that can actually distort what a transcript looks like. And a key distinction is that transcripts can mask whether someone's being sarcastic or what their tone is during, during the conversation. So someone could say something that could, again, if you grab that one part, it can be very incriminating sounding, but in fact it was a complete joke."
And the AI-generated summary is different again, because it involves judgment:
"An AI-generated note, I mean, this is... very judgment-oriented. Just like you have a person, if you have a different person in a meeting taking notes, it depends what things they, that person thinks is important in that conversation and the way and the style that they like to create notes."
Four artifacts, four different risk profiles, and, per Mirzaee, four different answers to whether each one is a record at all: "It really depends on what stance you take on which one of these things you want to consider to be books and records. And depending on that, or depending on the meeting types, you may have like a different protocol that you want to apply."
The most common position, and its limit
Sheridan's read on where most firms currently land: "the reality is folks are treating— I would say predominantly they're saying they're not part of books and records." Mirzaee's view from working directly with compliance teams tracks the same pattern, with a specific mechanism attached to it:
"For most organizations, they're taking the view, at least, from our customers, that as long as it's on Fellow systems and it's not on their systems, that they're not considering it as part of books and records."
The moment that changes is the moment the content leaves the meeting tool. Both speakers were explicit that email is the trigger. A live audience question raised the case of a tool that automatically emails an AI summary to the user's inbox:
Mirzaee: "What we've heard from most of our clients is that the second that it's emailed, it needs to be archived. I mean, and again, if you have Global Relay, it's going to be archived. And so I think that's the main thing. So for us, what people typically do, like the first thing that we do is we turn off emails because there's no room for a human in the loop or anything like that if it just automatically happens in that way."
Sheridan: "I would just echo Aydin's comments there. The minute, if you're in a regulated population that is being monitored, then, you know, once it is emailed, it is considered part of books and records for that employee."
That single design choice, whether a tool auto-sends a transcript to email by default, determines which side of the books-and-records line a firm ends up on before anyone has made a policy decision at all.
Why the human-in-the-loop step matters
The other variable Sheridan and Mirzaee returned to repeatedly is whether a person reviews the AI output before it moves anywhere. Mirzaee described how this plays out with CRM syncing specifically:
"One of the things that we've seen with our clients is that they don't have that be automatic. There is always a human in the loop. So whereas when we work with organizations outside of financial services, it's nope, just it's automatic. Meeting happens, CRM gets updated, no human involved. Whereas in financial services, our clients actually get us to turn that automatic feature off so that someone can actually look at the content, then it can make its way into the CRM system."
Sheridan connected that review step directly to discovery risk:
"I think you hit on something really important there around accuracy and completeness. There has to be a review process because what could potentially happen is if the record is wrong and you're turning over documents for discovery and the chain of events is different than what those meeting notes depicted, now you have a whole nother problem. So I do agree with you 100% that compliance programs from a financial services perspective, or even any other regulated entity, you have to have policies and procedures and controls in place to ensure completeness and accuracy."
Mirzaee's own comparison for this is the way board meetings have always worked:
"In a board meeting, you don't take the verbatim comments from everything that everyone said and then just send that out to everyone. There's some judgment applied, there's some synthesis that is applied, and then the decisions, the outcomes, those are the things that become the board meeting notes."
The delay between an AI note being generated and it becoming a record isn't a loophole. It's the same review step firms have always applied to formal minutes, now applied to a faster input.
The regulatory ambiguity is not going to sit still
Sheridan was clear that firms should not expect today's informal consensus to be the final word. Asked directly what happens next, he pointed to a specific, dated industry proposal and a specific enforcement signal:
"SIFMA had put out some recommendations around this time last year to the SEC to take this matter up. And it's my understanding that the SEC is going to take this under review in Q4 of 2026. So hopefully we will get some guidance going forward, probably in early 2027.
I think it is also noteworthy that just last week, the SEC created an AI and analytics function within enforcement. It's not that they didn't have AI and analytics departments before, but I think it's noteworthy that they did it within enforcement. So that tells me that they're really starting to think about these, these types of communication tools."
Asked what the SIFMA proposal would mean in practice if adopted, Sheridan's guess leaned toward more conservative treatment, not less:
"Given the technology is there to capture these, my guess is they will probably lean and be a little bit more conservative and want to pull some of these communications into the archive... My sense is that they will probably err on the side of caution and ensure that these communications, if in fact they are business-related or ultimately become judgments of business, that they are pulled in for monitoring."
He was equally direct that this is not yet an examination reality. Asked live whether any firm had been asked to produce an AI meeting recording or transcript during an exam, his answer was specific and current:
"It seems to be very exploratory, just to see firms, how they are using these tools, what tools they are using. They haven't yet said, hey, produce these types of records. Now, that's not to say that it doesn't happen in litigation, perhaps, or, you know, a civil or criminal [matter]. But at least in the examination process, I'm not aware of examination teams beginning to ask for this yet."
What this means for a firm building policy today
Nothing above resolves into a single rule, because there isn't one yet. What it gives a compliance team is a framework for the decision it actually has to make:
Separate the four artifacts. Video, audio, transcript, and AI-generated notes are not interchangeable, and a policy that treats them as one thing will be wrong for at least one of them.
Decide the email trigger explicitly. Per both speakers, the point of no return is the same across firms they work with: once content is emailed out, it is being treated as a record. Whether that happens automatically or only after human review is a configuration choice, not an accident.
Keep a human in the loop before anything syncs to a system of record. This is what makes a transcript's known weaknesses, tone loss and transcription error, defensible rather than disqualifying.
Expect the answer to firm up, not loosen. SIFMA's recommendation to the SEC, the SEC's Q4 review, and the new AI and analytics function inside enforcement all point toward more structure arriving in 2027, not less.
Fellow was built around this exact set of distinctions: configurable retention down to zero data retention, a review step before content reaches a CRM or archive, and an audit trail for firms that need to show a regulator how a decision was made.
The mechanism matters less here than the discipline behind it. The firms in the best position when the SEC does issue guidance will be the ones who already treat each artifact differently, on purpose, today.
Fellow's integration with Global Relay enables regulated organizations to automatically capture and archive Fellow’s AI-generated meeting intelligence (including transcripts, summaries, notes, and action items) in compliance with MiFID II, FINRA Rule 4511, and SEC Rule 17a-4.
Record, transcribe and summarize every meeting with the only AI meeting assistant built with privacy and security in mind.






