Regulatory and Legal Contexts Where Decision Records Are Required

Regulators across finance, healthcare, and AI now mandate written records of key decisions.

Columnist · · 11 min read
Cover illustration for “Regulatory and Legal Contexts Where Decision Records Are Required”
Decision Records · October 4, 2026 · 11 min read · 2,460 words

Across financial services, healthcare, corporate governance, and the emerging body of AI regulation, the duty to create and keep a record of certain decisions comes from statute and case law. That distinction has teeth. A best practice can be set aside when it's inconvenient, with no consequence beyond a slightly messier file. A legal mandate carries sanctions, personal liability for the people who ignored it, and evidentiary weight in whatever dispute follows. Three separate regulatory traditions are converging on the same conclusion at once: financial communications archiving rules, corporate fiduciary duty law, and a new wave of AI-specific statutes, each arriving by its own route at the same demand, that certain decisions be written down and kept. The spread of AI meeting tools has made that convergence hard to ignore, because the same transcript that helps a salesperson remember to follow up with a client becomes, in a regulated setting, a document that regulators, opposing counsel, and judges can pull apart line by line.

Financial services: what securities regulators require firms to capture and keep

Securities regulators require financial firms to capture, archive, and supervise the communications their employees have with clients, and that duty now extends to AI-generated content on the same terms as any email or phone call. MiFID II requires firms to record every telephone conversation and electronic communication connected to, or intended to result in, a client order or transaction. MiFID II requires that these records be immutable and retrievable on demand, not simply stored somewhere and hoped for.

FINRA has built its guidance on a simple premise: the rules are "technologically neutral." That means a firm using generative AI is bound by the same securities laws that bind a firm using an old-fashioned phone system, and firms are expected to work through their compliance obligations before they test or roll out an AI tool, not after. FINRA has gone further, stating that the content standards under Rule 2210, which govern communications with the public, apply whether a human or a technology tool produced the communication. Separately, AI-generated meeting summaries and transcripts fall under the same recordkeeping and supervision requirements that apply to any other firm record under rules such as Rule 4511. There's no carve-out for content a machine wrote instead of a person.

The enforcement pattern is also moving toward individuals, not just institutions. FINRA has barred individuals from associating with any member firm in connection with off-channel communication investigations, including cases where the violation was a failure to cooperate with FINRA's inquiry itself. A personal phone used for a client conversation can end a career, not just produce a fine against the firm. None of this happened in a settled regulatory climate. The 2025-2026 period in financial services has been among the most dynamic since the aftermath of Dodd-Frank, with agency priorities shifting and supervisory philosophies evolving in real time. Even so, the core duty to archive and supervise communications has not loosened at all during that churn. Healthcare runs on a different legal theory entirely, one built not around capturing conversations but around proving a process happened.

Healthcare: how HIPAA structures documentation as a condition of compliance, not a byproduct of it

HIPAA treats documentation as the compliance itself. If a risk analysis, a remediation step, or a sanction isn't written down, HIPAA treats it as though it never occurred, regardless of what actually happened in the room. The security management process HIPAA requires has specific components: a risk analysis, a risk management plan, a sanctions policy, and procedures to regularly review how information systems are being used, and every one of these has to be documented, not just performed.

The record-keeping duty extends past the initial decision. When sanctions are applied, that application has to be documented too, and the full set, the analyses, the remediation plans, the sanctions, and the reviews, has to be kept for at least six years, whether on paper or inside a HIPAA-compliant system. That's a different structure from financial services archiving. Financial rules are largely about capturing communications as they happen. HIPAA requires specific categories of decision to be recorded as proof that a required process was actually followed.

The mandate keeps expanding rather than settling into a fixed shape. The Confidentiality of Substance Use Disorder Patient Records Rule, with a compliance date of February 16, 2026, extended this same documentation logic to SUD records, adding another category of decision that now has to be written down and retained on the same terms. Organizations using AI meeting tools in clinical or administrative settings face a new wrinkle here. Any meeting where a covered decision gets made, a risk analysis finding, a sanctions determination, a review conclusion, can now produce a transcript that sits alongside the formal record and either backs it up or contradicts it. That same tension, a verbatim machine record next to a curated human one, becomes far more consequential once it reaches the boardroom.

Corporate governance: the business judgment rule and board minutes

Board minutes function as a legal instrument that carries legal weight beyond summarizing what was said in a meeting. The business judgment rule gives directors a defense against personal liability for decisions made in good faith on the basis of adequate information, and that defense only holds up if the documentary record shows those conditions were actually met. A set of minutes that's drafted with care is the artifact that activates legal protection for the individual directors who relied on it, so the form, scope, and accuracy of that record carries direct legal consequence for the people in the room.

Corporate governance differs from financial communications archiving in one structural way: no single regulator enforces how board minutes should be kept. The obligation comes from Delaware corporate law, from state fiduciary duty standards, and from the courts that interpret both over time. That also means the standard isn't fixed in a rulebook the way FINRA's or HIPAA's requirements are. It gets worked out case by case, through litigation.

The curation of traditional board minutes is a deliberate legal choice, not a weakness in the record. Minutes are meant to capture what the board agreed should stand as the official account of its decision, and they leave out speculative remarks, preliminary thinking, or offhand comments precisely because those things can be twisted out of context later. That curation has worked as a legal shield for decades. In 2026, a Delaware court tested what happens when a second, uncurated record of the same meeting exists alongside it.

The ATG Capital decision and AI transcripts as a competing record

The Delaware Chancery Court's decision in ATG Capital, decided August 28, 2026, showed that an AI-generated transcript of a board meeting can function as a second, competing record that shapes how a court reads the board's actual motivations, even when the transcript isn't the document that decides the case. The court had two written accounts of the same boardroom events in front of it: the official minutes, prepared the traditional way, and AI-generated transcripts of the same meetings, captured verbatim.

The two didn't agree. At one meeting, the official minutes recorded that a defensive measure had been adopted to protect stockholders. The AI-generated transcript recorded the chairman describing that same measure as "necessary in order for the board to remain in its position," a characterization of intent that reads very differently from the one in the minutes. The transcripts didn't resolve the case on their own, but the court cited them in weighing the board's motivations, and a machine-generated record shaped the judicial reading of the board's own official account of itself.

This is the "two records" problem: boards using AI meeting tools now routinely generate a verbatim transcript running in parallel with their curated minutes, and the two can diverge in ways that matter in court. A Cahill Gordon analysis found that verbatim AI transcripts can preserve speculative, critical, or offhand remarks that curated minutes would normally leave out in favor of a cleaner, contextualized summary, and that this complicates fiduciary duty or securities litigation when those remarks surface later in filings or discovery, stripped of the context that made them harmless in the room. Management and executive meetings carry the same exposure, often worse, because most AI transcripts come out of management calls and pre-meeting discussions that were never formally minuted. In those cases the transcript is the only written record that exists, and records like that are generally discoverable in commercial litigation, employment disputes, and regulatory investigations. The exposure here doesn't start with what the transcript says. It starts earlier, with whether the people in the meeting ever agreed to being recorded.

The legal risk around an AI-generated meeting record doesn't wait for the transcript to be produced. It starts the moment recording begins, and in a number of jurisdictions, failing to get proper consent before that moment is itself the violation, independent of anything the transcript later contains. A bot sitting visibly in a participant list isn't legal consent in any of these jurisdictions. Some states, Oregon and Connecticut among them, apply different consent rules depending on the type of communication involved, but the common thread is that explicit disclosure is required no matter how the recording is made.

The exposure here isn't theoretical. A class action filed in December 2025 alleges violations of the Illinois Biometric Information Privacy Act, which requires written notice and consent before a company collects biometric identifiers, including voiceprints, and the suit is built on claims that AI transcription was used without the disclosure or consent the statute requires. A legal opinion cited in connection with that case concluded that clients have to be notified, and their consent obtained, whenever their calls are being recorded by an AI-powered system. Consent can't be assumed just because a bot happened to be visible on the call.

The geography compounds the problem for any organization that operates across state lines. When a recorded call includes participants from multiple states, the strictest applicable state law governs the whole call, so a single meeting can fall under California's or Illinois's consent standards regardless of where the company itself is headquartered. A compliance policy built around the law of one state doesn't protect a firm whose calls routinely include people somewhere else. The same question, who had access to what was said, and on what terms, resurfaces in a different legal context once the conversation touches a lawyer.

Attorney-client privilege and the question of whether AI-processed communications can be protected

Courts are currently split on whether a communication processed through a third-party AI tool keeps its attorney-client privilege, and at least one federal court has already held that it does not. The reasoning rests on the third-party doctrine: when a communication passes through a system whose terms of service let the provider access or use that content, the expectation of confidentiality that privilege depends on can be lost, even if nobody at the company ever reads the transcript.

That reasoning bears directly on any organization that routes board or legal meeting content through a cloud-based AI transcription service as a matter of routine. The question hasn't been settled uniformly. Other courts, weighing similar facts, have reached different conclusions. An organization can't assume its own jurisdiction will treat the issue the way a single widely discussed ruling did. What's clear is that the question is live, actively being litigated, and carries real consequences for any legal team that assumed privilege would simply carry over from an in-person meeting to a transcribed one. Legal teams should therefore run privilege review before deploying an AI meeting tool for legally sensitive sessions, not after opposing counsel has already asked for the transcript in discovery. While U.S.

The EU AI Act's employment provisions and "high-risk" retention requirements

Starting December 2, 2027, the EU AI Act's high-risk obligations apply to AI systems used in employment settings, and they require deployers, the employers and HR teams actually using a third-party AI tool, to retain AI-generated logs for at least six months. The obligation falls on both sides of the relationship. The AI vendor, as provider, and the organization using the tool, as deployer, each have to retain the logs under their own control, under Article 19 for providers and Article 26(6) for deployers. HR and legal teams need a clear answer to a basic question: what is the AI meeting tool generating, and where is that output actually stored.

That retention duty doesn't sit neatly inside the EU's existing privacy framework. It interacts with GDPR's data minimization principle without being fully subordinate to it, which creates a real tension: organizations have to retain AI logs long enough to satisfy the Act's compliance purpose while still respecting the limits GDPR places on how long personal data can be kept. Resolving that tension is a legal judgment call.

None of this sits on the horizon as a future problem to plan for eventually. The effective date was August 2, 2026. Organizations already using AI tools in hiring decisions or performance reviews are subject to these obligations now, whether or not their compliance programs have caught up.

What meeting intelligence tools must do inside these obligations

Across every one of these frameworks, financial archiving, HIPAA, board governance, consent law, privilege doctrine, and the EU AI Act, the same lesson repeats: compliance has to be built into how a meeting intelligence tool is deployed, before convenience drives the original choice of tool. The "two records" problem that ATG Capital exposed means an organization needs to make a deliberate, documented decision about whether its AI-generated transcripts count as official records, as drafts subject to review before anything is finalized, or as neither. Whatever the answer, it has to be written down and defensible on its own terms, the same way the minutes it sits beside are.

Consent has to be designed into deployment from the start, not patched in once a regulator or a plaintiff's lawyer asks about it. In two-party consent states, and under the EU AI Act's logging requirements, the method used to disclose that a recording is happening, and the proof that the disclosure actually reached the people on the call, are themselves pieces of the compliance record. Data residency and third-party access matter just as much on the privilege side: routing board or legal meeting content through a vendor whose terms of service allow employee access to that content risks destroying the very confidentiality expectation that privilege depends on. None of these obligations are hypothetical or pending. They are active, enforced, and already shaping how courts read the records that AI tools are generating inside boardrooms, clinics, and trading floors right now.

Sources

  1. 2025 Year‑in‑Review and 2026 Look-Ahead: Financial Regulatory Developments, What Has Changed Since Publication, and What’s to Come: Moore & Van Allen
  2. 1 Regulatory Compliance in 2026 and Beyond Updated as of 1/15/2026
  3. 20 26 December 2025 FINRA ANNUAL REGULATORY OVERSIGHT REPORT
  4. Books and Records Requirements Checklist for Broker-Dealers Page 1
  5. HIPAA Security Rule Changes in 2026: What You Need to Know (and Do) Now
  6. Joint Opinion Minutes of directors' meetings
  7. 10 Tips for Board Meeting Minutes: The Year in Governance
Filed underDecision Records

More in Decision Records