The Modular Briefing, August 22, 2026 · 5:31

Three different authorities, in two different countries, inside ten days. A bar association, a securities examiner and a national cyber agency. Not one of them asked whether anybody’s AI was any good. All three asked the harder question: can you show your work?

In this episode

  • The default setting is the policy. The New York City Bar Association released Formal Opinion 2026-2 on August 17 (the opinion itself is dated August 5), extending two earlier opinions from clients to co-counsel, opposing counsel, witnesses, prospective clients and a firm’s own investigators. Get consent from every participant before an AI captures a conversation, and absent a good reason, the default should be to leave it switched off. The duty of competence now includes knowing how to turn the thing off. A New York City opinion rather than a national rule, but the reasoning travels. Formal Opinion 2026-2
  • What examiners want is the minutes. Financial Advisor Magazine, working from an examination request document obtained by Citywire, reports what SEC examiners are asking investment advisers about AI: does the firm have an AI committee, does it keep written minutes, which channels promote the firm’s AI (the “AI washing” probe, with two 2024 cases settled for a combined $400,000), and were employees ever trained on the policy. No rule requires a document titled “AI policy”; advertising, compliance, privacy, recordkeeping and fiduciary rules already do the work. The ask is evidence, not a binder. Financial Advisor Magazine
  • Agent governance, written down at last, and it is four controls. The UK’s National Cyber Security Centre published interim guidance on agentic AI on August 20. Every agent gets its own identity in a class distinct from humans, credentials scoped and short-lived, a named individual accountable for its activity, and its actions logged into monitoring the way a person’s are. Their maturity ladder ends, for the most sensitive work, at no external access with the model hosted locally. Interim guidance from a British agency, not American law. NCSC

The question we asked

Pick the newest AI tool inside your business. Can you name the person accountable for it, and show what it did last week? Get the Modular Briefing by email and reply to it. A person reads every reply.

A note on the voices

Laura and Arthur are AI-generated voices, produced locally on Modular’s own infrastructure. The reporting, editorial judgement and script are the work of the Modular team. Facts and figures are drawn from the linked sources; check them there before acting on anything.

Transcript

Read the full transcript

Laura: Welcome to The Modular Briefing, the show that cuts through the AI noise and tells you what it actually means for your business. I’m Laura.

Arthur: And I’m Arthur. Here’s what tied this week together. Three different authorities, in two different countries, inside ten days. A bar association, a securities examiner, and a national cyber agency. Not one of them asked whether your AI is any good. All three asked the same much harder question. Can you show your work?

Laura: Story one, and it is about the quietest piece of software in your building. The meeting notetaker. On August seventeenth the New York City Bar Association released a formal ethics opinion from its Professional Ethics Committee on using AI to capture, transcribe and summarize conversations with people who are not your clients. The headline conclusion is one most firms have never actually made on purpose. Unless you have a good reason in that specific instance, the default should be to leave it switched off.

Arthur: And the reach is wider than it sounds. Two earlier opinions covered conversations with clients. This one extends the same principles to co-counsel, opposing counsel, witnesses, prospective clients, and your own investigators. Get consent from everyone on the call before anything starts capturing. And the line that should land for a small firm: competence now includes knowing how to switch the thing off. Two honest notes. This is a New York City bar opinion, not a national rule, and the opinion itself is dated August fifth even though it was announced on the seventeenth. But the reasoning travels. And then the situation you don’t control at all: when the other side’s notetaker is running, you don’t own its security and you may never see the transcript. So the default setting is the policy. Somebody at your firm has to decide whether the bot joins the call, and if nobody has decided, then your vendor decided for you. Your data, your rules, and that goes for the AI itself. Your AI, your rules.

Laura: Story two. In finance the same question arrived as a document request. Financial Advisor Magazine reported on August eighteenth, working from an examination request list obtained by Citywire, what Securities and Exchange Commission examiners are now asking investment advisers about artificial intelligence. And the questions are not about the technology. Does the firm have an AI committee. Does that committee keep written minutes.

Arthur: Worth saying plainly: we have not read that document ourselves, so we are relaying the reporting, not the source. What the reporting describes is a paper trail hunt. Every channel where the firm advertises its AI, which is the agency checking for what the industry calls AI washing. It brought the first two of those cases in twenty twenty-four, and they settled for a combined four hundred thousand dollars. And whether employees were ever actually trained on the policy they were handed. Here is the part that travels well past finance. There is no rule requiring a document titled AI policy. The rules that already exist do the work: advertising, compliance, client privacy, recordkeeping, and your duty to the client. So nobody is asking you to invent a new binder. They are asking for evidence. An inventory of which tools are actually running. A training log with dates on it. Minutes that show a decision and who made it. That is an afternoon of work this month, and it is impossible to manufacture in the middle of an examination.

Laura: Story three, and it’s the one I’d print out. On August twentieth the United Kingdom’s National Cyber Security Centre published interim guidance on the cyber risk of agentic AI. As far as we can tell it is the first time a government body has written down what governing an agent actually means in practice. It is shorter than anybody selling you a governance platform would like.

Arthur: Four things. Every agent gets its own identity, in a class of its own, not a human’s login. Its credentials are narrow and short lived. A named person is accountable for what that agent does. And the agent’s actions get logged into your monitoring exactly the way a person’s activity is. That’s the list. Notice what it fixes. If your agent runs on an employee’s credentials, then in your own logs the agent and the employee are the same actor, and you can’t answer the only question that matters afterward: which one of you did that? Give the agent its own name and the answer writes itself. One caveat, said clearly: this is a British agency, and it’s interim guidance, not American law. Nobody needs to wait for their own regulator to copy four controls that already work. And note where their own maturity ladder ends up for sensitive work. No external access, model hosted locally, on infrastructure you control. From dirt to desktop. Your data, your rules.

Laura: So the thread. A bar association asked for consent before the software listens. An examiner asked for the minutes. A cyber agency asked for an owner and a log. Two continents, three authorities, ten days, and none of them wanted a demo. Every one of them wanted proof. Capability is the part you buy. Evidence is the part you keep, and nobody can buy it for you afterward.

Arthur: So here’s our question this week. Pick the newest AI tool inside your business. Can you name the person accountable for it, and show what it did last week? If both come easily, you’re in better shape than most. If they don’t, that’s not a failure, it’s just the next thing to write down. Reply to the Modular Briefing email and tell us where you landed, or write to me at arthur at modtechgroup dot com. A person reads every reply.

Laura: Thanks for spending a few minutes with us.

Laura & Arthur: This has been The Modular Briefing. Your data, your rules. We will see you next time.

Your data, your rules.