5 AI-related steps to take before the SEC examiner knocks

Regulators may have no formal rule governing advisors' use of AI. Even so, their goal is clear: prevent firms from using the burgeoning technology in ways that violate long-standing investor and market protections.

Processing Content

Compliance consultants say that as firms seek new uses for artificial intelligence and machine learning, many are anxious about existing rules designed to protect private customer data and ensure clients receive accurate, suitable advice. 

In the absence of industry regulation specifically governing AI, here are steps experts recommend advisors can take to stay on the right side of the law:

  • Write policies stating explicitly when there needs to be a "human in the loop" — a person who reviews AI's work to make sure it's supported by underlying factual material and isn't inaccurate or biased.
  • Review cybersecurity policies to ensure that any private client data shared with a large language model or other AI system cannot be leaked onto the broader internet or shared with other AI users.
  • Revise policies concerning private data shared with third-party service providers. Are outside firms allowed to use AI? What should they do if there is a security breach and private information is released online?
  • Review marketing statements to ensure current and potential clients are told exactly how the firm uses AI.
  • Consider making one person or team responsible for the firm's AI use. 

Carlo di Florio, the president of the compliance consultant ACA Group, said that a recent survey his firm conducted of compliance officers at 411 investment advisor firms found that only 48% of the respondents had a policy requiring a human to be in the loop at certain times checking AI-generated results.

"That means over 50% don't have that formal policy in place, and we know that AI hallucinates and there's biases and there's errors," he said.

READ MORE: Advisors love AI, but most are scared of the compliance risks

Patchwork of rules governing advisors' AI use

There was a time when firms' AI uses seemed destined to be governed by a regulation drafted specifically for that purpose. Under former Chairman Gary Gensler, the Securities and Exchange Commission had contemplated a rule that would have made firms responsible for finding and mitigating conflicts of interest in their use of AI. Following strong resistance from wealth managers and trade groups, the proposal was dropped last summer amid a lighter regulatory approach taken by the Trump administration.

Di Florio said the wealth managers he speaks to don't necessarily want a comprehensive AI governance rule to replace the one previously put forward by the SEC. But many would like guidance on how existing rules apply to their AI use and suggestions on how to avoid violations. 

"Without the clarity of regulation, firms are grappling with trying to understand: How should we design our controls to meet regulatory expectations?" di Florio said.

Many of the SEC's current regulations touch on possible uses of AI. One of the most prominent is Regulation S-P, the primary rule requiring advisors to protect private client data. 

Recent revisions give advisors that have suffered security breaches 30 days to tell clients whose data may have been exposed. Third-party firms that advisors enlist for various services come under the same requirement.

Advisory firms have largely adopted internal policies meant to keep private client data from being entered into a public version of a large language model and shared with other users. But many have not adopted policies insisting outside service providers do the same.

Di Florio noted that ACA Group's recent survey found that less than a third of the respondents had policies governing third parties' AI use.

"We know that vendors are a major potential source of AI risk in that they might be using your information to educate their models," he said. "They might be using your information in other ways, and suddenly your sensitive information could be exposed."

Another regulation touching on AI is the SEC's books-and-records rule, which requires advisors to keep accurate records on their finances, operations and dealings with clients. Industry groups like the Investment Company Institute and Investment Adviser Association have called on the SEC to revise the books-and-records rule to clarify how it applies to modern technological developments.

Di Florio said it remains an open question what firms are supposed to do with the client-meeting summaries many now generate using AI notetakers.

"Are these transcripts books and records?" di Florio said. "And if they are, what are your expectations about what we should be doing with them? There's a very specific pain point where they would like to have some clarity."

READ MORE: SEC warns firms to get their AI house in order 

AI likely to come up in exams this year

Compliance experts note that some of the concerns about AI are being raised by regulators themselves. The SEC's list of examination priorities — which influences what investigators look for at the thousands of firms they subject to regulatory exams every year — lists AI as a top focus.

In its 2026 AI Regulatory Rundown, the consultant firm Comply said SEC examiners won't be seeking to impose new requirements on firms under scrutiny. Advisors will instead be asked to show that their AI uses fall in line with existing obligations like the fiduciary duty to always put client interests first.

"For compliance leaders, that means AI is already part of the examination cycle," Comply wrote. "Which means compliance teams need to have defensible proof around how and where AI is leveraged and how it's making decisions."

READ MORE: With 'bad' AI in regulators' sights, 6 tips to cut risk 

What advisors are doing to get ready

Advisors are preparing for the test. Adam Spiegelman, the founder of Spiegelman Wealth Management in East Bay, California, said he has yet to undergo an SEC examination since starting his firm last year following his departure from Commonwealth Financial Network. So far, his uses of AI have been very cautious, he said.

He uses the notetaker Zocks for client meeting summaries and often feeds the results into Anthropic's Claude large language model for helping drafting emails, reports and other follow-up documents.

Spiegelman said one of his first precautions was to pay for the Enterprise version of Claude, an offering designed to keep information entered into it private and not available to other users. Spiegelman said he's also careful to take anything Claude writes in an email or a report about a client meeting and consult the original transcript for accuracy.

He acknowledged that such back-checking may not save much time — one of the chief benefits touted by AI advocates. But he said he sees other advantages to the technology.

Spiegelman said a client once sent him an article about a financial topic that, at first, was a bit difficult to grasp. Spiegelman fed the article into Claude and had it produce a summary.

He then took that, put it into his own words and sent it back to the client to make sure the general idea had been captured.

"And the client got back to me and said, 'Wow, you really understand the concept,'" Spiegelman said. "So that was a relationship builder. This is someone that doesn't really give a lot of feedback at all, and for him to say that and to give a compliment was … wow."

READ MORE: The 4 AI tools I use in my practice — and 3 questions to avoid 'AI ick' 

Along with compliance, SEC wants to see AI experimentation

Di Florio of ACA said he doesn't think the SEC necessarily expects firms to show they've checked everything produced by an AI for accuracy. Instead, he said, regulators want firms to show they've tested AI results enough to show they have a reasonable expectation that they're not getting misleading answers, hallucinations or biased conclusions.

For many firms, the biggest hesitation about AI stems from using it to provide advice or make investment recommendations to clients, although ACA's latest industry survey showed a greater willingness to experiment. Twelve percent of the respondents said they were using AI for external, client-facing purposes. That was up substantially from last year.

Di Florio said firms should take comfort in knowing that even as regulators in the current administration seek to prevent abuses of AI, they also want to avoid stifling new uses of the technology.

"They want to see firms adopt it, so they're not going to come down with a heavy hand on AI adoption," he said. "But they are looking at it in exams, and they are going to find those cases where they're going to say, 'Hey, this is stepping over the line.'"


For reprint and licensing requests for this article, click here.
Practice and client management Wealth management Regulation and compliance Artificial Intelligence SEC
MORE FROM FINANCIAL PLANNING
Load More