Regulators have moved from flagging concerns to rolling out expectations on the use of artificial intelligence in wealth management. In the process, they have increased the pressure on advisory firms that treat governance as optional — not by writing new rules, but by

The SEC's
As for FINRA, the priorities of the broker-dealer self-regulator
The overall message from industry regulators is consistent: Fiduciary obligations attach to the outcome of advice, not the method used to generate it. While firms may use AI to improve efficiency, they remain fully accountable for every recommendation, disclosure and client communication.
Here are five pressing compliance risks relating to AI use by advisory firms and their fixes. A common throughline: the need for human oversight.
READ MORE:
1. AI-generated client communications
The risk: When generic or inaccurate AI-drafted content reaches a client without review, a firm is exposed to a fiduciary disclosure violation by the SEC, which holds client communications to the same accuracy and supervisory standard regardless of how they were drafted. An example would be a portfolio commentary email that misstates a fund's recent performance because the AI model summarized the wrong data.
The fix: Every AI-generated client communication should route through a human approval step before it goes out, the same way any advisor-drafted correspondence would.
2. Automated trade recommendations
The risk: When an AI tool recommends or executes a trade without checking it against a client's actual risk tolerance and investment objectives, the firm risks a suitability violation — a core fiduciary breach.
The fix: Auto-execution based solely on an AI output is exactly the kind of gap examiners look for. AI can surface the recommendation, but a human advisor should verify suitability and make the final call.
3. Sharing client data in public chatbots
The risk: Entering client account details, holdings or personal information into a public AI chatbot moves that data outside the firm's controlled environment, which can run afoul of
The fix: Firms should limit AI use to firm-hosted or enterprise-grade tools with contractual data privacy protections, not consumer-facing chat products.
4. Undisclosed AI use
The risk: If a firm uses AI to help generate recommendations or manage portfolios, but doesn't disclose that in its Form ADV or client materials, that's a fiduciary transparency violation.
The fix: Clients are entitled to know how the advice they're receiving was produced. Disclosures should be updated to reflect actual AI use as it evolves, not lag behind it. Form ADV, compliance manuals and supervisory procedures should accurately reflect how firms are using AI in practice. A firm using AI to draft portfolio commentary or investment recommendations, for example, should disclose that use in its Form ADV rather than describing the process as purely advisor-driven.
READ MORE:
5. AI audit trail gaps
The risk: If a firm can't reconstruct how an AI-assisted decision was reached — what data went in, what the model produced, who reviewed it and what action followed — that's a supervisory gap examiners will flag immediately.
The fix: Every AI-assisted action should generate an immutable log connecting the input, the output and the human who acted on it.
AI compresses hours of analytical work into seconds, surfaces patterns that manual review misses and helps smaller firms deliver institutional quality service. AI can also dramatically improve advisor productivity — from compliance monitoring and document preparation to client servicing and operational efficiency.
But under Section VII.B of the SEC's 2026 exam priorities, the expectation is clear: Firms remain accountable for every AI-assisted recommendation, disclosure and operational decision. In the eyes of regulators, responsible use of AI is fast becoming a baseline expectation.











