Sometime in the next twelve months, someone with authority over your firm is going to ask you one question: how does your firm supervise its use of artificial intelligence? The phrasing will vary. An SEC examiner will ask for your policies and procedures and the evidence that you follow them. A high-net-worth client will ask whether their personal financial data is being fed into tools you cannot name. An E&O underwriter will ask it as a new section on your renewal application. The question is the same, and an improvised answer reads exactly like what it is: a compliance program that has not caught up to its own firm.
Adoption Has Outrun Governance
The numbers explain why the question has become unavoidable. ACA Group's 2025 AI benchmarking survey found that 71% of financial services firms now formally use AI, a 26-point jump in a single year, with internal-only use climbing from 37% to 60%. Meanwhile, the 2025 Investment Management Compliance Testing Survey of 577 advisers, run jointly by ACA and the Investment Adviser Association, found compliance officers naming AI their top compliance concern, ahead of every category that dominated prior years. Read those two findings together: most firms are using AI, and the people responsible for supervising that use are telling surveyors they are not confident in how.

Why 2026 Is the Year the Question Gets Asked
The SEC's 2026 examination priorities weave AI through nearly every category that touches an RIA: whether firms have implemented adequate policies and procedures to monitor and supervise their use of AI, whether representations about AI capabilities are accurate, and whether AI-assisted outputs align with client investment profiles. We covered the full document in our breakdown of what the 2026 priorities mean for your IT program, but the AI thread deserves its own attention because of what it signals: AI review is becoming a component of routine examinations, not a specialty inquiry.
Some firms read the SEC's withdrawal of the proposed predictive data analytics rule in June 2025 as a reprieve. It was the opposite. Withdrawing the proposal did not deregulate AI; it confirmed that existing rules will do the work. Fiduciary duty, the Marketing Rule, the Compliance Rule, and Regulation S-P all apply to AI use today, with no new rulemaking required and no implementation period to hide behind.
The Enforcement Floor Already Exists
The SEC has already shown its hand. In March 2024, it charged Delphia and Global Predictions with making false and misleading statements about their use of AI, extracting $225,000 and $175,000 in penalties under the Marketing Rule and the Compliance Rule. Neither case required an AI-specific regulation. Overstating what your AI does is already a violation, and the same logic runs in reverse: using AI throughout your operation while disclosing none of it creates the disclosure gap examiners are now primed to find.
Three People Will Ask, and Each Needs a Different Answer
The examiner wants documents: a written AI policy, an inventory of tools in use, evidence of supervision, and training records. Verbal assurances that the firm is careful with AI have the same examination value as verbal assurances about anything else, which is none.
The client wants specifics, especially at the high-net-worth level. Which tools touch my data? Is it used for model training? Who can see it? Advisers who answer fluently convert the question into a differentiator. Advisers who answer with marketing language lose ground to the firm down the street that can name its vendors and its controls.
The E&O underwriter wants accuracy. AI questions are appearing on renewal applications, and an answer that does not match your actual practices jeopardizes coverage precisely when an AI-related claim would trigger it. Your application answers must come from your tool inventory, not from memory.
A Practical Framework for Approving or Restricting AI Tools
Step 1: Inventory actual use, including the unofficial kind
Survey what your people actually use, not what the firm officially licensed. Shadow AI, the personal accounts and browser extensions nobody approved, is where the real exposure lives, and you cannot supervise what you have not found. The inventory is also the source document for every disclosure, application, and client answer that follows.
Step 2: Classify tools by data exposure
A tool that drafts commentary from public market data and a tool that ingests client PII are different risk classes and deserve different rules. The amendments to Regulation S-P raise the stakes on the second class: firms must maintain an incident response program and notify affected customers within 30 days, with smaller firms subject to the requirements as of June 2026. If an AI vendor holds customer information, that vendor now sits inside your Reg S-P perimeter. Our Reg S-P compliance guide for RIAs maps the full set of obligations.
Step 3: Investigate AI vendors like any other critical third party
Ask whether the vendor trains models on your data, how long prompts and outputs are retained, whether enterprise terms differ from consumer terms, and whether independent attestations like SOC 2 exist. The differences between tiers of the same product are material. We published an honest sub-vertical look at where mainstream AI tools fit inside RIAs, CPAs, and insurance agencies and where they do not, which doubles as a diligence template.
Step 4: Write the policy before the next tool arrives
The policy needs an approved tools list, prohibited uses, a request path for new tools, and a review cadence. It should be short enough that people read it and specific enough that violations are recognizable. Our 90-day AI governance plan lays out a realistic sequence for getting from nothing to defensible in one quarter.
Step 5: Supervise, document, and fold it into your annual review
Sample AI-assisted outputs the way you sample marketing materials. Log training completion. Review the tool inventory quarterly, and make AI use a standing item in the annual compliance review required by Rule 206(4)-7. Examiners give credit for programs that show their work, and none for programs that exist only as a PDF.
Step 6: Keep the records that the Advisers Act already requires
AI does not suspend your books and records obligations. If an AI tool contributes to a recommendation, the analysis behind that recommendation still has to exist somewhere retrievable, and a chatbot conversation that vanished when the session closed does not satisfy anyone. Decide now which AI interactions constitute records, where they are archived, and how they surface during an exam. Firms that already run compliant archiving for email and messaging can usually extend the same discipline to AI outputs; firms that cannot answer where their AI outputs live have found their first remediation project.
What a Defensible Answer Sounds Like
Put the pieces together and the answer to the opening question stops being frightening. It sounds like this: we maintain an inventory of every AI tool in use at the firm, each tool is classified by the data it can access, vendors holding customer information passed third-party diligence and sit inside our Reg S-P incident response scope, our written policy defines approved and prohibited uses, we sample outputs quarterly, staff complete annual training, and all of it is reviewed as part of our 206(4)-7 annual review. Six clauses, each backed by a document.
Notice what that answer does not require: expensive tooling, a data science team, or a position on whether AI will transform wealth management. It requires the same thing every other part of a compliance program requires, which is a decision to treat the risk as real before someone with a badge, a portfolio, or a policy quote treats it as real for you. Most firms are closer than they think. The inventory takes a week. The policy takes two. The gap between having nothing and having something defensible is measured in a quarter, which is roughly the amount of runway left before exam season makes the question routine.
Where This Fits in Your Broader Program
AI governance does not stand alone. In the 2026 priorities, it sits alongside cybersecurity, Reg S-P, and operational resiliency as facets of a single question: does this firm control its technology, or merely use it? Firms without CISO-level ownership of that question increasingly answer it with fractional security leadership rather than a full-time hire they cannot justify.
Techvera builds and operates that layer for financial services firms: Managed AI for governed deployment, vCIO Services for the strategy and documentation examiners expect, and Compliance Readiness to keep the evidence file current between exams. Schedule a consultation before the question gets asked. The firms that answer it well in 2026 will have decided, well in advance, to have an answer.
Frequently Asked Questions
Does the SEC have a specific AI rule for investment advisers?
No. The SEC withdrew its proposed predictive data analytics rule in June 2025, and no AI-specific regulation currently applies to RIAs. Existing rules do the work instead: fiduciary duty, the Marketing Rule, the Compliance Rule, and Regulation S-P all reach AI use today, and the Delphia and Global Predictions enforcement actions show the Commission applying them without waiting for new rulemaking.
What AI documentation will SEC examiners ask an RIA for?
Expect requests for a written AI policy, an inventory of tools in use, vendor due diligence files, evidence of output supervision, staff training records, and proof that AI use is covered in the annual compliance review under Rule 206(4)-7. The consistent theme in the 2026 examination priorities is documentation: examiners credit programs that show their work.
Can our advisers use free consumer AI chatbots for client work?
Only if your policy explicitly permits it for the data class involved, and most firms conclude it should not. Consumer tiers of popular AI tools often retain prompts and may use them for model training, which is difficult to reconcile with Regulation S-P once client information enters the conversation. The workable pattern is vetted enterprise tools for anything touching client data, with consumer tools restricted to public information tasks.
About the Author
Team Techvera
Techvera Team
Articles written collaboratively by the Techvera team, combining expertise across cybersecurity, managed services, and digital transformation.
