Framework · 2026 · Updated September 14, 2026

AI Compliance Framework
for SEC-Registered Advisers

There is no AI rule for investment advisers. AI use falls under obligations advisers already have: fiduciary duty, the Compliance Rule, Regulation S-P, the Marketing Rule, and books and records. This framework organizes those obligations into six control areas and marks which items a rule requires and which are our recommended practice.

Download the PDF

The regulatory landscape

AI changes the evidence a firm needs to produce, not the rules it follows. The SEC's Fiscal Year 2026 Examination Priorities say examiners will review the adequacy of advisers' policies and procedures for monitoring AI use and the accuracy of what firms say about their AI capabilities. Firms should be ready to show which AI tools are in use, who approved them, what data they can reach, and how the vendors are overseen. The rules below are the ones most often relevant. Which of them apply, and how, depends on how the firm actually uses AI.

Rule 206(4)-7: Compliance Programs

The Compliance Rule requires written policies and procedures reasonably designed to prevent violations of the Advisers Act, and a review of their adequacy and effectiveness at least annually. It does not mention AI. If AI use creates risks the existing policies do not address, such as AI-drafted client communications or AI inputs to investment decisions, the firm should update its policies to cover them. The annual review is the natural place to test whether those controls work.

Regulation S-P (as amended, 2024)

The amendments are now in force for every registered adviser. Larger advisers ($1.5 billion or more in assets under management) had to comply by December 3, 2025, and all others by June 3, 2026. Three provisions matter most for AI:

  • Service provider oversight. A service provider is any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution such as the adviser (17 CFR 248.30(d)(10)). An AI vendor the firm engages fits that definition when customer information flows to it. The firm's incident response program must include written policies and procedures requiring oversight of those providers, through due diligence and monitoring. The procedures must be reasonably designed to ensure providers protect customer information and notify the firm as soon as possible, but no later than 72 hours after becoming aware of a breach in security resulting in unauthorized access to a customer information system they maintain (248.30(a)(5)(i)).
  • Customer notification. When sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, the firm must notify affected individuals as soon as practicable, and no later than 30 days after becoming aware of it. The exception is a determination, after a reasonable investigation, that the information has not been and is not reasonably likely to be used in a manner that would result in substantial harm or inconvenience (248.30(a)(4)).
  • Records. The written policies, incident documentation, and notification determinations must be kept under Rule 204-2(a)(25).

A vendor ordinarily does not become the firm's service provider just because an employee used a personal consumer account without authorization; the firm should assess the facts against the definition. Customer information entered that way may still be unauthorized access or use that the firm's response program has to assess. That is the practical case against consumer accounts for firm work: no contract, no administrative control, and no firm-administered way to retrieve, preserve, or delete what was entered.

Rule 206(4)-1: Marketing Rule

The Marketing Rule prohibits advertisements that contain untrue statements of material fact, material claims the firm cannot substantiate on demand, or content that is otherwise materially misleading. That applies whether or not AI drafted the advertisement, and it applies to claims about the firm's own use of AI. The SEC's March 2024 settlements with Delphia and Global Predictions included Marketing Rule charges over AI capabilities the firms did not have. The rule does not require pre-publication approval. Having a qualified person review AI-drafted marketing before it goes out is our recommended control. Rule 204-2(a)(11) generally requires the firm to keep a copy of each advertisement it disseminates, with alternative records allowed for oral advertisements.

Rule 204-2: Books and Records

Rule 204-2(a)(7) requires advisers to keep written communications sent and received relating to recommendations made or proposed, advice given or proposed, the receipt, disbursement, or delivery of funds or securities, and the placing or execution of orders. These records are generally kept for five years from the end of the fiscal year of the last entry. AI does not change what counts as a record. A client email drafted with Copilot is a record once it is sent if it falls in those categories, and an AI meeting summary that documents advice given to a client may be one too. The question to answer is whether the firm's archiving captures those outputs where they actually live.

Other obligations that may apply

  • Fiduciary duty. Advice must be in the client's best interest and rest on a reasonable basis. We recommend independent human validation of any AI output used in forming advice.
  • Form ADV Part 2A. Where AI is material to the firm's methods of analysis or investment strategies, disclosure may be required, and it must be accurate.
  • Regulation S-ID. Advisers subject to the Identity Theft Red Flags Rule, which generally includes advisers that can direct transfers or payments from client accounts to third parties, should consider whether voice cloning, deepfake impersonation, and AI-generated phishing are relevant red flags for their covered accounts.
  • State recording laws. AI notetakers that record client calls can trigger consent requirements under state law.

The SEC withdrew its 2023 predictive data analytics proposal in June 2025. This framework does not treat it as law.

Six Control Areas

The framework

Each area separates what a rule requires from what we recommend. Rules rarely dictate a specific AI control, so most of the practical steps below are our recommendations for meeting a broader obligation.

1. Inventory, ownership, and approved uses

What the rules require. No rule requires a document called an AI inventory. The Compliance Rule does require policies that address the firm's actual risks, and Reg S-P oversight applies to every service provider that receives customer information. A firm cannot meet either obligation without knowing which AI tools are in use.

What we recommend. Keep a one-page AI tool register: tool, vendor, product tier, owner, business purpose, data permitted, approval date, due diligence date, and records treatment. Include AI features built into software the firm already licenses, such as meeting platforms, CRM, financial planning, and portfolio reporting, which vendors often turn on by default. Survey staff anonymously about what they actually use; in our experience the answer is usually longer than IT's list. Publish an approved-tool list, give every tool a named owner, and route new tools and newly enabled AI features through a short approval: business need, data involved, vendor review, CCO sign-off.

2. Data handling and vendor oversight

What the rules require. Reg S-P safeguards, service provider oversight under 248.30(a)(5), and the customer notification program apply when an AI vendor receives customer information.

What we recommend. Set plain data rules: which categories of information may go into which approved tools. Keep sensitive customer information, such as Social Security numbers, account numbers, and credentials, out of any tool not approved for it. Complete vendor due diligence before client data flows: training terms, retention, where data is processed, subprocessors, breach notification commitments that meet the 72-hour standard, and export and deletion at termination. Get the vendor's commitments in writing. The rule requires oversight rather than a specific contract, but a contract is the clearest evidence of it. Block consumer AI accounts for firm work where your tools allow it, and prohibit them in policy where they do not.

Product tier Training on your data Typical fit, subject to your own review
Consumer plans: ChatGPT Free, Plus, and Pro; Claude Free, Pro, and Max; personal Gemini; consumer CopilotDefaults vary by vendor and setting; conversations may be used for model training unless the user opts out. Personal accounts the firm cannot administer.Not recommended for firm work. Any exception should be documented and limited to public information.
ChatGPT Business (formerly Team) and ChatGPT EnterpriseBusiness data is not used for training by default. Firm-administered workspace.General drafting and analysis once vendor review is complete.
Claude Team and Claude Enterprise (Anthropic)Not used for training by default under commercial terms. Firm-administered workspace.General drafting and analysis once vendor review is complete.
Microsoft 365 Copilot and Copilot Chat, signed in with a work accountPrompts and responses are not used to train foundation models. Microsoft's commercial data protection terms apply.Firms on Microsoft 365, after a permissions review. Copilot can surface content the user has access to but would not normally find.
Gemini in Google Workspace (Business and Enterprise editions)Workspace content is not used to train models outside your organization without permission.Firms on Google Workspace, after a sharing review.
Azure OpenAI, AWS Bedrock, and direct model APIsTerms vary by provider; the major providers' commercial terms generally exclude API data from training. Processing location and retention depend on configuration. Verify each service separately.Custom builds by firms with the staff to run and secure them.

Vendor terms change and differ by contract. Verify the current terms for your plan before approval. Reviewed September 2026.

3. Client communications, advice, and marketing

What the rules require. Fiduciary duty requires advice in the client's best interest with a reasonable basis. The Marketing Rule applies to AI-drafted advertisements and to claims about the firm's use of AI. Form ADV must describe material AI use accurately where it is part of the firm's methods or strategies.

What we recommend. Require human review of any AI output that reaches a client, informs a recommendation, or appears in a filing. Keep a claims file that substantiates every statement about AI on the website, in pitch materials, and in Form ADV. Avoid both boilerplate ("the firm may use artificial intelligence") and overstatement ("our AI optimizes client portfolios"). Make clear to staff that AI-drafted text becomes their text once they send it.

4. Books and records, meeting tools, and communication channels

What the rules require. Rule 204-2 retention for communications about advice, funds, and orders, a copy of every advertisement, and Reg S-P incident records under 204-2(a)(25). State consent laws may apply to recorded calls.

What we recommend. Decide in writing which AI outputs are records and where they are kept. Confirm the archive actually captures them: a Copilot draft that becomes a sent email is captured, but a transcript sitting in a notetaker vendor's cloud usually is not. Approve or prohibit meeting notetakers by name (Otter, Fathom, Zoom AI Companion, Teams recaps), set a consent procedure for client calls, and stop unapproved bots from joining meetings. Treat AI chat tools used with clients like any other channel: approved and captured, or prohibited.

5. Access, devices, and AI-specific threats

What the rules require. Reg S-P safeguards for customer information, and Reg S-ID red flags for advisers subject to that rule.

What we recommend. Use work accounts with single sign-on and multi-factor authentication for every approved AI tool, so access ends when employment does. Review what an AI assistant can reach before rollout; Copilot can surface stale shared mailboxes and overshared SharePoint sites the user still has access to. Review connected apps, plugins, and browser extensions that can read email or files. Treat instructions hidden in outside documents (prompt injection) as a real risk: limit what AI tools can act on, and have staff send suspicious attachments to IT first. Require call-back verification on a known number for wires, banking changes, and credential resets, because voice cloning now defeats "it sounded like the boss." Set rules for AI apps on personal phones.

6. Training, monitoring, and annual review

What the rules require. The Rule 206(4)-7 annual review and the Reg S-P incident response program.

What we recommend. Add an AI module to annual training built on the firm's own approved list and data rules. Run one tabletop a year with an AI scenario; a cloned voice asking for a wire works well. At least quarterly, review licensed users, admin settings, and newly enabled AI features using whatever reporting the vendor provides. Treat a vendor's new AI feature as a change that reopens its due diligence. Add AI scenarios to the annual risk assessment and include AI in the annual compliance review. Document AI controls where they fit in the existing program (acceptable use, vendor management, marketing, records, incident response). A standalone AI policy is one way to do it, not a requirement.

If you build your own AI tools

Some firms build internal assistants on their own documents, call models through an API, or use models in trading and portfolio tools. Those firms need controls this page does not cover in depth: least-privilege access to APIs and document stores, protection of the source documents the tool draws on, testing before deployment and after model changes, change logs and rollback, and periodic adversarial testing. Models used in investment decisions also raise conflict, testing, and override questions under fiduciary duty. The PDF edition covers these in an appendix.

Implementation

30/60/90-day starting plan

Timeframe Priority actions
Days 1-30 Inventory AI tools, personal accounts used for work, meeting bots, browser extensions, and AI features inside existing software. Survey staff anonymously. Issue interim rules: no client data in unapproved tools, and human review before anything AI-drafted reaches a client. Stop any consumer-account use involving client data.
Days 31-60 Approve specific tools and uses. Complete vendor review for tools that receive client data. Decide the records treatment for AI outputs and notetakers. Configure sign-on, MFA, sharing, and retention settings. Update the incident response program and, if applicable, the Reg S-ID red flags.
Days 61-90 Train staff on the approved list and data rules. Run an AI tabletop. Spot-check a sample of AI-assisted client communications to confirm they were reviewed and archived. Document exceptions and fold the results into the annual review.

Documented controls sized to the AI a firm actually uses let it show an examiner how it identified and addressed those risks. Firms that cannot show who approved a tool, what data it can reach, and how the vendor is overseen will have gaps to explain.

This framework is general guidance. Requirements depend on each firm's facts and applicable law. It does not constitute legal advice.

BrainTrust Premium includes this document

This document is part of the full template library available to BrainTrust Premium subscribers. Members can sign in to download it.

Sign in or view BrainTrust Premium