Back to Insights

For registered investment advisers, the AI governance conversation has moved from theoretical to concrete. Regulators are watching. Clients are asking. And the compliance framework the industry is going to converge on is coming into view.

Registered investment advisers occupy a specific regulatory position. Fiduciary duty is not aspirational language for RIAs — it is the operative legal standard. Every technology decision, including AI adoption, is measured against that standard. Which means the AI governance conversation for RIAs is fundamentally different from the AI governance conversation for a general business.

Over the last eighteen months, the SEC has signaled clear priorities around AI use in advisory contexts, state regulators are following, and the industry is beginning to converge on what a defensible RIA AI governance framework actually looks like. Here is what that framework consists of, why it matters, and how a mid-market RIA can implement it without a dedicated compliance technology team.

The regulatory question for RIAs is not whether to adopt AI — it is whether you can demonstrate that your AI adoption is consistent with your fiduciary obligations. That demonstration requires documentation, and documentation requires a framework.
Section 01

The regulatory landscape as it actually stands

The SEC has repeatedly indicated that AI use by advisers falls squarely within the existing regulatory framework rather than requiring separate rules. That is significant. It means that the standards for AI use are the standards RIAs are already familiar with — fiduciary duty, best execution, adequate disclosure, robust supervisory procedures, and documented compliance program. The AI question is how those existing obligations translate to a technology that was not contemplated when the rules were written.

The state regulatory picture is more varied, but the direction is consistent. California, New York, and a growing number of other states have added AI-specific disclosure requirements for financial services firms operating in their jurisdictions. For most mid-market RIAs, the practical implication is that the governance framework needs to be built for the most restrictive jurisdiction the firm operates in — and increasingly, that means treating AI use as a disclosable material fact.

For RIA CCOs, the working assumption should be that AI use will be examined during the next routine examination. Whether or not it becomes a formal deficiency will depend on whether the firm can produce documentation of what AI tools are in use, why, with what oversight, and what disclosures have been made to clients.

Section 02

The five pillars of RIA AI governance

A defensible RIA AI governance framework rests on five pillars. Missing any one of them creates a documented gap that a regulator or plaintiff's attorney can exploit. Getting all five in place — even in simple form — creates a defensible position.

Pillar 1 — Data protection

Client information is subject to Regulation S-P, state privacy laws, and increasingly to specific AI-related restrictions on how data may be processed. The firm must document which AI tools may receive client information, which may not, and what technical and contractual controls prevent unauthorized data flow. This is the pillar most commonly missing in mid-market firms — usually because staff have been using consumer AI tools with client information without formal authorization.

Pillar 2 — Model validation and understanding

The firm must have a documented understanding of what any AI tool it uses actually does, how it produces its outputs, and what its known limitations are. This does not require the firm to build models from scratch — but it does require the firm to be able to explain why the tool is trustworthy for the specific use case it has been adopted for. "The vendor told us it works" is not sufficient.

Pillar 3 — Disclosure

If AI is materially involved in the advice a client receives, in how their portfolio is managed, or in how they interact with the firm, that must be disclosed. Disclosure standards are evolving quickly. The prudent position is disclosure at ADV Part 2A level for anything that touches investment recommendations, and separate disclosure at point of interaction for anything client-facing.

Pillar 4 — Audit trail

The firm must be able to reconstruct, at any point, what AI tools were used in connection with a specific client, when, by whom, and for what purpose. Most consumer AI tools do not produce this audit trail natively. This drives the choice of enterprise-grade tools that log usage and provide administrative visibility.

Pillar 5 — Human oversight

No AI-produced output that reaches a client or affects a portfolio may go through without human review by a qualified professional. The reviewing professional must have both the authority and the practical capability to override the AI recommendation. This is the pillar most connected to fiduciary duty — because fiduciary duty is inseparable from professional judgment.

Section 03

The written AI use policy

The concrete expression of the framework is a written AI use policy — two to three pages, approved by leadership, distributed firm-wide, referenced in the compliance manual, and acknowledged during onboarding. This is the document a regulator will ask for, and its existence versus non-existence is often the single strongest indicator of whether the firm has thought seriously about AI governance.

The policy should cover, at minimum, six areas. Which AI tools are approved for use and for what purposes. Which categories of information may or may not be shared with AI tools. What review requirements apply before AI output reaches a client. Who has authority to approve new AI tools. What disclosure obligations attach to AI-involved services. What the process is for reporting suspected AI misuse.

Two pages. Approved by the managing principal. Signed by every staff member. That is the artifact. Building it does not require a vendor, a consultant, or a legal opinion — though having one review is inexpensive insurance for a firm at any material scale.

Section 04

Vendor management for RIA AI tools

Every AI tool the firm uses is a vendor relationship subject to the firm's existing vendor management program. The AI-specific additions to a normal vendor review are relatively small but they are material.

Data handling — where client information flows, where it is stored, and whether the vendor uses firm data for model training. Contractual protections — right to audit, breach notification, data return on termination. Regulatory alignment — does the vendor operate consistently with SEC and state requirements for the firm's jurisdiction. Business continuity — what happens if the vendor fails or is acquired. Cybersecurity — what are the vendor's security controls and how are they demonstrated. Insurance — does the vendor carry E&O or cyber coverage adequate to the risk.

The RIA does not need to build a new vendor management program for AI tools. It needs to add AI-specific line items to its existing vendor questionnaire and require that new AI vendors satisfy them before adoption.

Section 05

Client communications and the disclosure question

Perhaps the most consequential AI governance question for RIAs is what to do about client communications. AI-generated content in emails to clients, AI-drafted meeting summaries, AI-assisted responses to client questions — these are increasingly common and, in most firms, are happening without formal governance.

The prudent position: any client communication that has been materially drafted by AI should be reviewed and personalized by a human before sending. Standardized templates that are AI-drafted and human-reviewed are acceptable. Fully-automated AI responses to specific client questions require disclosure at the point of interaction that the response is AI-generated. And no investment recommendation may be delivered to a client without a qualified professional's independent review, regardless of how helpful the AI's initial draft may have been.

This is not a limit on AI's usefulness. It is a framework within which AI is genuinely useful — as a first-draft accelerator, a research assistant, a documentation aid — without creating undisclosed risk.

The Path Forward

The 60-day RIA governance sprint

For most mid-market RIAs, the practical path to a defensible AI governance posture is a 60-day sprint that produces the framework artifacts rather than tries to build them incrementally:

  1. Week 1-2: Inventory current AI use across the firm, including individual staff shadow use.
  2. Week 3-4: Draft the written AI use policy. Have compliance and legal review it.
  3. Week 5-6: Update ADV Part 2A disclosures and client agreements as needed.
  4. Week 7-8: Train all staff on the policy. Establish the AI vendor review process. Communicate disclosure updates to existing clients.

At the end of the sprint, the firm has documentation. Documentation is the single most important thing to produce, because in an examination context, the difference between "we're thinking about AI governance" and "here is our policy, our inventory, and our audit trail" is the difference between a note in the exam report and a documented compliance program.