Advisor Perspectives welcomes guest contributions. The views presented here do not necessarily represent those of Advisor Perspectives.
Since December 2021, the SEC’s crackdown on off-channel business communications has resulted in more than $2 billion in penalties, reinforcing one lesson for the industry: If a business conversation happens somewhere you cannot preserve it, you have a books-and-records problem, no matter how ordinary the channel feels.
The crackdown started with bankers texting on WhatsApp and personal devices. By 2024, it had reached stand-alone registered investment advisors, including Senvest Management, which paid $6.5 million. Many advisory firms have not yet connected that lesson to what their advisors are now doing every day.
Here is the connection: In many firms, advisors are already using AI to help think through client decisions. This does not look dramatic. It looks like an advisor asking ChatGPT to pressure test a rollover recommendation before a meeting, clean up the rationale for a client note, compare risks in a concentrated-stock position, or find the obvious hole in an annuity replacement analysis.
Using AI this way is fast, it is useful, and no one is writing it down. Call it shadow AI, and the SEC’s 2026 examination priorities point right at it.
Here is the part the industry keeps getting backward: The firms most exposed are not always the ones using AI. Often, they are the ones who wrote a policy swearing they do not.
The Ban Is the Trap
The instinct is to prohibit AI use. Add a line to the manual: No generative AI in the advisory process. Except a prohibition you cannot enforce is not a control. It is a confession with a timestamp.
Picture the exam: An examiner asks a few of your advisors how they use AI in a normal week, and they answer honestly, because they do not think they are doing anything wrong.
Now your written policy says one thing and your practice does another. That is a compliance program that does not describe how the firm actually operates. Rule 206(4)-7 asks whether the program is reasonably designed for the risks the firm actually faces. A program built around a fiction is not.
The Records Problem Underneath It
For advisors, Rule 204-2 is the quieter half. When prompts or outputs contain written communications relating to recommendations or advice, the firm must determine whether they are records that need to be preserved. Shadow AI creates a similar production problem one layer deeper: What has gone off channel is not only the message. It is the reasoning.
When an advisor makes a recommendation, there is supposed to be a basis for it, and between the books-and-records rule and your duty of care you should be able to reconstruct it later.
My 14 years around markets have taught me one uncomfortable thing about conviction: It outlives its sources. You remember being convinced. However, retracing exactly what convinced you, months later, is far harder. In a portfolio, that is a discipline problem. In advice, where the reasoning belongs in a file someone else may open, it is the difference between a defensible decision and a shrug.
Now, a real slice of that reasoning may happen under a login the firm does not control. If a recommendation goes sideways and a client complains, the question is short and brutal: Show me how you got here. “The advisor asked a chatbot, and it seemed right” is not a sentence you want to say to a regulator — and definitely not to a plaintiff’s attorney. The absence of the record is the exposure. AI is not the villain in that story. The silence is.
The Answer Might Be Wrong
A quick prompt to a chatbot is asking a confident stranger with no memory of your client a question, and acting on the first thing it says. It does not know about the risk tolerance you documented, the concentration you spent three years unwinding, the estate plan the last recommendation was built around, or the tax issue the CPA raised last April.
A chatbot can afford to give generic answers, but you can't. Strip out what you know about the client, and the recommendation fits no one. Taking raw information and perfectly tailoring it to the client's life is your actual job — and it's the reason they hire you instead of a robot.
Picture a client with real health concerns and a two-out-of-ten risk tolerance whose monthly income picture is still being assembled. One reasonable path parks her in money markets until the picture is complete. Another locks in an annuity today.
Reasonable professionals can land in different places, and the client's file — not the loudest voice in the room — should be what settles it. That is advice for a particular person in a particular moment. The model answers the question. The advisor answers the person.
A model can sound certain even when its answer does not fit the file. Asking it to critique its own answer may improve the output, but it is not an independent check; the same assumptions and omissions can survive both passes. The model does not sit with the case nobody asked about: the concentrated position that gaps down, the annuity that traps the client for seven years, the tax bill no one modeled until April, or the beneficiary issue hiding in the estate documents.
The unlikely outcome is the one that matters, because the tail is where the complaints and the exam findings live. So shadow AI is two risks stacked: The recommendation may be shallow, and there is no record of how you got there.
What a Defensible Process Looks Like
You do not fix this by buying software alone, and you do not fix it by pretending it is not happening. You write down what is already true and put a fence around it.
Start with the inventory. Where is AI already being used: meeting prep, client notes, rollover rationale, portfolio reviews, marketing, email drafting, research? Then draw the line. What is permitted, what is prohibited, what requires review, and what never goes into a public tool? Clients’ nonpublic personal information belongs on the wrong side of that line, because Reg S-P is hiding inside the AI issue.
That inventory matters because AI is not sitting in one place. Within a nonrandom document study of 35 Form ADV filer records retrieved in July 2026, 28 were selected because their current brochures addressed AI. Of those 28, 11 described AI in recommendation, rating, allocation, or portfolio construction; 13 described it in operations, client service, or research support; and 4 discussed only risk or possible future use.
The study does not show how common AI use is among advisors generally. But the split makes the governance point: A firm that treats "AI use" as one activity will miss where the actual risks, records, and review obligations sit.
Supervise the Person, Not the Tool
Keep the human where the law expects the human to be. The tool informs the call. The advisor remains the decision-maker of record. The firm supervises the process. The record captures what was considered, what was rejected, what risks were identified, and who approved the final judgment. The AI is not the supervised person. Your advisor is.
Concretely, for one rollover recommendation, the record is short: the question as the advisor framed it; what the tool suggested; the two risks the review surfaced; the one the advisor overrode and why; and a sign-off with a date on it. A page, not a binder.
Here is the practical test: Ask for one recent AI-assisted recommendation and see whether your team can produce that page without reconstructing it after the fact.
FINRA’s July 9 proposal points in the same direction. Regulatory Notice 26-14 would replace the general principal pre-use approval requirement with written procedures determining which retail communications still require approval, backed by training, documentation, surveillance, and evidence that the procedures ran.
FINRA also says firms remain responsible for AI-generated communications and may use generative AI in supervision if the tools are vetted, tested, and monitored. This is a brokerage proposal, not a rule, and it does not govern RIA-only firms. But the architecture is familiar: define the risk, document the controls, and preserve the evidence.
A defensible AI process is not a ban, and it is not a free-for-all.
Adapting to AI does not require you to be first, or to bet the firm on a vendor. It requires you to stop writing policy for a world that does not exist.
The Uncomfortable Part
The AI question is not really a technology question for your firm; it is a documentation question wearing a technology costume. Your advisors are already using it, and the SEC has already told you it is watching how you handle it. The only open question is whether, when an examiner asks, you can show your work.
Read more by Dan Zimon:
Dan Zimon spent 14+ years across institutional finance and wealth-channel advisory and has passed the Series 7 and 66 examinations. He now builds decision-documentation tools for advisory teams at Teranode.
A message from Advisor Perspectives and VettaFi: Discover something new! Click here to register for our upcoming webcasts.
More Insurance & Annuities Topics >