Advisor Perspectives welcomes guest contributions. The views presented here do not necessarily represent those of Advisor Perspectives.
Only 15% of RIA firms have an established AI policy, yet the SEC is specifically prioritizing AI governance in exams for 2026 Q3 onward. If your firm is among the 85% without a formal policy, a surprise examination could lead to civil fines, C&D orders, and formal censures.
This article is the first in a series about implementing AI while maintaining rigorous data regulation and governance practices.
Can We Admit the Current Wild West Landscape of AI Implementation Was Inevitable?
While speaking with close to 2,000 advisors about AI over the past two years, certain patterns have emerged. The same advisors who thrive on technical analysis (TA), quant screening, and the like naturally gravitate toward weekend tech projects. You may understand the allure of vibe-coding your own dashboard, deploying it on Monday, and then feeling nervous when your chief compliance officer (CCO) asks, “So, what’d you do this weekend?”
This compliance angst remains largely unresolved for advisors in the RIA arena. The exact interface you’ve dreamed of for years is now mere minutes away thanks to a stack of Claude tokens and a third cup of coffee at 2 a.m. At conferences and happy hours, advisors are ushering me to the corner of the room to show off a test version of their new AI creation. They’re giddy about the possibilities, but their experimentation raises a crucial question: Should you build your own advisor solutions?
With the right sandbox, absolutely. Use dummy data, jump into amazing programs like NotebookLM, Claude Design, Gamma, and Lindy, and build something that matches your vision. Advisors who can design a mock-up of their vision are in a much stronger position to create an AI-forward future. The question is, who else at your firm is doing the same thing, but without guardrails?
One of your colleagues, in the spirit of seeing how far and fast AI can build, is uploading account statements, estate documents, and other personally identifiable information (PII) into their personal ChatGPT account. That sounds absurd, but I received this exact call from a paraplanner at a multilocation RIA firm. The person was fired, but their firm didn’t have an AI policy in place. The employee wasn’t set up for success. How much weight and responsibility does that firm’s inaction carry for that paraplanner’s future prospects with other firms?
The conversation about advisors’ use of AI needs to start with governance and enforcement. More RIAs are learning the hard way exactly where the SEC stands on AI monitoring.
SEC Exam Priorities & AI Governance by RIA Firms
Three large firms ($1 billion-plus assets) all shared the same dilemma with me over the past two weeks: “We’re wrapping up or just completed an SEC audit, and we have multiple issues with our tech. Can we talk about AI policies?”
Why? The SEC asked all three firms for their AI governance documentation. None of the firms provided sufficient information.
One of the first details on the SEC’s updated exam checklist is AI governance. This is what the Division of Examinations specifically cited in its Fiscal Year 2026 Examination Priorities document:
With respect to AI, the Division will focus on recent advancements in AI and will review for accuracy registrant representations regarding their AI capabilities or AI. The Division will assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies, including for tasks related to fraud prevention and detection, back-office operations, anti-money laundering (AML), and trading functions, as applicable. Reviews will also consider firm integration of regulatory technology to automate internal processes and optimize efficiencies.
It’s no secret that the SEC understands the tectonic fracturing felt throughout the advisory space. AI, which once felt like nothing more than a parlor trick, is already playing a substantial role in disrupting the investment space. How is the SEC adapting for AI implementation among RIA firms?
Currently, there are no new rules from the SEC regarding AI governance and enforcement. That said, the Fiscal Year 2026 Examination Priorities indicate that the SEC considers AI usage monitoring to be well within existing examination parameters. The SEC doesn’t need new AI-specific rules to hold firms accountable in the spirit of fiduciary responsibility.
When Should RIA Firms Implement an AI Policy?
The first step I recommend RIA firms take with AI is developing a solid AI policy. While this isn’t an exhaustive list, your AI policy should include the following:
- Appropriate use cases for preapproved tech sorted into tiers or levels of usage based on the capabilities inside each platform
- Vendor vetting procedures to meet the amended Reg S-P requirements that went into effect for all firms as of June 3, 2026
- Parameters around marketing, public-facing communications, and implementation of AI capabilities in the interest of avoiding “AI washing”
- Documentation showing firmwide distribution of your AI policy with the corresponding timestamp
Take this step before implementing any new AI capabilities, and certainly before you buy whatever newly repackaged software is showcased at the next advisor conference. (You know the software I’m talking about, the one that has been rebranded with “AI” in the name since you last saw it 90 days ago. That’s the one. The only material change is the title, none of the substance.)
Your AI policy can protect you from investing in the wrong products, as well as other potential missteps, while deploying the right solutions as more AI-forward opportunities enter the RIA conversation.
Your clients deserve to know your firm has a clear stance on AI usage and governance. How else can they know the appeal of AI isn’t compromising trust, relationships, and worthwhile conversations? Creating a solid AI policy is a step in the right direction. It’s reassurance in a world where investors are increasingly craving certainty.
Legal said I should include a short disclaimer: I’m not an attorney, nor am I your compliance authority. Nothing in this article should be taken as legal or regulatory advice. Consult with your legal and/or regulatory authority before new policy implementation.
Jon Cook is the founder of Keynote Content, AI for advisors keynote speaker, YouTube host, and previous contributor to TheStreet, MarketWatch, Retirement Daily, and Proactive Advisor Magazine. He’s personally worked with almost 300 advisory firms to build human-first, AI-forward practices. Connect with Jon through keynotecontent.com or youtube.com/@keynotecontent.
A message from Advisor Perspectives and VettaFi: Discover something new! Click here to register for our upcoming webcasts.
More Wealth Management Topics >