AI Overtakes Cybersecurity as Top Compliance Worry

Survey of 411 adviser firms finds 85% view AI compliance as a top concern; 37% named cybersecurity.

A survey of compliance professionals at 411 registered investment adviser firms found 85% of respondents listed artificial intelligence compliance as a top concern, while 37% flagged cybersecurity. The results were released July 29.

Respondents identified privacy and the U.S. Securities and Exchange Commission’s Regulation S-P as a top issue for 35% of firms, advertising and marketing compliance for 19%, and prediction markets for 14%.

Regulation S-P, adopted in 2024, requires advisers and brokers to notify clients about data security breaches within 30 days. Larger firms had a December 2025 compliance deadline; smaller firms were given until June 2026. Smaller registered advisers often use outside compliance technology and services.

The survey was distributed to clients of the ACA Group, Yuter Compliance Consulting and members of the Investment Adviser Association.

On firm preparedness for AI, 86% reported having acceptable-use policies for AI, up from 64% in the fall of 2025. Fifty-nine percent reported a formal AI governance committee. Survey authors noted AI use moved from experimental to broad deployment after three years of tracking.

Carlo di Florio, president of the ACA Group, urged firms to set explicit data-use limits in vendor contracts, saying, “Make sure that your vendor isn’t using your information in a way that you wouldn’t want them to, and usually you lay that out in the contract, ‘Here’s what you can and can’t do with our data that we provide to you or use inside of your systems,'” and he recommended monitoring and testing of vendors.

He warned that vague policies can lead employees to use personal AI tools such as ChatGPT or Claude, which typically have fewer controls.

To manage AI-related compliance risks, di Florio recommended firms issue an authorized-use policy that names governance responsibilities; inventory who in the firm uses AI and for what purposes; require model testing to check whether sensitive client data enters systems and to screen for bias, errors and hallucinations; assess cybersecurity impacts of AI deployments; and strengthen vendor oversight with monitoring and testing.

Survey participants highlighted overlap between AI and cybersecurity risks and advised including AI use cases in cyber risk assessments and testing models for data leakage and other vulnerabilities as part of broader security programs.

Articles by this author