AI Tops Compliance Worries for Adviser Firms

A July 29 survey of 411 investment-adviser firms found 85% of compliance professionals listed AI as their top concern versus 37% for cybersecurity.

A survey of 411 investment-adviser firms released July 29 found 85% of compliance professionals ranked AI compliance as their top concern, while 37% listed cybersecurity as the primary issue. Privacy and the SEC’s Regulation S‑P was cited by 35% of respondents, advertising and marketing by 19% and prediction markets by 14%.

The survey was distributed to clients of ACA Group and Yuter Compliance Consulting and to members of the Investment Adviser Association. Respondents reported increased use of AI tools at advisory firms and rising questions about governance and protection of client data.

Eighty-six percent of firms reported having acceptable use policies for AI, up from 64% in the fall of 2025. Fifty-nine percent said they have a formal AI governance committee. Carlo di Florio, president of ACA Group, noted that after three years of tracking AI use the technology moved from experimental stages to broad adoption across firms.

Regulation S‑P, adopted in 2024, requires firms to notify clients about data security lapses within 30 days. Larger firms had to comply by December 2025 and smaller advisers by June 2026, deadlines that firms cited when weighing how client information may be used in AI models and by third-party systems.

Some large financial firms have said AI could increase advisor productivity and expand client capacity, and others have projected AI-driven investing tools may outperform a standard 60-40 portfolio in certain scenarios. Those examples were presented by firms as they plan AI deployments.

Di Florio recommended a five-part approach to manage AI risk: adopt clear authorized-use policies that assign governance responsibilities; maintain an inventory of who is using AI and for what purposes; test models for bias, errors and hallucinations and review whether sensitive client data enters the systems; evaluate the cybersecurity implications of AI deployment; and strengthen vendor oversight and contracts to control how outside providers use firm data.

He also warned about uncontrolled personal use of commercial AI tools, noting that employees using personal accounts may operate without the controls firms apply to company systems. Firms were urged to make policies clear and to monitor vendor activity and employee access.

Respondents and ACA Group representatives highlighted overlap between AI and cybersecurity risks, pointing to issues such as data leakage, model integrity and third-party access. The survey noted smaller registered investment advisers often rely on compliance technology from vendors, increasing the importance of contract terms and oversight. The results show most firms have introduced basic AI policies while fewer have established formal governance committees.

Articles by this author