Five AI compliance risks for advisors and fixes

SEC and FINRA apply fiduciary and disclosure rules to advisors’ AI use, flag five risks and require human oversight and durable recordkeeping.

The Securities and Exchange Commission and FINRA are applying existing fiduciary and disclosure obligations to how advisory firms use artificial intelligence, identifying five specific compliance risks and telling firms they remain responsible for all advice and client communications. The SEC included AI governance, supervision and recordkeeping in its 2026 Examination Priorities; FINRA reiterated supervision and suitability expectations for broker-dealers using generative AI. Regulators expect firms to explain how AI-assisted decisions are reached and to preserve records that will withstand an exam.

One risk regulators flagged is AI-generated client communications that reach clients without human review. If an AI-generated email or portfolio commentary contains an incorrect performance figure or a wrong projection, the firm can face disclosure or supervisory violations. Firms are expected to require human approval for any client-facing content produced or edited by AI, treating those messages the same as advisor-drafted correspondence.

A second risk involves automated trade recommendations or executions that bypass suitability checks. When an AI tool proposes a trade and it is acted on without checking a client’s risk tolerance, investment objectives and other suitability factors, the firm risks a suitability breach. Firms should use AI to generate ideas but require a human advisor to verify suitability and authorize any trade.

A third area of concern is entering client account details, holdings or personally identifiable information into public chatbots or consumer-grade AI services. Moving client data outside a firm-controlled environment can violate data safeguarding rules such as Regulation S-P. Firms are expected to confine client data to firm-hosted or enterprise-grade AI tools that include contractual privacy and security protections and to prohibit the use of public chat products for account-specific inquiries.

Undisclosed use of AI is a fourth risk. If a firm uses AI to generate recommendations, draft portfolio commentary or manage accounts but does not reflect that practice in its Form ADV, client materials or supervisory procedures, regulators can view that as a transparency violation. Disclosure documents and compliance manuals should be updated to describe how AI is used and how human oversight is applied.

The fifth risk concerns gaps in the AI audit trail. Examiners will look for the ability to reconstruct how an AI-assisted decision was reached, including the data inputs, model outputs, who reviewed the output and what action followed. Firms should implement immutable logging that links inputs, outputs and the human reviewers or approvers so records survive regulatory inspection.

According to Deb Misra, founder and CEO of Engineersmind, regulators are increasing pressure by applying existing duties rather than creating new rules. The SEC and FINRA expect firms to supervise AI-generated output, manage conflicts of interest arising from AI use and maintain records suitable for an exam.

Regulatory guidance focuses on human oversight, explainability and durable recordkeeping. Firms that adopt enterprise-grade tools, require human approval for client-facing outputs, disclose AI uses in regulatory filings and maintain comprehensive, immutable audit trails will align with the practices referenced in exam priorities.

Articles by this author