
I’ll tell you a quick story.
A firm sent out a beautiful client proposal. Clean. Confident. Looked like something you’d expect from a top-tier RIA.
Then the client called.
The data in the recommendation—the numbers that supported the strategy—weren’t real.
They didn’t come from bad research.
They came from AI.
The Risk No One Wants to Admit
I’m seeing this more and more with RIAs right now.
AI is showing up everywhere:
- Inside Microsoft 365
- Built into CRM tools
- Sitting quietly in your email drafts
- Offering to “help” summarize client notes
And I get it—it’s helpful.
It saves time. It makes your team faster. It feels like leverage.
But here’s the part that keeps me up at night:
Most firms are using AI without a supervision model.
You Didn’t Hire an Intern… But You Gave It Access
Let me put it plainly.
Using AI without guardrails is like hiring an intern and saying:
“Here’s our client data, our financials, and our internal notes…
just figure it out.”
No training.
No policies.
No oversight.
And in an RIA environment, that’s not just risky…
That’s a compliance problem.
What’s Actually Happening Inside RIA Firms
When I talk to advisors and compliance officers, three patterns show up every time.
-
Client Data Is Being Shared Without Realizing It
Someone pastes:
- A client email
- A financial summary
- A planning scenario
…into a public AI tool to “clean it up” or summarize it.
No bad intent.
But now you’ve got potential exposure of non-public personal information (NPI)—the exact thing regulations like Reg S-P are designed to protect.
-
Shadow AI Is Quietly Growing
Your team is smart. They’re resourceful.
So they find tools that help them move faster.
The problem?
- IT doesn’t know what’s being used
- Compliance hasn’t approved it
- No one has reviewed the data policies
It’s the same issue as shadow IT—just faster and harder to see.
-
Output Is Trusted Too Quickly
This one worries me the most.
AI sounds confident.
It writes like it knows what it’s doing.
But it doesn’t:
- Understand fiduciary duty
- Know SEC expectations
- Verify sources
So when it makes something up…
It doesn’t hesitate.
And if no one reviews it before it goes to a client?
That’s where reputational risk turns into regulatory risk.
The Part the SEC Actually Cares About
Here’s the piece many firms miss.
This isn’t just a “tech issue.”
It falls directly under:
- Cybersecurity controls
- Data protection
- Compliance program effectiveness
And according to the , the SEC is actively examining whether your controls actually work in practice.
If your team is using AI:
- Where is that data going?
- Who approved the tools?
- What safeguards are in place?
If you can’t answer that clearly…
That’s exposure.
AI Doesn’t Create Problems—It Speeds Them Up
I always say this:
AI doesn’t break your process.
It reveals it.
If your firm already has:
- Clear policies
- Strong access controls
- A culture of review
AI will make you faster in the right direction.
But if those things aren’t in place?
You just move faster toward risk.
How I’d Supervise an “AI Intern” in Your RIA
I’m not here to tell you to stop using AI.
That’s not realistic—and frankly, it’s not smart.
The firms that win will be the ones who use it well.
Here’s what I’d do instead:
-
Decide What’s Approved
Keep a simple list:
- Approved AI tools
- Prohibited tools
- Use cases that are allowed
This is basic governance—but most firms skip it.
-
Set One Clear Rule
AI drafts. Humans approve.
Nothing goes to:
- Clients
- Custodians
- Regulators
…without human review.
Every time.
-
Draw a Hard Line Around Data
Make this simple for your team:
Never put into AI:
- Client names
- Financial data
- Account details
- Anything that would trigger a Reg S-P concern
If they don’t know the line, they’ll cross it by accident.
-
Treat It Like Part of Your Compliance Program
Because it is.
This should tie into:
- Your WISP
- Your data protection policies
- Your vendor oversight
Not sit off to the side as a “productivity tool.”
A Simple Question to Sit With
If the SEC asked you tomorrow:
“How is your firm controlling the use of AI tools?”
What would you show them?
A policy?
A system?
Or a guess?
Final Thought
I’ve worked with enough RIAs to know this:
You’re not trying to cut corners.
You’re trying to keep up.
AI feels like help.
And it is.
But only if someone is supervising it.
Because just like any intern…
It doesn’t know what matters.
Until you show it.
If you want help putting real guardrails around AI in your firm without slowing your team down—I’m here.
We can make this simple, clear, and fully aligned with how the SEC actually looks at your firm.
Just start with a quick conversation.
Schedule here.

