SEC Is Asking RIAs To Show Their AI Work. Here’s What Examiners Want
The Securities and Exchange Commission isn’t just asking registered investment advisors whether they use artificial intelligence. Examiners increasingly want firms to prove they know exactly how employees are using it—and who is watching them.
Recent SEC examination requests have sought details about firms’ internal AI oversight, including whether they have AI committees and whether those committees maintain written meeting minutes, according to Citywire.
There is no SEC rule requiring advisors to maintain a standalone AI policy. But that doesn’t mean AI operates in a regulatory vacuum. Existing requirements governing advertising, compliance, client privacy, recordkeeping and fiduciary conduct apply to firms’ use of the technology, experts say.
The SEC’s fiscal 2026 examination priorities explicitly put advisors’ AI controls under the microscope. Examiners will assess whether firms have adequate policies and procedures to monitor and supervise AI used for everything from trading and back-office operations to fraud detection and anti-money laundering.
They also will test whether firms’ public claims about their AI capabilities match what the technology actually does.
That puts advisors at risk from two directions: exaggerating their use of AI to clients and failing to supervise how AI is actually being used inside the firm.
The first has become known as “AI washing.”
The SEC brought its first AI-washing cases in 2024 against investment advisors Delphia (USA) and Global Predictions, alleging the firms made false or misleading statements about their use of AI. Both settled and paid a combined $400,000 in civil penalties.
Now examiners appear to be looking beyond marketing.
NobleCloak, a governance platform for regulated firms, says the problem starts with knowing what technology is actually operating inside a business.
“You can’t govern what you can’t see,” the company warned in a blog.
Existing rules give examiners several ways to scrutinize AI. The SEC’s Marketing Rule prohibits misleading or unsubstantiated advertising claims, including claims about AI. Regulation S-P requires firms to safeguard clients’ nonpublic personal information and oversee service providers handling protected data.
The Advisers Act compliance rule, meanwhile, requires RIAs to adopt and implement written policies and procedures reasonably designed to prevent violations of the law. AI isn’t specifically named, but the SEC’s examination priorities make clear that examiners are looking at whether firms adequately supervise its use.
Advisors also remain bound by their fiduciary duties when technology is involved.
DKBinnovative, a managed IT and cybersecurity services provider, argues that firms using AI without formal governance aren’t escaping regulation simply because there is no dedicated AI rule.
“A firm that uses AI without a governing policy is not avoiding regulation — it is simply undocumented,” DKBinnovative said.
Documentation issue becomes particularly important when employees use generative AI for research, client communications or operations without the knowledge of compliance personnel.
So-called shadow AI creates another potential examination headache. Employees can enter client account information, financial documents or other sensitive data into consumer AI platforms without understanding where that information goes or how it may be retained.
NobleCloak frames the challenge simply: “AI is everywhere. Proof is nowhere.”
DKBinnovative recommends firms maintain an inventory of approved AI tools, establish data-handling rules and document human review of AI output. Firms also should know which vendors have embedded AI into products already operating inside the firm.
And those controls can’t remain static.
“AI changes monthly; a static policy ages badly,” DKBinnovative said.
Governance matters, too.
If an RIA has created an AI committee, examination requests indicate firms should be prepared to demonstrate what that committee actually does. Written agendas, minutes, decisions and follow-up actions can provide evidence that oversight exists beyond paper policies.
The same principle applies to employee training. A policy prohibiting confidential client information from being placed into unauthorized AI tools has limited value if employees were never trained on it.
For advisors, the message from the SEC’s examination priorities is increasingly difficult to miss: Firms don’t necessarily need a document labeled “AI policy.” They do need to prove they are governing AI.