AI compliance obligations for a multi-family office in the EU

AI compliance obligations for a multi-family office in the EU

4 AI-adoption compliance obligations apply, each cited to primary law.

Serving external families re-attaches the full suitability duty

Rule: MiFID II Art 24 & 25

What it requires: Because an MFO provides investment services to client families (third parties) by way of business, it sits inside the MiFID II perimeter. It must act in each client's best interests and ensure suitability — and where AI contributes to advice or a suitability assessment, the firm keeps full responsibility for the outcome.

Do this: Treat AI in the advice chain exactly as a WM firm would: map every tool that can touch a recommendation or suitability assessment and keep a named human sign-off on any output that reaches a client family.

Source: Directive 2014/65/EU (MiFID II), Articles 24-25; ESMA Public Statement on the use of Artificial Intelligence in the provision of retail investment services, 30 May 2024 (ref ESMA35-335435667-5924).

Confidence: Sourced

Keep service and transaction records across every client family

Rule: MiFID II Art 16(6)

What it requires: The MFO must keep records of all services, activities and transactions sufficient for the competent authority to monitor compliance, including where an AI system drafted, screened or supported work for a client family.

Do this: Log which AI tool was used, on what input and who reviewed it, against each client family's record, so the service record is complete whether or not a model was involved.

Source: Directive 2014/65/EU (MiFID II), Article 16(6).

Confidence: Sourced

Record and retain client-family communications

Rule: MiFID II Art 16(7)

What it requires: Records of communications relating to (at least) the reception, transmission and execution of orders must be kept and retained for five years, extendable to seven. AI that drafts client-family emails or summarises calls produces records that carry this duty.

Do this: Ensure any AI that drafts client-family emails, transcribes meetings or summarises calls writes into a retained store; the retention duty attaches to the communication, not the tool.

Source: Directive 2014/65/EU (MiFID II), Article 16(7); Commission Delegated Regulation (EU) 2017/565, Article 72.

Confidence: Sourced

Guard automated decisions and disclose AI to client families

Rule: GDPR Art 22 & AI Act Art 50

What it requires: A client has the right not to be subject to a solely-automated decision with legal or similarly significant effect (GDPR Art 22), and people must be told when interacting with an AI system unless obvious (AI Act Art 50). Serving multiple families multiplies the personal data at stake.

Do this: Keep a person in the loop on any client-affecting decision, run a DPIA before high-risk processing, and add an AI-use disclosure to client-family material where a model contributed.

Source: Regulation (EU) 2016/679 (GDPR), Articles 22 and 35; Regulation (EU) 2024/1689 (AI Act), Article 50.

Confidence: Sourced