AI compliance obligations for a single family office in the EU

AI compliance obligations for a single family office in the EU

4 AI-adoption compliance obligations apply, each cited to primary law.

A single family office is generally outside the MiFID advice/conduct perimeter

Rule: MiFID II perimeter (Art 4(1)(1) & Art 2)

What it requires: MiFID II conduct obligations bite where a firm provides investment services to third parties by way of business. An SFO investing only its own family's capital, with no external clients, is not providing a service to third parties, so the Art 24/25 suitability duties and Art 16(6)/(7) service-and-communication records do not apply to it in the way they do to a WM firm or adviser.

Do this: Confirm in writing that the office serves one family only and takes on no external clients, and re-test that boundary before onboarding any non-family capital — the moment external clients appear, the perimeter (and the MFO obligations) re-attach.

Source: Directive 2014/65/EU (MiFID II), Article 4(1)(1) (definition of 'investment firm' — providing investment services to third parties on a professional basis) and Article 2 (exemptions).

Confidence: Sourced

Run a data-protection impact assessment before high-risk AI processing

Rule: GDPR Art 35 (DPIA)

What it requires: Even outside the conduct perimeter, an SFO processes personal data of family members, beneficiaries and counterparties. Where AI processing is likely to result in a high risk to individuals — profiling, or processing at scale — GDPR requires a Data Protection Impact Assessment before processing begins.

Do this: Complete a DPIA before putting family or beneficiary personal data through a new AI tool, and keep a human decision-maker on any significant outcome. This obligation does not depend on being a regulated firm.

Source: Regulation (EU) 2016/679 (GDPR), Articles 22 and 35.

Confidence: Sourced

Meet AI transparency duties and screen for high-risk uses

Rule: EU AI Act Art 50 & Annex III

What it requires: The EU AI Act applies to deployers of AI systems regardless of financial-services licensing. People must be informed when interacting with an AI system unless obvious (Art 50), and certain uses (e.g. AI in employment or creditworthiness decisions) are classed high-risk under Annex III, triggering heavier obligations.

Do this: Inventory your AI uses against the Annex III high-risk list, add an AI-use disclosure wherever a model interacts with a person, and treat any HR- or credit-adjacent AI as high-risk until you have checked otherwise.

Source: Regulation (EU) 2024/1689 (AI Act), Article 50 and Annex III.

Confidence: Sourced

Keep orderly AI records even without a conduct regulator

Rule: Records & governance (prudential)

What it requires: An SFO has no MiFID service-record duty, but audit trails still matter for tax, succession, family governance and to evidence the DPIA and AI-Act steps above. AI that drafts or summarises should not do so in an ephemeral, unretained way.

Do this: Point AI tools that draft memos, summarise meetings or process family data at a retained store, capturing the input, the output and the reviewer, so the office can evidence its own governance and its GDPR / AI-Act compliance.

Source: Regulation (EU) 2016/679 (GDPR), Article 5(2) accountability; Regulation (EU) 2024/1689 (AI Act) record-keeping duties for deployers.

Confidence: Sourced