AI compliance obligations for a single family office in the EU
4 AI-adoption compliance obligations apply, each cited to primary law.
A single family office is generally outside the MiFID advice/conduct perimeter
Rule: MiFID II perimeter (Art 4(1)(1) & Art 2)
What it requires: MiFID II conduct obligations bite where a firm provides investment services to third parties by way of business. An SFO investing only its own family's capital, with no external clients, is not providing a service to third parties, so the Art 24/25 suitability duties and Art 16(6)/(7) service-and-communication records do not apply to it in the way they do to a WM firm or adviser.
Do this: Confirm in writing that the office serves one family only and takes on no external clients, and re-test that boundary before onboarding any non-family capital — the moment external clients appear, the perimeter (and the MFO obligations) re-attach.
Source: Directive 2014/65/EU (MiFID II), Article 4(1)(1) (definition of 'investment firm' — providing investment services to third parties on a professional basis) and Article 2 (exemptions).
Confidence: Sourced
Run a data-protection impact assessment before high-risk AI processing
Rule: GDPR Art 35 (DPIA)
What it requires: Even outside the conduct perimeter, an SFO processes personal data of family members, beneficiaries and counterparties. Where AI processing is likely to result in a high risk to individuals — profiling, or processing at scale — GDPR requires a Data Protection Impact Assessment before processing begins.
Do this: Complete a DPIA before putting family or beneficiary personal data through a new AI tool, and keep a human decision-maker on any significant outcome. This obligation does not depend on being a regulated firm.
Source: Regulation (EU) 2016/679 (GDPR), Articles 22 and 35.
Confidence: Sourced
Meet AI transparency duties and screen for high-risk uses
Rule: EU AI Act Art 50 & Annex III
What it requires: The EU AI Act applies to deployers of AI systems regardless of financial-services licensing. People must be informed when interacting with an AI system unless obvious (Art 50), and certain uses (e.g. AI in employment or creditworthiness decisions) are classed high-risk under Annex III, triggering heavier obligations.
Do this: Inventory your AI uses against the Annex III high-risk list, add an AI-use disclosure wherever a model interacts with a person, and treat any HR- or credit-adjacent AI as high-risk until you have checked otherwise.
Source: Regulation (EU) 2024/1689 (AI Act), Article 50 and Annex III.
Confidence: Sourced
Keep orderly AI records even without a conduct regulator
Rule: Records & governance (prudential)
What it requires: An SFO has no MiFID service-record duty, but audit trails still matter for tax, succession, family governance and to evidence the DPIA and AI-Act steps above. AI that drafts or summarises should not do so in an ephemeral, unretained way.
Do this: Point AI tools that draft memos, summarise meetings or process family data at a retained store, capturing the input, the output and the reviewer, so the office can evidence its own governance and its GDPR / AI-Act compliance.
Source: Regulation (EU) 2016/679 (GDPR), Article 5(2) accountability; Regulation (EU) 2024/1689 (AI Act) record-keeping duties for deployers.
Confidence: Sourced