AI compliance obligations for an IFA / RIA in the US
4 AI-adoption compliance obligations apply, each cited to primary law.
Keep the records of advice the AI helps produce
Rule: Advisers Act Rule 204-2 (Books & Records)
What it requires: A registered investment adviser must make and keep true, accurate and current books and records relating to its advisory business, including recommendations and client communications. Output an AI tool drafts or supports is part of that advisory record.
Do this: Log which AI tool was used, on what input, and who reviewed it, retained with the client's advisory file for the required period, so the record is complete with or without a model in the loop.
Source: Investment Advisers Act of 1940, Rule 204-2 (17 CFR 275.204-2).
Confidence: Verify
Adopt written policies governing your AI use
Rule: Advisers Act Rule 206(4)-7 (Compliance)
What it requires: An adviser must adopt, implement and annually review written policies and procedures reasonably designed to prevent Advisers Act violations. Introducing AI into advisory workflows is a change those policies must address.
Do this: Add AI governance — approved tools, human-review checkpoints, data handling, testing — to your compliance manual and cover it in the annual review.
Source: Investment Advisers Act of 1940, Rule 206(4)-7 (17 CFR 275.206(4)-7).
Confidence: Verify
AI in the advice chain does not move your fiduciary duty off the firm
Rule: Advisers Act fiduciary duty (Section 206)
What it requires: An investment adviser owes a fiduciary duty of care and loyalty to its clients; the SEC's 2019 interpretation confirms a recommendation must be in the client's best interest. Where AI contributes to a recommendation, the adviser remains fully responsible for the advice given.
Do this: Keep a named adviser accountable for any recommendation an AI tool helped shape, and document the basis for the advice so the best-interest standard is evidenced.
Source: Investment Advisers Act of 1940, Section 206; SEC Commission Interpretation Regarding Standard of Conduct for Investment Advisers (Release IA-5248, 2019).
Confidence: Verify
Have an incident-response program and meet the breach-notice timeline
Rule: Regulation S-P (Release 34-100155)
What it requires: Under the Regulation S-P amendments adopted 15 May 2024, SEC-registered advisers must maintain a written incident-response program and notify affected individuals of a breach of sensitive customer information as soon as practicable and no later than 30 days. Client data entering AI tools falls within this duty.
Do this: Bring any AI tool that touches customer information inside your Reg S-P safeguards and incident-response program, and confirm your breach-notice process meets the 30-day deadline.
Source: SEC Release No. 34-100155 (Regulation S-P amendments, adopted 15 May 2024); 17 CFR 248.30.
Confidence: Verify