AI compliance obligations for a multi-family office in the US

AI compliance obligations for a multi-family office in the US

4 AI-adoption compliance obligations apply, each cited to primary law.

Serving unrelated families requires registration and full books & records

Rule: Advisers Act registration & Rule 204-2

What it requires: An office serving multiple unrelated families cannot rely on the family office rule and must register as an investment adviser. As a registered adviser it must keep true, accurate and current books and records of its advisory business — including work an AI system drafts or supports.

Do this: Confirm your registration status, and log which AI tool was used, on what input, and who reviewed it, retained with each client family's advisory record for the required period.

Source: Investment Advisers Act of 1940, Rule 204-2 (17 CFR 275.204-2); family office rule 202(a)(11)(G)-1 does not apply to unrelated client families.

Confidence: Verify

Adopt written policies governing your AI use

Rule: Advisers Act Rule 206(4)-7 (Compliance)

What it requires: A registered MFO must adopt, implement and annually review written policies and procedures reasonably designed to prevent Advisers Act violations. Deploying AI in advisory workflows is a change those policies must address.

Do this: Add AI governance — approved tools, human-review checkpoints, data handling, testing — to your compliance manual and cover it in the annual compliance review.

Source: Investment Advisers Act of 1940, Rule 206(4)-7 (17 CFR 275.206(4)-7).

Confidence: Verify

AI-generated marketing and client communications must be fair and substantiated

Rule: Marketing Rule 206(4)-1

What it requires: The Marketing Rule prohibits untrue or misleading statements in advertisements and requires a reasonable basis for claims. AI that drafts marketing copy, performance summaries or client-facing material must meet this standard across every client family.

Do this: Route any AI-drafted advertisement or client communication through marketing-rule review before it goes out, and keep records substantiating the claims it makes.

Source: Investment Advisers Act of 1940, Rule 206(4)-1 (17 CFR 275.206(4)-1), the Marketing Rule.

Confidence: Verify

Have an incident-response program and meet the breach-notice timeline

Rule: Regulation S-P (Release 34-100155)

What it requires: Under the Regulation S-P amendments adopted 15 May 2024, SEC-registered advisers must maintain a written incident-response program and notify affected individuals of a breach of sensitive customer information as soon as practicable and no later than 30 days. Client-family data entering AI tools falls within this duty.

Do this: Bring any AI tool that touches customer information inside your Reg S-P safeguards and incident-response program across all client families, and confirm your breach-notice process meets the 30-day deadline.

Source: SEC Release No. 34-100155 (Regulation S-P amendments, adopted 15 May 2024); 17 CFR 248.30.

Confidence: Verify