AI compliance obligations for a multi-family office in the US
4 AI-adoption compliance obligations apply, each cited to primary law.
Serving unrelated families requires registration and full books & records
Rule: Advisers Act registration & Rule 204-2
What it requires: An office serving multiple unrelated families cannot rely on the family office rule and must register as an investment adviser. As a registered adviser it must keep true, accurate and current books and records of its advisory business — including work an AI system drafts or supports.
Do this: Confirm your registration status, and log which AI tool was used, on what input, and who reviewed it, retained with each client family's advisory record for the required period.
Source: Investment Advisers Act of 1940, Rule 204-2 (17 CFR 275.204-2); family office rule 202(a)(11)(G)-1 does not apply to unrelated client families.
Confidence: Verify
Adopt written policies governing your AI use
Rule: Advisers Act Rule 206(4)-7 (Compliance)
What it requires: A registered MFO must adopt, implement and annually review written policies and procedures reasonably designed to prevent Advisers Act violations. Deploying AI in advisory workflows is a change those policies must address.
Do this: Add AI governance — approved tools, human-review checkpoints, data handling, testing — to your compliance manual and cover it in the annual compliance review.
Source: Investment Advisers Act of 1940, Rule 206(4)-7 (17 CFR 275.206(4)-7).
Confidence: Verify
AI-generated marketing and client communications must be fair and substantiated
Rule: Marketing Rule 206(4)-1
What it requires: The Marketing Rule prohibits untrue or misleading statements in advertisements and requires a reasonable basis for claims. AI that drafts marketing copy, performance summaries or client-facing material must meet this standard across every client family.
Do this: Route any AI-drafted advertisement or client communication through marketing-rule review before it goes out, and keep records substantiating the claims it makes.
Source: Investment Advisers Act of 1940, Rule 206(4)-1 (17 CFR 275.206(4)-1), the Marketing Rule.
Confidence: Verify
Have an incident-response program and meet the breach-notice timeline
Rule: Regulation S-P (Release 34-100155)
What it requires: Under the Regulation S-P amendments adopted 15 May 2024, SEC-registered advisers must maintain a written incident-response program and notify affected individuals of a breach of sensitive customer information as soon as practicable and no later than 30 days. Client-family data entering AI tools falls within this duty.
Do this: Bring any AI tool that touches customer information inside your Reg S-P safeguards and incident-response program across all client families, and confirm your breach-notice process meets the 30-day deadline.
Source: SEC Release No. 34-100155 (Regulation S-P amendments, adopted 15 May 2024); 17 CFR 248.30.
Confidence: Verify