AI compliance obligations for a single family office in the US
4 AI-adoption compliance obligations apply, each cited to primary law.
A qualifying single family office is excluded from the Advisers Act
Rule: Family Office Rule 202(a)(11)(G)-1
What it requires: The SEC family office rule excludes a family office that serves only 'family clients', is wholly owned and controlled by family members/entities, and does not hold itself out as an investment adviser, from the definition of investment adviser. A qualifying SFO is therefore outside 204-2, 206(4)-7 and the Marketing Rule — but the exclusion is conditional and narrow.
Do this: Confirm the office meets every condition of the rule — only family clients, family ownership and control, no holding-out — and re-test it before serving anyone outside the family definition, because a single non-qualifying client can break the exclusion.
Source: Investment Advisers Act of 1940, Rule 202(a)(11)(G)-1 (the family office rule; 17 CFR 275.202(a)(11)(G)-1).
Confidence: Verify
Data-security and privacy duties still apply to family data
Rule: Reg S-P / GLBA & state privacy law
What it requires: Even excluded from the Advisers Act, a family office holds sensitive personal and financial data of family members and staff. GLBA/Reg S-P safeguards may apply where financial products are involved, and state privacy laws (e.g. the CCPA/CPRA in California) can bind the office directly regardless of adviser status.
Do this: Map which AI tools touch family personal or financial data, apply a written safeguards and incident-response process to them, and check whether your state's privacy law (e.g. CCPA/CPRA) imposes direct obligations.
Source: Gramm-Leach-Bliley Act, 15 U.S.C. 6801-6809 and Regulation S-P (17 CFR 248.30); California Consumer Privacy Act / CPRA where applicable.
Confidence: Verify
Keep orderly AI records even without an SEC record-keeping duty
Rule: Records & governance (prudential)
What it requires: A qualifying SFO has no Rule 204-2 duty, but audit trails still matter for tax, estate and family-governance purposes and to evidence the data-security steps above. AI drafting or summarising should not happen in an unretained way.
Do this: Point AI tools that draft memos, summarise meetings or process family data at a retained store, capturing input, output and reviewer, so the office can evidence its governance and data-security posture.
Source: Prudential recordkeeping; consistency with GLBA/Reg S-P safeguards (17 CFR 248.30) and applicable state privacy law.
Confidence: Verify
Keep a person on significant automated decisions affecting individuals
Rule: Human oversight of automated decisions
What it requires: Where an SFO uses AI in ways that significantly affect individuals — for example hiring, or profiling family members — emerging state privacy laws and best practice call for transparency and meaningful human involvement, even though no SEC conduct rule applies.
Do this: Add an AI-use note where a model interacts with or profiles individuals, and ensure a person, not the model alone, makes any decision that significantly affects someone.
Source: State privacy statutes addressing automated decision-making (e.g. California CPRA regulations); office governance policy.
Confidence: Verify