AI compliance obligations for a single family office in the US

AI compliance obligations for a single family office in the US

4 AI-adoption compliance obligations apply, each cited to primary law.

A qualifying single family office is excluded from the Advisers Act

Rule: Family Office Rule 202(a)(11)(G)-1

What it requires: The SEC family office rule excludes a family office that serves only 'family clients', is wholly owned and controlled by family members/entities, and does not hold itself out as an investment adviser, from the definition of investment adviser. A qualifying SFO is therefore outside 204-2, 206(4)-7 and the Marketing Rule — but the exclusion is conditional and narrow.

Do this: Confirm the office meets every condition of the rule — only family clients, family ownership and control, no holding-out — and re-test it before serving anyone outside the family definition, because a single non-qualifying client can break the exclusion.

Source: Investment Advisers Act of 1940, Rule 202(a)(11)(G)-1 (the family office rule; 17 CFR 275.202(a)(11)(G)-1).

Confidence: Verify

Data-security and privacy duties still apply to family data

Rule: Reg S-P / GLBA & state privacy law

What it requires: Even excluded from the Advisers Act, a family office holds sensitive personal and financial data of family members and staff. GLBA/Reg S-P safeguards may apply where financial products are involved, and state privacy laws (e.g. the CCPA/CPRA in California) can bind the office directly regardless of adviser status.

Do this: Map which AI tools touch family personal or financial data, apply a written safeguards and incident-response process to them, and check whether your state's privacy law (e.g. CCPA/CPRA) imposes direct obligations.

Source: Gramm-Leach-Bliley Act, 15 U.S.C. 6801-6809 and Regulation S-P (17 CFR 248.30); California Consumer Privacy Act / CPRA where applicable.

Confidence: Verify

Keep orderly AI records even without an SEC record-keeping duty

Rule: Records & governance (prudential)

What it requires: A qualifying SFO has no Rule 204-2 duty, but audit trails still matter for tax, estate and family-governance purposes and to evidence the data-security steps above. AI drafting or summarising should not happen in an unretained way.

Do this: Point AI tools that draft memos, summarise meetings or process family data at a retained store, capturing input, output and reviewer, so the office can evidence its governance and data-security posture.

Source: Prudential recordkeeping; consistency with GLBA/Reg S-P safeguards (17 CFR 248.30) and applicable state privacy law.

Confidence: Verify

Keep a person on significant automated decisions affecting individuals

Rule: Human oversight of automated decisions

What it requires: Where an SFO uses AI in ways that significantly affect individuals — for example hiring, or profiling family members — emerging state privacy laws and best practice call for transparency and meaningful human involvement, even though no SEC conduct rule applies.

Do this: Add an AI-use note where a model interacts with or profiles individuals, and ensure a person, not the model alone, makes any decision that significantly affects someone.

Source: State privacy statutes addressing automated decision-making (e.g. California CPRA regulations); office governance policy.

Confidence: Verify