The most common AI mistakes EU wealth firms make

The most common AI mistakes EU wealth firms make

The most common AI mistakes EU wealth firms make are treating AI as a separate regime, letting model output reach clients unreviewed, putting client data into general-purpose tools, keeping no MiFID II record of the AI step, and misclassifying AI Act risk. Each breaches a rule that already applies. Below is each mistake and the compliant fix.

The EU regulates AI in wealth through rules that mostly predate the AI Act: MiFID II conduct and recordkeeping, ESMA's 2024 statement, the GDPR, and, from 2026, the EU AI Act's transparency duties. There is no AI carve-out. An EU firm that runs AI outside these rules is not in a grey area; it is in breach of rules that already bind it. The fix is almost always the same shape: a named human, a written basis, and a record.

Mistake 1: Treating AI as a separate regime instead of MiFID II

Why it is a problem. ESMA's position is that a firm using AI has to meet its existing MiFID II obligations; the technology does not create a carve-out. In its May 2024 statement, ESMA said firms using AI are expected to comply with relevant MiFID II requirements, particularly on organisational aspects, conduct of business, and the obligation to act in the best interest of the client. Waiting for a bespoke "AI regime" means running unreviewed AI against conduct rules that already apply.

The compliant fix. Map each AI use onto the MiFID II duty it touches. The conduct standard you meet for a human-drafted client communication is the standard an AI-drafted one must meet, because MiFID II requires information to clients to be fair, clear, and not misleading. Treat AI adoption as a conduct-and-governance exercise, not a wait for new rules.

Mistake 2: Letting AI output reach a client without a named human

Why it is a problem. A polished, confident AI client note is a regulated communication, and confident wording is not the same as accurate wording. MiFID II requires information addressed to clients to be fair, clear, and not misleading, and ESMA expects firms to act in the best interest of the client when using AI. An unreviewed AI output that reaches a client puts that standard outside anyone's control.

The compliant fix. Treat any model output that touches a client as a draft, not a deliverable. Put a named human between the model and the client, and make that reviewer accountable for the fair-clear-not-misleading standard. Suitability is the same: a model can help assemble the case, but the firm, not the model, owns the assessment that the product fits the client.

Mistake 3: Putting client data into a general-purpose AI tool

Why it is a problem. The moment client personal data enters a prompt, the GDPR (Regulation (EU) 2016/679) applies to that processing, and the firm needs an Article 6 lawful basis. Pasting a client's name, holdings, and circumstances into a general-purpose tool never scoped for confidential financial data is a processing decision the firm must be able to justify, and rarely can, for a public tool that may retain or train on the input.

The compliant fix. Decide which tools are allowed to see client data and contain that work inside a covered, contracted environment. Keep live client data out of general-purpose AI tools entirely, as a baseline discipline, and document the Article 6 lawful basis for any real-data workflow before it runs.

Mistake 4: Automated decisions that ignore GDPR Article 22

Why it is a problem. GDPR Article 22(1) gives a data subject the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. A suitability outcome or a portfolio action is exactly that kind of effect. Where automated decision-making is permitted, Article 22(3) requires safeguards including human intervention, the right to express a view, and the right to contest the decision. A decision resting on the model alone, without those safeguards, breaches Article 22.

The compliant fix. Keep a human in the loop on any decision that significantly affects a client, so the Article 22 safeguards are real rather than notional. The human must be able to intervene and change the outcome; a rubber-stamp is not human intervention within the meaning of the Article.

Mistake 5: Keeping no MiFID II record of the AI step

Why it is a problem. Recordkeeping does not soften because a model did the drafting. MiFID II (Directive 2014/65/EU) Article 16(6) requires a firm to keep records of all services, activities, and transactions, sufficient for the competent authority to verify compliance. Article 16(7) requires records of relevant electronic communications, kept for a minimum of five years. Every model-drafted memo, AI-summarised call, and model-screened shortlist that feeds a client decision is a record that has to be reconstructable after the fact.

The compliant fix. Log the AI step inside the same evidence chain you already keep for the human one. Capture the prompt, the output, the reviewer, and the sign-off, and retain it on the MiFID II clock, five years minimum under Article 16(7). A firm that cannot show what the model was asked, what it produced, and who signed off has a recordkeeping gap, not a productivity gain.

Mistake 6: Misclassifying AI Act risk (over- or under-stating it)

Why it is a problem. Firms either panic that all AI is "high-risk" or assume none of it is regulated. Both are wrong. Under the EU AI Act (Regulation (EU) 2024/1689), the high-risk financial-services use is narrow: AI intended to evaluate the creditworthiness of natural persons or establish their credit score, per Annex III point 5(b), with a fraud-detection exception. Drafting client communications, summarising research, and internal productivity work are not in Annex III's high-risk list. But a firm running AI to score individual clients' creditworthiness has a high-risk system and the heavier regime that comes with it.

The compliant fix. Classify each AI system by what it does, not by how advanced it is. Map any creditworthiness-scoring use to the high-risk track. Treat client-facing generative and interactive uses as limited-risk transparency obligations under Article 50, covered next.

Mistake 7: Missing the EU AI Act Article 50 transparency duties

Why it is a problem. Article 50 reaches everyday wealth AI. It requires providers of AI systems intended to interact directly with natural persons to ensure those persons are informed they are interacting with an AI system, unless obvious from context (Article 50(1)). It also requires deployers who use AI to generate or manipulate published text on matters of public interest to disclose that the text is artificially generated, subject to limited exceptions such as human editorial review (Article 50(4)). The Article 50 transparency obligations apply from 2 August 2026, a diarised date, not a distant one.

The compliant fix. For any client-facing chatbot or assistant, disclose that clients are dealing with AI. For AI-generated content you publish, disclose it where Article 50(4) applies. Diarise 2 August 2026 for the transparency baseline and build the disclosure into the workflow now, rather than retrofitting it under deadline.

The binding constraint is governance, not the model

Read the seven together and one thing is constant. Not one of them regulates which model you pick. They regulate whether a human owns the output, whether client data stays contained, whether client-facing AI is disclosed, and whether you can reconstruct what the model did. That is governance. A firm can swap one model for another and change nothing about its compliance position, because the binding constraint sits in the workflow around the model, not in the model itself.

This is the work Serra Education does with EU wealth firms: adopting AI with the guardrails built in from the start, meaning validated output with a named human check, contained client data, disclosed client-facing use, and an audit trail that exists before anyone asks for it. The differentiator is the Regulator Test: we build each AI workflow so it can answer the question an ESMA or national-competent-authority reviewer would actually ask, before the reviewer asks it. The entry point is a Consulting 1 session, 250 EUR, credited toward the Tier 1 audit if you go on to the full engagement.

See the full picture at AI for Wealth. For the full EU rulebook, read the AI rules every EU wealth-management firm must follow; for the UK mirror of this list, the AI mistakes UK financial advisers make; and for why this is a governance gap, the AI gap in wealth is governance, not adoption. Running an EU wealth-management firm? Start with the EU wealth-manager compliance finder. To book the Consulting 1 session, use the report and booking page.

FAQ

Does the EU AI Act ban wealth firms from using AI?

No. Most wealth-management AI, drafting, summarising, internal productivity, is limited-risk under the EU AI Act and carries only Article 50 transparency duties from 2 August 2026. Only a narrow use, scoring the creditworthiness of individual clients, is high-risk under Annex III point 5(b). Classify each system by what it does.

Is MiFID II or the EU AI Act the main rule for AI in wealth?

Both apply, and MiFID II bites first. ESMA's position is that a firm using AI must meet its existing MiFID II conduct, best-interest, and recordkeeping duties; the AI Act adds transparency obligations on top from 2026, it does not replace MiFID II. Map your AI use to MiFID II first, then the AI Act.

How long must we keep records of AI-assisted client work?

At least five years, under MiFID II Article 16(7), for relevant electronic communications. Capture the prompt, the output, the reviewer, and the sign-off, and retain the AI step inside the same evidence chain as the human one. A missing record is a recordkeeping breach independent of the content.

Can we use an AI tool to make a suitability decision automatically?

Not solely. GDPR Article 22 gives a client the right not to be subject to a solely automated decision with significant effects, and a suitability outcome qualifies. Keep a named human able to intervene, express a view, and change the outcome. The model can assemble the case; the firm owns the assessment.

How is the EU different from the UK on AI in wealth?

The substance is close: both demand a named human, a data boundary, and records. The EU routes it through MiFID II, ESMA's 2024 statement, the GDPR, and the EU AI Act; the UK through the FCA's Consumer Duty, SM&CR, SYSC, COBS, and UK GDPR under the ICO. The EU has a codified AI Act; the UK has said it will not write AI-specific rules.


Serra Education provides process and tooling consulting only, never Serra Wealth investment advice.

This article is general information on AI-adoption process and governance. It is not investment, legal, or compliance advice. Each firm is responsible for its own regulatory compliance and for validating any AI output it relies on. No live client data should be placed in any AI workflow that is not contracted and assessed for it. Regulatory positions and timelines can change; confirm current obligations with qualified counsel and against the primary sources before you rely on them.

About the author

Daniel Martinez — Founder & CEO, Serra Wealth

Daniel Martinez is the founder and CEO of Serra Wealth, an independent, non-discretionary consulting firm for UHNW families and principals. He has picked stocks on fundamental and technical analysis since 2014 and managed his own crypto and public-equity portfolios since 2016. He holds a BBA from Esade and a Professional Investment and Risk Management certification. He is a professor at The American College of the Mediterranean (ACM/IAU), a recurring guest professor at UPF Barcelona School of Management, and a guest lecturer at Esade, was previously a professor at the Instituto de Inversiones Bursátiles y Trading (IBT), and speaks regularly at industry conferences.