AI & Technology Transparency: How Serra Wealth Uses AI (and Protects Your Data)

AI & Technology Transparency: How Serra Wealth Uses AI (and Protects Your Data)

A client and prospect transparency page. This is a policy and process page, not a product. It explains how AI is used inside Serra's engagement work, where your data does and does not go, and who stays accountable for anything AI touches. It is not investment advice, and it is not a description of a Serra Wealth investment product.

Serra Education ยท Last reviewed: 29 July 2026

This page is part of Serra's AI-in-Wealth resource hub. For related reading, see how Serra protects client data when using AI and what happens when you put client data into ChatGPT as a wealth adviser.


Does Serra use AI tools to process my financial data?

Only where a named lawful basis and a defined data boundary already exist, and never to make a decision about your money on its own. Serra's AI work is process-and-governance consulting: we help wealth firms and family offices run AI inside their conduct rules, under human oversight, logged, and inside that boundary.

Serra's thesis is narrow. The blocker to using AI in wealth is not the model, it is governance. A capable model with no data boundary, no validation step, and no audit trail is a compliance liability, not an efficiency gain. The three things that make AI safe to use on client data are the same three things a regulator asks for: a lawful basis for the processing, a boundary that keeps the data where it belongs, and a record of what happened. We build those first, then let the model do work inside them.

Under the GDPR, any processing of your personal data needs a lawful basis set out in Article 6 of Regulation (EU) 2016/679. AI does not create a new basis. If a task had no lawful basis without AI, adding a model does not fix that; if it had one, the model runs inside it.

Where does my data go, and what is the data boundary?

Your data stays inside the boundary the firm has defined for it and does not become training material for a public model. The boundary is a written, enforced rule about which systems your data may enter, which it may not, and what leaves. Serra designs and audits that boundary.

In practice, a well-drawn boundary answers four questions:

The UK Information Commissioner's Office guidance on AI and data protection is explicit that data-protection principles, including purpose limitation and data minimisation, apply in full to AI systems. A data boundary is how those principles become operational rather than aspirational.

For higher-risk processing, Article 35 of the GDPR requires a Data Protection Impact Assessment before the processing begins. Where an AI use case is likely to result in a high risk to individuals, the DPIA is not optional, and it belongs in the boundary design rather than after it.

Who is accountable for AI-assisted output, and is there human oversight?

A named person is accountable for every AI-assisted output, exactly as they would be without AI. The model drafts or accelerates; a qualified human reviews, corrects, and signs. Accountability does not move to the tool, and "the AI produced it" is never an answer to a regulator or to you.

Serra will not let a firm blur that line. AI in a well-run wealth process is an assistant to a named human, not a decision-maker. The human who would have owned the work owns it still, with the same duty of care and the same signature.

The GDPR draws a hard line here too. Article 22 gives individuals the right not to be subject to a decision based solely on automated processing where it produces legal or similarly significant effects. Advice and decisions about your finances can reach that bar, which is precisely why meaningful human involvement is designed into the process rather than bolted on.

The EU AI Act reinforces the same principle for higher-risk systems, requiring that they be designed so a human can effectively oversee them while in use. Serra's oversight design gives the reviewing human what they need to catch a real error, not a rubber stamp on output they cannot inspect.

Under the UK FCA's Consumer Duty (PRIN 2A), a firm must act to deliver good outcomes for retail customers. That obligation does not soften because a model was involved. If an AI-assisted output would produce a poor outcome, the accountable human is the control that stops it.

Is client-facing AI disclosed?

Yes. Where AI meaningfully shapes something you see or interact with, it is disclosed, not hidden behind a human veneer. Serra treats disclosure as a default of the process, and every client-facing artifact we produce or help a firm produce carries an AI-disclosure line, under human review.

The EU AI Act sets transparency obligations for AI that interacts with people, including that individuals are told they are interacting with an AI system where that is not already obvious, and that certain AI-generated content is marked as such. Serra's disclosure standard is built to meet that expectation as a baseline rather than a ceiling.

Disclosure also protects the firm. A client who knows AI assisted a document, under human review, is a client who was told the truth about the process. That is the durable position; concealment is the fragile one.

Is Serra vendor-neutral, or is this a way to sell me an AI product?

Serra is vendor-neutral. We do not resell an AI stack, take a margin on a model, or push you toward a particular vendor. The engagement is process-and-governance consulting: validation, data boundary, audit trail. The model a firm chooses is theirs to choose, and theirs to swap later without unpicking the governance.

This matters for the same reason independence matters anywhere in wealth: if the advice were a sales channel for a product, you could not trust the advice. Serra's recommendation is about how AI is governed, not which logo sits on it. A firm can act on Serra's governance work with almost any competent enterprise model.

Nothing on this page is Serra Wealth investment advice. Serra's AI-optimisation work is process and governance for how a firm operates. It is separate from any investment relationship and does not make a recommendation about your portfolio.

How does Serra stay inside MiFID II, GDPR, the EU AI Act, and FCA conduct rules while using AI?

By making the governance, not the model, do the compliance work: a lawful basis and boundary for the data, human accountability for every output, and a record that survives an audit. Each rule below maps to one of those three controls, which is why one governance design can satisfy several regimes at once.

What does MiFID II require for records of an AI-assisted process?

Article 16(6) of Directive 2014/65/EU requires an investment firm to keep records of its services, activities and transactions sufficient for the competent authority to fulfil its supervisory tasks. An AI-assisted process must be at least as recordable as the manual one it replaces, capturing what was processed, what the model produced, who reviewed it, and what changed.

Serra's audit-trail design captures those elements, so the record answers the regulator's question rather than raising it.

Which GDPR articles govern AI processing of client data?

Three. Article 6 requires a lawful basis for the processing; Article 22 protects against decisions based solely on automated processing with significant effects, so meaningful human involvement is designed in; and Article 35 requires a Data Protection Impact Assessment where the processing is high-risk. The ICO's AI guidance is the practical companion to all three.

The ICO guidance applies data minimisation and purpose limitation to the AI system itself, turning the GDPR principles into operational controls.

How does the EU AI Act's risk tier decide the controls, and when do they apply?

The EU AI Act is risk-tiered: obligations scale with how the system is used, so Serra's first step on any use case is to place it correctly in that tier. Higher-risk uses carry human-oversight and documentation duties; AI that interacts with people carries transparency and disclosure duties. The main high-risk obligations apply from 2 August 2026.

Placing a use case in the wrong tier means the wrong controls, so the tier sets both the controls and the timeline.

What do the FCA conduct rules add for a UK firm using AI?

For UK-regulated firms, Consumer Duty (PRIN 2A) requires acting to deliver good outcomes for retail customers, and SYSC 9.1 requires orderly records of the firm's business and internal organisation. AI gets no carve-out from either. The same human-accountability and audit-trail controls that satisfy MiFID II recording also evidence the conduct obligations.

The through-line is plain: same headcount, a quarter of the hours, still inside your conduct rules. The efficiency comes from the model. The "still inside your conduct rules" comes from the governance. Serra builds the second so a firm can safely have the first.

What this page is, and what it is not

This is process-and-governance guidance, not legal, investment, or compliance advice. It describes how Serra approaches AI governance in wealth. It does not tell you what your specific obligations are, and it is not Serra Wealth investment advice. Regulation changes and applies differently by firm and jurisdiction; confirm every obligation against the primary source and your own counsel.

AI disclosure: This page was drafted with AI assistance and reviewed by a member of the Serra team before publication.

Related reading: Return to the AI-in-Wealth resource hub, or read Serra's responsible-AI governance framework for wealth firms and how Serra protects client data when using AI.


Primary sources referenced