Skip to content

Regtech Surge: Regulators May Not Need New AI Rules To Enforce AI Failures

AI Governance Must Be Mapped Into Existing Compliance Categories, Including Recommendations, Controls, Recordkeeping And Data Entry, Rather Than Treated As A Tech Issue

Regtech Surge: Regulators May Not Need New AI Rules To Enforce AI Failures
Sid Yenamandra, Founder & CEO, SurgeONE.ai
Published:

A common misconception I often hear around the wealth management space is that firms can wait for specific AI rules before building governance. That is a risky assumption. The absence of AI-specific rules does not mean the absence of regulatory exposure.

Let’s look at a useful real-world comparison with algorithmic and high-frequency trading. When algorithmic trading accelerated, regulators did not need an entirely new framework to bring enforcement actions. They applied existing rules related to manipulation, supervision and firm responsibility.

The same logic applies to AI. If AI contributes to a misleading recommendation, a privacy breach, deficient supervision, inaccurate records, fraudulent representation or failure to follow procedures, regulators can evaluate the conduct under existing obligations.

For RIAs, this means AI governance should be mapped to existing compliance categories rather than treated as a separate technology issue.

AI And Investor Harm

Regulatory scrutiny will focus heavily on investor harm or potential investor harm. This can arise in several ways. AI may generate inaccurate client communications. It may summarize investment risks incorrectly. It may produce a recommendation or analysis based on outdated or incomplete data. It may expose client information. It may create biased outputs. It may be used in workflows that affect trading, supervision or client service without adequate review.

The key issue is not whether the firm intended harm – that is not the standard. The issue is whether the firm had reasonable controls to prevent, detect and correct foreseeable risk.

The issue is whether the firm had reasonable controls to prevent, detect and correct foreseeable risk.

If AI is used in any process that touches investor outcomes, firms should apply heightened scrutiny. That includes client communications, recommendations, portfolio reviews, risk assessments, financial plans, account surveillance, complaint analysis, trade monitoring and even marketing materials.

AI And Reg BI, Fiduciary Duty And Recommendations

AI can create issues if its output constitutes or supports a recommendation to buy or sell particular securities.

For RIAs, the analysis should be tied to fiduciary duty. If an AI tool contributes to advice, recommendations, portfolio construction or client-specific analysis, the firm must ensure the output is appropriate for the client’s circumstances and consistent with the firm’s obligations. AI should not be allowed to generate client-facing advice without qualified review.

Firms should be careful not to let productivity tools drift into advice functions. A tool originally approved for summarization of meeting notes may later be used to draft recommendations. A tool approved to save time researching may later be used to produce client-ready commentary. A tool approved just for internal analysis may become part of a client deliverable.

Firms should be careful not to let productivity tools drift into advice functions.

This is why use-case boundaries matter. AI governance should specify not only which tools are approved, but what those tools are approved to do.

AI And Privacy

Non-public personal information and client data exposure are among the most serious AI risks. Privacy risk is especially acute when employees use public AI tools or personal accounts. If client data is entered into an open AI system, the firm may lose control over where that data goes, how it is stored, whether it is retained and whether it can be retrieved or deleted.

The firm’s AI policy should include bright-line rules about data entry. These rules should be practical enough that employees understand them.

A few examples on data entry could be:

  • Do not enter client names, account information, financial data or personally identifiable information into unapproved AI tools.
  • Do not upload client files, statements, reports, agreements or compliance records into unapproved AI tools.
  • Do not use personal AI accounts for firm business.
  • Do not use AI note-taking tools for client or internal meetings unless approved.
  • Do not use AI-generated output in client-facing communications without required review.
  • Do not rely on AI for final compliance, legal, investment or supervisory judgment.

But remember, written rules are not enough. The firm needs to test whether employees are following those rules.

AI And Recordkeeping

AI also creates recordkeeping issues. If employees use AI to generate content, summarize meetings, draft communications or analyze records, the firm must determine whether prompts, outputs, approvals, edits and final versions need to be retained. If AI tools operate outside approved systems, the firm may lose records that should have been preserved.

Personal AI accounts are problematic.

This is another reason personal AI accounts are problematic. Even if no client data is exposed, the firm may not be able to retain or supervise the activity.

A defensible AI framework should define recordkeeping standards for each use case. For high-risk uses, the firm should preserve enough information to reconstruct what happened.

That may include anything from prompt or instruction to AI-generated output to human edits to testing results.

The goal is not to retain unnecessary noise. The goal is to preserve evidence of supervision and decision-making where regulatory risk exists.

Sid Yenamandra is the Founder and CEO of SurgeONE.ai, a compliance, cybersecurity and data services platform for wealth management that unifies the offerings of RegVerse, Kovair, Security Snapshot and MGL Consulting.

More in Beltway & Beyond

See all

More from WSR Newsroom

See all

From our partners