AnyLearn
All lessons
Businessintermediate

Supervision, AI Washing, and What the Client Is Paying For

Running AI inside a regulated advisory practice: keeping tools within the firm's capture and supervision system, the confidentiality problem, what you may and may not say about your own AI use after the SEC's first enforcement actions, and the parts of the job a client structurally cannot get elsewhere.

Updated · AI-authored, review-gated · how lessons are made

Not signed in: your progress and quiz score won't be saved.
Progress1 / 8

The tool is inside the regulated perimeter

The governance question that comes before every other one is whether the tool sits inside or outside the firm's supervised environment, and most firms discover the answer late.

An advisory firm operates a supervisory system: communications are captured, records are retained for prescribed periods, and someone is responsible for reviewing them. That system was designed around email, telephone and approved messaging platforms.

A generative AI tool used for client work creates communications and work product that may fall within the same requirements. If an advisor works through a client's position in a chat window, that exchange concerns advice, involves client information, and lives somewhere the firm's retention system does not reach.

This is structurally the same problem as off-channel communications, which regulators have pursued firms over at significant scale. The difference is that off-channel messaging was obviously a channel. A chat window feels like a tool, more like a calculator than like a conversation, and the categorisation error follows from that feeling.

FINRA's Regulatory Notice 24-09 makes the position explicit: the supervision obligation under Rule 3110 applies whether the firm develops the tool itself or uses a third party's, including AI features embedded in existing products.

The practical consequence. The first decision is procurement, not usage. Which tools are approved, do they retain in a way the firm can access, and is the output reviewable. An advisor using a personal account for client work has created a supervision gap regardless of how good the output is.

Full lesson text

All 8 steps on one page, for reading, reference, and search.

Show

1. The tool is inside the regulated perimeter

The governance question that comes before every other one is whether the tool sits inside or outside the firm's supervised environment, and most firms discover the answer late.

An advisory firm operates a supervisory system: communications are captured, records are retained for prescribed periods, and someone is responsible for reviewing them. That system was designed around email, telephone and approved messaging platforms.

A generative AI tool used for client work creates communications and work product that may fall within the same requirements. If an advisor works through a client's position in a chat window, that exchange concerns advice, involves client information, and lives somewhere the firm's retention system does not reach.

This is structurally the same problem as off-channel communications, which regulators have pursued firms over at significant scale. The difference is that off-channel messaging was obviously a channel. A chat window feels like a tool, more like a calculator than like a conversation, and the categorisation error follows from that feeling.

FINRA's Regulatory Notice 24-09 makes the position explicit: the supervision obligation under Rule 3110 applies whether the firm develops the tool itself or uses a third party's, including AI features embedded in existing products.

The practical consequence. The first decision is procurement, not usage. Which tools are approved, do they retain in a way the firm can access, and is the output reviewable. An advisor using a personal account for client work has created a supervision gap regardless of how good the output is.

2. Client data is the most sensitive category there is

The confidentiality problem in this profession is more acute than in most, because of what advisors hold.

A client file typically contains a complete financial picture: net worth, income, debts, tax position, account numbers, and identity documents. Alongside that sits information that is sensitive for entirely non-financial reasons: a diagnosis that changed a retirement plan, a divorce, an estranged child excluded from an inheritance, a business in difficulty.

That combination is unusually valuable to an attacker and unusually damaging if disclosed.

The regulatory frame in the United States includes Regulation S-P, which requires policies and procedures to safeguard customer records and information, and which the SEC amended in 2024 to add incident response and customer notification requirements. In Europe the GDPR applies with financial data attracting particular scrutiny.

The failure mode is mundane rather than dramatic. An advisor pastes a client's full position into a consumer chat tool to get a second view on the allocation. Nothing goes wrong visibly. The data has left the firm, may be retained, and under some consumer terms may be used to improve the service.

The practical controls, in order. Use firm-procured tools with terms that address retention and training use. Minimise what you paste: most analytical questions do not need names, account numbers or identity documents. And keep a hard category list of what never goes into any external tool, whatever its terms.

And note that this exposure is invisible. Nobody complains, and it accumulates quietly across a practice.

3. What you may say about your own AI use

There is one area where regulators have already acted specifically on AI in this sector, and it is not about how firms use the technology. It is about what they claim.

On 18 March 2024 the SEC announced settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions, Inc., for false and misleading statements about their use of artificial intelligence. Delphia paid a civil penalty of 225,000 dollars and Global Predictions 175,000 dollars. The SEC's charges included violations of the antifraud provisions of the Advisers Act, the Marketing Rule, and the Compliance Rule for failing to implement policies reasonably designed to prevent the violations.

The conduct is instructive. Delphia was charged with advertising that it used AI to analyse client data and predict investment trends when, according to the SEC, it had not used client data in that way and had not built the algorithm described.

The pattern this establishes, often called AI washing, is that describing a capability you do not have is an ordinary misstatement case. No new rule was required. The Marketing Rule's prohibition on untrue statements of material fact and its substantiation requirement were sufficient.

The practical rule for a practice. You may say what you actually do. We use AI to prepare meeting documentation is fine if true. Our AI analyses market data to optimise your portfolio requires that something meeting that description exists and that you can substantiate it on demand.

And the inverse holds. Understating is safe. Overstating is an enforcement matter.

4. Telling clients, and why most of it is not required

Advisors ask whether they must tell clients that AI is used in the practice, and the answer separates into cases that are frequently conflated.

Where disclosure is required or close to it. Recording a client meeting, which requires consent and in some jurisdictions the consent of all parties. Any system interacting directly with a client, which under Article 50 of the EU AI Act requires that the person be informed they are dealing with an AI system where that is not obvious, applying from 2 August 2026. And any material conflict of interest arising from how a tool is used, which is disclosable under the ordinary fiduciary duty of loyalty rather than under any AI rule.

That third one is the underrated case. If a tool's output is influenced by an arrangement between the vendor and a product provider, that is a conflict, and it is disclosable on exactly the same basis as any other conflict.

Where disclosure is not required. That drafting assistance was used in preparing a letter you reviewed and adopted. Clients do not expect an advisor to have personally typed every word of a review document, and the disclosure signals anxiety without informing anything.

The test that separates them. Would this change the client's assessment of the advice or the relationship. A conflict changes it. A recording changes it. A drafting tool the advisor reviewed does not.

And note the asymmetry with the previous step. You need not advertise your AI use. If you do advertise it, it must be true and substantiated.

5. The four governance questions

A sequence for evaluating any AI use in an advisory practice, in the order the questions actually bind.

First, capture. Does the tool sit inside the firm's retention and supervision system. If not, nothing else matters, because usage creates a gap regardless of quality.

Second, data. What client information enters it, under what terms, and does the arrangement satisfy the safeguarding obligation. This is where a technically approved tool can still be used wrongly.

Third, output. Does anything reach a client or the file without a person adopting it. If yes, that is the point to fix, because the advisor is asserting whatever goes out.

Fourth, claims. Does the firm describe this capability externally, and can every description be substantiated on demand. This is the question that has actually produced enforcement.

The ordering matters. Firms tend to start at the third question, because output review feels like the responsible thing to do, and it is. But an approved review process on a tool that sits outside the supervisory perimeter fixes the visible problem and leaves the structural one.

flowchart TD
A["Proposed AI use"] --> B["1. Capture: inside retention and supervision?"]
B --> C["No: stop, the gap exists regardless of output quality"]
B --> D["2. Data: what client information enters, under what terms?"]
D --> E["3. Output: does anything reach a client without a person adopting it?"]
E --> F["4. Claims: can every external description be substantiated?"]
F --> G["Deployable, with the review discipline for that workflow"]

6. The advice gets cheaper, the advising does not

The structural question for the profession is what happens as the analytical and administrative layers get cheap, and it is worth being precise about which part is exposed.

Automated portfolio management has existed at scale for over a decade and has taken the part of the business that was purely allocation and rebalancing. That process is largely complete, and the advisors it displaced were the ones whose service was portfolio construction alone.

What generative tools compress is different: the documentation, the explanation, the preparation, the research digestion. That is a cost reduction inside the practice rather than a substitution for it.

The part that resists both is planning and behaviour. Deciding whether to take the pension as income or a lump sum given a specific family situation. Working out whether the client can afford to help their son with a deposit without compromising their own retirement. Talking someone out of liquidating in a falling market.

That last one is the clearest case. Research on investor behaviour, including the long-running work on the gap between fund returns and investor returns, consistently finds that investors underperform the funds they hold because of the timing of their own purchases and sales. The methodologies are debated and the size of the gap varies by study, but the direction is well documented. An advisor who prevents one badly timed exit has justified years of fees, and the mechanism by which they do it is a relationship, not an analysis.

So the fee compresses toward what it was always actually for.

7. What a client cannot get elsewhere

Naming precisely what is not substitutable, because that is what the fee is for and it is a shorter list than advisors assume, but a solid one.

An accountable party. A client who is badly advised has someone to hold responsible, professionally, and through a regulator, and often through insurance. That accountability is a substantial part of what is purchased, and no system provides it.

Judgement across domains that do not connect cleanly. A retirement decision touches tax, pensions, estate planning, family dynamics and the client's own health, and the right answer is a compromise between them rather than an optimum in any one. This is exactly the shape of problem that resists automation, because the objective function is not stated anywhere.

Knowing what the client actually wants. Covered in lesson two, and worth restating: the stated objective and the real objective differ, and the reconciliation happens in conversation.

Behavioural intervention. Being the person who is called before the panicked sale, and being trusted enough that the call happens.

And continuity. A relationship that spans decades, holds the history of why decisions were made, and knows the family. That accumulated context has no substitute, and it is why advisory relationships are unusually long.

The pattern matches the other profession cursus in this catalogue: production compresses, judgement and accountability do not. What is distinctive here is that the regulation has already drawn the line explicitly, which makes the boundary easier to see than in professions where it is only a matter of practice.

8. A short policy for a practice

What a small advisory firm can write down, which is the realistic form of governance below the scale that has a compliance department.

Approved tools. A named list. Client work happens only on tools from that list, and the list is chosen for retention, supervision access and data terms rather than for output quality. Personal accounts are not used for client work.

Client data. A category list of what never leaves the approved environment: identity documents, account numbers, and anything about a client's health, family circumstances or financial difficulty. Minimise what is supplied for any analytical question.

Calculation. Numbers come from the planning system, the portfolio system or the spreadsheet. A language model explains a number, it does not produce one.

Meetings. Recording with consent, obtained at the start. The transcript is a client record. The generated note is reviewed for misattribution and compressed caveats before it is filed.

Client-facing output. Reviewed and adopted by the advisor before it goes out. Anything meeting the definition of an advertisement goes through normal marketing review with substantiation for each material claim.

Recommendations. Made by the advisor. A model may inform the analysis and draft the explanation, and the named person owes the duty.

Claims. The firm describes only what it actually does, and each description is substantiable on demand.

Seven paragraphs, and every one of them derives from an obligation that already existed before any of these tools did.

Check your understanding

The lesson ends with a 5-question quiz. Take it in the player above to see your score.

  1. Why is a chat tool used for client work structurally similar to an off-channel communication problem?
    • Both involve unencrypted data transmission
    • Both create business communications about advice that sit outside the firm's capture and supervision system
    • Both are prohibited by FINRA rules
    • Both require client consent
  2. What did the SEC's March 2024 actions against Delphia and Global Predictions establish?
    • That AI use by advisers requires pre-registration
    • That predictive analytics tools are prohibited for retail advice
    • That describing an AI capability you do not have is an ordinary misstatement case under existing rules
    • That AI-generated marketing content must be labelled
  3. Which AI-related fact about a practice is disclosable under the ordinary fiduciary duty rather than any AI-specific rule?
    • That a drafting tool was used to prepare a reviewed letter
    • The name of the model the firm uses
    • The firm's total spend on AI tooling
    • A material conflict of interest arising from how a tool is used
  4. Why does the governance sequence put capture before output review?
    • Output review is unnecessary once capture is solved
    • Regulators inspect retention systems first
    • An approved review process on a tool outside the supervisory perimeter fixes the visible problem and leaves the structural one
    • Capture is cheaper to implement
  5. What does the lesson identify as the clearest case of non-substitutable advisor value?
    • Behavioural intervention: being called before a panicked sale, and being trusted enough that the call happens
    • Access to institutional research
    • Speed of portfolio rebalancing
    • Lower-cost fund selection

Related lessons

Law & Compliance
advanced

Proof: Disclosure, Presumptions, and the Complexity Rule

Strict liability is worthless if the claimant cannot prove a defect they never saw. Articles 9 and 10 answer that with a disclosure order, three presumptions of defectiveness, a presumption of causation, and a rule turning complexity into the claimant's ally. This lesson works through the cascade, the three-year and ten-year clocks, and what a defendant should be able to produce.

10 steps·~15 min
Law & Compliance
advanced

Who Pays, and For What Damage

The Directive builds a chain of liable operators so an injured person in the EU always has someone to sue. This lesson covers the manufacturer and component manufacturer, the importer and fulfilment service provider route, the distributor's one-month rule, online platforms, how a modification makes you a manufacturer, the heads of damage including data loss, and the exemptions.

10 steps·~15 min
Law & Compliance
advanced

Defectiveness: The Safety a Person Is Entitled to Expect

A product is defective when it lacks the safety a person is entitled to expect. Article 7 turns that into circumstances a court weighs, several written for software: the ability to learn after release, interconnection, cybersecurity requirements, and recalls. This lesson works through the list, the rule that a later improvement is not an admission, and why compliance is not a defence.

10 steps·~15 min
Law & Compliance
advanced

Software as a Product: What the New Liability Directive Changed

Directive (EU) 2024/2853 replaces the 1985 regime and settles a forty-year argument by naming software a product. This lesson covers the new definition and why delivery method is irrelevant, why information is not a product, how components and related services extend the net, where open source sits, and why liability cannot be disclaimed by contract.

10 steps·~15 min