AI compliance hinges on a human-in-the-loop policy
A 411-firm survey finds 48% can point to a human-review policy for AI output, leaving the rest to answer an exam letter built on Regulation S-P.
Only 48% of compliance officers at investment advisory firms can point to a policy requiring a human to check AI-generated output at defined points, according to an ACA Group survey of 411 firms reported by Financial Planning, which leaves more than half without a documented step where a person verifies the model's work before it reaches a client. In a regulatory environment with no AI-specific rule, that is the number examiners are likely to start with.
The search for an AI rule was abandoned: the SEC under former Chairman Gary Gensler had considered making firms responsible for finding and mitigating conflicts of interest in their use of AI, but the proposal was dropped last summer amid the lighter regulatory approach of the Trump administration. Carlo di Florio, president of compliance consultant ACA Group, told Financial Planning that wealth managers do not necessarily want a comprehensive AI governance rule to replace it; many would like guidance on how existing rules apply and how to design controls that meet regulatory expectations. Without that clarity, firms are left to infer the standard from the rules they already have.
The existing rules already cover the ground: Regulation S-P, the primary rule requiring advisors to protect private client data, was revised to give advisors 30 days to notify clients after a security breach, and third-party firms that advisors enlist for services come under the same requirement. Financial Planning frames the regulator's goal as preventing firms from using AI in ways that violate long-standing investor and market protections, which points the exam agenda at privacy, suitability, and advertising rather than the technology itself. A 30-day clock leaves little room for a vendor to sit on news of a breach, which is why the vendor question matters as much as the internal one.
No specific AI rule exists, and Financial Planning's report argues the SEC's goal is to prevent firms from using AI in ways that violate long-standing protections, with those protections technology-neutral. Regulation S-P does not care whether the leak came from a human mistake or a model's output; it cares that client data was exposed and that clients were told. The same logic runs through suitability duties: a recommendation is a recommendation regardless of its source.
The gap between internal policy and vendor oversight is where the exposure sits: advisory firms have largely adopted internal policies meant to keep private client data from being entered into a public version of a large language model, but many have not required outside service providers to do the same, according to the ACA Group survey. A vendor that feeds client account numbers or financial details into a public model could create a breach scenario with the 30-day clock already running, and the survey's split is a warning that the firm's own firewall is not the boundary of its data.
The human-in-the-loop number is the clearest measure of readiness, and Di Florio put it directly: 'We know that AI hallucinates and there's biases and there's errors.' An exam question about how the firm verifies AI-generated output is answered by a documented human review process; without one, the answer becomes a description of how the model works, which is not evidence of supervision. The human checkpoint is not skepticism of the technology; it is the legal standard, because a recommendation generated by AI is still a recommendation the firm makes, and the suitability duty does not pause because the analysis came from a prompt.
Because the AI rule proposal was dropped last summer, the firms responding to ACA Group are operating in a gray zone, advising on rules that do not mention AI, and the first examiners asking about AI will likely not have a checklist of AI-specific violations to cite. They will have Regulation S-P, the suitability rule, and the advertising rules, which is a wider net, not a narrower one.
The practical work before the next exam is mapping each AI use case to the rule it touches — client data to Regulation S-P, recommendations to suitability duties, marketing language to advertising rules — then writing the human-review policy and asking vendors whether client data touches a public large language model. Firms that treat AI governance as a vendor-management problem will get more from their compliance time than those waiting for a bright-line rule from Washington, because the rule is not coming soon and the exam agenda is set by the rules already on the books. Financial Planning's related reporting has captured the industry's split: advisors love AI, but most are scared of the compliance risk.
When the examiner asks who checked the output, 'we trust the model' will not be an answer. The 48% have a policy to point to; the rest will be writing one on the examiner's timeline.