$200M+
AI Washing Fines
Delphia and Global Predictions (2024)
2026
Examination Priority
SEC lists AI governance in annual priorities
30 Days
Breach Notification
Under amended Reg S-P (effective June 2026)
5 Years
Records Retention
AI-related books and records under Rule 204-2
The Securities and Exchange Commission has spent the last two years making its expectations clear: if your firm uses artificial intelligence, you are responsible for governing it. That responsibility carries documentation requirements, supervision obligations, disclosure standards, and examination exposure that most registered investment advisers are not fully prepared for.
This article covers what the SEC has said, what it has done, and what a defensible AI governance program looks like for an RIA in 2026.
The Regulatory Foundation: What Rules Apply to AI
No single SEC rule is titled "AI Governance." What exists instead is a framework of existing rules — adopted decades before AI was a mainstream business tool — that the SEC has made clear apply fully to how your firm uses AI today.
Investment Advisers Act Rule 206(4)-7 requires every registered investment adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act. The SEC's position, articulated in multiple examination priority letters and risk alerts, is that AI use without governance controls is a failure of this requirement. If your firm uses AI to support investment decisions, client communications, compliance workflows, or any regulated activity — and you lack written policies governing that use — you have a Rule 206(4)-7 gap.
Rule 204-2 (Books and Records) requires advisers to maintain specific records for defined retention periods. The SEC staff has stated that AI-generated outputs, AI system prompts, and the records of AI-assisted decisions qualify as required records. If your firm is using AI to research securities, draft client communications, or support compliance functions, those interactions may be required records under Rule 204-2 — and must be preserved accordingly.
Investment Advisers Act Section 206 (Anti-Fraud) prohibits any adviser from employing any device, scheme, or artifice to defraud clients. In 2024, the SEC applied this provision directly to AI when it brought its first AI enforcement actions.
The 2024 Enforcement Actions: AI Washing Is a Violation
In March 2024, the SEC settled charges against two investment advisers — Delphia (USA) Inc. and Global Predictions Inc. — in what the agency described as the first-ever AI washing cases.
📌 Important
Delphia claimed in marketing materials that it used client transaction data to train its AI, implying it had a proprietary data advantage that informed its investment process. The SEC found these claims were false — the firm did not use client data in its AI as described. Penalty: $225,000.
Global Predictions claimed to provide "expert AI-driven forecasts" and called itself "the first regulated AI financial adviser." The SEC found the firm made false and misleading statements about its AI capabilities and use of certain predictive models. Penalty: $175,000.
Both settlements required remediation of disclosures and policies. Neither firm's AI was sophisticated enough to justify the claims made — and the SEC treated that gap as fraud.
The implication for every RIA: your Form ADV disclosures, your marketing materials, your website, and your client communications must accurately describe how your firm uses AI — or doesn't use it. Overclaiming is a Section 206 problem. Undisclosing material AI use is also a problem.
SEC Examination Priorities: AI Is on the List
The SEC Division of Examinations published its fiscal year 2026 examination priorities explicitly listing investment adviser AI governance as an area of focus. Specifically, examiners will look at:
⚠️ Warning
This is not a future concern. SEC examiners are currently visiting firms and asking about AI governance. If your CCO cannot answer basic questions about what AI tools your firm uses, what data flows through them, how outputs are reviewed, and how records are maintained — that is an examination finding in progress.
What the SEC Expects: The Five Core Requirements
Based on published guidance, examination priorities, enforcement actions, and SEC staff statements, a defensible AI governance program for an RIA in 2026 addresses five areas:
1. Written Policies and Procedures
Your policies must identify every AI tool the firm uses in a business or compliance context. For each tool, the policy must address: who is authorized to use it, what data may be input, what types of decisions it may support, how outputs are reviewed before use, and what documentation is required. A general technology use policy that mentions AI in passing does not satisfy this requirement.
2. Supervision of AI-Assisted Outputs
AI tools do not absolve advisers of their supervisory obligations. If an employee uses AI to research a security recommendation, draft a client communication, or support a compliance determination — a supervisor must review the output before it is acted on. That review must be documented. The supervision framework must be written, assigned to specific roles, and tested.
3. Accurate Disclosure in Form ADV
Your Form ADV must accurately describe how your firm uses AI. If you use AI to support investment research, that should be disclosed. If you use AI in portfolio construction, that should be disclosed. If you market AI-driven capabilities, those capabilities must be what they appear to be. The SEC's AI washing enforcement actions established that inaccurate AI disclosures are a fraud risk, not just a marketing compliance issue.
4. Records Retention for AI Interactions
AI-generated outputs that support investment decisions or client communications are records under Rule 204-2. Your records management system must capture and retain those outputs — along with sufficient context to reconstruct the basis for the decision — for the applicable retention period (generally three years for most records, five years for certain records, with the first two years in an accessible location).
5. Vendor Oversight for Third-Party AI
Most RIAs are not building their own AI tools. They are using third-party platforms — portfolio management systems, CRM tools, research platforms — that have embedded AI features. Each of those vendors is a service provider who may be processing client data. Your vendor oversight policies must address AI-specific risks: what data is being processed by the vendor's AI, under what terms of service, and whether those terms are compatible with your regulatory obligations.
The Disclosure Trap Most RIAs Miss
The most common AI governance failure for RIAs is not deliberate overclaiming. It is the gap between what the Form ADV says and what is actually happening in the firm.
If your ADV says your firm does not use AI — but your analysts are using ChatGPT, your CRM has an AI assistant enabled, or your compliance monitoring tool uses AI to flag anomalies — your ADV disclosure is inaccurate. That inaccuracy is a compliance failure.
✅ Action
The SEC does not require advisers to avoid using AI. It requires advisers to govern their AI use and disclose it accurately. Firms that have done the inventory, written the policies, and updated their ADV are in a defensible position. Firms that have not are accumulating examination risk with every month that passes.
What a Technically Enforced SEC AI Governance Program Looks Like
Written policies are necessary but not sufficient. The SEC expects evidence of implementation — not just documentation of intent. A defensible program has three layers working together:
Governance layer: Written policies, supervision procedures, disclosure review, and a compliance calendar that includes AI policy updates as regulatory guidance evolves.
Technical layer: Controls that enforce the policies — approved AI tool lists enforced at the network level, data loss prevention rules that prevent client data from reaching unauthorized AI platforms, audit logs that capture AI interactions for records purposes.
Evidence layer: Retained records that demonstrate the governance and technical controls are operating as described — examination-ready documentation that examiners can review in the first 24 hours of a visit.
Firms that rely solely on the governance layer — policies without technical enforcement — will struggle in examinations because they cannot demonstrate that employees are actually following the policies. The CB Financial Form 8-K filed in May 2026 is the clearest available illustration of what happens when policies exist but technical controls are absent: one employee, one unauthorized AI tool, one SEC disclosure.
🔗 Related Service: AI Governance Program
Centience builds and operates SEC-ready AI governance programs for registered investment advisers — technically enforced, not just documented.

Frequently Asked Questions




