Back to Insights
AI Governance

SEC AI Governance Requirements: What Investment Advisers Must Have in 2026

The SEC has issued examination risk alerts, enforcement actions, and guidance that make AI governance a compliance requirement for registered investment advisers. This article covers exactly what the agency expects — and what a defensible program looks like.

Orville Matias
Orville Matias
SEC AI Governance Requirements: What Investment Advisers Must Have in 2026

$200M+

AI Washing Fines

Delphia and Global Predictions (2024)

2026

Examination Priority

SEC lists AI governance in annual priorities

30 Days

Breach Notification

Under amended Reg S-P (effective June 2026)

5 Years

Records Retention

AI-related books and records under Rule 204-2

The Securities and Exchange Commission has spent the last two years making its expectations clear: if your firm uses artificial intelligence, you are responsible for governing it. That responsibility carries documentation requirements, supervision obligations, disclosure standards, and examination exposure that most registered investment advisers are not fully prepared for.

This article covers what the SEC has said, what it has done, and what a defensible AI governance program looks like for an RIA in 2026.

The Regulatory Foundation: What Rules Apply to AI

No single SEC rule is titled "AI Governance." What exists instead is a framework of existing rules — adopted decades before AI was a mainstream business tool — that the SEC has made clear apply fully to how your firm uses AI today.

Investment Advisers Act Rule 206(4)-7 requires every registered investment adviser to adopt and implement written policies and procedures reasonably designed to prevent violations of the Advisers Act. The SEC's position, articulated in multiple examination priority letters and risk alerts, is that AI use without governance controls is a failure of this requirement. If your firm uses AI to support investment decisions, client communications, compliance workflows, or any regulated activity — and you lack written policies governing that use — you have a Rule 206(4)-7 gap.

Rule 204-2 (Books and Records) requires advisers to maintain specific records for defined retention periods. The SEC staff has stated that AI-generated outputs, AI system prompts, and the records of AI-assisted decisions qualify as required records. If your firm is using AI to research securities, draft client communications, or support compliance functions, those interactions may be required records under Rule 204-2 — and must be preserved accordingly.

Investment Advisers Act Section 206 (Anti-Fraud) prohibits any adviser from employing any device, scheme, or artifice to defraud clients. In 2024, the SEC applied this provision directly to AI when it brought its first AI enforcement actions.

The 2024 Enforcement Actions: AI Washing Is a Violation

In March 2024, the SEC settled charges against two investment advisers — Delphia (USA) Inc. and Global Predictions Inc. — in what the agency described as the first-ever AI washing cases.

📌 Important

The SEC's AI washing enforcement actions established a clear precedent: making false or misleading claims about your firm's AI capabilities is a securities law violation, not just a marketing problem. Advisers who overclaim AI sophistication in client materials or Form ADV disclosures face fraud exposure under Section 206.

Delphia claimed in marketing materials that it used client transaction data to train its AI, implying it had a proprietary data advantage that informed its investment process. The SEC found these claims were false — the firm did not use client data in its AI as described. Penalty: $225,000.

Global Predictions claimed to provide "expert AI-driven forecasts" and called itself "the first regulated AI financial adviser." The SEC found the firm made false and misleading statements about its AI capabilities and use of certain predictive models. Penalty: $175,000.

Both settlements required remediation of disclosures and policies. Neither firm's AI was sophisticated enough to justify the claims made — and the SEC treated that gap as fraud.

The implication for every RIA: your Form ADV disclosures, your marketing materials, your website, and your client communications must accurately describe how your firm uses AI — or doesn't use it. Overclaiming is a Section 206 problem. Undisclosing material AI use is also a problem.

SEC Examination Priorities: AI Is on the List

The SEC Division of Examinations published its fiscal year 2026 examination priorities explicitly listing investment adviser AI governance as an area of focus. Specifically, examiners will look at:

  • Whether advisers have adopted written policies governing AI use
  • Whether those policies address supervision of AI-generated outputs
  • Whether firms have appropriate disclosures in Form ADV regarding AI use
  • Whether records requirements are being met for AI-assisted activities
  • Whether compliance programs have been updated to account for AI-specific risks
  • ⚠️ Warning

    The 2026 examination priorities document reflects what experienced examiners will ask about on day one of a review. Firms that have not updated their compliance programs to address AI use will face deficiency letters. Firms that have made material representations about AI in their ADV without supporting infrastructure face enforcement referrals.

    This is not a future concern. SEC examiners are currently visiting firms and asking about AI governance. If your CCO cannot answer basic questions about what AI tools your firm uses, what data flows through them, how outputs are reviewed, and how records are maintained — that is an examination finding in progress.

    What the SEC Expects: The Five Core Requirements

    Based on published guidance, examination priorities, enforcement actions, and SEC staff statements, a defensible AI governance program for an RIA in 2026 addresses five areas:

    1. Written Policies and Procedures

    Your policies must identify every AI tool the firm uses in a business or compliance context. For each tool, the policy must address: who is authorized to use it, what data may be input, what types of decisions it may support, how outputs are reviewed before use, and what documentation is required. A general technology use policy that mentions AI in passing does not satisfy this requirement.

    2. Supervision of AI-Assisted Outputs

    AI tools do not absolve advisers of their supervisory obligations. If an employee uses AI to research a security recommendation, draft a client communication, or support a compliance determination — a supervisor must review the output before it is acted on. That review must be documented. The supervision framework must be written, assigned to specific roles, and tested.

    3. Accurate Disclosure in Form ADV

    Your Form ADV must accurately describe how your firm uses AI. If you use AI to support investment research, that should be disclosed. If you use AI in portfolio construction, that should be disclosed. If you market AI-driven capabilities, those capabilities must be what they appear to be. The SEC's AI washing enforcement actions established that inaccurate AI disclosures are a fraud risk, not just a marketing compliance issue.

    4. Records Retention for AI Interactions

    AI-generated outputs that support investment decisions or client communications are records under Rule 204-2. Your records management system must capture and retain those outputs — along with sufficient context to reconstruct the basis for the decision — for the applicable retention period (generally three years for most records, five years for certain records, with the first two years in an accessible location).

    5. Vendor Oversight for Third-Party AI

    Most RIAs are not building their own AI tools. They are using third-party platforms — portfolio management systems, CRM tools, research platforms — that have embedded AI features. Each of those vendors is a service provider who may be processing client data. Your vendor oversight policies must address AI-specific risks: what data is being processed by the vendor's AI, under what terms of service, and whether those terms are compatible with your regulatory obligations.

    The Disclosure Trap Most RIAs Miss

    The most common AI governance failure for RIAs is not deliberate overclaiming. It is the gap between what the Form ADV says and what is actually happening in the firm.

    If your ADV says your firm does not use AI — but your analysts are using ChatGPT, your CRM has an AI assistant enabled, or your compliance monitoring tool uses AI to flag anomalies — your ADV disclosure is inaccurate. That inaccuracy is a compliance failure.

    ✅ Action

    The right first step for any RIA is a complete AI inventory: identify every tool in the firm's technology stack that uses artificial intelligence, document what data it processes and what decisions it supports, then compare that inventory against your current ADV disclosure. Close the gaps before the examiner does.

    The SEC does not require advisers to avoid using AI. It requires advisers to govern their AI use and disclose it accurately. Firms that have done the inventory, written the policies, and updated their ADV are in a defensible position. Firms that have not are accumulating examination risk with every month that passes.

    What a Technically Enforced SEC AI Governance Program Looks Like

    Written policies are necessary but not sufficient. The SEC expects evidence of implementation — not just documentation of intent. A defensible program has three layers working together:

    Governance layer: Written policies, supervision procedures, disclosure review, and a compliance calendar that includes AI policy updates as regulatory guidance evolves.

    Technical layer: Controls that enforce the policies — approved AI tool lists enforced at the network level, data loss prevention rules that prevent client data from reaching unauthorized AI platforms, audit logs that capture AI interactions for records purposes.

    Evidence layer: Retained records that demonstrate the governance and technical controls are operating as described — examination-ready documentation that examiners can review in the first 24 hours of a visit.

    Firms that rely solely on the governance layer — policies without technical enforcement — will struggle in examinations because they cannot demonstrate that employees are actually following the policies. The CB Financial Form 8-K filed in May 2026 is the clearest available illustration of what happens when policies exist but technical controls are absent: one employee, one unauthorized AI tool, one SEC disclosure.

    🔗 Related Service: AI Governance Program

    Centience builds and operates SEC-ready AI governance programs for registered investment advisers — technically enforced, not just documented.

    Learn More →

    Orville Matias, Founder and CEO of Centience

    Article written by

    Orville Matias

    Orville Matias is Founder & CEO of Centience, an AI and Technology Governance firm for regulated industries. He has 20+ years of experience building and operating compliance programs for organizations under SEC, FINRA, and HIPAA oversight.

    Frequently Asked Questions

    Ready to Build a Defensible Governance Program?

    Centience delivers AI and technology governance built on managed infrastructure — enforceable, not just documented.

    Get Your Free Governance Score