Published on: August 25, 2026 · Author: Zach Carothers · Reviewed by the TorchLight SOC · Reading time: 5 minutes
The SEC does not have an “AI Rule.” It still wants you to prove you are governing AI.
This week we are focused on Wealth Management & Investment Firms, but our lesson is far more broad. If you are in a Credit Union, Healthcare, Education, or Government, AI Governance is becoming a true focal point of cyber risk. Artificial intelligence has moved into RIA operations faster than many compliance programs have adapted.
Employees are using AI for research, writing and meeting summaries, vendors are adding AI features to existing software, and marketing teams are experimenting with AI-assisted content. In parallel, investment and compliance platforms are also becoming more automated.
And the SEC is paying attention.
There is still no standalone SEC rule requiring RIAs to maintain a specific AI policy or committee. In fact, the Commission withdrew its proposed predictive-data-analytics rules in June 2025.
But AI is explicitly included in the SEC’s 2026 Examination Priorities.
Examiners may review whether firms have adequate policies and procedures to monitor and supervise AI, and whether public claims about AI match what the technology actually does.
For RIA executives, the question can be more complicated than it needs to be:
If an examiner asked how AI is being governed inside your firm, what could you show them?
The Existing Rules Still Apply
AI may be new, but the regulatory framework around it is not.
RIAs are still subject to requirements covering:
- Compliance policies and procedures
- Marketing and advertising claims
- Fiduciary duties
- Client privacy
- Vendor oversight
- Cybersecurity and data protection
Regulation S-P is especially relevant. Both compliance deadlines have now passed, including the June 3, 2026 deadline for smaller covered firms.
That means firms should already have stronger safeguards around customer information and service providers.
AI simply creates another place where sensitive data can travel.
We covered the broader Reg S-P requirements in The Reg S-P Clock Ran Out: Then The Breaches Began.
AI Washing Was the Warning Shot
The SEC has already taken action against advisers over AI claims.
In 2024, Delphia and Global Predictions settled SEC charges involving false or misleading statements about their use of artificial intelligence, where the firms paid a combined $400,000 in civil penalties.
The lesson should be obvious.
If your firm says it is “AI-powered,” “AI-driven,” or using proprietary AI to improve investment decisions, those claims need to match reality.
AI marketing is still marketing.
The Bigger Risk May Be Shadow AI
The harder problem may be AI use leadership cannot see.
- An employee pastes client information into a public AI tool.
- A team starts using an AI meeting assistant.
- A browser extension gets installed.
- A CRM vendor quietly adds generative AI.
- A research platform introduces an AI feature during an update.
None of this requires bad intentions, it simply happens faster than traditional compliance and procurement processes can react.
Before a Registered Investment Advisor (RIA), Wealth Manager or Investment Firm can govern AI, leadership needs to know:
- What systems are using AI?
- What information can they access?
- Which vendors are involved?
- Who is responsible for approving and supervising their use?
For RIAs and wealth managers, this is increasingly part of the broader technology-governance challenge addressed through TorchLight’s wealth management and investment services.
Client Data Changes the Risk
There is a major difference between asking AI to summarize a public market report and asking it to summarize a client’s tax return or portfolio information.
The technology may be the same, but the risk definitely is not.
RIAs need clear rules for:
- Which AI systems are approved
- What information employees may enter
- Which vendors can handle sensitive data
- When human review is required
This becomes even more difficult when AI is built into software the firm already uses.
The question is no longer just:
Which AI tools did we buy?
It is:
Where has AI entered our technology environment?
What RIA Executives Should Do Now
Good AI governance does not require a massive new bureaucracy.
You just need to start with the basics.
- Build an inventory. Identify AI tools, embedded AI features and known employee use.
- Set data boundaries. Define what information may and may not be entered into AI systems.
- Assign ownership. Someone needs authority to approve tools and investigate exceptions.
- Review vendors. AI platforms handling sensitive information belong in the firm’s vendor-risk process.
- Keep evidence. Document approvals, training, exceptions and significant governance decisions.
For firms that need help translating regulatory expectations into technical controls, TorchLight’s Professional Security Services can help connect cybersecurity, compliance and executive oversight.
The Question That Matters
Imagine an examiner asked tomorrow:
Show us where your firm uses AI, what information those systems can access, who approved them and how you supervise their use.
Could your team answer?
That is the real AI-readiness test.
The SEC has not created one sweeping AI regulation for RIAs, but the direction is clear.
Firms need to understand where AI is operating, what risks it creates, who owns those risks and whether they can prove that appropriate oversight is actually happening.
Their goal is not to halt AI adoption, it is to make sure AI does not spread through the organization faster than leadership can govern it.
About TorchLight
TorchLight is a Secured & Managed IT provider focused on making cybersecurity an enabler of every next opportunity. Our team delivers 24×7 monitoring, detection and response, virtual CISO services, and incident response for regulated mid-market organizations. Our tagline: Risk Aligned. Reward Defined.
Sources
- SEC: Division of Examinations Announces 2026 Priorities
- SEC: SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence (March 18, 2024)
- SEC: Conflicts of Interest Associated with the Use of Predictive Data Analytics by Broker-Dealers and Investment Advisers (withdrawn June 2025)
- SEC: SEC Adopts Rule Amendments to Regulation S-P (May 16, 2024)
- Dechert: SEC Withdraws Significant Number of Rule Proposals (June 2025)
- Goodwin: 2026 SEC Exam Priorities for Registered Investment Advisers and Registered Investment Companies (December 2025)
- Mayer Brown: Securities and Exchange Commission Brings First Enforcement Actions Over “AI-Washing” (April 2024)
Frequently Asked Questions
No standalone rule requires every RIA to maintain a document specifically called an AI policy. However, firms still need policies and controls appropriate to how they actually use AI.
No. What matters is clear ownership and demonstrable oversight.
Build an inventory. Know what AI is already being used before writing new policies around it.

