Nobody Wrote an AI Rule for Your Firm. They Did Not Need To.


In July 2023 the SEC proposed a rule that would have governed how advisers and broker-dealers use predictive data analytics, a category written broadly enough to cover AI. In June 2025 the Commission formally withdrew it. There is, today, no SEC rule about artificial intelligence.
It would be easy to read that as a gap. It is closer to the opposite.
The obligations that already govern client information at your firm were written to be indifferent to technology. They do not list approved software. They describe what you owe regardless of what tool is in front of the person, and AI did not arrive with an exemption.
What your firm already owes
Strip the frameworks down and the same four obligations appear in every one of them.
Know where client information is. Not roughly. Specifically enough to write it down.
Control who can reach it. The right people, the right systems, nothing broader than the job requires.
Be able to reconstruct what happened. Records, supervision, an answer to who did what, and when.
Vet anyone you hand it to. Due diligence before, monitoring after.
None of those four sentences mentions a technology. That is the point. They applied to the fax machine, they applied to cloud storage, and they apply to an AI tool an employee opened in a browser tab this morning.
The rule that already covers this went live while nobody was looking
The SEC amended Regulation S-P in May 2024. The amendments carry a requirement that reads, in the Commission's own words, that covered institutions must establish, maintain, and enforce written policies and procedures reasonably designed to require oversight, including through due diligence and monitoring, of service providers.
Two things about that sentence deserve a moment.
The first is who it covers. Covered institutions means SEC-registered investment advisers, broker-dealers, investment companies, and transfer agents. If you are reading this, it almost certainly means you.
The second is when it started. The compliance date for larger entities was December 3, 2025. For everyone else it was June 3, 2026. Both dates have passed. This is not a deadline approaching. It is an obligation your firm has been carrying for months.
The amendments also require that service providers notify you as soon as possible, and no later than 72 hours, after they become aware of a breach, and that you notify affected customers within 30 days.
The SEC's own examination priorities for this fiscal year say the Division will examine whether firms have developed, implemented, and maintained policies and procedures in accordance with the rule's new provisions.
The part that has no equivalent in your industry
Here is where financial services is in a harder position than healthcare, and most firms have not noticed.
A medical practice that wants to use an AI tool with patient information can ask the vendor for a Business Associate Agreement. It is a named document. The vendor either signs it or does not, and the answer is checkable in an afternoon.
Financial services has no such instrument. None of the major AI vendors offers a named agreement for SEC or FINRA obligations. What is available is a standard commercial data processing addendum and a commitment not to train on your data, on paid business tiers.
Which means the obligation does not transfer anywhere. Reg S-P puts the due diligence and monitoring squarely on your firm, and there is no counterparty document that discharges it for you.
The vendor terms themselves also differ in ways worth knowing, and the differences run along account type rather than brand.
On consumer accounts at several major providers, conversations can be used for model training unless the individual user finds the setting and turns it off. On paid business and enterprise tiers that default is reversed. And a personal login gets consumer terms no matter what the firm pays for elsewhere: the firm's enterprise agreement covers the firm's accounts, not the employee's own.
The practical version: the same tool, used by the same person on the same laptop, sits under completely different terms depending on which account is signed in. That distinction is invisible from the outside, and it is exactly the distinction Reg S-P expects you to have policies about.
What is actually happening inside firms
In a Schwab Advisor Services study published in January 2026, surveying 533 independent registered investment advisers, 63 percent said their firm uses AI tools, more than double the 2023 figure.
The detail underneath it is the one that matters. Among the advisers using AI, 82 percent rely on generative AI tools, and the study found that use happens most often through individual experimentation rather than firm-wide systems.
Read that as an operations sentence rather than a technology one. In most firms that use AI, the way it gets used is that individual people decide individually.
A separate 2026 survey of 2,906 advisory professionals found 52 percent using search or generative AI tools, up from 41 percent a year earlier, while only about 22 percent of firms reported using any of the dedicated cybersecurity tools the survey tracks. Adoption is running well ahead of the controls around it.
What it costs when it goes wrong
IBM's 2026 Cost of a Data Breach report puts the average breach in financial services at $6.29 million, the second highest of any industry behind healthcare, and up from $5.56 million the year before.
From the same report, and this figure is across all industries rather than financial services alone: employee use of unapproved AI tools was involved in 43 percent of security incidents in 2026, up from 20 percent the year before. It more than doubled in a year.
Two things we are not going to claim
No regulator has brought an enforcement action against a financial firm for staff putting client data into a public AI tool. Not the SEC, not FINRA, not a state regulator, as of August 2026. If a vendor tells you the fines are already landing, ask them for the case number.
That absence does not mean the conduct is unregulated. It means the enforcement has not caught up to the practice. The safeguards rule already covers it, and for broker-dealers so does the supervision rule.
And the AI cases the SEC has brought are about something else entirely. Delphia, Global Predictions, and Rimar Capital were all penalized for overstating AI capabilities they did not have. That is a marketing problem, not a data problem. Useful to know, but it is not this.
Where a firm actually starts
Not with a policy. With a list.
Every one of the four obligations at the top of this article fails the same way. You cannot control access to a system you do not know an employee is using. You cannot produce records of activity you never captured. You cannot run due diligence on a vendor you do not know you have.
An inventory is not a fifth control to add. It is the thing the other four already assume you have.
So the order runs:
Find out what is in use. Every AI application, browser extension, and connected agent across your machines, and which account each one is signed into.
Sort it. Some will be legitimate work that deserves a sanctioned path on a firm account. Some will be client information sitting in a personal login, and that stops.
Then write the rules, naming specific tools rather than categories, because no client data in public AI tools is unenforceable when nobody can say which tools count.
Then keep looking, because an inventory taken once describes a single Tuesday.
Where we fit, and where we do not
We are a managed security provider. We are not a compliance consultancy, we do not write your policies and procedures, we do not perform your risk assessment, and we do not certify anything. Be wary of a security vendor who offers to.
What we run is the layer those documents assume is already working. Our Managed AI Security service starts with a free Shadow AI Discovery: a light install, about a week of quiet observation, then a report of every AI tool, extension, and agent in use across your machines, including which are running on personal accounts, risk ranked in plain English. Nothing changes for your staff while it runs, and the report is yours whatever you do next.
After that we enforce what you decide, on the tools you approve, and keep watching as new ones appear.
None of this guarantees compliance and no honest vendor would say otherwise. It supports obligations your firm already carries, and it answers the one question those obligations cannot be met without.
More on how this looks for advisory firms specifically: cybersecurity for financial advisors.
The question worth asking this week
Not do we have an AI policy. Ask instead: if an examiner asked which AI tools touch client information here, and on whose accounts, could we answer with a document rather than a guess?
Most firms cannot yet. That is a solvable problem, and it starts with looking.
If you run a small or medium financial firm in Washington DC, Northern Virginia, or Maryland and want a plain-English read on where you stand, book a free 15-minute call.
Comments