Most conversations about AI in a regulated practice start in the wrong place. Are we allowed to use it. That question has an answer and the answer is not very interesting.
We are not your compliance adviser and none of this is advice. It is a description of published rules with the links attached, so you can hand it to the person who is.
The interesting question is what happens to the document afterwards.
The rule is about the communication, not the tool
For SEC-registered investment advisers, the books and records rule — 17 CFR 275.204-2 — requires, at paragraph (a)(7), "originals of all written communications received and copies of all written communications sent by such investment adviser relating to… any recommendation made or proposed to be made and any advice given or proposed to be given."
Two things in that sentence do work, and they are worth separating. The records are written communications sent or received. And the subject matter reaches advice proposed to be given, not only advice that went out.
Paragraph (e)(1) says those records are kept "in an easily accessible place for a period of not less than five years from the end of the fiscal year during which the last entry was made on such record, the first two years in an appropriate office of the investment adviser."
Now put a draft recommendation in a chat window and ask whether that is a communication sent. We are not going to tell you it plainly is. There is an argument that it is: the text was transmitted to a vendor, which is a recipient nobody at the firm chose. There is an argument that it is not, because it never reached a client or a colleague and remained a draft.
That question is your compliance counsel's to settle rather than ours, and anybody selling you software should be the last person you take it from. What does not depend on the answer is the position it leaves you in: the only copy of something touching client advice is sitting where nobody at the firm knows to look, and the argument about whether it had to be kept happens afterwards.
The failure is not "you used a chatbot". The failure is that the only copy of something lives somewhere your retention system has never heard of.
Supervision, when the tool is doing part of it
FINRA Regulatory Notice 24-09, 27 June 2024, puts it plainly for member firms: "If a firm is using Gen AI tools as part of its supervisory system — for the review of electronic correspondence, for instance — its policies and procedures should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model."
The same notice says its rules apply whether the firm built the tool or is "leveraging the technology of a third party, including through embedded features in existing third-party products."
And that the content standards for communications with the public "apply whether member firms' communications are generated by a human or technology tool." That does not name who signs. It does close off one answer — "a machine wrote it" is not a status the content standards recognise.
Then there is the breach half of it
The amendments to Regulation S-P require covered institutions — broker-dealers, registered investment advisers, funds, funding portals and transfer agents — to run an incident response programme, to notify affected individuals within 30 days in defined circumstances, and to oversee service providers through due diligence and monitoring. Larger entities were in from 3 December 2025; smaller entities from 3 June 2026.
Service provider oversight is the line that lands on this subject. A consumer AI account somebody opened with a firm email address is a service provider nobody selected, contracted with, or monitored.
What we learned about "staff will review it"
Here is our own number, and it is uncomfortable.
We ran 510 measured, timed answers out of a model doing the jobs four of our own specialists actually do. Correct answers had a median response time of 1.20 seconds. Wrong answers had a median of 0.60 seconds.
Correct: median 1.20 seconds.
Wrong: median 0.60 seconds.
The gap is the time it takes to go and look.
The wrong ones were fast because they never checked anything. And one answer came back in six tenths of a second, named the right file, and we counted it as a failure — because six tenths of a second is not enough time to have looked. It happened to be right that day. Nothing about how it arrived would change on the day it was wrong.
Apply that to a practice. "Staff review the output" is not a control if the output arrives faster than a review takes, and it is not a control at all if nothing records that the review happened.
Three questions for any tool
- Where does the text go when it leaves the keyboard, and who else can read it there?
- Where does the output land — in the file, or only in the window?
- Could you produce it in five years without knowing in advance that you would be asked?
What to do
Pick one recent piece of client work that had AI anywhere near it, and answer those three questions about it from the systems you already have. One file, one sitting, and whoever owns the engagement file can have the answers back the same day.
Whatever comes back unanswered is the shape of the gap, and it is usually much narrower than people fear. Most often it is one tool, used by two people, with no route into the file.
The cost of leaving it is reconstruction: establishing, long after the fact and out of records that were never built to answer the question, what a draft said and who approved it.
If the answer to the second question turns out to be "only in the window", that is a plumbing problem rather than a policy one, and it is the kind of thing we build.