Where We Have Been, Where the Signals Point, and What to Do Before Year-End The […]
AI Ethics in Wealth Management: Where Innovation, Oversight, and Fiduciary Duty Collide

Artificial intelligence has arrived in wealth management not as a future consideration but as a present operational reality. Portfolio construction tools are generating recommendations. Client-facing interfaces are fielding questions. Compliance functions are being filtered through algorithmic screens. And through all of it, the Investment Advisers Act of 1940 remains the governing document; a statute drafted before the transistor, now being asked to govern systems that learn.
The resulting tension is not merely technical. It is philosophical. And it is consequential in ways that many registered investment advisers have yet to fully internalize.
The fiduciary standard that governs RIAs is deceptively simple in its articulation and deceptively complex in its application. Advisers owe clients a duty of care - the obligation to provide advice that is in the client's best interest, grounded in sound information and reasonable analysis - and a duty of loyalty, which requires them to subordinate their own interests and to disclose, or eliminate, material conflicts.
Neither duty contains a carve-out for algorithmic decision-making.
This is not a speculative regulatory interpretation. The SEC has made clear, through both examination guidance and enforcement, that the deployment of AI in advisory operations does not attenuate fiduciary obligations. The Division of Examinations identified AI oversight as a specific focus area in its 2026 Examination Priorities, noting that examiners will assess the accuracy of firms' AI-related disclosures and evaluate whether advisers have implemented written policies and procedures adequate to monitor and supervise AI use, across both investment functions and operational and compliance tasks. Notably, the 2026 priorities integrate AI oversight into nearly every examination category: cybersecurity, emerging technology, automated investment tools, and operational resiliency alike. AI is no longer a stand-alone line item, it is a cross-cutting lens.
What makes this moment particularly acute is the asymmetry between adoption pace and governance maturity. Firms are deploying AI tools at a rate that their compliance infrastructure has not kept pace with; not out of bad faith, but because the tools are available, the competitive pressure is real, and the written rules remain, for now, largely inferred rather than codified.
That inferential gap is precisely where regulatory exposure lives.
There is a persistent and dangerous misconception embedded in the way some firms discuss AI adoption: that deploying a model constitutes a transfer of responsibility.
The SEC has signaled, through both guidance and early enforcement actions, that a failure to ensure the reliability of automated models, and a failure to implement written supervisory policies governing those models, can itself constitute a breach of the fiduciary duty of care. The logic is direct: an adviser who relies on an unvalidated analytical tool, whose outputs it cannot explain and whose methodology it has not reviewed, is no different from an adviser who relies on an unvetted third-party analyst without performing any diligence. The mechanism differs, the obligation does not.
This principle carries specific implications for how firms must approach AI governance as a compliance function, not merely as a technology procurement question. CRC's AI governance and compliance work is built precisely around this distinction: the difference between having an AI tool and having a supervisory framework around it that can withstand examination.
The duty of loyalty presents its own distinct challenge. AI models trained on data that reflects firm economics, or designed to optimize outputs that benefit the adviser, introduce conflicts of interest that are structural rather than situational. A model that systematically nudges clients toward higher-margin products or shorter rebalancing cycles is not a neutral optimizer; it is a conflict embedded in software. The SEC has explicitly identified this risk, noting in now-withdrawn rulemaking that predictive analytics can be used to advance adviser interests at the expense of investor welfare, regardless of whether the adviser intended that outcome. The withdrawal, however, does not eliminate the underlying conflict of interest standards that already apply.
The SEC's March 2024 enforcement actions against Delphia (USA) Inc. and Global Predictions Inc. were the agency's first explicit AI-related charges against registered investment advisers, and they carried a message that had less to do with AI than with disclosure integrity. Both firms had marketed their use of artificial intelligence in their investment processes in ways that were materially false: the AI, as described, did not exist as described. The violations were brought under Sections 206(2) and 206(4) of the Advisers Act, the same antifraud provisions the Commission has used across a generation of enforcement actions. There was no new AI-specific rule required. The existing framework, applied to new facts, was sufficient, and that is a lesson worth sitting with.
The SEC does not need a bespoke AI regulation to pursue AI-related misconduct. The antifraud provisions, the Marketing Rule, and the Compliance Rule collectively cover the terrain. What changes with AI is not the legal standard but the surface area of potential violation. Firms that have embedded AI claims into their Form ADV, their marketing materials, their pitch decks, and their client-facing platforms without ensuring those representations are accurate and substantiated are carrying latent enforcement exposure today, not at some future date when the rules are "finalized."
In December 2025, the SEC's Investor Advisory Committee advanced a recommendation calling for formal guidance requiring issuers and registrants to define their use of AI, disclose board-level oversight mechanisms, and report on material AI deployments, both internally and in client-facing applications. This is not the posture of an agency that has deprioritized the space. It is the posture of an agency building toward more formal requirements by documenting the inadequacy of current disclosure practice.
For RIAs, the parallel to ESG greenwashing enforcement is apt and instructive. The Commission pursued ESG misrepresentation cases not by waiting for ESG disclosure rules to be finalized, but by applying existing antifraud standards to existing marketing claims. The AI enforcement cycle is following the same arc. Firms that learned from the ESG experience have already audited their AI representations for accuracy and substantiation. Those that have not should do so before an examiner does it for them.
CRC’s registered investment adviser compliance consulting services include exactly this kind of proactive audit: reviewing AI-related disclosures across Form ADV, marketing materials, and client communications to identify gaps between what is represented and what is operationally true.
This is where the regulatory conversation must advance beyond its current boundaries.
The dominant discussion of AI in wealth management compliance has centered on disclosure and supervision. Questions focus on whether firms have written policies, whether their marketing is accurate, whether examiners can document what AI tools are being used, etc. These are necessary conditions, but they are not sufficient ones to capture the complete compliance picture.
The more difficult and largely unresolved question is whether an adviser can meet its fiduciary duty of care when the basis for its advice is not fully explicable, either to the client, to the regulator, or even to the adviser itself.
Black-box AI models, systems that produce outputs without surfacing the reasoning behind them, present a structural challenge to the fiduciary framework that existing guidance has not fully confronted. An adviser is required to have a reasonable basis for its recommendations. It is required to know its client and match advice to that client's circumstances. When advice is filtered through or substantially generated by a model whose internal logic the adviser cannot explain, the epistemological foundation of that advice is unclear.
The SEC's 2026 examination priorities sharpen this issue in practical terms: examiners will want to know whether a firm can explain how its AI reached a specific decision. Systems that cannot demonstrate their decision-making process, that cannot produce what amounts to a compliance-auditable rationale, create regulatory risk that no disclosure regime can fully neutralize.
This is not an argument against AI adoption. It is an argument for what CRC refers to as expert-in-the-loop governance: the requirement that human oversight is not merely nominal, but is substantive, documented, and capable of explaining how and why AI outputs were incorporated into client-facing recommendations. The compliance framework around AI has to be able to answer the questions an examiner will ask: Who reviewed this output, what did they review it against, and how do we know the recommendation served the client?
The political and regulatory climate of 2026 has produced a somewhat paradoxical environment for AI governance in financial services. The SEC, under its current leadership, has created an internal AI Task Force and withdrawn the 2023 proposed rule on predictive data analytics conflicts, a rule that would have imposed affirmative conflict-neutralization requirements on AI-driven advisory tools. The posture is, in some ways, more permissive on the rulemaking front.
But permissive rulemaking is not the same as reduced regulatory exposure.
The examination priorities remain demanding. The anti-fraud provisions remain operative. The fiduciary standard is unchanged. What the current environment reflects is not a relaxation of substantive expectations but a shift in the mechanism of enforcement, from prescriptive rulemaking toward principles-based examination and case-by-case action under existing authority. For firms with robust governance programs, this is favorable. For firms that read the withdrawal of the predictive analytics rule as a clearing signal, the reading is incorrect and the consequences of that misreading are not theoretical.
The compliance infrastructure appropriate to this moment is not exotic; it is methodical. Firms that manage this well are doing the following:
CRC works with registered investment advisers at all stages of this process, from initial AI governance framework development, to Form ADV disclosure review, to examination preparation. The work is not speculative; the regulatory expectations are already in the examination priorities, already in the enforcement record, and already being assessed in examinations that are happening now. to examination preparation. The work is not speculative; the regulatory expectations are already in the examination priorities, already in the enforcement record, and already being assessed in examinations that are happening now.
That is its durability and, for the unprepared firm, its challenge.
Artificial intelligence in wealth management is not a compliance problem to be deferred until the rules catch up. The rules, applied with doctrinal consistency to new facts, are already operative. The examination program is already running. The enforcement record is already being built.
What AI introduces is not a new legal standard. It introduces a new set of ways to breach the standard that has always applied, through disclosure that does not match practice, models whose conflicts are structural rather than situational, and automated systems that advise without the fiduciary infrastructure that client relationships require.
The firms that navigate this period well will be those that treat AI governance not as a technology question but as a fiduciary one, and that build the compliance infrastructure around it before they are asked to explain why they did not.
Compliance Risk Concepts provides registered investment adviser regulatory consulting services, including AI governance framework development, Form ADV disclosure review, examination preparation, and ongoing compliance program support. For more information or to schedule a consultation, contact us.
Where We Have Been, Where the Signals Point, and What to Do Before Year-End The […]
There is a comfortable fiction embedded in how most registered investment advisers and broker-dealers think about material nonpublic […]
The recent FinCEN advisory directing financial institutions to detect and report suspicious activity linked to […]
Where We Have Been, Where the Signals Point, and What to Do Before Year-End The […]
There is a comfortable fiction embedded in how most registered investment advisers and broker-dealers think about material nonpublic […]
The recent FinCEN advisory directing financial institutions to detect and report suspicious activity linked to […]