In every conversation I have with CCOs right now, AI comes up. And what I still hear, even at this point, is some version of "we haven't really made a decision about AI yet." I understand what people mean by that — the governance framework isn't built, the approved tool list doesn't exist, the policy hasn't been written. From that standpoint, the decision is still pending.


But the question I'd ask is: if your employees can access ChatGPT from any browser on any device, has the firm not made a decision yet? Or has the decision just been made without you?

That gap — between the official policy timeline and the reality of what's already in use — is where most firms' AI compliance exposure lives. Not in the tools they've formally adopted. In the ones they haven't accounted for.

 

What Regulators Are Actually Looking For


Regulators don't have AI-specific rules yet — they're learning too, and working out how they can use AI to be better regulators while also figuring out what they need to do to supervise firms. But compliance officers who are waiting for an AI-specific rulebook before they act are, I think, misreading the situation.

Mostly what regulators are looking for right now is: are you doing something? If an examiner walks into your firm and asks what you're doing on AI, and the answer is that you haven't started, that's going to be a red flag for them to start looking further. They're not necessarily expecting a sophisticated program. They want to see that you're aware of what's happening in your firm and that you've taken some steps.

There's also a wrinkle for firms that have decided to ban AI — and I think this is something compliance officers don't always think through fully. If you're saying your advisors aren't allowed to use AI, you're going to need to show how you're controlling that. How are you ensuring they're not using consumer AI tools on their own? And if you can't answer that, a blanket prohibition may create more compliance exposure than a thoughtful framework would.

 

Mapping to the Rules You Already Have

The best place to start on responsible AI governance is the regulatory framework you're already working within. That's it. You don't need a new set of rules — you need to think about how the existing ones apply.

Think about what framework you're operating under. Whether you're an RIA, a broker-dealer, or duly registered, you have obligations — like a duty of care or duty of loyalty — that don't go away because the tool changed. If you're using AI to help manage a client's account or support an investment decision, you still need to show that you're acting in their best interest and that a qualified person has been in the loop at the right points.

From there, the compliance questions aren't new ones. Is this tool doing what we think it's doing? Are we reviewing AI-generated outputs before they reach clients? If AI is supporting client-facing work, have we assessed whether we need to disclose that? And then there's the books and records question, which is something I think about a lot — AI notetakers are a hot topic right now with regulators, and firms need to be thinking about which parts of those notes constitute records they're required to keep and potentially produce. The last piece is thinking through when an activity needs to be performed by a registered person, and whether AI is crossing that line in any of your workflows.
 

Financial decision making
AI Resources for Advisory Firms

The Compliance Framework You Need to Build Now

Orion's AI Resource Hub brings together governance tools, security guidance, and compliance perspectives for firm leaders navigating AI decisions.

The CCO's Role Has Changed

Something I've noticed in my own practice, and heard from peers, is that the CCO's role in AI governance has become significantly more cross-functional than it was even two years ago. Compliance used to show up at the end — reviewed a finished product and said yes or no. That model doesn't work for AI. By the time you're reviewing a completed AI tool or a fully drafted policy, the important decisions have already been made.

What I've found is that effective governance requires compliance to be at the table while tools are being evaluated and capabilities are being built — before decisions are locked in. At Orion, my team has worked shoulder to shoulder with legal, product development, and security to shape how AI features are designed, not just whether they pass review. That model is harder to sustain, but it produces better outcomes. The guardrails are stronger when they're built in rather than added on.

For CCOs at advisory firms, the implication is similar. Don't wait until your firm's AI adoption is underway to get involved. Be in the room during vendor evaluation. Ask the compliance questions during procurement. The compliance function is most valuable when it shapes decisions, not when it ratifies them.

 

What to Do First

If your firm is in the early stages, the place to start isn't the comprehensive policy. It's the baseline assessment. What tools are employees using today, officially or not? What data are those tools touching? Which use cases create compliance obligations, and which don't?

From that baseline, you can build something specific to your firm — a framework that reflects your actual risk profile, not a generic industry template. Regulators are looking for governance that's thoughtful and specific to how your firm operates. A program built on your own assessment is more defensible than an adopted checklist.

If you start with that baseline — just knowing what's already in use in your firm — you've put yourself so far ahead of where most firms are right now. And you can build from there. The governance framework that gets you through an exam isn't the most sophisticated one. It's the one that's specific to your firm, that shows you understand your own operations, and that you can demonstrate the same. Start there.

Go Deeper on AI Compliance

Your Firm Needs a Baseline Before It Needs a Policy

Whether you're just starting your AI governance program or refining an existing one, Orion's AI Resource Hub is where compliance leaders find what they need.

Mark Audrain is the Chief Compliance Officer of Orion Wealth Management.