In every conversation I have with CCOs right now, AI comes up. And what I still hear, even at this point, is some version of "we haven't really made a decision about AI yet." I understand what people mean by that — the governance framework isn't built, the approved tool list doesn't exist, the policy hasn't been written. From that standpoint, the decision is still pending.
But the question I'd ask is: if your employees can access ChatGPT from any browser on any device, has the firm not made a decision yet? Or has the decision just been made without you?
That gap — between the official policy timeline and the reality of what's already in use — is where most firms' AI compliance exposure lives. Not in the tools they've formally adopted. In the ones they haven't accounted for.
What Regulators Are Actually Looking For
Regulators don't have AI-specific rules yet — they're learning too, and working out how they can use AI to be better regulators while also figuring out what they need to do to supervise firms. But compliance officers who are waiting for an AI-specific rulebook before they act are, I think, misreading the situation.
Mostly what regulators are looking for right now is: are you doing something? If an examiner walks into your firm and asks what you're doing on AI, and the answer is that you haven't started, that's going to be a red flag for them to start looking further. They're not necessarily expecting a sophisticated program. They want to see that you're aware of what's happening in your firm and that you've taken some steps.
There's also a wrinkle for firms that have decided to ban AI — and I think this is something compliance officers don't always think through fully. If you're saying your advisors aren't allowed to use AI, you're going to need to show how you're controlling that. How are you ensuring they're not using consumer AI tools on their own? And if you can't answer that, a blanket prohibition may create more compliance exposure than a thoughtful framework would.
Mapping to the Rules You Already Have
The best place to start on responsible AI governance is the regulatory framework you're already working within. That's it. You don't need a new set of rules — you need to think about how the existing ones apply.
Think about what framework you're operating under. Whether you're an RIA, a broker-dealer, or duly registered, you have obligations — like a duty of care or duty of loyalty — that don't go away because the tool changed. If you're using AI to help manage a client's account or support an investment decision, you still need to show that you're acting in their best interest and that a qualified person has been in the loop at the right points.
From there, the compliance questions aren't new ones. Is this tool doing what we think it's doing? Are we reviewing AI-generated outputs before they reach clients? If AI is supporting client-facing work, have we assessed whether we need to disclose that? And then there's the books and records question, which is something I think about a lot — AI notetakers are a hot topic right now with regulators, and firms need to be thinking about which parts of those notes constitute records they're required to keep and potentially produce. The last piece is thinking through when an activity needs to be performed by a registered person, and whether AI is crossing that line in any of your workflows.