
July 2026 Compliance News: New SEC Guidance on AI Use by RIAs
Mid-year 2026 has brought fresh SEC signals on how registered investment advisers should govern their use of artificial intelligence. The message is consistent with earlier examination priorities but sharper on documentation, disclosure, and vendor accountability. RIAs relying on AI for client-facing recommendations, marketing, research, or operations should treat July as a checkpoint, not a summer slowdown.
What the New Guidance Emphasizes
Recent staff statements and enforcement actions point in the same direction. Regulators expect firms using AI to inventory every model in use, describe the business purpose of each, identify who owns it, and document how outputs are reviewed before they reach a client. The SEC is not asking firms to stop using AI. It is asking firms to prove that AI use is supervised.
Advisers should also expect scrutiny of AI-generated marketing content, chat interfaces, meeting summarizers, and research assistants. If the tool touches client communications, examiners will want to see the approval workflow, the retention path for the generated content, and the disclosures made to clients about how AI contributed to the output.
Model Inventory
Maintain a living inventory of every AI tool, its owner, its purpose, and its data inputs.
Human Review
Document the human-in-the-loop step for anything reaching clients, prospects, or regulators.
Disclosure
Align Form ADV, brochures, and marketing pages with how AI actually supports the service.
Model Validation and Testing Expectations
The updated guidance reinforces that adopting a third-party AI tool does not transfer responsibility. Advisers still own the outputs. Firms should keep evidence of pre-deployment testing, sample-based review of live outputs, and periodic revalidation when the vendor updates the underlying model. Where the model is used to draft client communications or summarize meetings, testing should confirm accuracy, completeness, and absence of fabricated facts.
Recordkeeping matters as much as testing. If a model output was corrected before delivery, the correction should be traceable. If a model was replaced or retrained, the change should be dated and documented so that reviewers can reconstruct which version produced which output.
Vendor and Third-Party AI Oversight
Most RIAs consume AI through vendors, and the SEC has flagged vendor oversight as a persistent gap. Firms should refresh due diligence files for AI providers with attention to data handling, training data provenance, security certifications, subprocessors, model change management, and the vendor's own testing practices. Contracts should address the adviser's audit rights, incident notification, and the vendor's obligation to disclose material model changes.
When vendor answers are thin, firms should compensate with tighter controls on how the tool is used internally, including narrower use cases, mandatory human review, and enhanced client disclosure.
Disclosure Alignment
Form ADV and client-facing materials should describe AI use in plain language. Firms that market personalization, proprietary insights, or algorithmic advantages should back those statements with documentation. Where AI plays a role in advice, communications, or research, disclosures should describe the role honestly, note the limitations, and identify the safeguards.
Key Takeaways for RIAs
- Stand up or refresh an AI model inventory with named owners and business purposes.
- Document pre-deployment testing and ongoing review for every model touching clients.
- Refresh vendor due diligence files with AI-specific questions and evidence.
- Align Form ADV and marketing language with how AI is actually used today.
- Retain corrected outputs, prompt logs, and model version history where practical.
Need help operationalizing AI governance?
NextReg helps RIAs build AI inventories, testing workpapers, vendor files, and disclosure updates that hold up in an SEC exam.
Schedule a Consultation