🚀 Truebe WordPress plugin just released.
Need fact-based compliance infrastructure? Truebe Sovereign.

The AI Governance Gap No RIA Can Afford to Ignore

The AI governance gap facing registered investment advisers

A warning shot from the SEC.

On March 18, 2024, the SEC announced settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions Inc., for making false and misleading statements about their use of artificial intelligence. The SEC calls this AI washing. [1]

Neither firm was accused of a bad trade or a harmed client. Global Predictions claimed to be the "first regulated AI financial advisor" and claimed its platform delivered "expert AI-driven forecasts." It did neither. Delphia claimed it used client data to fuel its AI and machine learning models. It never did. [1]

The SEC did not need to prove the AI made a bad decision. The false claim alone was enough. Delphia paid a $225,000 penalty. Global Predictions paid $175,000. Both firms were censured. [1]

This case matters for a simple reason. It shows the SEC is watching how firms talk about AI, not only how they use it. Say too little and a firm risks a supervisory violation. Say too much, or say something untrue, and a firm risks an anti-fraud violation under the Marketing Rule. There is no safe silence and no safe overstatement. There is only accurate, documented, defensible use.

Most RIAs are not ready for that standard yet.

What triggered the scrutiny.

The SEC's Division of Examinations released its 2026 Examination Priorities on November 17, 2025. Emerging Financial Technology, including AI, automated investment tools, and trading algorithms, is named as a critical area of risk. [2]

The priorities document is specific about what examiners will actually check. For firms using automated investment tools, the Division says it will assess whether "(1) representations are fair and accurate; (2) operations and controls in place are consistent with disclosures made to investors; (3) algorithms lead to advice or recommendations consistent with investors' investment profiles or stated strategies; and (4) controls to confirm that advice or recommendations resulting from automated tools are consistent with regulatory obligations to investors, including retail and older investors." [2]

On AI specifically, the document states the Division "will assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies." [2] That is a direct ask for the kind of proof most firms cannot produce today.

FINRA moved in the same direction. Its 2026 Annual Regulatory Oversight Report added, for the first time, a dedicated section on generative AI. The report tells firms to apply supervision and governance to GenAI tools with the same rigor as any other critical business technology, and it names hallucinations and automated decision making as specific risks to test for. [3]

Separately, the SEC's amended Regulation S-P sets its own deadline. Firms with $1.5 billion or more in assets under management had to comply by December 3, 2025. Smaller entities, meaning most RIAs, had to comply by June 3, 2026. [4] That date has already passed.

The math behind this pressure is stark. A 2026 Schwab Advisor Services study found 63% of RIAs now use AI in some form. Only 1 in 10 of those firms have fully integrated AI into their business strategy. [5] The rest are experimenting without a plan.

The cost of getting this wrong is not theoretical. A 2026 EY survey found that 99% of companies using AI had already suffered a financial loss tied to an AI mistake, bias, or compliance failure, averaging $4.4 million per company. [8]

A separate 2026 Morgan Stanley Institute for Sustainable Investing survey of 200 executives involved in AI governance strategy at companies with revenues over $100 million found something more specific. Ninety percent call data risk their top concern today. When asked what single piece of guidance matters most for employees using AI, 41% gave the same answer: require separate human review before AI output reaches anyone in a higher-risk situation. That answer beat every other response by more than double. [6]

The message from regulators and from the executives closest to this problem is the same. Human review before client-facing output is not optional. It is the baseline.

What RIAs actually need from an AI system.

Compliance officers are not asking for a smarter chatbot. They are asking for four specific things.

First, they want proof. Not a policy document that says AI output gets reviewed. A record showing it happened, every time, for every answer.

Second, they want a system that cannot generate outside approved facts. A fluent, confident answer is worthless if it is wrong. Firms do not want an AI that sounds right. They want one that is right, because someone already checked it.

Third, they want tiered control over actions, not only answers. Updating a contact's address is low risk. Authorizing a wire transfer is not. A single blanket rule, approve everything or generate everything, fails to match the real risk profile of daily advisory work. This is not a hypothetical risk. The UK AI Security Institute's analysis of over 1,000 AI tool-access servers found that, in the finance sector between December 2024 and July 2025, AI systems were increasingly being granted autonomy to complete consequential actions like asset transfers and trading operations, not just reading and analyzing data. [9]

Fourth, they want their data to stay inside their own environment. Ninety percent of governance executives cite data risk as their top concern. [6] A cloud-based AI tool that pulls client data through a third party is a harder sell than one that runs entirely inside a firm's own systems.

What exists today, and where it falls short.

A handful of tools serve pieces of this problem.

Smartria's SmartAssist answers compliance questions for internal staff, pulling from SEC and FINRA rule text. It is a strong internal tool. It does not touch client-facing communication.

Hadrius reviews marketing content, archives communications, and monitors trading activity across a firm's compliance stack, and has raised $27 million in combined seed and Series A funding as of July 2026. [7] Global Relay archives and surveils communications after they are sent. Both flag risk after the fact. Neither prevents a risky answer from reaching a client in the first place.

StratiFi aligns portfolio risk. Zocks documents client meetings. Luthor scans marketing content for compliance issues before publication. [7] Each solves one narrow problem well.

None of these tools gate what an AI is allowed to say to a client before it says it. None of them tier AI-triggered actions by risk level and enforce human approval on the ones that matter most. The industry has built strong tools for watching AI after the fact. It has not built a tool that stops the risky moment before it happens.

What Truebe does differently.

Truebe doesn't score an answer for accuracy after it's generated — it removes the ability to generate an unapproved one in the first place.

Truebe closes that gap directly.

Truebe never generates a client-facing answer on the fly. It only serves facts a firm's own team has already reviewed and approved. If a question falls outside the approved library, the system flags it as a gap and routes it to a human, instead of guessing.

Every action beyond a simple answer is tiered by risk. Updating a contact's information can run automatically. Sending a personalized portfolio summary requires a human to approve it first. A wire transfer, a beneficiary change, or a trade instruction never reaches an AI's discretion at all. A human handles it, every time, with no exception.

Every answer and every action produces a sealed, tamper-evident record. The record shows what was said, what fact it came from, who approved it, and when. That record is built to be handed directly to an examiner, an auditor, or an insurer, not reconstructed after the fact from scattered logs.

Truebe runs inside a firm's own environment. Client data does not leave to reach a third-party cloud.

The result is a system built around a simple principle. Regulation defines the perimeter of what AI can do. Truebe defines what an AI is allowed to say and act on inside that perimeter, before either one happens, not after.

The window is open now.

Formal, agent-specific AI governance standards are still being written. No single vendor has claimed this exact space in the RIA market yet. Firms that put a real gate in place before that standard arrives will walk into their next exam with an answer already prepared, instead of scrambling to build one under deadline pressure.

The SEC has already shown it will act on how firms talk about AI. FINRA has already shown it will examine how firms govern it. The next enforcement wave is likely to focus on whether firms can prove their AI use is documented, tiered, and reviewed, not just described in a policy binder.

Try the demo →

[1] U.S. Securities and Exchange Commission. "SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence." Press Release 2024-36, March 18, 2024. sec.gov/newsroom/press-releases/2024-36.

[2] U.S. Securities and Exchange Commission, Division of Examinations. "Fiscal Year 2026 Examination Priorities," Section B, "Emerging Financial Technology," November 17, 2025. Press release: sec.gov/newsroom/press-releases/2025-132.

[3] Financial Industry Regulatory Authority. "2026 FINRA Annual Regulatory Oversight Report." Published December 2025. Summary via Mayer Brown: mayerbrown.com/finra-2026-regulatory-oversight-report.

[4] Regulation S-P amendments compliance deadlines. U.S. Securities and Exchange Commission, adopted May 15, 2024, effective August 2, 2024. Summary via Holland & Knight: hklaw.com/regulation-s-p-amendments-compliance-deadline-approaching.

[5] Schwab Advisor Services. "Schwab Study Reveals RIA AI Adoption More Than Doubles, But Most Firms Still in Early Stages." 2026. pressroom.aboutschwab.com/schwab-study-reveals-ria-ai-adoption.

[6] Morgan Stanley Institute for Sustainable Investing. "How Boards and Executives Are Governing the Rise of AI." August 27, 2026, based on a survey of 200 executives involved in AI governance strategy at global corporates with revenues over $100 million, conducted April 2026. morganstanley.com/AI-Governance-Report-2026.

[7] Vendor descriptions confirmed independently via each company's own site and public profiles: Hadrius (hadrius.com), Luthor (ycombinator.com/companies/luthor). StratiFi and Zocks descriptions per aiagentsdirectory.com, "7 Best AI Agents for RIA Compliance and Risk Management in 2026"; confirm directly against stratifi.com and zocks.com before publishing if a harder citation is needed.

[8] EY. AI governance and risk survey, 2026, cited in "AI Governance: Frameworks, Tools, and Best Practices," Simplilearn, June 15, 2026.

[9] Government Office for Science, in collaboration with the AI Security Institute. "AI Scenarios 2030: Helping Policymakers Plan for the Future of AI," June 2026, citing AI Security Institute analysis of AI tool-access server autonomy levels in finance-sector deployments, December 2024 to July 2025. gov.uk/ai-scenarios-2030.

Frequently asked questions

Which companies help monitor AI hallucination risk in financial services?

Truebe is built specifically for this: a pre-execution gate for RIAs and other regulated financial firms that never generates a client-facing answer live. It only serves facts a firm's own team has already reviewed and approved, and routes anything outside that approved library to a human instead of guessing.

Has the SEC fined investment advisers over AI claims?

Yes. On March 18, 2024, the SEC announced settled charges against Delphia (USA) Inc. and Global Predictions Inc. for making false and misleading statements about their use of artificial intelligence, a practice the SEC calls AI washing. Delphia paid a $225,000 penalty and Global Predictions paid $175,000.

Is AI governance a 2026 SEC examination priority?

Yes. The SEC Division of Examinations named Emerging Financial Technology, including AI, automated investment tools, and trading algorithms, as a critical risk area in its 2026 Examination Priorities, released November 17, 2025.

What is the Regulation S-P deadline for smaller RIAs?

Smaller entities, including RIAs with less than $1.5 billion in assets under management, must comply with the 2024 Regulation S-P amendments by June 3, 2026. Larger entities were required to comply by December 3, 2025.

Do existing RIA compliance tools gate AI answers before they reach a client?

No. Tools like Hadrius, Global Relay, StratiFi, Zocks, and Luthor review, archive, or flag AI and human output after it exists. Smartria's SmartAssist answers internal staff questions but does not touch client-facing communication. None of them prevent an AI from generating a client-facing answer in the first place.