What actually constrains an advisory firm at this size, and it is not investment research.
An advisory firm's revenue is a fee applied to assets, and its growth comes from adding relationships without adding advisors in proportion. That single sentence explains most of what is worth automating and most of what is not. Portfolio construction at an $8M to $50M firm is rarely the bottleneck; models come from an investment committee, a turnkey platform, or a small set of decisions made once and reviewed quarterly. The bottleneck is everything that surrounds a relationship, and almost none of it is billable on its own.
Look at where a senior advisor's week actually goes. Preparing for a review meeting means pulling positions from the custodian, performance from the portfolio accounting system, and history from the CRM, then assembling those into something a client can follow. After the meeting somebody has to write what was discussed back into the CRM, open the service items it generated, and chase the ones that stall. Onboarding a household means paperwork that gets returned not in good order more often than anyone admits. Then there is the standing exception list: accounts opened and never funded, beneficiary designations that have not been reviewed since a divorce, distributions that need to happen before a deadline, held-away assets the firm reports on but does not custody.
None of that is advice. All of it is the price of advice, and it scales linearly with household count while the fee schedule does not. A firm that removes half the preparation and note-capture burden from six advisors has not saved a line item; it has changed how many relationships those six people can carry, which is the only lever at this size that moves enterprise value rather than margin. That is the business case, and it is worth stating plainly before any discussion of models, because it also tells you which workflows to leave alone.
It is the same shape we see in the other two professional-services verticals we work in most, which is why the arguments in what actually works for CPA firms and AI for mid-market law firms transfer here with one difference. In an advisory firm, more of the surrounding paperwork is a regulated record by default, which narrows the design space considerably.
Every output worth automating is already a required record, and that is the whole design constraint.
Start with the rule text rather than with a summary of it. Rule 204-2 under the Investment Advisers Act, at paragraph (a)(7), requires an adviser to maintain "Originals of all written communications received and copies of all written communications sent by such investment adviser relating to" a list that begins with "Any recommendation made or proposed to be made and any advice given or proposed to be given." Paragraph (e)(1) sets the horizon: those records are to be "maintained and preserved in an easily accessible place for a period of not less than five years from the end of the fiscal year during which the last entry was made on such record, the first two years in an appropriate office of the investment adviser." The text is on the eCFR at 17 CFR 275.204-2.
Now hold an AI meeting-notes product against that language. It listens to a client review, produces a written summary describing what was discussed and frequently what was recommended, and stores that summary in the vendor's cloud. Whether that specific artifact is a required record is a question for the firm's chief compliance officer and its counsel, and reasonable compliance officers land in different places on it. What is not in dispute is that the artifact is a written thing, generated by the adviser's process, describing advice. The moment a workflow starts producing text like that at volume, the firm has changed the shape of its own recordkeeping surface, usually without a decision ever being taken.
The SEC's own Division of Investment Management concedes the boundary is unclear. In a February 3, 2026 speech, Division Director Brian Daly listed the issues the industry and the regulator have not resolved in twenty years and included this one directly: "Confusion over what electronic communications fall within the Books and Records Rule (or other retention requirements) remains a live topic," adding that "The Books and Records Rule is still reflective of an age when advisers typed client letters that were snail-mailed." Those remarks are published on sec.gov and are the staff's own view rather than the Commission's.
Here is why that unresolved boundary is an architecture problem and not a legal one. If you build so the artifact lands in a system the firm controls, you never have to resolve it. Retention becomes a policy the firm sets and can change. If you buy so the artifact lands in a vendor tenant, you have made the answer depend on someone else's export tooling, someone else's data retention schedule, and someone else's continued existence. Two firms can hold identical legal opinions and end up with completely different exposure, purely because of where the file sits.
The same rule has a second paragraph that matters for anyone letting a model near marketing. Paragraph (a)(11) requires "A copy of each" advertisement, as that term is defined in the Marketing Rule, "that the investment adviser disseminates, directly or indirectly," with advertisements carrying their own five-year clock. A generative tool that lets four people produce prospect-facing copy in an afternoon has multiplied the number of things that have to be captured, reviewed and stored, and the capture step is the one that gets skipped.
Anything that faces a prospect is an advertisement, with a substantiation burden attached.
The Marketing Rule, 17 CFR 275.206(4)-1, defines an advertisement at paragraph (e)(1) as "Any direct or indirect communication an investment adviser makes to more than one person" that "offers the investment adviser's investment advisory services with regard to securities to prospective clients," with narrow carve-outs including extemporaneous live oral communications. The definition is about what the communication does, not about who or what wrote it, so a model drafting the copy changes nothing.
What follows is a list of general prohibitions worth reading in the original, because three of them describe exactly what an unsupervised generative workflow produces. An advertisement may not "Include any untrue statement of a material fact." It may not "Include a material statement of fact that the adviser does not have a reasonable basis for believing it will be able to substantiate upon demand by the Commission." And it may not "Discuss any potential benefits to clients or investors connected with or resulting from the investment adviser's services or methods of operation without providing fair and balanced treatment of any material risks or material limitations associated with the potential benefits." The full text is on the eCFR.
A language model asked to write persuasive copy about an advisory practice will produce benefit language and will not supply the balance unless something in the workflow forces it, because balance is not what persuasive copy optimizes for. It will also produce confident specifics, and specifics are precisely what the substantiation prohibition attaches to. Generation is the cheap half of the problem. Substantiation, review and retention are the expensive half, and they are the half that does not get faster just because drafting did.
Which is why the AI worth buying for an advisory firm's marketing function is usually a review layer rather than a writing layer: something that reads what a human wrote and flags the sentence making an unsubstantiated performance claim, the testimonial missing its disclosure, the benefit paragraph with no balancing statement. That system has an obvious right answer for every flag, a human decides, and the firm ends up with more supervision rather than more output to supervise.
The SEC has already charged advisers over AI, and both cases were about the description.
On March 18, 2024 the Commission announced settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions Inc., "for making false and misleading statements about their purported use of artificial intelligence." The firms paid $400,000 in combined civil penalties, Delphia $225,000 and Global Predictions $175,000. Delphia had claimed, according to the order, that it "put[s] collective data to work to make our artificial intelligence smarter so it can predict which companies and trends are about to make it big and invest in them before everyone else," and the Commission found it did not have the capabilities it claimed. Global Predictions had described itself as the "first regulated AI financial advisor" and advertised "[e]xpert AI-driven forecasts." Both were charged under the Marketing Rule. The press release is on sec.gov.
Notice what is absent from both matters. Neither turned on a model producing a bad recommendation, a client losing money because of an algorithm, or a technical failure of any kind. Both turned on how the firm described its own technology in materials that reached prospective clients. Then-Chair Gary Gensler put it in one line: "Investment advisers should not mislead the public by saying they are using an AI model when they are not."
The practical consequence for a firm scoping its first system is unglamorous and cheap. Before anything is built, write down in plain language what the system will actually do, and make that description the only one anybody is allowed to use externally. The gap that produces an enforcement problem is almost never between the technology and reality. It is between the technology and the sentence a marketing consultant wrote about it eighteen months later, when nobody remembered the original scope. That is a governance artifact rather than a technical one, and it belongs with the small set of decisions described in AI governance without an enterprise budget.
The off-channel cases are the precedent that should shape your architecture, not the AI headlines.
The most instructive enforcement pattern for an advisory firm buying AI has nothing to do with AI. On January 13, 2025 the SEC announced charges against nine investment advisers and three broker-dealers "for failures by the firms and their personnel to maintain and preserve electronic communications," with combined civil penalties of $63.1 million. The firms admitted the facts. The orders describe personnel using unapproved communication methods, and the Commission noted the failures "involved personnel at multiple levels of authority, including supervisors and senior managers." One firm that self-reported paid $600,000 where its peers paid eight and eleven and twelve million. The press release lists every firm and penalty, and it is the latest in a sequence of these actions running back several years.
Read that as a structural lesson rather than a story about texting. In every one of those matters, a communications channel existed that the firm's capture layer could not see. Nobody decided to evade recordkeeping. People used a convenient tool, the tool sat outside the archive, and years later the gap was an admitted violation with a number attached.
An AI assistant is a new channel with exactly that shape. Staff paste client circumstances into a prompt box and get back text about what to do. Those prompts and outputs are communications about advice, they live in a vendor's system, and most firms have no idea how many exist or how to retrieve them. Whether they are records is for counsel. Whether you could produce them is a question of architecture, and only one of those two is inside the firm's control. Assume that within the next examination cycle somebody will ask.
The diligence that closes this gap is the same diligence any system touching client data deserves, and it is worth running before the vendor call rather than during it. We wrote the question list out in full in the security and data questions to ask before an AI build: where each record rests, who controls each resting place, and what the system can do rather than merely see.
What the fiscal year 2026 examination text actually asks for, in the regulator's own words.
The Division of Examinations publishes its priorities annually, and the fiscal year 2026 document is the clearest available statement of what an examiner will ask an adviser about AI. It carries a disclaimer worth repeating: it represents the views of the staff, "has no legal force or effect," and "creates no new or additional obligations for any person." It is a map of attention rather than a rule.
Under the heading Emerging Financial Technology, the Division writes that it "remains focused on registrants' use of certain products and services, such as automated investment tools, AI technologies, and trading algorithms or platforms, and the risks associated with the use of emerging technologies and alternative sources of data." Reviews assess, among other things, "whether: (1) representations are fair and accurate; (2) operations and controls in place are consistent with disclosures made to investors."
Then the sentence that should shape a firm's policy: "With respect to AI, the Division will focus on recent advancements in AI and will review for accuracy registrant representations regarding their AI capabilities or AI. The Division will assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies, including for tasks related to fraud prevention and detection, back-office operations, anti-money laundering (AML), and trading functions, as applicable." The full document is a PDF on sec.gov.
Two words in that passage do more work than the rest. The first is "representations," which lands in the same place the 2024 orders did: the firm's description of its own AI is an examined item. The second is "back-office operations." The supervision expectation is not scoped to investment decisions. A tool that only writes meeting summaries and only touches internal process is squarely inside the sentence, which quietly removes the most common internal argument for skipping a written procedure, that the tool does not touch advice.
The same document treats AI as a security matter too, noting focus on "training and security controls that firms are employing to identify and mitigate new risks associated with artificial intelligence (AI) and polymorphic malware attacks." Firms that scoped AI purely as a productivity project tend to have nothing written for that question at all.
No AI rule is coming to settle this, because the proposal was withdrawn.
A number of firms are running a strategy of waiting for regulatory clarity before committing to anything. It is worth knowing that the event they are waiting for was formally cancelled. In August 2023 the Commission proposed rules addressing "certain interactions between broker-dealers or investment advisers and investors through these firms' use of predictive data analytics." In 2025 it withdrew that proposal along with thirteen others, stating plainly that "The Commission does not intend to issue final rules with respect to these proposals. If the Commission decides to pursue future regulatory action in any of these areas, it will issue a new proposed rule." The withdrawal notice is Release No. 33-11377.
From the other direction, the Division of Investment Management is asking firms to move. In the same February 2026 speech, Daly said the feedback from industry surveys, direct outreach and the Examinations Division "is that adoption is still uneven and often tentative," that "the greatest impediment to a more widespread adoption of AI is liability concerns," and that those concerns "should not be insurmountable obstacles." He went further and invited firms in: "if you have ideas, if you want to explore a pilot program, if you would like to request a no-action letter or staff guidance, come talk to us."
So the honest state of play is that the existing rules already govern the conduct, the regulator has said what it will examine, and the thing that is missing is a separate rulebook explaining exactly how. Waiting for that rulebook is a plan with no completion date. It is also, in our experience, rarely the real reason a firm has not started. The real reason is that nobody has been asked to name one workflow and go find out, which is a different problem with a much cheaper fix, and the design that forces an answer is laid out in how to run a pilot that produces a decision.
Where AI pays inside an advisory firm, ranked by how little judgment it touches.
The ranking that survives contact with a compliance department is by judgment, not by enthusiasm. Start at the bottom of the judgment scale and work up only as far as the firm's supervision can follow.
Meeting preparation is first. Every input already exists in a system of record: positions at the custodian, performance in portfolio accounting, history and open items in the CRM, planning assumptions in the planning tool. Assembly is mechanical, tedious, and currently done by a person with a licence or by an associate who could be doing something harder. The output is a document a human reads before anything happens, so a wrong number is caught at the desk rather than in front of a client.
Note capture and CRM write-back is second, and it is the workflow that most obviously wants to be built rather than bought, for the reasons above. The value is not transcription. The value is that the structured items inside the conversation, the follow-ups, the changes in circumstance, the things that trigger a service ticket, land in the firm's system as data instead of sitting in a paragraph nobody re-reads.
Service request triage is third: reading inbound client email, classifying it, routing it, and drafting a status reply for a human to send. Fourth is completeness checking on account opening and transfer paperwork, where the model is comparing a document against a checklist rather than exercising discretion, and where the payoff is the return-not-in-good-order rate, a number the operations lead can already quote from memory.
Fifth is exception surfacing, which is a query problem wearing an AI costume: accounts opened and never funded, beneficiary designations untouched for years, distributions with deadlines approaching, cash balances outside policy. Most firms run this as a quarterly manual sweep because building the query across three systems was never anybody's project. Sixth is internal knowledge retrieval over the firm's own material, its procedures, its investment policy statement templates, its custodian workflows, so a newer associate can ask a question in plain language instead of interrupting someone senior.
What every one of those has in common is that the model never makes a recommendation. That single property is what keeps them inside the supervisory framework the firm already operates rather than requiring it to invent a new one, and it is the reason this list is short and boring. We have not put a number on any of these, deliberately. We do not hold an audited panel of advisory firms, and any figure we quoted would be a number we made up.
What we would decline to build, and the reason is commercial rather than moral.
Four things, and each is a refusal because the failure mode is an examination finding rather than a bug ticket, which means it lands on the client long after the invoice is paid.
Anything that sends a recommendation to a client without a named human approving that specific output. Not a policy that says a human reviews recommendations; a mechanism that will not transmit until somebody has clicked, with the click recorded. The difference between those two is the entire difference between a supervised process and a described one.
Anything that writes performance figures into client-facing material without a source-linked path back to the system that produced them. The substantiation prohibition is unforgiving, and a number whose provenance nobody can reconstruct is a liability whether it is right or wrong.
Any system whose only copy of a client communication lives in a vendor tenant. If the firm's retention answer depends on a third party's export feature continuing to exist, the firm does not have a retention answer.
And any system described to clients in language the firm cannot demonstrate is accurate. That is the Delphia lesson applied prospectively, and it costs nothing to honor at the start and a great deal to correct after the language has been on a website for two years.
Buy it or commission it, and the deciding question is who can produce the record.
Buy when the need is genuinely a commodity and the artifact is disposable. A ten-person firm that wants transcription plus a CRM sync should buy that. It is a solved problem, several products do it competently, and commissioning a build would be the wrong instrument at many times the price. We will say that on a diagnosis call, and we would rather say it than sell around it.
Commission when one of three things is true. The workflow crosses systems no single vendor spans, which describes most advisory operations stacks the moment the custodian, the portfolio accounting system and the CRM all have to agree. The firm's own procedures encode the logic, so a generic product would require the firm to adapt its process to the software rather than the reverse. Or the output is an artifact the firm may have to produce years after the fact, which is where this vertical differs from most.
The deciding question is not capability, because on capability the products often win. It is who can produce the record. A subscription tool holds your client-communication artifacts inside a tenant you do not control, on export terms the vendor wrote and can revise, with a retention answer that changes if the vendor is acquired or your contract lapses. A commissioned system runs inside the firm's own cloud environment and the firm receives the source code at handoff, so the retention answer is set by the firm's own policy and outlives every vendor relationship. That distinction is irrelevant for a transcript nobody will ever request and decisive for anything describing advice given to a client. The general form of the argument is in why code handoff matters and the build versus buy decision; what is specific to advisory firms is that the regulator has already told you the artifact matters.
There is a cost dimension too, and it runs the opposite way to intuition. Per-seat AI pricing scales with headcount while the work it removes does not, which is the arithmetic worked through in the real cost of off-the-shelf AI at scale. A firm adding advisors is adding subscription cost on exactly the axis it was trying to make cheaper.
How to scope the first system, in the week before anybody gets a call.
Five steps, and none of them require a vendor or a budget.
Name one workflow rather than a category. Not "AI for client service." Something like: preparing the quarterly review packet for a household with three accounts and an outside 401(k). A named workflow can be measured, argued about and scoped. A category can only be discussed.
List every artifact that workflow produces, then mark each one as a record, an advertisement, or neither. This takes an operations lead and a compliance officer about an hour, and it is the step that almost nobody does. It is also the step that determines the architecture, because every artifact in the first two columns has a retention answer that has to hold for five years and a location that has to be under the firm's control.
Ask your CCO the retention question for each marked artifact before you evaluate a single product. Not "is this allowed," which invites a defensive no. Ask: if we produce this artifact, where does your policy say it has to live and for how long. That reframes the conversation from permission to specification, and compliance officers are considerably better at specification.
Measure the current cycle while the tool still does not exist. How long the workflow takes, how often it comes back for a fix, how many times a licensed person touches it. Two weeks of manual counting is enough, and it cannot be reconstructed later. Whether the underlying inputs are even in a usable state is the subject of data readiness for one named workflow.
Only then look at tools, and evaluate them against the artifact list rather than the demo. The product that wins a demo and the product that survives an examination are frequently not the same product, and the artifact list is what separates them.
If you would rather have the first two steps done for you, the AI Maturity Index gets you to a single named workflow and establishes whether its output is something a person reads or something written into a record, which is the fact everything else here turns on. If you want to see how a commission actually runs before committing to one, the process is written out, along with the fee bands. And if you are weighing outside help against an internal hire, the checklist in how to choose an AI consultant applies to this vertical without modification.
One local note, since a large share of the firms we sit across from are within an hour of Boston: nothing in this memo is Massachusetts-specific, because the rules cited are federal and the operating problem is the same wherever the firm happens to be registered. What is local is only who we talk to, which is the backdrop to AI automation for Massachusetts mid-market operators, and the reason this memo exists at all.
Everything above is general information about how the rules shape system design. It is not legal or compliance advice, and none of it substitutes for your own counsel and CCO reading the same rule text against your own facts.