How RIAs Should Manage AI Use in 2026 & 2027 

Managing AI as a registered investment advisor (RIA) really comes down to just four things:  

  • Knowing what tools your staff are using 
  • Having a plain-language policy 
  • Naming someone to own the vendor review process 
  • Keeping a record showing a human checked the work before it was used for business purposes  

I have this conversation with RIA and wealth management clients almost every week now, and it usually starts with someone on the team already using AI, whether the firm approved it or not. 

However, RIAs don’t need a legal treatise to get this right. They need a process they’ll keep up with, because the tools change every few months and your policy needs to keep up. In this article, we’ll look at how RIAs are using AI to be more profitable as well as the best way to manage its use to reduce risk. 

Key Takeaways

  • Most RIAs use AI, but very few have connected it to the systems that hold client data. 
  • The SEC named AI oversight a 2026 examination priority, and it applies to small advisory firms. 
  • Your risk isn’t malicious use. It’s employees trying to work faster with a tool nobody vetted. 
  • You need a program you’ll actually keep up with that includes an accurate inventory, a plain-language policy, a named reviewer, and a paper trail. 

Table of Contents

How RIAs Are Using AI Right Now

Most RIAs are using AI in some form in 2026. A recent Orion survey revealed that 73% of advisors now use AI tools – which reflects what I’ve been seeing. Generally speaking, I’ve seen our RIA and wealth management clients use AI the most in:  

Meeting notes and summaries.  

Advisors record client meetings and let AI turn the transcript into a summary with next steps, instead of typing it up by hand. That saves a ton of time. 

Drafting client communication.

Newsletters, blog posts, and outreach get a first draft from AI, then a person edits it before it goes to a client. That editing step matters more than the drafting step.

Sales and segmentation.

Advisors point AI at their CRM or spreadsheet data to sort clients by assets, geography, or whatever criteria they’re working from. I do a version of this myself, across our own client base, all the time. 

Early back-office reporting.

A few firms are starting to connect AI to accounting and reporting tools to reconcile accounts or build dashboards. Most software already has decent native reporting, so this one’s still early.

Somebody asked me recently if AI could replace the Monte Carlo retirement-planning software they already pay for. Honestly, I haven’t seen a client do that yet, but I think some of those niche software vendors are going to feel pressure as AI closes that gap. 

Why AI isn't Being Connected to Core RIA Systems…Yet

The short answer is trust.

According to a Schwab study, only about one in ten RIAs have fully integrated AI into their business strategy. And 82% of RIA use is based solely on individual experimentation. Governance, or proper use, of AI is the biggest concern.

There are a lot of concerns about letting AI touch the business data that lives in CRM and billing systems. AI introduces risks around client data that RIAs just don’t know how to navigate. 

Most of our clients use Microsoft, so they’re using Copilot Chat in Microsoft 365. It’s free, and it comes with the enterprise data protection that Microsoft includes as part of that service.  

I also hear, anecdotally, that people are using ChatGPT or Claude on the side. But that’s not unique to RIAs. We see that type of behavior in nearly every regulated industry we work with.  

What The SEC Expects from RIAs on AI in 2026

The SEC’s 2026 Examination Priorities name AI oversight, under “emerging financial technology,” as a focus area. This applies to smaller advisory firms too.  

Under the Emerging Financial Technology section, it states that: 

  • Examiners are watching how firms use automated investment tools, AI, trading algorithms, and outside or “alternative” data sources. 
  • If your firm offers automated advice or recommendations, you can expect scrutiny on whether what you’ve told clients matches what the tool actually does. 
  • They’ll check whether your algorithms produce advice that fits each client’s actual investment profile and stated strategy. 
  • They want to see controls that catch it if an automated recommendation conflicts with your regulatory obligations, especially to retail and older investors. 
  • They’re assessing whether you have policies and supervision for how AI gets used across fraud detection, back-office work, trading, and – where it applies to your firm – anti-money laundering tasks. 
  • Reviews will also look at whether you’re using regulatory technology to automate compliance work and run more efficiently. 

Examiners expect RIAs to inventory AI use across the firm, including tools used by affiliates and outside service providers, and to keep written policies and records for at least five years. 

ai risk

3 Sources of AI Risk

These sources of risk are rarely malicious. People are just trying to do their job faster, better, smarter. They include: 

1. Client trust exposure.

When sensitive client data goes into a tool that wasn’t built to protect it. 

2. Contract and regulatory exposure.

When your obligations to clients or regulators are violated by how a tool is used, even unintentionally. 

3. Unapproved tool exposure.

When employees sign up for free accounts on ChatGPT, Claude, or similar tools on their own, because the firm hasn’t given them a sanctioned option yet. 

When I’m walking a client through evaluating their risk, I boil it down to three questions:  

  • Did you approve this tool?  
  • Can you see what it’s doing with your data?  
  • Is it covered by your policy, and did someone review what it produced? 

If the answer to any of those is no, that’s where you need to start. 

Remember, free AI tools are free because your data acts as the payment. Those companies use what you type in to improve their product, unless you’re on a plan built for business use.  

Most employees using ChatGPT.com or a free Claude account on the side don’t realize that. Education is genuinely the first step here, well before you even get to the technology controls.

Manage AI at Your RIA in Four Steps

Here’s the four-step version I walk clients through, and it’s in alignment up with what NIST’s AI Risk Management Framework calls the “govern” function:  

1. Inventory what's already in use.

Talk to your staff about where they’re going for AI, not just what’s installed on their laptops. As an MSP, we can see the software on a client’s machines, but anyone can visit any website. You need to know which of those tools have an AI component. 

2. Write a policy in plain language.

One to two pages, not fifteen. Everyone on staff should be able to read it and know what’s allowed and what isn’t. Review it more often than you’d review a typical policy. We review most policies annually, but AI is moving faster than that, so plan on revisiting this one every six months. 

3. Name who owns vendor review.

Someone specific needs to be accountable for reviewing the AI tools and vendors your firm uses, on a set schedule, not “whoever gets to it.” 

4. Document human review.

When something gets produced with AI, keep a record showing a person reviewed it before it went out. My cofounder and I built the outline for a recent client virtual event using Claude, and it got us most of the way there, but I still went back through and fixed things it didn’t get right before we presented it. Human in the loop isn’t a slogan. It’s the part of the process that catches what the AI got wrong. 

 

Pro tip: If you’re wondering where to start, start with the inventory. You need to understand the lay of the land before you can write a policy that actually matches what your team is doing. 

How RIAs Use and Manage AI Mockup

Most RIA firms have adopted AI faster than they’ve built a way to manage it. Use this guide to explore uses, risks, and the four steps you can use to close the gap.

Managing AI The Right Way Protects Your RIA's Growth

AI is expanding the capabilities of the RIAs and wealth management firms I work with. The firms getting value out of it are the ones treating management and security as a part of the rollout.

If you want a gut check on where your firm stands, an inventory and a plain-language policy are the two things I’d tackle first.  

Our AI consulting and automation engineering services are perfect for firms that don’t have the IT capacity to map everything out or implement the necessary policies.

Our team can build everything you need, provide training, and help you build the workflows that will grow your business. Reach out if you’re interested in speaking with me about how our team can help.  

Reid Johnston

Reid Johnston is the cofounder and Chief Intelligent Transformation Officer of Teal, with over 25 years of experience guiding small and mid-sized businesses through technology transformation. He specializes in end-to-end IT strategy, AI consulting, automation engineering, Microsoft 365, and Copilot deployment for organizations investing in technology-driven growth. His work turns those investments into measurable business results for IT leaders and executives.

Latest Teal News
Recent Articles

Join Leading Execs to See What's Next in IT

Thousands of executives already get invited to live virtual events for straight talk on AI, M365, cybersecurity, compliance, and automation. Sign up today. 

Categories
Our Most-read Articles This Month

KEEP EXPLORING