Marketing Agency Case Study Cover

How RIAs Use and Manage AI

A guide for RIA principals who need an answer ready before an examiner or a buyer asks for one

Your firm has probably adopted AI faster than you’ve learned how to manage it. However, AI governance made the SEC’s exam priority list for RIAs in 2026 and examiners expect you to manage AI use in your firm. This guide shows you where AI touches client data at a firm like yours, and where that exposure is easiest to miss. 

Where AI Security Breaks Down First

The guide breaks AI exposure into three sources: client trust, contract and regulatory obligations, and unapproved tools. The third one is usually the biggest blind spot. Staff paste client names and account data into a personal ChatGPT or Claude account to move faster on a proposal or an email — not out of malice, just to get the job done. That data lands in a tool your firm never approved, can’t see, and can’t account for if a client or an examiner asks. Reid Johnston, Teal’s cofounder, calls that the shadow AI test: never approved, can’t see it, can’t account for it. Fail any one of the three, and it’s shadow AI. 

What's Inside

  • How RIAs are using AI 
  • The three sources of AI risk inside a typical advisory firm 
  • What the SEC’s 2026 exam priorities and Reg S-P actually require from firms your size 
  • A four-step process to manage AI from our CITO 

About the Author

Written by Reid Johnston, Teal’s cofounder and Chief Intelligent Transformation Officer (CITO). Reid has more than 25 years of experience guiding small and midmarket businesses through technology transformation, with a focus on AI consulting, automation engineering, and cybersecurity. 

Teal has more than 25 years supporting regulated industries, holds CMMC Level 2 certification, is one of the first 62 Registered Provider Organizations in the country, and is CompTIA Trustmark+ accredited. 

 

Download your copy today before an examiner or a buyer asks questions you don’t have answers for.