AI Outran Your Policy. Now What?

The SEC's 2026 examination priorities single out artificial intelligence, cybersecurity, privacy, and compliance program effectiveness, putting firms on notice that AI oversight is now a core exam focus. As artificial intelligence becomes more deeply embedded in investment management, operations, marketing, and client service, firms are under increasing pressure to ensure that their use of AI is controlled and managed. The real question is not whether a firm permits AI use, but whether it has built the governance, IT controls, and practical procedures that make that use safe, consistent, and compliant.

For many firms, AI adoption has outpaced the development of formal oversight. Employees may already be turning to public tools like Grok, ChatGPT, Claude, and Gemini to draft communications, summarize documents, generate ideas, or assist with internal workflows, often without clear guardrails, creating risk across confidentiality, accuracy, recordkeeping, vendor oversight, supervision, and disclosures.

The SEC's Division of Examinations has specifically flagged AI-related risk and the accuracy of AI-capability representations as a 2026 priority, and examiners will assess whether firms' policies and procedures are adequate for supervising AI use in fraud prevention, back-office operations, AML, and trading. FINRA's 2026 oversight themes reinforce the same expectations: enterprise-level governance, testing and monitoring, accurate disclosures, cybersecurity, data governance, and training. Given this level of scrutiny, firms should consider whether their AI governance framework includes each of the following:  

  • A policy alone will not hold up in practice.

    • An effective AI governance program rests on three parts: a foundational use policy, supporting procedures, and IT controls that make the policy operational. Without procedures, access restrictions, monitoring, approval workflows, and training, a well-written policy may read well but fail when tested.

  • Programs need to address a defined set of minimum elements.

    • At minimum, firms should document how employees may use AI, what uses are prohibited, what data may never be entered into an external tool, and which business functions require pre-approval or heightened review. The program should also define who oversees it, how incidents are escalated, how vendors are reviewed, and how the firm documents its own compliance with these standards.

  • IT controls carry as much weight as the written policy.

    • Access controls, logging, data loss prevention tools, prompt restrictions, approved enterprise platforms, and audit trails help ensure that AI use aligns with the firm's broader risk management culture and regulatory obligations. Written rules without operational controls behind them are unlikely to satisfy examiners.

  • Output accuracy deserves the same scrutiny as any other advice or marketing content.

    • Firms using AI to support advice, marketing, research, or operational decision-making should be able to show that the output is reviewed, validated, and consistent with disclosures and supervision requirements, particularly where AI-generated content reaches client-facing materials or performance discussions.

  • Training has to go beyond how to use the tool.

    • Employees should understand not only how to use approved AI tools, but why certain uses are restricted, what confidentiality obligations apply, and when human review is required. Regulators are increasingly testing whether training is meaningful and whether supervisors can actually monitor the tools their teams are using.

  • A gap analysis is the practical starting point.

    • Firms building or updating a program should identify where AI is already being used, whether current policies address those use cases, whether existing IT controls are adequate, and whether procedures for approval, escalation, testing, and oversight are clearly documented. Where the firm relies on third-party tools or service providers, vendor due diligence should be updated to reflect AI-specific risks.

AI governance should be treated as an extension of a firm's broader compliance and technology-risk framework, not a standalone initiative. Firms that build effective use policies, strengthen IT controls, and align supervision with real-world usage will be better positioned as expectations continue to evolve. What will distinguish a thoughtful AI program from a merely aspirational one is a working governance model: clear standards, real controls, trained personnel, and ongoing oversight.

Next
Next

Inside the SEC Exam Room: What CCG is Seeing