● For financial advisors
AI for Financial Advisors on Long Island: What SEC and FINRA Actually Require
There is no SEC or FINRA rule written for AI. There are rules that already decide how an advisory firm can use it, and most of them come down to one question: where your clients’ information goes. Here is what they actually say, from the documents themselves.
- Published
- Reading
- 10 min
- Sources
- 11 cited
- By
- Long Island AI
In short
- 01There is no SEC or FINRA rule written specifically for AI. The SEC withdrew its 2023 AI-related proposal in June 2025, and FINRA says its rules are technology neutral.[8][9]
- 02The rules that apply are the ones you already have, and the sharpest is Regulation S-P, whose amendments now require written oversight of any service provider that touches customer information.[3]
- 03Advisers based in New York with $25 million or more under management generally register with the SEC, so this covers most Long Island advisory firms of any size.[1]
- 04Where an AI tool sends client data is a compliance decision, not an IT detail. So is how you describe the tool to clients.[6][7]
First: who regulates your firm’s AI use
If you are an investment adviser with your principal office on Long Island, the New York Attorney General’s guidance is that firms with a principal place of business in New York must register with the SEC once they have $25 million or more in assets under management.[1] That is lower than in most states. SEC staff explain why: New York is the only state where a “mid-sized” adviser ($25 million to $100 million) is not subject to examination by the state securities authority, so those advisers register with the SEC instead.[2]
The practical upshot:
- SEC-registered advisers answer to the SEC’s rules, including Regulation S-P.[3]
- Broker-dealers and their registered representatives are also subject to FINRA’s rules. Dually registered firms deal with both.
- Smaller, state-registered advisers are regulated in New York by the Attorney General’s office. The Regulation S-P amendments discussed below apply to SEC-registered advisers, so a state-registered firm should confirm its own obligations with compliance counsel.[1][3]
There is no AI rule. That is not the same as no rules.
In August 2023, the SEC published proposed rules on “Conflicts of Interest Associated with the Use of Predictive Data Analytics by Broker-Dealers and Investment Advisers,” aimed at certain interactions between firms and investors through the firms’ use of predictive data analytics. By a notice dated June 12, 2025, the Commission withdrew that proposal along with 13 others, including its proposed cybersecurity risk management rules for advisers. “The Commission does not intend to issue final rules with respect to these proposals,” the notice says, and if it acts in those areas again, it will issue a new proposed rule.[8]
FINRA has taken the same line from the other direction. Its Regulatory Notice 24-09, published June 27, 2024, reminds member firms that its rules, “which are intended to be technology neutral,” continue to apply when firms use generative AI, “just as they apply when member firms use any other technology or tool.”[9] The notice says it does not create new requirements. It also says the rules apply whether a firm builds its own tool or uses a third party’s, “including through embedded features in existing third-party products.”[9] That last point matters: the AI feature your CRM or email platform switched on last year counts.
Regulation S-P: the rule that governs your AI vendors
On May 16, 2024, the SEC adopted amendments to Regulation S-P, the privacy rule it first adopted in 2000, to address the expanded use of technology and the risks that have come with it.[3] They apply to broker-dealers, funding portals, investment companies, SEC-registered investment advisers, and registered transfer agents.[3] The amendments require:
- a written incident response program reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information;[3]
- notice to affected individuals as soon as practicable, and no later than 30 days, after you become aware that their sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization;[3]
- written policies requiring oversight of service providers, including making sure they protect customer information and notify you as soon as possible, and no later than 72 hours, after becoming aware of a breach that gave someone unauthorized access to a customer information system they maintain;[3] and
- written records documenting compliance.[3]
Larger entities, which for advisers means those with more than $1.5 billion in assets under management, had to comply by December 3, 2025. Everyone else had until June 3, 2026.[3][5] Both dates have passed. These obligations are in force now.
Why this is really an AI rule
The amended rule defines a service provider broadly:
Service provider means any person or entity that receives, maintains, processes, or otherwise is permitted access to customer information through its provision of services directly to a covered institution.
Apply that to the AI tools advisers are adopting. A meeting note-taker that records and transcribes client reviews, a chatbot on your website that takes account questions, an assistant that drafts emails from your CRM: if the company behind it receives, processes, or has access to customer information through the service it provides you, it fits the definition. Each one needs to be inside your oversight policies, with an answer to the 72-hour question.
Examiners intend to check. The SEC’s Division of Examinations lists Regulation S-P among its fiscal year 2026 priorities, with focus on firms’ “policies and procedures, internal controls, oversight of third-party vendors, and governance practices,” and says that after the compliance dates it will examine whether firms have developed, implemented, and maintained policies under the rule’s new provisions.[6]
What examiners say they will look at on AI
The same priorities document addresses AI directly. The Division says it will:
- “review for accuracy registrant representations regarding their AI capabilities or AI”;[6]
- assess whether firms have “adequate policies and procedures to monitor and/or supervise their use of AI technologies,” including for fraud prevention and detection, back-office operations, anti-money laundering, and trading functions, as applicable;[6] and
- look at the training and security controls firms use to identify and mitigate new risks associated with AI, as part of its cybersecurity review.[6]
One honest caveat: the priorities document says it represents the views of the Division’s staff, is not a rule, and has no legal force.[6] It is, however, a clear statement of what an examiner is likely to ask you about.
Don’t overstate it
The SEC has already brought cases over AI claims. On March 18, 2024, it announced settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions Inc., for false and misleading statements about their use of AI; the firms agreed to pay $225,000 and $175,000 in civil penalties.[7] According to the SEC, Delphia claimed AI and machine learning capabilities it did not have, and Global Predictions falsely called itself the “first regulated AI financial advisor.” Both were also charged under the Marketing Rule.[7]
The lesson for a small firm is simple. If you mention AI on your website, in your Form ADV, or in a pitch, describe exactly what it does and doesn’t do. “We use an AI tool to draft meeting summaries, which an adviser reviews” is a defensible sentence. “AI-powered portfolio intelligence” probably isn’t, unless you can show it.
If you are also FINRA-registered
For broker-dealers and their representatives, Notice 24-09 points to two rules in particular. Under Rule 3110 (Supervision), a firm using generative AI as part of its supervisory system, for example to review electronic correspondence, should have policies that address technology governance, including model risk management, data privacy and integrity, and the reliability and accuracy of the model.[9] And the content standards of Rule 2210 (Communications with the Public) apply whether a communication is generated by a person or a technology tool.[9]
FINRA’s 2026 Annual Regulatory Oversight Report, published in December 2025, adds a section on generative AI. It reports that the most common use among member firms is “Summarization and Information Extraction,” and lists what firms may want to consider, including testing for privacy, integrity, reliability, and accuracy, and ongoing monitoring that may include “storing prompt and output logs for accountability and troubleshooting” and “tracking which model version was used and when.”[10] In the same report, its suggested practices for third-party vendors include assessing each vendor’s use of generative AI, adding contract language that prohibits firm or customer sensitive information from being ingested into a vendor’s open-source generative AI tool, keeping an inventory of the data types vendors access or store, and having vendors return or destroy firm data when a contract ends.[10]
Change may be coming on the communications side. In Regulatory Notice 26-14, dated July 9, 2026, FINRA requested comment on a proposal to modernize Rule 2210, citing advances in generative AI among its reasons; it would replace the principal pre-use approval requirement for retail communications with risk-based supervision standards.[11] Comments were due September 11, 2026, and it remains a proposal. The notice is explicit that the content standards would not change, and repeats that members “are responsible for their communications, regardless of whether they are generated by a human or AI technology.”[11]
Where the data lives is the compliance question
Put the pieces together and a pattern shows up. The SEC’s rule is about who holds customer information and how you oversee them. FINRA’s suggested practices are about what vendors do with your data and whether you can see what the model did. Both point at the same design decision: where the AI runs, and where client information goes when someone uses it.
That is the reason we build AI that runs on hardware a practice owns or controls. When the model itself runs on your systems, the AI step doesn’t add another company receiving client records on its servers, and the prompt and output logs FINRA describes can stay with you. It removes one category of vendor risk for that work.
It does not make the rest disappear, and we would rather say so here than in an exam:
- Anyone you give access to the system, including the firm that installs and supports it, can still be a service provider under Regulation S-P’s definition. Your oversight policies should cover us like anyone else.
- You still need written policies, supervision, and testing of how the tool is used.
- Your marketing has to describe it accurately.
- Your recordkeeping obligations don’t change because a model drafted the message.
As our homepage puts it, no software makes a practice compliant on its own. You can read the rest of those straight answers, or see what a first job looks like for financial advisors and accountants.
Questions to ask any AI vendor, including us
- Does our clients’ information leave our systems? If so, where is it stored, and who at your company can access it?
- Is anything we put in used to train or improve a model, ours or anyone else’s?
- Will you commit in writing to notify us within 72 hours of a breach affecting a customer information system you maintain?
- Can we export prompt and output logs, with the model version used?
- Which other companies (your own vendors) touch our data?
- What happens to our data, and your access, when the contract ends?
Short answers.
- Is there an SEC rule specifically about AI for investment advisers?
- No. The SEC's 2023 proposal on conflicts of interest from predictive data analytics was withdrawn by a notice dated June 12, 2025, and FINRA says its rules are technology neutral. Existing obligations, including Regulation S-P, the Marketing Rule, and supervision and recordkeeping rules, apply to AI use.
- Does Regulation S-P apply to a Long Island advisory firm?
- It applies to SEC-registered investment advisers. According to the New York Attorney General, firms with a principal place of business in New York must register with the SEC once they have $25 million or more in assets under management. The 2024 amendments took effect for smaller entities on June 3, 2026, and for larger entities on December 3, 2025.
- Is an AI note-taker or chatbot company a service provider under Regulation S-P?
- If it receives, maintains, processes, or is otherwise permitted access to customer information through services it provides directly to your firm, it meets the amended rule's definition of a service provider. Your written policies must provide for oversight of it, including notification within 72 hours of a breach of a customer information system it maintains.
- Can an advisory firm say it uses AI in its marketing?
- Yes, if the statements are accurate. The SEC's Division of Examinations says it will review registrants' representations about their AI capabilities for accuracy, and in March 2024 the SEC settled charges against two advisers for false and misleading claims about their use of AI.
Sources
Every factual claim above points to one of these, and each was checked against the source itself, not a summary of it.
- [1]Investment Advisers FAQOffice of the New York State Attorney General · Accessed October 9, 2026
- [2]Division of Investment Management: Frequently Asked Questions Regarding Mid-Sized AdvisersU.S. Securities and Exchange Commission · Last reviewed June 30, 2017
- [3]Enhancements to Regulation S-P: A Small Entity Compliance GuideU.S. Securities and Exchange Commission · 2024
- [4]Regulation S-P: Privacy of Consumer Financial Information and Safeguarding Customer Information (final rule, Release No. 34-100155; IA-6604)U.S. Securities and Exchange Commission · May 16, 2024
- [5]Regulation S-P Amendments: Compliance Deadline Approaching for “Smaller Entities”Holland & Knight · May 7, 2026
- [6]Examination Priorities: Fiscal Year 2026U.S. Securities and Exchange Commission, Division of Examinations · Fiscal year 2026
- [7]SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial IntelligenceU.S. Securities and Exchange Commission · March 18, 2024
- [8]Withdrawal of Proposed Regulatory Actions (Release No. 33-11377; IA-6885)U.S. Securities and Exchange Commission · June 12, 2025
- [9]Regulatory Notice 24-09: FINRA Reminds Members of Regulatory Obligations When Using Generative Artificial Intelligence and Large Language ModelsFINRA · June 27, 2024
- [10]2026 FINRA Annual Regulatory Oversight ReportFINRA · December 2025
- [11]Regulatory Notice 26-14: FINRA Requests Comment on Proposed Changes to Modernize Rule 2210 (Communications with the Public)FINRA · July 9, 2026