
March 2026 Compliance News: AI Use, Marketing Reviews, and Supervision
RIAs are adopting AI tools for research, marketing, operations, surveillance, and client service. March 2026 compliance developments show that regulators are less focused on whether firms use AI and more focused on whether firms supervise it with the same discipline applied to other advisory processes.
AI Governance Needs Clear Ownership
Firms should maintain an inventory of AI-enabled systems and identify whether each tool affects investment advice, portfolio management, trading, client communications, advertising, compliance testing, or operations. The inventory should include the tool owner, vendor, data inputs, permitted uses, prohibited uses, review controls, and documentation requirements.
Compliance should work with business leaders to decide where human review is required. An AI-generated marketing draft, client email, risk summary, or investment rationale may be useful, but the firm remains responsible for accuracy, fairness, disclosure, and recordkeeping. The policy should make that responsibility visible.
Inventory
Track AI tools, users, use cases, data inputs, vendors, and approval status.
Marketing
Review AI-assisted content for claims, testimonials, performance references, and disclosures.
Testing
Sample outputs and document exceptions, approvals, and remediation.
Marketing Review Procedures Should Cover AI Content
Marketing Rule obligations apply regardless of whether content was drafted by a person, an outside agency, or an AI tool. RIAs should review claims about investment process, performance, rankings, testimonials, awards, tax outcomes, planning results, and technology capabilities. Firms should avoid publishing AI-generated statements that sound authoritative but cannot be substantiated.
Compliance teams should update approval workflows so AI-assisted content is labeled internally, reviewed against the same standards as other advertising, and archived with the final approval record. If prompts or generated outputs are needed to explain how content was created, the firm should define how those records are preserved.
Supervision Must Match the Risk
Not every AI use case carries the same risk. A tool that summarizes public regulatory updates may need lighter controls than a tool used to rank clients, draft personalized recommendations, or generate performance commentary. The compliance program should distinguish low, moderate, and high-risk uses and apply controls accordingly.
High-risk uses should generally require documented testing, user training, output review, data restrictions, vendor diligence, and periodic reassessment. Firms should also consider whether client disclosures need updates when AI materially supports advisory services or client communications.
Key Takeaways for RIAs
- Create an AI tool inventory with ownership and permitted use cases.
- Apply Marketing Rule review standards to AI-assisted advertising.
- Keep substantiation for claims created or improved with AI tools.
- Use risk tiers to decide review, testing, and documentation depth.
- Train employees on confidential data, client information, and prohibited prompts.
Modernize AI and marketing supervision
NextReg helps RIAs build practical AI governance, marketing review, and compliance testing workflows.
Schedule a Consultation