RIAs Should Proceed With Caution When Using AI Tools on Calls With Clients

Paul J. Foley, Kiki Scarff, John M. FaustAdvisor Perspectives welcomes guest contributions. The views presented here do not necessarily represent those of Advisor Perspectives.

The text in this article was originally generated using artificial intelligence. The underlying data, financial arguments, and strategic insights were authenticated by the authors, who retain full accountability for the accuracy of the content.

Summary

Registered investment advisors (RIAs) are increasingly adopting artificial intelligence (AI) tools that automatically transcribe and summarize client calls. While these technologies may offer efficiency gains, they introduce significant legal and compliance risks. This article discusses the intersection of AI transcription tools with state wiretapping laws, privacy considerations, Securities and Exchange Commission (SEC) requirements, and the evolving litigation landscape.

AI-Generated Transcripts and Call Summaries: The New Normal in Advisory Practices?

RIAs have long maintained records of client communications by preparing and storing contemporaneous notes in their customer relationship management (CRM) systems. AI transcription tools have fundamentally altered this practice, enabling platforms to automatically transcribe calls in real time and generate detailed summaries without human intervention.

Although these tools assist advisors, the automated generation of transcripts and summaries creates legal exposure across multiple dimensions, including state wiretapping statutes, privacy concerns, federal securities recordkeeping requirements, and civil litigation discovery. Firms that have adopted these tools without a thorough compliance review, including evaluation by their chief compliance officers (CCOs), may already be in violation of applicable law.

All-Party Consent State Issues: Criminal and Civil Exposure Under State Wiretapping Laws

The legal framework governing telephone recording varies by jurisdiction. While some states follow a one-party consent rule, a significant number require the consent of all relevant parties.

As of the time of publication, these all-party consent jurisdictions include California, Connecticut, Delaware, Florida, Illinois, Maryland, Massachusetts, Michigan (under certain circumstances), Montana, Nevada, New Hampshire, Oregon, Pennsylvania, and Washington.

When an AI tool records a client call, it may constitute an interception under these statutes. If the client has not provided affirmative consent, the advisor may be violating state criminal law and face potential penalties. For example, California Penal Code Section 632 makes unauthorized recording punishable by fines of up to $2,500 per violation and imprisonment, while Florida's statute imposes felony liability. It is important to note that a disclosure buried in an advisory agreement may not suffice.

The patchwork nature of state consent laws compounds the challenge. An RIA headquartered in Texas (a one-party consent state) speaking with a client located in California – even if the client is only there on vacation – may be subject to California law. Determining which law governs a recording requires careful analysis that many RIA firms have not conducted.

Beyond criminal exposure, violations of wiretapping statutes frequently give rise to civil claims for statutory damages, actual damages, and attorneys' fees. In a class action context, exposure could multiply rapidly across an entire client base.