Advisor Perspectives welcomes guest contributions. The views presented here do not necessarily represent those of Advisor Perspectives.
I have spent the last 10 years building AI and data systems for regulated industries — financial services, healthcare, and insurance — and watching smart people make the same mistake: evaluating AI by asking what it can produce, rather than what happens when a regulator asks where that output came from. One firm I worked with made this mistake, caught it before it became a violation, and rebuilt its approach in a way I think every RIA should study.
The firm was a midsize wealth management shop with a few billion in AUM and a compliance team of three people drowning in review work. Like a lot of firms this year, it wanted an AI assistant, and wanted it fast.
The firm’s first instinct — the instinct almost everyone starts with — was to buy one general-purpose assistant and point it at everything: drafting client emails, summarizing meeting notes, monitoring accounts for suitability flags, and even helping prep for SEC exams. One brain, every job. It felt efficient. It felt modern.
When a General Model Crosses the Line
The team used the AI assistant for about six weeks before the compliance officer caught something that stopped the rollout cold. The assistant generated a client account summary that blended details from two different households — same last name, different account numbers, similar portfolios. Nothing malicious, no breach in the technical sense. Just a retrieval error, the kind of thing that happens when a single model holds broad access to a shared pool of client data and no hard wall separates one household's records from another's.
The advisor caught it before it went out. But the compliance officer asked the question that mattered: If we hadn't caught it, could we explain to an examiner why it happened? No one in the room could answer that.
That's the moment the firm's thinking changed, and it's the point I want you to consider. A hallucinated summary or a crossed-wire retrieval isn't a productivity hiccup you patch and move past.
This type of error is a fiduciary event waiting to happen, because your obligation isn't just to give the client accurate information — it's to be able to show, on demand, exactly where every piece of information in an output came from and who could have touched it. A general-purpose assistant, by design, doesn't think in those terms. It thinks in terms of getting the task done.
Architecting for Compliance & Verification
The firm rebuilt its system around a different premise: No single agent gets to do everything. It split the work into four distinct functions: One agent monitored accounts for compliance flags, one drafted client-facing communications, one summarized meetings and calls, and one ran source verification before anything reached a human.
Each client's data sat behind its own walled-off partition at the infrastructure level, not just a permissions setting inside one shared model. Critically, every output carried a citation back to the specific document, transcript, or data field it came from, so an advisor could verify it in seconds rather than blindly trusting it.
The firm also didn't flip every switch at once, and this is the part most firms skip. The team started with the lowest-stakes function — meeting summarization, where an error is embarrassing but not compliance-relevant — and ran it for months before touching anything closer to suitability or exam prep. Trust in the architecture had to be earned function by function, not assumed on day one because the demo looked good.
Substantiating Claims to Regulators
I think about that sequence every time a client asks me how fast they can move. The honest answer is: as fast as your compliance program can defend, not as fast as the technology allows.
The SEC's Marketing Rule (17 CFR 275.206(4)-1, adopted December 2020) already puts the burden of substantiation on the firm for any claim it makes to a client — and an AI-generated summary is a claim. If you can't trace it, you can't substantiate it, and if you can't substantiate it, it doesn't matter how good the model is.
Ask your vendor one question before you sign anything: When something goes wrong, can you show me exactly where it came from? If the response is vague, you already have your answer.
The firms I see succeeding with AI right now aren't the ones with the flashiest assistants. They're the ones whose compliance officers helped design the architecture instead of it being handed over after the fact. That single change — inviting compliance into the build, not just the review — is the difference between an AI program you can defend and one you're hoping no one ever questions.
Deb Misra is the CEO and founder of Engineersmind, a New Jersey-based AI and data engineering firm serving financial services, healthcare, and enterprise clients since 2016. With over two decades of experience building intelligent systems for regulated industries, Deb leads a team focused on translating AI capability into practical, compliant business outcomes.
A message from Advisor Perspectives and VettaFi: Discover something new! Click here to register for our upcoming webcasts.
More Wealth Management Topics >