# What AI Disclosure Requirements Apply to Financial Advisers in 2026?

Olivia Watson · September 20, 2026

> Direct answer for 2026 As of 21 September 2026, no single United States rule requires every AI financial adviser to display the same universal...

## Direct answer for 2026

As of 21 September 2026, no single United States rule requires every AI financial adviser to display the same universal disclaimer. The practical answer is that disclosure is usually required when AI affects a client-facing recommendation, communication, data use, performance claim, or conflict, while the exact wording and timing depend on SEC, state, FINRA, privacy, and consumer-protection duties. A broker-dealer registered with FINRA may also face different obligations from an SEC-registered investment adviser, even when both use the same software.

**Also worth reading:** [How do AI compliance tools help financial advisors meet regulatory requirements in 2026?](https://cashcache.co/knowledge/how_do_ai_compliance_tools_help_financial_advisors_meet_regulatory_requirements_in_2026.php) · [What are agentic AI governance frameworks and how do they apply to financial advisory?](https://cashcache.co/knowledge/what_are_agentic_ai_governance_frameworks_and_how_do_they_apply_to_financial_advisory.php) · [What are the FHA streamline refinance requirements in 2026?](https://cashcache.co/knowledge/what_are_the_fha_streamline_refinance_requirements_in_2026.php)

The strongest current US hook is the SEC’s 2023 conflicted-interaction rules, which cover Regulation Best Interest and the Advisers Act. Covered firms must eliminate or disclose and otherwise mitigate conflicts associated with predictive data analytics or similar systems. A predictive data analytics system is broadly defined as a computational, statistical, machine-learning, or similar system that makes predictions or analyses based on data and is used to guide or determine interactions with an investor or client. The compliance date was 11 December 2023 for firms with at least $100 million in regulatory assets under management or $100 million or more in gross revenue, and 10 June 2024 for smaller firms.

That rule does not create a blanket label saying “AI was used.” It targets conflicts, such as a system that steers clients toward products, accounts, trades, or actions that benefit the firm. A generic sentence about artificial intelligence does not cure a bad incentive. The firm must identify the conflict, remove it where possible, and make any remaining conflict clear enough for the client to understand.

Other duties can create separate disclosure needs. Form ADV asks advisers to describe material practices and conflicts involving material new technologies, including artificial intelligence. Privacy notices must address how nonpublic personal information is collected, shared, and protected. Marketing, books-and-records, cybersecurity, and state rules may also matter. The result is a layered compliance model rather than one national AI checkbox.

## What the SEC’s 2023 rules actually require

The SEC’s rules became effective on 5 October 2023 and applied in two stages. The first deadline, 11 December 2023, covered larger firms meeting either the $100 million regulatory-assets threshold or the $100 million gross-revenue threshold. The second deadline, 10 June 2024, covered smaller firms. Those dates are past, so a firm that has not assessed covered systems is already late on the federal compliance timeline.

The rules apply to covered predictive data analytics or similar systems used to guide or determine interactions with an investor or client. That can include robo-advice engines, recommendation models, lead scoring, account-opening workflows, portfolio tools, and systems that influence which product or message a person sees. The rule is technology-neutral, so a traditional statistical model can be covered even if the firm does not call it AI.

For a conflict to matter, the system must be tied to an interaction that could benefit the firm or its associated person. Examples include steering toward proprietary products, generating more transaction revenue, increasing advisory fees, or favoring an account type that pays the firm more. A system that merely formats a report or checks spelling may not create the same issue, although records, privacy, and accuracy duties can still apply.

Disclosure must be specific enough to explain the conflict, but it is not a substitute for mitigation. A vague statement that “technology may influence recommendations” can fail because it does not tell the client what is being influenced or why the firm benefits. The SEC’s framework asks firms to remove the conflict where practicable and to design controls around any conflict that remains.

## Other US rules that can trigger disclosure

Form ADV is a major source of adviser-specific disclosure. The SEC has stated that investment advisers must disclose material conflicts and business practices involving material new technologies, including artificial intelligence. If AI materially affects portfolio construction, client segmentation, trade recommendations, or another advisory service, the description may belong in the brochure or another client-facing disclosure document. The filing must match the actual workflow, not merely the vendor’s marketing language.

The marketing rule under the Investment Advisers Act can also require care. AI-generated performance illustrations, backtests, hypothetical results, testimonials, and comparative claims must not be materially misleading. A firm must be able to substantiate the claim, identify material limitations, and keep supporting records. If a model produces a client-specific illustration, the adviser remains responsible for the output even when the text was generated automatically.

Privacy duties operate independently. A firm that sends client information to an AI provider may need to account for that provider as a service provider, restrict the purpose of processing, and update its privacy notice if personal information is shared in a way covered by Regulation S-P or state law. A disclosure that AI was used does not replace consent or security controls where those are required. The same issue can arise when a chatbot is trained on client emails, uploaded statements, or call transcripts.

FINRA-member firms must add broker-dealer duties to the analysis. FINRA Rule 2210 covers communications with the public, Rule 3110 addresses supervision, and Rule 4511 requires books and records. A chatbot script, personalized product message, or AI-assisted sales recommendation can therefore require principal review, retention, and a documented approval process. State-registered advisers should also check their administrator’s guidance because state requirements are not uniform.

## How to disclose AI without misleading clients

A useful disclosure should name the function, the data, the human role, and the material limitation. For example, a client receiving a recommendation influenced by a model should be told that AI was used to analyze specified information, what the system was asked to evaluate, whether a person reviewed the result, and whether the firm or a provider receives a financial benefit. The wording should be short enough to read before a decision, with a longer explanation available in the brochure or privacy notice.

Timing matters. A privacy notice may be delivered at onboarding and updated when the firm’s practices change, while a product or transaction conflict may need to be disclosed before or at the point of the recommendation. A chatbot should be identified as automated at the start of the conversation, not only in a footer. A client should not have to infer that an apparently human conversation is being generated by software.

A label such as “AI-generated” is useful for transparency, but it is not a complete legal disclosure. If the system can make an error, omit a material fact, or favor a revenue-producing option, the client needs that information in plain language. If a human adviser reviews and approves the output, the disclosure should say so rather than implying either full automation or full human authorship.

The disclosure should also distinguish assistance from decision-making. “Our adviser used an AI tool to screen information, and a qualified adviser reviewed the recommendation” is materially different from “an automated system selected this portfolio without human review.” The first describes a workflow; the second describes a higher-risk allocation of responsibility. Neither sentence should be used unless it accurately reflects the operating model.

## Comparison: disclosure, consent, and control

| Feature | AI transparency disclosure | Conflict disclosure and mitigation | Privacy notice or consent | Human review and controls | Records and testing |
| --- | --- | --- | --- | --- | --- |
| Main purpose | Tell the client that AI participated | Address incentives that may affect a recommendation | Explain collection, sharing, and protection of personal information | Reduce error and retain accountability | Preserve evidence and detect failures |
| Typical timing | Before or during the affected interaction | Before or at the relevant recommendation or transaction | At onboarding and when practices materially change | Before output reaches the client where risk warrants it | Continuously and at defined review intervals |
| Useful evidence | Bot label, workflow description, client-facing wording | Conflict inventory, incentive analysis, mitigation records | Privacy notice, vendor terms, data-flow map | Approval logs, reviewer training, exception reports | Model tests, prompts, outputs, versions, complaints |
| Main limitation | A label does not remove a conflict | Disclosure alone does not cure an unfair design | A notice does not replace reasonable security | Review can become a rubber stamp | Records do not prove that a system is fair or accurate |

These mechanisms are alternatives only in a limited sense. A firm may use a simple AI label for a low-risk drafting tool, while a system that influences product selection normally needs conflict analysis, supervision, and records in addition to a label. Privacy controls are needed when client information is processed, even if the AI output is never shown directly to the client. Human review is valuable, but it is not a legal safe harbor if the reviewer lacks time, training, or authority to change the result.
For a low-risk use, such as grammar correction on an internal draft, a short internal note and vendor review may be enough. For a client-facing portfolio recommendation, the file should normally contain the model purpose, data sources, known limitations, conflict assessment, approval history, and a clear explanation to the client. The more directly the system affects money, access, or a transaction, the harder it is to justify a thin disclosure.

## Practical implementation plan for advisers and firms

Start by assigning each AI use to a risk tier. Tier 1 covers administrative assistance with no client-specific output, such as summarizing a public article. Tier 2 covers client communications or analysis that a qualified person reviews. Tier 3 covers personalized recommendations, account openings, trade ideas, eligibility decisions, or any system that can change a client’s financial outcome. Tier 3 should receive the most detailed review before launch.

Create an inventory that records the vendor, model version, input data, output audience, decision point, financial incentive, retention period, and responsible employee. Map whether client information leaves the firm and whether the provider can use it for training. A spreadsheet is acceptable for a small firm if it is kept current; a large firm may need a system of record linked to change management and incident response.

Test the system against realistic cases before using it with clients. Check for unsupported claims, omitted limitations, inconsistent recommendations, and different treatment of similar clients. Run at least one review after deployment and after every material model, prompt, data, or vendor change. A 30-, 60-, and 90-day review cadence is a practical starting point, although a high-risk trading or suitability system may need continuous monitoring.

Write two versions of every client disclosure: a short notice at the point of use and a longer explanation in the brochure, privacy notice, or service agreement. Train advisers and supervisors to explain the distinction between AI assistance, automated analysis, and automated decision-making. Keep the version shown to the client, the date it was shown, the model version, and the human approval record where applicable. If a client asks how the recommendation was produced, the firm should be able to answer without exposing trade secrets or making an unsupported promise.

## Common mistakes and what happens when firms get it wrong

The most common error is treating disclosure as a one-sentence disclaimer placed in a website footer. A sentence that says “we may use AI” does not explain whether the system selects investments, communicates with clients, or shares personal information. It also does not disclose a conflict where the firm earns more when a client follows a recommendation. The SEC’s approach is concerned with the substance of the interaction, not the presence of the word AI.

A second mistake is assuming that a vendor’s compliance statement transfers responsibility. The adviser or broker-dealer remains responsible for recommendations, communications, supervision, and client records. A vendor may provide useful documentation, but the firm must verify the actual data flow, retention terms, model behavior, and escalation process. A low-cost tool can create a high-cost incident if it exposes client data or produces an unreviewed recommendation.

Firms also confuse automation with personalization. A chatbot that answers a general question about a 401(k) is not the same as a system that recommends rolling an account, changing an allocation, or buying a product. The latter can trigger conflict, suitability, marketing, and recordkeeping analysis even when the user interface looks conversational. The risk rises when the system uses account balances, age, income, tax status, or stated goals.

Over-disclosure is a problem too. A page filled with legal language can obscure the fact that a client is speaking with a bot or that a recommendation carries a revenue conflict. The better approach is a short, direct notice followed by a readable explanation. If the firm cannot explain the system in ordinary language, it probably has not completed the operational review needed to use it safely.

## When to act, and what it may cost

A firm should act before the next client-facing AI use, not after a complaint. New systems, new vendors, material prompt changes, new data sources, and new product integrations should trigger review. Existing systems should have been assessed by the SEC deadlines of 11 December 2023 or 10 June 2024, depending on firm size. A firm discovering a gap now should document the issue, stop any unsupported client-facing use, and involve compliance or securities counsel.

Cost varies with scope. A small adviser may spend 10 to 30 staff hours building an inventory, revising a privacy notice, and drafting a point-of-use disclosure, with outside legal review often ranging from about $1,500 to $7,500 depending on the number of workflows. A multi-state or broker-dealer operation with several models, vendors, and client journeys can spend tens of thousands of dollars on testing, policy work, training, and monitoring. Vendor fees are separate and can range from free or low-cost subscriptions to five-figure annual contracts for regulated deployments.

The cheapest option is not always the least risky. A free chatbot that stores prompts externally may cost more after a privacy incident than a paid tool with contractual controls, audit logs, and a defined retention policy. Conversely, an expensive platform is not automatically compliant. Price should be compared with the controls actually delivered, including data segregation, access restrictions, model-change notice, output logging, and the ability to disable a problematic feature.

A sensible budget covers four items: legal review of the applicable rule set, technical testing of the model and data flow, training for the people who approve outputs, and ongoing monitoring. Firms should reserve money for correction as well as launch. A model that cannot be explained, tested, or turned off is a poor candidate for personalized financial advice regardless of its advertised accuracy.

## Bottom line for cashcache.co readers

The right question is not whether an AI financial adviser must use one universal label. The right question is whether AI changes what the client receives, how personal information is handled, or why the firm benefits from a recommendation. If the answer is yes, disclosure should sit alongside conflict controls, privacy safeguards, supervision, and records.

For a reader evaluating an AI adviser, ask whether the service identifies automated interactions, explains human review, describes conflicts, and states how client data is used. For a firm offering the service, keep the disclosure specific, timely, and tied to the actual workflow. That approach is more durable than copying a generic disclaimer because it addresses the trust problem created by the system rather than the brand name of the tool.

## Quick answers

### Do US financial advisers need to say when they use AI?

There is no single universal US AI label for every adviser. A firm should disclose AI when it materially affects a client interaction, recommendation, communication, data practice, or conflict, and FINRA firms may have additional communication and supervision duties.

### What did the SEC require by December 2023 and June 2024?

The SEC’s conflicted-interaction rules required covered firms to eliminate or disclose and otherwise mitigate conflicts from predictive data analytics or similar systems. The first deadline was 11 December 2023 for firms with at least $100 million in regulatory assets under management or $100 million in gross revenue, and the second was 10 June 2024 for smaller firms.

### Is an AI disclaimer enough for a robo-adviser?

Usually not. A disclaimer may explain that AI participated, but it does not remove a conflict, correct a misleading performance claim, or replace privacy and security controls. A robo-adviser needs disclosure matched to the recommendation, data flow, and client impact.

### How much does AI compliance cost for a small adviser?

A small adviser may spend 10 to 30 staff hours on an inventory, notices, and workflow review. Outside legal help commonly ranges from about $1,500 to $7,500 for a limited review, while larger or multi-state deployments can cost tens of thousands of dollars.

### Can a client ask how an AI recommendation was made?

A client can ask, and a well-governed firm should be able to explain the system’s role, the data used, the human review process, and any material conflict. The answer should be accurate and understandable without promising that the model is error-free or revealing protected trade secrets.

Canonical: https://cashcache.co/knowledge/what_ai_disclosure_requirements_apply_to_financial_advisers_in_2026.php
Markdown: https://cashcache.co/knowledge/what_ai_disclosure_requirements_apply_to_financial_advisers_in_2026.php/index.md
