What the SEC Is Asking About AI

and What Firms Should Be Ready to Produce

Overview

Listen

Across our client base and in conversations we’ve had in the industry, we’re hearing a consistent pattern: the SEC’s Division of Examinations is requesting information about how firms are integrating artificial intelligence into their operations. Request letters are targeting AI-driven portfolio management, algorithmic trading models, and marketing claims — with particular scrutiny on whether firms’ AI representations hold up, a practice regulators have labeled “AI washing.” In this Red Oak chat, you’ll learn what regulators are asking for.

Critical Questions Powered by Red Oak

The SEC’s Division of Examinations has been issuing requests for information about how firms integrate AI into their operations, and most compliance professionals report they haven’t received one yet. The requests are following the pattern of past examination waves: a concentrated group of firms gets requests early, word spreads, and adjacent firms begin preparing as the scope broadens. When a request arrives, firms need a complete inventory on two fronts: every material where AI use is mentioned, including written, audio, and video, and every AI tool in operational use across the organization. Most firms don’t have that inventory today, and building one typically requires pulling together IT, cybersecurity, legal, and marketing. The firms getting ahead are using this window to build toward readiness before a request lands.

AI washing refers to overstated claims about what a firm’s technology can actually do, and it is one of the key topics SEC request letters are targeting. On the disclosure side, the SEC is asking for all materials where AI use is mentioned, and a single marketing claim about AI can surface in ADV Part 2, on the website, in pitch materials, and in video content. The scrutiny centers on whether those representations are consistent, accurate, and substantiated across every channel. Firms should be prepared to produce documentation that supports any AI-related claim they have made, in any format and on any channel. A practical first step is to inventory every public AI claim the firm has made and verify each one is accurate and substantiated.

Roughly two-thirds of the compliance and legal professionals Red Oak has spoken with report having some form of AI governance committee or working group. In practice, day-to-day ownership of AI systems has often landed with IT by default, because IT manages the tools. The gap is that IT evaluates technology for network uptime and cybersecurity, not for whether a tool’s output holds up against a fiduciary duty to a client, which leaves compliance, legal, and audit to verify that what IT says the AI is doing matches what it actually does.

Surviving an examination means documenting that oversight in a defensible way: ongoing review, meeting records, and evidence of AI-specific training, all of which recent SEC requests call out specifically. The clearest place to start is to assign ownership of AI governance so there is someone accountable for the documentation, training records, and committee structure regulators are asking for.

Transcript

Speaker 1: 00:00
So today’s deep dive is well, it’s about this massive scramble happening right now in the corporate world. We’re looking at a stack of recent compliance reports, regulatory filings, and uh industry surveys about the SEC and their highly targeted information requests on how financial firms are integrating AI.

Speaker: 00:20
Yeah. And it’s a fascinating situation.

Speaker 1: 00:22
Right. And I want to say right up front, even if you don’t work in finance, you really need to hear this because what we’re seeing here with you know this whole shadow AI thing, it’s forcing a massive corporate reckoning around accountability and tech governance. I know. And it is absolutely coming to your industry next. It’s like a like a tsunami warning, right? The wave hasn’t hit everyone yet, but the sirens are blaring and companies are panic preparing.

Speaker: 00:45
They definitely are. And the really interesting part of these reports is the strategy the regulators are using. I mean, they’re following a very classic playbook here.

Speaker 1: 00:53
Oh, targeting the big guys first.

Speaker: 00:55
Exactly. They target a concentrated early group of major firms just to set a precedent. So most compliance professionals, they actually haven’t received a request yet.

Speaker 1: 01:04
But word spreads, obviously. You see the heavy hitters getting audited, and suddenly all these adjacent firms are scrambling. They’re trying to figure out exactly where AI actually lives inside their own business.

Speaker: 01:15
Right, which is proving to be incredibly difficult.

Speaker 1: 01:17
Yeah. Looking at these surveys, it sounds like a nightmare. Okay, so let’s unpack this.

Speaker: 01:22
Yeah.

Speaker 1: 01:22
Because firms are having to hunt down AI on two distinct fronts, right? External public claims and then the internal system.

Speaker: 01:30
Yeah, let’s look at the external side first. Regulators are cracking down on what they call AI washing.

Speaker 1: 01:35
Right, which is essentially just overstating what your tech can actually do, just to sound cutting edge.

Speaker: 01:40
Exactly. So the SEC wants to see every marketing deck, website copy, and even, you know, ADV Part 2 disclosures.

Speaker 1: 01:46
Which, if you aren’t in finance, is basically that mandatory brochure financial advisors have to give clients, you know, explaining how they do business and manage risks.

Speaker: 01:55
Right. They are specifically looking for discrepancies between what firms promise the public and what the tech actually delivers.

Speaker 1: 02:02
Okay, but the internal systems side, that seems to be where the real panic sets in. Compliance teams are discovering that AI adoption is just completely decentralized. They’re finding random departments using generative AI tools that upper management didn’t even know existed.

Speaker: 02:19
Yeah, that’s the shadow AI we were talking about.

Speaker 1: 02:21
I just struggle to understand this. How does a modern corporation simply not know what software its own employees are using? I mean, don’t IT departments have really strict procurement processes?

Speaker: 02:33
They do, but think of shadow AI like employees bringing their own custom-built power tools to a highly regulated construction site.

Speaker 1: 02:40
Oh wow, okay.

Speaker: 02:42
Right? The workers are getting the job done much faster, which is great. But the site manager has literally no idea if the proper safety guards are installed.

Speaker 1: 02:49
That is terrifying for a compliance officer.

Speaker: 02:51
It is. And it’s not always rogue employees secretly buying new software either. Often the vulnerability is a hidden vendor risk.

Speaker 1: 02:57
Ah, meaning a platform you already use suddenly gets an AI makeover.

Speaker: 03:02
Exactly. You might have bought a standard, fully compliant project management tool. Then six months later, that third-party vendor pushes a routine software patch that just happens to include, say, an automatic AI meeting summarizer?

Speaker 1: 03:18
Wait, really? Just baked into the update.

Speaker: 03:20
Yeah. And suddenly those due diligence questionnaires, those long security surveys vendors fill out during procurement, they are completely outdated.

Speaker 1: 03:28
Because that hidden vendor update isn’t just a visibility problem, it creates a massive data trap. I mean, if that new AI tool automatically summarizes client meetings, what happens to the highly sensitive data the employee typed in to generate that summary?

Speaker: 03:42
Well, that brings us directly to this concept of prompt retention.

Speaker 1: 03:45
Right. I wanted to ask about that.

Speaker: 03:47
The whole expectation around archiving employee communications is shifting. Firms generally aren’t expected to save prompts for basic, you know, Google-like searches.

Speaker 1: 03:56
Right, like looking up a stock ticker or whatever.

Speaker: 03:58
Exactly. But for higher risk use cases like generating financial advice or drafting client emails, archiving expectations are rising really fast.

Speaker 1: 04:06
But wait, looking at these filings, the SEC hasn’t actually written official rules for AI prompt retention yet. Why are they demanding this if they haven’t even drawn the lines? That feels like a trap.

Speaker: 04:17
Well, it is a regulatory gray zone right now. We are in this awkward transitional period where the technology is just moving way faster than the rule book.

Speaker 1: 04:26
Yeah, no kidding.

Speaker: 04:27
And because the official lines aren’t drawn, regulators are basically looking for good faith efforts. Meticulous proactive documentation is literally the only defensible posture a firm can take when the examiners actually show up.

Speaker 1: 04:40
So if you have blurry rules on one hand and then these silent AI updates popping up like weeds on the other, the ultimate question really becomes who is actually in charge of keeping the firm out of trouble?

Speaker: 04:51
Yeah, that is the huge governance gap identified in the surveys.

Speaker 1: 04:54
Because roughly two-thirds of compliance professionals say their firm has formed an AI working group. But in practice, day-to-day ownership defaults almost entirely to IT.

Speaker: 05:04
Yeah, pretty much.

Speaker 1: 05:04
Why IT, though? Just because they manage the software licenses.

Speaker: 05:08
Basically, yeah. They hold the administrative keys to the network. But you have to remember, IT evaluates tools for network uptime and cybersecurity.

Speaker 1: 05:18
Right. They aren’t compliance officers.

Speaker: 05:20
Exactly. They don’t evaluate whether a generative AI’s financial advice violates a fiduciary duty to a client.

Speaker 1: 05:27
That makes total sense.

Speaker: 05:28
And that is exactly why legal and compliance teams are panicking right now. They’re being asked to verify that these AI tools are legally compliant, but they simply don’t have the technical access to prove it.

Speaker 1: 05:39
And to survive an exam, you can’t just shrug and point to your IT department. You have to produce concrete meeting records, cross-department sign-offs, and proof of AI-specific training. You really do. So based on the reports we are looking at, there seems to be a pretty clear three-step action plan for companies to get ahead of this. One, inventory every public AI claim to make sure it’s accurate. Two, list every operational AI tool internally and check your data policies against it. Right. And three, assign clear cross-departmental governance ownership so IT isn’t just left holding the bag.

Speaker: 06:11
It sounds so straightforward when you say it like that. But in a decentralized corporate environment, executing those three steps is just a massive operational lift.

Speaker 1: 06:20
Oh, I bet. But the regulatory scrutiny is definitely coming no matter what industry you are in. So before we wrap up this deep dive, here is something to think about for your own career.

Speaker: 06:30
Yeah, I love this point.

Speaker 1: 06:31
If regulators eventually demand a permanent, fully auditable record of every single AI prompt employee’s type merge, how will that level of surveillance change the way you psychologically interact with AI at your own job? Will you still brainstorm with it the exact same way? Think about it.

Read the Blog Post

The SEC’s Division of Examinations has been issuing requests for information about how firms are integrating AI into their operations. Across our client base and in conversations with compliance and legal teams throughout the industry, patterns are surfacing around what firms are finding challenging, where the gray areas are, and where to start.

When we ask compliance professionals whether they’ve received an AI-related request in an exam, the majority say no. Or at least not yet. The SEC’s requests have been issued in a pattern consistent with past examination waves: a concentrated group of firms receives requests early, word spreads, and firms in adjacent categories begin preparing as the scope broadens. Firms are using this time to understand what regulators have started asking and building toward it now. Here’s what we’re hearing.

Taking Inventory

Whether the topic is AI claims in marketing materials or AI tools in use across the firm, the same challenge surfaces: most firms don’t have a complete inventory, and building one is harder than it looks.

On the disclosure side, the SEC is asking for all materials where AI use is mentioned, including written, audio, and video. For many firms, that’s a wide and poorly mapped surface area. Consider a common scenario: marketing makes a claim about AI, and that claim appears in ADV Part 2, on the website, in pitch materials, and in video content. Does the compliance team know whether those claims are consistent, accurate, and substantiated across all of those channels? Request letters are targeting marketing claims as one of the key topics, with particular scrutiny on whether firms’ AI representations hold up – overstated claims that regulators have labeled “AI washing.” Firms should be prepared to produce documentation that supports any AI-related claim they’ve made, in any format, across any channel.

On the systems side, getting to a complete inventory typically requires pulling together IT, cybersecurity, legal, and marketing. Several firms described finding groups within their organizations using AI tools that compliance had no visibility into. AI adoption has been decentralized, and governance programs are catching up.

Vendor management compounds this. Firms are recognizing that a third-party vendor using AI in a product they’ve purchased creates exposure they need to document and understand. Not just at onboarding, but on an ongoing basis. Several compliance teams described revisiting their due diligence processes specifically to build in AI-related questions, because a DDQ from six months ago may already be incomplete.

Where Guidance is Still Forming

There’s a significant amount of gray area that’s generating candid conversations in the market.

On prompt retention: what we’re hearing is that firms are not retaining AI prompts and responses for tasks analogous to a Google search. However,  that expectation is evolving, particularly for higher-risk use cases, like client communications, where the documentation bar is already higher. Some archiving platform providers are building AI capture capabilities now, anticipating that this will become a standard requirement.

On ADV disclosure: there’s no dedicated field for AI use in the ADV today, but the conversation about whether and how to disclose is happening inside firms. Some are starting to include it proactively within existing technology disclosure fields. Others are waiting for clearer guidance. The regulatory expectation isn’t defined yet, and firms are making judgment calls in the meantime.

On AI-generated marketing content: whether using AI to draft marketing materials requires disclosure came up as an open question. In most of these conversations, firms are leaning toward documenting and retaining more rather than less, given the direction of regulatory attention. But the line isn’t drawn anywhere officially.

The common thread: the SEC hasn’t specified expectations clearly in many of these areas, and firms are operating in a period where careful documentation is the most defensible posture available, even without formal requirements to point to.

The Governance Gap

Roughly two-thirds of the compliance and legal professionals we’ve spoken with report having some form of AI governance committee or working group. In many firms, day-to-day ownership of AI systems has landed with IT by default because they manage the tools. What compliance, legal, and audit are still working out is how to verify that what IT says the AI is doing is what it’s actually doing, and how to document that oversight in a way that would survive an examination. That requires ongoing review, meeting records, and evidence of AI-specific training. The SEC requests that we have seen call out all of these specifically.

Where to Start

When looking at what the SEC is asking, there are a few practical places to start to ensure your firm is ready. Inventory every public AI claim your firm has made and verify it’s accurate and substantiated. List every AI tool in operational use and check whether your existing written policies specifically address it. And assign clear ownership of AI governance, so there’s someone accountable for the documentation, training records, and committee structure regulators are asking for.

These may be challenging, particularly in firms where departments have adopted AI independently and at different speeds. But this is what SEC requests are asking for, and what firms will need to defend in an exam.

Contributor

Mike Lubansky serves as the Senior Vice President of Strategy at Red Oak. Connect with Mike on LinkedIn.