Most of what passes for AI in advisory practices is a note-taker. It listens to the meeting, writes the summary, updates the CRM. Useful, and the surveys show it is where adoption started. The larger opportunity is analysis on a client's real balance sheet: concentration, liquidity, tax-efficient funding, retirement sustainability, a client-ready report in the firm's colors, drafted in minutes from live data. That is also where the compliance questions stop being theoretical, because it is the point at which client financial data leaves the building.

This guide sets out where advisors actually use AI today, the three tiers of use and why the third is different, what the SEC and FINRA require of each, what data should and should not leave, a workable AI policy for a small RIA, and the "AI drafts, you decide" workflow that keeps the advisor where the fiduciary duty sits.

AI for Financial Advisors at a Glance

  • Adoption is real but shallow. In Advisor360°'s fall 2025 survey of 301 US advisors, 74% called AI advantageous, 31% used it for meeting notes, 26% for meeting prep, 14% to identify investment opportunities, and 3% for AI-generated recommendations. 55% named compliance as the primary barrier; 93% insisted on keeping control of decisions.
  • There is no AI rule. The SEC withdrew its predictive data analytics proposal on June 12, 2025 (Dechert). Existing rules govern: the Marketing Rule, Regulation S-P, the books-and-records and compliance-program rules, and fiduciary duty. FINRA's Regulatory Notice 24-09 applies the same logic to broker-dealers.
  • The 2026 SEC examination priorities target "AI washing," whether actual AI use matches what firms tell clients, and policies to supervise AI across functions (Goodwin). The amended Reg S-P makes any AI vendor that touches customer data a service provider the firm must oversee, from December 3, 2025 for larger advisers and June 3, 2026 for smaller ones.
  • The data question decides everything. Pasting statements into a consumer chatbot sends PII to a tool that may train on it. A structured, read-only connection sends positions, values and history and nothing else, to a plan that contractually will not train on it, and can be switched off firm-wide.
  • Kubera White Label hands the client's whole balance sheet to whichever AI the firm already uses (Claude, ChatGPT, Gemini, Grok, Perplexity, anything that speaks MCP). The AI drafts. The advisor decides. Kubera puts its name on neither the output nor the advice.

Where Advisors Are Actually Using AI

The picture from the field is consistent: advisors are optimistic, cautious, and mostly using AI for the parts of the job that do not touch client money. Advisor360° surveyed 301 US-based advisors at RIAs, broker-dealers and banks in the fall of 2025, managing an average of $548 million individually or as a team.

What advisors use AI for, and what holds them back (Advisor360°, fall 2025)

MeasureShare of advisors
Say AI is advantageous to their practice74%
Use AI for meeting summaries and notes31%
Use AI to update CRM records28%
Use AI to prepare for client meetings26%
Use AI for routine client communications25%
Use AI to identify investment opportunities14%
Rely on AI-generated financial recommendations3%
Cite compliance and regulatory hurdles as the primary barrier55%
Lack confidence in AI outputs46%
Insist on retaining control over decisions and advice93%
Proactively discuss AI use with clients21%

Two lines matter most. Fourteen percent using AI to find opportunities and three percent relying on it for recommendations means almost nobody is running analysis on real client data yet. And 55% citing compliance as the barrier means the reason is not doubt about the technology. It is doubt about whether the firm can defend the use of it. Both are addressable, and the rest of this guide is about how.

The Three Tiers of AI Use in an Advisory Practice

Every use of AI in a practice falls into one of three tiers, and the tiers are defined by what data the model sees.

The three tiers of advisor AI use: drafting with no client data, analysis on pasted documents, connected analysis on live structured data

Three tiers, three risk profiles

TierWhat it isWhat the model seesMain riskWhere most firms are
1. Drafting and notesMeeting summaries, emails, marketing copy, CRM updates, researchLittle or no client financial data; names and context at mostMarketing Rule on anything client-facing; PII in notesHere (31% notes, 28% CRM)
2. Analysis on pasted dataUploading statements, exporting a CSV, pasting a balance sheet into a chatWhatever was pasted: account numbers, holdings, PII, often stale and incompleteData leaves in an uncontrolled form to a plan that may retain or train on it; analysis built on partial dataA minority, quietly
3. Connected analysisThe AI reads the client's live balance sheet through a structured, read-only connection and works from thatPositions, values, history and cash flows, scoped to the portfolio, current as of now; no credentials, no documentsVendor oversight under Reg S-P; output review; disclosureAlmost nobody (14% opportunities, 3% recommendations)

Tier 2 is where firms get into trouble without noticing. An advisor who pastes a PDF statement into a consumer chatbot has sent account numbers and a client's name to a third party with no contract, no due diligence file and, on many consumer plans, a default that lets the provider train on the conversation. The analysis that comes back is also built on a snapshot that was stale the day it was printed and covers only the accounts the advisor happened to have. Tier 3 fixes both problems at once: the data is scoped, structured and live, and it moves under a contract the firm can document.

The compliance problem with AI is not the model. It is the paste.

What Connected Analysis Looks Like

The Model Context Protocol, MCP, is an open standard that lets an AI assistant read from an application through a defined, permissioned interface instead of through copy and paste. Kubera exposes a client's balance sheet over MCP: the assistant can ask for positions, values, history, cash flows, allocation, IRR and CAGR, and gets back structured data scoped to that portfolio. The client or firm connects it once in Claude, ChatGPT, Grok, Perplexity or a command-line tool, with setup steps in Kubera's MCP guide. What the advisor can then ask is the whole point.

What advisors actually ask a connected balance sheet

Use casePromptWhat the AI needs to see
Branded client report"Build a client-ready 12-month PDF in my firm's colors: balance-sheet summary, performance vs the S&P 500, concentration, top and bottom five."Full balance sheet with history; benchmark data
Retirement sustainability"Run a Monte Carlo: probability of running out over 30 years at a 7% withdrawal, with percentiles and assumptions."Investable assets, allocation, liabilities
Crypto benchmarking"Benchmark this client's crypto against BTC over 12 months: relative return, volatility, drawdown, each holding's contribution."Wallet and exchange positions with history; no legacy platform can see these
Liquidity planning"Give me the most tax-efficient way to raise $3M from this portfolio, as a step-by-step plan."Positions with cost basis and holding periods across accounts, including held-away
Charitable and estate strategy"Client is 67, pledging $1M to a university over five years. Draft the funding strategy and the lifetime estate and gift-tax plan."Full balance sheet including entities and trusts
Concentration review"Where is this family over-concentrated, by issuer, asset class and currency? Keep it to what I'd say in a review meeting."Everything, including private stock and property in other currencies

Every one of those takes an analyst an afternoon and a legacy platform a module. The reason they take an AI minutes is not that the model is clever; it is that the model can see the whole balance sheet, including the founder shares, the LP commitments, the wallet and the Lisbon mortgage that no custodian feed carries.

The Compliance Map: What the Rules Actually Require

There is no AI-specific rule for investment advisers, and there is not going to be one soon. The SEC's proposal on conflicts of interest from predictive data analytics, which would have imposed new obligations on any technology that interacts with investors, was formally withdrawn on June 12, 2025, with the Commission stating it "does not intend to issue final rules" on it (Dechert). That leaves the existing framework, which is more than sufficient to get a firm in trouble.

Existing rules and what they mean for AI use

RuleWhat it requiresWhat it means for AIThe control
Fiduciary duty (Advisers Act §206)Advice in the client's best interest, with care and loyaltyThe advisor owns the advice regardless of what drafted it; "the AI said so" is not a defenseHuman review of every output that reaches a client; document the review
Marketing Rule (Rule 206(4)-1)No untrue or misleading statements; strict conditions on performance, hypothetical performance and testimonialsAI-drafted client materials, projections and Monte Carlo output are advertisements if they go to prospects; hypothetical performance rules apply to modelled resultsRoute AI-drafted marketing through the same review as any other; label projections and assumptions
Regulation S-P (amended 2024)Safeguard customer information; written incident response; oversee service providers with 72-hour breach notice; notify customers within 30 daysAny AI vendor that receives client data is a service provider; consumer chatbots with no contract cannot satisfy thisApproved-tools list; enterprise or team plans with written terms; vendor due diligence file (Baker Donelson)
Books and records (Rule 204-2)Retain communications and records supporting adviceIf a recommendation rests on an AI analysis, the analysis is a recordSave the prompt, the output and the reviewed version with the client file
Compliance program (Rule 206(4)-7)Written policies reasonably designed to prevent violations; annual reviewFirms need a written AI policy and evidence it is followedThe policy below; annual review of tools and usage
2026 exam prioritiesExaminers will test "AI washing," whether use matches representations, and supervision of AI across functionsSay exactly what AI does and does not do in your process; nothing moreConsistent language in ADV, website and client conversations (Goodwin)
FINRA Notice 24-09Reminds member firms that existing rules apply to generative AI: supervision, communications, recordkeepingSame map for BD-affiliated advisorsCoordinate with the broker-dealer's AI policy (FINRA)

Read across the rows and the same three controls appear every time: a human reviews the output, the data goes only to vendors the firm has vetted and contracted with, and the firm keeps a record. None of that is new. It is the firm's existing compliance program applied to a new tool.

What Should Leave, and What Should Not

The single most consequential decision is which data reaches the model and under what terms. It splits into two parts: the data itself, and the plan it goes to.

What leaves and what doesn't: positions, values, history and cash flows go to the AI; credentials, documents and PII stay behind

On the data, the working rule is that an AI needs values, not identities. Positions, market values, history, cash flows and allocation are enough to run every prompt in the table above. Account numbers, login credentials, Social Security numbers, statements and tax documents add nothing to the analysis and add everything to the breach. A connected balance sheet should be designed so that only the first list can leave. Kubera's connection sends positions, values, history and cash flows, never credentials and never documents, and Kubera does not train models on client data.

On the plan, the difference between a consumer subscription and a business one is contractual, and it is the difference that matters to Reg S-P. Consumer plans commonly retain conversations and may use them to improve models unless the user opts out; business and enterprise plans typically exclude customer content from training by contract, offer administrative controls, retention settings and audit logs, and come with terms a firm can put in a due diligence file. The rule for a firm is simple: use an AI plan that contractually will not train on the data, and put the contract in the vendor file.

Consumer vs. business AI plans for advisory use

ConsiderationConsumer planBusiness or enterprise plan
Training on your contentOften permitted by default, with an opt-outExcluded by contract
RetentionProvider defaultConfigurable; zero-retention options on some plans
Administrative controlsNoneUser management, tool permissions, connector controls
Audit logNoneAvailable on most plans
Written terms for the vendor fileClick-throughNegotiated or standard enterprise terms; DPA
Reg S-P service-provider oversightCannot be satisfiedCan be documented

A Workable AI Policy for a Small RIA

A written policy does not need to be long. It needs to answer the questions an examiner will ask and to be followed. The elements below fit on two pages.

Elements of an RIA generative-AI policy

ElementWhat to write downEvidence it is followed
Approved tools and plansWhich assistants, which plan tier, which connectors; everything else is prohibitedVendor file per tool with terms, DPA and SOC 2 report
Data rulesNo PII, account numbers, credentials or documents in any prompt; connected data only through approved read-only connectionsSpot checks of usage; connector settings
Human reviewNo AI output reaches a client or a decision without advisor review; the reviewer is namedReviewed version saved with the client file
RecordkeepingPrompts and outputs that support advice are retained under Rule 204-2Retention in the document system, not in the chat history
Marketing reviewAI-drafted client-facing material goes through the standard advertising review; projections labelled with assumptionsReview log
DisclosureConsistent, accurate language in ADV and client conversations about what AI does in the process; no more, no lessADV language; a one-paragraph client explainer
Client choiceClients may decline AI-assisted analysis; the firm can disable the connection firm-wideOpt-out record; firm-level setting
Vendor oversightDue diligence at selection, annual review, 72-hour breach-notice termReg S-P service-provider file
Testing and trainingTools tested on sample data before use; staff trained on the policy annuallyTest notes; training attendance

Most of this exists in the firm already for other technology. The new work is the approved-tools list, the data rules, and the habit of saving the reviewed output. The 2026 exam priorities make one more point worth building in: describe the firm's AI use accurately everywhere it is described, because a website that says "AI-powered" and a process that uses AI for meeting notes is an AI-washing finding waiting to happen.

The Workflow: The AI Drafts, You Decide

With the policy in place, the day-to-day workflow is five steps, and the fiduciary sits in the middle of it.

The AI-drafts-you-decide workflow: connect, ask, review, decide, deliver, with time per client report before and after
  • Connect. The client's balance sheet is linked to the firm's approved assistant once, through a read-only connection the firm can switch off. Nothing is pasted.
  • Ask. The advisor asks the question they would ask an analyst: concentration, liquidity against commitments, a funding plan, a report in the firm's template. Assumptions and methodology are requested alongside the answer.
  • Review. The advisor checks the output against the balance sheet and their own judgment. Where the model is wrong, and it will be, this is where it gets caught. Kubera's own guidance calls an AI a perspective, not a prophet.
  • Decide. The advisor decides what to recommend. The AI does not give advice, Kubera does not give advice, and the output goes nowhere until a person has decided it should.
  • Deliver and record. The reviewed version goes to the client under the advisor's name, through the normal review for anything client-facing, and is saved with the file.

The time saving is in the first two steps. A branded twelve-month client report that took an afternoon of pulling statements, reconciling a spreadsheet and formatting a PDF takes a prompt and a review. A concentration analysis across public, private, real and digital assets in three currencies, which most firms simply did not do because the data was never in one place, takes the same prompt. The review step does not get shorter, and it should not.

Where AI Gets It Wrong

Three failure modes account for most of the risk, and all three are handled by the review step. The first is fabrication: a model asked for a figure it does not have will sometimes produce one, which is why connected data beats pasted data and why "show your assumptions" belongs in every prompt. The second is stale or partial input: an analysis on last quarter's statement for four of the client's nine accounts is confidently wrong, which is the case for a live, complete balance sheet rather than for less AI. The third is over-reach: a model asked for a plan will produce a plan, and a plan is advice. The advisor decides what is advice, and the model's draft is an input to that decision, not a substitute for it.

The Advisor360° finding that 46% of advisors lack confidence in AI outputs is, read this way, the right instinct. The answer is not to avoid the tool. It is to feed it complete data and to review what comes back.

How Kubera White Label Fits

Kubera white-label

Kubera White Label is the client's whole balance sheet under the firm's brand: every asset class, every currency, every entity, across bank and brokerage, private stakes and LP positions, crypto and DeFi, real assets and structures, with Recap, Fast Forward, IRR and CAGR built in. It hands that balance sheet to the AI the firm already uses (Claude, ChatGPT, Gemini, Grok, Perplexity or anything that speaks MCP) through a read-only connection that sends positions, values, history and cash flows and never credentials or documents. Kubera does not train models on client data, does not put its name on the output and does not give advice. The firm can turn the AI connection off firm-wide, and the SOC 2 Type II report is available under NDA before signing. Pricing starts at $300 a month with no implementation fee, and setup starts within 24 hours.

Legacy platforms sell reporting, planning, risk and tax as four modules and then charge for the training. Kubera gives the balance sheet to the assistant the advisor already pays for, and the assistant does not bill for the meeting.

Request a demo, or take the 14-day trial as a client, connect your own AI and try the prompts above on your own money first.

Frequently Asked Questions

Can financial advisors use ChatGPT or Claude?

Yes. There is no rule prohibiting it. The obligations that apply are the existing ones: fiduciary duty, the Marketing Rule for anything client-facing, Regulation S-P for any client data shared with the vendor, books-and-records for analysis that supports advice, and a written compliance policy. Use a business or enterprise plan that excludes training by contract.

Is there an SEC rule on AI for investment advisers?

No AI-specific rule. The SEC withdrew its predictive data analytics conflicts proposal on June 12, 2025. The 2026 examination priorities do target "AI washing" and supervision of AI use, applying existing rules.

Can I put client data into an AI tool?

Only under a contract the firm has reviewed, only the data the analysis needs (values, not identities), and only through an approved tool. Pasting statements or account numbers into a consumer chatbot is the practice to stop. A structured, read-only connection that sends positions and values and nothing else is the practice to adopt.

Does using AI for client reports trigger the Marketing Rule?

If the material goes to prospects or is otherwise an advertisement, yes, the same as any other material. Projections and Monte Carlo output are hypothetical performance and carry the rule's conditions. Route AI-drafted material through the standard review.

What is MCP and why does it matter for advisors?

The Model Context Protocol is an open standard that lets an AI assistant read from an application through a permissioned interface rather than by copy and paste. It means the assistant sees live, complete, scoped data, and the firm can document and control what it sees.

Do I have to tell clients I use AI?

The firm's representations must be accurate, so whatever the ADV, website and advisors say about AI should match what the firm actually does. Many firms add a short, plain explanation; 21% of advisors in the Advisor360° survey proactively discuss it. Clients should be able to decline AI-assisted analysis.

Can clients turn the AI connection off?

On Kubera White Label, the firm can disable the AI connection firm-wide, and individual clients control their own connections.

Does Kubera give investment advice through AI?

No. Kubera provides the balance sheet to the AI the client or firm chooses. The AI drafts; the advisor reviews and decides; the advice is the advisor's.

The Principle Worth Keeping

Feed the model complete data through a connection the firm controls, send it values rather than identities under a contract that forbids training, and keep a person between the output and the client. Do that and AI is the analyst a small firm could never hire. Skip it and the compliance department is right to be worried.

This article is general information, not legal or compliance advice. The application of the Advisers Act, the Marketing Rule and Regulation S-P depends on the firm's facts; confirm your policy with compliance counsel.

Sign Up to Kubera5 Star ReviewsLearn more about Kubera