Most of what passes for AI in advisory practices is a note-taker. It listens to the meeting, writes the summary, updates the CRM. Useful, and the surveys show it is where adoption started. The larger opportunity is analysis on a client's real balance sheet: concentration, liquidity, tax-efficient funding, retirement sustainability, a client-ready report in the firm's colors, drafted in minutes from live data. That is also where the compliance questions stop being theoretical, because it is the point at which client financial data leaves the building.
This guide sets out where advisors actually use AI today, the three tiers of use and why the third is different, what the SEC and FINRA require of each, what data should and should not leave, a workable AI policy for a small RIA, and the "AI drafts, you decide" workflow that keeps the advisor where the fiduciary duty sits.
Where Advisors Are Actually Using AI
The picture from the field is consistent: advisors are optimistic, cautious, and mostly using AI for the parts of the job that do not touch client money. Advisor360° surveyed 301 US-based advisors at RIAs, broker-dealers and banks in the fall of 2025, managing an average of $548 million individually or as a team.
What advisors use AI for, and what holds them back (Advisor360°, fall 2025)
Two lines matter most. Fourteen percent using AI to find opportunities and three percent relying on it for recommendations means almost nobody is running analysis on real client data yet. And 55% citing compliance as the barrier means the reason is not doubt about the technology. It is doubt about whether the firm can defend the use of it. Both are addressable, and the rest of this guide is about how.
The Three Tiers of AI Use in an Advisory Practice
Every use of AI in a practice falls into one of three tiers, and the tiers are defined by what data the model sees.

Three tiers, three risk profiles
Tier 2 is where firms get into trouble without noticing. An advisor who pastes a PDF statement into a consumer chatbot has sent account numbers and a client's name to a third party with no contract, no due diligence file and, on many consumer plans, a default that lets the provider train on the conversation. The analysis that comes back is also built on a snapshot that was stale the day it was printed and covers only the accounts the advisor happened to have. Tier 3 fixes both problems at once: the data is scoped, structured and live, and it moves under a contract the firm can document.
The compliance problem with AI is not the model. It is the paste.
What Connected Analysis Looks Like
The Model Context Protocol, MCP, is an open standard that lets an AI assistant read from an application through a defined, permissioned interface instead of through copy and paste. Kubera exposes a client's balance sheet over MCP: the assistant can ask for positions, values, history, cash flows, allocation, IRR and CAGR, and gets back structured data scoped to that portfolio. The client or firm connects it once in Claude, ChatGPT, Grok, Perplexity or a command-line tool, with setup steps in Kubera's MCP guide. What the advisor can then ask is the whole point.
What advisors actually ask a connected balance sheet
Every one of those takes an analyst an afternoon and a legacy platform a module. The reason they take an AI minutes is not that the model is clever; it is that the model can see the whole balance sheet, including the founder shares, the LP commitments, the wallet and the Lisbon mortgage that no custodian feed carries.
The Compliance Map: What the Rules Actually Require
There is no AI-specific rule for investment advisers, and there is not going to be one soon. The SEC's proposal on conflicts of interest from predictive data analytics, which would have imposed new obligations on any technology that interacts with investors, was formally withdrawn on June 12, 2025, with the Commission stating it "does not intend to issue final rules" on it (Dechert). That leaves the existing framework, which is more than sufficient to get a firm in trouble.
Existing rules and what they mean for AI use
Read across the rows and the same three controls appear every time: a human reviews the output, the data goes only to vendors the firm has vetted and contracted with, and the firm keeps a record. None of that is new. It is the firm's existing compliance program applied to a new tool.
What Should Leave, and What Should Not
The single most consequential decision is which data reaches the model and under what terms. It splits into two parts: the data itself, and the plan it goes to.

On the data, the working rule is that an AI needs values, not identities. Positions, market values, history, cash flows and allocation are enough to run every prompt in the table above. Account numbers, login credentials, Social Security numbers, statements and tax documents add nothing to the analysis and add everything to the breach. A connected balance sheet should be designed so that only the first list can leave. Kubera's connection sends positions, values, history and cash flows, never credentials and never documents, and Kubera does not train models on client data.
On the plan, the difference between a consumer subscription and a business one is contractual, and it is the difference that matters to Reg S-P. Consumer plans commonly retain conversations and may use them to improve models unless the user opts out; business and enterprise plans typically exclude customer content from training by contract, offer administrative controls, retention settings and audit logs, and come with terms a firm can put in a due diligence file. The rule for a firm is simple: use an AI plan that contractually will not train on the data, and put the contract in the vendor file.
Consumer vs. business AI plans for advisory use
A Workable AI Policy for a Small RIA
A written policy does not need to be long. It needs to answer the questions an examiner will ask and to be followed. The elements below fit on two pages.
Elements of an RIA generative-AI policy
Most of this exists in the firm already for other technology. The new work is the approved-tools list, the data rules, and the habit of saving the reviewed output. The 2026 exam priorities make one more point worth building in: describe the firm's AI use accurately everywhere it is described, because a website that says "AI-powered" and a process that uses AI for meeting notes is an AI-washing finding waiting to happen.
The Workflow: The AI Drafts, You Decide
With the policy in place, the day-to-day workflow is five steps, and the fiduciary sits in the middle of it.

- Connect. The client's balance sheet is linked to the firm's approved assistant once, through a read-only connection the firm can switch off. Nothing is pasted.
- Ask. The advisor asks the question they would ask an analyst: concentration, liquidity against commitments, a funding plan, a report in the firm's template. Assumptions and methodology are requested alongside the answer.
- Review. The advisor checks the output against the balance sheet and their own judgment. Where the model is wrong, and it will be, this is where it gets caught. Kubera's own guidance calls an AI a perspective, not a prophet.
- Decide. The advisor decides what to recommend. The AI does not give advice, Kubera does not give advice, and the output goes nowhere until a person has decided it should.
- Deliver and record. The reviewed version goes to the client under the advisor's name, through the normal review for anything client-facing, and is saved with the file.
The time saving is in the first two steps. A branded twelve-month client report that took an afternoon of pulling statements, reconciling a spreadsheet and formatting a PDF takes a prompt and a review. A concentration analysis across public, private, real and digital assets in three currencies, which most firms simply did not do because the data was never in one place, takes the same prompt. The review step does not get shorter, and it should not.
Where AI Gets It Wrong
Three failure modes account for most of the risk, and all three are handled by the review step. The first is fabrication: a model asked for a figure it does not have will sometimes produce one, which is why connected data beats pasted data and why "show your assumptions" belongs in every prompt. The second is stale or partial input: an analysis on last quarter's statement for four of the client's nine accounts is confidently wrong, which is the case for a live, complete balance sheet rather than for less AI. The third is over-reach: a model asked for a plan will produce a plan, and a plan is advice. The advisor decides what is advice, and the model's draft is an input to that decision, not a substitute for it.
The Advisor360° finding that 46% of advisors lack confidence in AI outputs is, read this way, the right instinct. The answer is not to avoid the tool. It is to feed it complete data and to review what comes back.
How Kubera White Label Fits

Kubera White Label is the client's whole balance sheet under the firm's brand: every asset class, every currency, every entity, across bank and brokerage, private stakes and LP positions, crypto and DeFi, real assets and structures, with Recap, Fast Forward, IRR and CAGR built in. It hands that balance sheet to the AI the firm already uses (Claude, ChatGPT, Gemini, Grok, Perplexity or anything that speaks MCP) through a read-only connection that sends positions, values, history and cash flows and never credentials or documents. Kubera does not train models on client data, does not put its name on the output and does not give advice. The firm can turn the AI connection off firm-wide, and the SOC 2 Type II report is available under NDA before signing. Pricing starts at $300 a month with no implementation fee, and setup starts within 24 hours.
Legacy platforms sell reporting, planning, risk and tax as four modules and then charge for the training. Kubera gives the balance sheet to the assistant the advisor already pays for, and the assistant does not bill for the meeting.
Request a demo, or take the 14-day trial as a client, connect your own AI and try the prompts above on your own money first.
Frequently Asked Questions
Can financial advisors use ChatGPT or Claude?
Yes. There is no rule prohibiting it. The obligations that apply are the existing ones: fiduciary duty, the Marketing Rule for anything client-facing, Regulation S-P for any client data shared with the vendor, books-and-records for analysis that supports advice, and a written compliance policy. Use a business or enterprise plan that excludes training by contract.
Is there an SEC rule on AI for investment advisers?
No AI-specific rule. The SEC withdrew its predictive data analytics conflicts proposal on June 12, 2025. The 2026 examination priorities do target "AI washing" and supervision of AI use, applying existing rules.
Can I put client data into an AI tool?
Only under a contract the firm has reviewed, only the data the analysis needs (values, not identities), and only through an approved tool. Pasting statements or account numbers into a consumer chatbot is the practice to stop. A structured, read-only connection that sends positions and values and nothing else is the practice to adopt.
Does using AI for client reports trigger the Marketing Rule?
If the material goes to prospects or is otherwise an advertisement, yes, the same as any other material. Projections and Monte Carlo output are hypothetical performance and carry the rule's conditions. Route AI-drafted material through the standard review.
What is MCP and why does it matter for advisors?
The Model Context Protocol is an open standard that lets an AI assistant read from an application through a permissioned interface rather than by copy and paste. It means the assistant sees live, complete, scoped data, and the firm can document and control what it sees.
Do I have to tell clients I use AI?
The firm's representations must be accurate, so whatever the ADV, website and advisors say about AI should match what the firm actually does. Many firms add a short, plain explanation; 21% of advisors in the Advisor360° survey proactively discuss it. Clients should be able to decline AI-assisted analysis.
Can clients turn the AI connection off?
On Kubera White Label, the firm can disable the AI connection firm-wide, and individual clients control their own connections.
Does Kubera give investment advice through AI?
No. Kubera provides the balance sheet to the AI the client or firm chooses. The AI drafts; the advisor reviews and decides; the advice is the advisor's.
The Principle Worth Keeping
Feed the model complete data through a connection the firm controls, send it values rather than identities under a contract that forbids training, and keep a person between the output and the client. Do that and AI is the analyst a small firm could never hire. Skip it and the compliance department is right to be worried.
This article is general information, not legal or compliance advice. The application of the Advisers Act, the Marketing Rule and Regulation S-P depends on the firm's facts; confirm your policy with compliance counsel.






