THE INTELLIGENT FIRM | PART 7 OF 9
Key Takeaways
- Most AI governance conversations in wealth management focus on whether the technology is safe in the abstract. The more useful question is narrower: whether the AI operates inside the firm’s existing controls.
- FINRA’s 2026 Regulatory Oversight Report devotes new attention to autonomous AI agents, flagging auditability, scope of authority, and system access as the risks that matter most.
- The SEC’s FY2026 examination priorities focus on whether AI governance is demonstrable: whether a firm can explain how its AI reached a decision, and whether it can prove its policies are enforced rather than merely written.
- Three properties determine whether an AI system fits inside a firm’s existing controls: auditability, permissioning, and policy enforcement.
- A firm does not need a separate governance program for AI; it needs AI that operates inside the governance program it already has.
The question most firms are asking
Ask a compliance officer what worries them about AI, and the answer usually starts with a version of the same fear: what if the model gets something wrong. It is a reasonable fear, and it is also the wrong starting point for evaluating whether an AI system belongs inside a regulated firm.
Every technology a firm adopts can make mistakes. Advisors make mistakes. Spreadsheets make mistakes. The question regulators actually ask is not whether a tool can be wrong. It is whether the firm can see when it was wrong, control what it was allowed to do, and prove that its policies were followed.
The right question is not whether an AI system can make a mistake, but whether the firm can see it, contain it, and prove what happened afterward.
What the regulators are actually asking
Two of the most detailed regulatory documents published this year give a clear answer, and neither of them asks whether AI is inherently trustworthy. FINRA’s 2026 Regulatory Oversight Report devotes a new, expanded section to generative AI, and for the first time gives specific attention to autonomous AI agents, which they define as: systems capable of taking action, not just generating text. The report is candid about what makes agents different from a chatbot. It flags autonomy, scope of authority, data sensitivity, and, above all, auditability: whether a firm can trace and explain what a multi-step agent actually did.
The SEC’s FY2026 examination priorities take a similar position from the other direction. Examiners will look at whether firms have adequate policies and procedures to supervise their use of AI, and they will review the accuracy of any claims a firm makes about its own AI capabilities. The standard they describe is explainability: whether a compliance team can walk an examiner through why an AI system produced a specific output, on request, without assembling the explanation after the fact.
Neither regulator is asking firms to prove that AI never makes mistakes. Both are asking firms to prove that they are watching, that access is controlled, and that policy is more than a document nobody checks against the system it is supposed to govern.
The three properties examiners actually test
Strip away the specifics of any single report, and the same three properties keep reappearing. They are not abstract principles. They are the specific things an examiner, or a firm’s own compliance team, will actually try to test.
Auditability. Can the firm trace what the AI did and why, well enough to reconstruct the reasoning for an examiner who was not in the room. FINRA’s own language is specific: complicated, multi-step agent reasoning can make outcomes difficult to trace or explain. An AI system that cannot produce that trail is not ready for a regulated environment, regardless of how good its answers are.
Permissioning. Can the firm control precisely what an AI agent is allowed to see and do, at the level of an individual client record, and restrict it the same way a firm already restricts human access. Both regulators single out scope of authority as a defining risk of agentic AI: a system that can act beyond what a human intended undermines the entire premise of supervision.
Policy enforcement. Does the firm’s AI actually follow the compliance policies already written down, or does it operate next to them. The SEC’s language here is direct: policies and procedures must be implemented and enforced, not simply drafted. A policy that lives in a manual while a system operates independently of it amounts to the same failure in an examination.
| POLICY ON PAPER AI governance exists as a written document describing how the system should behave, disconnected from what the system actually does. | POLICY IN THE SYSTEM AI governance is enforced by the platform itself: access controls, audit trails, and permissions that make the policy the only way the system can operate. |
Examiners do not grade the document. They grade whether the system actually behaves the way the document says it will.
Why this matters before a firm deploys anything
Firms that wait until after deployment to think about governance usually discover the gap the hard way, in the middle of an examination, when a regulator asks a question nobody prepared to answer. Auditability, permissioning, and policy enforcement are far easier to build into a system from the start than to retrofit onto one that is already running across hundreds of client relationships.
This is especially true for a firm running a workforce of specialist AI agents, the model we described earlier in this series: more agents performing more tasks across more client relationships means more surface area for exactly the risks regulators are flagging.
This is also why the governance question belongs earlier in the evaluation process than most firms currently place it. It is not the last box to check after deciding an AI system delivers enough value, but one of the first questions that determines whether the system belongs in the firm at all.
A framework for evaluating any AI system. Before deploying any AI system into a regulated workflow, three questions are worth asking directly.
• Can we reconstruct exactly what the AI did and why, without assembling the explanation by hand.
• Can we control precisely what data and actions each AI agent is allowed to touch.
• Are our policies enforced by the system itself, not just described in a document next to it.
The platform we’re launching in August was built with these requirements at the foundation, not retrofitted, not approximated. Be the first to know when it’s here.


