The US Securities and Exchange Commission’s Division of Examinations has begun seeking information from financial firms about their use and oversight of artificial intelligence, putting pressure on companies to document their systems and support claims made to investors and clients.

The requests cover AI-assisted portfolio management, algorithmic trading models and marketing communications, Red Oak found in an analysis of the examination activity. A central concern is whether firms can substantiate statements about their AI capabilities and avoid “AI washing,” the practice of exaggerating or misrepresenting the role of the technology in products or operations.

Examiners are requesting a broad range of materials in which firms discuss AI. These can include Form ADV Part 2 disclosures, websites, sales presentations, audio recordings and videos. That scope requires firms to check not only whether individual statements are accurate, but also whether descriptions remain consistent across regulatory filings, public communications and promotional content.

Creating a reliable inventory of AI systems is emerging as an immediate governance challenge. AI tools can be adopted by business units without the knowledge of legal or compliance personnel, while responsibility for technical systems has traditionally rested with information technology or cybersecurity teams. Identifying every model, application and embedded feature may therefore require cooperation among compliance, legal, audit, marketing, IT and security functions.

Third-party products add another layer of complexity. Software used for trading, research, communications or other business processes may contain AI features even when a financial firm did not develop the underlying technology. Firms must determine where those capabilities are in use, what data they process and how vendors test and monitor them. Red Oak said some organizations are revising vendor due-diligence questionnaires to address risks specific to AI.

Governance arrangements remain uneven. Roughly two-thirds of the compliance and legal professionals surveyed by Red Oak said their organizations had some form of AI governance committee. In practice, however, routine supervision has often remained with IT personnel. Compliance, legal and audit teams are increasingly being asked to verify that systems work as internally described and that the organization can demonstrate meaningful oversight.

That evidence may include training records, committee mandates, meeting minutes and documentation showing who approved a tool or use case. Clear accountability is especially important when an AI system influences investment activity or when its capabilities become part of a firm’s marketing message.

Some recordkeeping and disclosure questions are not yet settled. Form ADV does not contain a dedicated field for reporting AI use, and expectations continue to develop around retaining prompts and model responses or labeling marketing material produced with generative AI. Faced with that uncertainty, firms are tending to preserve more records rather than risk being unable to reconstruct how a system was used.

The examination activity follows earlier SEC attention to misleading AI claims in the investment industry. Existing securities laws already prohibit materially false or misleading statements, meaning a dedicated AI rule is not necessarily required for regulators to challenge unsupported representations. The agency can also examine whether registered firms maintain policies and controls appropriate to the technology’s role in their business.

Red Oak described the requests as following a familiar examination pattern in which an initial group of firms receives detailed inquiries before the issues become more widely recognized. Most compliance professionals in its survey had not received an AI-specific request, but many were preparing for the possibility.

The compliance firm recommends that organizations first review every public claim about AI, compare an inventory of tools in operational use with existing policies, and assign explicit ownership of AI governance. Those steps are intended to give firms a defensible record connecting what they say about AI with how the technology is actually selected, tested, monitored and supervised.

Sources: AI regulation