BEDROCKOperations Consulting
AI & ComplianceJuly 27, 2026·6 min read

AI won't get you fined. Ungoverned AI will.

Talk to ten RIA principals about AI and you'll hear the same two postures. Half have quietly banned it: too risky, compliance would never allow it, we'll wait and see. The other half have no policy at all, which means their advisors are already pasting client situations into free chatbots on their personal phones. One group is falling behind. The other is running an unmanaged risk they haven't priced.

Both postures make the same mistake: they treat AI as a single yes-or-no decision. It isn't. It's a set of use cases, and the use cases carry wildly different risk.

Sort by blast radius

Drafting an internal meeting agenda with AI has a blast radius of roughly zero. Summarizing your own process documentation, writing a first draft of a blog post, building a spreadsheet formula: same. These are low-stakes, high-frequency wins, and banning them buys you no safety at all. It just buys you slower work.

On the other end: anything with client personal information, anything that could read as investment advice, anything client-facing that goes out unreviewed. That's where the real rules live, and where your existing compliance obligations already apply whether AI is involved or not. The regulator doesn't have a special AI rulebook for you yet. It has the same rulebook it always had: supervise your communications, protect client data, don't mislead.

A policy that fits on one page

The firms doing this well have a policy a normal human can remember. Approved tools, on firm accounts, not personal ones. No client personally identifiable information in prompts, ever. Everything client-facing gets human review before it ships, same as it always did. A short list of green-light use cases so people know where the open field is, and one named person who owns questions.

That's it. One page, reviewed with your compliance support, trained in one lunch meeting. Now your team gets the compounding speed of AI on the 80 percent of work that is internal and low-stakes, and your risk profile on the sensitive 20 percent is actually better than before, because you replaced silent freelancing with explicit rules.

The cost of waiting

Here's the uncomfortable math. The firm across town that adopted AI with guardrails last year is producing content faster, prepping meetings faster, and answering operational questions faster. Their advisors spend more hours with clients. Your ban isn't protecting you from that competition. It's subsidizing it. Govern the tool. Don't fear it.

Recognize your firm in this?

This is exactly the kind of thing a practice audit surfaces and fixes. The first call is 30 minutes and free.

Start a conversation