During my visits with clients, some have been asking about creating an AI policy. Neither the SEC nor FINRA has issued AI-specific rules, but both have offered guidance making clear that existing obligations, such as supervision, recordkeeping, communications and fiduciary duty, apply to AI the same way they apply to any other tool.
In the retirement plan context, existing ERISA fiduciary standards continue to govern how AI is used. The Department of Labor (DOL) has issued best practice guidance for employers on the use of AI, highlighting themes like transparency, human oversight and responsible use of data. While it’s focused on workplace use, it helps reinforce the importance of clear guardrails when incorporating AI into a practice.
With these guidelines in mind, consider implementing an AI-usage policy. Not a 30-page compliance manual. Just a clear document that answers the basics so everyone's on the same page. While not an exhaustive list, some examples of what you may consider covering in your AI policy include:
- What tools can we use? Define what's approved and who can authorize new ones.
- What data stays out? Client and proprietary data should never go into a public AI tool. Be specific so there's no gray area.
- Who reviews the output? While firm policies and regulatory requirements may differ, consider whether every AI work product gets reviewed by a human before it goes anywhere.
- What do we keep on file? If AI helped produce it, consider retaining the record the same as any other work product.
- Are we being transparent? If AI played a meaningful role, say so.
- How often do we revisit this? At least once a year and more frequently as needed. AI is moving fast and your policy should keep up.