Financial firms are facing growing pressure to demonstrate how artificial intelligence is being used, governed and disclosed as the US Securities and Exchange Commission’s Division of Examinations begins requesting information on AI practices, according to an analysis from Red Oak.
For firms, one of the biggest challenges is developing a complete understanding of where AI is being used across their operations. Red Oak’s analysis highlights that organisations must identify AI tools in use, review how those systems are governed and ensure public statements about AI capabilities are accurate and consistent.
The SEC’s requests are focused on three areas: AI-driven portfolio management, algorithmic trading models and marketing claims. Regulators are particularly examining whether firms can substantiate statements about their AI capabilities, an issue commonly referred to as “AI washing”.
Building an inventory of AI usage is proving complex for some organisations. The SEC is requesting written, audio and video materials where firms reference AI, including ADV Part 2 filings, websites, pitch materials and video content.
Red Oak found that identifying these materials often requires coordination across IT, cybersecurity, legal and marketing teams. Some firms have also discovered that internal teams are using AI tools without compliance teams being aware.
Third-party technology providers present another challenge, as firms need to document and monitor products that include AI capabilities. According to Red Oak, some organisations are updating their due diligence questionnaires to include AI-specific risks.
While firms work to strengthen oversight, several areas remain unclear. There is currently no dedicated field for AI use within ADV filings, while guidance around retaining AI prompts and responses, as well as disclosures for AI-generated marketing content, continues to develop.
In response to this uncertainty, many firms are choosing to retain more documentation and information rather than less.
Red Oak’s analysis also found that AI governance structures vary across organisations. Around two-thirds of compliance and legal professionals surveyed reported having some form of AI governance committee, although responsibility for day-to-day AI oversight has often remained with IT teams.
Red Oak recommends firms focus on three immediate actions: reviewing public AI claims for accuracy, cataloguing AI tools currently in operational use against existing policies and assigning clear ownership of AI governance.
Compliance, legal and audit functions are now working to verify that AI systems operate as described by IT teams and to document oversight through training records, committee structures and meeting records, which examiners are specifically requesting.
Read the full Red Oak analysis
Copyright © 2026 RegTech Analyst
Copyright © 2018 RegTech Analyst





