The disclosure exposure runs in both directions, and it attaches to what the marketing team wrote rather than to what the engineers built. Overstating what the agents do is the obvious half. A regulator testing whether a claimed AI capability is real is the half nobody prepares for.

The mechanism

IOSCO puts it without hedging: misleading claims about AI development, implementation, use, function or performance “can be the basis for enforcement actions against market participants in certain jurisdictions.” Its member survey found firms failing to disclose AI use in portfolio management, misrepresenting AI-related investment activity, making false statements about the level of implementation of AI in research or security selection, and reporting false performance attributed to AI. The named population is this wiki’s reader: the survey observed these failures “specifically with respect to certain asset managers, fund managers, and issuers.”

The three artifacts an examiner reads against each other are marketing materials, Form ADV, and client communications. They will also test the inverse: a firm claiming AI drives portfolio management has to show the tools “genuinely influence investment decisions rather than serve merely as supplemental research.” A pilot that ran once and a deck that says “AI-driven investment process” are a disclosure problem even when the pilot was honest work.

Enforcement here predates any AI rule. Delphia and Global Predictions settled in March 2024 for $225,000 and $175,000 over AI claims they could not support, charged under the antifraud provisions and the Marketing Rule. Rule 206(4)-1 requires that advertising avoid untrue statements of material fact and not discuss potential benefits without fair and balanced treatment of the risks. An agent that generates marketing copy is subject to that rule with nobody in the loop.

The trap most firms walk into is subtler than lying. The SEC’s compliance-program release states, in the fund context, that failing to adhere to a disclosed policy “may render the prospectus disclosure materially misleading” and violate Securities Act §17(a), Exchange Act §10(b) and Rule 10b-5. Written carefully, an aspirational AI-use policy nobody enforces is worse than no policy: the document creates the liability. Note also the third audience in the enumerated compliance topics: “the accuracy of disclosures made to investors, clients, and regulators.” An overstated description of a firm’s agent program in a due-diligence questionnaire or an exam response is inside that topic, not adjacent to it.

Three failure modes that come from operations rather than marketing. A system gets scaled back or retired and the website still describes it, because the decommissioning process updated the registry and nothing else. A wrapper around a vendor model gets called “proprietary.” And nobody owns the channel through which a client, an employee or a journalist flags an overstatement, so the first time the firm hears about it is from someone with subpoena power.

Then the narrower question of whether the agent says it is one. Most deployed agents do not: of the 30 systems in the 2025 AI Agent Index, 21 have no documented default disclosure behaviour and 3 support watermarking, with enterprise platforms shifting the burden onto the deploying firm. IOSCO treats disclosure-at-every-interaction versus one-time disclosure as a live supervisory question rather than a settled one. In the EU, Article 50 transparency survives the timetable changes and applies from August 2026. In the US there is no general rule requiring an agent to identify itself to a client, and the exposure runs through the antifraud and communications rules instead.

Scope, because it decides which paragraph above applies to a given firm. Form ADV and Rule 206(4)-1 are adviser instruments; a broker-dealer has neither. FINRA’s parallel is Rule 2210, which requires that retail communications mentioning AI “accurately describe how these offerings incorporate AI technology and balance the discussion of benefits with appropriate discussion of risks,” and its chatbot practice requires retaining both the communications and the chat sessions. Rule 2210 binds member firms only. The interpretations that actually decide chatbot cases are two entries in FINRA’s advertising-regulation FAQ, B.4 on supervising chatbot communications and D.8 on AI-created communications; Notice 24-09 points at them by name rather than restating the rule.

What to do

Create a substantiation record for every AI claim in client-facing material, and gate publication on it. IOSCO names this as the artifact supervisors expect and asks what internal controls validate claims “before they appear in disclosure documents.” Nobody ships an AI claim without evidence on file. This is cheap, it is Day 1, and it is the single control that answers most of this page.

Run the three diagnostic tests IOSCO borrows from a Canadian continuous-disclosure review over the firm’s own deck before someone else does: are capability claims supported by facts and activity; do leadership claims match the financials; is disclosure emphasis proportionate to what the technology actually contributes.

Give retirement a disclosure step. When an agent is decommissioned or scaled back, the same ticket that updates the registry should ask what public material described it; see offboarding.

Decide the Form ADV question with counsel rather than by default. Part 2A requires disclosure of methods of analysis and investment strategies, so the trigger is an agent’s participation in formulating investment advice, not AI use generally. An agent drafting meeting notes is out. An agent screening or ranking securities is arguably in. Counsel writing on this say advisers “should consider whether” the brochure should describe AI-based analytical methods, and the hedge is counsel’s own. Part 2A also limits the brochure to conflicts a firm actually has or is reasonably likely to have, so generic AI-risk boilerplate is not a safe default either.

Say the honest thing. A firm describing its agent as “a summarization tool with human review” carries less exposure than one whose pitch deck says “AI-driven investment process,” and the second firm usually has the same tool.

How you’d know it’s working

Someone can produce the substantiation file for the AI claims currently on the firm’s website and in its last investor letter. If no such file exists, the claims are unverified by construction.

A named person owns correcting public descriptions when a system changes, and one instance where that happened can be named.

Ask a portfolio manager and the head of marketing, separately, what the agents do. The gap between the two answers is the exposure, measured directly.

What this doesn’t solve

This is the disclosure axis only. Whether the agent works is unreliable output; whether the records were kept is recordkeeping and compliance gaps.

No enforcement action has been brought over an agent that failed to identify itself. The AI cases so far are about firm-level claims, not agent-level self-disclosure, and treating the second as settled because the first exists would be overreach.

The observed failure modes come from an IOSCO member survey with no per-jurisdiction attribution and no case citations, and the worked example of bad disclosure is an issuer continuous-disclosure matter rather than an adviser one. The pattern is well evidenced; the specific frequency is not.

There is no Form ADV Part 2B analogue for an agent. Part 2B covers the individuals who provide advice, and an agent that materially shapes advice appears nowhere. That is a real gap in the disclosure architecture and nobody has closed it — see open questions.

See also

  • Regulatory exposure — what an inaccurate disclosure costs, and why the compliance-program charge rides along with the marketing charge.
  • Unreliable output acting on your systems — the gap between what the agent does and what the firm believes it does, which makes disclosure hard.
  • Agent inventory and registry — the record of what each agent actually does, and the raw material a substantiation file is built from.
  • Exam readiness — the disclosure questions a supervisor brings, taken from IOSCO’s published question bank.
  • Registry review cadence — where stale claims get caught, if anywhere.
  • Frameworks — EU AI Act Article 50 and why it amounts to less of a cliff edge than it looks.