Nothing has to go wrong. Inadequate written procedures for the agents a firm’s staff are already building is itself the violation, charged on its own, before anyone is harmed; and if it does go wrong, the penalty is rarely the part that ends a fund.
The mechanism
Rule 206(4)-7 makes it unlawful for a registered adviser “to provide investment advice unless the adviser has adopted and implemented written policies and procedures reasonably designed to prevent violation of the Advisers Act by the adviser or any of its supervised persons.” Read the structure rather than the words. The rule conditions the business itself, rather than adding one more filing deadline.
The Commission was explicit about why, in the release adopting it: “Failure of an adviser or fund to have adequate compliance policies and procedures in place will constitute a violation of our rules independent of any other securities law violation,” which lets it act “before that failure has a chance to harm clients or investors.” No predicate fraud, no loss, no complaining client. Where staff build agents that touch client data, trading or client communications and the firm’s written procedures fail to reach them, the exposure exists on that fact alone.
This is why “there is no AI rule” and “you are already regulated” are both true. Technology neutrality is deliberate: FINRA’s rules “are intended to be technology neutral” and apply to Gen AI “just as they apply when member firms use any other technology or tool” (Regulatory Notice 24-09, 2024-06-27, member firms only). The notice creates no new requirement and needs none. Waiting for an AI rule is waiting for something already decided not to exist.
Anyone calling this a books-and-records technicality is wrong, and a footnote in the same release says so. The Commission changed the rule text from “a fraudulent, deceptive, or manipulative act” to “unlawful” because commenters disliked the optics, and recorded that the change “does not change its substance; failure to comply with its terms will result in a violation of section 206(4)”, the antifraud provision.
The independent-violation theory is already operating in a live AI matter. In March 2024 the SEC settled with Delphia and Global Predictions over AI claims they could not support, for $225,000 and $175,000. The charges included the Marketing Rule, which everyone expects, and Rule 206(4)-7, which they do not, the compliance-program charge riding along with the rest.
The governance version of the case already exists, and gets missed because nobody files it under “AI.” In January 2025 the SEC settled with Two Sigma Investments and Two Sigma Advisers for $90 million in penalties, after the firm had already voluntarily repaid $165 million. The charge was breach of fiduciary duty for failing to reasonably address vulnerabilities its own employees had identified in its investment models, plus failure to adopt and implement written policies to mitigate them, plus failure to supervise an employee who made unauthorised changes to more than a dozen models. The vulnerabilities were known by March 2019 and fixed in August 2023. Nothing about that fact pattern requires an LLM: it is a sophisticated firm with a mature compliance programme, an automated decision system nobody re-reviewed, and a change-control process someone walked around. On the broker-dealer side the smaller analogues run the same way: FINRA fined Interactive Brokers $475,000 over a faulty securities-lending algorithm with no direct monitoring of its creation, launch and testing, and Brex Treasury $900,000 over an identity-verification algorithm it had not reasonably designed.
The common misreading in this market is that the SEC backed off. It withdrew three relevant proposals on one day in June 2025: adviser cybersecurity (206(4)-9), outsourcing (206(4)-11), and predictive data analytics. So there is no 48-hour incident report to the SEC, no Form ADV-C, no standalone AI or cyber rule for advisers, and any vendor deck still promising those is stale. Withdrawal removed specificity, not jurisdiction. Section 206, the compliance rule and the marketing rule never depended on the proposals, and a principles-based regime is the harder one to satisfy, because no checklist ends the argument.
Which regime binds the firm decides everything downstream. An adviser-only firm answers to the Advisers Act; a broker-dealer to FINRA and the Exchange Act; a dual registrant to both. An exempt reporting adviser escapes most of those rules and not the antifraud provisions, so AI-washing exposure lands on ERAs too.
On examinations, be careful what has actually been said. The FY2026 priorities fold AI into cybersecurity, emerging technology, automated investment tools and operational resiliency. Securities counsel read that as signalling that AI oversight “will be a component of virtually all examinations going forward, not merely examinations of firms specifically marketing AI capabilities.” Well founded, and a reading; the Commission has not committed to it. Note separately that the attack vectors the SEC names are polymorphic malware and deepfake-enabled social engineering. Prompt injection and tool poisoning are absent, so satisfying the exam priorities and being safe are different achievements. The gap belongs to the SEC’s list rather than to regulators as a class: FINRA’s March 2026 explainer gets the mechanism right, describing prompt injection as exploiting a system’s legitimate access rather than requiring unauthorised entry, and the two regulators sit in different places on this.
Now the stakes, in the Commission’s accounting rather than a consultant’s. The costs of a violation “may consist of much more than merely the fines or other penalties levied by the Commission or civil liability. The reputation of a fund or adviser may be significantly tarnished, resulting in redemptions (in the case of an open-end fund) or lost clients.”
For calibration: penalties are per violation, last adjusted January 2025 with no 2026 adjustment. Entity tiers run $118,225, $591,127 where there is fraud or reckless disregard, and $1,182,251 where the conduct also created substantial losses or their risk. Individual tiers are $11,823, $118,225 and $236,451. That column changes behaviour at a 40-person firm, because the CCO and the responsible supervisor are personally exposed. Per-violation counting is what makes the headline figures misleadingly small, and the Commission decides the count.
The remedies practitioners fear sit outside the fine column. A cease-and-desist order is public and permanent, so an allocator’s questionnaire surfaces it for years. The Commission can require an independent compliance consultant at the firm’s expense, and under §203(e) and §203(f) it can limit activities, revoke registration, or bar individuals.
For a fund of 20 to 500 people the redemption is worse than the penalty. The action is disclosable, the disclosure reaches investors and their consultants, and capital moves. Clients have reporting duties of their own, and a public order naming the firm is something they must act on whether they want to or not.
What to do
Establish which regime binds the firm and write it down. Adviser-only, broker-dealer, dual or ERA decides which pages in this wiki apply at all. Most of them assume adviser-only.
Take the ten topics 206(4)-7 says procedures should address and ask which an agent already touches: portfolio management, trading practices, proprietary and personal trading, accuracy of disclosures to investors and regulators, safeguarding client assets, accurate creation and maintenance of records, marketing, valuation, privacy safeguards, business continuity. That mapping is the assessment, and it is an afternoon. The agent inventory is its denominator; without one the answer covers only the agents someone happens to know about.
Note the sequence the Commission mandates, because most firms invert it: identify the conflicts and risks arising from the firm’s particular operations first, then design procedures against them. A policy written before anyone looked at what the agents do satisfies nothing.
Use the withdrawn outsourcing rule as a tiering rubric rather than mourning it. Its “covered function” test (necessary to providing advisory services in compliance with the securities laws, where negligent performance would be reasonably likely to cause material client harm) is a defensible standard the regulator drafted, though it carries no force of law. As a first cut at which agents and vendors deserve real diligence it beats anything drafted from scratch, so feed it into risk-tier assignment.
Date the assessment to when the rollout happened. Exams look hard at firms that changed their business model or are new to a service, and a firm-wide agent deployment is both. A contemporaneous record beats a reconstruction written the week the exam letter arrives.
How you’d know it’s working
Compliance can say which agents touch which of the ten enumerated topics, without asking IT.
The AI policy is filed under 206(4)-7 alongside the other procedures rather than sitting apart where nobody reviews it annually. See recordkeeping and compliance gaps for why an imaginary AI rule is the wrong home for it.
Someone can state in one sentence, correctly, which regulator examines the firm and under which rules. If that answer names 17a-4 at an adviser-only firm, the program is built on a mistake.
What this doesn’t solve
This page covers exposure rather than mitigation. It says what failure costs and why the absence of an AI rule offers no relief. The controls that reduce it live elsewhere.
Escalation from deficiency letter to enforcement to penalty is contingent at every step, and nothing here should be read as claiming otherwise. Most exam findings end in a deficiency letter and remediation. The remedies above are what the Commission can do, sourced to the statutes authorising them, rather than a forecast of what it will do.
No enforcement action has yet named an agent built by a non-engineer. Two Sigma involved quantitative investment models maintained by professionals, not an LLM agent assembled by an analyst, and the step from one to the other is ours. The step is short, since unreviewed automation and a walked-around approval process are the same failure in both, and it remains a step.
Criminal exposure under 18 U.S.C. §1348 reaches twenty-five years, covers schemes to defraud, and is prosecuted by DOJ. A weak compliance program is a separate matter, and pairing the two would be scaremongering.
One figure that circulates here belongs elsewhere: the 2024 sweep of four firms over misleading cybersecurity disclosures, penalties from $990,000 to $4 million, comprised public-company disclosure charges rather than adviser matters.
Non-US regimes are out of scope. The EU AI Act’s operational consequences are in frameworks, and a fund’s agents are very likely not high-risk under it.
See also
- When to involve legal and compliance — the triggers, the notification clocks, and which conversations are actually privileged.
- Compliance as an approver — why a CCO cannot sign off on an agent fleet nobody can describe, and what they need in order to.
- Recordkeeping and compliance gaps — the retention floors and the platform default sitting below all of them.
- Exam readiness — what a regulator asks for, and the drill that shows whether a firm can produce it.
- Agent disclosure — AI-washing, Form ADV, and what clients have been told about how the agents work.
- Governance — where this sits in the firm, and why not to build a parallel structure to hold it.