SEC 2026 exam priorities — AI use and AI washing
Author
Audrey
NobleCloak's AI Correspondent · AI-drafted, fact-checked against our sourced evidence before publishing.
Date Published
What happened
In November 2025, the SEC's Division of Examinations published its Fiscal Year 2026 Examination Priorities — the annual signal of where examiners will spend their attention across investment advisers and other registrants. Artificial intelligence runs through the document in three distinct ways, and it's worth separating them because they call for different evidence.
First, AI use. The Division says it will look at whether advisers have policies and procedures to monitor and supervise the AI technologies they've adopted across their operations — not just in the investment process, but wherever AI has crept into the firm.
Second, "AI washing." Examiners will scrutinize misleading or overstated claims about a firm's AI capabilities or the role AI plays in its investment process. The test is alignment: do a firm's marketing materials, Form ADV disclosures, and client communications accurately describe the extent, nature, and limitations of how it actually uses AI? If you say AI drives your portfolio decisions, examiners will expect to see AI genuinely driving them — not a research assistant dressed up in the language of a strategy.
Third, AI-enabled cybersecurity risk. The priorities flag the security controls firms use to identify and mitigate new AI-driven threats — including AI-enabled social engineering such as deepfake-driven phishing. And notably, the same document carries Regulation S-P and Reg S-ID forward as named priorities, with their emphasis on written policies, incident response, and vendor oversight.
The priorities are, as the commentary noted, largely consistent with prior years. That's the point. This isn't a new rule. It's the examiner telling you, in advance, which existing obligations they'll pull the thread on.
Why it matters
A quiet but important fact sits underneath all of this: the SEC has not issued a standalone AI rule for advisers. The proposed predictive-data-analytics rule did not become a final requirement. So the AI items on the 2026 list are not enforcing an AI-specific mandate. They are applying rules you already live under — the marketing rule, the compliance-program rule, Reg S-P, your fiduciary duty — to the AI you've adopted.
"AI washing" is the sharpest version of that. It is not a new offense. It's the anti-fraud and marketing rules meeting a firm that described its technology more impressively than the technology performs. The exposure is a gap — the distance between what your disclosures say about AI and what your operations actually do. That gap can open two ways. The obvious one is overstatement: the firm that markets an "AI-driven" strategy running on a spreadsheet and a subscription. The subtle one is the reverse — the firm quietly using AI across client communications and research that its Form ADV and policies never mention at all. Both are misalignments, and alignment is exactly what examiners said they'll test.
The cyber angle connects to the same nerve. AI-enabled phishing and deepfakes make the service-provider and incident-response controls in Reg S-P more load-bearing, not less. An examiner reviewing your AI posture and your Reg S-P file is reviewing one continuous question: do you know what AI is operating in and around your firm, and can you show the controls?
What it means for you
If you're an RIA or broker-dealer: this is your list, and the do-this-Monday version is concrete.
- Reconcile your AI disclosures with your AI reality. Pull your Form ADV, your website, your pitch decks, and your client communications, and line every AI claim up against what your firm actually does. Where you say "AI," be able to point to the tool, its role, and its limits. Where you use AI but never disclosed it, decide whether it needs to be described. This reconciliation is the single most valuable hour you'll spend before an exam.
- Write the AI-supervision policy you're assumed to have. Examiners expect procedures to monitor and supervise the AI technologies you've adopted. A short, honest policy that names your AI tools, assigns oversight, and states your limits beats an elaborate one you don't follow.
- Fold AI into your Reg S-P vendor oversight. Your service providers are adding AI; that's covered ground in the silent expansion of your third-party AI surface. The oversight file you build for Reg S-P is the same file that answers the exam's AI-use question. Build it once — the step-by-step is in the Reg S-P oversight playbook.
If you're a bank or credit union: the SEC's list isn't your regulator's, but don't look away. AI washing is a disclosure-integrity problem, and the same logic — your public claims about AI must match your operations — is exactly how your own examiners think about consumer-facing statements and third-party oversight. And the AI-enabled-phishing warning is regulator-agnostic; deepfake social engineering doesn't check your charter type. Read the SEC list as a preview of the questions coming to every regulated compliance owner, worded first for advisers.
How to get ahead of it
The prepared adviser turns "AI washing" from a risk into a non-event with one artifact: an honest, current inventory of where AI actually operates in the firm — in the investment process, in client communications, in operations, and inside your vendors' products — paired with the disclosures that describe it accurately. Do the reconciliation before the examiner does. When your Form ADV, your marketing, and your operations tell the same story about AI, "AI washing" has nothing to catch.
Then keep it current. AI use in a firm drifts — a new tool here, a vendor feature there — and last year's honest disclosure becomes this year's quiet overstatement or omission. A dated inventory you refresh is what lets you say, at the exam, "here is every place AI touches this firm, here is what we told clients, and here is why those two match." That sentence is the whole game.
What to watch out for
The trap is treating AI washing as a marketing cleanup — softening a few website adjectives — while the operational reality goes uninventoried. Toning down your copy without knowing what your firm and your vendors are actually running just moves the gap somewhere an examiner can still find it. The fix is reconciliation, not word-smithing.
The second trap is the overcorrection: scrubbing every mention of AI to avoid scrutiny, while your staff quietly use AI tools that now appear nowhere in your policies or disclosures. Silence isn't safety here — undisclosed, unsupervised AI use is its own finding. And be wary of vendors selling "AI-washing compliance" as a product; there's no such certificate. What genuinely protects you is the boring, honest inventory and the disclosures that match it — not a badge.
The bottom line
The SEC's 2026 priorities don't create an AI rule; they promise to test whether your AI story is true — whether what you say about AI matches what you and your vendors actually do. The firm that wins that exam is the one that already reconciled its disclosures against a current inventory of its real AI footprint. Surfacing that footprint — including the AI your vendors added without telling you — is exactly what a Discover scan is built to do.
Get your Reg S-P AI vendor file. We run it with you.