Phillip Dickson · Founder, BastionAI · July 2026
As the leader of a registered investment advisory firm, I have evaluated numerous compliance software solutions. Nearly every AI compliance product on the market today shares a common characteristic:
They all begin to operate only after potential damage can occur.
For example, an advisor drafts an email using ChatGPT. The AI generates an inaccurate performance figure, and the email is sent. Minutes, hours, or even a review cycle later, the compliance tool flags the issue. A reviewer investigates, a remediation ticket is created, and the advisor must contact the client to address the error.
The industry refers to this as AI compliance, but it is more accurately described as AI-assisted filing—a faster, more efficient version of traditional filing systems. While search capabilities have improved, violations can still reach clients.
There are only two fundamental architectures, and every vendor aligns with one of them
Disregarding marketing terms such as AI-native platforms, real-time guardrails, and agentic supervision, every compliance product in wealth management is based on one of two architectures.
Detection reviews content after it is created. It scans sent emails, published posts, and archived messages, then flags, queues, and escalates issues. Detection is useful for reconstructing events and demonstrating oversight. However, detection only addresses violations after they have occurred. By that point, the client has already received inaccurate information, and sensitive data may have already been disclosed. The best possible outcome is a prompt remediation.
A firewall operates proactively. It sits between the advisor and any AI model, evaluating every prompt and response in real time against the SEC Marketing Rule, FINRA 2210, Reg S-P, and the firm’s policies. Prompts containing client account numbers are blocked before reaching the language model. Responses with unsubstantiated performance claims are prevented from reaching the advisor or the client. Violations are stopped before they occur.
Detection identifies what went wrong. A firewall prevents issues from occurring.
This is not a difference in features, but a fundamental architectural distinction determined from the outset. A review platform cannot become a firewall simply by adding AI to its queue, as the queue itself allows content to exist before review.
Why after-the-fact compliance is no longer sufficient
For two decades, after-the-fact review was standard because regulators also conducted retrospective examinations by sampling archives. This approach is changing, as regulators have now made clear.
SEC examiners are now asking RIAs — verbatim, per industry reporting this spring — for “documentation showing that AI-assisted recommendations are subject to human supervisory review before they reach clients.” Before. Not “show me your review queue.” Not “show me your archive.” Before they reach clients.
FINRA’s 2026 Regulatory Oversight Report says the same thing from a different angle. On AI agents, FINRA names the risks — unchecked autonomy, scope creep, auditability challenges — and prescribes the fix: “clear guardrails, human-in-the-loop oversight protocols and access controls from the outset.” From the outset. Not bolted on after deployment. Not discovered in the next quarter’s review cycle.
And the trade press has caught up to the logic. As InvestmentNews put it in June: “The platform you choose and the governance policy around it are the same decision — compliance exposure starts the moment an AI tool touches a client communication, before any output ever reaches a regulator.”
One securities-enforcement attorney summarized the entire enforcement record in a sentence this summer: “These were not technology failures — they were governance failures.” The technology worked exactly as designed. The governance arrived after the fact. That’s the whole story of every AI enforcement action to date, and it’s the story examiners are now built to look for.
The penalty regime got friendlier. That raises the bar, not lowers it.
Many vendors misunderstand this point, as they continue to focus on fear-based selling.
The SEC, under its current leadership, has shifted away from regulation-by-enforcement. The new cooperation framework allows for penalties to be eliminated for firms that identify, remediate, and document issues. However, many advisors mistakenly believe this reduces regulatory pressure.
The framework specifies that zero penalties are granted to firms that can demonstrate they had controls in place, identified issues, and resolved them. The new regime does not reward firms with no violations simply due to lack of oversight; it rewards those with documented evidence. A firewall provides this evidence continuously by generating an immutable log of every prompt, response, block, and human approval—creating the documentation examiners require, proactively.
In the new regulatory environment, successful firms are those that can demonstrate how their controls addressed issues, not merely claim that no issues occurred.
What an AI compliance layer actually does
In this context, a compliance layer is positioned between your team and any AI model. It performs four key functions for every interaction:
Screens the prompt. Client PII, account data, and restricted information are caught before they ever leave the firm.
Screens the response. Performance claims, hallucinated figures, and Marketing Rule violations are blocked before the advisor can use them.
Enforces firm policy. Approved tools, prohibited topics, and required disclosures are applied automatically for every advisor.
Creates an audit record. Every interaction generates an immutable, exam-ready audit entry.
Read the full article on our website.
How to evaluate compliance vendors
If you are looking at AI compliance tools this year, ask: When does your product step in? Before something reaches a client, or after?
That question matters more than any feature list.
BastionAI is building the answer. Learn more at bastionai.io.
Disclaimer: This post is for informational purposes only and does not constitute legal or regulatory advice.