Best Practices in AI Compliance: How Real Firms Are Making the Call

Jump CEO Parker Ence recaps how real firms handle AI disclosure, data retention, and PII protection, and where regulators still leave room to decide.
Questions about AI and financial services compliance rarely have a single right answer. Regulators have been clear that existing rules apply to AI, but short on specifics for exactly how, which leaves firm leaders and CCOs to work out the details themselves.
Jump CEO and co-founder Parker Ence recently broke down how compliance, risk, and legal teams at firms of every size, from solo advisors to some of the largest broker-dealers in the country, are approaching disclosure, data retention, and client privacy as they roll out AI. Here's what that looks like in practice, and how to think through it at your own firm.
Key takeaways:
- Most firms disclose AI meeting capture to clients even when it isn't legally required.
- There's no industry consensus yet on how long firms should retain raw AI meeting data.
- Human review stays the standard before any AI-generated content reaches a client or a permanent record.
What Financial Regulators Are Saying About AI
Guidance from the SEC, FINRA, and CFP Board converges on five common themes:
- Existing rules apply: There aren’t yet any new AI-specific regulations, but existing supervision/oversight rules extend to AI.
- Firms are responsible: Advisors are responsible for AI outputs and actions, requiring functional understanding of the technology.
- Protect client data: Protecting clients may require disclosure, consent, privacy, confidentiality, and recordkeeping considerations.
- Govern AI programs: Firms should include AI governance in their policies and procedures. This includes conducting due diligence on AI vendors.
- Keep a human in the loop: A responsible person should review AI outputs, especially public-facing or part of permanent records.
Practical AI Compliance Considerations for Financial Advisors
- Disclosure of meeting capture is standard, even where it isn't strictly required: Regardless of whether your state requires one-party or all-party consent, disclosing AI meeting capture to clients has become the norm. If you're rolling out AI-assisted meeting capture across a large firm, pairing visual and audible disclosure covers accessibility too. If you're weighing whether disclosure is legally required for your state, the safer bet is to disclose anyway. It may hold up better under scrutiny than trying to argue an exception.
- Clients take their cue from you: A client asking to go off the record is rare, and a client canceling over it is rarer still. If you're nervous about bringing it up, keep it simple: a short, casual line like "I'm going to use my note-taking technology so I can focus on you instead of typing, is that okay?" does more work than a formal disclosure ever could, because, as Parker says, "the client is only going to feel weird about it if you're weird about it."
- Data retention still comes down to your own risk tolerance: Some firms keep full video, audio, and transcripts on hand indefinitely for reference and documentation. Others auto-delete raw meeting data after a set window, and some skip recording entirely in favor of real-time summarization with no file created at all. There's no regulatory consensus yet, so the right retention window has less to do with finding "the answer" and more to do with how your firm weighs documentation value against exposure risk. Jump supports recording, transcription-only, or summary-only workflows so firms can follow their preferred policies.
- Human review is still the guardrail, no matter how much AI is doing: Whether AI is drafting meeting summaries, CRM updates, or account opening paperwork, review before anything goes external or gets saved to a permanent record is close to universal practice. AI can produce the first draft, but a person is still responsible for what actually goes out the door.
What to ask before you bring on an AI vendor
Before you sign with any AI partner, get clear answers on the same questions any CCO would ask about the rest of your tech stack, just applied to AI.
- Vendor and AI model due diligence: Ask whether the vendor can clearly explain which AI models they use and where your data is processed and stored. A vendor that can't give you a straight answer here usually can't give you one anywhere else either.
- Data handling, ownership, and security: Confirm who owns the data, whether it's ever used to train a model, and whether the vendor has independent verification like SOC 2 Type II and a penetration test report on file. Full data ownership, and a guarantee your data isn't sold or shared for advertising, should be table stakes at this point, not a differentiator.
- Human oversight, end to end: This applies both to what the AI is producing and to what it's allowed to do on its own. Every AI output, whether it's a CRM update, a client email, or compliance documentation, should get reviewed by a person before it's saved or sent, and no AI agent should be able to take an action, like updating a record or pushing something out, without someone approving it first.
- Regulatory enforcement and incident response: Compliance settings should be enforceable firm-wide, not left to individual advisor discretion. The vendor should be able to tell you exactly what happens, and who gets notified, if something goes wrong. If either answer is vague, that’s a red flag.
If you wouldn't be comfortable explaining any of this to a regulator in plain language, it's worth pushing the vendor for more before you sign.
Watch the full session
To learn more, visit our resource library and trust center for a closer look at how we handle AI safety, data protection, and compliance configuration in detail.
The information provided by Jump is for informational purposes only and does not constitute legal advice. You should consult with your own qualified legal counsel regarding any legal questions or decisions specific to your circumstances.