Sixty-four per cent of financial services firms are already investing in AI.[1] That number is not surprising. What is surprising is how few of those investments are producing anything that a firm’s clients or regulators would recognise as genuinely better outcomes. The gap between deployment and results is the defining challenge for advice firms in 2026, and it is widening.

This is not an argument that AI is overhyped. It is an argument that most firms are going about adoption in the wrong order. The firms that tend to benefit are not the ones spending the most. They are the ones that are clear about what problem they are solving before they buy anything.

What is actually changing, and why it matters for advice firms

AI in financial services is no longer a forward-looking topic. It is a present operational reality. TCS, one of the largest technology services firms in the world, has partnered with Anthropic to deploy Claude across its own operations and to build industry-specific AI products for regulated sectors.[2] EIOPA has made a data-driven culture a stated strategic priority in its 2025 annual report, actively supporting industry efforts to use AI for risk management.[3] The infrastructure is mature. The question is not whether to adopt, but what to adopt and how to govern it.

For an IFA or wealth management business, that means cutting through a lot of noise to reach the handful of decisions that actually matter. The practical areas where AI is generating real value for advice firms right now are:

  • Client meeting preparation and follow-up. AI tools that read a client’s file, recent interactions, and portfolio position ahead of a meeting can draft initial notes and flag items for the adviser’s attention, with human review of outputs before anything is acted on or sent.
  • Compliance workflow support. Monitoring, flagging, and documentation tasks that are rule-bound and repeatable, with a qualified person reviewing what the system surfaces.
  • Paraplanning support. First-draft report generation, research synthesis, and suitability letter drafting, all requiring human review before any document reaches a client.
  • Operational triage. Routing incoming queries, categorising documents, and surfacing exceptions that need a human decision.

Aaron Klein, founder of Conteo, has built an AI-driven “operating system for meetings” that prepares financial advisers for client reviews using prior conversation data.[4] It is a narrow, specific application. That narrowness is deliberate and it is worth copying as a principle.

The governance problem that most firms are not taking seriously

Here is where honest advice diverges from optimistic sales copy.

The gap between deploying AI and being able to secure, evaluate, and govern it is creating liability exposure for regulated firms.[5] Twenty-one per cent of finance firms report having AI pilots that have not reached production.[6] The most common reason is not technical failure. It is that the governance controls required to take an AI system into production in a regulated environment were not designed at the outset.

The FCA has noted significant variation across firms in their approaches to risk assessment, and there is a risk that firms deploying AI without adequate governance frameworks could draw closer regulatory scrutiny as a result.[7] Customer-facing AI in financial services can present real risks of client discrimination if systems lack proper validation.[8] That is not a reason to stop. It is a reason to build carefully.

The firms that benefit from AI adoption are not the ones deploying the most tools. They are the ones that know, for each tool, exactly who reviews its outputs before anything reaches a client or a regulator.

Three specific governance failures are appearing repeatedly in firms I talk to:

Treating AI output as a finished product. A suitability letter drafted by an AI system is a starting point for a qualified adviser, not a deliverable. This sounds obvious. In practice, under time pressure, the distinction erodes. It needs to be architectural, not cultural: the system should not allow an AI-drafted document to be sent without a named human sign-off step.

Sharing credentials between AI agents and core systems. Fifty-four per cent of enterprises have experienced an AI agent security incident, and the majority continue to allow agents to share credentials.[9] For a firm holding client financial data, that is a breach pathway, not a configuration risk.

Buying infrastructure faster than you can measure what it costs. AI spend is growing faster than the frameworks to attribute it, evaluate it, or justify it.[5] In a regulated business, that is not just a financial control weakness. It is a governance failure.

What Level 1, Level 2, and Level 3 actually means for your firm

Most firms arrive at AI conversations thinking they need a custom build. Most do not.

Level 1 (education) covers everything that is already inside tools you are paying for. Microsoft 365 Copilot, built into your existing licence. Improved prompting of the AI tools you already use. A template library for paraplanning first drafts. These require no additional spend and no integration work. For many firms, Level 1 alone would produce six to ten hours a week of recovered capacity across a paraplanning or admin team.

Level 2 (integration) is where two or three existing systems are connected so that information flows between them without manual re-entry. A CRM that updates automatically after a client call. A compliance checklist that is triggered by a case reaching a certain stage. This is configuration work, typically taking days to a few weeks and costing hundreds to low thousands of pounds, not a major technology project.

Level 3 (custom build) is real engineering: bespoke pipelines, complex logic, orchestration across multiple data sources. This is appropriate for a small number of firms with genuinely complex, high-volume problems. It is not the right starting point for most advice businesses.

The discipline is always to try Level 1 first. The majority of firms that come to me expecting a Level 3 engagement find that their most pressing problems are Level 1 or 2.

A practical roadmap for the next ninety days

This is not a transformation programme. It is a sequence of decisions a senior decision-maker can move through without a major project.

First, list the five tasks in your firm that consume the most time relative to their complexity. Not the tasks that feel strategic. The ones where qualified people are spending hours on work that is rule-bound, repetitive, and does not require their professional judgement. These are your Level 1 candidates.

Second, for each task, ask whether a tool you already pay for can do it with better prompting or configuration. Before you buy anything new, your Microsoft 365, your CRM, and your back-office platform all have AI features that most firms are not using. This is a one-hour audit, not a project.

Third, identify one workflow where two systems should talk to each other but do not. The most common example in advice firms is the gap between a client meeting note and the compliance record. If someone is manually copying information between systems, that is a Level 2 candidate.

Fourth, before anything touches a client or a regulatory output, define who reviews it and what they are signing off. This is the governance question that most implementations skip. Answer it in writing before you deploy, not after an incident.

Fifth, treat AI spend like any other operational expenditure. What does it cost? What does it produce? Who is accountable for the answer? If you cannot answer those three questions for an AI tool your firm is already using, that is the problem to solve before adding more.

Where cybersecurity fits into this picture

One area that deserves specific attention: Anthropic’s own research has indicated that powerful AI models could be widely accessible to attackers within six to twelve months.[10] For a regulated firm, this is not an abstract concern. It means the attack surface for AI-enabled fraud and social engineering is expanding faster than most compliance frameworks have been designed to handle.

Client identity verification workflows, voice and video-based authentication, and any process that relies on a human recognising another human as genuine are now material risk areas. This does not require a new technology programme. It does require that your existing fraud and impersonation controls are reviewed with this specific threat in mind.

The honest summary

In the medium term, most financial services firms will need to engage seriously with AI to remain operationally competitive. But firms that treat it as an urgent transformation programme, buying infrastructure before they have governance, deploying tools before they have defined who reviews the outputs, and measuring success by the number of tools in use rather than outcomes for clients, could face regulatory scrutiny and client harm as a result.

The firms that will look back on 2026 as a turning point are the ones that started with a precise problem, chose the simplest intervention that addressed it, and built the governance architecture before the deployment, not after.

If you want to think through where your firm sits in this picture, a discovery call with Cordrey Consulting is a good place to start.


This article is for informational purposes only and does not constitute regulated financial advice or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.


Sources

[1] Emerj, ‘AI in Financial Services Executive Cheat Sheet’, Emerj Artificial Intelligence Research, 2026. Available at: https://emerj.com/fcs1 [Source date unconfirmed; treat statistic as indicative.]

[2] Anthropic, ‘TCS and Anthropic partnership announcement’, Anthropic, June 2026. Available at: https://www.anthropic.com/news/tcs-anthropic-partnership

[3] EIOPA, ‘Annual Report 2025’, European Insurance and Occupational Pensions Authority, 2026. Available at: https://www.eiopa.europa.eu/publications/annual-report-2025_en

[4] fintech-impact, episode featuring Aaron Klein, Founder, Conteo, 26 May 2026. [Cited for named application of AI in financial adviser meeting preparation.]

[5] VentureBeat (2026) ‘The AI compute gap: enterprises are buying infrastructure faster than they can measure what it costs’, VentureBeat, 21 July 2026. Available at: https://venturebeat.com/ai/the-ai-compute-gap-enterprises-are-buying-infrastructure-faster-than-they-can-measure-what-it-costs

[6] Zen van Riel (2026) ‘AI agent scaling gap: pilot to production’, AI Engineer Blog, June 2026. Available at: https://zenvanriel.com/ai-engineer-blog/ai-agent-scaling-gap-pilot-production-2026 [21% figure for finance sector pilots not reaching production.]

[7] FCA (2026) ‘Non-handbook guidance: CorePRU 7 overall risk assessment’, Financial Conduct Authority, July 2026. Available at: https://www.fca.org.uk/publications/guidance-consultations/gc26-4-non-handbook-guidance-corepru-7-overall-risk-assessment

[8] European Central Bank (2024) Research evidence on customer-facing AI discrimination risks in financial services. [Industry report cited for validation requirements in customer-facing AI deployments.]

[9] VentureBeat (2026) ‘The agent security gap: 54% of enterprises have already had an AI agent incident and most still let agents share credentials’, VentureBeat, 18 July 2026. Available at: https://venturebeat.com/ai/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-agents-share-credentials

[10] Anthropic (2026) ‘Expanding Project Glasswing’, Anthropic, June 2026. Available at: https://www.anthropic.com/news/expanding-project-glasswing