The US still has no federal AI law — and unlike the EU, the direction of travel has not been toward one. What governs a US adviser’s AI use instead is supervision through existing securities law, an active enforcement line on AI claims, and a voluntary framework that functions as the de facto standard.

The state patchwork that wasn’t

Firms that built plans around a hardening US state patchwork should re-check those assumptions. Colorado’s pioneering AI Act — the first comprehensive state statute aimed at algorithmic discrimination — was delayed from February to June 2026, then substantially revised and pushed to January 2027 by a replacement bill signed in May 2026, with enforcement of the original law also tangled in litigation.

SEC: examination priorities and the AI-washing line

What fills the gap is supervision. The SEC’s examination priorities for fiscal 2026 put adviser use of AI squarely in scope: examiners will look at whether firms have policies and procedures to monitor and supervise their AI use, whether staff are trained, and — pointedly — whether representations about AI capabilities are accurate [1].

That last item reflects the SEC’s continuing “AI washing” enforcement line, which began in March 2024 with charges against two investment advisers for false and misleading statements about their use of AI [2]. The practical rule: every AI claim in your marketing — including claims your vendors made and you repeated — needs substantiation you can produce.

FINRA: generative-AI expectations for broker-dealers

For broker-dealers, FINRA’s 2026 Regulatory Oversight Report devotes a section to generative AI: assess compliance obligations before deployment, establish governance over usage, address hallucination and bias, and keep humans monitoring outputs — with early attention to autonomous AI agents [3].

NIST: voluntary, but what examiners recognise

On the framework side, the NIST AI Risk Management Framework remains voluntary but is the de facto US reference for AI governance [4]; in February 2026 the US Treasury, with the Cyber Risk Institute, released a Financial Services AI Risk Management Framework mapping NIST’s structure into sector-specific control objectives. Neither is law; both are what a US examiner will recognise as good practice.

What this means in practice

The US regime rewards exactly the converged core in the overview — inventory, named owner, human review, vendor due diligence, records — with one US-specific emphasis: substantiation of AI claims. If your firm serves US clients from elsewhere, note that promotion rules attach where material is received: one AI-drafted commentary sent to a mailing list spanning the EU, UK and US can engage the SEC’s AI-washing line alongside European transparency obligations. The cross-border mechanics are covered in AI governance for cross-border financial advisers.

This article is for informational purposes only and does not constitute regulated financial advice, legal advice, or a compliance opinion. Consult a qualified compliance professional for advice specific to your firm.

Sources

[1] US Securities and Exchange Commission, ‘SEC Division of Examinations Announces 2026 Priorities’, November 2025. Available at: https://www.sec.gov/newsroom/press-releases/2025-132-sec-division-examinations-announces-2026-priorities

[2] US Securities and Exchange Commission, ‘SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence’, March 2024. Available at: https://www.sec.gov/newsroom/press-releases/2024-36

[3] FINRA, ‘2026 FINRA Annual Regulatory Oversight Report — GenAI: Continuing and Emerging Trends’, December 2025. Available at: https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report/gen-ai

[4] NIST, ‘AI Risk Management Framework’, accessed July 2026. Available at: https://www.nist.gov/itl/ai-risk-management-framework