Share with your CISO
AI compliance anxiety among investment advisors has hit a level the ACA Group calls unprecedented in 21 years of annual surveys, with 85% of respondents naming AI their top compliance concern, 50 percentage points ahead of cybersecurity in second place. The jump from last year is 28 points. But the ACA Group’s 2026 Investment Management Compliance Testing Report, drawing on 411 firms surveyed in spring 2026, shows firms building governance scaffolding faster than they’re filling the critical gaps: fewer than half have formal human-in-the-loop oversight plans, and only 30% have policies covering third-party AI use.
What this means for your business
The story here isn’t the anxiety number, it’s the shape of what’s missing. Firms have rushed to write policies (86% have employee AI use policies) and stand up governance committees (59%), which are the visible, auditable moves that satisfy a regulator asking “what have you done?” What they haven’t done is instrument the actual risk surface: who’s validating AI outputs before they reach a client, and what happens when a vendor’s AI model drifts. If your firm is in that 80% using AI tools, the question isn’t whether you have a policy document; it’s whether anyone is actually running the checks the document describes.
The third-party gap deserves its own reckoning. Only 30% of firms have policies governing third-party AI use, yet most enterprise AI deployments aren’t homegrown, they run on vendor models embedded in portfolio management, CRM, and communications platforms. A firm can have airtight internal AI governance and still be fully exposed through a fintech vendor that updated its underlying model without notice. The 27% figure for firms that have implemented continuous or periodic vendor risk reviews is the number that should alarm any CISO whose vendors include AI-enabled SaaS tools, which at this point is essentially all of them.
ACA Group, an advisory firm whose commercial interest runs toward surfacing compliance gaps its clients then pay to fix, has an incentive to frame the picture as “progress but far from done,” and the framing is accurate enough that the tilt barely matters here. The real signal for CISOs is that AI governance is now a regulatory expectation being stress-tested in real time, not a future-state aspiration. Any CISO renewing a vendor contract with an AI component in 2026 who can’t answer “what model version are they running and what’s our review cadence” is carrying undocumented risk. That’s the gap worth closing before the next audit cycle, not the policy document, which most firms already have.
Based on reporting from AI Compliance Concerns Surge Among Investment Advisors, originally published 2026-07-29 14:12:00.

