Artificial intelligence has quickly moved from an emerging concern to a central compliance priority for investment advisers. Now, firms are beginning to face a more difficult question: Are their oversight practices keeping pace with adoption?

The 2026 Investment Management Compliance Testing Survey from ACA Group, the Investment Adviser Association, and Yuter Compliance Consulting found that 85% of respondents identified AI as the hottest compliance topic of the year. That represents a 28-percentage-point increase from 2025 and the widest margin recorded in the survey’s 21-year history.

Cybersecurity ranked a distant second at 37%, followed by privacy and Regulation S-P at 35%.

AI Testing Is Increasing

As firms adopt AI tools, they are also dedicating more compliance resources to their use. 72% of respondents reported an increase in AI-related compliance testing over the past year, the largest year-over-year increase among all topics covered by the survey.

AI use has also become widespread. Eighty percent of firms reported using AI tools for internal or external purposes. Most firms remain cautious about how those tools are deployed:

  • 70% limit AI use to internal applications, such as drafting communications or summarizing research.
  • 10% permit client-facing or other external uses.
  • 18% are still exploring how they may use AI.
  • 2% have prohibited its use entirely.

These results suggest that firms increasingly see AI as a practical business tool, but many are still limiting its use while they evaluate the associated compliance risks.

Governance Programs Take Shape

Most firms have taken initial steps to establish AI governance. According to the survey, 86% have adopted policies and procedures addressing employee use of AI, while another 10% are developing them.

Governance structures are also becoming more common. Fifty-nine percent of firms have established a formal AI governance committee, and 86% maintain an inventory of approved AI tools.

These measures provide an important foundation by defining which tools employees may use and establishing responsibility for AI-related decisions. However, having a written policy or list of approved tools does not necessarily show how firms are reviewing AI-generated content or monitoring the technology over time.

Oversight Gaps Remain

The survey identified several areas where firms’ oversight practices have not yet caught up with their policies.

Fewer than half of respondents, 48%, have formal policies requiring human oversight of AI outputs. Only 37% have procedures for testing and validating those outputs before they reach clients.

Oversight of external providers presents another concern. Just 30% of firms have policies addressing third-party use of AI, even as firms increasingly rely on vendors that may incorporate AI into their products and services.

Incident response planning also appears to be in its early stages. Only 14% of firms have updated their plans to address disruptions or other incidents involving AI.

Without clearly defined review, validation, and escalation procedures, firms may have difficulty demonstrating how they identify inaccurate outputs, protect sensitive information, supervise third-party tools, and respond when an AI system does not perform as expected.

Existing Obligations Still Apply

Although AI introduces new risks, firms must continue addressing familiar compliance requirements. Advertising, books and records, conflicts of interest, privacy, and vendor oversight remain areas of regulatory focus, regardless of whether AI is involved.

Compliance teams should consider whether their existing programs account for how AI could affect each of these responsibilities. This may include reviewing approved use cases, defining when human review is required, documenting how outputs are tested, evaluating vendors’ AI practices, and incorporating AI-related events into incident response plans.

The survey shows that firms have made meaningful progress in establishing AI policies. The next phase will be ensuring those policies are supported by controls that can be tested, documented, and consistently applied.