Skip to main content
Registered Investment AdvisorCharlotte, NC

Most Providers Say No to AI. We Said Yes, Safely.

A Charlotte SEC-registered investment advisor deployed Microsoft 365 Copilot and Claude inside a governed compliance perimeter — strengthening its Regulation S-P position rather than weakening it.

Most security providers have one answer to "can our staff use AI?"

No.

It is a defensible answer. It is also a losing one — because staff use AI anyway, on personal accounts, pasting client information into consumer chatbots the firm has no visibility into, no contract with, and no ability to audit. The prohibition does not eliminate the risk. It relocates the risk somewhere the compliance officer cannot see it.

On transition friction: this firm has no internal IT function — Vigil Cyber performs 100% of the IT and security work. There was no incumbent team to coordinate with, no split accountability to negotiate, and no internal roadmap to work around. For a 20-person firm, that structure is what makes enterprise-grade security and governed AI adoption economically reachable in the first place.

The Problem Every RIA Has Right Now

Two facts are simultaneously true at most advisory firms, and they are in direct conflict.

The obligation is live and specific

The amended Regulation S-P has been in force for every covered institution since June 3, 2026. It requires a written incident response program and customer notification within 30 days of becoming aware that unauthorized access to customer information has occurred or is reasonably likely to have occurred.

Staff are already using AI

Survey data varies by methodology but points consistently in one direction — estimates of employees using unapproved AI tools range from roughly half to more than three-quarters, and a meaningful share report entering sensitive corporate data into external AI platforms without authorization.

Put those together and the picture is uncomfortable. A staff member pasting client portfolio details into a consumer chatbot has plausibly performed an unauthorized disclosure of customer information. The firm cannot detect it, cannot scope it, cannot document it, and therefore cannot notify anyone about it inside 30 days — because the clock never starts.

A prohibition-based AI policy is, functionally, a policy of not knowing. It produces a clean-looking compliance manual and an entirely unmonitored data egress path. The firms most exposed here are frequently the ones most confident they are not, because their policy says the thing is not happening.

Reg S-P Stopped Being Advisory

On May 16, 2024, the SEC adopted amendments to Regulation S-P that moved the rule from a general obligation to safeguard customer information toward a specific, auditable operational standard. The compliance clock has already run out.

Larger Entities — $1.5B+ AUM

December 3, 2025

Deadline passed

All Other Covered Institutions

June 3, 2026

Deadline passed

The clock starts at awareness, not certainty

It begins when the firm becomes aware that unauthorized access has occurred or is reasonably likely to have occurred. A firm that spends three weeks deciding whether something counts as an incident has spent most of its notification window on deliberation.

You cannot notify what you cannot detect

The notification requirement is downstream of a detection capability. A firm without continuous monitoring does not have a 30-day problem — it has an indefinite one, because the clock never starts. Detection is the load-bearing control.

The Client and the Foundation

An RIA's data is unusually concentrated in value. A single client file can contain Social Security numbers, account numbers, custodial relationships, beneficiary designations, tax positions, estate documents, and a detailed map of exactly where a high-net-worth household's money lives. There is no low-sensitivity tier. For an attacker, an RIA is not a target because of the firm's own balance sheet — it is a target because of the client list.

The firm runs 20+ employees and no internal IT function whatsoever. Vigil Cyber performs 100% of the IT and security work. In a firm with an internal IT director, an MSSP is a specialist layer on someone else's operational baseline, and accountability for any given control is split. Here it is not split. The Reg S-P incident response program is not something the firm was advised on — it is something Vigil Cyber operates on their behalf, end to end, and can produce evidence for.

AI governance on a weak foundation is theater

The foundation came first.

24/7 SOC

RocketCyber

Continuous monitoring and alert triage — the detection capability the 30-day notification clock depends on.

Endpoint detection & response

CrowdStrike

Behavioral detection and containment at the endpoint.

Ransomware detection

Datto Ransomware Protection

Dedicated ransomware behavior detection layered beneath the EDR.

RMM / patch & configuration

Datto RMM

Keeps the estate patched and configured to a known baseline.

Backup & recovery

Datto Backup

The "recover from" half of the incident response requirement.

Email security

Check Point Harmony (Avanan)

API-based inspection of inbound, outbound, and internal mail.

M365 backup & archiving

Dropsuite

Independent copy of mail and SaaS data, plus archiving and retention for books-and-records obligations.

The SOC is load-bearing

The 30-day clock starts at awareness. Continuous monitoring is what converts "we have a written policy" into a policy the firm can actually execute. For a 20-person firm with no internal IT, buying 24/7 coverage is the only way this obligation gets met at all.

Backup is a regulatory element

The rule requires programs reasonably designed to detect, respond to, and recover from unauthorized access. Recovery is explicit in the regulation, not merely an operational nicety.

Archiving does double duty

Investment advisers must retain business communications in retrievable form. An independent archive of Microsoft 365 mail serves the Reg S-P safeguarding obligation and the books-and-records obligation simultaneously — one control, two requirements.

The Deployment

Sanctioned AI Inside the Perimeter

Two platforms, chosen because they do genuinely different jobs.

Microsoft 365 Copilot

AI where the work already lives

Copilot operates inside the tenant, against data the firm already holds — mail, documents, meetings, chats. It requires no change in behavior: the assistance appears inside Outlook, Word, Excel, and Teams where the work is already happening.

  • Prompts, responses, and Graph data are not used to train the foundation models
  • Protections enforced within the tenant boundary
  • Feedback is also excluded from model training

Claude Team Plan

AI for reasoning work outside the document

Claude covers what Copilot is not shaped for: extended analysis, research synthesis, drafting and refining complex client communications, and working through problems conversationally rather than inside a specific file.

  • Commercial inputs and outputs are not used to train models by default
  • Training only occurs where a customer explicitly opts in
  • Governed by a commercial agreement, not consumer terms

The retention position, stated plainly

Team-plan users can delete their own conversations. What the Team plan does not provide is automated custom retention timelines — an organization-wide policy expiring conversation data after a defined period. That control is an Enterprise-tier feature.

For most businesses this is a non-issue. For an SEC-registered investment adviser it is worth being deliberate about. Two observations, neither of which is a problem today: the primary system of record is Microsoft 365, backed up and archived with retention intact — Claude is a drafting surface, not the record, and the finished communication lands inside the archived estate. And the gap is retention policy automation, not retention capability: nothing is uncontrolled, there is simply no automatic expiry timer.

This is written into the case study rather than omitted from it, deliberately. A compliance-focused engagement that quietly steps around the one compliance-relevant limitation in its own stack is worth less than one that names it and shows the reasoning. An examiner asking about AI governance wants to see that the firm reasoned about it — not that it bought the most expensive tier.

The Part Most Rollouts Get Wrong

Copilot Does Not Create a Data Leak. It Reveals the One You Already Had.

Microsoft 365 Copilot respects existing permissions exactly. It surfaces only what the requesting user already has access to. That sounds like a complete security answer. It is not — it is a mirror.

In most tenants that have grown organically over years, permissions have sprawled: SharePoint sites shared broadly during a project and never locked back down, "anyone with the link" documents, Teams channels with legacy membership, an HR or compensation folder inheriting permissions nobody has audited since it was created. That over-permissioning has always been a latent exposure. What kept it contained was obscurity — the material was technically reachable, but nobody knew the file existed or where to look.

Copilot eliminates obscurity. It is a semantic search engine with a helpful personality — ask a natural-language question and it will retrieve, summarize, and cheerfully cite anything the user can technically reach.

At an RIA the failure modes are immediate and concrete: a staff member asks an innocuous question about compensation and receives a summary of partner comp; a question about a client relationship returns material from a household that employee has no business seeing.

The correct sequence

1

Audit before deployment — find over-shared sites, broken inheritance, stale "anyone with the link" grants, and orphaned permissions.

2

Remediate — restore least-privilege access to sensitive material.

3

Classify and label — apply sensitivity labeling so protection travels with the document.

4

Then enable Copilot — against a permissions model that is actually correct.

5

Monitor continuously — permissions sprawl is not a one-time cleanup, it is an ongoing entropy problem.

This remediation was performed at this client before Copilot was enabled. Enabling Copilot is a licensing action — anyone can do it in an afternoon, and most providers do exactly that. Auditing and remediating a tenant's permissions model first is unglamorous, time-consuming, and invisible to the client until you explain what you found. It is the difference between a reseller turning on a product and a security provider deploying a capability.

Mapping the Deployment to Reg S-P

Safeguard customer information

Client data stays inside contracted commercial platforms with tenant-boundary enforcement, rather than dispersing into consumer AI accounts.

Written policies and procedures

Documented AI acceptable-use policy defining sanctioned tools, permitted data classes, and prohibited uses.

Incident response program

Detection and response coverage extends to the AI platforms; AI usage is in scope for the same monitoring as the rest of the environment.

30-day notification capability

Governed platforms produce audit trails, so scope of exposure can actually be determined — a determination that is impossible with shadow AI.

Recover from an incident

Backup and independent archiving provide recovery paths. "Recover from" is an explicit element of the rule, not an optional extra.

Books-and-records retention

Archiving preserves Microsoft 365 mail with retention intact, so the record survives independently of the mailbox.

Service provider oversight

Commercial agreements with Microsoft and Anthropic carry contractual data commitments. Consumer accounts carry none.

The AI deployment made the firm's Reg S-P position stronger, not weaker.

It converted an invisible, ungoverned, uncontractable exposure into a documented, monitored, contractually protected one. The firm went from not knowing what its staff were doing with client data to being able to produce an answer.

Business Outcomes

Shadow AI eliminated

Sanctioned tools replaced the personal-account workaround, closing an unmonitored egress path for customer information.

Reg S-P posture strengthened

AI usage moved inside the documented incident response and monitoring perimeter.

Contractual protection established

Commercial agreements with enforceable data commitments, replacing consumer terms that carried none.

Productivity without a compliance trade

Staff got real capability instead of a prohibition they would have routed around.

Permissions model corrected

Over-shared sites and stale access grants were found and remediated before Copilot could surface them.

Examination-ready documentation

The firm can now answer what AI tools are in use, what data they touch, and what governs them.

If You Run an RIA, Three Things Are True at Once

1

Your Reg S-P compliance deadline has passed

Both the December 3, 2025 and June 3, 2026 dates are behind us. The written incident response program and the 30-day notification capability are current obligations, not upcoming ones. The question is no longer when — it is whether you could produce the program and the evidence if an examiner asked this week.

2

Your staff are already using AI

If your firm has not sanctioned a tool, that use is happening on personal accounts, outside your visibility, with client information you remain responsible for. The absence of incidents in your ticket queue is not evidence it is not happening. It is evidence you cannot see it.

3

These are the same problem

Ungoverned AI use is an unauthorized-disclosure pathway under the regulation you are already obligated to satisfy. Solving the second solves part of the first — which is why AI governance belongs in your Reg S-P program rather than in a separate technology conversation.

Four Questions Worth Asking Your Provider

“Did you audit our Microsoft 365 permissions before enabling Copilot?”

If the answer is no, or the question causes confusion, you have a licensing arrangement rather than a security engagement. Copilot inherits your permissions model exactly — including everything over-shared during a project three years ago and never locked back down.

“What happens in the first 24 hours if customer information is exposed?”

The 30-day clock starts at awareness. A firm that spends three weeks deciding whether something qualifies as an incident has spent most of its notification window deliberating.

“Can you show me the audit trail for our sanctioned AI tools?”

If no such trail exists, the tools are not actually governed — they are merely permitted.

“Which of our obligations does each control satisfy?”

A provider who can map tooling to specific regulatory requirements is running a compliance program. One who lists products is running a catalog.

The strategic point

The firms handling this well are not the ones with the strictest prohibitions. They are the ones that provided a sanctioned path before the unsanctioned one became the default — because by the time a policy is written, the behavior it prohibits is usually already established.

The reflexive "no" to AI is not caution. It is the appearance of caution, purchased by pushing the risk somewhere nobody has to look at it. Doing the harder thing — auditing the permissions model, selecting platforms with contractual data commitments, writing the acceptable-use policy, bringing the tools inside the monitoring perimeter, and documenting the retention position honestly including its limitations — produces a firm that is both more productive and more defensible.

Related

Client details in this case study have been anonymized. Regulatory requirements cited from SEC Release No. 34-100155 (Regulation S-P amendments, adopted May 16, 2024). Vendor data-handling commitments cited from Microsoft and Anthropic published documentation. This case study is not legal or compliance advice — consult your compliance counsel regarding your firm's specific obligations.

Ready to Reduce Risk?

Need cybersecurity support or a secure AI build?

We can review the security controls protecting your data, users, and Microsoft 365 environment, then help scope secure AI applications or workflows where they make sense.