AI Agents Need Data Controls Before Regulators Ask
Visa’s recent take on agentic commerce made a point that applies well beyond payments. The piece argued that the “agentic enterprise” doesn’t start with a flashy pilot. It starts with controls. Who can an AI agent talk to. What can it see. What happens when it gets something wrong. If you run a financial advisory firm and you’re experimenting with AI agents that touch client portfolios, personal data, or advice documents, that’s the exact conversation you need to have this quarter, not next year.
Here’s the uncomfortable part. A lot of firms in the $1M-25M range already have AI quietly doing work. An adviser pastes client notes into a chatbot to draft a summary. A paraplanner uses an AI tool to speed up file notes. Nobody wrote a policy for any of it. Nobody documented what data went where. That’s not a technology problem. That’s a compliance gap waiting for a regulator, or a client complaint, to expose it.
The Visa point, translated for wealth management
Visa’s argument was simple: agentic systems need permissioning, auditability, and clear boundaries before they get access to money or sensitive data. Swap “payments” for “client PII and portfolio data” and you’ve got the exact brief for a financial advisory firm building or buying AI agents in 2026.
Regulators haven’t caught up with agentic AI specifically, but they don’t need to. Existing obligations around data handling, record-keeping, and advice documentation already cover most of what an AI agent touches. If an agent reads a client’s portfolio to draft a meeting brief, that’s a data access event. If it drafts part of a Statement of Advice, that’s a compliance document with a paper trail requirement. The rules aren’t new. What’s new is that nobody’s written down how AI fits into them.
We usually see one of two situations when we sit down with a firm. Either there’s no AI in use yet and the owner is nervous about starting without a framework, or there’s already ad hoc AI use across three or four different tools and nobody could produce a data-access map if asked tomorrow. Both situations get fixed the same way: document what the agents touch, why, and who’s accountable for the output.
The manual work agents are already being pointed at
Before you can control what an agent accesses, you need to know what work you’re actually asking it to do. In most firms this book of size, three jobs eat the most adviser and paraplanner time, and they’re also the three jobs where AI agents are already showing up, invited or not.
Meeting prep and write-ups. Advisers typically spend somewhere between 5 and 10 hours a week per adviser pulling together portfolio positions, checking recent communications, and reviewing goal progress before client reviews, then writing it all up again afterward. None of that is billable. All of it touches client financial data, which means any AI tool doing this work is handling PII whether anyone thought about it that way or not.
Compliance documentation. SOAs, ROAs, and file notes are where paraplanner hours disappear. Cycle times on a single advice document commonly run into weeks, and the fully loaded cost of getting one document through review and out the door often lands somewhere between $3,000 and $8,000 depending on complexity. If an AI agent is drafting any part of that document, the firm needs a record of what source material it used and how the output was checked.
Onboarding and KYC. New client onboarding in this industry still runs 30 to 60 days as a norm, dragged out by document collection, fact-finding, and risk profiling. Every one of those steps involves collecting and storing sensitive personal and financial information. An onboarding agent that’s fast but undocumented is a liability with a nice UI.
These three jobs are worth automating. They’re also exactly where “we didn’t write anything down” turns into a real problem the day a client asks how their data was used, or a regulator asks the same thing in a file review.
What “undocumented AI use” actually looks like
It’s rarely dramatic. It looks like an adviser copying a client’s portfolio summary into a general-purpose AI tool to get help writing a meeting note. It looks like a paraplanner using an AI drafting tool that stores prompts on a third-party server nobody vetted. It looks like a new hire assuming the AI tool the last person used is fine to keep using, because nobody told them otherwise.
None of that is malicious. All of it is a gap. And the gap isn’t really about the AI tool being risky. It’s about the firm having no record of the decision to use it, no defined boundary on what data it can see, and no review step before the output reaches a client or a file.
If you’ve read anything from us before on this, you’ll recognize the theme from our broader insights content: the risk in AI adoption for advisory firms isn’t the technology itself, it’s the absence of a documented process around it. That’s the whole thrust of the Visa piece too. Controls first, capability second.
What a documented data-access policy actually contains
You don’t need a 40-page framework. You need something specific enough that if a regulator, an auditor, or a client asked “what does your AI touch and why”, someone in the firm could answer in five minutes with a document, not a shrug.
At minimum it should cover:
- Which systems and data sources each AI agent is allowed to read from, and which it’s explicitly blocked from.
- Who owns the output review before it reaches a client. An agent drafting a file note is not the same as an agent sending one.
- Where the data lives during processing and how long it’s retained.
- A record of every agent in use, what it does, and who approved it. If you can’t list your agents, you don’t have a controls framework yet, you have a collection of tools.
- A change log. When you update what an agent can access, that update gets recorded too.
None of this needs to slow you down. Firms that get this right treat it as a design step, not a compliance tax bolted on afterward. That’s the difference between an AI rollout that survives a file review and one that becomes the finding.
What this looks like end to end, with the agents we actually build
We build agents with this exact framing baked in from day one, not added after the fact. Three come up constantly in advisory firms this size.
The Meeting Prep Agent pulls portfolio data, recent client communications, and goal progress into a one-page brief the adviser reads before every review meeting. The control question isn’t “can it do this fast”, it’s “what exactly does it read to build that brief, and does the adviser see a log of the sources it pulled from”. Built properly, the agent only touches the systems it’s been given explicit access to, and every brief carries a footer showing what data went in. That’s the auditability piece Visa’s argument leans on, applied to a one-page PDF instead of a payment transaction.
The Advice Document Agent drafts SOAs, ROAs, and file notes from meeting transcripts and your firm’s own compliance template. This is the one that touches the most sensitive ground, because the output is a formal advice document. The control that matters here is a mandatory human review step before anything goes to a client, plus a record of exactly which transcript and template version fed the draft. Done right, this doesn’t remove the paraplanner from the loop, it removes the blank-page problem and the four rounds of formatting edits, while keeping a clean paper trail of what the AI touched versus what a human decided.
The Client Onboarding Agent runs a guided fact-find with new clients, collects KYC documents, and assembles a clean onboarding pack for the adviser. This one’s worth naming explicitly in your data-access policy because it’s the agent most directly handling identity documents and financial disclosures from people who aren’t yet clients, which changes the retention and consent conversation. Where does that document go if the person doesn’t proceed. Who’s responsible for deleting it. Those are policy questions, not technical ones, and they need answers before the agent goes live, not after.
Across all three, the pattern is the same. The agent does the tedious pulling-together work. A human still owns the judgment call. And there’s a written record of what the agent was allowed to see, so the firm can answer for it later. That’s the whole Visa argument, just applied to wealth management instead of card networks.
If you want a broader look at how this operations layer fits together across a firm, our Omni ops page walks through the pattern in more depth, and our guides section has more detail on how firms sequence AI rollout without creating new compliance risk in the process.
The dollar reality
Firms this size, doing $1M-25M in revenue, typically leak somewhere between $70,000 and $200,000 a year in adviser and paraplanner time tied up in exactly the three jobs above: meeting prep, advice documentation, and onboarding. That number doesn’t include the cost of a compliance finding, a client complaint about how their data was handled, or the six months it takes to rebuild trust with a regulator after an undocumented AI use turns up in a file review.
The uncomfortable math is that the fix costs less than the leak. A firm spending $150,000 a year in tied-up adviser and paraplanner hours isn’t looking at a six-figure technology investment to close that gap. It’s looking at a focused build on two or three agents, done with proper access controls from the start, which usually pays for itself well inside the first year. The bigger risk isn’t the spend. It’s doing nothing and having the leak compound while an ad hoc AI tool somewhere in the firm creates a control gap nobody’s tracking.
Where the Omni Audit fits
We don’t start with a build. We start with an audit, because you can’t design the right controls for agents you haven’t mapped yet.
The Omni Audit is 60 minutes, on a call, no deck. We walk through your current workflow for meeting prep, advice documentation, and onboarding, and we map exactly where AI could take over the mechanical parts of that work and where a human needs to stay in the loop for compliance reasons. You walk away with three things: a clear picture of where your hours and dollars are actually going, a shortlist of the two or three agents worth building first, and a straight answer on what a documented data-access approach looks like for your specific systems.
If you’d rather see the vertical breakdown first, see Omni for financial advisory firms before the call, it covers how this plays out for firms your size in more detail. You can also book a 60-min Omni Audit directly if you already know this is the conversation you need to have.
The decision in front of you
The firms that get burned by agentic AI won’t be the ones that moved slowly. They’ll be the ones that moved fast without writing anything down. Visa’s point about the agentic enterprise applies just as much to a 12-person advisory practice as it does to a payments network: the controls come first, and the capability follows.
You’ve likely got adviser and paraplanner hours tied up in meeting prep, advice documentation, and onboarding right now, whether or not you’ve named an AI tool as the reason. Ignore that and the $70,000-$200,000 leak we typically see in firms this size just keeps running. Add AI without documenting what it touches and you’ve traded a time problem for a compliance one.
The better path is to map the workflow, name the controls, and build the agents with those boundaries in from the start. That’s exactly what the AI audit for financial advisory firms is built to do, and it’s a better use of an hour than another quarter of ad hoc AI use with no record behind it. If you’re ready to see what that looks like for your firm, book my Omni Audit and we’ll go through it together.