โ†
AI for Financial Advisors & Wealth Managers
Aware ยท M10 ยท lesson 10 of 17 ยท queued
Preview โ€” browse every lesson free. Enroll to mark lessons complete, open partner links and save your progress. Login & enroll โ†’
SEC Marketing Rule (Rule 206(4)-1) and AI
๐Ÿ“–
now learning

SEC Marketing Rule (Rule 206(4)-1) and AI

15 min

It is a Wednesday in February 2026. An RIA principal opens a new tab and pastes a Google review from a satisfied client into ChatGPT with the prompt: "rewrite this as a one-paragraph case study for our website, in our voice." Eleven seconds later, a clean, marketing-ready paragraph appears. She copies it to the firm's WordPress staging site, schedules a Tuesday publish, and moves on. What she has just done โ€” without intending to โ€” is create a written communication subject to SEC Rule 206(4)-1, repurpose a third-party endorsement without the required "clear and prominent" disclosures, originate a marketing record subject to Rule 204-2 retention, and trigger an off-cycle Form ADV Part 2A amendment if the firm hasn't already disclosed that AI generates client-facing language. The 2024-2025 AI-washing settlements (Delphia, Global Predictions, and the broader 2025 enforcement cluster), the SEC Division of Examinations' recurring Marketing Rule risk alerts, and the January 2026 staff FAQs on third-party ratings have made one operating reality clear for every adviser using AI: every AI-generated client-facing word is a marketing communication, and the Marketing Rule applies to it from the moment it appears on the screen.

Why Rule 206(4)-1 Is the Rule That Touches Every AI Output

The Marketing Rule, codified at 17 CFR ยง275.206(4)-1, became effective November 4, 2022 and consolidated what had been a fifty-year-old patchwork of the old advertising rule (Rule 206(4)-1) and the old cash-solicitation rule (Rule 206(4)-3) into a single principles-based regime. The compliance date is now firmly behind the industry; the enforcement era is firmly in front of it. By May 2026, the rule has been the subject of more SEC Division of Examinations risk alerts than any other single Advisers Act rule in recent memory. The Division has published an initial Risk Alert (September 2022), an "Additional Observations" companion piece, a 2024 Risk Alert pulled apart in the Paul Hastings and Mintz client alerts, and the January 2026 staff FAQs that quietly relaxed certain aspects of third-party-rating mechanics while tightening expectations on what an adviser must substantiate before publishing.

The rule applies to any "advertisement," which the rule defines extremely broadly. The definition reaches direct and indirect communications, includes one-on-one written communications to more than one person when they offer advisory services to prospective clients or new services to current clients, and explicitly captures any compensated testimonial or endorsement (subject to a de minimis exception). The rule reaches website content, social posts, LinkedIn updates, podcast transcripts, YouTube descriptions, sponsored event language, conference handouts, Catchlight or SmartAsset lead-gen funnels, retargeting copy, drip-email sequences, Google reviews republished by the adviser, Barron's / Forbes ranking citations, and โ€” critically for 2026 โ€” any AI-generated draft of any of the above that the firm publishes or sends.

The Mayer Brown and McGuireWoods unpacks of the January 2026 staff FAQs (the "Additional FAQs" series following the original December 2023 staff FAQ release) added flexibility on portrayal of extracted performance and certain third-party rating mechanics, but did not relax the core principle: a "clear and prominent" disclosure of all material facts required by the rule must accompany the advertisement, and the adviser must be able to substantiate every material statement of fact at the time it is made. AI-generated marketing collapses the production cost of advertising by an order of magnitude. The Marketing Rule did not move.

The 2024-2025 AI-Washing Settlements and What the SEC Actually Charged

The watershed moment for AI-and-the-Marketing-Rule was the SEC's March 2024 charges against Delphia (USA) Inc. and Global Predictions, Inc. โ€” the first dedicated "AI-washing" enforcement actions naming registered investment advisers. The Commission alleged that both firms had made false and misleading statements in client-facing marketing about their use of artificial intelligence and machine learning in the investment process. Delphia's marketing claimed it used AI in ways the SEC alleged it did not; Global Predictions' marketing made similar misrepresentations. Both firms settled, paying combined civil penalties of $400,000 and agreeing to censure and cease-and-desist orders. Then-Chair Gary Gensler used the moment to deliver one of the most-quoted regulatory lines of the AI era: "AI washing, whether it's by financial intermediaries... or by public issuing companies... may violate the securities laws."

The 2025 enforcement cluster followed. The Commission charged additional advisers and other registrants throughout 2024 and 2025 with similar marketing misrepresentations โ€” overstating the role of AI in investment decisions, mischaracterizing the proprietary nature of "AI" that was in fact a third-party API wrapper, and claiming "AI-managed" portfolios that were in reality human-managed with AI-generated commentary attached. The pattern across the AWCs and settled orders was consistent: an adviser made a marketing statement about AI capability that was not, at the time made, substantiated by the actual operation of the firm's investment or advisory process. Under Rule 206(4)-1, that is a violation regardless of intent, regardless of whether any client was harmed, and regardless of whether the misrepresentation would have been material to a sophisticated counterparty.

The substantive lesson for every adviser by May 2026 is the substantiation principle: every claim the firm makes about its use of AI โ€” "AI-powered planning," "machine-learning-driven portfolio construction," "proprietary AI," "algorithmic best-interest analysis" โ€” must be supportable, at the moment it is made, against the actual operation of the firm. The substantiation file is the defensive artifact: a written record, contemporaneous with the marketing claim, documenting what the firm's AI actually does, who built it (or which vendor provides it), what training data underlies it, and how its outputs flow into the advisory or investment process. The L4 Ch7 AI-Washing Risk Audit lesson will operationalize the substantiation file as a recurring workflow; this lesson establishes why the file exists.

The January 2026 Staff FAQs on Third-Party Ratings and What They Mean for AI-Generated Content

The Division of Investment Management staff published an updated set of Marketing Compliance FAQs in January 2026 (the "Additional FAQs," following the prior December 2023 release and earlier guidance). The 2026 update covered third-party ratings, hypothetical performance, gross-and-net performance presentation, and testimonial / endorsement mechanics. Three takeaways carry the most operational weight for an adviser using AI in marketing.

First, on third-party ratings: the staff clarified that an adviser may include a third-party rating (Barron's Top 100, Forbes Best-In-State Advisors, a peer-survey ranking, a robo-rating from a NerdWallet or Bankrate piece) in an advertisement only if (a) the adviser has a reasonable basis to believe the ratings methodology is not biased toward selection of any particular adviser, (b) the rating provides the date or period for which the rating was given, (c) the identity of the third party is disclosed, and (d) any compensation provided to the third party in connection with the rating is disclosed. The 2026 FAQs allowed flexibility on certain mechanics โ€” for example, the staff confirmed that an adviser may, in some circumstances, present an extract of a rating without the entire rating's surrounding context, provided the extract is not misleading and required disclosures accompany it.

Second, on hypothetical performance under Rule 206(4)-1(d)(6): hypothetical performance โ€” backtested, model, target, or projected performance โ€” generally may not be included in an advertisement unless the adviser has adopted and implemented policies and procedures reasonably designed to ensure the hypothetical performance is relevant to the likely financial situation and investment objectives of the intended audience. For AI-generated content, this lands hard. An AI-generated "what if you had invested $100,000 with us in 2020" case study is hypothetical performance. An AI-summarized success scenario projecting forward returns is hypothetical performance. The Marketing Rule does not permit either to a general audience advertisement; the audience-tailoring policies-and-procedures requirement is the operative compliance gating.

Third, on testimonials and endorsements (Rule 206(4)-1(b)): a "testimonial" is a statement by a current client; an "endorsement" is a statement by a non-client. Both must include clear-and-prominent disclosures: whether the person is a client (or not), whether compensation was provided, and any material conflicts. Compensation includes not only cash but anything of value โ€” directed brokerage, reduced fees, gifts, free services. The 2026 FAQs confirmed that Google reviews republished by the firm on its own website or social media qualify as testimonials and require the disclosures; an AI-generated paragraph repurposing a Google review carries the same obligations.

How to Write Compliant Disclosures on AI-Touched Marketing Artifacts

The "clear and prominent" disclosure standard in Rule 206(4)-1(b)(1) is the operative test. "Clear and prominent" is not a font-size rule โ€” it is a holistic standard the SEC and the Division will apply by asking whether a reasonable reader would notice and understand the disclosure in the same context the marketing claim is made. Footnote 47 in 8-point gray text below a 24-point AI-generated headline does not satisfy "clear and prominent." Inline, same-font, same-color disclosure adjacent to the claim does. The four most common AI-touched marketing artifacts in a 2026 advisor practice each have a disclosure template; the templates below are starting points to be adapted to the firm's specific facts and ADV Part 2A language.

Third-Party Rating Citation

When the firm cites a Barron's, Forbes, Five Star, or other third-party ranking on its website, in a LinkedIn post, in an AI-generated capabilities deck, or in a Catchlight / SmartAsset profile, the disclosure must include the third party's identity, the date or period of the rating, the criteria the third party used, the universe from which the rating was drawn (so the reader can assess selection bias), and any compensation paid in connection with the rating. Example: "[Firm] was named to the [Year] [Publication] [Ranking Name] based on [briefly describe methodology โ€” e.g., assets under management, regulatory record, client retention, and survey responses]. The ranking was published [Date] and reflects data from the period [Period]. [Publication] is an independent third party. [Firm] did / did not pay a fee to be considered for or included in the ranking." The disclosure runs same-font, same-color, adjacent to the citation, not in a footer.

Republished Google Review or Testimonial

When the firm republishes a Google review, a Yelp review, a LinkedIn recommendation, or any client statement โ€” including an AI-rewritten version of any of the above โ€” Rule 206(4)-1(b) requires inline disclosure of (a) whether the person is a current client, (b) whether the person was compensated, (c) any material conflicts of interest on the part of the person, and (d) if the person is being compensated, the material terms of the compensation arrangement. Example placed inline below the quote: "Testimonial by a current client. The client was not compensated for this testimonial. [Firm] is not aware of any material conflicts of interest on the part of this client." If the testimonial has been rewritten by AI for clarity, the firm should add: "Statement has been edited for length and clarity from the client's original posted review on [Source]; original text on file."

AI-Generated Case Study

An AI-summarized case study describing how the firm helped a client must avoid (1) hypothetical performance under 206(4)-1(d) unless audience-tailoring policies are in place, (2) cherry-picked single-client results presented as representative of the firm's investment performance generally, and (3) any client-identifying detail without consent under Reg S-P and the GLBA Safeguards Rule. Example disclosure: "Composite or representative client example. Facts have been modified to protect client confidentiality under SEC Regulation S-P. Individual results vary. Past performance is not indicative of future results. This is not an offer of advisory services and should not be relied upon as personalized advice. [Firm] is a registered investment adviser; please review our Form ADV Part 2A at [link] for material risks, fees, and conflicts."

Hypothetical Performance Illustration Under 206(4)-1(d)

Hypothetical performance โ€” backtests, models, targets, projections, "what if you had invested" illustrations, AI-generated retrospective scenarios โ€” generally cannot appear in a general-audience advertisement under Rule 206(4)-1(d). To present hypothetical performance, the adviser must have adopted and implemented policies and procedures reasonably designed to ensure the hypothetical performance is relevant to the likely financial situation and investment objectives of the intended audience, must provide sufficient information for the intended audience to understand the criteria and assumptions used, and must provide the risks and limitations of using the hypothetical performance. Practically, this means hypothetical performance content goes only to gated, sophisticated audiences (institutional, accredited investor pages behind login walls with audience-tailoring controls) and never to a general-public website page. AI-generated retrospective case-study language that drifts into hypothetical performance must be flagged in the firm's pre-use review queue and stripped before publication.

The FINRA Rule 2210 Interlock for the Hybrid Advisor

Most US wealth practices are hybrid โ€” registered as both an RIA (under the Advisers Act) and a broker-dealer or representative thereof (under the Securities Exchange Act of 1934 and FINRA membership). The same piece of AI-generated marketing content can therefore be simultaneously subject to Rule 206(4)-1 (Marketing Rule) and FINRA Rule 2210 (Communications with the Public). The two regimes overlap but do not perfectly align. Rule 2210 requires principal pre-use review and approval of retail communications and correspondence in specified circumstances; the Marketing Rule does not impose a pre-use review requirement but does require substantiation, disclosure, and recordkeeping. The hybrid practice must satisfy both. The next lesson (L1 Ch4 L2) on Reg BI begins the parallel analysis; L1 Ch4 L3 develops the FINRA Rule 2210, 3110, and 4511 framework in detail.

Recordkeeping Under Rule 204-2 and the Prompt as Record

Rule 204-2 under the Advisers Act requires the adviser to maintain a copy of each advertisement disseminated, the records used to substantiate the calculations and information in the advertisement, and (for advertisements that include hypothetical performance or testimonials/endorsements) additional supporting records. By May 2026, the practitioner consensus across Smarsh, Global Relay, and the major law-firm client alerts (Sidley, Debevoise, Mayer Brown, Mintz) is that the adviser's "advertisement" record must include not only the final published version but also the inputs that produced it โ€” including, in the AI context, the prompts the advisor used to generate the draft, the AI tool used, the version of the model, the AI-generated output, the advisor's edits, and the principal / compliance reviewer's signoff. The retention period is the Rule 204-2 minimum of five years (the first two in an easily accessible location). FINRA Rule 4511 imposes a parallel three-year obligation for BD records; the practical convention is to retain to the longer of the two.

The Substantiation File and the Pre-Use Review Queue as Operational Defenses

The two operational defenses that survive a 2026 SEC examination are the substantiation file and the pre-use review queue. The substantiation file is the documented evidence โ€” contemporaneous with each AI-related marketing claim โ€” supporting every material statement of fact: what the firm's AI actually does, the vendor (Jump, Zocks, Holistiplan, FP Alpha, Wealth.com, Catchlight, SmartAsset, Salesforce Einstein for FSC, Microsoft Copilot, OpenAI Enterprise), the data residency, the human-in-the-loop architecture, the WSPs governing use. The pre-use review queue is the principal / compliance workflow that screens every piece of AI-generated client-facing content before publication for Marketing Rule compliance, hypothetical-performance exposure, testimonial-disclosure adequacy, ADV-disclosure consistency, and substantiation. The L4 Ch3 lesson on principal review of AI-drafted communications under FINRA Rule 2210 develops the review queue at scale; the L4 Ch7 lesson on AI-washing risk audit develops the substantiation file at scale. This lesson establishes the regulatory anchor for both.

The Tuesday Morning Decision

Back to the RIA principal pasting the Google review into ChatGPT. The compliant version of that workflow looks different. She opens the firm's approved enterprise LLM (OpenAI Enterprise or Microsoft Copilot, not a free public chatbot), confirms the client posted the review publicly on Google (a public source the firm may republish subject to disclosure), drafts the case-study paragraph with the prompt explicitly instructing the model to preserve the client's original meaning and avoid hypothetical performance language, runs the output through the firm's pre-use review queue (a compliance reviewer applies the testimonial-disclosure template, confirms no hypothetical performance has crept in, confirms the ADV Part 2A AI-use disclosure already covers this workflow, and adds the inline "Testimonial by a current client; client was not compensated" disclosure), archives the prompt, output, edits, and signoff in Smarsh under Rule 204-2 and FINRA Rule 4511, and schedules publication. The whole compliant workflow takes nine minutes instead of eleven seconds. It also does not produce the next AI-washing enforcement headline.

Key Takeaways

  • Rule 206(4)-1 (the Marketing Rule) applies to every AI-generated client-facing word โ€” website copy, social posts, LinkedIn updates, podcast descriptions, AI-rewritten Google reviews, AI-summarized case studies, AI-generated capabilities decks, AI-drafted lead-gen funnels, AI hypothetical-performance illustrations.
  • The 2024-2025 AI-washing settlements (Delphia, Global Predictions, the 2025 enforcement cluster) established that overstating AI capability is a Marketing Rule violation regardless of intent, harm, or sophistication of the audience. The substantiation principle: every claim must be supportable, at the moment made, against the actual operation of the firm.
  • The January 2026 staff FAQs added flexibility on certain third-party rating mechanics and on extracted performance, but did not relax the "clear and prominent" disclosure standard or the substantiation requirement. Hypothetical performance under 206(4)-1(d) remains gated by the audience-tailoring policies-and-procedures requirement.
  • Third-party ratings, republished Google reviews, AI case studies, and hypothetical-performance illustrations each have a disclosure template โ€” inline, same-font, same-color, adjacent to the claim โ€” that the firm should standardize and route through its pre-use review queue.
  • Recordkeeping under Rule 204-2 (and FINRA Rule 4511 for BDs) extends in practice to the prompts, AI tool / model version, outputs, advisor edits, and principal signoff that produced the advertisement. Retention is the longer of the Rule 204-2 five years or FINRA Rule 4511 three years.
  • Hybrid practices (RIA + BD) must satisfy both Rule 206(4)-1 and FINRA Rule 2210 simultaneously. The Rule 2210 principal-review requirement (covered in L1 Ch4 L3) is the operational checkpoint; the Marketing Rule's substantiation and disclosure standards run in parallel.
  • The substantiation file and the pre-use review queue are the two operational defenses that survive a 2026 SEC examination. Build them now; the L4 Ch3 and L4 Ch7 lessons develop both at practice scale.