Agentic AI in Advisor Workflows — What's Plausible, What's Regulated, What's Banned
The 2026 baseline limits AI in advisor workflow to drafting, summarizing, extracting, and classifying — not action-taking. The FINRA 2026 Annual Regulatory Oversight Report framed agentic AI as a Rule 3110 supervisory obligation, the SEC's Compliance Rule 206(4)-7 framework reads it as a 206(4)-7 design issue, and Reg Notice 24-09 set the early supervisory expectations. The 2027-2028 trajectory extends that baseline forward into territory where the AI actually takes action against the client's account: rebalance execution under Orion Eclipse + 55ip + BlackRock Aladdin Wealth, RMD processing under IRC 401(a)(9), beneficiary maintenance with custodian electronic-signature workflows, ACATs initiation, draft 1040 amendments via Holistiplan, opt-in agentic portal moves per L5 Ch5 L1, and limited trade execution. None of which is universally banned; none of which is universally permitted; each lives in a specific supervisory and disclosure architecture under L4 Ch3 L3 agentic-AI WSPs + L5 Ch3 L3 disclosure framework + FINRA Rules 2210 / 3110 / 4511 + SEC Rule 204-2 + Reg S-P 17 CFR Part 248 + the Reg BI §240.15l-1 four obligations. This lesson installs the framework that names what's plausible, what's regulated, and what's effectively banned at the firm-by-firm decision level.
The FINRA 2026 Framing, Extended Forward
FINRA's 2026 Annual Regulatory Oversight Report treats agentic AI as a Rule 3110 reasonable-design obligation under the supervisory system requirement; Sidley, Snell & Wilmer, Debevoise, ACA Group, and Smarsh have all published 2025-2026 teardowns reinforcing that the regulatory posture is functional — the FINRA examiner asks not "do you use agentic AI?" but "can you supervise its actions, can you reconstruct its decisions, can you reverse them, and can you document them under Rule 4511?" Reg Notice 24-09 anchored the early position; the 2026 report extended it. The SEC's Compliance Rule 206(4)-7 — which requires written policies and procedures reasonably designed to prevent securities-law violations — applies the same functional test. Reg BI §240.15l-1's four obligations (Disclosure, Care, Conflict, Compliance) all extend to agentic actions because an agentic action against a retail-customer account that influences a securities recommendation or that constitutes a recommendation engages Reg BI directly.
The 2027-2028 trajectory adds specificity. Agentic actions split into categories — high-supervisory (trade execution, ACATs initiation), medium-supervisory (rebalance against an established IPS, RMD calculation + processing, beneficiary maintenance with electronic signature), low-supervisory (draft 1040 amendments awaiting human + CPA signoff, scheduling and confirmation, document retrieval). Each category carries a distinct combination of pre-action review, post-action review, kill-switch, audit-log architecture, and disclosure under ADV Part 2A and the engagement letter.
Categories of Agentic Action — What's Plausible
Trade Execution
The 2027-2028 plausible-but-narrowly-scoped category. Limited use cases include (a) tax-loss harvesting within Orion Eclipse + 55ip + BlackRock Aladdin Wealth under an IPS-aligned algorithm with pre-defined band limits per security and total portfolio drift; (b) rebalance to IPS targets within bands; (c) cash sweep into approved sweep vehicles. Out-of-scope through 2028: discretionary security selection, unsolicited cross-trades, options strategies, leverage, alternatives. The supervisory architecture: kill-switch at the trader / advisor level (immediate halt, queued unwound); pre-action review on the first 30 days of a new IPS configuration; post-action review queue under Rule 2210 + Rule 3110 with risk-based sampling per L4 Ch3 L2; full audit log under Rule 4511 + SEC Rule 204-2 covering prompt + retrieved context + execution decision + venue + price + timestamp. ADV Part 2A item 8 (Methods of Analysis) + item 16 (Discretionary Authority) updates per the L5 Ch7 L6 amendment workflow. Engagement letter: explicit opt-in by category, with revocation mechanism documented per Section 6 IRP of L5 Ch3 L1 policy.
Rebalance Against IPS
The most mature 2026-2027 use case. Orion Eclipse, 55ip, and BlackRock Aladdin Wealth already ship rebalance algorithms; the agentic-AI question is whether the algorithm acts within the firm's L4 Ch3 L3 WSP without each rebalance constituting an individual recommendation requiring Reg BI memo. Rule of thumb: rebalance to IPS bands established and documented in advance, with the IPS as the recommendation memo's referenced authority, is generally non-recommendation territory at most firms — confirmation rather than recommendation per the L5 Ch7 L1 + L5 Ch7 L3 framework on drawdown communications. Exception: any rebalance outside band, or any change to the IPS itself, escalates to advisor review and Reg BI memo. Audit log under Rule 4511 captures the IPS reference + the bands + the agentic decision + the execution.
Beneficiary Maintenance
The L5 Ch5 L1 portal lesson framed this as an opt-in agentic feature for 2027-2028. The mechanics: client initiates beneficiary update via portal → AI drafts the custodian's beneficiary form with the requested change + Cardinal Rule L1 Ch2.3 source-system verification on existing beneficiary record → advisor reviews and confirms the change is consistent with the household's estate plan (FP Alpha + Wealth.com cross-reference per L3 Ch5) → electronic signature → custodian processing → confirmation back to client. The advisor's review is non-optional even under agentic configuration because beneficiary changes are legally significant and the Reg BI Care Obligation §240.15l-1(a)(2)(ii) implications cannot be delegated. Audit log captures the original beneficiary, the requested change, the estate-plan cross-reference, the advisor's confirmation, and the custodian's processing record. Smarsh / Global Relay retention under Rule 4511 + SEC Rule 204-2 five-year + two-year accessible.
RMD Processing
IRC 401(a)(9) RMD obligations starting age 73 (SECURE 2.0; moving to 75 in 2033 per the statute) trigger annual calculations across each Traditional IRA, SEP, SIMPLE, and inherited IRA. The agentic workflow: AI calculates RMD per the published Uniform Lifetime Table or Joint Life and Last Survivor Expectancy Table per the IRS Publication 590-B tables for the appropriate divisor + Cardinal Rule source-system verification against custodian December 31 prior-year balance → AI drafts the distribution instruction → advisor reviews and signs off → custodian processes → 1099-R generated in following January. The supervisory architecture: pre-action review by advisor (not agentic-only) because the RMD election (cash, in-kind, QCD per IRC 408(d)(8), distribution to a specific account) implicates Reg BI Care Obligation + tax planning judgment that the AI cannot exercise unilaterally. Post-action audit log per Rule 4511 + SEC Rule 204-2 covers calculation method + divisor + tables version + custodian balance verification + advisor signoff + distribution detail.
ACATs Initiation
Account transfers via ACATs (Automated Customer Account Transfer Service under FINRA Rule 11870) move client assets between custodians. The agentic workflow: client requests transfer via portal → AI validates the source custodian's holdings + ACATs eligibility + receiving custodian's account setup status → AI drafts ACATs Transfer Initiation Form (TIF) + Cardinal Rule verification on every position and account number → advisor reviews and signs off (non-optional because of Reg BI rollover-comparable Care Obligation analysis if the transfer involves a retirement plan rollover triggering the L2 Ch7 L2 rollover documentation requirement) → submission to source custodian → standard 3-6 business day ACATs settlement window. Audit log per Rule 4511 + SEC Rule 204-2. Marketing Rule 206(4)-1 substantiation file per L4 Ch7 L1 if the agentic ACATs is marketed as a firm capability.
Draft 1040 Amendments
Holistiplan's OCR + bracket scan + extraction capability can identify discrepancies between a client's filed 1040 and the planning team's understanding of the household's tax position (e.g., missed QCD per IRC 408(d)(8), un-deducted SEP contribution, unclaimed foreign tax credit, mis-categorized capital gain). The agentic 2027-2028 workflow: AI drafts the 1040-X amendment + supporting schedule recalculation + Cardinal Rule source-system verification against original 1040 (verifying every line that flows into the 1040-X) → CPA reviews + signs → advisor reviews + signs → client signs → IRS filing within the 3-year amendment window. The CPA's signature is non-optional because the firm's advisors are typically not the household's tax-return preparer; the Reg BI Care Obligation + the AICPA professional standards both anchor on the CPA's signature. The agentic AI is drafting + extracting + cross-referencing, not signing the 1040-X itself.
Categories of Agentic Action — What's Regulated
Regulated by Design, Not Banned
The 2027-2028 regulated category captures actions that are not banned outright but that require explicit regulatory architecture before they can ship. The pattern across all of them: pre-action human review, post-action audit log, kill-switch, ADV disclosure, engagement-letter opt-in by category, FINRA Rule 4511 + SEC Rule 204-2 retention, Reg BI Care Obligation memo on each recommendation surface, Marketing Rule 206(4)-1 substantiation for any external claim of the capability, and outside-counsel review at least annually per L5 Ch4 L1 AI Compliance Specialist workflow.
Opt-In by Category
The L5 Ch3 L3 disclosure framework's opt-in architecture extends naturally: each agentic category is independently opt-in via the engagement letter; each category has independent revocation; each category has its own audit-log identifier. Households can opt into rebalance + RMD calculation but decline ACATs + beneficiary maintenance + trade execution. The default through 2028 across the program firms is opt-in (not opt-out) per the L5 Ch3 L3 framework's default-off posture for agentic categories. Wirehouse channels and aggregators tend toward stricter (mandatory advisor pre-action review even on opt-in categories); RIAs vary based on segment and the L4 Ch3 L3 WSP architecture.
Kill-Switch and Reversibility
The L4 Ch3 L3 WSP framework names the kill-switch as a non-negotiable design requirement under FINRA Rule 3110 reasonable design + SEC Compliance Rule 206(4)-7. The 2027-2028 kill-switch architecture spans (a) household-level pause (one client opts out of a previously opted-in category); (b) advisor-level halt (a single advisor halts agentic action across their book); (c) firm-level emergency stop (CCO halts agentic action across the entire firm in response to a discovered fault or breach); (d) category-level unwind (one agentic category — e.g., rebalance — is reversed across the firm). Reversibility varies by action — beneficiary updates are reversible if caught quickly via custodian re-filing; ACATs in-flight may have a 24-48 hour cancellation window depending on receiving custodian; trade executions create market exposure that may not be fully reversible without slippage cost.
Audit-Log Architecture
Per L4 Ch3 L3 agentic-AI WSPs + FINRA Rule 4511 + SEC Rule 204-2, each agentic action retains: timestamp, household identifier, action category, agentic decision rationale (the LLM's intermediate output where retained), retrieved context (RAG vault references per L5 Ch3 L2 data architecture), human review chain (advisor + CCO + outside-counsel signoff as applicable), execution venue + result, post-action exception flags, kill-switch invocations. Smarsh / Global Relay's compliance archive holds the immutable layer with five-year retention + two-year accessible.
Categories of Agentic Action — Effectively Banned Through 2028
Discretionary Security Selection
Through 2028 the firm-by-firm consensus is that AI does not select securities to buy or sell at the household level without advisor pre-action review. The Reg BI Care Obligation §240.15l-1(a)(2)(ii) requires the advisor's recommendation memo on each material recommendation; the L1 Ch1 framing — that AI cannot exercise professional judgment under the CFP Code or Reg BI Care Obligation — extends to security selection. Vendors may ship security-selection AI; firms generally do not enable it for autonomous execution.
Unsolicited Cross-Trades
Cross-trades between client accounts under Investment Advisers Act Rule 206(3)-2 require specific disclosure and consent mechanics that the 2027-2028 agentic AI cannot replicate without significant additional architecture. Effectively banned at the firm level for autonomous execution.
Options, Leverage, Alternatives
Complex strategies — options spreads, margin leverage, private alternatives, hedge funds, structured products — fall outside the 2027-2028 plausible band because the suitability + Reg BI Care Obligation + Marketing Rule 206(4)-1 + state law accredited-investor + qualified-purchaser requirements create surface area the agentic AI cannot adequately cover. Firm-level ban through 2028 is standard.
Financial Product Recommendations That Influence Comp
Any agentic action that influences a recommendation generating differential comp to the firm or advisor (annuities, insurance, proprietary funds) is effectively banned for autonomous execution through 2028 because the Reg BI Conflict Obligation §240.15l-1(a)(2)(iii) cannot be discharged by an AI's prompt distribution; the L5 Ch5 L2 recommendation-influence conflict framework requires advisor pre-action review.
Supervisory and Disclosure Architecture Each Requires
FINRA Rule 3110 Reasonable Design
The supervisory system must be reasonably designed to achieve compliance. For agentic AI this means: written WSP per L4 Ch3 L3 covering each agentic category; pre-action review architecture per category; post-action audit and exception handling; kill-switch design and testing; principal review queue per L4 Ch3 L2; risk-based sampling architecture; vendor due diligence per L4 Ch2; periodic system testing under SEC Compliance Rule 206(4)-7; outside-counsel review at least annually.
FINRA Rule 4511 + SEC Rule 204-2 Retention
Audit log + retrieved context + advisor signoff + execution record + kill-switch invocations → five-year retention with two-year accessible. Smarsh / Global Relay hold the immutable layer. Per L5 Ch3 L2 data architecture, retention spans the entire prompt-and-context history that drove the agentic decision.
ADV Part 2A Disclosure
Item 4 (Advisory Business) describes the agentic AI capabilities. Item 8 (Methods of Analysis) describes the AI-driven methods. Item 16 (Discretionary Authority) describes the discretionary scope. The L5 Ch7 L6 annual amendment workflow handles material year-end changes; off-cycle prompt amendment within 90 days under IA-1992 + Form ADV General Instruction 4 for material capability launches. Engagement letter carries the per-category opt-in language. Form CRS reflects the agentic capabilities at the disclosure-summary level.
Reg BI Four Obligations
Disclosure (ADV + engagement letter + Form CRS), Care (advisor pre-action review on recommendation surfaces), Conflict (recommendation-influence conflict surfaces documented per L5 Ch5 L2 + Conflict Obligation §240.15l-1(a)(2)(iii)), Compliance (written policies under Rule 206(4)-7 + L4 Ch3 L3 WSP + outside-counsel review).
Reg S-P + NY DFS Part 500 + NAIC AI Model Bulletin
Agentic AI accesses Class 4 NPI per L5 Ch3 L2 data classification. Reg S-P 17 CFR Part 248 May 2024 amendments require 30-day breach notification + written IRP + vendor oversight. NY DFS 23 NYCRR 500 layers 72-hour notification on NY-resident affected. NAIC AI Model Bulletin and Model #275 apply to annuity-licensed advisors using AI in insurance product recommendations.
Case Study — $12B Aggregator Agentic Rollout
A $12B RIA aggregator with 280 advisors began an agentic-AI rollout in Q4 2026 targeting full implementation by Q4 2028. Phase 1 (Q4 2026 - Q2 2027): rebalance against IPS (Orion Eclipse + 55ip across the entire advisor base, with BlackRock Aladdin Wealth at the top tier of $25M+ households); RMD calculation + processing (advisor pre-action review required); beneficiary maintenance opt-in via portal (advisor confirmation non-optional). Phase 2 (Q3 2027 - Q1 2028): ACATs initiation (advisor pre-action review on every transfer regardless of opt-in); draft 1040 amendments via Holistiplan (CPA + advisor + client signoff required). Phase 3 (Q2 2028 - Q4 2028): limited trade execution for tax-loss harvesting within IPS bands (pre-action review for first 30 days of any new IPS configuration; risk-based sampling thereafter).
Q4 2028 outcomes: rebalance agentic-AI handled 94% of in-band rebalances without escalation; 6% escalated to advisor for IPS-band exception (within target); RMD processing achieved 99.4% accuracy against IRS Publication 590-B Uniform Lifetime Table + Joint Life Tables (cross-checked monthly); beneficiary maintenance handled 1,400 changes across the book with zero unwind events; ACATs initiation handled 380 transfers with one in-flight cancellation triggered by client request within the 24-hour window; tax-loss-harvesting trade execution achieved $4.2M in realized losses across the eligible book with no Reg BI Care Obligation memo deficiencies on outside-counsel sample; kill-switch invoked twice (once at advisor level during a single-household IPS dispute, once at category level during a 4-hour vendor outage); zero Reg S-P 17 CFR Part 248 incidents; ADV Part 2A item 4 + item 8 + item 16 amended three times across the rollout with no SEC staff inquiry; L4 Ch7 L1 audit framework scored the program 9/10 in Q4 2028. The agentic-AI rollout became the documented competitive-differentiation narrative at the aggregator's three tuck-in conversations through 2028 — buyers cited the agentic infrastructure as one of the top three valuation drivers per Mercer Capital / ECHELON Q3-Q4 2025 framing (top-quartile ~8x-10x adjusted EBITDA, premium-top ~11.6x, with AI maturity +0.5x to +1.5x).
Key Takeaways
- The FINRA 2026 framing treats agentic AI as a Rule 3110 reasonable-design obligation + Reg Notice 24-09 supervisory expectations + SEC Compliance Rule 206(4)-7 written policies + Reg BI §240.15l-1 four-obligations extension. The functional test: can you supervise the actions, reconstruct the decisions, reverse them, and document them under Rule 4511?
- Three categories of agentic action by 2027-2028: plausible (trade execution narrowly scoped via Orion Eclipse + 55ip + BlackRock Aladdin Wealth, rebalance against IPS, beneficiary maintenance, RMD processing per IRC 401(a)(9) + IRS Pub 590-B tables, ACATs initiation under FINRA Rule 11870, draft 1040 amendments via Holistiplan); regulated by design (opt-in by category, kill-switch and reversibility, full audit-log architecture per L4 Ch3 L3 WSPs); effectively banned through 2028 (discretionary security selection, unsolicited cross-trades under Rule 206(3)-2, options / leverage / alternatives, comp-influencing product recommendations).
- Each plausible category carries a distinct supervisory + disclosure pattern: pre-action review (advisor or principal, varies by category), post-action review queue under Rule 2210 + Rule 3110 with risk-based sampling per L4 Ch3 L2, kill-switch architecture (household / advisor / firm / category level), audit log under Rule 4511 + SEC Rule 204-2 (Smarsh / Global Relay immutable layer, five-year + two-year accessible), ADV Part 2A item 4 + 8 + 16 disclosure, engagement-letter per-category opt-in, Reg BI Care + Conflict Obligation analysis.
- Reversibility varies sharply by action category: beneficiary updates reversible via custodian re-filing if caught quickly; ACATs in-flight 24-48 hour cancellation window depending on receiving custodian; trade executions create market exposure that may not be fully reversible. The Reg S-P 17 CFR Part 248 May 2024 amendments' 30-day breach clock and NY DFS 23 NYCRR 500's 72-hour notification both layer onto any agentic-action incident.
- The opt-in default through 2028 is OFF per L5 Ch3 L3 disclosure framework's agentic default posture. Each category is independently opt-in, independently revocable, with its own audit-log identifier. Wirehouse channels and aggregators tend toward stricter (mandatory advisor pre-action review even on opt-in); RIAs vary based on segment and L4 Ch3 L3 WSP architecture.
- $12B aggregator case study: 280 advisors, phased Q4 2026 - Q4 2028 rollout. Phase 1 rebalance + RMD + beneficiary, Phase 2 ACATs + 1040 amendments, Phase 3 limited trade execution. Q4 2028: rebalance 94% in-band handled without escalation; RMD 99.4% accuracy against IRS Pub 590-B; 1,400 beneficiary changes zero unwind; 380 ACATs with one in-flight cancellation; $4.2M realized tax-losses with no Reg BI Care deficiencies; kill-switch invoked twice; zero Reg S-P incidents; L4 Ch7 L1 audit framework 9/10. The agentic infrastructure became one of the top three valuation drivers in tuck-in conversations per Mercer Capital / ECHELON Q3-Q4 2025 framing (top-quartile ~8x-10x, premium-top ~11.6x, AI maturity +0.5x to +1.5x).
Skill.re