AI compliance obligations for a wealth management firm in the EU
4 AI-adoption compliance obligations apply, each cited to primary law.
AI that touches advice or suitability must stay inside your conduct rules
Rule: MiFID II Art 24 & 25
What it requires: Where an AI tool contributes to a personal recommendation or a suitability assessment, the firm remains fully responsible for acting honestly, fairly and professionally in the client's best interests, and for the suitability of the outcome. AI does not shift the conduct obligation off the firm.
Do this: Map every AI tool that can touch an advice, suitability or client-communication workflow, and keep a human sign-off on any output that reaches a client. Treat the tool as a drafting aid inside your existing suitability process, not a replacement for it.
Source: Directive 2014/65/EU (MiFID II), Articles 24-25; ESMA Public Statement on the use of Artificial Intelligence in the provision of retail investment services, 30 May 2024 (ref ESMA35-335435667-5924).
Confidence: Sourced
Keep records of the services and transactions the AI helps produce
Rule: MiFID II Art 16(6)
What it requires: The firm must arrange for records to be kept of all services, activities and transactions sufficient to let the competent authority monitor compliance, including where an AI system drafted, screened or supported the work.
Do this: Log which AI tool was used, on what input, and who reviewed the output, alongside the underlying client record, so the record of the service is complete whether or not a model was in the loop.
Source: Directive 2014/65/EU (MiFID II), Article 16(6).
Confidence: Sourced
Record and retain relevant client communications
Rule: MiFID II Art 16(7)
What it requires: Records of telephone conversations and electronic communications relating to (at least) transactions and the reception, transmission and execution of orders must be kept, and retained for five years, extendable to seven by the competent authority.
Do this: Make sure any AI that summarises calls, drafts client emails or transcribes meetings writes into a retained store, not an ephemeral chat. The retention obligation attaches to the communication, not to the tool.
Source: Directive 2014/65/EU (MiFID II), Article 16(7); Commission Delegated Regulation (EU) 2017/565 Art 72.
Confidence: Sourced
Guard automated decisions and disclose AI to the client
Rule: GDPR Art 22 & AI Act Art 50
What it requires: A client has the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (GDPR Art 22). Separately, under the EU AI Act, natural persons must be informed when they are interacting with an AI system unless it is obvious (Art 50 transparency).
Do this: Keep a person in the loop on any client-affecting decision, and add a short AI-use disclosure to client-facing material where a model contributed, the same disclosure Serra puts on its own briefings.
Source: Regulation (EU) 2016/679 (GDPR), Article 22; Regulation (EU) 2024/1689 (AI Act), Article 50.
Confidence: Sourced