The financial services industry is experiencing a seismic shift as artificial intelligence (AI) rapidly ascends to the forefront of compliance priorities, eclipsing long-standing concerns like cybersecurity. A comprehensive new survey conducted by ACA Group, in collaboration with the Investment Adviser Association and Yuter Compliance Consulting, underscores this dramatic pivot, revealing that AI has become the paramount compliance concern for a significant majority of firms. The findings suggest a decisive move from mere awareness of AI’s potential impact to active implementation and resource allocation, though critical gaps in oversight and policy development persist.

The 2026 Investment Management Compliance Testing Report, based on online surveys of 411 firms conducted in April and May of 2026, paints a clear picture of this evolving landscape. AI was identified as the top compliance concern by a staggering 85% of respondents. This figure represents a substantial leap, outpacing cybersecurity, the second-highest concern, by a remarkable 50 percentage points. This margin of dominance is unprecedented in the 21-year history of ACA Group’s annual survey. Carlo di Florio, President of ACA Group, emphasized the historic nature of this finding, stating that no single topic has ever commanded such a commanding separation from other issues in the firm’s extensive research.

"What makes this year’s results particularly meaningful is that firms are no longer just naming AI as a concern; they are allocating compliance resources, standing up governance committees and increasing testing," di Florio remarked. However, he cautioned that the work is far from complete, highlighting persistent deficiencies in crucial areas. "But the gaps in human oversight, output validation and third-party AI policies tell us the work is far from done."

The Rise of AI as a Compliance Priority: A Timeline of Growing Concern

The surge in AI’s prominence as a compliance concern did not occur overnight. While AI has been a topic of discussion in the financial sector for several years, its practical implications for compliance departments began to crystallize more acutely in the preceding 18-24 months leading up to the survey. Early discussions often centered on the theoretical risks and potential benefits of AI adoption. As firms began to experiment with and integrate AI tools into their operations, the tangible compliance challenges associated with these technologies became increasingly apparent.

The ACA Group’s previous survey, conducted in 2025, had already indicated a growing awareness of AI’s compliance implications. However, the 2026 report reveals a significant escalation, with the percentage of respondents marking AI as a chief concern increasing by 28 percentage points from the previous year. This rapid acceleration suggests that firms have moved beyond theoretical discussions and are actively grappling with the practical realities of AI deployment. The data points to a critical period of transition, where initial exploration has given way to a more structured, albeit incomplete, approach to AI governance.

Survey Demographics and AI Adoption Landscape

The survey’s respondents represent a diverse cross-section of the investment management industry. The majority of firms reported assets under management ranging from $1 billion to $10 billion. These firms were evenly distributed in their client focus, serving private funds, institutional clients, and high-net-worth individuals, or a combination thereof. A notable segment of respondents, approximately 34%, also indicated working with retail clients (accounts under $1 million), while 24% engaged with family offices. This broad representation ensures that the survey’s findings reflect a wide spectrum of industry practices and concerns.

The adoption of AI tools among these firms is widespread. Approximately 80% of respondents reported currently utilizing AI tools. Of these, a significant majority, 70%, have confined AI’s application to internal use cases. A smaller proportion, 10%, are employing AI both internally and externally. The remaining 18% of firms are actively exploring AI adoption but have not yet implemented any tools, while a small but notable 2% have either banned or significantly restricted the use of AI. This data suggests that while AI is becoming ubiquitous, its integration into client-facing activities or broader market operations is still more cautious.

Establishing the Framework: Policies, Governance, and Testing

In response to the escalating concerns, a substantial number of firms have taken foundational steps to govern AI within their organizations. According to the ACA Group’s findings, 86% of surveyed firms have established policies and procedures specifically addressing employee use of AI. This indicates a proactive approach to setting internal guidelines and expectations for AI engagement.

Further demonstrating a commitment to structured AI management, 59% of firms have instituted AI governance committees. These committees are likely tasked with overseeing AI strategy, risk assessment, and policy enforcement. Complementing these governance structures, 72% of firms reported having completed compliance testing for AI tools. This suggests that firms are not only creating rules but also verifying that AI implementations adhere to established compliance standards.

Persistent Gaps in Oversight and Third-Party Risk Management

Despite these positive developments, the survey unequivocally highlights critical areas where firms are lagging. Less than half of the respondents (48%) reported having formal plans in place for "human-in-the-loop" oversight of AI outputs. This is a significant concern, as it implies that in many cases, the decisions or information generated by AI systems may not be subject to adequate human review and validation, increasing the risk of errors, biases, or unintended consequences.

ACA Group: AI Skyrockets as Firms’ Top Compliance Concern

Even more pronounced is the deficiency in policies governing the use of third-party AI. Only 30% of firms have established comprehensive policies addressing the use of AI tools provided by external vendors. This oversight is particularly concerning given the increasing reliance on third-party AI solutions across the industry. The ACA Group specifically flagged this as a key area requiring more attention from firms.

Navigating Third-Party AI Risk: A Critical Challenge

The survey’s deep dive into third-party risk management reveals a landscape where firms are beginning to address vendor-related AI risks, but progress is uneven. Six in ten firms have made or are making "significant" changes to their third-party risk management programs. This proactive stance suggests an acknowledgment of the heightened risks associated with external AI providers.

Furthermore, 48% of firms have completed compliance testing on vendor due diligence, indicating a nascent but growing focus on vetting AI vendors. In line with this, 69% have updated their third-party risk procedures, and 58% have introduced or revised vendor risk-tiering criteria, differentiating between "critical" and "non-critical" vendors. These efforts are crucial for categorizing and prioritizing vendor oversight.

However, the effectiveness of these measures appears to be limited in practice. Only 31% of firms have improved internal tracking mechanisms for third-party AI risks, and a mere 27% have implemented or enhanced continuous or periodic vendor risk reviews. This suggests that while firms are updating their frameworks, the ongoing monitoring and evaluation of third-party AI solutions may not be robust enough to effectively mitigate evolving risks. The implications are significant: a failure to adequately manage third-party AI risks could expose firms to data breaches, regulatory non-compliance, and reputational damage.

Beyond AI: Other Pressing Compliance Concerns

While AI has captured the lion’s share of attention, other critical compliance areas continue to demand significant resources and focus. Cybersecurity remains a top concern for 37% of respondents, underscoring its persistent importance in the financial sector. Privacy and Regulation S-P considerations are also high on the agenda for 35% of firms. Advertising and marketing compliance, an area that has historically required careful navigation, is a concern for 19% of respondents.

In the realm of cybersecurity, firms are actively reviewing and updating their incident response plans (81% of respondents) and business continuity plans (88% annually). However, the frequency of actual testing for these plans is lower. Only 77% of respondents reported conducting yearly testing for business continuity plans. The scenarios most frequently tested include cybersecurity incidents (62%), critical vendor or service outages (48%), and facility inaccessibility (46%). This data suggests a potential vulnerability if untested plans are put to the test during a real-world crisis.

The "Mile Wide, Inch Deep" Dilemma: AI’s Limited Scope in Practice

The paradox of AI’s rapid ascent and its practical application within compliance departments is further illuminated by commentary from ACA Group’s leadership. Joseph Kochansky, ACA’s head of product and engineering, previously described the current state of AI adoption in compliance as "mile wide and an inch deep." This sentiment stems from a prior ACA Group survey that revealed that while 84% of respondents reported using AI, "active AI use" occurred in only two out of twenty compliance and operations sub-functions, on average. Alarmingly, only 18% of firms reported using AI specifically for compliance tasks.

The most common compliance-related application of AI identified in that earlier survey was "compliance program administration," cited by 35% of users. This broad category encompassed day-to-day tasks such as summarizing reports, drafting initial communications, and reviewing policies and disclosures. However, it is crucial to note that this sub-function often included users leveraging readily available desktop AI tools like Claude, Microsoft Copilot, and ChatGPT. While these tools offer ease of use for individual tasks, Kochansky pointed out that they can be "cumbersome when applied to firms’ compliance management" at a broader organizational level. This suggests that the current widespread use of AI in compliance may be superficial, lacking the deep integration and strategic application needed to truly transform compliance functions.

Implications and the Road Ahead

The ACA Group’s 2026 Investment Management Compliance Testing Report delivers a critical message: AI is no longer a peripheral concern but a central focus for compliance leaders. The industry is demonstrating a clear intent to integrate AI into its operational fabric, evidenced by the establishment of policies, governance structures, and testing protocols. However, the report also serves as a stark reminder that the journey is far from over.

The identified gaps in human oversight of AI outputs and the underdeveloped policies for third-party AI use present significant risks. As AI technologies continue to evolve at an unprecedented pace, firms must accelerate their efforts to ensure robust governance, comprehensive risk management, and diligent oversight. Failure to do so could not only lead to regulatory penalties and financial losses but also erode the trust that is fundamental to the financial services industry. The coming years will be crucial in determining whether firms can successfully navigate the complexities of AI compliance, moving from a state of broad awareness to one of deep, effective, and responsible integration. The industry’s ability to manage these emerging challenges will be a key determinant of its future success and stability.

By