AI strategy for investment firms: what investment leaders need to own

Artificial intelligence entered the investment process faster than the authority to direct it. This is a working account of the decisions senior investment professionals are now expected to own, covering where the technology creates advantage as well as where it creates exposure, and what competence it takes to make those calls well.

International Council for Derivative Trading (ICFDT)  ·  Reviewed August 2026
On this page
  1. The work has a name
  2. Where the advantage actually is
  3. The architecture decisions
  4. The control decisions
  5. Who owns which decision
  6. Four stages of adoption
  7. Building the competence
  8. Questions we are asked

Most firms did not decide to adopt artificial intelligence. It arrived through the side door, in the form of analysts pasting filings into general models to summarize them, research teams trialing tools that promise to surface signals, and vendors appearing every week with something that compresses a week of work into an afternoon. Very little of this was directed at the point it began, most of it happens below the level where leadership can see it clearly, and the result is that a great many investment firms are already producing AI-influenced work without having decided how that work should be produced.

That broader pattern is visible in the regulatory record. In February 2026, the Director of the SEC’s Division of Investment Management said many investment advisers were already using AI, while adoption remained uneven and often tentative.[1] FINRA likewise reports that firms are implementing generative AI particularly for internal processes and information retrieval.[2]

The people who now have to sort this out spent fifteen to twenty-five years becoming expert allocators of capital. The advice they are usually given, that senior investors should acquire programming and machine learning skills, answers the wrong question. Your firm does not need you to build these systems and gains very little if you spend a year learning to build them badly. What it needs from you is judgment about how the systems should be used, which is a distinct professional competence rather than a lighter version of engineering.

Two framings dominate the discussion and both are incomplete. The first treats AI as a compliance problem, producing a policy, a committee, and very little change in how research is actually done. The second treats it as a procurement problem, producing a collection of tools nobody has placed inside the investment process. The firms getting real value are doing something harder, which is deciding where in their process artificial intelligence produces better decisions, redesigning the work around that answer, and building the controls that let them rely on the result.

The work has a name

The function that spans these decisions is financial intelligence architecture, and the practitioner performing it is a Financial Intelligence Architect.

Canonical definition

A Financial Intelligence Architect is a finance professional who designs, evaluates, integrates, and governs the systems through which artificial intelligence, financial data, and human judgment combine to support financial decision-making.

Definition maintained by ICFDT. See the full reference entry: What is a Financial Intelligence Architect?

The distinction worth holding onto is that this is broader than AI governance. Governance establishes policies, controls, and oversight for the technology. Financial intelligence architecture covers the complete decision architecture, meaning the system, the information environment feeding it, the financial use case it serves, the workflow around it, the controls applied to it, the people making the resulting decisions, and the accountability structure over the outcome. Governance is one component of that scope rather than the whole of it, which is why a firm that has written an AI policy and stopped there has addressed only one part of the work.

The reference entry linked above covers the function in full, including how it compares with adjacent roles such as machine learning engineer, quantitative analyst, and model risk professional, along with the competency areas relevant to the function. What follows here is the operational version, meaning the decisions themselves.

Where the advantage actually is

For many investment firms, some of the clearest early gains appear in research and information retrieval, while the more durable advantage can come from the firm-specific data environment that competitors cannot reproduce simply by licensing the same model.

It is worth being concrete about where artificial intelligence changes investment work, because the defensive conversation has crowded out the productive one. In most firms the earliest real gains appear in research, where the constraint has always been the number of hours a capable analyst can spend reading. Systems that summarize filings, extract comparable disclosures across a peer set, surface changes in language between reporting periods, and assemble the first draft of a company note compress that constraint substantially. The gain is not that the machine produces the judgment. It is that the analyst can reach the judgment after covering substantially more source material in the same period. FINRA’s 2026 oversight report identifies summarization and information extraction as the leading GenAI use case among its member firms.[2]

The same logic applies to monitoring, where coverage has always been rationed by attention. A system watching a defined universe for the conditions you specified does not get tired at four in the afternoon, which makes it well suited to the surveillance layer beneath a portfolio and poorly suited to deciding what the observations mean. FINRA has specifically identified financial-data analysis, research summarization, and surveillance support among potential GenAI applications in securities firms.[5]

Underneath both sits the part that produces lasting advantage. Any competitor can license the same model you did, so the model is not the edge. What cannot be replicated is the accumulated proprietary material a firm holds, meaning its own research history, its notes from management meetings, its internal debate about positions it took and positions it declined. A firm that has organized that material so its own systems can search it holds something no vendor sells. A firm whose research lives in inconsistent formats across disconnected systems will get disappointing results regardless of which model it buys, and will usually conclude the technology failed when the data foundation was never ready.

Function What AI changes What capturing it requires
Fundamental research Breadth of coverage per analyst hour, speed to first draft, systematic comparison across a peer set Governed tool access and a review standard people actually follow
Portfolio monitoring Continuous surveillance against defined conditions rather than periodic review Clear specification of what constitutes a signal worth escalating
Internal knowledge Institutional memory becomes searchable rather than dependent on who remembers A retrieval layer, and research organized well enough to sit underneath it
Investment workflow The sequence of research work is redesigned rather than accelerated in place Willingness to change the process instead of bolting tools onto it
Client and reporting work Drafting, tailoring, and query handling absorb far less senior time Review before anything client-facing leaves the firm

The last row of that table is where most firms find their quickest uncontroversial win, and the fourth is where the largest gains hide. Applying these systems to a process designed around the constraints of manual work produces a modest improvement. Asking what the research process would look like if breadth were cheap and synthesis were fast produces a different answer, and that redesign is an investment leadership decision rather than a technology one.

The architecture decisions

These determine what the firm is capable of. They come before the control decisions, because controls applied to an architecture nobody chose deliberately tend to be controls in name only.

Whether analysts should be using general AI models

Provide one governed, contracted tool good enough that nobody has reason to reach for an ungoverned one, then keep the data boundary short enough that people remember it.

The practical choice is between governed and ungoverned use. A prohibition without a usable approved alternative can push activity onto personal accounts and devices, where the firm has less visibility. Firms should therefore evaluate the contractual data-use, retention, access, security, and confidentiality terms of any approved service rather than assume consumer and commercial offerings are equivalent. As of August 2026, both OpenAI and Anthropic state that inputs and outputs from their commercial offerings are not used for model training by default, subject to their respective terms and opt-in arrangements.[6][7] Governed use should still be paired with a short, memorable statement of what may not be entered. The failure mode is a well-meaning analyst who did not recognize a draft, client record, or internal research note as sensitive.

What an internal system should be allowed to see

Grant the least access the use actually requires, and treat any connection you could not reconstruct six months later as a connection you have not really made.

The instinct of most implementations is to connect the model to as much as possible, on the theory that more context produces better answers. Inside an investment firm that instinct is dangerous, because the information a firm holds is not uniform in sensitivity and a system that can see everything can surface anything, including combinations of information no single person was supposed to hold at once. Sort the firm’s material into tiers before deciding what any system may touch: public and published, internal but non-sensitive, proprietary research and positioning, and finally client information and anything touching material nonpublic information, which is governed by obligations that predate AI and that AI does not soften.

Whether the firm needs its own knowledge layer

A retrieval layer over your own research pays when that research is both substantial and reasonably organized. When it is neither, the first investment belongs in the research and its organization.

A general model answers from what it absorbed in training, which makes it fluent, broad, and unaware of anything specific to your firm. Retrieval sits above this, storing your documents so the system can search them, pulling relevant passages when a question is asked, and grounding the answer in your material with citations back to the source. That grounding is what makes such a system usable where an unsupported assertion is worthless. The value of the layer is bounded above by the quality of what sits underneath it, which is why the sequencing matters more than the software.

Build or buy

Buy the general capability, build only the thin layer that encodes something genuinely proprietary, and decline to build the parts that are hard, generic, and improving on their own.

Buying is the right default for most firms most of the time, because vendor capabilities are improving quickly and the cost of maintaining a system in a field where the underlying technology turns over faster than internal projects can keep pace is routinely underestimated. The case for building rests on a narrow claim, that the capability sits close enough to the firm’s actual edge that owning it matters and no vendor can supply it without requiring you to hand over the proprietary material you should be most reluctant to share. The failure mode on the buying side is a sprawl of overlapping tools, none integrated, together creating a surface nobody can see across.

Where autonomous agents belong

Let agents run where an error is contained and recoverable. Keep them out of any step where the action moves client capital or reaches a client.

The distinction that matters is whether a system assists a decision a person makes or takes an action on its own. Agents are genuinely useful for work that is well defined, repetitive, and low in consequence, including gathering and organizing information, monitoring for defined conditions, and handling routine process. The property that makes them efficient, that they act without stopping for approval, is precisely the property you do not want near a fiduciary decision. This is a judgment about where the firm is willing to place an action taken without a person choosing to take it, and it can be revisited as controls mature. FINRA specifically identifies autonomy, scope and authority, auditability, and data sensitivity among the risks firms should consider when deploying AI agents.[2]

The control decisions

These determine whether the firm can rely on what the architecture produces, and whether it can explain itself afterward.

How AI-assisted research is reviewed

Treat AI output as a draft from a capable but unaccountable source. Verify anything a decision will rest on against a primary source, and keep accountability with the named human.

A model does not signal uncertainty the way a junior analyst does. An analyst who is unsure hedges and flags the thinness of the evidence, which cues the reader to check. A model that is entirely wrong sounds precisely as assured as one that is entirely right, produces citations that look correct and are sometimes invented, and assembles a confident narrative from fragments in a way that reads as analysis. That is why a plausible, well-written piece of AI-assisted research is an efficient vehicle for a subtle error to travel from a prompt into a position. Calibrate the depth of review to what rests on the output, so that anything leaving the firm or moving capital receives the full discipline and lighter uses do not collect a requirement people will quietly route around. FINRA explicitly flags hallucinations and recommends validation and human-in-the-loop review of GenAI outputs as part of firms’ controls.[2]

Which decisions stay with a human

Define the boundary before a system becomes capable enough to make crossing it tempting, and place it where fiduciary accountability sits rather than where current capability happens to end.

For registered investment advisers, using AI does not displace the adviser’s underlying fiduciary obligations. The SEC continues to describe an investment adviser as owing duties of care and loyalty to its clients.[4] That makes the human-control boundary a question of accountability as well as capability. Some decisions may therefore warrant a named human decision-maker even when a system could technically perform more of the work. Settling that boundary early is easier than settling it under commercial pressure once a system is performing well.

Whether AI influence can be reconstructed afterward

If you could not reconstruct how AI influenced a decision six months later, you cannot defend that decision, and in a fiduciary business the ability to defend a decision after the fact is not a nicety.

This is the question that converts intention into something that survives contact with a regulator or a client. It requires knowing what the system was given, what it returned, who reviewed it, and what was done as a result. Firms that treat this as a documentation problem to be solved later may discover the records they need were never created. FINRA notes that monitoring can include storing prompt and output logs, tracking model versions, and validating outputs, while the NIST AI Risk Management Framework emphasizes documentation as a means of improving transparency, human review, and accountability.[2][3]

What to ask AI vendors

Shift the evaluation away from the demonstration, which the vendor controls, toward the data handling, failure behavior, exit terms, and accountability, which you will live with.

The demonstration shows the system working on a case the vendor chose. What you need to know is how it behaves on the cases the vendor did not choose. A serious vendor answers direct questions about retention, error behavior, and lock-in plainly, and the ease with which a vendor engages with the list below is itself among the more reliable signals available.

  1. What happens to the data we submit, is it retained, and is it ever used to train models other clients benefit from?
  2. When the system is wrong, how is it wrong, and can you show us cases where it failed rather than only cases where it succeeded?
  3. Where does our proprietary information sit, who can access it, and can we retrieve and delete all of it on exit?
  4. What are we locked into, and what happens to anything we have built on top of you if we leave?
  5. How do you handle the underlying model changing, given that the capability we are buying may be replaced within a year?
  6. Can you produce, for any output, a record of what the system was given and what it returned?
  7. Who is contractually accountable when the system contributes to a decision that goes wrong?

Who owns which decision

Technology owns the systems and compliance owns the obligations. The layer that goes unowned is the investment judgment about how AI belongs in the investment process, and it has to sit with a named senior person on the investment side.

Both technology and compliance hold legitimate claims to part of this, and firms rarely get either wrong, because each maps onto responsibilities those functions already hold. The gap opens where neither can reach, since deciding how these systems belong inside the investment process requires knowing how investment decisions are actually made. When that layer is left undefined it does not stay empty. It gets absorbed by whichever function is willing to take it, which can leave the investment use case without a clearly accountable owner. NIST’s AI Risk Management Framework similarly calls for clearly documented roles and responsibilities and places responsibility for AI risk decisions with executive leadership.[3]

Decision Natural owner Consulted
Where AI sits in the investment process Investment leadership Technology, research heads
Which tools are approved for use Investment leadership Technology, compliance, security
What data a system may access Investment leadership Compliance, technology, data owners
Review standard for AI-assisted work Investment leadership Research heads, compliance
Which decisions require a human Investment leadership Compliance, risk
Platform, integration, and security Technology Investment leadership
Recordkeeping and disclosure Compliance Investment leadership, technology
Model validation and monitoring Risk or model risk Investment leadership, technology

The pattern in that table is the point. Most rows sit with the investment side, which is precisely the function least likely to have been given a structured way to think about them.

Four stages of adoption

Firms tend to move through recognizable stages, and knowing which one you are in tells you what the next useful step is. Skipping stages generally fails, because each depends on the foundation laid by the one before it.

Stage What it looks like The next step
Experimental Individuals use general tools on their own initiative. No approved provider, no data boundary, no visibility at the leadership level. Establish governed access and a short data boundary
AI-assisted An approved tool is in place and used across research and drafting. The process itself is unchanged and gains are individual rather than institutional. Define the review standard, then redesign one workflow around the new constraint
Integrated AI is embedded in defined workflows with review standards, and the firm’s own material is reachable through a retrieval layer. Establish reconstruction and documentation before scale exposes the gap
AI-native The investment process is designed around what these systems make cheap, with ownership named, controls operating, and AI involvement in any decision reconstructable. Extend deliberately, and keep the human boundary fixed as capability grows

Establish where your firm currently stands

The AI Readiness Assessment for Investment Firms scores a firm across strategy, models, data, research, governance, vendors, and accountability, returns a stage from the four above, and identifies the gap costing the firm the most at present. It takes about ten minutes, requires no account, and is built to be shared with an investment committee.

Take the assessment

Building the competence

Reading back through the decisions above, none is a coding problem and all are judgment problems, each asking how a person who understands the investment business should design, evaluate, place, and take responsibility for artificial intelligence inside the investment process. That competence is teachable, and it is examinable.

The Chartered Financial Intelligence Architect (CFIA) designation, administered by ICFDT, covers this body of knowledge across seven examined modules. Its weighting reflects the balance described on this page rather than a compliance reading of the subject, with the practice side carrying more of the examination than the control side.

Module Covers Weight
Risk, compliance and AI governance Model risk, explainability, regulatory landscape, governance frameworks, cybersecurity 20%
AI for alpha generation and research AI-assisted fundamental research, signal generation, portfolio construction, execution 18%
Investment data infrastructure Market data architecture, research platforms, knowledge systems, signal integrity 16%
Foundation models and AI systems How models and agents work strategically, design patterns, retrieval, vendor landscape 13%
The AI-native investment firm Maturity models, organizational design, human-AI teaming, process redesign 12%
Vendor strategy and build/buy architecture Build versus buy frameworks, AI vendor due diligence, RFP design, integration 11%
AI leadership, ethics and fiduciary duty Business case construction, AI strategy, ethics, fiduciary accountability 10%

The designation requires no programming background and no prior credential. It is examined over 200 questions in four hours, charterholders are listed in a public registry that employers and clients can search without an account, and the curriculum is updated annually, which matters in a field where a body of knowledge fixed in place goes stale within a year.

Next steps

The CFIA Body of Knowledge sets out the full competency framework module by module, with examination weightings, and is the most direct way to judge whether the curriculum covers what your firm needs.

View the CFIA designation and enroll  ·  Enrollment for investment teams

Questions we are asked

Is the CFIA an AI governance credential?

Only in part. Governance and compliance form one of seven examined modules at 20 percent of the examination, while the practice side carries more weight in aggregate, covering AI for alpha generation and research at 18 percent, investment data infrastructure at 16 percent, foundation models and AI systems at 13 percent, the AI-native investment firm at 12 percent, and vendor strategy at 11 percent. The designation covers how artificial intelligence is used in investment work as well as how it is controlled.

Where do investment firms actually get value from AI?

The earliest gains usually appear in research, where breadth of coverage per analyst hour has always been the binding constraint, and in client and reporting work, where drafting absorbs senior time. The durable advantage comes from the firm’s own accumulated research and institutional knowledge, since any competitor can license the same model but none can license your research history.

Who should own AI decisions inside an asset manager?

Technology owns the platform and compliance owns the regulatory obligations, but the judgment about where AI belongs in the investment process, which tools are approved, what data they may access, and what review their output receives belongs to a named senior person on the investment side. Left undefined, that layer is absorbed by whichever function is willing to take it.

Should investment firms allow analysts to use ChatGPT or Claude?

Yes, under governed access. Prohibition without an approved alternative pushes usage onto personal accounts where the firm has no visibility. The workable answer is one contracted enterprise tool whose terms keep submitted content out of the provider’s training data, paired with a short statement of what may not be entered, which is proprietary research, client identities and holdings, and anything touching material nonpublic information.

Does a senior investment professional need to learn to code?

No. The decisions that determine whether a firm uses AI well concern where it belongs in the process, what data it may access, how its output is evaluated, and who is accountable. Those require investment judgment rather than engineering skill, and software engineers implement the systems that result.

How is financial intelligence architecture different from AI governance?

AI governance establishes policies, controls, and oversight for the technology. Financial intelligence architecture covers the complete decision architecture, including the financial use case, the information environment, the workflow, the human decision-makers, and the accountability structure. Governance is one component of that scope. The reference entry on the function sets out the distinction in full.

Should an investment firm build its own AI system or buy one?

Most firms should buy the general capability and build only the thin layer that encodes something genuinely proprietary. Building a general capability that vendors already provide better tends to produce a system a year behind the market while consuming staff who should have been doing other work.

How should AI-assisted investment research be reviewed?

As a draft from a capable but unaccountable source. Every factual claim a decision would rest on is verified against a primary source, every citation is checked, and the analyst whose name appears on the work owns its accuracy. Depth of review should scale with what rests on the output.

Selected external sources and regulatory context

  1. U.S. Securities and Exchange Commission, Division of Investment Management. Brian Daly, Artificial Intelligence and the Future of Investment Management, February 3, 2026. Daly stated that many advisers were already using AI while adoption remained uneven and often tentative. These remarks were delivered in his official capacity but do not necessarily reflect the views of the Commission, Commissioners, or other staff. Source.
  2. FINRA. GenAI: Continuing and Emerging Trends, 2026 Regulatory Oversight Report. FINRA discusses observed use cases including summarization and information extraction, and considerations around hallucinations, governance, documentation, prompt/output logging, human review, and AI-agent risks. Source.
  3. National Institute of Standards and Technology. Artificial Intelligence Risk Management Framework (AI RMF 1.0). The framework addresses governance, documentation, accountability, human-AI roles, ongoing monitoring, and executive responsibility for AI risk decisions. Source.
  4. U.S. Securities and Exchange Commission, Division of Examinations. Fiscal Year 2025 Examination Priorities. The Division states that an investment adviser owes duties of care and loyalty to clients and must serve clients’ best interests. Source.
  5. FINRA. Regulatory Notice 24-09, FINRA Reminds Members of Regulatory Obligations When Using Generative Artificial Intelligence and Large Language Models, June 27, 2024. FINRA notes applications in financial-data analysis, document summarization, research, surveillance, and the associated concerns around accuracy, privacy, bias, intellectual property, and security. Source.
  6. OpenAI. Business data privacy, security, and compliance. OpenAI states that, by default, it does not use inputs or outputs from its business products and API platform to train or improve its models, and describes retention and access controls for business offerings. Source.
  7. Anthropic. Is my data used for model training? Anthropic states that, by default, inputs and outputs from its commercial products are not used to train its models, subject to explicit feedback or other opt-in arrangements. Source.

Further reading: the reference entry on the Financial Intelligence Architect function; the Chartered Financial Intelligence Architect (CFIA) designation and its Body of Knowledge; the public charterholder registry and Code of Professional Conduct; the FINRA designation profile; and Michael Clark, Governing Algorithmic Capital: Principal-Agent Theory, AI Accountability Gaps, and the Case for the Chartered Financial Intelligence Architect.