If an AI vendor holding your client information is breached, the duty to make sure your clients are told is yours. Regulation S-P is explicit: notwithstanding a firm's use of a service provider, "the obligation to ensure that affected individuals are notified ... rests with the covered institution." You can contract for the vendor to send the notices. You cannot contract away the responsibility for making sure they go out.
So the useful question is not whether your vendor is careful. It is what they have promised you in writing, how fast, and where that promise is recorded. We read the public documents of twenty-seven companies selling AI into wealth management and adjacent advisory work. Nineteen published enough to assess.
What we found
Ten of the nineteen publish a deadline. Nine say 72 hours, one says 48. Three more promise notice but state no period we could apply to a US advisory firm. For the remaining six we found no notification provision in the documents we read.
Eight of those ten keep it out of the privacy policy. Five put it in a data processing agreement, two in the terms of service, one in a subscription agreement on a different company's website. Read only the privacy policy and you would conclude that eight of these vendors promised you nothing.
Two of the nineteen name Regulation S-P. Both put the rule and the deadline in the same sentence, which tells you the number was written with an advisory firm's obligation in view. We found no reference to the FTC Safeguards Rule in any of the nineteen.
Every breach-notification deadline in this review runs to your firm, never to your client. Among the ten AI vendors that publish a deadline, we found no commitment to notify affected individuals or a regulator directly. That is not a gap in the contracts, it is how the rules are built. Their clock exists so you can meet a deadline that stays yours.
Three of the ten published deadlines carry qualifiers
One counts business hours rather than calendar hours, and the clause does not let you work out how much calendar time that is. One can be replaced by whatever your own master services agreement says, so the number that governs you is in your paperwork rather than on their website. One starts on a suspected breach rather than a confirmed one, which puts the vendor's investigation before your clock instead of inside it.
The number is the least interesting part of the clause. What starts it, what kind of hours it counts, and whether your contract overrides it all matter more than 48 versus 72.
Which deadline is yours depends on who registers you
If your firm is SEC-registered, Regulation S-P sets your deadline. Regulation S-P requires you to notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, as soon as practicable and no later than 30 days after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. Thirty days is the ceiling, not the target. There is no minimum number of affected people. The exception is narrow and has two parts: notice is not required only if, after a reasonable investigation, you determine that the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience. Your incident response program must also be reasonably designed to ensure service providers notify you as soon as possible and no later than 72 hours. These amendments have been in force since 3 December 2025 for advisers at $1.5 billion or more in assets under management, and since 3 June 2026 for everyone else.
One point worth keeping straight, because it is easy to assume otherwise. The paragraph of Regulation S-P that requires written documentation of a no-notice determination applies to certain unregistered investment companies, not to registered investment advisers. If your firm is an RIA, the reason to document that determination is your own books and records obligation under Advisers Act Rule 204-2, which is the same reason the answers to the nine questions below belong in a file.
If your firm is state-registered, the FTC Safeguards Rule is the more likely fit. The Safeguards Rule covers investment advisers who are not required to register with the SEC. It requires you to notify the FTC no later than 30 days after discovering an event involving the unencrypted information of 500 or more consumers. That notice runs to the regulator, not to your clients; client notice comes from state breach laws, which the FTC is explicit about not displacing. The rule also requires you to select, contract with, and monitor service providers on safeguards.
Either way the arithmetic is the same. Their hours, then your thirty days. What differs is who you owe the notice to.
The 72-hour service-provider window is also a diligence standard. Regulation S-P does not order you to insert a clause, only to maintain policies reasonably designed to get you that notice. But if a vendor has published nothing and you have obtained nothing, it is worth asking [what you would point to as evidence](/blog/a-policy-without-a-record/) that your program is reasonably designed.
Nine questions worth sending
- Will you notify us within 72 hours of becoming aware of a breach? Please point to the clause and tell us which document it is in.
- Are those calendar hours or business hours, and can our contract override the period?
- Where is our client data physically processed, including by any subcontractor?
- Please name every subprocessor and every model provider that touches our data.
- Is our data used to train any model, yours or a third party's, in any form including de-identified?
- What is your retention period, and what happens to our data when we terminate?
- Can we export our complete audit trail without requesting your permission?
- Do your records satisfy Advisers Act Rule 204-2, or do your terms disclaim that?
- What is your liability cap, and do you indemnify us?
Send all nine questions to the vendor in writing and keep the answers with the contract. The first question matters most, and not only for its content. A vendor who can name the clause and the document in a day has thought about your obligation.
What we read
Every AI vendor in this breach-notification review, with the deadline each one publishes and the document it appears in. Nineteen vendors, reviewed 12 August 2026. The deadline column records what the document says, not an assessment of the vendor.
| Vendor | Published deadline | Where we found it |
|---|---|---|
| WealthAi | 48 hours | Data processing agreement §9.1 |
| Egnyte | 72 hours | Data processing agreement §E.5.1 and §F.1.3 |
| FastTrackr AI | 72 hours | Privacy policy and terms of service |
| Hadrius | 72 hours, scoped to Regulation S-P data | Terms of service §5.5 |
| Hazel | 72 business hours | Altruist Software Subscription Agreement §11.3 |
| Jump | 72 hours from a suspected breach | Data processing agreement §7.1 |
| Orion | 72 hours, mutual between both parties | Data processing agreement §V |
| SideDrawer | 72 hours | Data processing agreement §8.1 |
| Strata AI | 72 hours | Privacy policy §19 and security page |
| Zocks | 72 hours, unless the firm's MSA specifies otherwise | Terms of service §6.4 |
| Hamachi.ai | Notice promised, no period stated | Privacy policy |
| SS&C Black Diamond | We found notice provisions only in the Australian and South African annexes | Privacy policy and annexes |
| Verapath | Notice by posting to their website, no period stated | Privacy policy |
| eMoney Advisor | We did not find a provision | Privacy policy and terms of service |
| Lira AI | We did not find a provision | Privacy policy and terms of service |
| Masttro | We did not find a provision | Privacy policy and terms of service |
| VastAdvisor | We did not find a provision | Privacy policy and terms of service |
| Verlo | We did not find a provision | Privacy policy and terms of service |
| WealthFluent | We did not find a provision | Privacy policy and terms of service |
The two vendors that name Regulation S-P, Hadrius and Zocks, say so plainly. Hadrius, terms of service §5.5: "For Security Incidents involving data subject to Regulation S-P, Hadrius shall notify Customer within seventy-two hours of confirmation." Zocks, terms of service §6.4: "In alignment with the newly adopted SEC amendments to Regulation S-P, Zocks will notify impacted customers of any unauthorized access to customer information within 72 hours of determining that such an incident occurred, unless a specific notice period is specified in your firm's MSA."
Method. We reviewed public documents from twenty-seven companies serving wealth management and its advisors; nineteen published enough to assess. For each we read the privacy policy, terms of service, data processing agreement where one exists, and any security or trust page. Reviewed 12 August 2026. One gap worth naming: for Egnyte we did not read the terms of service.
These findings describe what vendors publish, not their actual security or their practices. Several hold terms under non-disclosure that public documents do not reflect, and a negotiated agreement may say considerably more than a published one. Absence here means we could not find it, not that it does not exist. We have named the document each promise appears in so that any of this can be checked or corrected.
The practical implication
Vendor diligence tends to start and end at the privacy policy, because it is easy to find and reads like it should contain the answer. For eight of the ten vendors who committed to anything, it does not. Ask [the nine questions](/blog/nine-questions-to-send-any-ai-vendor/) before you sign, and file the answers where your next examiner or your next successor can find them.
Update, 17 August 2026. This article has been corrected in four places, all in the section on Regulation S-P. The client-notification deadline is "as soon as practicable, but not later than 30 days," and an earlier version gave only the thirty-day ceiling. The exception to notifying has two parts, past and prospective, and an earlier version stated only the prospective half. The requirement to document a no-notice determination sits in a paragraph of Regulation S-P that does not apply to registered investment advisers; for an RIA that documentation duty comes from Advisers Act Rule 204-2 instead. And the larger-entity threshold is "assets under management," which is the wording the SEC's adopting release uses. The vendor findings and the nine questions are unchanged.
Advisor Insights provides general professional information, not individualized investment, legal, cybersecurity, or compliance advice. Your obligations depend on your registrations, your systems, and your contracts, and should be confirmed with counsel. Regulatory descriptions are U.S. federal and current as of August 2026. Vendor findings reflect public documents reviewed on 12 August 2026 and may have changed since.