Technology governance

If Your AI Vendor Is Breached, You Have Thirty Days to Tell Your Clients

If my AI vendor is breached, what have they actually promised me, and where is that promise written down?

The duty to notify clients after a vendor breach sits with the advisory firm, not the vendor. Of nineteen AI vendors serving wealth management whose public documents we reviewed, ten publish a notification deadline, and eight of those ten put it in a data processing agreement, the terms of service, or a subscription agreement rather than the privacy policy. Two name Regulation S-P. Three of the ten deadlines carry qualifiers that change what they mean. The article closes with nine questions a firm can send any vendor.

If an AI vendor holding your client information is breached, the duty to make sure your clients are told is yours. Regulation S-P is explicit: notwithstanding a firm's use of a service provider, "the obligation to ensure that affected individuals are notified ... rests with the covered institution." You can contract for the vendor to send the notices. You cannot contract away the responsibility for making sure they go out.

So the useful question is not whether your vendor is careful. It is what they have promised you in writing, how fast, and where that promise is recorded. We read the public documents of twenty-seven companies selling AI into wealth management and adjacent advisory work. Nineteen published enough to assess.

What we found

Ten of the nineteen publish a deadline. Nine say 72 hours, one says 48. Three more promise notice but state no period we could apply to a US advisory firm. For the remaining six we found no notification provision in the documents we read.

Eight of those ten keep it out of the privacy policy. Five put it in a data processing agreement, two in the terms of service, one in a subscription agreement on a different company's website. Read only the privacy policy and you would conclude that eight of these vendors promised you nothing.

Two of the nineteen name Regulation S-P. Both put the rule and the deadline in the same sentence, which tells you the number was written with an advisory firm's obligation in view. We found no reference to the FTC Safeguards Rule in any of the nineteen.

Every breach-notification deadline in this review runs to your firm, never to your client. Among the ten AI vendors that publish a deadline, we found no commitment to notify affected individuals or a regulator directly. That is not a gap in the contracts, it is how the rules are built. Their clock exists so you can meet a deadline that stays yours.

Three of the ten published deadlines carry qualifiers

One counts business hours rather than calendar hours, and the clause does not let you work out how much calendar time that is. One can be replaced by whatever your own master services agreement says, so the number that governs you is in your paperwork rather than on their website. One starts on a suspected breach rather than a confirmed one, which puts the vendor's investigation before your clock instead of inside it.

The number is the least interesting part of the clause. What starts it, what kind of hours it counts, and whether your contract overrides it all matter more than 48 versus 72.

Which deadline is yours depends on who registers you

If your firm is SEC-registered, Regulation S-P sets your deadline. Regulation S-P requires you to notify each affected individual whose sensitive customer information was, or is reasonably likely to have been, accessed or used without authorization, as soon as practicable and no later than 30 days after becoming aware that unauthorized access to or use of customer information has occurred or is reasonably likely to have occurred. Thirty days is the ceiling, not the target. There is no minimum number of affected people. The exception is narrow and has two parts: notice is not required only if, after a reasonable investigation, you determine that the sensitive customer information has not been, and is not reasonably likely to be, used in a manner that would result in substantial harm or inconvenience. Your incident response program must also be reasonably designed to ensure service providers notify you as soon as possible and no later than 72 hours. These amendments have been in force since 3 December 2025 for advisers at $1.5 billion or more in assets under management, and since 3 June 2026 for everyone else.

One point worth keeping straight, because it is easy to assume otherwise. The paragraph of Regulation S-P that requires written documentation of a no-notice determination applies to certain unregistered investment companies, not to registered investment advisers. If your firm is an RIA, the reason to document that determination is your own books and records obligation under Advisers Act Rule 204-2, which is the same reason the answers to the nine questions below belong in a file.

If your firm is state-registered, the FTC Safeguards Rule is the more likely fit. The Safeguards Rule covers investment advisers who are not required to register with the SEC. It requires you to notify the FTC no later than 30 days after discovering an event involving the unencrypted information of 500 or more consumers. That notice runs to the regulator, not to your clients; client notice comes from state breach laws, which the FTC is explicit about not displacing. The rule also requires you to select, contract with, and monitor service providers on safeguards.

Either way the arithmetic is the same. Their hours, then your thirty days. What differs is who you owe the notice to.

The 72-hour service-provider window is also a diligence standard. Regulation S-P does not order you to insert a clause, only to maintain policies reasonably designed to get you that notice. But if a vendor has published nothing and you have obtained nothing, it is worth asking [what you would point to as evidence](/blog/a-policy-without-a-record/) that your program is reasonably designed.

Nine questions worth sending

  1. Will you notify us within 72 hours of becoming aware of a breach? Please point to the clause and tell us which document it is in.
  2. Are those calendar hours or business hours, and can our contract override the period?
  3. Where is our client data physically processed, including by any subcontractor?
  4. Please name every subprocessor and every model provider that touches our data.
  5. Is our data used to train any model, yours or a third party's, in any form including de-identified?
  6. What is your retention period, and what happens to our data when we terminate?
  7. Can we export our complete audit trail without requesting your permission?
  8. Do your records satisfy Advisers Act Rule 204-2, or do your terms disclaim that?
  9. What is your liability cap, and do you indemnify us?

Send all nine questions to the vendor in writing and keep the answers with the contract. The first question matters most, and not only for its content. A vendor who can name the clause and the document in a day has thought about your obligation.

What we read

Every AI vendor in this breach-notification review, with the deadline each one publishes and the document it appears in. Nineteen vendors, reviewed 12 August 2026. The deadline column records what the document says, not an assessment of the vendor.

VendorPublished deadlineWhere we found it
WealthAi48 hoursData processing agreement §9.1
Egnyte72 hoursData processing agreement §E.5.1 and §F.1.3
FastTrackr AI72 hoursPrivacy policy and terms of service
Hadrius72 hours, scoped to Regulation S-P dataTerms of service §5.5
Hazel72 business hoursAltruist Software Subscription Agreement §11.3
Jump72 hours from a suspected breachData processing agreement §7.1
Orion72 hours, mutual between both partiesData processing agreement §V
SideDrawer72 hoursData processing agreement §8.1
Strata AI72 hoursPrivacy policy §19 and security page
Zocks72 hours, unless the firm's MSA specifies otherwiseTerms of service §6.4
Hamachi.aiNotice promised, no period statedPrivacy policy
SS&C Black DiamondWe found notice provisions only in the Australian and South African annexesPrivacy policy and annexes
VerapathNotice by posting to their website, no period statedPrivacy policy
eMoney AdvisorWe did not find a provisionPrivacy policy and terms of service
Lira AIWe did not find a provisionPrivacy policy and terms of service
MasttroWe did not find a provisionPrivacy policy and terms of service
VastAdvisorWe did not find a provisionPrivacy policy and terms of service
VerloWe did not find a provisionPrivacy policy and terms of service
WealthFluentWe did not find a provisionPrivacy policy and terms of service

The two vendors that name Regulation S-P, Hadrius and Zocks, say so plainly. Hadrius, terms of service §5.5: "For Security Incidents involving data subject to Regulation S-P, Hadrius shall notify Customer within seventy-two hours of confirmation." Zocks, terms of service §6.4: "In alignment with the newly adopted SEC amendments to Regulation S-P, Zocks will notify impacted customers of any unauthorized access to customer information within 72 hours of determining that such an incident occurred, unless a specific notice period is specified in your firm's MSA."

Method. We reviewed public documents from twenty-seven companies serving wealth management and its advisors; nineteen published enough to assess. For each we read the privacy policy, terms of service, data processing agreement where one exists, and any security or trust page. Reviewed 12 August 2026. One gap worth naming: for Egnyte we did not read the terms of service.

These findings describe what vendors publish, not their actual security or their practices. Several hold terms under non-disclosure that public documents do not reflect, and a negotiated agreement may say considerably more than a published one. Absence here means we could not find it, not that it does not exist. We have named the document each promise appears in so that any of this can be checked or corrected.

The practical implication

Vendor diligence tends to start and end at the privacy policy, because it is easy to find and reads like it should contain the answer. For eight of the ten vendors who committed to anything, it does not. Ask [the nine questions](/blog/nine-questions-to-send-any-ai-vendor/) before you sign, and file the answers where your next examiner or your next successor can find them.

Update, 17 August 2026. This article has been corrected in four places, all in the section on Regulation S-P. The client-notification deadline is "as soon as practicable, but not later than 30 days," and an earlier version gave only the thirty-day ceiling. The exception to notifying has two parts, past and prospective, and an earlier version stated only the prospective half. The requirement to document a no-notice determination sits in a paragraph of Regulation S-P that does not apply to registered investment advisers; for an RIA that documentation duty comes from Advisers Act Rule 204-2 instead. And the larger-entity threshold is "assets under management," which is the wording the SEC's adopting release uses. The vendor findings and the nine questions are unchanged.

Advisor Insights provides general professional information, not individualized investment, legal, cybersecurity, or compliance advice. Your obligations depend on your registrations, your systems, and your contracts, and should be confirmed with counsel. Regulatory descriptions are U.S. federal and current as of August 2026. Vendor findings reflect public documents reviewed on 12 August 2026 and may have changed since.

Primary sources

ValaisOS is building a more enduring operating foundation for private-wealth professionals.

Request early access