PROSPERO WEALTH AI POLICY
1. Purpose and Philosophy
Prospero Wealth (“Prospero,” “the Firm,” “we”) believes that thoughtful, well-governed use of artificial intelligence (“AI”) is a defining advantage in serving our clients.
Used well, AI lets us deliver more personalized advice, more responsive service, and more rigorous analysis than would otherwise be possible.
Used carelessly, AI creates risks to client privacy, data integrity, regulatory standing, and the trust on which our fiduciary relationships depend.
This policy is designed to enable maximum, durable use of AI — including AI systems that process client personally identifiable information (“PII”) — while ensuring that every such use is consistent with our fiduciary duty under the Investment Advisers Act of 1940, applicable privacy laws, and the reasonable expectations of our clients. The Firm’s default posture is “yes, with controls,” not “no.” Where the controls in this policy are followed, employees are encouraged to use AI assertively to improve client outcomes.
2. Guiding Principles
All AI use at Prospero is governed by the following principles, which take precedence in any conflict with operational guidance elsewhere in this policy.
With regards to AI adoption, Prospero Wealth’s default posture is “Yes, with controls,” not “No.” Our AI Policy lays out the controls to ensure that we are responsible to our clients.
Client data is client property. All client data belongs to the client. As advisors, we are entrusted stewards of client data. While we use client data in our practice—even Personally Identifiable Information (“PII”)—it is never sold, never used to train third-party public models, nor is it disclosed (except as authorized).
Fiduciary first. Human accountability. While AI is a tool that can provide support for decision-making. A named human—typically the lead advisor—is accountable for every output that impacts a client. AI will never relieve any person from the Fiduciary obligations of care and loyalty.
Transparency over opacity. We disclose our AI policy to clients in plain terms, document how systems are used internally, and maintain records sufficient to review any AI-based decision.
Proportional controls. The intensity of our review and approval of AI outputs, scales with the sensitivity of the data being used and the consequences of those outputs.
Continuous improvement. Always. As with all things in technology, the AI Policy is a living document and will be revised over time. Prospero Wealth will continue to proactively pilot, evaluate, and adopt new AI technologies.
3. Scope and Definitions
3.1 Scope
This policy applies to all employees, partners, contractors, interns, and third-party service providers who use or develop AI systems in connection with Prospero’s business. It applies to AI systems regardless of how they are accessed: standalone applications, embedded features in approved software, browser extensions, API integrations, and bespoke systems built in-house.
3.2 Definitions
AI System
Any software that uses machine learning, large language models, generative models, or other statistical inference techniques to produce outputs that influence Firm processes or client deliverables.
Client Data
Any information that identifies, describes, or relates to a Prospero client or prospective client, in any form.
PII
Personally identifiable information, including name, address, date of birth, government identifiers (SSN, ITIN, driver’s license), account numbers, financial holdings, beneficiary information, biometric data, and any data combination that can reasonably identify an individual.
Confidential Firm Data
Non-public information about Prospero, including financial records, employee information, strategy documents, vendor terms, source code, and internal communications.
Approved AI System
An AI system listed on the Firm’s AI Tool Register, which has completed vendor due diligence, security review, and CCO approval for a defined data class and use case.
Material AI-Assisted Decision
Any output of an AI system that is delivered to a client, used in a recommendation, used in trading, or used in a regulatory filing or response.
4. Governance
4.1 AI Steering Committee
The AI Steering Committee (“ASC”) is the Firm’s governing body for AI. It is chaired by the CCO and includes the CEO on one hand, CTO/Head of Technology, Head of Investments, Head of Client Service, and Data Protection Lead. The ASC meets at least semi-annually and is responsible for:
Approving and maintaining the AI Tool Register.
Approving new use cases involving Tier 2 or Tier 3 data (see Section 6).
Reviewing incident reports, audit findings, and client complaints related to AI.
Approving annual updates to this policy and to the Firm’s client-facing AI disclosures.
Approving the Firm’s position on emerging AI capabilities (e.g., autonomous agents, voice cloning, on-device models) before they are deployed in client work.
4.2 Roles
Chief Compliance Officer
Owner of this policy. Final authority on permitted use cases, vendor approvals, and disclosures. Maintains the AI Tool Register and incident log.
Chief Technology Officer
Responsible for technical controls: data egress restrictions, access management, logging, key management, and integration security.
Data Protection Lead
Conducts vendor due diligence, privacy impact assessments, and breach response coordination. May be the CCO in smaller-firm configurations.
Lead Adviser (per relationship)
Accountable for AI-assisted outputs delivered to their clients. Responsible for reviewing and signing off on Material AI-Assisted Decisions.
All Personnel
Responsible for following this policy, completing training, and reporting incidents or near-misses promptly.
5. Approved AI Systems
Personnel may only use AI systems that appear on the AI Tool Register, and only for the data classes and use cases approved on that register. Use of any other AI system in connection with Firm business — including free public chatbots, free browser extensions, or trial software — is prohibited unless and until it has been added to the Register.
5.1 Adding a Tool to the Register
To request approval of a new AI system, the requester submits a brief intake (template maintained by the CCO) describing the proposed use case, vendor, the data classes involved, and the business benefit. The CCO and CTO conduct due diligence proportional to the data class and intended use, including the items in Section 9. Approval, denial, or conditional approval is documented in the Register.
5.2 Examples of Initially Approved Categories
This list is illustrative; the live Register controls. Tools described here have been pre-evaluated for their typical configurations and remain subject to use-case-specific approval.
Enterprise generative AI assistants with contractual no-training commitments, zero-data-retention or short retention windows, and SSO/SCIM integration (for drafting, summarization, research, and code).
Embedded AI features in approved client systems (CRM, portfolio management, planning software, custodial portals) where the data already lives in those systems and the vendor’s data handling has been reviewed.
Meeting transcription and note-taking tools with explicit client consent, contractual no-training terms, and segregated storage within the Firm’s tenant.
Internal/private model deployments (Firm tenant or self-hosted) where data does not leave the Firm’s control boundary.
6. Data Classification and AI Tiers
Every AI use case is matched to a data tier. Each tier specifies which AI systems may be used.
Tier 0
Public information; Firm marketing copy; non-sensitive research inputs.
Any Approved AI System, including general-purpose enterprise assistants.
Tier 1
Confidential Firm Data without client identifiers (e.g., internal process documents, anonymized analyses).
Approved AI Systems with contractual no-training and confidentiality terms.
Tier 2
Client Data including PII (names, contact info, account values, holdings, planning details).
Only AI Systems explicitly approved for Tier 2 on the Register, operating under a signed DPA, with no-training commitments, encryption in transit and at rest, and Firm-managed access controls.
Tier 3
Highly sensitive data: government identifiers (SSN, passport), credentials, account numbers used for movement of money, biometrics, health-related data, and minor-related data.
Only AI Systems explicitly approved for Tier 3, with additional safeguards: tokenization or redaction at ingest, segregated logging, and CCO-approved use case. Default posture: avoid sending Tier 3 data to AI systems unless there is a clear, documented business reason.
7. Permitted Use Cases
The following use cases are explicitly endorsed and may proceed under the controls described, without further case-by-case approval, provided the AI system used is on the Register at the appropriate tier.
7.1 Internal productivity
Drafting, editing, and summarizing internal documents and communications.
Researching markets, products, regulations, and tax topics using public sources.
Generating, reviewing, and explaining code used in Firm systems (subject to security review before merge).
7.2 Client work (Tier 2 permitted)
Preparing meeting agendas, follow-up summaries, and review materials drawing on client data already in approved Firm systems.
Drafting client correspondence for adviser review and approval before sending.
Synthesizing planning scenarios, cash-flow models, and tax-aware projections, with all assumptions and outputs reviewed by the lead adviser.
Generating proposed portfolio analyses, risk diagnostics, and rebalancing candidates, subject to Investment Committee or adviser sign-off before any action is taken.
Transcribing and summarizing client meetings, subject to Section 10 consent requirements.
7.3 Operations and compliance
Reviewing communications archives for supervisory purposes.
Triaging service requests, identifying anomalies, and supporting fraud and identity theft monitoring under Reg S-ID.
Drafting policies, procedures, and regulatory responses for human review.
8. Prohibited Uses
The following are prohibited regardless of business benefit. The CCO may grant a written exception only after ASC review.
Pasting client PII or Confidential Firm Data into any AI system that is not on the Register at the appropriate tier, including free public chatbots and personal accounts.
Using AI output as a final recommendation to a client without human review. A licensed adviser must review and adopt the recommendation before it is communicated.
Allowing AI to place trades, move money, change account information, or initiate any irreversible client-affecting action autonomously. A human authorizes each such action.
Using client data to train or fine-tune any external (non-Firm-controlled) model, or contributing client data to vendor model improvements, even when offered as an opt-out default.
Generating synthetic media that imitates a real client, employee, or third party’s voice or likeness without that person’s explicit, written consent.
Using AI to produce performance presentations, hypothetical performance, or testimonials/endorsements except in compliance with the SEC Marketing Rule (17 CFR 275.206(4)-1) and Section 12 below.
Bypassing or disabling logging, monitoring, or DLP controls on Firm-issued devices or accounts.
Using AI to circumvent supervisory review, recordkeeping, or other compliance controls.
Connecting personal AI accounts to Firm data sources (email, cloud storage, CRM, custodial portals) under any circumstances.
9. Vendor and Third-Party AI Due Diligence
Before any AI system handling Tier 1 or higher data is added to the Register, the CCO and CTO confirm that the vendor meets the following baseline. Findings and any compensating controls are documented.
9.1 Contractual
A signed Data Processing Agreement (DPA) governing the data classes involved, with breach notification obligations.
Explicit contractual prohibition on using Firm or client data to train, improve, or evaluate the vendor’s or any third party’s models.
Explicit contractual confidentiality, with downstream subprocessor disclosure and approval rights.
Right to audit or, at minimum, to receive current third-party attestations (SOC 2 Type II or equivalent).
Defined data location and a commitment to notify the Firm of changes.
Contractual indemnities for IP infringement and data-handling violations, proportional to the engagement.
9.2 Technical
Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent).
SSO and least-privilege access; SCIM provisioning where available.
Configurable retention with the shortest workable window; logging of access and queries.
Tenant isolation; no cross-tenant model fine-tuning or retrieval.
Documented evaluation of model behavior, including hallucination rates, bias, and prompt-injection resilience for the intended use case.
9.3 Operational
A designated security and privacy contact at the vendor.
A current incident response plan and a track record of timely breach notifications.
Sufficient financial and operational viability for the data trusted to it.
10. Client Disclosure and Consent
10.1 Standing Disclosure
Prospero will maintain plain-language disclosures describing how the Firm uses AI in serving clients. These disclosures are included in the Firm’s Privacy Notice, in Form ADV Part 2A where material, and on the Firm’s website. They explain, at minimum: the categories of tasks for which AI is used; that client data may be processed by approved AI systems under contractual safeguards; that client data is not used to train third-party public models; that human advisers review and approve all recommendations and communications; and how clients may ask questions or opt out of specific uses where opt-out is offered.
10.2 Use-Case-Specific Consent
Where AI use materially expands the audience for client data or creates a new processing relationship a reasonable client would not expect, the lead adviser obtains use-case-specific consent. Examples that require explicit consent:
Recording or transcribing a client meeting using an AI tool, with disclosure of the tool used and the retention policy.
Sharing identifiable client information with a new third-party AI vendor not previously covered by the standing disclosure.
Using an AI-generated synthetic voice or video featuring the adviser or any other person.
Consent is captured in writing (including email or e-signature) and stored in the client file.
11. Human Oversight and Review
AI assists; humans decide. The level of review scales with the sensitivity of the output.
Internal-only drafts and research
User self-review for accuracy and policy compliance.
None required beyond standard records.
Client communications (email, letters, summaries)
Lead adviser review and approval before sending.
Outbound communication is captured under Books and Records (Rule 204-2).
Investment recommendations and trade ideas
Lead adviser approval; Investment Committee where required by IPS.
Decision rationale, including the role AI played, captured in CRM or investment file.
Financial planning deliverables
Lead adviser approval and CFP® review where applicable.
Plan version, assumptions, and adviser sign-off retained.
Marketing materials, performance, testimonials
CCO approval before distribution; Marketing Rule review.
Approval log, source data, and AI-generated drafts retained per Rule 204-2.
Compliance filings and regulatory responses
CCO final review.
Drafts and adopted version retained.
12. Marketing, Performance, and Public Communications
Any client- or prospect-facing material created with AI assistance is subject to the SEC Marketing Rule (17 CFR 275.206(4)-1) and the Firm’s Marketing Procedures. Specifically:
AI-generated content must be reviewed and approved by the CCO or designee before distribution.
Performance figures and any hypothetical or projected performance must be calculated by approved methodologies. AI tools may assist in formatting and explanation but may not be the source of performance numbers.
Testimonials and endorsements must comply with the Marketing Rule’s required disclosures and may not be fabricated or composited.
Synthetic media (AI voice or video) of any Firm representative must be clearly disclosed as such if used in marketing.
13. Recordkeeping and Documentation
To meet the Books and Records Rule (17 CFR 275.204-2) and to enable supervision and audit:
AI systems used to create or substantially edit records must be configured to retain inputs and outputs for the applicable retention period (generally five years from the end of the fiscal year of last use, with the first two years easily accessible).
Client communications drafted with AI assistance are captured by the Firm’s communications archive in the same way as any other electronic communication.
Material AI-Assisted Decisions are documented to a level sufficient for a third party to reconstruct what the AI was asked, what it produced, and what the reviewing human approved.
The AI Tool Register, ASC minutes, vendor due diligence files, incident logs, and training records are retained for the applicable period and made available to regulators on request.
14. Model Risk and Output Quality
All AI systems can produce confidently wrong outputs. Personnel are expected to apply professional skepticism, particularly when the output looks polished. The Firm manages model risk through:
Use-case fit. Each approved use case identifies the failure modes that matter for that task (e.g., hallucinated citations, miscalculated performance, biased screening) and specifies the controls that address them.
Verification of factual claims. Citations, statutory references, regulatory thresholds, and quantitative outputs are independently verified before use in client work.
Bias and fairness review for any AI system that influences client onboarding, segmentation, or service levels.
Periodic testing. Approved systems are re-evaluated at least annually against a Firm-maintained set of representative tasks.
Conflict-of-interest review. Where an AI system’s recommendations could be influenced by the Firm’s or vendor’s economic interests, the conflict is identified, mitigated, and disclosed consistent with our fiduciary duty.
15. Security Requirements
Access to AI systems is via Firm-issued accounts with SSO and multi-factor authentication. Personal accounts may not be used for Firm work.
Firm-issued devices enforce endpoint protection, disk encryption, and DLP rules sufficient to flag prohibited transfers of Tier 2/3 data.
Tier 3 data (e.g., SSNs, full account numbers) is tokenized or redacted before any AI processing unless an explicit, documented exception applies.
API keys, credentials, and secrets are never pasted into AI systems. Code generated by AI is reviewed for embedded secrets, vulnerabilities, and license compliance before merge.
Logging of AI system usage is enabled and retained per Section 13.
AI agents that act on Firm systems (e.g., browser agents, autonomous workflows) operate under least-privilege credentials, with explicit allowlists of permitted actions and human approval for any irreversible step.
16. Incident Response
An “AI incident” includes any of: suspected exposure of client or Firm data through an AI system; a materially incorrect AI output that affected a client; misuse of AI by an employee or vendor; a vendor security or privacy incident affecting Firm data; or a credible third-party report of bias, harmful output, or model behavior change.
Reporting is mandatory and prompt. Any employee who identifies a potential AI incident reports it to the CCO within 24 hours, and earlier if client harm is plausible. The CCO triages, opens an incident record, coordinates technical containment with the CTO, evaluates client and regulator notification obligations under Reg S-P, Reg S-ID, and applicable state laws, and documents the resolution and lessons learned. Material incidents are reported to the ASC and, where appropriate, to the Firm’s insurer and counsel.
17. Training and Competency
All personnel complete AI policy training upon hire and at least annually thereafter, including practical exercises in safe use, prompt hygiene, and incident reporting.
Advisers complete additional training covering supervision of AI-assisted work, fiduciary obligations, and the Marketing Rule’s application to AI-generated content.
Technical staff who build or integrate AI systems complete training on secure development, prompt-injection defenses, and evaluation methodology.
Completion is tracked in the Firm’s training system and is a condition of continued use of approved AI tools.
18. Monitoring, Testing, and Audit
The CCO, supported by the CTO, conducts ongoing supervision of AI use, including:
Semi-annual review of AI system access logs, DLP events, and exception requests.
Annual independent test of a representative sample of Material AI-Assisted Decisions for accuracy, documentation, and disclosure.
Annual review of vendor attestations, subprocessor changes, and contract terms.
Inclusion of AI use in the Firm’s Rule 206(4)-7 annual compliance review.
19. Exceptions and Enforcement
Exceptions to this policy require written approval by the CCO, with notice to the ASC. Approved exceptions are time-bound and recorded. Violations may result in remediation, retraining, suspension of AI tool access, and disciplinary action up to and including termination, in addition to any regulatory consequences.
20. Policy Governance
This policy is reviewed at least annually by the CCO, who recommends updates to the ASC. Material changes are communicated to all personnel and incorporated into the next training cycle. Client-facing disclosures are revised in parallel where the policy change is material to clients. The current version of the policy is maintained on the Firm’s internal compliance site; superseded versions are retained per Section 13.
21. Acknowledgement
All personnel acknowledge in writing that they have read, understood, and will comply with this policy upon hire, upon any material update, and at least annually.
Employee name (printed)
Signature
Date
Role / Department
Section 21 is a representative example of what all employees sign, documenting their commitment to adhere to the AI policy.
