PROSPERO WEALTH AI POLICY

Prepared for review by the Chief Compliance Officer and Executive Team

Prepared for review by the Chief Compliance Officer and Executive Team

Effective Date: September 9, 2026

Effective Date: September 9, 2026

1. Purpose and Philosophy

Prospero Wealth (“Prospero,” “the Firm,” “we”) believes that thoughtful, well-governed use of artificial intelligence (“AI”) is a defining advantage in serving our clients.

Used well, AI lets us deliver more personalized advice, more responsive service, and more rigorous analysis than would otherwise be possible.

Used carelessly, AI creates risks to client privacy, data integrity, regulatory standing, and the trust on which our fiduciary relationships depend.

This policy is designed to enable maximum, durable use of AI — including AI systems that process client personally identifiable information (“PII”) — while ensuring that every such use is consistent with our fiduciary duty under the Investment Advisers Act of 1940, applicable privacy laws, and the reasonable expectations of our clients. The Firm’s default posture is “yes, with controls,” not “no.” Where the controls in this policy are followed, employees are encouraged to use AI assertively to improve client outcomes.

2. Guiding Principles

All AI use at Prospero is governed by the following principles, which take precedence in any conflict with operational guidance elsewhere in this policy.

  • With regards to AI adoption, Prospero Wealth’s default posture is “Yes, with controls,” not “No.” Our AI Policy lays out the controls to ensure that we are responsible to our clients.

  • Client data is client property. All client data belongs to the client. As advisors, we are entrusted stewards of client data. While we use client data in our practice—even Personally Identifiable Information (“PII”)—it is never sold, never used to train third-party public models, nor is it disclosed (except as authorized).

  • Fiduciary first. Human accountability. While AI is a tool that can provide support for decision-making. A named human—typically the lead advisor—is accountable for every output that impacts a client. AI will never relieve any person from the Fiduciary obligations of care and loyalty.

  • Transparency over opacity. We disclose our AI policy to clients in plain terms, document how systems are used internally, and maintain records sufficient to review any AI-based decision.

  • Proportional controls. The intensity of our review and approval of AI outputs, scales with the sensitivity of the data being used and the consequences of those outputs.

  • Continuous improvement. Always. As with all things in technology, the AI Policy is a living document and will be revised over time. Prospero Wealth will continue to proactively pilot, evaluate, and adopt new AI technologies.

3. Scope and Definitions

3.1 Scope

This policy applies to all employees, partners, contractors, interns, and third-party service providers who use or develop AI systems in connection with Prospero’s business. It applies to AI systems regardless of how they are accessed: standalone applications, embedded features in approved software, browser extensions, API integrations, and bespoke systems built in-house.

3.2 Definitions

AI System

Any software that uses machine learning, large language models, generative models, or other statistical inference techniques to produce outputs that influence Firm processes or client deliverables.

Client Data

Any information that identifies, describes, or relates to a Prospero client or prospective client, in any form.

PII

Personally identifiable information, including name, address, date of birth, government identifiers (SSN, ITIN, driver’s license), account numbers, financial holdings, beneficiary information, biometric data, and any data combination that can reasonably identify an individual.

Confidential Firm Data

Non-public information about Prospero, including financial records, employee information, strategy documents, vendor terms, source code, and internal communications.

Approved AI System

An AI system listed on the Firm’s AI Tool Register, which has completed vendor due diligence, security review, and CCO approval for a defined data class and use case.

Material AI-Assisted Decision

Any output of an AI system that is delivered to a client, used in a recommendation, used in trading, or used in a regulatory filing or response.

4. Governance

4.1 AI Steering Committee

The AI Steering Committee (“ASC”) is the Firm’s governing body for AI. It is chaired by the CCO and includes the CEO on one hand, CTO/Head of Technology, Head of Investments, Head of Client Service, and Data Protection Lead. The ASC meets at least semi-annually and is responsible for:

  • Approving and maintaining the AI Tool Register.

  • Approving new use cases involving Tier 2 or Tier 3 data (see Section 6).

  • Reviewing incident reports, audit findings, and client complaints related to AI.

  • Approving annual updates to this policy and to the Firm’s client-facing AI disclosures.

  • Approving the Firm’s position on emerging AI capabilities (e.g., autonomous agents, voice cloning, on-device models) before they are deployed in client work.

4.2 Roles

Chief Compliance Officer

Owner of this policy. Final authority on permitted use cases, vendor approvals, and disclosures. Maintains the AI Tool Register and incident log.

Chief Technology Officer

Responsible for technical controls: data egress restrictions, access management, logging, key management, and integration security.

Data Protection Lead

Conducts vendor due diligence, privacy impact assessments, and breach response coordination. May be the CCO in smaller-firm configurations.

Lead Adviser (per relationship)

Accountable for AI-assisted outputs delivered to their clients. Responsible for reviewing and signing off on Material AI-Assisted Decisions.

All Personnel

Responsible for following this policy, completing training, and reporting incidents or near-misses promptly.

5. Approved AI Systems

Personnel may only use AI systems that appear on the AI Tool Register, and only for the data classes and use cases approved on that register. Use of any other AI system in connection with Firm business — including free public chatbots, free browser extensions, or trial software — is prohibited unless and until it has been added to the Register.

5.1 Adding a Tool to the Register

To request approval of a new AI system, the requester submits a brief intake (template maintained by the CCO) describing the proposed use case, vendor, the data classes involved, and the business benefit. The CCO and CTO conduct due diligence proportional to the data class and intended use, including the items in Section 9. Approval, denial, or conditional approval is documented in the Register.

5.2 Examples of Initially Approved Categories

This list is illustrative; the live Register controls. Tools described here have been pre-evaluated for their typical configurations and remain subject to use-case-specific approval.

  • Enterprise generative AI assistants with contractual no-training commitments, zero-data-retention or short retention windows, and SSO/SCIM integration (for drafting, summarization, research, and code).

  • Embedded AI features in approved client systems (CRM, portfolio management, planning software, custodial portals) where the data already lives in those systems and the vendor’s data handling has been reviewed.

  • Meeting transcription and note-taking tools with explicit client consent, contractual no-training terms, and segregated storage within the Firm’s tenant.

  • Internal/private model deployments (Firm tenant or self-hosted) where data does not leave the Firm’s control boundary.

6. Data Classification and AI Tiers

Every AI use case is matched to a data tier. Each tier specifies which AI systems may be used.

Tier

Data Class

Permitted AI Systems

Tier 0

Data Class

Public information; Firm marketing copy; non-sensitive research inputs.

Permitted AI Systems

Any Approved AI System, including general-purpose enterprise assistants.

Tier 1

Data Class

Confidential Firm Data without client identifiers (e.g., internal process documents, anonymized analyses).

Permitted AI Systems

Approved AI Systems with contractual no-training and confidentiality terms.

Tier 2

Data Class

Client Data including PII (names, contact info, account values, holdings, planning details).

Permitted AI Systems

Only AI Systems explicitly approved for Tier 2 on the Register, operating under a signed DPA, with no-training commitments, encryption in transit and at rest, and Firm-managed access controls.

Tier 3

Data Class

Highly sensitive data: government identifiers (SSN, passport), credentials, account numbers used for movement of money, biometrics, health-related data, and minor-related data.

Permitted AI Systems

Only AI Systems explicitly approved for Tier 3, with additional safeguards: tokenization or redaction at ingest, segregated logging, and CCO-approved use case. Default posture: avoid sending Tier 3 data to AI systems unless there is a clear, documented business reason.

7. Permitted Use Cases

The following use cases are explicitly endorsed and may proceed under the controls described, without further case-by-case approval, provided the AI system used is on the Register at the appropriate tier.

7.1 Internal productivity

  • Drafting, editing, and summarizing internal documents and communications.

  • Researching markets, products, regulations, and tax topics using public sources.

  • Generating, reviewing, and explaining code used in Firm systems (subject to security review before merge).

7.2 Client work (Tier 2 permitted)

  • Preparing meeting agendas, follow-up summaries, and review materials drawing on client data already in approved Firm systems.

  • Drafting client correspondence for adviser review and approval before sending.

  • Synthesizing planning scenarios, cash-flow models, and tax-aware projections, with all assumptions and outputs reviewed by the lead adviser.

  • Generating proposed portfolio analyses, risk diagnostics, and rebalancing candidates, subject to Investment Committee or adviser sign-off before any action is taken.

  • Transcribing and summarizing client meetings, subject to Section 10 consent requirements.

7.3 Operations and compliance

  • Reviewing communications archives for supervisory purposes.

  • Triaging service requests, identifying anomalies, and supporting fraud and identity theft monitoring under Reg S-ID.

  • Drafting policies, procedures, and regulatory responses for human review.

8. Prohibited Uses

The following are prohibited regardless of business benefit. The CCO may grant a written exception only after ASC review.

  • Pasting client PII or Confidential Firm Data into any AI system that is not on the Register at the appropriate tier, including free public chatbots and personal accounts.

  • Using AI output as a final recommendation to a client without human review. A licensed adviser must review and adopt the recommendation before it is communicated.

  • Allowing AI to place trades, move money, change account information, or initiate any irreversible client-affecting action autonomously. A human authorizes each such action.

  • Using client data to train or fine-tune any external (non-Firm-controlled) model, or contributing client data to vendor model improvements, even when offered as an opt-out default.

  • Generating synthetic media that imitates a real client, employee, or third party’s voice or likeness without that person’s explicit, written consent.

  • Using AI to produce performance presentations, hypothetical performance, or testimonials/endorsements except in compliance with the SEC Marketing Rule (17 CFR 275.206(4)-1) and Section 12 below.

  • Bypassing or disabling logging, monitoring, or DLP controls on Firm-issued devices or accounts.

  • Using AI to circumvent supervisory review, recordkeeping, or other compliance controls.

  • Connecting personal AI accounts to Firm data sources (email, cloud storage, CRM, custodial portals) under any circumstances.

9. Vendor and Third-Party AI Due Diligence

Before any AI system handling Tier 1 or higher data is added to the Register, the CCO and CTO confirm that the vendor meets the following baseline. Findings and any compensating controls are documented.

9.1 Contractual

  • A signed Data Processing Agreement (DPA) governing the data classes involved, with breach notification obligations.

  • Explicit contractual prohibition on using Firm or client data to train, improve, or evaluate the vendor’s or any third party’s models.

  • Explicit contractual confidentiality, with downstream subprocessor disclosure and approval rights.

  • Right to audit or, at minimum, to receive current third-party attestations (SOC 2 Type II or equivalent).

  • Defined data location and a commitment to notify the Firm of changes.

  • Contractual indemnities for IP infringement and data-handling violations, proportional to the engagement.

9.2 Technical

  • Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent).

  • SSO and least-privilege access; SCIM provisioning where available.

  • Configurable retention with the shortest workable window; logging of access and queries.

  • Tenant isolation; no cross-tenant model fine-tuning or retrieval.

  • Documented evaluation of model behavior, including hallucination rates, bias, and prompt-injection resilience for the intended use case.

9.3 Operational

  • A designated security and privacy contact at the vendor.

  • A current incident response plan and a track record of timely breach notifications.

  • Sufficient financial and operational viability for the data trusted to it.

10. Client Disclosure and Consent

10.1 Standing Disclosure

Prospero will maintain plain-language disclosures describing how the Firm uses AI in serving clients. These disclosures are included in the Firm’s Privacy Notice, in Form ADV Part 2A where material, and on the Firm’s website. They explain, at minimum: the categories of tasks for which AI is used; that client data may be processed by approved AI systems under contractual safeguards; that client data is not used to train third-party public models; that human advisers review and approve all recommendations and communications; and how clients may ask questions or opt out of specific uses where opt-out is offered.

10.2 Use-Case-Specific Consent

Where AI use materially expands the audience for client data or creates a new processing relationship a reasonable client would not expect, the lead adviser obtains use-case-specific consent. Examples that require explicit consent:

  • Recording or transcribing a client meeting using an AI tool, with disclosure of the tool used and the retention policy.

  • Sharing identifiable client information with a new third-party AI vendor not previously covered by the standing disclosure.

  • Using an AI-generated synthetic voice or video featuring the adviser or any other person.

Consent is captured in writing (including email or e-signature) and stored in the client file.

11. Human Oversight and Review

AI assists; humans decide. The level of review scales with the sensitivity of the output.

Output Category

Required Review

Documentation

Internal-only drafts and research

Required Review

User self-review for accuracy and policy compliance.

Documentation

None required beyond standard records.

Client communications (email, letters, summaries)

Required Review

Lead adviser review and approval before sending.

Documentation

Outbound communication is captured under Books and Records (Rule 204-2).

Investment recommendations and trade ideas

Required Review

Lead adviser approval; Investment Committee where required by IPS.

Documentation

Decision rationale, including the role AI played, captured in CRM or investment file.

Financial planning deliverables

Required Review

Lead adviser approval and CFP® review where applicable.

Documentation

Plan version, assumptions, and adviser sign-off retained.

Marketing materials, performance, testimonials

Required Review

CCO approval before distribution; Marketing Rule review.

Documentation

Approval log, source data, and AI-generated drafts retained per Rule 204-2.

Compliance filings and regulatory responses

Required Review

CCO final review.

Documentation

Drafts and adopted version retained.

12. Marketing, Performance, and Public Communications

Any client- or prospect-facing material created with AI assistance is subject to the SEC Marketing Rule (17 CFR 275.206(4)-1) and the Firm’s Marketing Procedures. Specifically:

  • AI-generated content must be reviewed and approved by the CCO or designee before distribution.

  • Performance figures and any hypothetical or projected performance must be calculated by approved methodologies. AI tools may assist in formatting and explanation but may not be the source of performance numbers.

  • Testimonials and endorsements must comply with the Marketing Rule’s required disclosures and may not be fabricated or composited.

  • Synthetic media (AI voice or video) of any Firm representative must be clearly disclosed as such if used in marketing.

13. Recordkeeping and Documentation

To meet the Books and Records Rule (17 CFR 275.204-2) and to enable supervision and audit:

  • AI systems used to create or substantially edit records must be configured to retain inputs and outputs for the applicable retention period (generally five years from the end of the fiscal year of last use, with the first two years easily accessible).

  • Client communications drafted with AI assistance are captured by the Firm’s communications archive in the same way as any other electronic communication.

  • Material AI-Assisted Decisions are documented to a level sufficient for a third party to reconstruct what the AI was asked, what it produced, and what the reviewing human approved.

  • The AI Tool Register, ASC minutes, vendor due diligence files, incident logs, and training records are retained for the applicable period and made available to regulators on request.

14. Model Risk and Output Quality

All AI systems can produce confidently wrong outputs. Personnel are expected to apply professional skepticism, particularly when the output looks polished. The Firm manages model risk through:

  • Use-case fit. Each approved use case identifies the failure modes that matter for that task (e.g., hallucinated citations, miscalculated performance, biased screening) and specifies the controls that address them.

  • Verification of factual claims. Citations, statutory references, regulatory thresholds, and quantitative outputs are independently verified before use in client work.

  • Bias and fairness review for any AI system that influences client onboarding, segmentation, or service levels.

  • Periodic testing. Approved systems are re-evaluated at least annually against a Firm-maintained set of representative tasks.

  • Conflict-of-interest review. Where an AI system’s recommendations could be influenced by the Firm’s or vendor’s economic interests, the conflict is identified, mitigated, and disclosed consistent with our fiduciary duty.

15. Security Requirements

  • Access to AI systems is via Firm-issued accounts with SSO and multi-factor authentication. Personal accounts may not be used for Firm work.

  • Firm-issued devices enforce endpoint protection, disk encryption, and DLP rules sufficient to flag prohibited transfers of Tier 2/3 data.

  • Tier 3 data (e.g., SSNs, full account numbers) is tokenized or redacted before any AI processing unless an explicit, documented exception applies.

  • API keys, credentials, and secrets are never pasted into AI systems. Code generated by AI is reviewed for embedded secrets, vulnerabilities, and license compliance before merge.

  • Logging of AI system usage is enabled and retained per Section 13.

  • AI agents that act on Firm systems (e.g., browser agents, autonomous workflows) operate under least-privilege credentials, with explicit allowlists of permitted actions and human approval for any irreversible step.

16. Incident Response

An “AI incident” includes any of: suspected exposure of client or Firm data through an AI system; a materially incorrect AI output that affected a client; misuse of AI by an employee or vendor; a vendor security or privacy incident affecting Firm data; or a credible third-party report of bias, harmful output, or model behavior change.

Reporting is mandatory and prompt. Any employee who identifies a potential AI incident reports it to the CCO within 24 hours, and earlier if client harm is plausible. The CCO triages, opens an incident record, coordinates technical containment with the CTO, evaluates client and regulator notification obligations under Reg S-P, Reg S-ID, and applicable state laws, and documents the resolution and lessons learned. Material incidents are reported to the ASC and, where appropriate, to the Firm’s insurer and counsel.

17. Training and Competency

  • All personnel complete AI policy training upon hire and at least annually thereafter, including practical exercises in safe use, prompt hygiene, and incident reporting.

  • Advisers complete additional training covering supervision of AI-assisted work, fiduciary obligations, and the Marketing Rule’s application to AI-generated content.

  • Technical staff who build or integrate AI systems complete training on secure development, prompt-injection defenses, and evaluation methodology.

  • Completion is tracked in the Firm’s training system and is a condition of continued use of approved AI tools.

18. Monitoring, Testing, and Audit

The CCO, supported by the CTO, conducts ongoing supervision of AI use, including:

  • Semi-annual review of AI system access logs, DLP events, and exception requests.

  • Annual independent test of a representative sample of Material AI-Assisted Decisions for accuracy, documentation, and disclosure.

  • Annual review of vendor attestations, subprocessor changes, and contract terms.

  • Inclusion of AI use in the Firm’s Rule 206(4)-7 annual compliance review.

19. Exceptions and Enforcement

Exceptions to this policy require written approval by the CCO, with notice to the ASC. Approved exceptions are time-bound and recorded. Violations may result in remediation, retraining, suspension of AI tool access, and disciplinary action up to and including termination, in addition to any regulatory consequences.

20. Policy Governance

This policy is reviewed at least annually by the CCO, who recommends updates to the ASC. Material changes are communicated to all personnel and incorporated into the next training cycle. Client-facing disclosures are revised in parallel where the policy change is material to clients. The current version of the policy is maintained on the Firm’s internal compliance site; superseded versions are retained per Section 13.

21. Acknowledgement

All personnel acknowledge in writing that they have read, understood, and will comply with this policy upon hire, upon any material update, and at least annually.

Employee name (printed)

Signature

Date

Role / Department

Section 21 is a representative example of what all employees sign, documenting their commitment to adhere to the AI policy.

7724 35th Ave NE #15170

Seattle, WA 98115-9955

(971) 716-1991

hello@prosperowealth.com

Prospero Wealth, LLC is an Investment Adviser registered with the SEC, principally located in the state of Washington. All views, expressions, and opinions included in this communication are subject to change.

The information on this site is not intended as tax, accounting or legal advice, nor is it an offer or solicitation to buy or sell, or as an endorsement of any company, security, fund, or other offering. Information provided should not be solely relied upon for decision making. Please consult your legal, tax, or accounting professional regarding your specific situation. Investments involve risk and have the potential for complete loss. It should not be assumed that any recommendations made will necessarily be profitable.

The information on this site is provided “AS IS” and without warranties either express or implied and the information may not be free from error. Your use of the information provided is at your sole risk.

© Prospero Wealth 2026. All rights reserved.

7724 35th Ave NE #15170

Seattle, WA 98115-9955

(971) 716-1991

hello@prosperowealth.com

Prospero Wealth, LLC is an Investment Adviser registered with the SEC, principally located in the state of Washington. All views, expressions, and opinions included in this communication are subject to change.

The information on this site is not intended as tax, accounting or legal advice, nor is it an offer or solicitation to buy or sell, or as an endorsement of any company, security, fund, or other offering. Information provided should not be solely relied upon for decision making. Please consult your legal, tax, or accounting professional regarding your specific situation. Investments involve risk and have the potential for complete loss. It should not be assumed that any recommendations made will necessarily be profitable.

The information on this site is provided “AS IS” and without warranties either express or implied and the information may not be free from error. Your use of the information provided is at your sole risk.

© Prospero Wealth 2026. All rights reserved.

7724 35th Ave NE #15170

Seattle, WA 98115-9955

(971) 716-1991

hello@prosperowealth.com

Prospero Wealth, LLC is an Investment Adviser registered with the SEC, principally located in the state of Washington. All views, expressions, and opinions included in this communication are subject to change.

The information on this site is not intended as tax, accounting or legal advice, nor is it an offer or solicitation to buy or sell, or as an endorsement of any company, security, fund, or other offering. Information provided should not be solely relied upon for decision making. Please consult your legal, tax, or accounting professional regarding your specific situation. Investments involve risk and have the potential for complete loss. It should not be assumed that any recommendations made will necessarily be profitable.

The information on this site is provided “AS IS” and without warranties either express or implied and the information may not be free from error. Your use of the information provided is at your sole risk.

© Prospero Wealth 2026. All rights reserved.