
Your AI Story Is an Examinable Representation, and the Exam Year Ends 30 September
For three years, the AI question in private equity pointed outward. Deal teams learned to ask what a target's models did, where its training data came from, whether its AI claims survived contact with the code, and what regulatory exposure came attached. That was the right question and it remains one.
The examination cycle now running adds a second question, pointed the other way. It is worth being blunt about the timing, because the honest version is more useful than a manufactured one: nothing new landed this summer. The SEC's Division of Examinations published its fiscal year 2026 priorities on 17 November 2025. What makes late July the moment to read them is not novelty. It is the calendar. The Division's fiscal year closes on 30 September 2026, which means firms have been inside this examination year since October, roughly three-quarters of it has already elapsed, and the next set of priorities will publish in the autumn. If your firm has not reconciled its AI claims against its AI reality, it has had ten months to do it and has about two left.
What the document actually says on the subject is short. In the Division's own words: "With respect to AI, the Division will focus on recent advancements in AI and will review for accuracy registrant representations regarding their AI capabilities or AI." Elsewhere it commits to reviewing controls to mitigate new risks associated with artificial intelligence and polymorphic malware attacks, alongside governance practices, data loss prevention, access controls, account management and responses to cyber-related incidents.
You will see that summarised in the trade press and in law-firm alerts as a crackdown on AI washing. That phrase is worth handling carefully: it does not appear anywhere in the SEC's document. It is the securities bar's shorthand, used notably in Goodwin's client alert, which characterises the Division as scrutinising misleading claims about firms' AI capabilities or the role of AI in investment processes. The gloss is a fair reading of the exposure and we use it here as such. It is not regulatory language, and a firm that repeats it as a direct quotation from the SEC is making exactly the category of imprecise attribution the underlying priority is about.
Read the actual sentence as a sponsor rather than as a compliance officer and it resolves into one uncomfortable question. Every deck, every fundraising conversation, every website paragraph in which your firm described what AI does for it is a representation that someone may ask you to evidence. Not because anyone suspects you of lying, but because the Division said it would check, and it has been checking since October.
Key Takeaways
- Nothing new happened this summer. The FY2026 priorities published 17 November 2025; the fiscal year ends 30 September 2026. The urgency is calendar, not news: about two months of this exam year remain
- The SEC's actual language is narrow: it will "review for accuracy registrant representations regarding their AI capabilities or AI." The term AI washing is law-firm shorthand for that exposure, not regulatory wording, and should not be quoted as the SEC's own
- The test is substance over description: a firm claiming AI-driven investment processes would be expected to show that AI tools genuinely influence decisions, not that they supplement research
- The same priorities cover controls for AI and polymorphic malware, plus governance, data loss prevention, access controls, account management and incident response, and the 2024 amendments to Regulation S-P
- For sponsors, the data flowing through AI tools is deal pipeline, target financials, valuation models, diligence findings, investor communications and MNPI, frequently through tools adopted at the desk rather than through procurement
- The work is a reconciliation: every AI claim the firm has made, set against what the firm actually does, with the gap closed while closing it is still an editorial choice rather than a response to a deficiency letter
What the Division Actually Said
The FY2026 priorities are not an AI document, and it is worth keeping the proportion right. They cover fiduciary duty, standards of conduct, the custody rule, compliance with new rules including the 2024 amendments to Regulation S-P, and a continued emphasis on newly registered advisers building robust compliance programs. AI appears as a cross-cutting theme rather than as the headline.
But where it appears, it appears with unusual specificity for a priorities document. Two distinct threads run through it.
The first is representational, and it is one sentence: the Division will focus on recent advancements in AI and will review for accuracy registrant representations regarding their AI capabilities or AI. That is the whole of it. Everything else in circulation about AI washing is the securities bar reading that sentence and telling you what it implies, which is a legitimate and useful exercise so long as you know which is which. The worked example that has circulated in the law-firm commentary is instructive: a firm claiming to use AI for portfolio management would be expected to demonstrate that AI tools genuinely influence investment decisions, rather than functioning as supplemental research that a human ignores. The test is whether the description matches the mechanism.
The second is operational. The Division said it will review controls to mitigate new risks associated with artificial intelligence and polymorphic malware attacks, and, in the cybersecurity portion, registrants' policies and procedures, governance practices, data loss prevention, access controls, account management, and responses to cyber-related incidents including ransomware. It also flagged whether firms have adequate policies and procedures to monitor AI use across functions including fraud prevention and detection, back-office operations, anti-money laundering and trading.
Those two threads are usually discussed separately and they should not be. An examination that tests whether your AI story is accurate, in the same visit as it tests whether the data moving through your AI tools is controlled, produces one combined finding: this firm described a capability it cannot evidence, running on data it cannot account for. That is a materially worse outcome than either finding alone.
Why This Lands Harder on a Sponsor
The generic version of this risk applies to any adviser. The sponsor-specific version is sharper, for a reason that has nothing to do with the sophistication of the AI and everything to do with the sensitivity of the inputs.
Consider what actually moves through a private markets firm's daily workflow: proprietary deal pipeline, target company financials under NDA, valuation models, diligence findings, management presentations, LP communications, and material non-public information about both public and private companies. This is the material a deal professional is most tempted to hand to an AI tool, because summarising a 200-page data room or reconciling three versions of a model is exactly the work these tools are good at.
Now recall how those tools generally entered the firm. Not through procurement, in most cases, and not through a security review. They arrived because an associate found something useful and used it, which is the shadow-AI pattern we set out in building a shadow AI risk register. The result is that a firm's most confidential material can be flowing through systems that its own compliance function has not inventoried, at a moment when an examiner has said they will ask about data loss prevention, access controls and account management. Microsoft's Data Security Index, published in January 2026, puts the general prevalence at 32% of surveyed organizations' data security incidents now involving generative AI tools, against 47% of security leaders implementing generative-AI-specific controls, up 8 percentage points year over year. The controls are being built, but they are being built behind the adoption.
None of this requires anyone to have behaved badly. It requires only that adoption outpaced governance, which it did nearly everywhere.
The Portfolio Side Does Not Wait for the Exam
Set the fund-level exposure next to what the portfolio is doing, because the two are usually managed by different people and are converging on the same investment committee.
The base rates are not marginal, and they are worth reading with their vintages attached, because a composite of surveys fielded across two different years is not a snapshot of today.
QBE North America, in fieldwork run by Wakefield Research between 13 December 2024 and 9 January 2025, surveyed 300 risk managers and CISOs at private equity firms managing between 1 billion and 50 billion dollars in assets. 54% reported that up to a quarter of their portfolio companies had experienced a cyber incident or attack in the previous 12 months, and 23% put it between a quarter and a half. Note what "the previous 12 months" means given the fielding dates: this is a picture of calendar 2024, and should be read as a baseline rather than as current conditions.
Kroll, surveying 325 private equity executives and publishing in early 2026, found that 80% had experienced disruption tied to cybersecurity risk during the hold period in the past year, that nearly 70% saw incidents increase year over year with 22% describing the increase as significant, and that the average financial impact was 2.1 million dollars per incident, with a 53% chance of exceeding 500,000 dollars and a 13% chance of exceeding 5 million.
ACA's benchmarking work across more than 300 portfolio companies in 18 industries and 12 countries found half in the elevated or high cyber risk categories. That headline is more often quoted than understood, and honesty requires the caveat: ACA notes that its portfolio companies split roughly evenly between lower- and higher-risk bands, and that this balance is expected, because the underlying 1-to-100 scoring model is designed so that most companies land in the middle. The finding is a useful distribution to benchmark your own holdings against. It is not evidence that half the industry is in trouble, and anyone presenting it that way to an investment committee should expect to be corrected.
Taken together, and allowing for their different vintages, those numbers describe an environment in which hold-period cyber events are an expected cost rather than a tail risk, which changes what "we take cybersecurity seriously" has to mean when a sponsor says it to an LP or writes it in a fund document. It is also the context in which the liability question we examined in the Bain and PowerSchool ruling matters: sponsor-level exposure for portfolio-level incidents is no longer purely theoretical, and a sponsor that has described its portfolio cyber oversight program is making another representation of exactly the kind the Division said it would test.
What Evidence Looks Like
The gap that catches firms is rarely dishonesty. It is that a claim made in good faith has never been reduced to evidence, because nobody expected to have to produce it. The remedy is to do that reduction now, on your own timetable.
| The claim you have made | What supports it | Where firms come up short |
|---|---|---|
| "We use AI in sourcing and screening" | Tool inventory, records showing the output reaches a decision-maker, description of how it ranks or filters | The tool is used by two people occasionally; the deck implies a firmwide capability |
| "AI accelerates our diligence" | Documented workflow, evidence of use on named deals, confidentiality controls on the documents processed | No record of which data rooms were processed through which tool, or under what terms |
| "Our AI is governed by a formal policy" | The policy, its approval date, training records, monitoring evidence | The policy exists and was circulated; nothing evidences that it is followed |
| "We monitor portfolio company cyber risk" | Assessment cadence, findings, remediation tracking, escalation path to the IC | Annual questionnaires with no verification and no consequence for a poor answer |
| "Our vendors are diligenced" | Vendor assessments covering AI subprocessors, data handling and retention | AI tools adopted at desk level never entered the vendor process at all |
The pattern is consistent across the column on the right: the claim is directionally true and evidentially thin. That is a survivable position if you fix it before you are asked, and an expensive one if you do not.
What Changes for the Investment Committee
Reconcile the claims first, because it is the cheapest thing on this list. Assemble every statement the firm has made about AI, in marketing, fundraising materials, Form ADV, investor reporting and the website, and set them beside an honest inventory of what the firm does today. Where a claim is supported, capture the evidence. Where it overstates, edit it now. This is a few weeks of work and it removes the single most avoidable finding in the entire category. The two months to 30 September are enough time to do it properly; a deficiency letter is not a schedule you control.
Inventory the tools before the examiner does. You cannot answer questions about data loss prevention, access control or account management for tools you have not enumerated. The desk-level adoption is where the confidential material actually went, so an inventory that only covers procured systems is not an inventory.
Decide, explicitly, what may touch MNPI and confidential deal material. Not a general AI policy, a specific rule about the data categories that matter in this business, with the tooling to enforce it. Information-barrier discipline is not a new competence for a private markets firm; it just has to be extended to a tool category that arrived faster than the policy did.
Hold the portfolio question to the same evidentiary standard as the fund question. If the firm has represented that it oversees portfolio cyber risk, that representation needs assessments, findings, remediation and escalation behind it. The base rates above make the difference between a real program and a questionnaire visible on a normal timescale, not a theoretical one. The outward-facing version of this discipline, the questions to ask a target, is set out in the questions an investment committee should ask about AI risk and AI diligence for PE deal teams; this is the same rigour turned around and applied to the firm making the assessment.
The Reasonable Version of This
It would be easy to read the priorities as a signal to say nothing about AI, on the theory that a claim not made cannot be inaccurate. That is the wrong lesson and a competitively bad one, since capability that genuinely exists is worth describing and LPs are entitled to know how their manager works.
The lesson is narrower and more useful: describe what you actually do, and keep the evidence that you do it. A firm that says "we use AI to accelerate first-pass screening and to summarise diligence materials, under a policy that excludes MNPI from third-party tools, with these controls" has made a claim that is specific, defensible and, not incidentally, more credible to a sophisticated investor than the vaguer alternative. Precision is the compliance posture and the commercial one at the same time.
How Innovaiden Approaches It
Innovaiden's AI representation and controls review runs the reconciliation described above as a defined exercise. It collects the firm's AI claims across marketing, fundraising, regulatory filings and investor materials; builds an honest inventory of the AI tools actually in use, including those adopted outside procurement; maps each claim to the evidence that would support it and identifies where that evidence does not yet exist; and assesses the controls around the data those tools touch, with particular attention to deal material and MNPI. For sponsors, the same review extends to the portfolio oversight program, so that what the firm says about monitoring portfolio cyber risk is backed by assessments, findings and an escalation path rather than by an annual questionnaire. The output is a claim-by-claim position: supported, supportable with work, or to be corrected now.
Reconcile Your AI Claims With Your AI Reality
Innovaiden reconciles what a firm says about its AI use, in marketing, in fundraising materials, and in regulatory filings, against what its systems and workflows actually do, and identifies where the evidence to support a claim does not yet exist. Reach out to scope it against your firm and your portfolio.
Get in TouchFrequently Asked Questions
Did the SEC say it is cracking down on AI washing?
Not in those words, and the distinction is worth getting right. The phrase AI washing does not appear anywhere in the SEC's fiscal year 2026 examination priorities. What the document says is narrower: 'With respect to AI, the Division will focus on recent advancements in AI and will review for accuracy registrant representations regarding their AI capabilities or AI.' AI washing is the term the securities bar has attached to that, notably in Goodwin's client alert, which describes the Division as scrutinising misleading claims about firms' AI capabilities or the role of AI in investment processes. The gloss is a fair characterisation of the underlying exposure, but it is commentary, not regulatory language, and quoting it as the SEC's own wording is a mistake worth avoiding in your own materials.
Does this apply to private equity sponsors, or only to public-market managers?
It applies to registered investment advisers, which includes most private equity and private credit sponsors above the registration thresholds. The examination priorities are written for advisers and investment companies generally, and the AI-related items are cross-cutting rather than strategy-specific. A sponsor that has described AI in its fundraising materials, its marketing, its Form ADV, or its investor reporting has made representations of the kind the Division said it would test. Firm size does not exempt you either: the Division has consistently prioritised newly registered advisers, and a newly registered manager with an AI story is squarely in the frame.
What else did the SEC name in its 2026 priorities that is relevant here?
Alongside the AI representation items, the Division said it will review controls to mitigate new risks associated with artificial intelligence and polymorphic malware attacks, and will examine registrants' policies and procedures, governance practices, data loss prevention, access controls, account management, and responses to cyber-related incidents such as ransomware. It also flagged compliance with new rules including the 2024 amendments to Regulation S-P. The pairing matters: the same examination that tests whether your AI claims are accurate also tests whether the data flowing through those AI tools is controlled.
Why is generative AI in a deal workflow a particular concern for a sponsor?
Because of what the data is. The material moving through a sponsor's workflows includes deal pipelines, target financials, valuation models, diligence findings, investor communications and, frequently, material non-public information. When those documents are pasted into or processed by AI tools, the questions an examiner would ask about data loss prevention, access controls and account management all attach to a set of systems that in many firms was adopted at the desk level rather than through procurement. The exposure is not exotic. It is ordinary confidentiality and information-barrier discipline, applied to a tool category that frequently entered the firm without passing through either.
How common are cyber incidents in portfolio companies?
Common enough that the base rate should inform your assumptions rather than your surprise. In a QBE North America survey of 300 risk managers and CISOs at private equity firms managing between 1 billion and 50 billion dollars in assets, 54% said up to a quarter of their portfolio companies had experienced a cyber incident or attack in the previous 12 months, and a further 23% put the figure between a quarter and a half. Kroll, surveying 325 private equity executives, found 80% had experienced some disruption tied to cybersecurity risk during the hold period in the past year, with an average financial impact of 2.1 million dollars per incident.
What evidence would an examiner expect for an AI claim?
Roughly what you would expect for any other material process claim: an inventory of the AI tools actually in use and by whom; the policies governing that use and evidence that they are followed; a record of how a tool influences the process it is said to influence; the diligence performed on the vendor; and the controls applied to the data the tool touches. The gap that catches firms is not usually dishonesty. It is that a claim made in a fundraising deck in good faith has never been reduced to evidence, because nobody expected to have to demonstrate it.
What should a sponsor do first?
Reconcile, before anyone asks you to. Collect every statement your firm has made about its AI use across marketing, fundraising materials, Form ADV, investor reporting and the website, and put them next to an honest inventory of what the firm actually does with AI today. Where a claim is supported, capture the evidence. Where it overstates reality, correct the language now, while correcting it is an editorial decision rather than a response to a deficiency letter. This exercise takes a few weeks and it is materially cheaper than the alternative.
Related Insights
Sources
- SEC Division of Examinations — Examination Priorities, Fiscal Year 2026. November 2025.
- SEC — Division of Examinations Announces 2026 Priorities. 17 November 2025.
- Goodwin — 2026 SEC Exam Priorities for Registered Investment Advisers and Registered Investment Companies. December 2025.
- Akin — SEC Announces 2026 Exam Priorities. December 2025.
- QBE North America — Private equity firms enhancing cyber resilience of portfolio companies. 2026.
- Kroll — Private equity: cybersecurity a significant risk to deals, with 2.1 million dollars average financial impact. 2026.
- ACA Group — Half of portfolio companies face elevated or high cyber risk, benchmarking report finds. 2026.
- Microsoft Security — New Microsoft Data Security Index report explores secure AI adoption to protect sensitive data. 29 January 2026.
- Ropes & Gray — Safeguarding the portfolio: incident readiness and the cyber landscape in 2026. 2026.