AI Use Cases in Investment Management: What a Registered Firm Can Actually Deploy

A portfolio manager asks whether an AI system can handle rebalancing. Someone else in the room says the models are not good enough yet. Both are having the wrong argument, because in Canada this question has already been answered in writing.

On 5 December 2024 the Canadian Securities Administrators published Staff Notice and Consultation 11-348, setting out how existing securities law applies to AI systems in capital markets. It is staff guidance and a consultation rather than a new rule, and it does not need to be a new rule to matter. It tells you which uses staff consider ordinary, which ones they will attach conditions to, and the one position they say an AI system cannot currently occupy.

TL;DR

  • Model quality is not the binding constraint. Accountability is. Ask whose name is on the outcome before you ask what the system can do.
  • Five uses are already ordinary in registered firms: back office, trade execution, KYC and onboarding, client support, and decision support.
  • Narrow automated execution is contemplated, inside what staff call narrowly prescribed constraints. Rebalancing to pre-set parameters is the example they give.
  • The ceiling is explicit. Staff do not believe an AI system can substitute for an advising representative as decision-maker and consistently satisfy regulatory requirements.
  • Support activity can be outsourced. Registerable activity cannot. That single line sorts most proposals faster than any technical review.
  • Explainability is a record-keeping requirement here, not a preference. If you cannot reconstruct why, you cannot evidence compliance.
  • Tell staff early. The notice invites it, and says conditions may be attached to your registration.

Ask whose name is on the outcome

Firms evaluate AI by capability. Regulators evaluate it by signature.

That gap explains most of the stalled AI proposals in registered firms. A team spends three months proving a model performs well on historical data, presents it, and runs into an objection nobody raised at the start: this output goes to a client under a registered individual’s name, and that individual has to be able to say why.

So run the test first, in one question. Whose name is on the outcome?

If the answer is a registered individual, AI can prepare the work, gather the inputs, draft the document and flag what changed. It cannot be the decision. If the answer is nobody in particular, because the output is an internal efficiency, the constraint drops away and the question becomes an ordinary one about accuracy and cost.

Call it the signature test. It takes ten seconds and it sorts a backlog of AI ideas into the ones worth scoping and the ones that will die in compliance review, before anyone builds anything.

Evaluating an AI proposal by capability asks whether the model is accurate enough, whether it beats the benchmark and whether the vendor is credible, and it stalls in compliance review. Evaluating it by signature asks whose name is on the outcome, what that person would have to explain and what record survives, and it produces a decision in minutes.
Both reviews are worth doing. Doing them in this order stops a firm spending a quarter on something that was never going to clear.

The five uses that are already ordinary

The notice describes uses that registrants are making today and treats them as unremarkable, subject to controls. None of them requires an argument about the future of the industry.

Back office and risk

Staff name trade surveillance, identification of cyber threats, safeguarding client personal information, and the preparation of reports to clients and regulators. This is the least contested category and usually the fastest to value.

Trade execution

Execution quality tools can replace rules-based algorithms doing the same job. Staff note this use does not involve making suitability determinations for clients, which is why it does not raise the concerns the later use cases do.

KYC and onboarding

AI can make know-your-product research, KYC information gathering and onboarding more efficient. The collection process still has to amount to what the notice calls a meaningful interaction with the client.

Client support

General support, including chatbots that answer questions about the firm's services and assist with complaint handling. Distinct from KYC, and held to the standard that the information delivered is accurate.

Decision support

Gathering information about a wider universe of investments and assessing it against KYC information, forecasting movements in volume, liquidity, volatility and price, and alerting a registrant when prescribed inputs change.

Decision support is the one worth pausing on, because it is where the line runs closest. Staff describe research use as not inherently problematic, on a condition worth reading twice: the registrant has to take reasonable steps to verify the quality and accuracy of the information sources, and must not automatically act on the output. The AI result is “no more than an input for their own decision-making, so that trades are ultimately recommended or directed by the registrant.”

An analyst who reads an AI summary, checks it, and forms a view is inside that. A workflow where the AI output routes straight into an order is not, and the difference is a design decision made early, not a policy written afterwards.

Worth keeping

  • Four of the five uses sit entirely behind the client. They are the fastest place to start and the easiest to evidence.
  • Decision support is where a firm first has to be deliberate about workflow design rather than tool selection.
  • "Verify the sources" is a real obligation with real cost. Budget for it rather than discovering it in review.

Where the ceiling actually sits

Two rungs sit above decision support, and they are treated very differently.

The first is bounded automation. Staff write that AI systems “could be used to make decisions that are automatically executed with human oversight but without direct human intervention, provided such decisions are within narrowly prescribed constraints.” The examples given are rebalancing trades designed to bring portfolios back to pre-set parameters, dynamic hedging strategies involving continual adjustment of positions, and high-frequency trading. The load-bearing words are narrowly prescribed. A constraint someone can write down, test against, and monitor is a constraint. A model deciding for itself what is reasonable is not.

The second rung is full discretion, and this is where the notice stops being permissive.

At the current stage of development of AI systems, we do not believe it is possible to use an AI system as a substitute for an advising representative acting as decision-maker for clients' investments and consistently satisfy regulatory requirements such as for making suitability determinations or reliably deliver the desired outcomes for clients.

Read that as an operating fact rather than a prediction. Staff also say that where a firm runs fully discretionary portfolio management without a registered individual making the ultimate decisions, “it would be challenging for a registrant using such a system to demonstrate proper compliance with securities laws.”

Note what is doing the work. The objection is not that the model would pick badly. It is that the firm could not demonstrate compliance afterwards. Those are different problems, and only one of them gets solved by a better model.

Five rungs of AI autonomy in a registered firm. Back office and execution carry no client decision and are the ordinary starting point. Research input requires the registrant to verify sources and not act automatically. Decision support requires that the registrant still recommends or directs the trade. Bounded automation is contemplated only inside narrowly prescribed constraints. Full discretion without a registered individual deciding is the rung staff say cannot currently be occupied.
The rung is set by who owns the decision, not by how capable the system is. Moving up a rung is a governance change before it is a technical one.

The line that sorts proposals fastest

One sentence in the notice does more practical work than the rest combined. Support activities such as data processing and report generation can be outsourced. Registerable activity, and staff give trade suitability determinations as the example, cannot.

That draws a boundary you can apply to a vendor proposal in an afternoon. Anything on the support side is a procurement and diligence question. Anything that reaches into registerable activity is a registration question, and it does not become a procurement question because a vendor says the model handles it.

The notice attaches a specific control to outsourced AI that is easy to miss and easy to implement: “if AI systems assist in the generation of client reports, the firm should be sampling the output and verifying accuracy on an ongoing basis.” Not once at launch. Ongoing. If nobody owns that sampling, the control does not exist.

What you have to be able to show afterwards

The obligations in the notice are mostly about evidence. Four are worth building into any deployment plan from the start, because retrofitting them is far more expensive than including them.

  1. Explainability sufficient for your records

    Staff write that AI systems used by registrants "should provide an appropriate degree of explainability so that registered firms are able to meet applicable record keeping requirements." The notice flags that lower-explainability systems, which it calls black boxes, may challenge transparency, accountability, record keeping and auditability. What counts as appropriate depends on the circumstances, and staff say they may publish guidance as they build experience with those determinations.

  2. Disclosure that a client can actually use

    Any use of AI that may directly affect the registerable services provided to a client has to be disclosed clearly and meaningfully, consistent with the relationship disclosure requirements in section 14.2 of NI 31-103 and the duty to deal fairly, honestly and in good faith. A line buried in a schedule is not the standard being described.

  3. Testing before and after, with a fallback

    The notice emphasises regularly testing the system and the results of its use both before and after adoption, by people with the necessary expertise. It also asks firms to consider how they would adjust or continue operations that depend on an AI system if material deficiencies were found. That is a continuity plan, and most AI business cases do not have one.

  4. Filings, and a conversation you are invited to have

    Use of AI in ways that may directly affect registerable services must be disclosed in registration applications and change filings. Beyond that, staff write that registrants considering AI "are strongly encouraged to contact staff at an early stage", and that depending on the use, tailored terms and conditions may be recommended for the firm's registration.

That last point is the one firms most often treat as a risk. It is closer to the opposite. Finding out in month one that a use case will carry conditions is cheap. Finding out in month nine, after the build, is not.

Worth keeping

  • Every obligation here is about what you can evidence later, so design the evidence at the same time as the workflow.
  • Ongoing sampling of AI-generated client output is named explicitly. Give it an owner and a cadence.
  • An early conversation with staff is invited, and it prices the compliance risk before you spend the build budget.

Six mistakes that cost the most time

  • Evaluating the model before evaluating the accountability. Why it fails: capability is not the constraint that stops these projects. Better: run the signature test in the first meeting and scope only what survives it.
  • Treating "human in the loop" as a checkbox. Why it fails: a human who approves without the information to disagree is not oversight, and the record will show it. Better: define what the reviewer sees, what they can change, and how a disagreement is captured.
  • Assuming a vendor's compliance claim transfers to you. Why it fails: registrants are responsible and accountable for all functions they outsource, and must supervise on an ongoing basis. Better: treat vendor claims as inputs to your own diligence, and write down what you verified.
  • Buying explainability last. Why it fails: it is far cheaper to choose a system you can reconstruct than to add reconstruction to one you cannot. Better: make explainability a selection criterion, weighed against capability, at shortlist stage.
  • Automating KYC collection out of the conversation. Why it fails: the process has to amount to a meaningful interaction with the client, and efficiency is not the standard being measured. Better: use AI to prepare and check the interaction rather than to replace it.
  • Launching the sampling control and then quietly dropping it. Why it fails: the expectation is ongoing verification, and a control that lapsed is worse in a review than one that never existed, because the lapse is dated. Better: put it on a schedule with a named owner from day one.

What this article deliberately does not do

It does not tell you what to invest in, for anyone, in any circumstances. Nothing here is investment advice, and the use cases above are operational questions about how a firm runs, not views about markets or securities.

It also does not tell you whether any particular product satisfies these expectations. No vendor’s compliance can be verified from the outside, and the guideline that will carry the heaviest model-governance weight in Canada, OSFI’s Guideline E-23, does not take effect until 1 May 2027, so nothing has a track record against it yet.

Two limits on the source itself are worth stating. Staff Notice 11-348 is staff guidance on how existing law applies, together with a consultation whose comment period closed on 31 March 2025. It is not a rule, and positions can develop. Firms whose dealers are members of the Canadian Investment Regulatory Organization are also subject to CIRO’s rules, and the notice directs those members to review CIRO guidance separately. This article does not summarise CIRO material, because summarising a document nobody read is how errors enter.

Check the current text before you rely on any of this. Regulatory status is the one thing on this page with an expiry date.

Glossary

AI system
In the notice, a machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions.
Registerable activity
The activity that requires registration, such as advising on or trading in securities. It can be supported by a service provider but not outsourced to one.
Advising representative
A registered individual authorised to advise on securities, subject to proficiency and conduct requirements, and responsible for the recommendations or decisions they make.
Suitability determination
The assessment that an investment action is suitable for a client, based on know-your-client information.
KYC
Know your client. The information a registrant gathers and keeps current about a client, collected through what the notice calls a meaningful interaction.
Explainability
The ability of a person to understand and explain how an AI system produced a given output, including which factors were used and the weight given to each.
Model drift
Degradation in a model's performance over time as live conditions move away from the conditions it was built on.
NI 31-103
National Instrument 31-103, the core rule governing registrant conduct, registration requirements and ongoing obligations in Canadian jurisdictions.

Questions firms actually ask

Can an AI system manage a discretionary portfolio in Canada?

Not as the decision-maker. CSA staff wrote in December 2024 that at the current stage of AI development they do not believe an AI system can substitute for an advising representative acting as decision-maker for clients' investments and consistently satisfy regulatory requirements. A registered individual makes the ultimate decisions.

Can AI run automated rebalancing?

The notice contemplates decisions that execute automatically with human oversight but without direct human intervention, provided they sit inside narrowly prescribed constraints, and gives rebalancing to pre-set parameters as an example. The work is in defining and evidencing those constraints.

Do we have to tell clients we use AI?

Where the use may directly affect the registerable services provided to them, yes, clearly and meaningfully, consistent with section 14.2 of NI 31-103 and the duty to deal fairly, honestly and in good faith. Purely internal uses that do not touch those services are a different question.

Does using a third-party AI service move the responsibility to the vendor?

No. Registrants remain responsible and accountable for functions they outsource, must conduct diligence before contracting, and must supervise on an ongoing basis. Where AI helps generate client reports, the firm is expected to sample output and verify accuracy over time.

Where should a firm start?

With uses that carry no client decision. Trade surveillance, threat detection, internal reporting and report preparation are named in the notice and are the easiest to evidence. They also build the governance muscle you will need before anything closer to the client is worth attempting.

Should we contact the regulator before we build?

The notice strongly encourages registrants considering AI to contact staff at an early stage, and says tailored terms and conditions may be recommended depending on the use. Early contact prices that risk before the build budget is committed.

What about OSFI's rules?

OSFI Guideline E-23 on model risk management applies to federally regulated financial institutions and takes effect on 1 May 2027. Its definition of a model expressly includes AI and machine learning methods. Securities registrants and federally regulated institutions are different populations, and a firm can sit in both.

The next question

Most firms do not need a view on artificial intelligence. They need a sorted list: which uses are ordinary, which carry conditions, and which are not available at all. That list is mostly written already, by the people who will review the work.

If you want the governance side of this rather than the use cases, the companion piece is AI governance in financial services, which covers what has to be true about any AI system a regulated firm runs, and the 2027 deadline that is already set.