AI Risk Matrix For Private Funds

AG
Akin Gump Strauss Hauer & Feld LLP

Contributor

Akin is a law firm focused on providing extraordinary client service, a rewarding environment for our diverse workforce and exceptional legal representation irrespective of ability to pay. The deep transactional, litigation, regulatory and policy experience we bring to client engagements helps us craft innovative, effective solutions and strategies.
Numerous journalists have showcased their use of "deep-voice" and other Artificial Intelligence technologies to spoof electronic confirmation systems. Although these attempts...
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

Numerous journalists have showcased their use of "deep-voice" and other Artificial Intelligence technologies to spoof electronic confirmation systems. Although these attempts to bypass security, so far, have largely been confined to retail banking and credit cards, private fund managers should focus on this new arrow in the scammer's quiver.

All private fund managers, including managers that use third-party administrators to manage subscriptions, redemptions and investor information processes (e.g., wiring instructions), should assess their susceptibility to AI-fueled scams, such as combining a redemption or transfer request from a hacked or spoofed email account with a "live" verification by an AI-enabled voice or video impersonation tool.

While it is early days, and given that there is no one-size-fits-all solution, we would suggest that all managers review and stress test their verification processes and consider whether additional safeguards are appropriate. Compliance personnel should also review existing (albeit pre-AI) regulatory guidance and industry best practices for indicative guidance (e.g., the SEC's Regulation S-ID Risk Alert).

One interim suggestion that we have is to implement a "2x2" requirement, i.e., requiring:

  • A bidirectional communication record
  • That occurs across two pre-approved media (e.g., "known" email accounts or telephone numbers)

for any investor-related change or transaction to occur.

For example, a voice request over a phone call originating from a pre-approved number must be validated by an email exchange with a pre-approved email address, or vice versa. We have distilled this suggestion into a (very simplified) matrix:

1329650a.jpg

Obviously, this effort will require collaboration among legal, compliance, operations and other firm personnel. Outside counsel can assist in identifying state, federal and foreign privacy, data transfer and similar laws, in addition to traditional regulatory compliance advice.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

AI Risk Matrix For Private Funds

United States Technology

Contributor

Akin is a law firm focused on providing extraordinary client service, a rewarding environment for our diverse workforce and exceptional legal representation irrespective of ability to pay. The deep transactional, litigation, regulatory and policy experience we bring to client engagements helps us craft innovative, effective solutions and strategies.
See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More