Skip to content
Blog

Financial Advisory Agents: Data, Disclaimers, and Regulated Outputs

Building AI agents that touch investment topics without hallucinating numbers or crossing regulatory lines — grounding, structured outputs, safety settings, and human review with the Gemini API.

Published on • October 9, 2026

AI Assistant

Financial advice is one of the highest-stakes domains you can point an LLM at. A hallucinated return figure, a missing disclaimer, or an unqualified recommendation is not a UX bug — it is potential liability. An agent that answers “what should I invest in?” needs three things working together: grounded data, constrained outputs, and a regulatory layer you design in from the start.

Here is how the pieces fit using the Gemini API as the reference stack.

1. Ground claims in real data

Function calling keeps your agent anchored to authoritative sources rather than the model’s memory of markets:

from google import genai
from google.genai import types

client = genai.Client()

tools = types.Tool(function_declarations=[{
    "name": "get_holdings",
    "description": "Fetch current holdings and cost basis for a portfolio ID",
    "parameters": {"type": "object", "properties": {"portfolio_id": {"type": "string"}}},
}])
config = types.GenerateContentConfig(tools=[tools])

For market news and filings, add Grounding with Google Search:

grounding_tool = types.Tool(google_search=types.GoogleSearch())
config = types.GenerateContentConfig(tools=[grounding_tool])
response = client.models.generate_content(
    model="gemini-3.8-flash",
    contents="Summarize the latest analyst reaction to this 13F filing",
    config=config,
)

The response carries groundingMetadata: webSearchQueries, groundingChunks (source URIs and titles), and groundingSupports mapping text segments to chunk indices — that mapping is your inline citation mechanism. Two obligations come with it: the Terms of Service require displaying the search suggestions widget, and the search tool is paid-tier.

Grounding is what turns “the model said” into “here is the source.”

2. Constrain outputs with JSON schema

Free-form text invites drift. Structured outputs force the model into a typed object you can validate, log, and gate:

config = {
    "response_mime_type": "application/json",
    "response_json_schema": RiskProfile.model_json_schema(),  # Pydantic → JSON Schema
}

The Gemini API supports a JSON Schema subset (string/number/integer/boolean/object/array/null, enum, format: date-time, minimum/maximum), with full JSON Schema — anyOf, $ref, preserved key order — available via response_json_schema since late 2025. Structured outputs can be combined with built-in tools including Grounding on Gemini 3.

Gotchas: very large or deeply nested schemas may be rejected, unsupported keywords are silently ignored, and older models need explicit propertyOrdering. Keep risk-profile schemas flat.

A well-designed schema is also a compliance tool — fields like disclaimer_shown: true and requires_human_review: bool become enforceable rather than aspirational.

3. Handle safety blocks as first-class states

Safety settings are keyed by HarmCategory (harassment, hate, sexually_explicit, dangerous) with probability-based block thresholds, and extra filters are off by default. Responses include safety ratings — always inspect finish_reason and handle blocking rather than assuming text arrived:

candidate = response.candidates[0]
if candidate.finish_reason != "STOP":
    handle_blocked_response(candidate)  # do not render a partial answer

Safety blocks firing mid-answer is normal behavior, not an error path to swallow.

The regulatory layer

This is what separates a “finance chatbot” from a defensible advisory agent.

The rules of thumb (US): the SEC’s 2023 predictive-data-analytics rule proposal was withdrawn in June 2025, so advisers fall back on Advisers Act §206 anti-fraud, the Marketing Rule 206(4)-1, and Reg S-P. The SEC has actively pursued “AI washing” enforcement — false claims about AI use are themselves a violation. Note that any marketing copy your agent produces is an “advertisement” under the Marketing Rule; hallucinated performance claims become §206 exposure.

Practical controls:

  • Disclosure — describe the AI’s nature, limits, and human-in-the-loop controls in Form ADV Part 2A; maintain written AI policies.
  • Human review — nothing client-facing ships without a human approving it. Treat agent output as a draft, not a deliverable.
  • Audit logging — record prompts, tool calls, grounded sources, and final outputs per interaction.
  • Refusal design — the agent must decline personalized allocation advice it is not licensed to give, and say so in plain language.
  • “Trust but verify” — verify research output and citations before they reach clients; a fabricated source is a §206 problem, not a footnote.

A worked shape for the agent loop

  1. Classify the request (informational vs. personalized advice).
  2. If personalized → either refuse with disclosure, or route to a licensed human with full context.
  3. If informational → call data tools (holdings, quotes, filings) + Search grounding.
  4. Generate with a structured schema requiring citations and disclaimer fields.
  5. Validate the schema; block on safety finish_reason.
  6. Log everything; hand off to human review before display.

Gotchas

  • Grounding requires displaying search suggestions per ToS.
  • Schema depth limits will reject over-modelled compliance objects — flatten them.
  • Safety categories should be tuned for your risk profile; defaults may be wrong for finance content.
  • Agent-produced marketing text is regulated content — apply your review workflow to it like any other advertisement.

Wrapping up

A financial advisory agent earns trust the same way a human does: cite your sources, stay inside your license, disclose your limits, and let a human sign off. Grounding gives you verifiable data, structured outputs make disclaimers and review flags enforceable, and audit logging makes the whole chain inspectable. The model is the easy part — the compliance architecture is the product.

References