CFTC and AI: Self-Reporting Incentives, Compliance Program Requirements, and Derivatives Trading
- October 3, 2026
- Posted by: allan
- Category: Uncategorized
The Commodity Futures Trading Commission regulates the U.S. derivatives markets—futures, options on futures, swaps, and the expanding universe of commodity-related products including, increasingly, digital assets. Firms operating in CFTC-regulated markets have been deploying AI at scale for years: algorithmic trading systems, automated order routing, AI-assisted surveillance for market abuse, AI-driven risk management, and generative AI tools for compliance and research. The CFTC has responded with two significant developments in its oversight of AI in regulated markets. In December 2024, the agency issued an inter-divisional staff advisory outlining what AI-related compliance obligations look like under existing law. And in May 2026, the CFTC’s Division of Enforcement issued a comprehensive new cooperation policy—CFTC Letter No. 26-15—that creates a meaningful path to declination for firms that self-report misconduct, cooperate fully, and remediate effectively.
Understanding both developments is essential for any compliance program operating in the CFTC-regulated space.
The December 2024 AI Staff Advisory: What Existing Law Requires
On December 5, 2024, the CFTC’s Divisions of Clearing and Risk, Data, Market Oversight, and Market Participants jointly issued a staff advisory on the use of AI by CFTC-registered entities and registrants. The advisory is notable as much for what it does not do as for what it says: it does not create new rules or impose new obligations. Instead, it takes the position that the CFTC’s existing regulatory framework—the Commodity Exchange Act (CEA) and CFTC regulations—applies fully to AI-powered systems, and it maps out what that means in practice.
Who the Advisory Covers
The advisory applies to the full spectrum of CFTC-registered entities and registrants:
- Designated contract markets (DCMs), swap execution facilities (SEFs), and swap data repositories (SDRs)
- Derivatives clearing organizations (DCOs)
- Futures commission merchants (FCMs), swap dealers (SDs), commodity pool operators (CPOs), commodity trading advisors (CTAs), introducing brokers (IBs), retail foreign exchange dealers (RFEDs), and associated persons
This is a broad universe. If your firm is registered with the CFTC in any capacity and you are using AI in any function related to your regulated activities, the advisory applies.
The Core Compliance Obligation
The advisory states the foundational principle clearly: a regulated entity must comply with all applicable CEA and CFTC requirements in its adoption and integration of AI, regardless of whether it develops the AI technology internally or procures it from a third-party service provider.
This is the same principle that the SEC and FINRA have articulated in their own AI guidance: regulatory responsibility follows the function, not the organizational chart. Buying a third-party AI trading system does not transfer the obligation to supervise that system’s compliance with CFTC rules to the vendor. The FCM, swap dealer, or other registered entity that deploys the system remains accountable.
The advisory emphasizes that regulated entities should assess the risks of using AI and update their policies, procedures, controls, and systems accordingly. That assessment is not a one-time exercise at deployment—it must be ongoing as AI systems evolve.
Material System Changes and Advance Notice
For certain registered entities—particularly DCMs, SEFs, DCOs, and SDRs—existing CFTC regulations require advance notice to CFTC staff of material planned changes to automated systems that may impact the reliability, security, or adequate scalable capacity of those systems. The advisory specifically reminds these entities that adopting AI may constitute such a material change, triggering the advance notice obligation.
This is not a trivial consideration. An exchange or clearing organization that replaces a core surveillance system with an AI model, or that integrates a large language model into its risk management processes, needs to assess whether that change triggers pre-notification requirements. Getting this wrong—by deploying a material AI system change without the required notice—creates a standalone compliance violation separate from any question about the AI system’s performance.
Cybersecurity and System Safeguards
The advisory specifically stresses the value of robust system safeguards to mitigate vulnerabilities that may lead to cybersecurity risks, algorithmic errors, and market disruptions caused by automated decision-making. For AI systems used in trading or risk management, this means the firm’s system safeguards program—required for DCMs, SEFs, DCOs, and SDRs under applicable CFTC regulations—must specifically address AI-related vulnerabilities.
AI trading systems can create market disruptions in ways that differ from conventional algorithmic trading systems. Machine learning models trained on historical market data may behave in unexpected ways in market conditions that differ significantly from the training environment. Surveillance systems using AI may generate false positives or miss patterns they were not trained to detect. Compliance programs must address these failure modes through testing, validation, and operational controls.
Examinations
The advisory notes that CFTC staff may incorporate AI as a topic in routine oversight activities, including examinations. Firms should anticipate that examination staff will ask about AI governance frameworks, policies and procedures governing AI use, vendor management for AI systems, and testing and validation documentation. The advisory effectively telegraphs the examination agenda.
The May 2026 Cooperation Policy: CFTC Letter No. 26-15
On May 19, 2026, the CFTC’s Division of Enforcement issued CFTC Letter No. 26-15, a comprehensive new staff advisory on self-reporting, cooperation, and remediation. The letter supersedes all prior CFTC policies on these subjects, including the February 2025 Enforcement Advisory. It represents the third generation of CFTC cooperation policy—what practitioners have called “Cooperation 3.0″—and it creates the most explicit path to declination in CFTC enforcement history.
The Letter is not AI-specific. It applies to all CFTC enforcement matters. But its framework is particularly relevant for AI-related misconduct, which often involves conduct that is difficult for regulators to detect without internal disclosure, that benefits significantly from prompt remediation, and that raises complex technical issues where cooperation with Division investigators is practically essential.
The Declination Framework
Under the new policy, the Division of Enforcement will not recommend to the Commission that an enforcement action be instituted when all of the following conditions are met:
1. Voluntary self-report. The firm must have reported the potential violation to CFTC staff voluntarily—that is, before the CFTC became aware of the potential misconduct through its own investigative activities or through a third-party disclosure. Timing matters. A report made after the CFTC begins inquiring about related conduct is not voluntary in the relevant sense, even if the firm was not specifically aware of the investigation.
2. Full cooperation. The firm must provide full cooperation throughout the Division’s investigation. The advisory defines full cooperation with precision: disclosing all relevant non-privileged information in the firm’s possession; sharing findings of internal investigations without breaching privilege or work product protections; making personnel available for interviews; preserving all records—explicitly including ephemeral messaging—at the time of self-report; undertaking good-faith efforts to secure documents located overseas; and continuing to report any additional violations discovered after the initial disclosure.
3. Timely and appropriate remediation. The firm must remediate the misconduct in a timely and appropriate manner. The advisory acknowledges that complex remediation may take time, and it allows the Division to grant a declination either before or after full implementation of the remediation plan, depending on complexity and circumstances. The key is that the plan must be credible, documented, and in progress.
4. Full restitution and/or disgorgement. Where the misconduct caused losses to others or generated unjust enrichment, the firm must provide full restitution to affected parties and/or disgorge ill-gotten profits. As with remediation, the Division may make a declination determination before actual payment if the firm has created and is implementing an appropriate payment plan, depending on the most effective method of returning funds to those harmed.
5. No aggravating circumstances. Even a firm that satisfies all four of the foregoing conditions may be ineligible for a declination if aggravating circumstances are present. The advisory limits aggravating circumstances to four categories: pervasive intentional or reckless misconduct by ownership or senior management; intentional or reckless misconduct occurring over an extended period; recidivist intentional or reckless misconduct; and misconduct that caused particularly egregious aggregate harm.
Partial Cooperation Credit
For firms that self-report but do not provide full cooperation, or that cooperate but did not self-report, the advisory provides for reduced penalties rather than declination. The Division will consider the degree of cooperation in its penalty recommendations, with meaningful credit available even for partial compliance with the framework. The incentive structure is graduated: the more a firm cooperates, the better the outcome—but the biggest reward (declination) requires full compliance with all five conditions.
Ephemeral Messaging
The explicit reference to preserving ephemeral messages—the types of communications that are automatically deleted on apps like WhatsApp, Signal, and similar platforms—is significant. The CFTC, like the SEC, has brought enforcement actions against regulated firms for failures to maintain records of business communications conducted on personal devices or through ephemeral messaging applications. In the cooperation context, the advisory makes clear that a firm claiming to cooperate while failing to preserve all relevant records—including messages that would otherwise be deleted—will not receive full cooperation credit.
How AI-Related Misconduct Fits the Declination Framework
The combination of the December 2024 AI advisory and the May 2026 cooperation policy creates a specific opportunity and obligation for regulated firms that discover AI-related compliance failures.
Consider common AI-related compliance failure patterns in CFTC-regulated markets:
Algorithmic trading errors causing market disruption. A firm discovers that its AI trading algorithm malfunctioned and contributed to a market disruption or executed trades that may have violated CFTC rules prohibiting disruptive trading practices. Under the cooperation framework, the path to a declination—or meaningful penalty reduction—runs through prompt self-report, preservation of all relevant records (including the model logs and training data), cooperation with CFTC’s technical investigation, and genuine remediation of the algorithm.
AI surveillance failures enabling market abuse. A firm’s AI-based market surveillance system failed to detect wash trading or spoofing activity, and the firm discovers the failure before CFTC does. Self-reporting the failure, providing full documentation of the surveillance system’s architecture and testing history, making the data scientists available for interviews, and implementing a remediated surveillance program positions the firm for cooperation credit.
Third-party AI vendor misconduct. A registered entity discovers that a third-party AI vendor was providing manipulated or inaccurate data that affected the entity’s compliance representations to the CFTC. The entity’s ability to obtain cooperation credit depends on promptly self-reporting once it discovers the problem, preserving records documenting what the vendor provided and what the entity knew, and cooperating fully even if doing so implicates the vendor.
Compliance program deficiencies revealed by AI audit. An internal AI audit reveals that the firm’s AI compliance tools have been miscategorizing certain trades in ways that may have resulted in inaccurate regulatory reporting. Proactive disclosure of the misreporting, correction of the records, and cooperation with CFTC’s review of the corrected data is the path to cooperation credit.
Building a CFTC-Compliant AI Program
The regulatory framework the CFTC has assembled around AI—through the December 2024 advisory and the cooperation policy—rewards compliance programs that are honest about their AI systems’ limitations and failures. Firms that are positioned to detect and report AI-related issues quickly are firms that can take advantage of the declination framework. Firms that bury AI-related compliance failures, or that discover them only because CFTC examiners come looking, forfeit that opportunity.
Practically, a CFTC-compliant AI program for registered entities should include:
An AI governance framework with clear ownership of AI systems across the three lines of defense (business, compliance, and internal audit), documented policies for AI development and deployment, and defined processes for identifying and reporting material system changes.
Updated written supervisory procedures that specifically address AI systems, including algorithmic trading systems, AI-driven surveillance tools, and any AI vendor systems used in regulated functions.
Pre-deployment testing documentation for AI systems used in regulated functions, including back-testing results, validation studies, and assessment of potential market impact.
Ongoing monitoring of AI system performance, with defined alert thresholds and escalation paths when AI systems behave unexpectedly.
A self-reporting protocol that defines who at the firm has authority to make voluntary disclosures to the CFTC, what the decision criteria are for triggering disclosure, and how the firm will preserve records once a potential violation is identified—including records of ephemeral communications.
Vendor agreements that provide the firm with the technical documentation, audit rights, and incident notification provisions it needs to comply with CFTC requirements and to cooperate effectively with any CFTC investigation involving the vendor’s systems.
The CFTC’s approach to AI compliance is deliberate: use existing regulatory authority to the fullest, make the obligations clear through guidance, and reward firms that embrace compliance over concealment. For firms operating in CFTC-regulated markets, the message is that the time to build these programs is before the examination request arrives, not after.
This post is for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. If you have questions about your specific situation, consult a qualified attorney.
