FINRA AI Supervision: What Every Broker-Dealer Must Do to Comply in 2026
- September 29, 2026
- Posted by: allan
- Category: Uncategorized
FINRA published its 2026 Annual Regulatory Oversight Report on December 9, 2025. The report, which FINRA issues annually to signal examination priorities and share findings from prior examination cycles, devotes substantial attention to generative AI for the second consecutive year. But the 2026 treatment is different from prior years in a material respect: it moves from describing what AI risks exist to specifying what supervisory frameworks firms must have in place — and it introduces, for the first time, a substantive regulatory framing for autonomous AI agents operating within brokerage workflows.
This post translates the 2026 Report’s AI supervisory priorities into a concrete compliance action plan for broker-dealers. The goal is not to summarize the report — any compliance officer can read the report — but to explain what it actually requires firms to build, document, and operate.
The Foundational Principle: Technology Neutrality
FINRA’s 2026 Report opens its GenAI discussion with a statement that frames everything that follows: FINRA’s rules are technology-neutral. The use of generative AI does not create a compliance exemption, and it does not create a new set of rules. It simply means that existing rules — supervision, communications, recordkeeping, outsourcing, fair dealing — apply to AI just as they apply to any other technology or tool.
This principle has significant practical implications. A broker-dealer cannot argue that its AI-generated communications are not subject to FINRA Rule 2210 (Communications with the Public) because they were produced by software rather than a human. It cannot argue that its AI-assisted supervisory processes satisfy Rule 3110 (Supervision) just because they involve sophisticated technology. And it cannot argue that the recordkeeping requirements of Rule 4511 and SEC Rule 17a-4 do not apply to AI-generated content that relates to the firm’s business.
What FINRA is saying, in essence, is: you already know what the rules require. Apply them to your AI systems.
The Five Supervisory Priority Areas for 2026
1. Governance and Pre-Deployment Assessment
The 2026 Report’s first expectation is that firms assess compliance obligations before deploying GenAI — not after. FINRA expects firms to evaluate the regulatory implications of any AI use case before the technology goes live, and to establish governance frameworks to supervise AI usage on an ongoing basis.
What this requires in practice:
Firms need a pre-deployment compliance review process for any new AI use case. That process should address: What does this AI system do? What existing FINRA and SEC rules apply to that activity? What are the specific risk vectors (hallucinations, bias, cybersecurity exposure, customer harm)? What supervisory controls will be applied?
The governance framework should also address who is responsible for AI oversight within the firm. As AI systems proliferate, the compliance function needs clearly assigned ownership — a specific individual or committee accountable for AI governance, with authority to review, approve, or reject AI deployments.
FINRA Regulatory Notice 25-07, released in April 2025, extended Rule 3110’s supervisory duties to generative AI workflows. Any firm that has not updated its Written Supervisory Procedures to reflect its AI use cases since that notice is already behind the supervisory expectation.
2. Written Supervisory Procedures That Actually Address AI
Rule 3110 requires broker-dealers to establish and maintain a reasonably designed supervisory system, including written supervisory procedures (WSPs). FINRA’s 2026 Report makes clear that a WSP that does not address the firm’s AI use cases is not reasonably designed for a firm that uses AI.
What effective AI WSPs must cover:
- The specific AI tools the firm uses, organized by function (customer communications, research, trade surveillance, supervisory review, back-office operations)
- The compliance rules applicable to each use case
- The approval process for deploying new AI tools or materially modifying existing ones
- The monitoring and testing protocols for each AI system in use
- Escalation procedures when AI outputs are flagged as problematic
- Recordkeeping requirements for AI-generated content
- Procedures for vendor oversight where AI is provided by third parties
The 2026 Report specifically states that if a firm uses GenAI as part of its supervisory system — meaning AI tools that help identify compliance issues — those tools must themselves be subject to oversight. An AI surveillance system is not a substitute for a supervisory system; it is a component of one, and it must be supervised like any other component.
3. Ongoing Monitoring, Logging, and Output Review
FINRA’s 2026 Report is explicit that deploying an AI system is not the end of the compliance obligation — it is the beginning. Ongoing monitoring is required to confirm that AI systems continue to perform as expected and produce compliant outputs.
The specific monitoring practices FINRA identifies:
- Storing prompt and output logs for accountability and troubleshooting
- Tracking which model version was used and when
- Validation and human-in-the-loop review of model outputs
- Regular checks for errors and bias
Hallucinations. The 2026 Report defines hallucinations as instances where the model generates information that is inaccurate or misleading, yet presents it as factual. The compliance risk is direct: an AI system that confidently generates an incorrect regulatory interpretation, misrepresents a product’s characteristics, or fabricates a market statistic — and that output is then used in a client communication or supervisory review — creates a compliance failure.
FINRA does not specify how frequently output logs must be reviewed or what percentage of outputs must receive human review. The standard is “reasonably designed” — which will be applied in the context of the firm’s specific use cases and the risk associated with errors in those use cases. High-stakes uses (customer-facing recommendations, regulatory filings) warrant more intensive review than lower-stakes uses (internal research summarization).
Bias. The 2026 Report defines AI bias as situations where a model’s outputs are skewed or incorrect due to model design decisions or limited or inaccurate training data. In the broker-dealer context, bias in AI systems used for customer communications, suitability analysis, or credit decisions could create fair-dealing violations. Firms should periodically test AI outputs across different customer demographics and product categories to identify systematic bias before it generates regulatory exposure.
4. Customer Communications and the Fair and Balanced Standard
Any AI-generated communication sent to customers — chatbot responses, AI-drafted emails, AI-generated account summaries, AI-produced research — is a firm communication subject to FINRA Rule 2210. Rule 2210 requires communications to be fair and balanced, not misleading, and consistent with the products and services the firm actually offers.
The 2026 Report addresses AI-generated customer communications with specific expectations:
Chatbots as firm communications. A chatbot interacting with customers is not a neutral technology tool — it is the firm speaking to the customer. It must be supervised and archived as a firm communication.
Accuracy of AI references in communications. If a firm references AI capabilities in customer communications — describing its AI-driven services, AI-enhanced research, or AI-assisted recommendations — those references must accurately reflect how AI is actually used and must include discussion of the risks and limitations of the AI, not just its benefits.
Suitability and Regulation Best Interest. An AI system that generates personalized investment recommendations or product suggestions for retail customers must comply with Regulation Best Interest. The Care Obligation under Reg BI requires that a recommendation be in the customer’s best interest based on the customer’s investment profile. An AI system that generates recommendations must be designed to consider customer profiles, and the firm must monitor whether AI-generated recommendations are actually meeting the Reg BI standard — not just assume they are.
5. Autonomous AI Agents: The 2026 Report’s New Frontier
The most significant new territory in the 2026 Report’s GenAI section is its treatment of autonomous AI agents. FINRA defines AI agents as “systems or programs that are capable of autonomously performing and completing tasks on behalf of a user.” This includes AI systems that can execute trades, submit orders, process customer requests, or take other operational actions within a firm’s systems without requiring a human to approve each action.
The 2026 Report flags AI agents as requiring “novel oversight” and identifies specific supervisory considerations that existing frameworks may not fully address.
Why agents are different from generative AI tools. A large language model that drafts an email waits for a human to send it. An AI agent that executes a task does not wait — it acts. The compliance implications are fundamentally different. When an AI agent takes an action that constitutes a violation, the question is not just whether the agent’s output was reviewed before use; it is whether the agent should have had the authority to take that action at all.
What the 2026 Report expects for AI agents:
-
Defined authorized actions. Firms should document what actions an AI agent is permitted to take, under what circumstances, and subject to what limitations. An agent that processes routine customer service requests operates under a different authorization scope than one that submits orders.
-
Escalation and human-in-the-loop protocols. The 2026 Report asks firms to consider where human-in-the-loop oversight should be required for AI agents. High-consequence actions — submitting orders above a threshold size, taking customer communications with legal or regulatory implications, modifying account settings — are candidates for mandatory human review.
-
Guardrails and restriction mechanisms. The 2026 Report expects firms to establish technical guardrails that limit AI agents from taking actions outside defined parameters. This is both a technical architecture requirement and a supervisory design requirement — the WSP should describe what the guardrails are and how they are monitored.
-
Books and records for agent actions. If an AI agent takes an action — submitting an order, sending a communication, modifying a record — that action is a firm activity subject to applicable recordkeeping requirements. Firms need to ensure that agent-initiated actions are captured in their books and records systems.
-
System access management. The 2026 Report notes that autonomous agents may require access controls that restrict what systems and data the agent can reach. This is both a cybersecurity requirement and a supervisory one — an AI agent should not have broader system access than is necessary for its authorized functions.
Vendor Oversight
A substantial proportion of broker-dealer AI use involves third-party AI tools — vendor-provided models, SaaS AI platforms, and AI components embedded in existing technology systems. The 2026 Report makes clear that outsourcing AI functions to a vendor does not transfer the compliance obligation.
FINRA has longstanding guidance on outsourcing supervision — the principle is that a firm must supervise outsourced activities as if they were performed in-house. This applies to AI vendors. Firms should:
- Conduct due diligence on AI vendors before deployment, including reviewing vendor validation practices, data governance, output monitoring, and security practices
- Include AI-specific provisions in vendor contracts, addressing data ownership, output accuracy, model change notification, audit rights, and the vendor’s own compliance with applicable regulations
- Monitor vendor AI system performance on an ongoing basis, not just at onboarding
- Have a contingency plan for vendor failure, model deprecation, or situations where the vendor’s AI system produces systematically non-compliant outputs
The Compliance Action Plan: What to Build in 2026
Converting the 2026 Report’s GenAI supervisory priorities into a compliance action plan requires work across several dimensions. Here is a prioritized framework:
Immediate actions (within 60 days):
- Complete an inventory of all AI tools currently in use, organized by function, vendor, and the regulatory activities they touch.
- Review existing WSPs and identify gaps — places where AI use cases exist but are not addressed in the WSP.
- Confirm that prompt and output logging is in place for AI tools that generate customer-facing content or affect supervisory processes.
Short-term actions (within 90 days):
- Update WSPs to address all identified AI use cases. For each use case, the WSP should specify the applicable rules, the supervision process, and the responsible supervisory principal.
- Establish or formalize an AI governance process for pre-deployment review of new AI use cases.
- Review vendor contracts for AI tools to confirm audit rights, change notification obligations, and data governance provisions.
Medium-term actions (within 180 days):
- Implement a bias testing protocol for AI systems used in customer-facing applications.
- For any AI agents in use or under development, document authorized actions, escalation protocols, and guardrails.
- Conduct a tabletop review of AI-related scenarios — hallucinations in customer communications, agent actions that cause erroneous orders, vendor AI system failure — to confirm that escalation and response procedures work.
Ongoing:
- Review AI-related WSPs annually, or more frequently when AI systems are updated or new use cases are deployed.
- Track FINRA guidance and regulatory notices for developments in AI supervision. The 2026 Report is not the final word; it is the current guidance in a rapidly evolving area.
The Examination Risk
FINRA examination staff will be looking at AI specifically in 2026 examinations. Based on the 2026 Report’s framing, examination staff will likely ask for:
- The firm’s inventory of AI tools and use cases
- The relevant WSP sections addressing those tools
- Evidence of pre-deployment compliance review
- Prompt and output logs for AI tools used in regulated activities
- Documentation of human review of AI outputs in high-risk use cases
- Vendor contracts and due diligence records for third-party AI tools
Firms that can produce organized, complete responses to these requests will be in a materially better position than firms that are constructing their compliance documentation in response to an examination request.
This post is for general informational purposes only and does not constitute legal advice. Reading this post does not create an attorney-client relationship. If you have questions about your specific situation, consult a qualified attorney.
