FINRA and the SEC have not issued AI-specific rules for broker-dealers or registered investment advisers as of mid-2026. Instead, both regulators are applying existing supervision, recordkeeping, and fiduciary-duty rules to AI use, and FINRA's 2026 Annual Regulatory Oversight Report — for the first time — dedicates a standalone section to generative AI, with specific recommendations for AI agents that can act or transact on a firm's behalf. This post covers what that report says and what it implies for a firm running AI agents in production.

This is not legal advice. Broker-dealer and investment-adviser compliance obligations are fact-specific and firm-specific; work through the details with your compliance and legal counsel, not a blog post.

No new AI rule — existing obligations, applied to a new technology

The first thing to understand is what has not happened: neither FINRA nor the SEC has published a bespoke AI rulebook for broker-dealers as of early 2026. Instead, both regulators have signaled that existing rules already cover AI-driven activity, and firms are expected to demonstrate that their AI governance satisfies obligations that predate generative AI by decades: supervision of associated persons and their tools, accurate recordkeeping, communications review, suitability, best execution, and marketing-rule compliance.

That framing matters operationally. It means a firm cannot treat "we don't have an AI policy yet" as a gap that has no consequence today — the underlying obligations already apply, they are simply being tested against a system that behaves differently from the tools compliance teams are used to supervising.

FINRA's 2026 Regulatory Oversight Report: the first standalone GenAI section

FINRA's 2026 Annual Regulatory Oversight Report is the first edition to give generative AI its own standalone section, titled "Generative AI: Continuing and Emerging Trends." The report reflects what FINRA examiners are seeing across member firms as AI tools move from research assistance into workflows that touch client-facing activity.

The report's specific recommendations for AI agents capable of acting or transacting — not just summarizing or drafting — are the most actionable part for engineering and compliance teams building agentic systems:

  • Narrow scope and permissions. An agent should be authorized for the specific task it performs, not given broad standing access to accounts, order systems, or client data beyond what that task requires.
  • Audit trails of actions. Every action an agent takes needs to be logged in a way that supports post-hoc reconstruction — what the agent did, on whose behalf, and what data it used to decide.
  • Explicit human checkpoints before execution. For actions with client or market impact, a human review step before the agent executes is expected rather than optional, particularly for anything resembling a trade, recommendation, or account change.

These three points map closely to controls that agent-governance teams already build for other reasons — least-privilege scoping, tamper-evident logging, and human-in-the-loop approval gates — but the report gives compliance teams a specific regulatory hook to point to when justifying the engineering investment.

Written Supervisory Procedures need to name AI explicitly

Broker-dealers are required to maintain Written Supervisory Procedures (WSPs) describing how the firm supervises its business activities. The expectation emerging from FINRA's guidance and broker-dealer regulatory-priorities commentary is that WSPs now need to explicitly address three things: AI governance (who approves an AI tool for use, and under what conditions), AI vendor risk management (how the firm evaluates and monitors third-party AI providers and models), and AI-agent monitoring (how ongoing agent behavior is supervised, not just pre-deployment approval).

A generic technology-use policy that predates agentic AI is unlikely to satisfy this expectation. If your WSPs mention "software tools" in general terms but never name AI, agents, or model providers specifically, that is a gap worth closing before an examination raises it.

Recordkeeping and audit trails for agent activity

Broker-dealer recordkeeping obligations require firms to retain business communications and records of the activity underlying regulated decisions. AI agents complicate this in a specific way: a single client-facing action can be the output of a multi-step agent process — retrieving data, applying a policy, drafting a recommendation, and (if permitted) executing it — and the record needs to cover that whole chain, not just the final output shown to the client or representative.

Practically, this means the audit trail for an agent needs to capture: what triggered the agent's action, what data and tools it used, what the agent produced, whether and how a human reviewed or approved it, and when each step occurred. For the technical approach to building that kind of durable, defensible trail, see audit trails that hold up and human-in-the-loop approvals for high-risk agent actions.

Communications, marketing, and agent-generated content

Existing communications-review and marketing-rule obligations apply to content an AI agent produces the same way they apply to content a human representative produces. If an agent drafts client correspondence, market commentary, or anything that could be read as a recommendation or performance claim, that output falls inside the same review pipeline as any other business communication — it does not get a lighter-touch review because a model generated it.

This creates a specific operational question: does your firm's communications-surveillance tooling actually see AI-agent output, or does it only capture communications sent through channels a human explicitly routes through review? Agents that draft directly into a client-facing channel, or that can send without a human forwarding step, need to be wired into the same surveillance pipeline as any other outbound channel — otherwise the agent becomes a blind spot in a control that already exists for every other communication path.

The same logic applies to performance claims and disclosures embedded in agent output. An agent summarizing account performance or making a forward-looking statement is subject to the same accuracy and disclosure standards as a human-authored version of the same content, and firms are expected to be able to show how that output was reviewed before or immediately after it reached a client.

What examiners are likely to test first

Based on the specific language in FINRA's report, four questions are the most likely starting point in an examination of a firm's AI-agent program:

  • Can you show the agent's permission scope, and does it match what the agent is actually doing in production rather than a broader grant that was never narrowed after initial rollout?
  • Can you reconstruct a specific agent action — what triggered it, what data it used, what it produced, who approved it — on demand, for an action from several months prior?
  • Do your WSPs name AI specifically, or do they rely on general technology-use language that predates agentic tools?
  • Is there a human checkpoint you can point to for any action with client or market impact, and is that checkpoint enforced technically rather than relying on a policy document that assumes staff will follow it?

Firms that can answer all four with evidence, not intent, are in a materially stronger position than firms that have a policy describing what should happen but no record of what actually did.

A practical checklist for firms deploying agents

  1. Inventory every AI agent touching client-facing or transactional workflows, and classify which ones can only inform a human versus which ones can act autonomously.
  2. Scope agent permissions to the specific task, not the broadest access convenient for development — this is FINRA's narrow-scope recommendation applied directly.
  3. Insert a human checkpoint before any execution step with client or market impact, and make that checkpoint auditable, not just a UI convention.
  4. Update WSPs to name AI governance, AI vendor risk management, and AI-agent monitoring explicitly.
  5. Build the audit trail before the agent goes live, not after an examiner asks for one — retrofitting logging into a production agent workflow is materially harder than instrumenting it from the start.
  6. Treat model and platform vendors as part of the supervised chain, evaluating their own controls the way you would any other technology vendor whose failures become your compliance failures.

How this fits the broader financial-services picture

FINRA and SEC expectations are the US securities-industry layer of a broader compliance surface that financial firms running AI agents now navigate. EU-domiciled or EU-serving firms face a parallel regime under DORA for AI vendors treated as ICT third parties — see DORA and AI vendors: when your ICT third-party risk regime applies — and US firms operating across multiple states may also face the state AI laws compared in US state AI laws compared: SB 53, RAISE, TRAIGA, Colorado. None of these regimes replace the others; a firm operating in the EU, several US states, and under FINRA/SEC jurisdiction is layering all of them. The broader governance foundation these obligations sit on top of is covered in AI agent governance for financial services and the AI governance pillar guide.

Praesidia is an AI agent security and governance control plane — agent identity and access, guardrails, audit evidence, and cost controls in one place — and the kind of scoped permissions, human-approval gates, and tamper-evident logs FINRA's report recommends are the category of control it is built to provide, regardless of which specific regulatory regime a firm is answering to.

Common questions

Is there a FINRA rule specifically for AI agents? No. As of mid-2026, FINRA has not issued a standalone AI-agent rule. It applies existing supervision, recordkeeping, and communications rules to AI-driven activity, and its 2026 Annual Regulatory Oversight Report sets out expectations — narrow permissions, audit trails, human checkpoints — as guidance rather than binding rule text. Treat the report as a strong signal of examination priorities, not a new rulebook.

Does an AI agent's recommendation still need to meet suitability requirements? Yes. Suitability, best-execution, and fiduciary-duty obligations attach to the recommendation or action itself, not to the method that produced it. An agent generating a recommendation does not create an exception to these duties — if anything, firms are expected to demonstrate they can supervise the agent's output at least as well as a human representative's.

Do RIAs face the same expectations as broker-dealers? The specific report cited here is a FINRA publication, which is directly binding guidance for FINRA member firms (broker-dealers). Registered investment advisers fall under SEC oversight, which has signaled the same general approach — applying existing fiduciary and recordkeeping rules to AI use — without a parallel standalone AI section published to date. RIAs should not assume this means less scrutiny; confirm current expectations with counsel familiar with SEC examination priorities.

What is the single most examination-relevant control to have in place? Based on the report's specific language, an audit trail sufficient to reconstruct an agent's actions after the fact is the most consistently cited expectation, because it is the evidence examiners and internal supervisors both need regardless of which specific rule is being tested against.

How does this interact with EU regulation if our firm operates in both markets? The US securities-regulator expectations described here and EU regimes like DORA operate independently and do not substitute for one another. A firm subject to both needs governance controls — audit trails, human oversight, vendor risk management — broad enough to satisfy each regime's specific documentation requirements, even where the underlying control (a logged, human-reviewed agent action) is the same.