FINRA’s 2026 Annual Regulatory Oversight Report says its rules and securities laws continue to apply when member firms use generative AI, just as they apply to other technologies. The report calls out supervisory systems, communications, recordkeeping and fair dealing as areas firms should assess before deploying these tools. FINRA 2026 Annual Regulatory Oversight Report: Generative AI

Follow the evidence

Trace how the event could reach markets, then inspect a competing explanation.

FINRA’s 2026 oversight report describes the use of generative AI at member firms and applicable existing rules.

Compare explanations

Switch lenses to see what each account explains—and what remains uncertain.

Main reading: AI adoption raises ordinary supervisory questions

FINRA’s report applies familiar obligations to new tools, including accuracy, records and firm-level oversight.

The regulator describes use cases and the rules firms still must meet

FINRA says its technology-neutral rules remain applicable when firms test or deploy generative AI. It notes that use may implicate supervision, customer communications, recordkeeping and fair dealing. Under Rule 3110, member firms need a supervisory system reasonably designed for their business. FINRA 2026 Annual Regulatory Oversight Report: Generative AI

The report says FINRA has seen firms focus on efficiency, internal processes and information retrieval. In FINRA’s observed portfolio, summarisation and information extraction was the most common use case: condensing large volumes of text or pulling entities and relationships from unstructured documents. FINRA 2026 Annual Regulatory Oversight Report: Generative AI

FINRA flags the possibility of inaccurate or misleading generated answers, bias, third-party cybersecurity risks and model changes over time. Its suggested practices include governance, testing, output logs, model-version records, guardrails for AI agents and human review where appropriate. These are supervisory considerations in the report, not a separate AI statute. FINRA 2026 Annual Regulatory Oversight Report: Generative AI

A useful control framework follows the output into the customer workflow

An AI-generated summary can affect a customer recommendation, compliance alert or internal decision even when a person enters the final action. Firms should map where outputs are used, who may rely on them, what source records are retained and how errors are escalated. That makes it easier to assess existing duties against the specific use case.

Testing only whether a tool responds quickly will miss whether it invents details, omits a material warning or changes behavior after a model update. Versioned prompts, access permissions and representative test cases can help compliance teams reproduce and review consequential outputs.

AI agents that can access accounts, market systems or customer data create a wider operational boundary than a drafting assistant. Least-privilege permissions, transaction limits, review steps and audit trails are practical ways to keep tool access aligned with the firm’s supervisory design. These are implementation examples, not a FINRA-endorsed product checklist.

Ask what the firm can reconstruct after an AI-assisted decision

Can the firm identify the model version, input data, user, output and reviewer for a material customer interaction? Are communications captured under the firm’s retention procedures? Can supervisors see when an answer was changed, rejected or used to trigger a later action? FINRA’s report makes reliability and recordkeeping central questions. FINRA 2026 Annual Regulatory Oversight Report: Generative AI

Review vendor arrangements as well as the model itself. A third-party tool can change, process sensitive data or depend on external services; the brokerage should know which controls it operates and which it relies on the vendor to provide.

The alternative is that a low-risk internal drafting tool has limited customer or market impact. Controls should therefore reflect the firm’s actual use and exposure. A documented assessment and periodic retesting are more informative than a broad claim that a brokerage is either 'AI-powered' or 'AI-safe'.