FINRA & SEC AI Compliance 2026: The Rules That Already Apply to Your AI
There is no separate AI rulebook for securities firms, and that is the difficulty rather than the relief. Supervision, books and records, Reg BI, communications standards and adviser disclosure were all written to be technology-neutral — so they attached to your AI tools the day you turned them on.
The Waiting Problem
A pattern repeats across compliance departments at broker-dealers and registered investment advisers. The firm adopts AI tooling — meeting summarization, client chat, marketing drafts, research assistance, surveillance triage, portfolio commentary — and treats the compliance question as pending because no regulator has issued a rule with "artificial intelligence" in the title. Meanwhile the tools are generating communications, creating records and shaping what clients are told.
Securities regulation does not work that way. Its obligations attach to activities: supervising the business, preserving records, communicating with the public, making recommendations, describing your process to clients. Nothing in those obligations is conditioned on a human performing the activity. When a model participates, the rule still governs the outcome, and the firm still owns it.
That produces a specific and avoidable failure: a firm that has thought carefully about model accuracy but has no supervisory procedure covering the tool, no archive path for what it generates, and no record of who reviewed its output before it reached a client.
Five Existing Obligations That Reach AI Output
Supervision and written procedures
A firm must have supervisory systems reasonably designed to achieve compliance across its business. Once a tool participates in that business, the system has to cover it: who approved deployment, what testing was done, how output is reviewed, and what happens when the tool behaves unexpectedly.
Why it bites: This is the most frequent examination finding pattern in new-technology cycles, because it does not require the regulator to prove the tool caused harm. The absence of a reasonably designed procedure is itself the deficiency, and it is provable from your own document set in an afternoon.
Books and records
Business communications and required records must be preserved in the prescribed manner and produced on request. AI chat interfaces, generated client emails, meeting summaries that inform advice, and prompt or output logs that evidence a recommendation are all candidates.
Why it bites: The gap is architectural rather than intentional. Vendor systems have their own retention windows, often short, and no default route into the firm's archive. A production request months later is when firms learn that the underlying conversations no longer exist in a preservable form.
Communications with the public
Content standards for retail communications — fair and balanced, no misleading claims, no unwarranted projections, required disclosures — apply to AI-drafted material identically. Principal review and approval requirements do not relax because a model produced the first draft.
Why it bites: Volume is the risk multiplier. Generative tools make it trivial to produce far more client-facing material than the review process was staffed for, and the failure appears as a review backlog or a silently skipped approval step rather than as a single bad piece.
Recommendation and care obligations
Where a tool surfaces, ranks or filters what a retail client is offered, the associated care, disclosure and conflict obligations attach to that outcome and remain with the firm and the associated person.
Why it bites: Model objectives can encode conflicts that no one wrote down. If a ranking function correlates with firm economics, that is a conflict embedded in software — identifiable, disclosable and mitigable, but only if someone has actually examined the output distribution.
Adviser disclosure and marketing
An adviser's description of its methods of analysis must be accurate, and marketing must not be misleading. Claims about AI capability in brochures, websites, pitch decks and RFP responses are subject to the same standard as performance claims.
Why it bites: This is where AI washing lands. The claim lives in a filed or distributed document, the reality lives in an engineering repository, and the comparison is straightforward for anyone who asks for both.
AI Washing: Why It Is the First Thing Enforced
Overstating AI capability has become the leading enforcement theme in this area, and the reason is structural rather than ideological. A regulator pursuing a model-quality theory has to prove something contestable about how a system performs. A regulator pursuing a misrepresentation theory only has to place the firm's marketing language next to its internal reality. The second case is faster, cleaner and far harder to defend.
The fact patterns are consistent across cases and internal reviews:
- Capability inflation. A deterministic screen, a spreadsheet model or a vendor's off-the-shelf feature described as proprietary artificial intelligence developed in-house.
- Scope inflation. A tool used in reporting or idea generation described as driving portfolio decisions, or a pilot in one strategy described as firmwide.
- Borrowed performance. Results attributable to a period, strategy or third party that the described model did not actually produce.
- Data-advantage claims. Assertions of unique or alternative data inputs that the firm does not license, ingest or use.
- Stale claims. Language that was accurate when written, kept in circulation after the pilot ended or the vendor contract lapsed.
The remedy is unglamorous and effective: build a claims register. Every external statement about AI capability gets a row, an owner, and a pointer to the internal artifact that substantiates it. Anything without substantiation gets edited before anyone external asks the question. Re-verify the register whenever the tooling changes, not annually.
The Supervisory Checklist for AI Tools
Scale each item to whether the tool touches recommendations, client communications or firm records. A meeting-notes summarizer used only internally and a chat interface answering client questions are not the same risk tier.
- ☐List every AI tool in use, including ones adopted on a corporate card without procurement
- ☐Assign a named business owner and a compliance reviewer to each tool
- ☐Assign a risk tier based on whether output reaches clients, records or recommendations
- ☐Record the approval decision and the evidence it relied on
- ☐Set a review trigger on model version change, not only on the annual cycle
- ☐Map every output type the tool creates to a retention determination
- ☐Confirm chatbot transcripts route to the firm archive, not just the vendor's storage
- ☐Verify the archive format satisfies your preservation and production requirements
- ☐Confirm the vendor's retention window is not shorter than your obligation
- ☐Test an end-to-end production of AI-generated records before you are asked for one
- ☐Document pre-deployment output sampling reviewed by a qualified person
- ☐Define the ongoing supervisory review method and sampling rate
- ☐Require principal review of AI-drafted retail communications before distribution
- ☐Check ranked or filtered output for correlation with firm economics
- ☐Define escalation criteria and an owner for anomalous or unexplained output
- ☐Maintain a claims register with substantiation for every external AI statement
- ☐Reconcile ADV language, website copy, pitch decks and RFP answers against each other
- ☐Describe limitations, not only capabilities, where AI informs advice
- ☐Remove claims tied to ended pilots or lapsed vendor relationships
- ☐Re-verify all of the above when the underlying tooling changes
Where Client-Facing Technology Adds a Second Obligation
Financial firms carry an accessibility exposure alongside the securities one, and AI interfaces have a habit of concentrating both. A chat widget bolted onto a client portal is simultaneously a communication subject to content standards, a record subject to retention, and an interface subject to accessibility expectations that apply to financial services websites. Firms in this sector are among the most frequently targeted in website accessibility claims, and a newly deployed AI widget is exactly the kind of component that ships without keyboard operability, without announced status updates, and without a non-visual path through the conversation. Reviewing the widget once, at deployment, closes a gap that is otherwise found by someone else.
Frequently Asked Questions
Is there a FINRA or SEC rule specifically about artificial intelligence?
Not as a standalone rulebook, and firms waiting for one are accumulating exposure meanwhile. Both regulators have taken the position that existing obligations are technology-neutral: if a tool participates in supervision, recommendation, communication, recordkeeping or advertising, the rules governing that activity apply to its output as they would to a person's. Supervisory procedures must reasonably cover the tool, communications it generates are communications, records it creates are records, and any recommendation it influences remains subject to the applicable care obligation. The absence of AI-specific text is not a grace period — it routes the analysis through rules written before the technology, which usually produces broader coverage rather than narrower.
What is AI washing and why is it an enforcement priority?
It is overstating the role, sophistication or performance of AI in a firm's process or operations, and it leads enforcement because it is an ordinary misrepresentation claim with unusually clean proof. A regulator does not need to litigate whether a model is good — only to compare the marketing claim against internal reality, which is a documentary exercise. Recurring patterns: a rules-based screen described as proprietary AI, a reporting tool described as driving decisions, performance quoted for a model the firm never ran, and a claimed data advantage the firm does not license. Every external claim should trace to something a person inside the firm can demonstrate on request.
Do AI chatbot conversations with clients have to be retained?
Treat them as retainable business communications until specific advice says otherwise. Recordkeeping obligations attach to business-related communications with the public regardless of channel or author, and a chatbot conversation about products, accounts or service is squarely business-related. The failures here are technical rather than legal: transcripts live in a vendor system with its own short retention period, they never route to the firm archive, they are not indexed for supervisory review, and they may not be producible in a compliant format. Solve it before deployment — retrofitting an archive path after a request arrives is when firms discover that months of client conversations existed only in a rolling buffer.
Can an AI tool make or influence a recommendation under Reg BI?
It can participate, and the obligation stays with the firm and the associated person. Reg BI applies to recommendations of securities transactions or strategies to retail customers, and the analysis does not turn on whether a human or a model generated the idea. If a tool surfaces, ranks, filters or prioritizes what a client is offered, the care, disclosure, conflict and compliance obligations attach to that outcome. The conflict component deserves specific attention: a model tuned toward products with better firm economics is a conflict embedded in software and must be identified, disclosed and mitigated like any other. Ask what the model optimizes for, and test the output distribution for economic skew before someone else does.
What should a firm's AI supervisory procedure actually contain?
At minimum: an inventory of AI tools with a named business owner for each; a risk tier reflecting whether the tool touches recommendations, client communications or records; documented pre-deployment testing including output sampled by a qualified reviewer; the supervisory review method and sampling rate once live; escalation criteria for anomalous output; retention and archival mapping for everything it generates; vendor terms covering data use, model-change notice and record production; and a review cadence tied to model version changes. That last trigger is the one most procedures omit, and it is why previously approved tools drift out of the state in which they were reviewed.
Do we need to disclose AI use in Form ADV?
If AI is a meaningful part of how you formulate advice, select securities, manage risk or set allocations, clients need an accurate description of it, and that generally belongs alongside your methods of analysis. Two failure modes matter equally. Under-disclosure leaves clients unaware of a material element of the process and its limits. Over-disclosure — describing a capability broader than what the firm operates — puts the AI-washing exposure inside a filed document, which is the worst place to keep it. Write the disclosure from what the firm does today, revisit it when the tooling changes, and make sure the ADV, the website and what advisers say in meetings describe the same process.
Does using a well-known vendor reduce our supervisory obligation?
It reduces execution risk and changes nothing about who is responsible. The firm remains the supervisor of its own business, the custodian of its own records, and the party making representations to its clients. What a mature vendor gives you is better documentation, clearer data terms, more reliable change notices and a counterparty who can answer questions during an examination — all genuinely valuable, and all inputs to your procedure rather than substitutes for it. The specific thing to negotiate for is contractual: notice of material model changes, retention terms that meet or exceed your own obligation, and the vendor's commitment to produce records in a usable format on your timeline.
Start With the Inventory, Not the Policy
Most firms cannot write a defensible AI supervisory procedure because they do not yet know the full list of tools it needs to cover. Pull expense data and SSO logs, list every AI tool actually in use, and sort by whether its output reaches a client, a record or a recommendation. The policy follows the list.
Then run the two checks that produce findings fastest: does every client-facing AI interface route its transcripts into your archive, and does every external AI claim trace to something you can demonstrate.