Guide · August 2026 edition
The Financial Services AI Compliance Guide.
SR 26-2 replaced SR 11-7 and left generative AI out of scope. FINRA 24-09 attached every existing obligation to it anyway. This guide maps what applies across the three surfaces where AI shows up in a firm (chat use, agents, and shadow AI), what examiners ask, and a 90-day path to evidence that answers. Free with a work email.
- Every claim linked inline to the regulator's own text: SR 26-2, the FINRA notices, NYDFS Part 500.
- Grounded examples on every surface, from an advisor's chat window to a KYC copilot.
- Opens right on this page; print or save as PDF once it's unlocked.
What's inside
Twelve chapters, one examiner's-eye view.
What applies, where it bites on each surface, and the order to build in.
The regulatory map
SR 26-2 and its OCC and FDIC companions, FINRA 24-09, NYDFS Part 500, and the records baseline, on one timeline with links to the primary texts.
The exposure, measured
IBM's 2026 breach study and banking-sector readiness surveys, charted, with sources named.
The three surfaces of AI
Chat use, agents, and shadow AI: what each one is, how the compliance profile differs, and a grounded example of each going wrong.
Prescriptive controls
For every surface, the control that answers: governed egress, tool allowlists, approval gates, coverage measurement.
What examiners ask
The five questions that open an AI line of inquiry, and the answers that hold up.
A 90-day path
Inventory, then policy and enforcement, then evidence that produces itself. Phase by phase.