Reference · Securities
FINRA 2026 Oversight Report: GenAI and AI Agent Expectations
What the report's GenAI section says about supervision, monitoring and AI agents
FINRA published the 2026 FINRA Annual Regulatory Oversight Report on 9 December 2025. It adds a topic dedicated to generative AI, titled "GenAI: Continuing and Emerging Trends" and marked new for 2026, with a subsection on AI agents.
The report sets no new obligations. In FINRA's words, it "does not create any new legal or regulatory requirements or new interpretations of existing requirements," and readers "should not infer that FINRA requires firms to implement any specific practices described in this Report that extend beyond the requirements of existing federal securities provisions or FINRA rules." What it offers is FINRA's view of how existing obligations meet generative AI, and the practices it has seen firms adopt.
What the GenAI section says
The section has four parts: regulatory obligations, how FINRA member firms use GenAI, emerging trends and current practices, and emerging trends in GenAI agents. It closes with a list of resources, including Regulatory Notice 24-09.
On obligations, FINRA restates the position of Notice 24-09. Its rules "are intended to be technologically neutral" and "continue to apply when firms use GenAI or similar technologies in the course of their businesses." The report names the areas GenAI can implicate: "rules regarding supervision, communications, recordkeeping and fair dealing." The one rule it cites by number is FINRA Rule 3110 (Supervision), under which "a member firm must have a reasonably designed supervisory system tailored to its business." It adds that where a firm relies on GenAI tools as part of its supervisory system, "its policies and procedures may consider the integrity, reliability and accuracy of the AI model."
On use, FINRA reports that firms have started with efficiency gains in internal processes and information retrieval, and that the top use case among member firms is "Summarization and Information Extraction."
Who it applies to
FINRA member firms. The section draws no line between a tool a firm builds and one a vendor supplies: its cybersecurity consideration covers "the firm's and its third-party vendors' use of GenAI," and its resources include Regulatory Notice 21-29 on supervising outsourced functions. The report also notes that some content "may not be relevant to individual firms based on their business models, size or practices."
The practices FINRA describes
The GenAI section presents its practices as considerations for "firms contemplating using GenAI tools and technologies." They fall under four headings:
- General. Supervisory processes to develop and use GenAI "at an enterprise level"; approaches to identify and mitigate accuracy risk (hallucinations) and bias; and a cybersecurity program that covers GenAI risk at the firm and its vendors.
- Supervision and governance. Implementing "formal review and approval processes" that include both business and technology experts, within a supervision, governance or model risk management framework that maintains "comprehensive documentation throughout."
- Testing. Testing that establishes "the capabilities, limitations and performance of the model," covering areas such as privacy, integrity, reliability and accuracy.
- Monitoring. "Ongoing monitoring of prompts, responses and outputs," which "may include storing prompt and output logs for accountability and troubleshooting; tracking which model version was used and when; and validation and human-in-the-loop review of model outputs, including performing regular checks for errors or bias."
AI agents
FINRA describes AI agents as "systems or programs that are capable of autonomously performing and completing tasks on behalf of a user," able to "plan, make decisions and take action to achieve specific goals without predefined rules or logic programming." It lists the risks agents carry:
Flow
Where FINRA's agent considerations sit on a single agent action
- StartAgent picks an actionA tool call, a record update, a message
- ConsiderationAccessWhich systems and data can this agent reach?
- ConsiderationGuardrailsIs the action within the limits set for this agent?
- ConsiderationHuman in the loopDoes a person approve this before it runs?
- OutcomeAction runs or is stoppedEither way, the firm has something to supervise
- ConsiderationTrackingThe action and the decision behind it are recorded
- Autonomy: "AI agents acting autonomously without human validation and approval."
- Scope and authority: "Agents may act beyond the user's actual or intended scope and authority."
- Auditability and transparency: "Complicated, multi-step agent reasoning tasks can make outcomes difficult to trace or explain, complicating auditability."
- Data sensitivity: agents "may unintentionally store, explore, disclose or misuse sensitive or proprietary information."
- Domain knowledge: general-purpose agents "may lack the necessary domain knowledge" for complex, industry-specific tasks.
- Rewards and reinforcement: "Misaligned or poorly designed reward functions" could lead an agent to optimize decisions that harm investors, firms or markets.
- The GenAI risks of bias, hallucination and privacy "also remain present and applicable for GenAI agents and their outputs."
What to expect in an examination
The report does not list examination requests, and it states that it is not a complete inventory of the topics FINRA will examine. Its practices translate directly into the document requests a firm using GenAI should be ready to answer:
- Which GenAI tools and use cases are approved, who approved them, and where the approval is recorded.
- The written supervisory procedures that cover each approved use, including any GenAI the supervisory system itself relies on.
- Test results for each model in use, and the version each result applies to.
- Retained prompts and outputs for a given interaction, with the model version and timestamp.
- Records of human review: who reviewed which outputs, when, and with what result.
- For each agent: the systems and data it can reach, the actions it took, the points where a person approved an action, and the limits it runs under.
Evidence you need
Rule 3110 and the existing communications and recordkeeping rules are the obligations. The practices above are FINRA's account of how firms meet them. The evidence below shows the supervisory system operating on GenAI day to day. Retention periods come from the underlying books and records rules, which apply to AI-generated records as to any other.
Control mapping
What a reviewer expects to be able to see.
| Obligation | What the system must do | Evidence a reviewer expects |
|---|---|---|
| Supervision (Rule 3110) | Bring GenAI use, including GenAI inside the supervisory system, under reasonably designed procedures | WSPs naming approved GenAI tools, their permitted uses, and review procedures |
| Enterprise governance | Review and approve GenAI use cases formally, with business and technology experts | Approval records per use case: reviewers, controls required, and approval date |
| Testing | Test the capabilities, limitations and performance of each model in use | Test plans and results tied to a specific model and version |
| Ongoing monitoring | Monitor prompts, responses and outputs, and track which model version was used and when | Retained prompt and output logs carrying model version and timestamp |
| Human review | Validate outputs with human-in-the-loop review and regular checks for errors or bias | Review records attributable to a named reviewer, with outcome and date |
| Agent access and data handling | Monitor which systems and data each agent can reach | Per-agent inventory of tools, systems and data, with access records |
| Agent actions and guardrails | Track agent actions and decisions, and limit what agents may do | A record of each action (tool, parameters, outcome, time) and of each blocked or approved action |
| Communications and recordkeeping | Retain AI-generated communications and records under existing rules | Retained records, retrievable within required timeframes |
Key dates
- 27 June 2024Regulatory Notice 24-09 issued.
- 9 December 20252026 FINRA Annual Regulatory Oversight Report published, with a new GenAI topic and a subsection on AI agents.
Primary sources
Common gaps
Where a firm's GenAI program usually falls short of the practices the report describes.
- No enterprise-level view. GenAI adopted team by team, each with its own tools and procedures, leaves the firm without the enterprise-level supervisory process the report lists first.
- Approvals with no record. A use case approved in a meeting, with no record of who assessed it or which controls were required, cannot be shown to an examiner.
- Logs that cannot name the model. Prompt and output logs without the model version and timestamp leave the firm unable to say which model produced a given output.
- Testing once, at launch. The report pairs testing with ongoing monitoring. A model that changes version after approval needs both.
- Human review on paper. A procedure that places a person in the loop needs review records attributable to that person. A review that leaves no record is hard to evidence.
- Agents supervised as chat assistants. An agent that calls tools and changes records needs a record of its actions and the limits it ran under. A transcript of its text covers only part of what it did.
In practice
Related
Last reviewed September 29, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.