Design Partner ProgramWe're accepting applications for the next cohort of design partners in finance, insurance, healthcare, and HR. Apply now →

meilynx

Reference · Securities

FINRA 2026 Oversight Report: GenAI and AI Agent Expectations

What the report's GenAI section says about supervision, monitoring and AI agents

Last reviewed September 29, 2026

FINRA published the 2026 FINRA Annual Regulatory Oversight Report on 9 December 2025. It adds a topic dedicated to generative AI, titled "GenAI: Continuing and Emerging Trends" and marked new for 2026, with a subsection on AI agents.

The report sets no new obligations. In FINRA's words, it "does not create any new legal or regulatory requirements or new interpretations of existing requirements," and readers "should not infer that FINRA requires firms to implement any specific practices described in this Report that extend beyond the requirements of existing federal securities provisions or FINRA rules." What it offers is FINRA's view of how existing obligations meet generative AI, and the practices it has seen firms adopt.

What the GenAI section says

The section has four parts: regulatory obligations, how FINRA member firms use GenAI, emerging trends and current practices, and emerging trends in GenAI agents. It closes with a list of resources, including Regulatory Notice 24-09.

On obligations, FINRA restates the position of Notice 24-09. Its rules "are intended to be technologically neutral" and "continue to apply when firms use GenAI or similar technologies in the course of their businesses." The report names the areas GenAI can implicate: "rules regarding supervision, communications, recordkeeping and fair dealing." The one rule it cites by number is FINRA Rule 3110 (Supervision), under which "a member firm must have a reasonably designed supervisory system tailored to its business." It adds that where a firm relies on GenAI tools as part of its supervisory system, "its policies and procedures may consider the integrity, reliability and accuracy of the AI model."

On use, FINRA reports that firms have started with efficiency gains in internal processes and information retrieval, and that the top use case among member firms is "Summarization and Information Extraction."

Who it applies to

FINRA member firms. The section draws no line between a tool a firm builds and one a vendor supplies: its cybersecurity consideration covers "the firm's and its third-party vendors' use of GenAI," and its resources include Regulatory Notice 21-29 on supervising outsourced functions. The report also notes that some content "may not be relevant to individual firms based on their business models, size or practices."

The practices FINRA describes

The GenAI section presents its practices as considerations for "firms contemplating using GenAI tools and technologies." They fall under four headings:

  • General. Supervisory processes to develop and use GenAI "at an enterprise level"; approaches to identify and mitigate accuracy risk (hallucinations) and bias; and a cybersecurity program that covers GenAI risk at the firm and its vendors.
  • Supervision and governance. Implementing "formal review and approval processes" that include both business and technology experts, within a supervision, governance or model risk management framework that maintains "comprehensive documentation throughout."
  • Testing. Testing that establishes "the capabilities, limitations and performance of the model," covering areas such as privacy, integrity, reliability and accuracy.
  • Monitoring. "Ongoing monitoring of prompts, responses and outputs," which "may include storing prompt and output logs for accountability and troubleshooting; tracking which model version was used and when; and validation and human-in-the-loop review of model outputs, including performing regular checks for errors or bias."

AI agents

FINRA describes AI agents as "systems or programs that are capable of autonomously performing and completing tasks on behalf of a user," able to "plan, make decisions and take action to achieve specific goals without predefined rules or logic programming." It lists the risks agents carry:

Flow

Where FINRA's agent considerations sit on a single agent action

  1. StartAgent picks an actionA tool call, a record update, a message
  2. ConsiderationAccessWhich systems and data can this agent reach?
  3. ConsiderationGuardrailsIs the action within the limits set for this agent?
  4. ConsiderationHuman in the loopDoes a person approve this before it runs?
  5. OutcomeAction runs or is stoppedEither way, the firm has something to supervise
  6. ConsiderationTrackingThe action and the decision behind it are recorded
The four considerations are from the AI agents subsection of the 2026 FINRA Annual Regulatory Oversight Report. The report lists them without an order; placing them along one action is ours.
  • Autonomy: "AI agents acting autonomously without human validation and approval."
  • Scope and authority: "Agents may act beyond the user's actual or intended scope and authority."
  • Auditability and transparency: "Complicated, multi-step agent reasoning tasks can make outcomes difficult to trace or explain, complicating auditability."
  • Data sensitivity: agents "may unintentionally store, explore, disclose or misuse sensitive or proprietary information."
  • Domain knowledge: general-purpose agents "may lack the necessary domain knowledge" for complex, industry-specific tasks.
  • Rewards and reinforcement: "Misaligned or poorly designed reward functions" could lead an agent to optimize decisions that harm investors, firms or markets.
  • The GenAI risks of bias, hallucination and privacy "also remain present and applicable for GenAI agents and their outputs."
FINRA suggests agents "may call for supervisory processes that are specific to the type and scope of the AI agent being implemented." Its considerations: how to monitor agent system access and data handling; where to place "human in the loop" oversight; how to track agent actions and decisions; and how to establish guardrails or control mechanisms that limit agent behaviors, actions or decisions.

What to expect in an examination

The report does not list examination requests, and it states that it is not a complete inventory of the topics FINRA will examine. Its practices translate directly into the document requests a firm using GenAI should be ready to answer:

  • Which GenAI tools and use cases are approved, who approved them, and where the approval is recorded.
  • The written supervisory procedures that cover each approved use, including any GenAI the supervisory system itself relies on.
  • Test results for each model in use, and the version each result applies to.
  • Retained prompts and outputs for a given interaction, with the model version and timestamp.
  • Records of human review: who reviewed which outputs, when, and with what result.
  • For each agent: the systems and data it can reach, the actions it took, the points where a person approved an action, and the limits it runs under.

Evidence you need

Rule 3110 and the existing communications and recordkeeping rules are the obligations. The practices above are FINRA's account of how firms meet them. The evidence below shows the supervisory system operating on GenAI day to day. Retention periods come from the underlying books and records rules, which apply to AI-generated records as to any other.

Control mapping

What a reviewer expects to be able to see.

ObligationWhat the system must doEvidence a reviewer expects
Supervision (Rule 3110)Bring GenAI use, including GenAI inside the supervisory system, under reasonably designed proceduresWSPs naming approved GenAI tools, their permitted uses, and review procedures
Enterprise governanceReview and approve GenAI use cases formally, with business and technology expertsApproval records per use case: reviewers, controls required, and approval date
TestingTest the capabilities, limitations and performance of each model in useTest plans and results tied to a specific model and version
Ongoing monitoringMonitor prompts, responses and outputs, and track which model version was used and whenRetained prompt and output logs carrying model version and timestamp
Human reviewValidate outputs with human-in-the-loop review and regular checks for errors or biasReview records attributable to a named reviewer, with outcome and date
Agent access and data handlingMonitor which systems and data each agent can reachPer-agent inventory of tools, systems and data, with access records
Agent actions and guardrailsTrack agent actions and decisions, and limit what agents may doA record of each action (tool, parameters, outcome, time) and of each blocked or approved action
Communications and recordkeepingRetain AI-generated communications and records under existing rulesRetained records, retrievable within required timeframes

Key dates

  • 27 June 2024Regulatory Notice 24-09 issued.
  • 9 December 20252026 FINRA Annual Regulatory Oversight Report published, with a new GenAI topic and a subsection on AI agents.

Primary sources

Common gaps

Where a firm's GenAI program usually falls short of the practices the report describes.

  • No enterprise-level view. GenAI adopted team by team, each with its own tools and procedures, leaves the firm without the enterprise-level supervisory process the report lists first.
  • Approvals with no record. A use case approved in a meeting, with no record of who assessed it or which controls were required, cannot be shown to an examiner.
  • Logs that cannot name the model. Prompt and output logs without the model version and timestamp leave the firm unable to say which model produced a given output.
  • Testing once, at launch. The report pairs testing with ongoing monitoring. A model that changes version after approval needs both.
  • Human review on paper. A procedure that places a person in the loop needs review records attributable to that person. A review that leaves no record is hard to evidence.
  • Agents supervised as chat assistants. An agent that calls tools and changes records needs a record of its actions and the limits it ran under. A transcript of its text covers only part of what it did.

Last reviewed September 29, 2026. This reference summarises publicly available regulatory guidance and is provided for general information. It is not legal advice. Obligations depend on an institution's charter, registration status, size, and activities. Verify against the primary sources cited above and consult counsel before relying on any summary here.

Regulatory updates

When a regulator changes what an AI examination asks for, hear about it first.

Short notes on SR 26-2, NYDFS 500, FINRA, the NAIC bulletin, the EU AI Act, and the employment-AI statutes, plus what we ship. A few emails a month.