There is no AI-specific rule, and nothing new can realistically bind before 2029. What the SEC and FINRA actually expect in 2026, and the documents your firm should be able to produce today.
An examiner arrives. They do not open with a question about artificial intelligence, because there is no AI rule for them to examine you against.
They ask about your compliance program, your books and records, your marketing, your cybersecurity and your vendors. Then, inside each of those, they ask how AI fits.
That is the whole shape of it, and it is better news than most firms expect. You are not being measured against a new framework you have not read. You are being measured against rules you have complied with for years, applied to a technology your staff started using eighteen months ago without telling you.
The primary documents, quoted, with nothing added.
On 12 June 2025 the SEC withdrew fourteen notices of proposed rulemaking issued between March 2022 and November 2023, effective 17 June 2025. The withdrawal states plainly: "The Commission does not intend to issue final rules with respect to these proposals."
Four of the fourteen matter here.
Conflicts of Interest Associated with Predictive Data Analytics was the closest thing to an AI rule the SEC ever proposed for advisers and broker-dealers. It covered "covered technology," a term that expressly included artificial intelligence and machine learning. It is gone. Outsourcing by Investment Advisers is gone. Both proposed cybersecurity risk management rules, one for advisers and funds and one for broker-dealers, are gone.
Note also that three of those four are cybersecurity and outsourcing rather than AI. There is no cybersecurity rule and no outsourcing rule for advisers either.
So the framework a firm will be examined against in 2026 is the framework that already existed. That is not a gap. It is the answer to the question most compliance officers are actually asking, which is what they are supposed to be complying with.
Rule 206(4)-7 does most of the work. It requires written policies and procedures reasonably designed to prevent violations, and a review "no less frequently than annually" of both their adequacy and the effectiveness of their implementation. Nothing in it mentions technology, which is exactly why it applies to all of it.
One thing the withdrawal notice does not say is that the subject is closed. The full sentence is worth reading:
The Commission does not intend to issue final rules with respect to these proposals. If the Commission decides to pursue future regulatory action in any of these areas, it will issue a new proposed rule. SEC, Withdrawal of Proposed Regulatory Actions, 17 June 2025
This is the first question a well-read compliance officer asks, and it deserves a direct answer.
The Cyber Risk Institute published the Financial Services AI Risk Management Framework on 12 February 2026, developed with the Financial Services Sector Coordinating Council and more than 100 financial institutions. Treasury announced it a week later, on 19 February, through the joint FBIIC and FSSCC AI Executive Oversight Group. It contains 230 control objectives, structured on the NIST AI Risk Management Framework's four functions of Govern, Map, Measure and Manage.
It is voluntary, and no US regulator has cited it. We looked specifically. The SEC Chairman gave his first dedicated AI remarks at an FSOC roundtable on 4 March 2026, two weeks after the framework launched, and did not mention it. FINRA's 2026 report cites the NIST AI RMF in its resources, not this. No OCC, Federal Reserve or FDIC guidance references it. A firm cannot be examined against it today, and anyone telling you otherwise is selling something.
So the honest description is that it is soft law. It creates no legal obligation, and it is the most useful thing available to align to.
The framework includes an AI Adoption Stage Questionnaire that places a firm in one of four stages: Initial, Minimal, Evolving or Embedded.
These are commonly described as maturity levels to climb, and that is a misreading worth correcting. They are scoping tiers. The stage reflects how deep your AI footprint is, and it determines how many of the 230 control objectives apply to you.
For a mid-size adviser or broker-dealer this is the framework's most useful feature and the reason to look at it rather than at NIST alone. A firm at the Initial stage is being asked to think about 21 control objectives, not 230. CRI publishes a Quick Start Guide covering the Initial stage only, alongside the questionnaire, the Risk and Control Matrix, the Guidebook and the Control Objective Reference Guide. All of them are free, and all require a short registration. Compare that with the usual experience of picking up a bank-scale framework and abandoning it in week two.
Where it matters is Rule 206(4)-7's standard, which is policies and procedures "reasonably designed." What counts as reasonable is shaped by what the industry does. As an industry framework built with a hundred institutions and announced by Treasury gains adoption, it becomes part of the answer to what a reasonable firm would have done. That happens without the SEC writing anything.
"We have an AI policy" is a weak answer. "We align to the NIST AI Risk Management Framework, we have completed the FS AI RMF adoption stage questionnaire and assessed ourselves at the Minimal stage, and here is our control mapping and the gaps we are working" is a strong one. Neither is required. The second one describes a firm that has thought about it.
The second fair question. A reader who has watched regulation swing before is right to ask whether any of this survives an election, and a paper that ducked it would deserve to be ignored.
Three things are worth separating: what can change quickly, what cannot change at all, and what the historical record actually shows.
The midterm elections are on 3 November 2026. All 435 House seats and 35 Senate seats are contested. On the current arithmetic Democrats need a net gain of three in the House and four in the Senate.
A flip of either chamber would change very little about AI rulemaking for financial services before 2029. Congress cannot legislate a new rule without the presidency. The Congressional Review Act runs the wrong way for this purpose, because it is a tool for disapproving finalised rules and it still requires the President's signature. What a Senate flip would realistically do is slow confirmations, which produces a smaller and slower Commission rather than a more active one.
The Commission is already thin. There are three sitting commissioners and two vacant seats with no nominations pending. Commissioner Peirce, whose term expired in June 2025 and who has been serving in holdover, has said she will leave in November 2026. That takes the Commission to two, where the Rule of Two applies and both members must agree for the body to act. That is not a Commission positioned to originate contested new rulemaking.
One thing did change, and it runs against the comfortable reading. On 29 June 2026 the Supreme Court decided Trump v. Slaughter six to three, holding that the FTC's for-cause removal protection is contrary to the separation of powers and overruling Humphrey's Executor. The opinion does not name the SEC, and it expressly reserved the Federal Reserve on the basis of its distinct historical tradition. The SEC's independence rested on the same foundation the Court removed. The practical consequence is that the lag between an election and a change in Commission posture is shorter than it used to be, not longer.
You do not have to speculate about whether a withdrawn proposal can come back, because one of the rules in Figure 1 is the example.
The SEC proposed amendments to Regulation S-P in 2008, to require incident response programmes and customer notification. They were not adopted. The subject sat for fifteen years. The Commission re-proposed in 2023, adopted in May 2024, and compliance became mandatory in December 2025 for larger entities and June 2026 for smaller ones. Sixteen years from a shelved proposal to a binding obligation that firms are now examined against.
The firms that had built incident response capability during those fifteen years absorbed the rule as a documentation exercise. The firms that read the 2008 withdrawal as an absence of obligation had eighteen months from adoption to compliance, from a standing start.
There is a second lesson in the same rule, and it is about this administration rather than a future one. The same SEC that withdrew both cybersecurity proposals in June 2025 let the Regulation S-P compliance dates arrive on schedule, without delay, stay or reopening, in December 2025 and June 2026. It withdrew the proposals and let the rule bite. That is the distinction this paper is built on, demonstrated by the deregulatory Commission's own conduct.
Section 206 of the Advisers Act is a statute. Changing it requires an Act of Congress, which puts it beyond the reach of any election short of unified government with the appetite to spend floor time on it.
Rule 206(4)-7 has been in force unchanged since December 2003, through four administrations. FINRA Rule 3110 is intact and is the rule FINRA named for AI supervision. Regulation S-P was strengthened rather than weakened, and took effect under a deregulatory Commission.
We would not overstate this, so here are the three counter-examples a well-prepared reader will raise.
Staff interpretation moves, even when rule text does not. The Marketing Rule is unchanged, but the staff reversed prior positions on extracted performance and portfolio characteristics in March 2025 and issued further FAQs in January 2026. The lesson is to build to the rule text rather than to a particular FAQ. Both of those changes were liberalising, so a firm that had built to the stricter reading lost nothing but effort.
New and contested rules can be killed. The Department of Labor's 2024 Retirement Security Rule was enjoined by two federal courts, the administration stopped defending it, and DOL moved to vacate it in March 2026. That is a fiduciary obligation, created by rule, ended within two years. Note the profile though: new, contested, under active constitutional challenge. That is the opposite profile to a twenty-three-year-old rule with settled interpretation.
Even Rule 206(4)-7 has been touched. The 2023 Private Fund Adviser Rules amended it to require that annual compliance reviews be documented in writing. The Fifth Circuit vacated those rules in full in June 2024, and that amendment went with them. Four words removed. The underlying obligation stood, and the challenge came from a court rather than from an administration.
That last point is the useful one. The threat to the durable layer is litigation, not elections, and the variable that predicts survival is not political alignment but legal settledness. A rule that is twenty years old, has settled interpretation and faces no pending challenge is a different proposition from a two-year-old rule in the Fifth Circuit.
Whichever way 2028 goes, a firm that can produce the documents in Part 3 and evidence the controls behind them is in good shape. The obligations those documents satisfy predate the current administration by two decades and are not on anyone's agenda to remove. A firm that read "no AI rule" as "no obligation" is exposed under every political configuration, including this one, because the enforcement actions in Part 2 were all brought under rules that already existed.
What is genuinely uncertain is enforcement intensity and staff interpretation. Those are weather. Build to the rule text and to a recognised framework, and the weather stops mattering.
Firms sometimes assume that if federal regulators step back, states will fill the gap, and that the federal preemption push closes that off. The picture is more specific than either.
Executive Order 14365, issued in December 2025, directs an AI Litigation Task Force to challenge state AI laws and conditions certain federal funding on states not maintaining onerous ones. It has no financial services carve-out. But an executive order does not itself preempt anything, and Congress has twice declined to enact a preemption moratorium. Colorado is a case of retreat rather than resistance: its AI Act was blocked in April 2026 and replaced in May by a materially weaker statute effective January 2027.
New York is the one to watch, and it is structurally different. NYDFS has not written an AI law. It has Part 500, a binding cybersecurity regulation with an examination function attached, and it has been applying that existing authority to AI, including two industry letters in May 2026 on frontier models. A general AI statute can be challenged, enjoined or repealed. A financial regulator applying an existing supervisory rule to AI cannot be, because there is no AI law for a task force to challenge.
That is this paper's argument, playing out one level down.
The priorities were published on 17 November 2025. Artificial intelligence appears substantively in two places. Here is all of it.
First, under Information Security and Operational Resiliency, one clause inside the cybersecurity paragraph:
In addition, focus will be on training and security controls that firms are employing to identify and mitigate new risks associated with artificial intelligence (AI) and polymorphic malware attacks, including how they are operationalizing information from threat intelligence sources. SEC Division of Examinations, 2026 Examination Priorities
Note what is and is not there. The SEC pairs AI with polymorphic malware. It does not mention deepfakes or social engineering anywhere in the document. Those are FINRA's framing, and attributing them to the SEC is a small error that a well-read examiner will notice.
Second, under Emerging Financial Technology, one paragraph:
With respect to AI, the Division will focus on recent advancements in AI and will review for accuracy registrant representations regarding their AI capabilities or AI. The Division will assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies, including for tasks related to fraud prevention and detection, back-office operations, anti-money laundering (AML), and trading functions, as applicable. SEC Division of Examinations, 2026 Examination Priorities
The phrase "AI capabilities or AI" reads like a drafting artifact, and it is. It is in the original, carried over from the prior year.
The same section sets out four assessments the Division applies to automated investment tools generally, and they are worth reading as AI questions even though the paragraph does not say AI. Reviews will include whether "representations are fair and accurate," whether "operations and controls in place are consistent with disclosures made to investors," whether algorithms produce advice consistent with investor profiles, and whether controls confirm that advice from automated tools meets regulatory obligations, "including retail and older investors."
This part runs against most of the commentary you will have read, so it is worth stating carefully.
The FY2025 priorities, published 21 October 2024, contained two AI passages that do not appear in the FY2026 document.
From the advisers' compliance section:
If advisers integrate artificial intelligence (AI) into advisory operations, including portfolio management, trading, marketing, and compliance, an examination may look in-depth at compliance policies and procedures as well as disclosures to investors related to these areas. SEC Division of Examinations, 2025 Examination Priorities, removed for 2026
And from Emerging Financial Technologies:
In addition, the Division will examine how registrants protect against loss or misuse of client records and information that may occur from the use of third-party AI models and tools. SEC Division of Examinations, 2025 Examination Priorities, removed for 2026
The second one matters most, because it means the 2026 priorities contain no AI-specific vendor or third-party language at all. A good deal of published commentary asserts that they do. That assertion is either recycled from the 2025 document or borrowed from FINRA.
We would not over-read it. The FY2026 document is shorter and less prescriptive throughout, which is consistent with Chairman Atkins's stated view that examinations should not be a "gotcha" exercise. The deletion may reflect editorial compression rather than a change of position. What we can say is what the text says, which is that the SEC narrowed its written AI language in 2026 rather than expanding it, while the enforcement unit responsible for AI fraud remained in place.
FINRA published its 2026 Annual Regulatory Oversight Report on 9 December 2025. The generative AI section is flagged as new for 2026, and its framing sentence is the one to take to your board.
FINRA's rules, which are intended to be technologically neutral, and the securities laws more generally, continue to apply when firms use GenAI or similar technologies in the course of their businesses, just as they apply when firms use any other technology or tool. FINRA 2026 Annual Regulatory Oversight Report
The report says that using generative AI "can implicate rules regarding supervision, communications, recordkeeping and fair dealing." That is one sentence, and it is the only place those four areas appear together.
One rule is named by number in the whole section:
Pursuant to FINRA Rule 3110 (Supervision), a member firm must have a reasonably designed supervisory system tailored to its business. If a firm is relying on Gen AI tools as part of its supervisory system, its policies and procedures may consider the integrity, reliability and accuracy of the AI model. FINRA 2026 Annual Regulatory Oversight Report
Rule 2210 is not cited in the generative AI section. Neither is Rule 4511 or Exchange Act Rule 17a-4. We checked the Communications with the Public and the Books and Records sections of the same report, and neither mentions AI, generative AI or chatbots. If you have read that FINRA's 2026 report applied the communications rules to AI, that is an overstatement of a single general sentence. The actual link to Rule 2210 comes from Regulatory Notice 24-09 in June 2024 and the Advertising Regulation FAQ of May 2024, both of which remain good guidance.
The most operationally useful line in the report is not in the AI section at all. It is in Third-Party Risk Landscape, among the effective practices:
ensuring contracts with third-party vendors comply with regulatory obligations (e.g., adding language that prohibits firm or customer sensitive information from being ingested into a third-party vendor's open-source GenAI tool) FINRA 2026 Annual Regulatory Oversight Report
That is a specific contract term, and most firms do not have it. The same section also asks firms to assess "the third-party vendor's use of GenAI in their products or services," which covers the AI your vendors added to products you bought before anyone was thinking about AI.
FINRA defines AI agents as "systems or programs that are capable of autonomously performing and completing tasks on behalf of a user," and sets out six risks. They are worth reproducing because they are the closest thing to a checklist any US regulator has published on agents.
| Risk | FINRA's description |
|---|---|
| Autonomy | "AI agents acting autonomously without human validation and approval." |
| Scope and Authority | "Agents may act beyond the user's actual or intended scope and authority." |
| Auditability and Transparency | "Complicated, multi-step agent reasoning tasks can make outcomes difficult to trace or explain, complicating auditability." |
| Data Sensitivity | "Agents operating on sensitive data may unintentionally store, explore, disclose or misuse sensitive or proprietary information." |
| Domain Knowledge | "General-purpose AI agents may lack the necessary domain knowledge to effectively and consistently carry out complex and industry-specific tasks." |
| Rewards and Reinforcement | "Misaligned or poorly designed reward functions could result in the agent optimizing decisions that could negatively impact investors, firms or markets." |
From the priorities, the enforcement record, and advisers who have recently been examined.
This is the area with the longest enforcement record and the clearest rule.
The Marketing Rule prohibits an advertisement that includes "a material statement of fact that the adviser does not have a reasonable basis for believing it will be able to substantiate upon demand by the Commission." Read that again with your own website in mind. The burden sits with you, the standard is substantiation, and the demand can come at any time.
The two March 2024 orders are still the clearest illustration. Delphia was charged under Advisers Act Sections 206(2) and 206(4) and Rules 206(4)-1 and 206(4)-7, and paid $225,000. Among the statements at issue: that it "uses machine learning to analyze the collective data shared by its members to make intelligent investment decisions" and that client data was "helping [Delphia] train [its] algorithm for pursuing ever better returns." The SEC found the conduct ran from August 2019 to August 2023, and continued after Delphia acknowledged the misrepresentations to examiners during a July 2021 examination.
Global Predictions paid $175,000 for claims including "[e]xpert AI-driven forecasts" and describing itself as the "first regulated AI financial advisor."
Two later cases add lessons that the first two do not.
Rimar Capital, in October 2024, was the first to reach both an offering and an advisory business. The firm falsely claimed to have "an AI-driven platform for trading securities," raising nearly $4 million from 45 investors. Penalties ran to $213,611 in disgorgement and interest plus a $250,000 civil penalty for the principal, with an associational bar.
Presto Automation, in January 2025, is the one most relevant to an ordinary firm that has bought rather than built. The company failed to disclose that "the AI speech recognition technology in all units of Presto Voice that the company had then deployed was owned and operated by a third party," and later "falsely claimed that its own AI product eliminated the need for human order-taking" when in fact "the vast majority of drive-thru orders placed through this version of Presto Voice required human intervention." No civil penalty was imposed, citing cooperation and remediation.
Two things follow from Presto that apply directly to advisers. Presenting a vendor's AI as your own proprietary technology is itself the violation. And overstating how automated a process is, while understating how much human intervention it requires, is the same misstatement in reverse. Firms are currently being encouraged to emphasise human review in their AI disclosures, which is right, and it is worth making sure the description is accurate in that direction too.
SEC v. AI Investment Education Foundation and SEC v. AI Financial Education Foundation, both filed November 2025, were charged under Advisers Act Sections 204(a) and 207 for false Form ADV filings. They involved no AI technology claims of any kind. "AI" appears only in the entity names. Several enforcement trackers count them, which inflates the apparent volume of AI enforcement.
Advisers we have spoken with who have been through an examination recently describe a consistent focus on third-party risk, and it is broader than most firms prepare for. It is not a question about whether you have a vendor list. It is four questions asked about each vendor that matters.
Take these one at a time, because firms are usually strong on the first and weak on the rest.
Technology. What the vendor does, where your data sits, who at the vendor can reach it, and what security attestations they hold. Most firms have this, because it is what a standard due diligence questionnaire asks.
Business continuity. What happens to your operations when the vendor is unavailable. Not whether the vendor has a plan, but whether you have one that assumes they are down. FINRA's 2026 report notes increased reporting of both cyberattacks and outages at third-party vendors, and observes that a single provider's problem can reach a large number of member firms at once.
Recoverability. If you leave, or they fail, what do you get back and in what form. This is the question firms answer worst, because the answer is usually in a contract nobody has read since signing. It is also the question with the clearest link to a data platform decision, since a firm that owns its own data lake has a materially different answer than one whose records live inside a vendor's system.
AI usage. This is the newest of the four and the one that catches firms out, because it has two halves. What AI you use from that vendor, and what AI that vendor uses in delivering the service to you. The second half is the one nobody inventories. A product you bought in 2023 that added AI features in a 2026 release is now an AI vendor, and your file probably does not say so.
FINRA writes the most specific guidance available on that last point, and it is a contract term rather than a policy. Among its effective practices for third-party risk:
ensuring contracts with third-party vendors comply with regulatory obligations (e.g., adding language that prohibits firm or customer sensitive information from being ingested into a third-party vendor's open-source GenAI tool) FINRA 2026 Annual Regulatory Oversight Report
The same section asks firms to assess "the third-party vendor's use of GenAI in their products or services." Between them, those two sentences are a small project: a clause to add at renewal, and a question to ask every existing vendor.
Recall from Part 3 that only 30% of adviser firms have a policy covering third-party AI use, against 86% with an acceptable use policy. Of everything in this paper, that is the widest gap between what examiners are asking about and what firms have prepared.
Regulation S-P deserves its own section, because it is the live examination topic in the RIA market this year and because it is where AI vendor risk stops being a governance question and becomes a notification obligation with a clock on it.
The amendments were adopted in May 2024. Both compliance dates have passed: 3 December 2025 for larger entities and 3 June 2026 for smaller ones. If your calendar still shows a Reg S-P deadline, it is out of date. The rule is now something you are examined on, and the SEC said so directly in the 2026 priorities:
In preparation for the compliance dates for the Commission's amendments to Regulation S-P, the Division will engage firms during examinations about their progress in preparing incident response programs reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. SEC Division of Examinations, 2026 Examination Priorities
Three obligations matter for a firm using AI.
An incident response program reasonably designed to detect, respond to and recover from unauthorised access to or use of customer information. Note the first verb. Detection comes before response, and detection is an architecture question.
Customer notification as soon as practicable, and not later than 30 days after becoming aware that unauthorised access has occurred or is reasonably likely to have occurred. Thirty days sounds generous until you try to determine which clients were affected.
Service provider oversight, including written contracts requiring providers to notify you of a breach so that you can meet your own notification clock. This is the point where the vendor file from the previous section becomes a Reg S-P control rather than a good practice.
Here is why this belongs in a paper about AI. Every AI tool your firm uses is a path your client data can take. If an incident occurs at an AI vendor, or through one, your ability to notify within 30 days depends entirely on whether you can establish what that tool could reach and what it actually retrieved. A firm that cannot answer that question is not failing an AI rule. It is failing Regulation S-P.
Which is the same problem we wrote about in our paper on permission-aware data access. You cannot scope an incident you cannot reconstruct.
This is the rule that does the work, and it is the one to organise your file around.
For advisers, Rule 206(4)-7 requires written policies and procedures reasonably designed to prevent violations, an annual review of their adequacy and of the effectiveness of their implementation, and a designated chief compliance officer. Both March 2024 AI orders included a 206(4)-7 charge alongside the Marketing Rule charge. That pairing is the template: the false claim breaches the Marketing Rule, and the absence of a compliance program that would have caught it breaches 206(4)-7.
For broker-dealers, Rule 3110 requires a supervisory system reasonably designed to achieve compliance, tailored to the business. FINRA's Regulatory Notice 24-09 put it directly: if a firm is using generative AI as part of its supervisory system, "its policies and procedures should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model."
Note the direction of that sentence. It is not only about supervising people who use AI. It is about supervising the AI you have put into your supervisory system, which is a harder problem and one that fewer firms have thought about.
The SEC's language here is one clause, quoted in Part 1. FINRA's is far more specific, and if you want a list of what to test your controls against, FINRA's is the one to use.
The 2026 report catalogues generative AI enabled fraud as threat actors "generating fake content (e.g., imposter sites, false identification documents, deepfake audio and video)," creating polymorphic malware, and "leveraging GenAI models to develop malicious tools, allowing those without technical ability to become sophisticated cybercriminals."
In the account fraud section it gets more concrete still, and these three should be tested against your own onboarding and verification procedures:
If your callback verification procedure relies on recognising a client's voice, it was designed for a world that no longer exists. That is a procedure change, not a technology purchase, and it is the cheapest item on any remediation list.
FINRA published separate educational material on prompt injection in March 2026, describing it as an attack that "manipulates a GenAI system that already has legitimate access to your firm's data and systems, exploiting the GenAI system to misuse this authorized access." It cites no rules and prescribes nothing, but it tells you where FINRA's attention is going.
The priorities ask whether "operations and controls in place are consistent with disclosures made to investors." In practice this cuts in both directions, and most firms are exposed on the second one.
The first direction is the one everybody knows about, which is claiming AI you do not have. The second is using AI you have not disclosed, have not inventoried and cannot describe.
Schwab's study of 533 advisers who custody with them, fielded in October 2025, found 63% using AI tools in some capacity, with adoption occurring "through individual experimentation rather than firm-wide systems." That is the sentence to worry about. If adoption happened one person at a time, then the firm's description of its own AI use, wherever that description appears, was written without knowing what is actually in use.
The question to ask internally is not whether you have an AI policy. It is whether you could produce a list of every AI tool in use today, including the AI features your existing vendors switched on in a product release you did not read.
What is published, what is not, and what to have ready.
A great deal of material circulates describing "what SEC examiners are asking about AI." Before you use any of it, including ours, it is worth knowing what the SEC has actually published.
There is no SEC risk alert on artificial intelligence. The Division of Examinations announcements for 2025 and 2026 cover Regulation S-P, the Marketing Rule, economic conflicts of interest and lost securityholders. The only AI item is a roundtable held in February 2025.
There is no published SEC document request list covering AI. The Division's published request list, in the risk alert of 6 September 2023, contains no mention of artificial intelligence, machine learning, algorithms or automated tools. AI requests arrive under the existing compliance program and information security headings.
The most recent Marketing Rule deficiency guidance, published 16 December 2025, is silent on AI. Its observations concern testimonials, endorsements and third-party ratings. Given that the two flagship AI enforcement actions were Marketing Rule cases, that silence is itself worth noticing.
It is practitioner consensus, assembled from compliance consultants and trade press between January and August 2026, and it is consistent across sources that have no reason to coordinate. It is not published SEC practice, and we are not going to present it as if it were. A compliance officer who takes an unsourced list into a board meeting and is asked where it came from should have a real answer.
Each of these has been named by at least one identifiable practitioner source. Taken together they are what a firm should be able to produce without a scramble.
A few of them deserve comment.
The AI inventory is first for a reason. Everything else refers back to it. It should cover tools your firm licensed, tools individuals adopted, and AI features embedded in products you already owned. That last category is where most inventories are wrong.
The governance committee minutes are the most specific item reported anywhere. Trade press in August 2026 described examiners asking not only whether firms have an AI committee, but whether that committee keeps written minutes. This is second-hand reporting rather than regulator guidance, and we flag it as such, but it is cheap to satisfy and expensive to lack.
Evidence of human review is the item firms consistently think they have and consistently do not. A policy saying that a human reviews AI output before it reaches a client is not evidence that a human did. Part 4 is about that difference.
Vendor files should cover data handling, storage location, retention, security and contract terms for each AI tool. FINRA's suggested contract language, quoted in Part 1, belongs in this file.
The Investment Management Compliance Testing Survey, run by the Investment Adviser Association with ACA Group and Yuter Compliance Consulting, surveyed 411 adviser firms in April and May 2026 and published in July. It is the best data available on this question, and the shape of it is more interesting than any single number.
Eighty-six per cent of firms have an acceptable use policy. Eighty-six per cent maintain an inventory. Then it falls away. Just under half have a documented approach to human review. Thirty-seven per cent have procedures for testing and validating AI outputs. Thirty per cent have policies covering third-party AI use, which is the area FINRA wrote the most concrete guidance about. Fourteen per cent have updated their incident response plans.
The pattern is that firms have done the things you can write and have not done the things you have to operate. That is not a criticism of anyone. Writing an acceptable use policy takes a week and testing model outputs is a standing programme. But it does mean that the average firm's readiness is thinner one layer down than the headline numbers suggest, and an examiner who asks a second question will find that out.
A separate survey of more than 200 compliance and operations professionals, fielded in April 2026, described adoption as "widespread but shallow" and noted that desktop tools such as consumer chatbots dominate rather than embedded, governed systems. Both findings point the same way.
If you want to know which of the nine documents your firm could produce today, we will walk your current setup and tell you where the gaps are. You keep the findings either way.
Book a demoWhy the second question is harder than the first.
Every item on the list in Part 3 has two versions. There is the document that says what should happen, and there is the record showing that it did.
An examiner asking about AI governance will usually start with the first and move to the second. Do you have an acceptable use policy. Show me. Does it require human review before AI-assisted material reaches a client. It does. Show me a month of that review happening.
The second question is where firms run out of road, and it is not because they were not doing the review. It is because the review left no trace. Someone read the draft, changed two sentences and sent it. There is no record that the draft was AI-assisted, no record of who reviewed it, and no way to distinguish that document from one written entirely by hand.
The same gap runs through the whole list. An inventory is a document; keeping it current is a process. A vendor file is a document; knowing that the vendor turned on a new AI feature last quarter is a process. Training records are the exception, which is why almost every firm has them.
This distinction is widely blurred and it is worth getting right, because the version that circulates is more alarming than the version that is true.
FINRA's 2026 report includes, among its effective practices for monitoring generative AI:
Ongoing monitoring of prompts, responses and outputs to confirm the GenAI solution continues to perform as expected and results in compliant behavior. This may include storing prompt and output logs for accountability and troubleshooting; tracking which model version was used and when; and validation and human-in-the-loop review of model outputs, including performing regular checks for errors or bias. FINRA 2026 Annual Regulatory Oversight Report
"May include" is practice guidance inside a discussion of effective controls. It is not a rule, and no regulator has said that AI prompts are books and records. Any vendor telling you that FINRA requires prompt logging is overstating, and a compliance officer who repeats it to their board will be corrected by counsel.
What is true is more ordinary and more useful. Advisers Act Rule 204-2(a)(7) requires originals of written communications received and copies of written communications sent relating to any recommendation made or advice given. FINRA Rule 4511 requires members to preserve for at least six years those books and records with no other specified period, in a format complying with Exchange Act Rule 17a-4. If an AI system produces a written communication relating to advice and it goes to a client, it is a record on ordinary principles, whatever anyone says about prompts.
So the practical position is this. Retaining the client-facing output is a records obligation you already have. Retaining prompts and model versions is a control that a regulator has described as effective practice and that you would want anyway, because it is what lets you answer the second question.
Take the awkward version. It is March. An examiner asks about a client report from June, and wants to know whether AI was involved in producing it, who reviewed it, and whether the person who ran it was entitled to the underlying data.
If your systems recorded that at the time, this is a retrieval task. If they did not, you are reconstructing from the current configuration of a system that has changed since, in front of someone whose job is to notice that.
This is the same problem in a different suit as the one we wrote about in our paper on permission-aware data access, where the question is which person the data layer thought was asking. Both come down to whether the system wrote something down at the time, and both are decided by architecture rather than by policy.
A deadline you set, and a calendar you did not.
Rule 206(4)-7(b) requires a review, no less frequently than annually, of the adequacy of your policies and procedures and the effectiveness of their implementation. There is no external date attached to it. You chose when it happens.
That review is where the SEC will look first, because it is the only document that shows the firm assessing itself. A 2026 annual review that does not address AI, in a year when 80% of adviser firms report having formally adopted AI tools, is a finding waiting to be written up. It does not need to be long. It needs to show that the question was asked.
Four things belong in it. What AI is in use across the firm and how you know. Whether the policies cover what is actually happening rather than what was anticipated. What testing was performed and what it found. What changed as a result.
Two things worth correcting first, because both appear on calendars that have not been updated.
There are no remaining Regulation S-P compliance dates. Larger entities passed on 3 December 2025 and smaller entities on 3 June 2026. Reg S-P is now an examination subject rather than a countdown, and the SEC's 2026 priorities say the Division will "engage firms during examinations about their progress in preparing incident response programs."
And there is no pending AI rulemaking to prepare for. That remains true.
The item most likely to affect broker-dealers is FINRA's Regulatory Notice 26-14, published 9 July 2026, which proposes replacing mandatory principal pre-use approval of retail communications with a risk-based standard. AI is an express driver: the notice says that "applying the principal pre-use approval requirement to AI-generated retail communications can be challenging," and that firms should ensure generative AI tools are "vetted, tested and monitored."
Be careful about how you describe its status. This is a concept-stage Regulatory Notice, not a filed rule change. After comments close, FINRA staff review, may revise, take a proposal to the FINRA Board, and file with the SEC under Section 19(b) for notice and comment. Twelve to twenty-four months to an effective rule is realistic. Do not plan around it, but do read it, because it tells you what FINRA thinks supervision of AI-generated communications should look like.
SR-FINRA-2026-004 is a separate, already-filed Rule 2210 change on projected performance and targeted returns. It was filed in February 2026 and has been through SEC proceedings since. It has no AI content. Commentary regularly conflates the two.
These are ordered so that a firm that cannot answer the first three has found its next project.
Most of what is above is compliance work, and no platform performs it for you. Three of the items are architecture rather than policy, and those are the ones we build.
The inventory stays current because the connections run through one place. When every AI tool and agent reaches firm data through a single governed entry point, the list of what is connected is a property of the system rather than a document somebody maintains.
The evidence is produced by the system, not by the reviewer. Every request records who asked, which agent acted, which policy version applied, what was returned and what was withheld. That is what turns "we require human review" into something you can show a month of.
Data does not leave your boundary. The lake and the infrastructure are yours. The vendor contract question in the list above is easier to answer when the technical control matches the contract term.
Control mapping is generated, not maintained by hand. Our App Deployment Service includes a questionnaire drawing on 23 frameworks, including the FS AI RMF, which produces the specific control objectives your firm needs to apply and then monitor. Firms that want to automate the alignment between AI use and control objectives, rather than keep it in a spreadsheet that ages, should reach out.
If your firm is somewhere in the gap in Figure 8, with the policies written and the operating controls still to build, that gap is the conversation we have most often.
Apply your existing obligations to AI rather than waiting for new rules: supervise AI use under FINRA Rule 3110 written procedures, protect customer data under Regulation S-P, keep required records of AI-assisted work, inventory your AI systems with named owners, and be able to produce evidence of who accessed what data and who reviewed which output.
No. In June 2025 the SEC formally withdrew fourteen proposed rules, including Conflicts of Interest Associated with Predictive Data Analytics, which expressly covered AI and machine learning, along with the proposed outsourcing rule and both proposed cybersecurity rules. The withdrawal states that the Commission "does not intend to issue final rules with respect to these proposals." AI is examined and enforced under existing rules, principally Advisers Act Rules 206(4)-7 and 206(4)-1, Section 206, and Regulation S-P.
AI appears substantively in two places. Under cybersecurity, the Division will focus on "training and security controls that firms are employing to identify and mitigate new risks associated with artificial intelligence (AI) and polymorphic malware attacks." Under Emerging Financial Technology, it will "review for accuracy registrant representations regarding their AI capabilities" and assess whether firms have "adequate policies and procedures to monitor and/or supervise their use of AI technologies." Two AI passages present in the 2025 priorities were removed for 2026.
No. FINRA's 2026 report lists prompt and output logging among effective practices, saying monitoring "may include storing prompt and output logs for accountability and troubleshooting." That is practice guidance, not a rule. Separately, if an AI system produces a written communication relating to advice or a recommendation that goes to a client, that communication is a record under existing rules such as Advisers Act Rule 204-2(a)(7) or FINRA Rule 4511, on ordinary principles.
AI washing is overstating a firm's use or capability in artificial intelligence. The term does not appear in the SEC's 2026 examination priorities; it comes from enforcement and commentary. Actions include Delphia and Global Predictions in March 2024, charged under Advisers Act Sections 206(2) and 206(4) and Rules 206(4)-1 and 206(4)-7, with penalties of $225,000 and $175,000; Rimar Capital in October 2024; and Presto Automation in January 2025. The Cyber and Emerging Technologies Unit, created in February 2025, has AI fraud expressly in scope.
The SEC has published no AI-specific document request list. Practitioner consensus, consistent across compliance consultants and trade press through 2026, points to nine items: an AI inventory, a written acceptable use policy, AI governance committee minutes, vendor due diligence files per tool, evidence of human review, training records, model testing and validation records, a review of AI claims in marketing and Form ADV, and an incident response plan updated for AI.
No SEC guidance requires AI-specific disclosure. The obligation derives from the Section 206 fiduciary duty and the Part 2A instructions, particularly Item 4 on advisory business and Item 8 on methods of analysis. The 2025 priorities referenced disclosures to investors in connection with AI integration, and that sentence was removed for 2026. Note the tension: the enforcement actions punished firms for overstating AI, so an elaborate AI disclosure carries its own accuracy risk under the same rules.
They had not been published as of early September 2026. The last three were published on 16 October 2023, 21 October 2024 and 17 November 2025, so mid-October to late November 2026 is a reasonable expectation. Earlier cycles were less regular, so treat this as a pattern rather than a schedule.
A concept-stage proposal published 9 July 2026 to modernise Rule 2210, replacing mandatory principal pre-use approval of retail communications with a risk-based standard. AI is an express driver, with the notice observing that applying pre-use approval to AI-generated communications "can be challenging." It is not a filed rule change. Any resulting rule would need FINRA Board approval and an SEC filing under Section 19(b), which realistically means twelve to twenty-four months.
Choose which categories of cookies and tracking technologies you allow. Strictly necessary cookies cannot be disabled. Read our full Cookie Policy.
Required for security, authentication, fraud prevention, load balancing, and storing your consent preferences. Always on.
Remember choices you make to provide a personalized experience (language, region, theme, saved filters).
Help us understand how the site is used (Google Analytics, Vercel Analytics, Microsoft Clarity, etc.).
Used for conversion tracking, retargeting, and personalized ads (LinkedIn, Meta, Google Ads, Bing, etc.).