White paper

What Examiners Are Actually Asking About AI

There is no AI-specific rule, and nothing new can realistically bind before 2029. What the SEC and FINRA actually expect in 2026, and the documents your firm should be able to produce today.

Key takeaways

  • In June 2025 the SEC formally withdrew fourteen proposed rules, including the one that would have created AI-specific obligations for advisers and broker-dealers. No AI rulemaking is pending, and nothing new can realistically bind before 2029. Your existing rules are the AI rules.
  • AI appears in exactly two places in the SEC's 2026 examination priorities: one clause under cybersecurity, and one paragraph under emerging financial technology.
  • The 2026 priorities contain less AI language than 2025, not more. Two AI passages from the prior year were removed.
  • FINRA's 2026 report names one rule in its generative AI section: Rule 3110 on supervision. It does not develop a link to Rule 2210 or Rule 4511, whatever you may have read.
  • The SEC has published no AI risk alert and no AI document request list. What circulates as "what examiners are asking" is practitioner consensus, and this paper labels it as such.
  • The Financial Services AI Risk Management Framework, published in February 2026, is voluntary. No US regulator has cited it. It is still the most useful thing to align to, and its adoption stages mean a smaller firm is scoped to 21 control objectives rather than 230.
  • Regulation S-P was proposed in 2008, shelved, re-proposed in 2023 and became binding in 2025. A withdrawn proposal is not a closed subject.
  • In a survey of 411 adviser firms published in July 2026, 86% had an AI acceptable use policy. Only 37% had procedures for testing and validating AI outputs, 30% covered third-party AI use, and 14% had updated their incident response plans.

An examiner arrives. They do not open with a question about artificial intelligence, because there is no AI rule for them to examine you against.

They ask about your compliance program, your books and records, your marketing, your cybersecurity and your vendors. Then, inside each of those, they ask how AI fits.

That is the whole shape of it, and it is better news than most firms expect. You are not being measured against a new framework you have not read. You are being measured against rules you have complied with for years, applied to a technology your staff started using eighteen months ago without telling you.

Part 1
What the Regulators Actually Said

The primary documents, quoted, with nothing added.

There Is No AI-Specific Rule Today

On 12 June 2025 the SEC withdrew fourteen notices of proposed rulemaking issued between March 2022 and November 2023, effective 17 June 2025. The withdrawal states plainly: "The Commission does not intend to issue final rules with respect to these proposals."

Four of the fourteen matter here.

Conflicts of Interest Associated with Predictive Data Analytics was the closest thing to an AI rule the SEC ever proposed for advisers and broker-dealers. It covered "covered technology," a term that expressly included artificial intelligence and machine learning. It is gone. Outsourcing by Investment Advisers is gone. Both proposed cybersecurity risk management rules, one for advisers and funds and one for broker-dealers, are gone.

Note also that three of those four are cybersecurity and outsourcing rather than AI. There is no cybersecurity rule and no outsourcing rule for advisers either.

So the framework a firm will be examined against in 2026 is the framework that already existed. That is not a gap. It is the answer to the question most compliance officers are actually asking, which is what they are supposed to be complying with.

WITHDRAWN 12 JUNE 2025 "The Commission does not intend to issue final rules" Predictive Data Analytics covered AI and machine learning expressly Outsourcing by Investment Advisers Cybersecurity Risk Management, advisers Cybersecurity Risk Management, BDs Ten further proposals were withdrawn at the same time. WHAT YOU ARE EXAMINED AGAINST Unchanged, and now doing all the work Advisers Act Rule 206(4)-7 policies, procedures, and the annual review Rule 206(4)-1, the Marketing Rule Section 206 and Regulation S-P FINRA Rules 3110 and 4511 No new framework to learn.
Figure 1: The SEC removed the rules that would have been AI-specific and kept examining AI under the rules that already existed.

Rule 206(4)-7 does most of the work. It requires written policies and procedures reasonably designed to prevent violations, and a review "no less frequently than annually" of both their adequacy and the effectiveness of their implementation. Nothing in it mentions technology, which is exactly why it applies to all of it.

One thing the withdrawal notice does not say is that the subject is closed. The full sentence is worth reading:

The Commission does not intend to issue final rules with respect to these proposals. If the Commission decides to pursue future regulatory action in any of these areas, it will issue a new proposed rule. SEC, Withdrawal of Proposed Regulatory Actions, 17 June 2025

What About the Financial Services AI Risk Management Framework?

This is the first question a well-read compliance officer asks, and it deserves a direct answer.

The Cyber Risk Institute published the Financial Services AI Risk Management Framework on 12 February 2026, developed with the Financial Services Sector Coordinating Council and more than 100 financial institutions. Treasury announced it a week later, on 19 February, through the joint FBIIC and FSSCC AI Executive Oversight Group. It contains 230 control objectives, structured on the NIST AI Risk Management Framework's four functions of Govern, Map, Measure and Manage.

It is voluntary, and no US regulator has cited it. We looked specifically. The SEC Chairman gave his first dedicated AI remarks at an FSOC roundtable on 4 March 2026, two weeks after the framework launched, and did not mention it. FINRA's 2026 report cites the NIST AI RMF in its resources, not this. No OCC, Federal Reserve or FDIC guidance references it. A firm cannot be examined against it today, and anyone telling you otherwise is selling something.

So the honest description is that it is soft law. It creates no legal obligation, and it is the most useful thing available to align to.

The four adoption stages, and what they actually mean

The framework includes an AI Adoption Stage Questionnaire that places a firm in one of four stages: Initial, Minimal, Evolving or Embedded.

These are commonly described as maturity levels to climb, and that is a misreading worth correcting. They are scoping tiers. The stage reflects how deep your AI footprint is, and it determines how many of the 230 control objectives apply to you.

ADOPTION STAGE DETERMINES SCOPE, NOT MATURITY Initial 21 control objectives Quick Start Guide Minimal 126 control objectives most mid-size firms Evolving 193 control objectives AI in core processes Embedded 230 control objectives AI across the business A firm is at Initial because its AI footprint is small, not because it is doing badly. The stages scope the work down. They are not a ladder to climb.
Figure 2: The FS AI RMF adoption stages. The framework is voluntary and no US regulator has cited it, but the scoping mechanism makes it usable by a firm that would abandon a 230-control framework in week two.

For a mid-size adviser or broker-dealer this is the framework's most useful feature and the reason to look at it rather than at NIST alone. A firm at the Initial stage is being asked to think about 21 control objectives, not 230. CRI publishes a Quick Start Guide covering the Initial stage only, alongside the questionnaire, the Risk and Control Matrix, the Guidebook and the Control Objective Reference Guide. All of them are free, and all require a short registration. Compare that with the usual experience of picking up a bank-scale framework and abandoning it in week two.

Where it matters is Rule 206(4)-7's standard, which is policies and procedures "reasonably designed." What counts as reasonable is shaped by what the industry does. As an industry framework built with a hundred institutions and announced by Treasury gains adoption, it becomes part of the answer to what a reasonable firm would have done. That happens without the SEC writing anything.

What to say when an examiner asks what you align to

"We have an AI policy" is a weak answer. "We align to the NIST AI Risk Management Framework, we have completed the FS AI RMF adoption stage questionnaire and assessed ourselves at the Minimal stage, and here is our control mapping and the gaps we are working" is a strong one. Neither is required. The second one describes a firm that has thought about it.

What Happens If the Politics Change

The second fair question. A reader who has watched regulation swing before is right to ask whether any of this survives an election, and a paper that ducked it would deserve to be ignored.

Three things are worth separating: what can change quickly, what cannot change at all, and what the historical record actually shows.

What can change, and how fast

The midterm elections are on 3 November 2026. All 435 House seats and 35 Senate seats are contested. On the current arithmetic Democrats need a net gain of three in the House and four in the Senate.

A flip of either chamber would change very little about AI rulemaking for financial services before 2029. Congress cannot legislate a new rule without the presidency. The Congressional Review Act runs the wrong way for this purpose, because it is a tool for disapproving finalised rules and it still requires the President's signature. What a Senate flip would realistically do is slow confirmations, which produces a smaller and slower Commission rather than a more active one.

The Commission is already thin. There are three sitting commissioners and two vacant seats with no nominations pending. Commissioner Peirce, whose term expired in June 2025 and who has been serving in holdover, has said she will leave in November 2026. That takes the Commission to two, where the Rule of Two applies and both members must agree for the body to act. That is not a Commission positioned to originate contested new rulemaking.

One thing did change, and it runs against the comfortable reading. On 29 June 2026 the Supreme Court decided Trump v. Slaughter six to three, holding that the FTC's for-cause removal protection is contrary to the separation of powers and overruling Humphrey's Executor. The opinion does not name the SEC, and it expressly reserved the Federal Reserve on the basis of its distinct historical tradition. The SEC's independence rested on the same foundation the Court removed. The practical consequence is that the lag between an election and a change in Commission posture is shorter than it used to be, not longer.

The precedent that answers the question

You do not have to speculate about whether a withdrawn proposal can come back, because one of the rules in Figure 1 is the example.

fifteen years dormant 2008 proposed not adopted 2023 re-proposed May 2024 adopted 2025 to 2026 compliance binding Sixteen years from a shelved proposal to an obligation firms are examined against. Firms that built incident response in the interim absorbed it as documentation. Firms that read the 2008 withdrawal as an absence of obligation had eighteen months, from a standing start.
Figure 3: Regulation S-P. The same Commission that withdrew both cybersecurity proposals in June 2025 let this rule take effect on schedule.

The SEC proposed amendments to Regulation S-P in 2008, to require incident response programmes and customer notification. They were not adopted. The subject sat for fifteen years. The Commission re-proposed in 2023, adopted in May 2024, and compliance became mandatory in December 2025 for larger entities and June 2026 for smaller ones. Sixteen years from a shelved proposal to a binding obligation that firms are now examined against.

The firms that had built incident response capability during those fifteen years absorbed the rule as a documentation exercise. The firms that read the 2008 withdrawal as an absence of obligation had eighteen months from adoption to compliance, from a standing start.

There is a second lesson in the same rule, and it is about this administration rather than a future one. The same SEC that withdrew both cybersecurity proposals in June 2025 let the Regulation S-P compliance dates arrive on schedule, without delay, stay or reopening, in December 2025 and June 2026. It withdrew the proposals and let the rule bite. That is the distinction this paper is built on, demonstrated by the deregulatory Commission's own conduct.

What does not change

Section 206 of the Advisers Act is a statute. Changing it requires an Act of Congress, which puts it beyond the reach of any election short of unified government with the appetite to spend floor time on it.

Rule 206(4)-7 has been in force unchanged since December 2003, through four administrations. FINRA Rule 3110 is intact and is the rule FINRA named for AI supervision. Regulation S-P was strengthened rather than weakened, and took effect under a deregulatory Commission.

We would not overstate this, so here are the three counter-examples a well-prepared reader will raise.

Staff interpretation moves, even when rule text does not. The Marketing Rule is unchanged, but the staff reversed prior positions on extracted performance and portfolio characteristics in March 2025 and issued further FAQs in January 2026. The lesson is to build to the rule text rather than to a particular FAQ. Both of those changes were liberalising, so a firm that had built to the stricter reading lost nothing but effort.

New and contested rules can be killed. The Department of Labor's 2024 Retirement Security Rule was enjoined by two federal courts, the administration stopped defending it, and DOL moved to vacate it in March 2026. That is a fiduciary obligation, created by rule, ended within two years. Note the profile though: new, contested, under active constitutional challenge. That is the opposite profile to a twenty-three-year-old rule with settled interpretation.

Even Rule 206(4)-7 has been touched. The 2023 Private Fund Adviser Rules amended it to require that annual compliance reviews be documented in writing. The Fifth Circuit vacated those rules in full in June 2024, and that amendment went with them. Four words removed. The underlying obligation stood, and the challenge came from a court rather than from an administration.

That last point is the useful one. The threat to the durable layer is litigation, not elections, and the variable that predicts survival is not political alignment but legal settledness. A rule that is twenty years old, has settled interpretation and faces no pending challenge is a different proposition from a two-year-old rule in the Fifth Circuit.

The practical answer

Whichever way 2028 goes, a firm that can produce the documents in Part 3 and evidence the controls behind them is in good shape. The obligations those documents satisfy predate the current administration by two decades and are not on anyone's agenda to remove. A firm that read "no AI rule" as "no obligation" is exposed under every political configuration, including this one, because the enforcement actions in Part 2 were all brought under rules that already existed.

What is genuinely uncertain is enforcement intensity and staff interpretation. Those are weather. Build to the rule text and to a recognised framework, and the weather stops mattering.

A note on the states

Firms sometimes assume that if federal regulators step back, states will fill the gap, and that the federal preemption push closes that off. The picture is more specific than either.

Executive Order 14365, issued in December 2025, directs an AI Litigation Task Force to challenge state AI laws and conditions certain federal funding on states not maintaining onerous ones. It has no financial services carve-out. But an executive order does not itself preempt anything, and Congress has twice declined to enact a preemption moratorium. Colorado is a case of retreat rather than resistance: its AI Act was blocked in April 2026 and replaced in May by a materially weaker statute effective January 2027.

New York is the one to watch, and it is structurally different. NYDFS has not written an AI law. It has Part 500, a binding cybersecurity regulation with an examination function attached, and it has been applying that existing authority to AI, including two industry letters in May 2026 on frontier models. A general AI statute can be challenged, enjoined or repealed. A financial regulator applying an existing supervisory rule to AI cannot be, because there is no AI law for a task force to challenge.

That is this paper's argument, playing out one level down.

What the SEC 2026 Priorities Say About AI

The priorities were published on 17 November 2025. Artificial intelligence appears substantively in two places. Here is all of it.

First, under Information Security and Operational Resiliency, one clause inside the cybersecurity paragraph:

In addition, focus will be on training and security controls that firms are employing to identify and mitigate new risks associated with artificial intelligence (AI) and polymorphic malware attacks, including how they are operationalizing information from threat intelligence sources. SEC Division of Examinations, 2026 Examination Priorities

Note what is and is not there. The SEC pairs AI with polymorphic malware. It does not mention deepfakes or social engineering anywhere in the document. Those are FINRA's framing, and attributing them to the SEC is a small error that a well-read examiner will notice.

Second, under Emerging Financial Technology, one paragraph:

With respect to AI, the Division will focus on recent advancements in AI and will review for accuracy registrant representations regarding their AI capabilities or AI. The Division will assess whether firms have implemented adequate policies and procedures to monitor and/or supervise their use of AI technologies, including for tasks related to fraud prevention and detection, back-office operations, anti-money laundering (AML), and trading functions, as applicable. SEC Division of Examinations, 2026 Examination Priorities

The phrase "AI capabilities or AI" reads like a drafting artifact, and it is. It is in the original, carried over from the prior year.

The same section sets out four assessments the Division applies to automated investment tools generally, and they are worth reading as AI questions even though the paragraph does not say AI. Reviews will include whether "representations are fair and accurate," whether "operations and controls in place are consistent with disclosures made to investors," whether algorithms produce advice consistent with investor profiles, and whether controls confirm that advice from automated tools meets regulatory obligations, "including retail and older investors."

PRESENT IN THE 2026 PRIORITIES Information Security and Operational Resiliency One clause: training and security controls for risks from AI and polymorphic malware. Emerging Financial Technology One paragraph: accuracy of AI representations, and whether policies and procedures monitor or supervise AI use in fraud detection, back office, AML and trading. REMOVED FROM THE 2025 PRIORITIES In-depth review of AI compliance policies and disclosures to investors Protection of client records from third-party AI models and tools
Figure 4: The 2026 priorities are shorter on AI than the 2025 priorities were. The second removed passage is the only AI-specific vendor language the SEC has published.

What the SEC Removed From Last Year's Priorities

This part runs against most of the commentary you will have read, so it is worth stating carefully.

The FY2025 priorities, published 21 October 2024, contained two AI passages that do not appear in the FY2026 document.

From the advisers' compliance section:

If advisers integrate artificial intelligence (AI) into advisory operations, including portfolio management, trading, marketing, and compliance, an examination may look in-depth at compliance policies and procedures as well as disclosures to investors related to these areas. SEC Division of Examinations, 2025 Examination Priorities, removed for 2026

And from Emerging Financial Technologies:

In addition, the Division will examine how registrants protect against loss or misuse of client records and information that may occur from the use of third-party AI models and tools. SEC Division of Examinations, 2025 Examination Priorities, removed for 2026

The second one matters most, because it means the 2026 priorities contain no AI-specific vendor or third-party language at all. A good deal of published commentary asserts that they do. That assertion is either recycled from the 2025 document or borrowed from FINRA.

How to read the deletion

We would not over-read it. The FY2026 document is shorter and less prescriptive throughout, which is consistent with Chairman Atkins's stated view that examinations should not be a "gotcha" exercise. The deletion may reflect editorial compression rather than a change of position. What we can say is what the text says, which is that the SEC narrowed its written AI language in 2026 rather than expanding it, while the enforcement unit responsible for AI fraud remained in place.

What FINRA Said, and Which Rule It Named

FINRA published its 2026 Annual Regulatory Oversight Report on 9 December 2025. The generative AI section is flagged as new for 2026, and its framing sentence is the one to take to your board.

FINRA's rules, which are intended to be technologically neutral, and the securities laws more generally, continue to apply when firms use GenAI or similar technologies in the course of their businesses, just as they apply when firms use any other technology or tool. FINRA 2026 Annual Regulatory Oversight Report

The report says that using generative AI "can implicate rules regarding supervision, communications, recordkeeping and fair dealing." That is one sentence, and it is the only place those four areas appear together.

One rule is named by number in the whole section:

Pursuant to FINRA Rule 3110 (Supervision), a member firm must have a reasonably designed supervisory system tailored to its business. If a firm is relying on Gen AI tools as part of its supervisory system, its policies and procedures may consider the integrity, reliability and accuracy of the AI model. FINRA 2026 Annual Regulatory Oversight Report

Rule 2210 is not cited in the generative AI section. Neither is Rule 4511 or Exchange Act Rule 17a-4. We checked the Communications with the Public and the Books and Records sections of the same report, and neither mentions AI, generative AI or chatbots. If you have read that FINRA's 2026 report applied the communications rules to AI, that is an overstatement of a single general sentence. The actual link to Rule 2210 comes from Regulatory Notice 24-09 in June 2024 and the Advertising Regulation FAQ of May 2024, both of which remain good guidance.

The vendor sentence worth acting on

The most operationally useful line in the report is not in the AI section at all. It is in Third-Party Risk Landscape, among the effective practices:

ensuring contracts with third-party vendors comply with regulatory obligations (e.g., adding language that prohibits firm or customer sensitive information from being ingested into a third-party vendor's open-source GenAI tool) FINRA 2026 Annual Regulatory Oversight Report

That is a specific contract term, and most firms do not have it. The same section also asks firms to assess "the third-party vendor's use of GenAI in their products or services," which covers the AI your vendors added to products you bought before anyone was thinking about AI.

The six agent risks

FINRA defines AI agents as "systems or programs that are capable of autonomously performing and completing tasks on behalf of a user," and sets out six risks. They are worth reproducing because they are the closest thing to a checklist any US regulator has published on agents.

RiskFINRA's description
Autonomy"AI agents acting autonomously without human validation and approval."
Scope and Authority"Agents may act beyond the user's actual or intended scope and authority."
Auditability and Transparency"Complicated, multi-step agent reasoning tasks can make outcomes difficult to trace or explain, complicating auditability."
Data Sensitivity"Agents operating on sensitive data may unintentionally store, explore, disclose or misuse sensitive or proprietary information."
Domain Knowledge"General-purpose AI agents may lack the necessary domain knowledge to effectively and consistently carry out complex and industry-specific tasks."
Rewards and Reinforcement"Misaligned or poorly designed reward functions could result in the agent optimizing decisions that could negatively impact investors, firms or markets."
Part 2
What They Actually Focus On

From the priorities, the enforcement record, and advisers who have recently been examined.

The Marketing Rule and Your AI Claims

This is the area with the longest enforcement record and the clearest rule.

The Marketing Rule prohibits an advertisement that includes "a material statement of fact that the adviser does not have a reasonable basis for believing it will be able to substantiate upon demand by the Commission." Read that again with your own website in mind. The burden sits with you, the standard is substantiation, and the demand can come at any time.

The two March 2024 orders are still the clearest illustration. Delphia was charged under Advisers Act Sections 206(2) and 206(4) and Rules 206(4)-1 and 206(4)-7, and paid $225,000. Among the statements at issue: that it "uses machine learning to analyze the collective data shared by its members to make intelligent investment decisions" and that client data was "helping [Delphia] train [its] algorithm for pursuing ever better returns." The SEC found the conduct ran from August 2019 to August 2023, and continued after Delphia acknowledged the misrepresentations to examiners during a July 2021 examination.

Global Predictions paid $175,000 for claims including "[e]xpert AI-driven forecasts" and describing itself as the "first regulated AI financial advisor."

Mar 2024 Delphia Global Predictions $400,000 combined Marketing Rule first adviser cases Oct 2024 Rimar Capital $463,611 and a bar offering and advisory Jan 2025 Presto Automation no penalty, cooperation vendor AI called proprietary Apr 2025 Nate, Inc. $42m raised filed, not resolved Every case turned on a claim the firm could not substantiate. The Marketing Rule requires a reasonable basis for believing a claim can be substantiated on demand.
Figure 5: SEC AI enforcement to date. The Nate case was filed in April 2025 and remains unresolved, so it should not be described as a conviction.

Two later cases add lessons that the first two do not.

Rimar Capital, in October 2024, was the first to reach both an offering and an advisory business. The firm falsely claimed to have "an AI-driven platform for trading securities," raising nearly $4 million from 45 investors. Penalties ran to $213,611 in disgorgement and interest plus a $250,000 civil penalty for the principal, with an associational bar.

Presto Automation, in January 2025, is the one most relevant to an ordinary firm that has bought rather than built. The company failed to disclose that "the AI speech recognition technology in all units of Presto Voice that the company had then deployed was owned and operated by a third party," and later "falsely claimed that its own AI product eliminated the need for human order-taking" when in fact "the vast majority of drive-thru orders placed through this version of Presto Voice required human intervention." No civil penalty was imposed, citing cooperation and remediation.

Two things follow from Presto that apply directly to advisers. Presenting a vendor's AI as your own proprietary technology is itself the violation. And overstating how automated a process is, while understating how much human intervention it requires, is the same misstatement in reverse. Firms are currently being encouraged to emphasise human review in their AI disclosures, which is right, and it is worth making sure the description is accurate in that direction too.

Two cases that will show up in your searches and should not count

SEC v. AI Investment Education Foundation and SEC v. AI Financial Education Foundation, both filed November 2025, were charged under Advisers Act Sections 204(a) and 207 for false Form ADV filings. They involved no AI technology claims of any kind. "AI" appears only in the entity names. Several enforcement trackers count them, which inflates the apparent volume of AI enforcement.

Third-Party and Vendor Risk

Advisers we have spoken with who have been through an examination recently describe a consistent focus on third-party risk, and it is broader than most firms prepare for. It is not a question about whether you have a vendor list. It is four questions asked about each vendor that matters.

FOUR QUESTIONS, ASKED ABOUT EACH MATERIAL VENDOR Technology Where does our data sit? Who at the vendor can reach it? most firms have this Continuity What do we do when they are down? Not their plan, ours. partially covered Recoverability If we leave, what do we get back, and in what form? rarely answered AI usage What AI do we use from them, and what AI do they use on us? rarely inventoried The second half of the fourth question is the one nobody inventories. A product bought in 2023 that added AI features in a 2026 release is now an AI vendor. Your file probably does not say so.
Figure 6: What advisers describe being asked about vendors. Firms are usually strong on the first column and thin on the other three.

Take these one at a time, because firms are usually strong on the first and weak on the rest.

Technology. What the vendor does, where your data sits, who at the vendor can reach it, and what security attestations they hold. Most firms have this, because it is what a standard due diligence questionnaire asks.

Business continuity. What happens to your operations when the vendor is unavailable. Not whether the vendor has a plan, but whether you have one that assumes they are down. FINRA's 2026 report notes increased reporting of both cyberattacks and outages at third-party vendors, and observes that a single provider's problem can reach a large number of member firms at once.

Recoverability. If you leave, or they fail, what do you get back and in what form. This is the question firms answer worst, because the answer is usually in a contract nobody has read since signing. It is also the question with the clearest link to a data platform decision, since a firm that owns its own data lake has a materially different answer than one whose records live inside a vendor's system.

AI usage. This is the newest of the four and the one that catches firms out, because it has two halves. What AI you use from that vendor, and what AI that vendor uses in delivering the service to you. The second half is the one nobody inventories. A product you bought in 2023 that added AI features in a 2026 release is now an AI vendor, and your file probably does not say so.

FINRA writes the most specific guidance available on that last point, and it is a contract term rather than a policy. Among its effective practices for third-party risk:

ensuring contracts with third-party vendors comply with regulatory obligations (e.g., adding language that prohibits firm or customer sensitive information from being ingested into a third-party vendor's open-source GenAI tool) FINRA 2026 Annual Regulatory Oversight Report

The same section asks firms to assess "the third-party vendor's use of GenAI in their products or services." Between them, those two sentences are a small project: a clause to add at renewal, and a question to ask every existing vendor.

Recall from Part 3 that only 30% of adviser firms have a policy covering third-party AI use, against 86% with an acceptable use policy. Of everything in this paper, that is the widest gap between what examiners are asking about and what firms have prepared.

Regulation S-P After the Deadlines

Regulation S-P deserves its own section, because it is the live examination topic in the RIA market this year and because it is where AI vendor risk stops being a governance question and becomes a notification obligation with a clock on it.

The amendments were adopted in May 2024. Both compliance dates have passed: 3 December 2025 for larger entities and 3 June 2026 for smaller ones. If your calendar still shows a Reg S-P deadline, it is out of date. The rule is now something you are examined on, and the SEC said so directly in the 2026 priorities:

In preparation for the compliance dates for the Commission's amendments to Regulation S-P, the Division will engage firms during examinations about their progress in preparing incident response programs reasonably designed to detect, respond to, and recover from unauthorized access to or use of customer information. SEC Division of Examinations, 2026 Examination Priorities

Three obligations matter for a firm using AI.

An incident response program reasonably designed to detect, respond to and recover from unauthorised access to or use of customer information. Note the first verb. Detection comes before response, and detection is an architecture question.

Customer notification as soon as practicable, and not later than 30 days after becoming aware that unauthorised access has occurred or is reasonably likely to have occurred. Thirty days sounds generous until you try to determine which clients were affected.

Service provider oversight, including written contracts requiring providers to notify you of a breach so that you can meet your own notification clock. This is the point where the vendor file from the previous section becomes a Reg S-P control rather than a good practice.

Here is why this belongs in a paper about AI. Every AI tool your firm uses is a path your client data can take. If an incident occurs at an AI vendor, or through one, your ability to notify within 30 days depends entirely on whether you can establish what that tool could reach and what it actually retrieved. A firm that cannot answer that question is not failing an AI rule. It is failing Regulation S-P.

Which is the same problem we wrote about in our paper on permission-aware data access. You cannot scope an incident you cannot reconstruct.

Whether You Supervise the AI You Use

This is the rule that does the work, and it is the one to organise your file around.

For advisers, Rule 206(4)-7 requires written policies and procedures reasonably designed to prevent violations, an annual review of their adequacy and of the effectiveness of their implementation, and a designated chief compliance officer. Both March 2024 AI orders included a 206(4)-7 charge alongside the Marketing Rule charge. That pairing is the template: the false claim breaches the Marketing Rule, and the absence of a compliance program that would have caught it breaches 206(4)-7.

For broker-dealers, Rule 3110 requires a supervisory system reasonably designed to achieve compliance, tailored to the business. FINRA's Regulatory Notice 24-09 put it directly: if a firm is using generative AI as part of its supervisory system, "its policies and procedures should address technology governance, including model risk management, data privacy and integrity, reliability and accuracy of the AI model."

Note the direction of that sentence. It is not only about supervising people who use AI. It is about supervising the AI you have put into your supervisory system, which is a harder problem and one that fewer firms have thought about.

Whether AI Has Changed Your Cyber Risk

The SEC's language here is one clause, quoted in Part 1. FINRA's is far more specific, and if you want a list of what to test your controls against, FINRA's is the one to use.

The 2026 report catalogues generative AI enabled fraud as threat actors "generating fake content (e.g., imposter sites, false identification documents, deepfake audio and video)," creating polymorphic malware, and "leveraging GenAI models to develop malicious tools, allowing those without technical ability to become sophisticated cybercriminals."

In the account fraud section it gets more concrete still, and these three should be tested against your own onboarding and verification procedures:

If your callback verification procedure relies on recognising a client's voice, it was designed for a world that no longer exists. That is a procedure change, not a technology purchase, and it is the cheapest item on any remediation list.

FINRA published separate educational material on prompt injection in March 2026, describing it as an attack that "manipulates a GenAI system that already has legitimate access to your firm's data and systems, exploiting the GenAI system to misuse this authorized access." It cites no rules and prescribes nothing, but it tells you where FINRA's attention is going.

Whether Stated Use Matches Actual Use

The priorities ask whether "operations and controls in place are consistent with disclosures made to investors." In practice this cuts in both directions, and most firms are exposed on the second one.

The first direction is the one everybody knows about, which is claiming AI you do not have. The second is using AI you have not disclosed, have not inventoried and cannot describe.

Schwab's study of 533 advisers who custody with them, fielded in October 2025, found 63% using AI tools in some capacity, with adoption occurring "through individual experimentation rather than firm-wide systems." That is the sentence to worry about. If adoption happened one person at a time, then the firm's description of its own AI use, wherever that description appears, was written without knowing what is actually in use.

The question to ask internally is not whether you have an AI policy. It is whether you could produce a list of every AI tool in use today, including the AI features your existing vendors switched on in a product release you did not read.

Part 3
The Document Request

What is published, what is not, and what to have ready.

What the SEC Has Published, and What It Has Not

A great deal of material circulates describing "what SEC examiners are asking about AI." Before you use any of it, including ours, it is worth knowing what the SEC has actually published.

There is no SEC risk alert on artificial intelligence. The Division of Examinations announcements for 2025 and 2026 cover Regulation S-P, the Marketing Rule, economic conflicts of interest and lost securityholders. The only AI item is a roundtable held in February 2025.

There is no published SEC document request list covering AI. The Division's published request list, in the risk alert of 6 September 2023, contains no mention of artificial intelligence, machine learning, algorithms or automated tools. AI requests arrive under the existing compliance program and information security headings.

The most recent Marketing Rule deficiency guidance, published 16 December 2025, is silent on AI. Its observations concern testimonials, endorsements and third-party ratings. Given that the two flagship AI enforcement actions were Marketing Rule cases, that silence is itself worth noticing.

So where does the list below come from

It is practitioner consensus, assembled from compliance consultants and trade press between January and August 2026, and it is consistent across sources that have no reason to coordinate. It is not published SEC practice, and we are not going to present it as if it were. A compliance officer who takes an unsourced list into a board meeting and is asked where it came from should have a real answer.

The Nine Documents to Have Ready

Each of these has been named by at least one identifiable practitioner source. Taken together they are what a firm should be able to produce without a scramble.

PRACTITIONER CONSENSUS, NOT PUBLISHED SEC PRACTICE 1 AI inventory licensed, individual, and AI embedded in tools you own 2 Acceptable use policy permitted tools, prohibited uses, approval gates 3 Committee minutes written, dated, and showing what was decided 4 Vendor files data handling, retention, security, contract terms 5 Human review records of who reviewed what, and when 6 Training records with completion dates per person 7 Testing records model validation, inputs and outputs reviewed 8 Claims review website, ADV and pitch materials substantiated 9 Incident response updated for AI outage, bad output, data exposure
Figure 7: The nine documents. Assembled from named compliance consultants and trade press through 2026, and consistent across sources.

A few of them deserve comment.

The AI inventory is first for a reason. Everything else refers back to it. It should cover tools your firm licensed, tools individuals adopted, and AI features embedded in products you already owned. That last category is where most inventories are wrong.

The governance committee minutes are the most specific item reported anywhere. Trade press in August 2026 described examiners asking not only whether firms have an AI committee, but whether that committee keeps written minutes. This is second-hand reporting rather than regulator guidance, and we flag it as such, but it is cheap to satisfy and expensive to lack.

Evidence of human review is the item firms consistently think they have and consistently do not. A policy saying that a human reviews AI output before it reaches a client is not evidence that a human did. Part 4 is about that difference.

Vendor files should cover data handling, storage location, retention, security and contract terms for each AI tool. FINRA's suggested contract language, quoted in Part 1, belongs in this file.

Where Firms Are Actually Short

The Investment Management Compliance Testing Survey, run by the Investment Adviser Association with ACA Group and Yuter Compliance Consulting, surveyed 411 adviser firms in April and May 2026 and published in July. It is the best data available on this question, and the shape of it is more interesting than any single number.

Share of 411 adviser firms with each measure in place, April to May 2026 Acceptable use policy 86% Inventory of AI tools 86% AI governance committee 59% Human review procedure 48% Testing and validation of outputs 37% Policy on third-party AI use 30% Incident response updated for AI 14% 0 25% 50% 75% 100% Things you write Things you have to operate
Figure 8: The gap is not between firms that care and firms that do not. It is between the documents a firm can write and the controls it has to run. Source: 2026 Investment Management Compliance Testing Survey.

Eighty-six per cent of firms have an acceptable use policy. Eighty-six per cent maintain an inventory. Then it falls away. Just under half have a documented approach to human review. Thirty-seven per cent have procedures for testing and validating AI outputs. Thirty per cent have policies covering third-party AI use, which is the area FINRA wrote the most concrete guidance about. Fourteen per cent have updated their incident response plans.

The pattern is that firms have done the things you can write and have not done the things you have to operate. That is not a criticism of anyone. Writing an acceptable use policy takes a week and testing model outputs is a standing programme. But it does mean that the average firm's readiness is thinner one layer down than the headline numbers suggest, and an examiner who asks a second question will find that out.

A separate survey of more than 200 compliance and operations professionals, fielded in April 2026, described adoption as "widespread but shallow" and noted that desktop tools such as consumer chatbots dominate rather than embedded, governed systems. Both findings point the same way.

Worth half an hour

If you want to know which of the nine documents your firm could produce today, we will walk your current setup and tell you where the gaps are. You keep the findings either way.

Book a demo
Part 4
The Evidence Problem

Why the second question is harder than the first.

Policies Are Easy, Evidence Is Not

Every item on the list in Part 3 has two versions. There is the document that says what should happen, and there is the record showing that it did.

An examiner asking about AI governance will usually start with the first and move to the second. Do you have an acceptable use policy. Show me. Does it require human review before AI-assisted material reaches a client. It does. Show me a month of that review happening.

The second question is where firms run out of road, and it is not because they were not doing the review. It is because the review left no trace. Someone read the draft, changed two sentences and sent it. There is no record that the draft was AI-assisted, no record of who reviewed it, and no way to distinguish that document from one written entirely by hand.

THE FIRST QUESTION THE SECOND QUESTION Do you have an AI policy? Does it match what people actually use? Does it require human review? Show me a month of it happening. Do you have a vendor list? When did that vendor add AI? Do you train staff on AI? Show me completion records. Almost every firm answers the left column. The right column is decided by systems, not by policy.
Figure 9: The left column is a drafting exercise. The right column is an operating one, and it is where examinations go.

The same gap runs through the whole list. An inventory is a document; keeping it current is a process. A vendor file is a document; knowing that the vendor turned on a new AI feature last quarter is a process. Training records are the exception, which is why almost every firm has them.

This distinction is widely blurred and it is worth getting right, because the version that circulates is more alarming than the version that is true.

FINRA's 2026 report includes, among its effective practices for monitoring generative AI:

Ongoing monitoring of prompts, responses and outputs to confirm the GenAI solution continues to perform as expected and results in compliant behavior. This may include storing prompt and output logs for accountability and troubleshooting; tracking which model version was used and when; and validation and human-in-the-loop review of model outputs, including performing regular checks for errors or bias. FINRA 2026 Annual Regulatory Oversight Report

"May include" is practice guidance inside a discussion of effective controls. It is not a rule, and no regulator has said that AI prompts are books and records. Any vendor telling you that FINRA requires prompt logging is overstating, and a compliance officer who repeats it to their board will be corrected by counsel.

What is true is more ordinary and more useful. Advisers Act Rule 204-2(a)(7) requires originals of written communications received and copies of written communications sent relating to any recommendation made or advice given. FINRA Rule 4511 requires members to preserve for at least six years those books and records with no other specified period, in a format complying with Exchange Act Rule 17a-4. If an AI system produces a written communication relating to advice and it goes to a client, it is a record on ordinary principles, whatever anyone says about prompts.

So the practical position is this. Retaining the client-facing output is a records obligation you already have. Retaining prompts and model versions is a control that a regulator has described as effective practice and that you would want anyway, because it is what lets you answer the second question.

What "Show Me" Looks Like Nine Months Later

Take the awkward version. It is March. An examiner asks about a client report from June, and wants to know whether AI was involved in producing it, who reviewed it, and whether the person who ran it was entitled to the underlying data.

If your systems recorded that at the time, this is a retrieval task. If they did not, you are reconstructing from the current configuration of a system that has changed since, in front of someone whose job is to notice that.

This is the same problem in a different suit as the one we wrote about in our paper on permission-aware data access, where the question is which person the data layer thought was asking. Both come down to whether the system wrote something down at the time, and both are decided by architecture rather than by policy.

Part 5
What To Do Before Your Next Exam

A deadline you set, and a calendar you did not.

Your Annual Review Is the Deadline That Matters

Rule 206(4)-7(b) requires a review, no less frequently than annually, of the adequacy of your policies and procedures and the effectiveness of their implementation. There is no external date attached to it. You chose when it happens.

That review is where the SEC will look first, because it is the only document that shows the firm assessing itself. A 2026 annual review that does not address AI, in a year when 80% of adviser firms report having formally adopted AI tools, is a finding waiting to be written up. It does not need to be long. It needs to show that the question was asked.

Four things belong in it. What AI is in use across the firm and how you know. Whether the policies cover what is actually happening rather than what was anticipated. What testing was performed and what it found. What changed as a result.

The Twelve Months Ahead

Two things worth correcting first, because both appear on calendars that have not been updated.

There are no remaining Regulation S-P compliance dates. Larger entities passed on 3 December 2025 and smaller entities on 3 June 2026. Reg S-P is now an examination subject rather than a countdown, and the SEC's 2026 priorities say the Division will "engage firms during examinations about their progress in preparing incident response programs."

And there is no pending AI rulemaking to prepare for. That remains true.

11 Sep 2026 FINRA RN 26-14 comments close Rule 2210 Oct to Nov 2026 SEC FY2027 priorities expected, not announced Dec 2026 FINRA 2027 report expected 31 Mar 2027 Form ADV annual amendment Your Rule 206(4)-7 annual review · runs throughout, and you set the date No Regulation S-P compliance dates remain. Both passed, in December 2025 and June 2026. No AI rulemaking is pending at the SEC for advisers or broker-dealers.
Figure 10: The only date on this list that you control is the one that matters most.

The item most likely to affect broker-dealers is FINRA's Regulatory Notice 26-14, published 9 July 2026, which proposes replacing mandatory principal pre-use approval of retail communications with a risk-based standard. AI is an express driver: the notice says that "applying the principal pre-use approval requirement to AI-generated retail communications can be challenging," and that firms should ensure generative AI tools are "vetted, tested and monitored."

Be careful about how you describe its status. This is a concept-stage Regulatory Notice, not a filed rule change. After comments close, FINRA staff review, may revise, take a proposal to the FINRA Board, and file with the SEC under Section 19(b) for notice and comment. Twelve to twenty-four months to an effective rule is realistic. Do not plan around it, but do read it, because it tells you what FINRA thinks supervision of AI-generated communications should look like.

One rulemaking that is often confused with it

SR-FINRA-2026-004 is a separate, already-filed Rule 2210 change on projected performance and targeted returns. It was filed in February 2026 and has been through SEC proceedings since. It has no AI content. Commentary regularly conflates the two.

Ten Questions to Test Your Own Readiness

These are ordered so that a firm that cannot answer the first three has found its next project.

  1. Can you produce a current list of every AI tool in use at the firm today? Good: a maintained inventory covering licensed tools, individually adopted tools and AI features inside existing products. Worrying: a list built once during a policy exercise and not updated since.
  2. Does your written AI policy describe what people are actually doing? Good: the policy was revised after the inventory. Worrying: the policy came first and nobody has checked it against reality.
  3. Can you show a month of human review actually happening? Good: records identifying reviewer, date and what was reviewed. Worrying: a policy requiring review, with nothing evidencing it.
  4. Does your 2026 annual review under Rule 206(4)-7 address AI? Good: a section covering what is in use, what was tested and what changed. Worrying: no mention, in a year when most firms adopted AI tools.
  5. For each AI vendor, do you have a file covering data handling, retention and contract terms? Good: a file per tool, including whether firm or client data can be ingested into the vendor's models. Worrying: a signed order form and nothing else.
  6. Do your contracts prohibit your data being used to train a vendor's models? Good: an express clause, and a technical control that enforces it. Worrying: a verbal assurance from a sales representative.
  7. Does every AI claim on your website, in your ADV and in your pitch materials have substantiation on file? Good: a documented basis for each claim, reviewed when the technology changes. Worrying: marketing copy nobody in compliance has read against the Marketing Rule.
  8. Do your identity verification procedures assume voice and video can be trusted? Good: callback and verification procedures redesigned for voice cloning and deepfake selfies. Worrying: "we recognise our clients' voices."
  9. If a client-facing document was AI-assisted, can you tell nine months later? Good: the record identifies the tool, the model version and the reviewer. Worrying: the document is indistinguishable from any other.
  10. Does your incident response plan contemplate an AI-related failure? Good: the plan covers a vendor model outage, a bad output reaching clients, and data exposure through an AI tool. Worrying: you are among the 86% who have not updated it.

How Clarista Helps

Most of what is above is compliance work, and no platform performs it for you. Three of the items are architecture rather than policy, and those are the ones we build.

The inventory stays current because the connections run through one place. When every AI tool and agent reaches firm data through a single governed entry point, the list of what is connected is a property of the system rather than a document somebody maintains.

The evidence is produced by the system, not by the reviewer. Every request records who asked, which agent acted, which policy version applied, what was returned and what was withheld. That is what turns "we require human review" into something you can show a month of.

Data does not leave your boundary. The lake and the infrastructure are yours. The vendor contract question in the list above is easier to answer when the technical control matches the contract term.

Control mapping is generated, not maintained by hand. Our App Deployment Service includes a questionnaire drawing on 23 frameworks, including the FS AI RMF, which produces the specific control objectives your firm needs to apply and then monitor. Firms that want to automate the alignment between AI use and control objectives, rather than keep it in a spreadsheet that ages, should reach out.

If your firm is somewhere in the gap in Figure 8, with the policies written and the operating controls still to build, that gap is the conversation we have most often.

Frequently Asked Questions

How do you ensure AI compliance in financial services?

Apply your existing obligations to AI rather than waiting for new rules: supervise AI use under FINRA Rule 3110 written procedures, protect customer data under Regulation S-P, keep required records of AI-assisted work, inventory your AI systems with named owners, and be able to produce evidence of who accessed what data and who reviewed which output.

Is there an SEC rule on artificial intelligence?

No. In June 2025 the SEC formally withdrew fourteen proposed rules, including Conflicts of Interest Associated with Predictive Data Analytics, which expressly covered AI and machine learning, along with the proposed outsourcing rule and both proposed cybersecurity rules. The withdrawal states that the Commission "does not intend to issue final rules with respect to these proposals." AI is examined and enforced under existing rules, principally Advisers Act Rules 206(4)-7 and 206(4)-1, Section 206, and Regulation S-P.

What do the SEC 2026 examination priorities say about AI?

AI appears substantively in two places. Under cybersecurity, the Division will focus on "training and security controls that firms are employing to identify and mitigate new risks associated with artificial intelligence (AI) and polymorphic malware attacks." Under Emerging Financial Technology, it will "review for accuracy registrant representations regarding their AI capabilities" and assess whether firms have "adequate policies and procedures to monitor and/or supervise their use of AI technologies." Two AI passages present in the 2025 priorities were removed for 2026.

Does FINRA require firms to log AI prompts?

No. FINRA's 2026 report lists prompt and output logging among effective practices, saying monitoring "may include storing prompt and output logs for accountability and troubleshooting." That is practice guidance, not a rule. Separately, if an AI system produces a written communication relating to advice or a recommendation that goes to a client, that communication is a record under existing rules such as Advisers Act Rule 204-2(a)(7) or FINRA Rule 4511, on ordinary principles.

What is AI washing and what has the SEC done about it?

AI washing is overstating a firm's use or capability in artificial intelligence. The term does not appear in the SEC's 2026 examination priorities; it comes from enforcement and commentary. Actions include Delphia and Global Predictions in March 2024, charged under Advisers Act Sections 206(2) and 206(4) and Rules 206(4)-1 and 206(4)-7, with penalties of $225,000 and $175,000; Rimar Capital in October 2024; and Presto Automation in January 2025. The Cyber and Emerging Technologies Unit, created in February 2025, has AI fraud expressly in scope.

What documents will an examiner ask for about AI?

The SEC has published no AI-specific document request list. Practitioner consensus, consistent across compliance consultants and trade press through 2026, points to nine items: an AI inventory, a written acceptable use policy, AI governance committee minutes, vendor due diligence files per tool, evidence of human review, training records, model testing and validation records, a review of AI claims in marketing and Form ADV, and an incident response plan updated for AI.

Does our Form ADV need to disclose that we use AI?

No SEC guidance requires AI-specific disclosure. The obligation derives from the Section 206 fiduciary duty and the Part 2A instructions, particularly Item 4 on advisory business and Item 8 on methods of analysis. The 2025 priorities referenced disclosures to investors in connection with AI integration, and that sentence was removed for 2026. Note the tension: the enforcement actions punished firms for overstating AI, so an elaborate AI disclosure carries its own accuracy risk under the same rules.

When do the FY2027 examination priorities come out?

They had not been published as of early September 2026. The last three were published on 16 October 2023, 21 October 2024 and 17 November 2025, so mid-October to late November 2026 is a reasonable expectation. Earlier cycles were less regular, so treat this as a pattern rather than a schedule.

What is FINRA Regulatory Notice 26-14?

A concept-stage proposal published 9 July 2026 to modernise Rule 2210, replacing mandatory principal pre-use approval of retail communications with a risk-based standard. AI is an express driver, with the notice observing that applying pre-use approval to AI-generated communications "can be challenging." It is not a filed rule change. Any resulting rule would need FINRA Board approval and an SEC filing under Section 19(b), which realistically means twelve to twenty-four months.

Sources and Further Reading

This paper is for general information and is not legal, compliance or investment advice. Regulatory materials are summarised and quoted rather than reproduced in full, and readers should consult the primary sources and their own counsel. Where this paper describes practitioner expectations rather than published regulatory guidance, it says so. Statements about examination practice are drawn from named consultants and trade press, not from the SEC or FINRA. Positions described are accurate as at early September 2026 and this topic moves quickly.