FINRA tightens GenAI governance guidance
FINRA expanded its GenAI guidance in its 2026 oversight report, detailing risks, testing, monitoring and supervision for member firms.
FINRA added generative AI to its 2026 Regulatory Oversight Report and outlined risks, testing, monitoring and supervision expectations for member firms.
Update September 20, 2026: FINRA added generative artificial intelligence to its 2026 Regulatory Oversight Report and expanded its discussion of the operational, compliance and recordkeeping risks it sees at member firms. The regulator also strengthened its expectations for governance, testing, human review and continuous monitoring of AI tools.
FINRA released its 2026 Regulatory Oversight Report and included generative artificial intelligence, or GenAI, among the topics covered for member firms in the financial sector. The regulator warned about the autonomy of AI agents, action beyond intended scope, auditability and transparency challenges in multi-step tasks, and possible failures in handling sensitive data.
Governance and model controls
The report recommends that investment firms establish a supervision, governance or model risk management framework specifically for GenAI. That framework should include clear policies and procedures for developing, deploying, using and monitoring these tools, along with full documentation of the model lifecycle.
FINRA also stressed the need to thoroughly test GenAI solutions before deploying them in regulated financial environments. That validation should cover privacy, integrity, reliability and accuracy. It also calls for continuous monitoring of prompts, responses and outputs to confirm behavior stays aligned with rules.
In explanatory materials tied to the report, FINRA leadership said GenAI can create significant operational and compliance risks. It also pointed to robust governance frameworks, continuous monitoring, proactive risk management, and systematic oversight and testing of AI tools as effective practices.
FINRA’s own AI page, updated in 2026, says the GenAI section of the Annual Regulatory Oversight Report is meant to inform member firms’ compliance programs, with annual guidance on applicable regulatory obligations, emerging trends and current practices.
What consultants and law firms saw
Several analyses published after the report said FINRA’s message is more demanding than in prior years. Financial Commission highlighted the need for regular testing and continuous monitoring of GenAI tools, including reviews of prompts, outputs and performance metrics, as part of compliance and oversight programs.
Compliance Week described the report’s GenAI section as a wake-up call for compliance professionals and said firms are now expected to implement formal review and approval processes before deploying GenAI. It also emphasized predeployment testing for privacy, integrity, reliability and accuracy, plus continuous monitoring after rollout.
DLA Piper said FINRA expects at least some level of human oversight and modified quality controls to show that a firm’s Written Supervisory Procedures, or WSPs, are reasonably designed when GenAI is used. The analysis also stressed robust testing for privacy, integrity, reliability and accuracy.
Troutman Pepper said FINRA’s core message remains technology neutrality in its rules, but with a higher level of enterprise oversight for GenAI. It highlighted review of new use cases, GenAI-specific model risk management, testing for accuracy, reliability, privacy and bias, logging of prompts and outputs, and human review in the loop.
Sidley added that FINRA expects firms to assess their regulatory obligations before deploying GenAI and to set up governance frameworks to oversee its use. That analysis also included hallucinations, bias, cybersecurity risks and the use of AI by malicious actors, along with the possibility that autonomous agents will require new oversight models.
McGuireWoods said the report recommends identifying and mitigating risks such as hallucinations and bias, and that FINRA suggests controls and supervision programs tailored specifically to GenAI. That includes robust testing for AI agents, continuous monitoring through output logs and model tracking, and governance that covers use cases, model risk, client communications, vendor diligence, capture of AI-enabled communications in books and records, and technology change management.
Sia Partners reduced those expectations to three pillars, oversight, testing and monitoring, plus corporate governance for AI applications. Its reading focuses on review and approval processes, model risk frameworks, thorough documentation, regular tests for reliability, accuracy, privacy and compliance, and continuous operational monitoring.
How this intersects with books and records
A technical briefing for broker-dealers explained that, under the technology-neutral approach reinforced in the 2026 report, specific supervision and recordkeeping obligations under FINRA Rules 3110 and 4511, along with SEC Rules 17a-4 and 204-2, apply when content generated by tools such as AI meeting notetakers qualifies as business communications that must be supervised and retained.
Another regulatory analysis on banks and broker-dealers said there is no specific AI rulebook in 2026. In that view, the technology-neutral framework rests on existing supervision, communications and books-and-records rules, including FINRA Rules 3110, 2210 and 4511 and the provisions of SEA 17a-3 and 17a-4, plus SEC attention to AI-washing practices and the model risk management frameworks used by banking agencies.
Federal framework in the United States
At the same time, the U.S. Treasury Department released the Financial Services AI Risk Management Framework, or FS AI RMF, and a shared AI Lexicon for the financial sector. Both are part of the president’s AI Action Plan and are meant to set clear standards, with a risk-based governance approach for the safe and responsible use of AI in financial services.
The moves by FINRA and Treasury come amid broader regulatory formalization around technology in finance, with a focus on oversight, model traceability and control of operational and security risks tied to generative AI systems.
Sources
- Financial Data Privacy in the 119th Congresseverycrsreport.com· EveryCRSReport
- U.S. SEC Incident Reporting and Management Oversightsans.org· SANS Institute
- AI in the Crosshairs: New Guidance From FINRA and Treasurytaftlaw.com· Taft Law
- GLBA Penetration Testing Requirementsbudgetsecurity.com· BudgetSecurity
- Navigating the 2026 Regulatory Oversight Report – Key Insights from FINRA Leadershipfinra.org· FINRA
- FINRA Highlights Trends and Risks in Member Firms’ Use of Generative AIfinancialcommission.org· Financial Commission
- FINRA's GenAI wake-up call: What compliance professionals must do nowcomplianceweek.com· Compliance Week
- FINRA flags generative AI risks and governance expectationsdlapiper.com· DLA PiperUnverified URL
- Key Takeaways from FINRA's 2026 Annual Regulatory Oversight Reporttroutman.com· Troutman Pepper
- FINRA Issues 2026 Regulatory Oversight Reportsidley.com· Sidley Austin
- 2026 FINRA Regulatory Oversight Report: Key Insights for GenAI Compliancesia-partners.com· Sia Partners
- FINRA's 2026 GenAI Rules for Broker-Dealers: What the Report Really Requiresbasilai.app· Basil AI
- AI Compliance for Banks: FINRA, SEC & OCC Rules for 2026gainam.com· GainAM
- As Regulators Warn of AI "Hallucinations" in Financial Marketsfinance.yahoo.com· Finance media outlet
- Artificial Intelligence (AI)finra.org· FINRA
- FINRA warns on AI risks and off-channel usefintech.global· Fintech Global
- FINRA Publishes 2026 Regulatory Oversight Report to Empower Member Firm Compliance and Investor Protectionfinra.org· FINRA
- FINRA's 2026 Annual Regulatory Oversight Report: Same Priorities, New Focus on AI and Cybersecuritymcguirewoods.com· McGuireWoods



