← Blog

FINRA guidance on AI agents, explained for operations teams

What FINRA has said about AI agents through September 2026, which rules apply, and what operations teams at broker-dealers should do before deploying an agent.

FINRA has no rule written specifically for AI agents. Its existing rules, starting with supervision under Rule 3110, apply to agents as they do to any other technology. Its 2026 oversight report names six risks specific to agents.

This guide covers what FINRA has published on AI agents through September 2026 and what it means for operations work: reconciliations, account maintenance, onboarding, and exceptions. It applies to FINRA member broker-dealers, including fintechs with a broker-dealer subsidiary. It is not legal advice.

What has FINRA published about AI agents?

Five publications, in order:

  • June 27, 2024: Regulatory Notice 24-09. FINRA's rules are "technologically neutral," and they apply "whether member firms are directly developing Gen AI tools for their proprietary use or when leveraging the technology of a third party."
  • December 9, 2025: 2026 Annual Regulatory Oversight Report. A new GenAI section discusses AI agents for the first time, lists their risks, and suggests what firms should consider.
  • January 27, 2026: Observations on AI Agents. A blog post by Greg Ruppert, FINRA's Chief Regulatory Operations Officer, describes six types of agents, from conversational agents to trade execution agents, and says firms are moving agentic AI "from conceptual discussion into early practical deployment."
  • March 6, 2026: Understanding GenAI and Prompt Injection Fundamentals. Explains how instructions hidden in websites, documents, or emails can manipulate an AI system that has legitimate access to firm data.
  • July 9, 2026: Regulatory Notice 26-14. Proposes modernizing Rule 2210 on communications with the public, partly because of AI. It states that "members are responsible for their communications, regardless of whether they are generated by a human or AI technology." The comment period closed September 11, 2026.

Which FINRA rules apply to AI agents?

The same rules that apply to the work the agent does. The 2026 report says GenAI "can implicate rules regarding supervision, communications, recordkeeping and fair dealing."

  • Supervision (Rule 3110). A firm must have a reasonably designed supervisory system tailored to its business. If a firm relies on AI tools as part of that system, the report says its policies and procedures "may consider the integrity, reliability and accuracy of the AI model."
  • Communications (Rule 2210). If an agent drafts or sends a customer communication, the firm is still responsible for it. Notice 26-14 says AI communication tools can be part of a reasonably designed supervisory system, "provided they are vetted, tested and monitored."
  • Recordkeeping. The report suggests storing prompt and output logs and tracking which model version was used and when.
  • Third-party vendors. Buying an agent does not move the obligation to the vendor. Notice 24-09 says the rules apply to third-party technology, and the report points firms to Regulatory Notice 21-29 on supervising outsourced functions.

That last point matters most in a buy vs build decision. The firm is responsible either way, so it needs the same visibility into a vendor's agent as into one it built.

Does FINRA require specific controls for AI agents?

No. The oversight report "does not create any new legal or regulatory requirements or new interpretations of existing requirements," and FINRA frames its agent guidance as considerations. The obligation is the existing one: a supervisory system reasonably designed for how the firm works, including the work an agent now does.

In practice, a firm deploying an agent should be able to explain what the agent may do, how the firm knows it does that work correctly, and how a person would catch and stop it when it does not. The same questions explain why most fund managers use AI but few run agents.

What risks does FINRA see in AI agents?

The 2026 report lists six. Here is each in FINRA's words, next to what it looks like in operations work:

Risk FINRA's description What it looks like in operations
Autonomy "AI agents acting autonomously without human validation and approval." An agent clears a reconciliation break or submits an account change that should have gone to a reviewer.
Scope and authority "Agents may act beyond the user's actual or intended scope and authority." An agent asked to update one customer's address can also read or edit other accounts it has access to.
Auditability and transparency Multi-step reasoning "can make outcomes difficult to trace or explain." A supervisor cannot tell which statement the agent relied on when it closed an exception.
Data sensitivity Agents "may unintentionally store, explore, disclose or misuse sensitive or proprietary information." Account numbers end up in a ticket, a log, or a request to an outside service.
Domain knowledge General-purpose agents "may lack the necessary domain knowledge" for industry-specific tasks. An agent treats a partial settlement as a match, or records a missing statement as a zero balance.
Rewards and reinforcement "Misaligned or poorly designed reward functions" can drive decisions that hurt investors, firms, or markets. An agent trained or scored on cases closed learns to close cases rather than resolve them.

The general GenAI risks, including bias, hallucinations, and privacy, still apply. FINRA's March 2026 guidance adds prompt injection: an agent that reads customer emails or uploaded documents can take instructions from whoever wrote them.

What does FINRA suggest firms do about AI agents?

For agents specifically, the report suggests supervisory processes "specific to the type and scope of the AI agent being implemented," and lists four considerations:

  • how to monitor agent system access and data handling;
  • where to have "human in the loop" oversight;
  • how to track agent actions and decisions;
  • how to establish guardrails that limit or restrict agent behaviors, actions, or decisions.

Its practices for GenAI in general apply to agents too: formal review and approval of new uses by business and technology experts; a supervision, governance, or model risk management framework with documentation; "robust testing" of capabilities, limitations, and performance; and ongoing monitoring with prompt and output logs, model version tracking, and human review of outputs.

What should operations teams do before deploying an AI agent?

Turn each FINRA consideration into a control you can show a supervisor or examiner:

  1. Write down the agent's scope: the workflows, systems, accounts, and actions it may touch, and what it must hand to a person.
  2. Give the agent its own credentials, limited to that scope, and enforce the limit outside the model. (Why an authenticated agent still needs limits.)
  3. Decide where a person approves. Common lines: anything that moves money, changes an account record, or reaches a customer.
  4. Log every action with the model version, evidence used, approvals, and resulting changes, so a supervisor can reconstruct any case.
  5. Keep a way to stop the agent mid-task, and decide who can use it.
  6. Test all of it on your own workflows before production. Our guide on how to test AI agents for finance operations covers the cases and attacks to run.
  7. If you buy, get the same evidence from the vendor: action logs, results on your cases, and the right to run your own tests.

None of these is a FINRA requirement. Together, they show that the firm's supervisory system covers the work the agent does.

At Zomma, we build AI agents and custom test environments for financial services operations. Our security page covers how we vault credentials, require human approval, and keep an audit trail.

Raise what your team can do.