Financial Industry Regulatory Authority (FINRA) has been consistent on one point for two years running: it isn't writing new rules for artificial intelligence. It's applying the rules already on the books, such as supervision, communications, recordkeeping, Regulation Best Interest (Reg BI), anti-money laundering (AML), to whatever tool a firm happens to be using, AI included. That's the good news. The bad news is that "no new rules" doesn't mean "no new exposure." It means the burden is on firms to map a fast-moving technology onto a rulebook that wasn't written with it in mind, and to do it before an examiner asks how.

The signal that this is no longer a back-burner issue has gotten louder with each FINRA publication. Regulatory Notice 24-09 reminded members that GenAI implicates essentially the entire rulebook. The 2025 Annual Regulatory Oversight Report added detail on governance and testing expectations. The 2026 Report went further still, adding a standalone GenAI section and, for the first time, explicit guidance on autonomous AI agents: systems that can act on a user's behalf without a human approving each step.

For compliance and legal teams, the practical problem is less "is AI a risk" and more "where exactly does our existing program have gaps." Many firms have “some” AI-related language in their written supervisory procedures (WSP) by now. Far fewer have an inventoried use case list, documented testing for hallucination and bias, supervisory sign-off mapped to Rule 3110, Rule 2210 review applied consistently to AI-drafted communications, vendor due diligence that actually asks how the vendor itself uses GenAI, and a recordkeeping process that captures AI prompts and outputs the same way it captures everything else.

That gap is exactly what we built our checklist to close.

**The AI Usage Controls Checklist for FINRA-Registered Broker-Dealers** organizes 13 control areas involving governance, supervision and WSPs, model risk testing, public communications, recordkeeping, cybersecurity and Regulation S-P (Reg S-P), vendor diligence, AML and fraud, senior investor protection, market integrity, outside business activities, training, and exam readiness into a single working document. Every control item is tied to the specific rule or FINRA guidance behind it, so the checklist doubles as a citation map when it's time to update WSP language or respond to an exam request. It also includes a quick-reference table of the underlying rules (3110, 2210, 4511, Regulation S-P, Regulation S-ID (Reg S-ID), 3310, and more) for anyone who wants the regulatory backbone at a glance.

If your firm hasn't formally inventoried its AI use cases, including the AI that may be quietly embedded in software you've been using for years, that's the place to start and Three Mile Advisors and Tarter Krinsky & Drogin can assist you in performing that analysis.

AI USAGE CONTROLS CHECKLIST

For FINRA-Registered Broker-Dealers

Prepared as a general compliance reference. Reflects FINRA Regulatory Notice 24-09, the 2025 and 2026 FINRA Annual Regulatory Oversight Reports' GenAI guidance, and related FINRA/SEC rules current as of June 2026.

How to Use This Checklist

This checklist translates FINRA's technology-neutral rulebook into concrete controls for firms that build, buy, or otherwise use AI — including generative AI (GenAI), large language models (LLMs), machine learning, and autonomous AI agents — anywhere in the business. FINRA does not regulate AI as a separate category; it applies existing rules (supervision, communications, recordkeeping, Reg BI, AML, outsourcing, cybersecurity) to whatever tool is used, AI included.

Organize your AI inventory by use case (e.g., marketing copy generation, trade surveillance, code generation, customer chatbots, summarization of research) and risk-rate each one. Higher-risk use cases — those touching customer communications, suitability, surveillance, or money movement — warrant the fullest version of these controls; low-risk internal use (e.g., drafting an internal memo) may warrant a lighter touch, but should still be inventoried.

Checkbox items map to a specific control. The citation in parentheses points to the rule or guidance driving that control so your WSPs can reference it directly.

1. Governance & Program Structure

  • Before any AI tool goes into production, the firm needs an enterprise-level framework that owns AI risk the way it owns any other compliance risk.
  • Maintain a written AI governance policy approved by senior management, defining what counts as “AI” for the firm's purposes and who owns the program.  (RN 24-09; 2026 Report, GenAI)
  • Designate a qualified individual or committee (compliance, technology, and business stakeholders) responsible for reviewing and approving new AI use cases before deployment.  (Rule 3110)
  • Maintain a current AI/GenAI use case inventory covering every tool in production, including embedded AI features inside third-party software the firm already uses.  (2026 Report, GenAI)
  • Classify each use case by risk tier (e.g., low/internal vs. high/customer-facing or surveillance-related) and apply review intensity proportionate to that risk.  (2025/2026 Report, GenAI)
  • Define and document prohibited use cases (e.g., AI providing unsupervised investment recommendations directly to retail customers) and confirm none are in production.  (2025 Report, GenAI)
  • Require compliance and legal sign-off before procuring, building, or materially modifying any AI tool used in the business.  (Rule 3110)
  • Review and update the AI governance policy at least annually, or whenever a new high-risk use case or material model change is introduced.  (Rule 3110)
  • Incorporate AI-specific risks into the firm's annual risk assessment used to build its WSPs.  (Rule 3110)

2. Supervision & Written Supervisory Procedures (WSPs)

Rule 3110 requires a reasonably designed supervisory system tailored to the firm's business — and FINRA has been explicit that this extends to AI-assisted and AI-driven workflows, including autonomous agents.

  • Document, in WSPs, exactly how each AI use case fits into the supervisory system: what it does, who supervises it, and how exceptions are escalated.  (Rule 3110; RN 24-09)
  • Assign a registered principal with the requisite knowledge to supervise each material AI use case (not a generic “Information Technology (IT) owns it” arrangement).  (Rule 3110)
  • For AI used in supervision/surveillance itself (e.g., reviewing electronic communications), document the model's integrity, reliability, and accuracy as part of the supervisory system design.  (RN 24-09)
  • Require human-in-the-loop review for any AI output that affects a customer, a regulatory filing, or a supervisory determination — do not allow fully automated sign-off on these.  (2026 Report, GenAI)
  • For autonomous AI agents, implement controls on system access, data handling permissions, and the scope of actions the agent may take without further human approval.  (2026 Report, GenAI)
  • Establish guardrails limiting agent autonomy (e.g., approval gates before the agent executes a transaction, sends a communication, or modifies a record).  (2026 Report, GenAI)
  • Test AI-driven supervisory tools initially and periodically thereafter to confirm they are catching what a human reviewer would catch (false-negative testing), not just efficiency gains.  (RN 24-09)
  • Document escalation procedures for when an AI tool's output is overridden, flagged as wrong, or fails — including who is notified and how the issue is remediated.  (Rule 3110)

3. Model Risk Management & Testing

AI-specific failure modes — hallucination and bias chief among them — need their own testing regime, not just standard software quality assurance (QA).

  • Test each AI tool prior to deployment for accuracy, reliability, and consistency against known-correct answers relevant to its use case.  (2026 Report, GenAI)
  • Specifically test for hallucinations — confident but factually wrong outputs — particularly where the tool touches regulatory analysis, customer communications, or product information.  (2026 Report, GenAI)
  • Specifically test for bias arising from limited, outdated, or unrepresentative training data, especially in any tool influencing customer-facing outcomes.  (2025/2026 Report, GenAI)
  • Re-test after any material model update, including vendor-side model version changes the firm did not initiate.  (2026 Report, GenAI)
  • Track which model/model version was used for each output, so results can be reproduced or investigated later.  (2026 Report, GenAI)
  • Log prompts and outputs for material use cases to support accountability, troubleshooting, and exam response.  (2026 Report, GenAI)
  • Conduct ongoing (not just pre-launch) monitoring of production AI outputs, with periodic sampling and human review for errors or drift.  (2026 Report, GenAI)
  • Set and document clear accuracy/quality thresholds for each use case, below which the tool is pulled from production pending remediation.  (2026 Report, GenAI)

4. Communications with the Public (Rule 2210/Reg BI)

FINRA has been unambiguous: Rule 2210 governs AI-generated public-facing content exactly as it governs human-drafted content — there is no AI carve-out for accuracy, balance, or disclosure.

  • Route all AI-generated or AI-assisted marketing, advertising, and retail communications through the same Rule 2210 principal review and approval process as human-drafted content.  (RN 24-09; Rule 2210)
  • Confirm AI-generated content meets Rule 2210 standards for fair, balanced, and not misleading presentation — including AI-drafted social media posts and chatbot scripts.  (RN 24-09)
  • Supervise and archive chatbot/virtual-assistant interactions with customers the same way other electronic communications are supervised and archived.  (2026 Report, GenAI)
  • Ensure any firm statement describing its own use of AI (in marketing or disclosures) accurately reflects how the technology is actually used, including limitations and risks — avoid 'AI-washing.'  (2025 Report, GenAI; FINRA Advertising FAQ)
  • Prohibit or tightly control AI tools that would generate direct, unsupervised investment recommendations to retail customers without principal review.  (2025 Report, GenAI)
  • Review AI-generated customized research or sentiment-analysis content given to customers for data quality, source reliability, and suitability before distribution.  (2025 Report, GenAI)
  • Confirm Reg BI/Form CRS obligations are met when AI tools influence what is recommended or disclosed to retail customers, including documentation of the basis for any AI-assisted recommendation.  (Reg BI)

5. Recordkeeping

AI-generated and AI-assisted records are still books and records — they don't get a lighter retention standard because a model produced them.

  • Capture and retain AI-generated communications, prompts, and outputs that constitute books and records under the same retention schedule as other records.  (SEC Rule 17a-4; FINRA Rule 4511)
  • Confirm the firm's existing WORM/retention infrastructure actually captures AI tool outputs and chat logs — don't assume a new tool is automatically in scope of the archiving system.  (Rule 4511)
  • Retain logs of prompts and outputs (not just final deliverables) for higher-risk use cases, to support reconstruction of how an output was produced.  (2026 Report, GenAI)
  • Address off-channel or unsanctioned AI tool use (e.g., employees using personal AI accounts for work communications) explicitly in recordkeeping policy and training.  (2026 Report, Books & Records)
  • Confirm retention obligations are met even when the AI tool is hosted by a third-party vendor, including on contract termination (data return/destruction terms).  (Rule 4511; RN 21-29)

6. Data Privacy, Cybersecurity & Reg S-P

Feeding customer or firm data into an AI model is a data-handling event subject to the same safeguarding obligations as any other system that touches that data.

  • Conduct a data-flow review before deployment: what customer or firm data, if any, the AI tool ingests, stores, or uses for further model training.  (Reg S-P Rule 30)
  • Confirm vendor contracts prohibit use of firm/customer data to train the vendor's models for other customers, unless explicitly agreed and risk-assessed.  (Reg S-P; RN 21-29)
  • Maintain written policies addressing administrative, technical, and physical safeguards for customer information processed by AI tools, consistent with Reg S-P.  (Reg S-P Rule 30)
  • Confirm the firm's incident response program explicitly covers AI-related incidents (e.g., data leakage through a model, prompt injection exposing customer data).  (Reg S-P (2024 amendments))
  • Assess whether cybersecurity programs adequately address AI as both an attack surface and an attack tool (e.g., AI-generated phishing, deepfake voice/video, synthetic identities used in account-opening fraud).  (2026 Report, GenAI & Cyber)
  • Implement stronger authentication and anomaly detection where GenAI may accelerate account-takeover or new-account fraud risk.  (2026 Report, Cyber)
  • Maintain a written identity theft prevention program (Reg S-ID) updated to reflect AI-enabled identity fraud techniques (e.g., synthetic IDs, deepfakes).  (Reg S-ID)

7. Third-Party Vendor & Outsourcing Due Diligence

Using a vendor's AI — including an AI feature embedded in software the firm already licenses — does not transfer the firm's regulatory responsibility to the vendor.

  • Conduct initial and ongoing due diligence on any vendor providing AI tools, specifically evaluating the vendor's own use of GenAI within the product.  (2026 Report, Third-Party Risk)
  • Confirm vendor contracts include data protection terms, audit rights, and clear allocation of responsibility for model errors or outages.  (2026 Report, Third-Party Risk)
  • Maintain an inventory of all vendor-provided AI systems, software versions in use, and what firm/customer data each vendor can access or store.  (2026 Report, Third-Party Risk; RN 21-29)
  • Assess and document the potential impact of a vendor cybersecurity incident on the firm's AI-dependent functions, and build contingency plans accordingly.  (2026 Report, Third-Party Risk)
  • Evaluate fourth-party risk — i.e., the sub-vendors and model providers your AI vendor itself relies on.  (2026 Report, Third-Party Risk)
  • On contract termination, confirm firm data is returned or destroyed and vendor access is promptly revoked.  (2026 Report, Third-Party Risk)
  • Remember outsourcing an activity to an AI vendor does not outsource the firm's supervisory or regulatory obligation for that activity.  (RN 21-29; Rule 3110)

8. AML, Fraud & Sanctions

Both sides of this risk matter: AI is increasingly a target/tool for bad actors, and AI is increasingly used by firms to detect them. Both uses need controls.

  • Update AML surveillance program risk assessments to account for GenAI-enabled fraud typologies (deepfake-assisted identity verification, AI-written phishing, synthetic documents).  (FINRA Rule 3310; 2026 Report)
  • If using AI/ML for transaction monitoring or suspicious activity detection, validate that alert thresholds and model logic are tailored to the firm's actual risk profile (not a vendor's generic default).  (Rule 3310; 2026 Report, AML)
  • Ensure alert review and investigation resourcing is adequate to handle AI-flagged alerts without rubber-stamping or backlog-driven dismissal.  (2026 Report, AML)
  • Train staff to recognize AI-enabled social engineering (voice cloning, deepfake video calls, highly personalized phishing) targeting employees or customers.  (2026 Report, Cyber & Fraud)
  • Confirm escalation procedures route AI-detected red flags to the AML function even when first identified outside it (e.g., by a customer service AI tool).  (2026 Report, AML)
  • Address AI-enabled new-account fraud and account-takeover risk in onboarding/KYC controls, including detection of synthetic or deepfake identity documents.  (2025/2026 Report, GenAI & Cyber)

9. Senior Investors & Vulnerable Clients

AI-driven personalization and fraud both intersect with FINRA's ongoing focus on protecting senior and vulnerable customers.

  • If AI tools are used to personalize outreach or product suggestions, confirm they do not exploit diminished capacity or override suitability-based safeguards for vulnerable clients.  (Reg BI; 2026 Report)
  • Ensure trusted contact person disclosures and collection processes (Rule 4512) are unaffected by — and not bypassed by — AI-driven account servicing tools.  (FINRA Rule 4512)
  • Confirm temporary hold procedures (Rule 2165) remain principal-driven and are not automated away by an AI tool without documented human judgment.  (FINRA Rule 2165)
  • Train staff on AI-enabled elder fraud schemes (e.g., deepfake voice calls impersonating family members) as part of escalation playbooks.  (2026 Report, Senior Investors)

10. Market Integrity & Trading Use Cases

Where AI touches order handling, pricing, or trading, the existing market-conduct rulebook applies in full.

  • If AI/ML models inform trading strategies or order routing, validate that outputs cannot result in manipulative or disruptive trading patterns under Rules 5210, 5270, 6140, and related rules.  (FINRA Rules 2020, 5210, 5270, 6140)
  • Confirm best execution analysis and order routing disclosures remain accurate and explainable when AI tools are involved in routing decisions.  (Best Execution; CAT reporting rules)
  • Ensure AI-assisted Consolidated Audit Trail (CAT) reporting processes are tested for completeness, accuracy, and timeliness, with human oversight of error correction.  (CAT reporting rules; 2026 Report)
  • Apply heightened surveillance where AI is used in fixed income fair-pricing analysis or market access risk controls, validating model outputs against independent benchmarks.  (Market Access Rule; 2026 Report)

11. Outside Business Activities & Conflicts of Interest

AI tools used by registered persons outside firm-sanctioned channels create the same OBA/PST and conflicts exposure as any other unsupervised activity.

  • Confirm policy explicitly addresses registered persons' personal use of public AI tools (e.g., personal ChatGPT accounts) for any work-related purpose.  (2026 Report; Rules 3270/3280)
  • Reinforce in training that using AI to assist with an undisclosed private securities transaction or outside business activity does not exempt it from disclosure obligations.  (FINRA Rules 3270, 3280)
  • Review conflicts-of-interest disclosures to ensure they account for any AI-driven product steering, recommendation weighting, or revenue-influenced outputs.  (Reg BI; 2026 Report)

12. Training & Culture

Controls on paper don't help if the people using the tools don't understand the limits.

  • Provide AI-specific training as part of annual compliance training, covering firm policy, prohibited uses, and how to recognize and escalate hallucinations or errors.  (2026 Report; Rule 3110)
  • Tailor training by role — registered representatives, supervisors, and compliance staff need different depth on AI risk recognition and escalation.  (2026 Report)
  • Update training content as new use cases, business lines, or AI agent deployments are introduced — treat this as a living program, not an annual checkbox.  (2026 Report)
  • Train staff explicitly that 'the AI said so' is never an adequate basis for a recommendation, disclosure, or compliance determination — human judgment and sign-off remain required.  (Rule 3110; RN 24-09)
  • Include case studies/examples of AI hallucination, bias, or fraud incidents (internal or industry) in training to make the risk concrete.  (2026 Report)

13. Ongoing Monitoring, Audit & Exam Readiness

Treat the AI program the way you'd treat any other area FINRA actively examines — because it now is one.

  • Include AI use cases in the scope of the firm's annual compliance program review (Rule 3120) and CEO certification process (Rule 3130).  (FINRA Rules 3120, 3130)
  • Periodically audit a sample of AI outputs across use cases for accuracy, tone, bias, and compliance with firm policy — not just at launch.  (2026 Report, GenAI)
  • Maintain documentation sufficient to demonstrate to an examiner how each AI use case was evaluated, approved, tested, and is being monitored.  (2026 Report, GenAI)
  • Map the firm's AI controls against FINRA's Annual Regulatory Oversight Report each year and document the gap analysis performed.  (2026 Report, Appendix)
  • Consider voluntary alignment with the NIST AI Risk Management Framework as an organizing structure for the points above, even though it is not a FINRA mandate.  (NIST AI RMF 1.0)

Quick-Reference: Key Rules & Guidance Cited

Use this table to anchor each control above to a specific rule or regulatory notice when drafting or updating WSP language.

Rule / Guidance

Why It Matters for AI Use

FINRA Regulatory Notice 24-09 (Jun. 2024)

Foundational reminder that all FINRA rules apply to AI/GenAI use; technology-neutral framework.

FINRA 2025 & 2026 Annual Regulatory Oversight Reports

Most detailed current FINRA guidance on GenAI governance, testing, monitoring, and AI agents.

FINRA Rule 3110 (Supervision)

Requires a reasonably designed supervisory system covering any AI used in the business.

FINRA Rule 2210 (Communications with the Public)

Governs AI-generated or AI-assisted public communications, regardless of who/what created them.

FINRA Rule 4511 / SEC Rule 17a-4

Books and records retention requirements apply to AI-generated records and communications.

Regulation S-P (incl. 2024 amendments)

Safeguarding customer information; incident response and notification requirements.

Regulation S-ID

Identity theft red flags program, relevant to AI-enabled identity fraud.

FINRA Rule 3310 (AML)

AML program obligations, including AI-enabled fraud typologies.

FINRA Rules 4512 / 2165

Trusted contact persons and temporary holds for vulnerable/senior investors.

FINRA Rules 3270 / 3280

Outside business activities and private securities transactions, including AI-facilitated ones.

FINRA Regulatory Notice 21-29

Supervisory obligations when outsourcing to third-party vendors, including AI vendors.

NIST AI Risk Management Framework (AI RMF 1.0)

Voluntary framework FINRA has referenced as a useful organizing structure.

Disclaimer: This checklist is a general compliance reference based on publicly available FINRA guidance as of June 2026. It does not constitute legal advice and does not cover every rule that may apply to a specific firm's business model (e.g., investment adviser dual registration, state-level requirements, or SEC rules outside those cited). Firms should validate this checklist against their own risk assessment and counsel before incorporating it into WSPs.

Stablecoins Just Got a Lot Cheaper to Hold: What the New 2% Haircut Means for Your Net Capital

For years, broker-dealers that wanted a proprietary position in a stablecoin faced a capital problem. Rule 15c3-1 has never explicitly addressed stablecoins, and in the absence of guidance, many firms did what cautious FinOps do with regulatory silence: they assumed the worst. A 100% haircut — treating the position as worthless for net capital purposes — was the conservative default at a number of firms, even though the underlying reserves backing those tokens looked a lot like the cash and short-term Treasuries sitting in a money market fund.

That math just changed.

Because broker-dealers must deduct applicable haircuts when calculating net capital, the percentage assigned to an asset directly affects how much regulatory capital the firm must maintain.  On February 19, 2026, the SEC’s Division of Trading and Markets updated its crypto FAQ to address exactly this gap. The staff stated it will not object if a broker-dealer treats a proprietary position in a qualifying “payment stablecoin” as having a “ready market” under Rule 15c3-1 and applies a 2% haircut — calculated on the market value of the greater of the long or short position, not netted — when computing net capital. Put simply: a $100 proprietary stablecoin position now counts as $98 toward net capital, not $0.

A few details worth noting:

It’s staff guidance, not a rule change. This is FAQ-level relief from SEC staff, not formal rulemaking. Commissioner Hester Peirce, who has been vocal that a 100% haircut was “unnecessarily punitive,” said she’d like to see Rule 15c3-1 formally amended to address stablecoins directly — but for now, firms are relying on a “we will not object” position. That’s meaningfully softer ground than a codified rule, and worth flagging in any capital adequacy memo.

The definition of “payment stablecoin” is doing a lot of work. The FAQ ties the 2% treatment to a specific definition — currently keyed to attestation standards around reserve composition, and after the GENIUS Act’s effective date, to stablecoins meeting that Act’s definition and issued by a “permitted” or “foreign” payment stablecoin issuer. Not every token marketed as a “stablecoin” will qualify. Treating a non-qualifying token under this favorable haircut would be a net capital miscalculation — exactly the kind of finding FINRA exam staff look for.

The “greater of long or short” detail isn’t a technicality. The haircut applies to whichever side of the position is larger; firms can’t reduce their capital charge by netting offsetting exposures on paper.

This lands squarely in FINRA’s existing net capital scrutiny. FINRA doesn’t need a new rule to examine this — net capital miscalculations, haircut misapplication, and inadequate processes for classifying nonmarketable or non-qualifying assets are already recurring findings in FINRA’s oversight reports. A firm claiming the 2% rate on a stablecoin that doesn’t meet the FAQ’s definition is the kind of “incorrect haircut” issue examiners have flagged before — just with a new asset class attached.

For broker-dealers already active in crypto, or weighing whether a stablecoin proprietary position makes sense, this guidance meaningfully narrows the capital cost of doing so. But “narrowed” isn’t “eliminated,” and the relief is only as good as the firm’s process for confirming, position by position, that what it’s holding actually meets the FAQ’s definition of a qualifying payment stablecoin.

Draft Newsletter

FINRA Isn't Writing New AI Rules. That's the Problem.

FINRA has been consistent on one point for two years running: it isn't writing new rules for artificial intelligence. It's applying the rules already on the books, such as  Supervision, Communications, Recordkeeping, Reg BI, AML, to whatever tool a firm happens to be using, AI included. That's the good news. The bad news is that "no new rules" doesn't mean "no new exposure." It means the burden is on firms to map a fast-moving technology onto a rulebook that wasn't written with it in mind, and to do it before an examiner asks how.

The signal that this is no longer a back-burner issue has gotten louder with each FINRA publication. Regulatory Notice 24-09 reminded members that GenAI implicates essentially the entire rulebook. The 2025 Annual Regulatory Oversight Report added detail on governance and testing expectations. The 2026 Report  went further still, adding a standalone GenAI section and, for the first time, explicit guidance on autonomous AI agents: systems that can act on a user's behalf without a human approving each step.

For compliance and legal teams, the practical problem is less "is AI a risk" and more "where exactly does our existing program have gaps." Many firms have “some” AI-related language in their WSPs by now. Far fewer have an inventoried use case list, documented testing for hallucination and bias, supervisory sign-off mapped to Rule 3110, Rule 2210 review applied consistently to AI-drafted communications, vendor due diligence that actually asks how the vendor itself uses GenAI, and a recordkeeping process that captures AI prompts and outputs the same way it captures everything else.

That gap is exactly what we built our checklist to close.

**The AI Usage Controls Checklist for FINRA-Registered Broker-Dealers** organizes 13 control areas involving governance, supervision and WSPs, model risk testing, public communications, recordkeeping, cybersecurity and Reg S-P, vendor diligence, AML and fraud, senior investor protection, market integrity, outside business activities, training, and exam readiness into a single working document. Every control item is tied to the specific rule or FINRA guidance behind it, so the checklist doubles as a citation map when it's time to update WSP language or respond to an exam request. It also includes a quick-reference table of the underlying rules (3110, 2210, 4511, Reg S-P, Reg S-ID, 3310, and more) for anyone who wants the regulatory backbone at a glance.

If your firm hasn't formally inventoried its AI use cases, including the AI that may be quietly embedded in software you've been using for years, that's the place to start and Three Mile Advisors and Tarter Krinsky &Drogin can assist you in performing that analysis.

AI USAGE CONTROLS CHECKLIST

For FINRA-Registered Broker-Dealers

Prepared as a general compliance reference. Reflects FINRA Regulatory Notice 24-09, the 2025 and 2026 FINRA Annual Regulatory Oversight Reports' GenAI guidance, and related FINRA/SEC rules current as of June 2026.

How to Use This Checklist

This checklist translates FINRA's technology-neutral rulebook into concrete controls for firms that build, buy, or otherwise use AI — including generative AI (GenAI), large language models (LLMs), machine learning, and autonomous AI agents — anywhere in the business. FINRA does not regulate AI as a separate category; it applies existing rules (Supervision, Communications, Recordkeeping, Reg BI, AML, Outsourcing, Cybersecurity) to whatever tool is used, AI included.

Organize your AI inventory by use case (e.g., marketing copy generation, trade surveillance, code generation, customer chatbots, summarization of research) and risk-rate each one. Higher-risk use cases — those touching customer communications, suitability, surveillance, or money movement — warrant the fullest version of these controls; low-risk internal use (e.g., drafting an internal memo) may warrant a lighter touch, but should still be inventoried.

Checkbox items map to a specific control. The citation in parentheses points to the rule or guidance driving that control so your WSPs can reference it directly.

1. Governance & Program Structure

Before any AI tool goes into production, the firm needs an enterprise-level framework that owns AI risk the way it owns any other compliance risk.

  • Maintain a written AI governance policy approved by senior management, defining what counts as 'AI' for the firm's purposes and who owns the program.  (RN 24-09; 2026 Report, GenAI)
  • Designate a qualified individual or committee (compliance, technology, and business stakeholders) responsible for reviewing and approving new AI use cases before deployment.  (Rule 3110)
  • Maintain a current AI/GenAI use case inventory covering every tool in production, including embedded AI features inside third-party software the firm already uses.  (2026 Report, GenAI)
  • Classify each use case by risk tier (e.g., low/internal vs. high/customer-facing or surveillance-related) and apply review intensity proportionate to that risk.  (2025/2026 Report, GenAI)
  • Define and document prohibited use cases (e.g., AI providing unsupervised investment recommendations directly to retail customers) and confirm none are in production.  (2025 Report, GenAI)
  • Require compliance and legal sign-off before procuring, building, or materially modifying any AI tool used in the business.  (Rule 3110)
  • Review and update the AI governance policy at least annually, or whenever a new high-risk use case or material model change is introduced.  (Rule 3110)
  • Incorporate AI-specific risks into the firm's annual risk assessment used to build its WSPs.  (Rule 3110)

2. Supervision & Written Supervisory Procedures (WSPs)

Rule 3110 requires a reasonably designed supervisory system tailored to the firm's business — and FINRA has been explicit that this extends to AI-assisted and AI-driven workflows, including autonomous agents.

  • Document, in WSPs, exactly how each AI use case fits into the supervisory system: what it does, who supervises it, and how exceptions are escalated.  (Rule 3110; RN 24-09)
  • Assign a registered principal with the requisite knowledge to supervise each material AI use case (not a generic 'IT owns it' arrangement).  (Rule 3110)
  • For AI used in supervision/surveillance itself (e.g., reviewing electronic communications), document the model's integrity, reliability, and accuracy as part of the supervisory system design.  (RN 24-09)
  • Require human-in-the-loop review for any AI output that affects a customer, a regulatory filing, or a supervisory determination — do not allow fully automated sign-off on these.  (2026 Report, GenAI)
  • For autonomous AI agents, implement controls on system access, data handling permissions, and the scope of actions the agent may take without further human approval.  (2026 Report, GenAI)
  • Establish guardrails limiting agent autonomy (e.g., approval gates before the agent executes a transaction, sends a communication, or modifies a record).  (2026 Report, GenAI)
  • Test AI-driven supervisory tools initially and periodically thereafter to confirm they are catching what a human reviewer would catch (false-negative testing), not just efficiency gains.  (RN 24-09)
  • Document escalation procedures for when an AI tool's output is overridden, flagged as wrong, or fails — including who is notified and how the issue is remediated.  (Rule 3110)

3. Model Risk Management & Testing

AI-specific failure modes — hallucination and bias chief among them — need their own testing regime, not just standard software QA.

  • Test each AI tool prior to deployment for accuracy, reliability, and consistency against known-correct answers relevant to its use case.  (2026 Report, GenAI)
  • Specifically test for hallucinations — confident but factually wrong outputs — particularly where the tool touches regulatory analysis, customer communications, or product information.  (2026 Report, GenAI)
  • Specifically test for bias arising from limited, outdated, or unrepresentative training data, especially in any tool influencing customer-facing outcomes.  (2025/2026 Report, GenAI)
  • Re-test after any material model update, including vendor-side model version changes the firm did not initiate.  (2026 Report, GenAI)
  • Track which model/model version was used for each output, so results can be reproduced or investigated later.  (2026 Report, GenAI)
  • Log prompts and outputs for material use cases to support accountability, troubleshooting, and exam response.  (2026 Report, GenAI)
  • Conduct ongoing (not just pre-launch) monitoring of production AI outputs, with periodic sampling and human review for errors or drift.  (2026 Report, GenAI)
  • Set and document clear accuracy/quality thresholds for each use case, below which the tool is pulled from production pending remediation.  (2026 Report, GenAI)

4. Communications with the Public (Rule 2210 / Reg BI)

FINRA has been unambiguous: Rule 2210 governs AI-generated public-facing content exactly as it governs human-drafted content — there is no AI carve-out for accuracy, balance, or disclosure.

  • Route all AI-generated or AI-assisted marketing, advertising, and retail communications through the same Rule 2210 principal review and approval process as human-drafted content.  (RN 24-09; Rule 2210)
  • Confirm AI-generated content meets Rule 2210 standards for fair, balanced, and not misleading presentation — including AI-drafted social media posts and chatbot scripts.  (RN 24-09)
  • Supervise and archive chatbot/virtual-assistant interactions with customers the same way other electronic communications are supervised and archived.  (2026 Report, GenAI)
  • Ensure any firm statement describing its own use of AI (in marketing or disclosures) accurately reflects how the technology is actually used, including limitations and risks — avoid “AI-washing.”  (2025 Report, GenAI; FINRA Advertising FAQ)
  • Prohibit or tightly control AI tools that would generate direct, unsupervised investment recommendations to retail customers without principal review.  (2025 Report, GenAI)
  • Review AI-generated customized research or sentiment-analysis content given to customers for data quality, source reliability, and suitability before distribution.  (2025 Report, GenAI)
  • Confirm Reg BI/Form customer relationship summary (CRS) obligations are met when AI tools influence what is recommended or disclosed to retail customers, including documentation of the basis for any AI-assisted recommendation.  (Reg BI)

5. Recordkeeping

AI-generated and AI-assisted records are still books and records — they don't get a lighter retention standard because a model produced them.

  • Capture and retain AI-generated communications, prompts, and outputs that constitute books and records under the same retention schedule as other records.  (SEC Rule 17a-4; FINRA Rule 4511)
  • Confirm the firm's existing write once, read many (WORM)/retention infrastructure actually captures AI tool outputs and chat logs — don't assume a new tool is automatically in scope of the archiving system.  (Rule 4511)
  • Retain logs of prompts and outputs (not just final deliverables) for higher-risk use cases, to support reconstruction of how an output was produced.  (2026 Report, GenAI)
  • Address off-channel or unsanctioned AI tool use (e.g., employees using personal AI accounts for work communications) explicitly in recordkeeping policy and training.  (2026 Report, Books & Records)
  • Confirm retention obligations are met even when the AI tool is hosted by a third-party vendor, including on contract termination (data return/destruction terms).  (Rule 4511; RN 21-29)

6. Data Privacy, Cybersecurity & Reg S-P

Feeding customer or firm data into an AI model is a data-handling event subject to the same safeguarding obligations as any other system that touches that data.

  • Conduct a data-flow review before deployment: what customer or firm data, if any, the AI tool ingests, stores, or uses for further model training.  (Reg S-P Rule 30)
  • Confirm vendor contracts prohibit use of firm/customer data to train the vendor's models for other customers, unless explicitly agreed and risk-assessed.  (Reg S-P; RN 21-29)
  • Maintain written policies addressing administrative, technical, and physical safeguards for customer information processed by AI tools, consistent with Reg S-P.  (Reg S-P Rule 30)
  • Confirm the firm's incident response program explicitly covers AI-related incidents (e.g., data leakage through a model, prompt injection exposing customer data).  (Reg S-P (2024 amendments)
  • Assess whether cybersecurity programs adequately address AI as both an attack surface and an attack tool (e.g., AI-generated phishing, deepfake voice/video, synthetic identities used in account-opening fraud).  (2026 Report, GenAI & Cyber)
  • Implement stronger authentication and anomaly detection where GenAI may accelerate account-takeover or new-account fraud risk.  (2026 Report, Cyber)
  • Maintain a written identity theft prevention program (Reg S-ID) updated to reflect AI-enabled identity fraud techniques (e.g., synthetic IDs, deepfakes).  (Reg S-ID)

7. Third-Party Vendor & Outsourcing Due Diligence

Using a vendor's AI — including an AI feature embedded in software the firm already licenses — does not transfer the firm's regulatory responsibility to the vendor.

  • Conduct initial and ongoing due diligence on any vendor providing AI tools, specifically evaluating the vendor's own use of GenAI within the product.  (2026 Report, Third-Party Risk)
  • Confirm vendor contracts include data protection terms, audit rights, and clear allocation of responsibility for model errors or outages.  (2026 Report, Third-Party Risk)
  • Maintain an inventory of all vendor-provided AI systems, software versions in use, and what firm/customer data each vendor can access or store.  (2026 Report, Third-Party Risk; RN 21-29)
  • Assess and document the potential impact of a vendor cybersecurity incident on the firm's AI-dependent functions, and build contingency plans accordingly.  (2026 Report, Third-Party Risk)
  • Evaluate fourth-party risk — i.e., the sub-vendors and model providers your AI vendor itself relies on.  (2026 Report, Third-Party Risk)
  • On contract termination, confirm firm data is returned or destroyed and vendor access is promptly revoked.  (2026 Report, Third-Party Risk)
  • Remember outsourcing an activity to an AI vendor does not outsource the firm's supervisory or regulatory obligation for that activity.  (RN 21-29; Rule 3110)

8. AML, Fraud & Sanctions

Both sides of this risk matter: AI is increasingly a target/tool for bad actors, and AI is increasingly used by firms to detect them. Both uses need controls.

  • Update AML surveillance program risk assessments to account for GenAI-enabled fraud typologies (deepfake-assisted identity verification, AI-written phishing, synthetic documents).  (FINRA Rule 3310; 2026 Report)
  • If using AI/machine learning (ML) for transaction monitoring or suspicious activity detection, validate that alert thresholds and model logic are tailored to the firm's actual risk profile (not a vendor's generic default).  (Rule 3310; 2026 Report, AML)
  • Ensure alert review and investigation resourcing is adequate to handle AI-flagged alerts without rubber-stamping or backlog-driven dismissal.  (2026 Report, AML)
  • Train staff to recognize AI-enabled social engineering (voice cloning, deepfake video calls, highly personalized phishing) targeting employees or customers.  (2026 Report, Cyber & Fraud)
  • Confirm escalation procedures route AI-detected red flags to the AML function even when first identified outside it (e.g., by a customer service AI tool).  (2026 Report, AML)
  • Address AI-enabled new-account fraud and account-takeover risk in onboarding/know your customer (KYC) controls, including detection of synthetic or deepfake identity documents.  (2025/2026 Report, GenAI & Cyber)

9. Senior Investors & Vulnerable Clients

AI-driven personalization and fraud both intersect with FINRA's ongoing focus on protecting senior and vulnerable customers.

  • If AI tools are used to personalize outreach or product suggestions, confirm they do not exploit diminished capacity or override suitability-based safeguards for vulnerable clients.  (Reg BI; 2026 Report)
  • Ensure trusted contact person disclosures and collection processes (Rule 4512) are unaffected by — and not bypassed by — AI-driven account servicing tools.  (FINRA Rule 4512)
  • Confirm temporary hold procedures (Rule 2165) remain principal-driven and are not automated away by an AI tool without documented human judgment.  (FINRA Rule 2165)
  • Train staff on AI-enabled elder fraud schemes (e.g., deepfake voice calls impersonating family members) as part of escalation playbooks.  (2026 Report, Senior Investors)

10. Market Integrity & Trading Use Cases

Where AI touches order handling, pricing, or trading, the existing market-conduct rulebook applies in full.

  • If AI/ML models inform trading strategies or order routing, validate that outputs cannot result in manipulative or disruptive trading patterns under Rules 5210, 5270, 6140, and related rules.  (FINRA Rules 2020, 5210, 5270, 6140)
  • Confirm best execution analysis and order routing disclosures remain accurate and explainable when AI tools are involved in routing decisions.  (Best Execution; CAT reporting rules)
  • Ensure AI-assisted Consolidated Audit Trail (CAT) reporting processes are tested for completeness, accuracy, and timeliness, with human oversight of error correction.  (CAT reporting rules; 2026 Report)
  • Apply heightened surveillance where AI is used in fixed income fair-pricing analysis or market access risk controls, validating model outputs against independent benchmarks.  (Market Access Rule; 2026 Report)

11. Outside Business Activities & Conflicts of Interest

AI tools used by registered persons outside firm-sanctioned channels create the same outside business activity (OBA)/private securities transaction (PST) and conflicts exposure as any other unsupervised activity.

  • Confirm policy explicitly addresses registered persons' personal use of public AI tools (e.g., personal ChatGPT accounts) for any work-related purpose.  (2026 Report; Rules 3270/3280)
  • Reinforce in training that using AI to assist with an undisclosed private securities transaction or outside business activity does not exempt it from disclosure obligations.  (FINRA Rules 3270, 3280)
  • Review conflicts-of-interest disclosures to ensure they account for any AI-driven product steering, recommendation weighting, or revenue-influenced outputs.  (Reg BI; 2026 Report)

12. Training & Culture

Controls on paper don't help if the people using the tools don't understand the limits.

  • Provide AI-specific training as part of annual compliance training, covering firm policy, prohibited uses, and how to recognize and escalate hallucinations or errors.  (2026 Report; Rule 3110)
  • Tailor training by role — registered representatives, supervisors, and compliance staff need different depth on AI risk recognition and escalation.  (2026 Report)
  • Update training content as new use cases, business lines, or AI agent deployments are introduced — treat this as a living program, not an annual checkbox.  (2026 Report)
  • Train staff explicitly that 'the AI said so' is never an adequate basis for a recommendation, disclosure, or compliance determination — human judgment and sign-off remain required.  (Rule 3110; RN 24-09)
  • Include case studies/examples of AI hallucination, bias, or fraud incidents (internal or industry) in training to make the risk concrete.  (2026 Report)

13. Ongoing Monitoring, Audit & Exam Readiness

Treat the AI program the way you'd treat any other area FINRA actively examines — because it now is one.

  • Include AI use cases in the scope of the firm's annual compliance program review (Rule 3120) and CEO certification process (Rule 3130).  (FINRA Rules 3120, 3130)
  • Periodically audit a sample of AI outputs across use cases for accuracy, tone, bias, and compliance with firm policy — not just at launch.  (2026 Report, GenAI)
  • Maintain documentation sufficient to demonstrate to an examiner how each AI use case was evaluated, approved, tested, and is being monitored.  (2026 Report, GenAI)
  • Map the firm's AI controls against FINRA's Annual Regulatory Oversight Report each year and document the gap analysis performed.  (2026 Report, Appendix)
  • Consider voluntary alignment with the NIST AI Risk Management Framework as an organizing structure for the points above, even though it is not a FINRA mandate.  (NIST AI RMF 1.0)

Quick-Reference: Key Rules & Guidance Cited

Use this table to anchor each control above to a specific rule or regulatory notice when drafting or updating WSP language.

Rule / Guidance

Why It Matters for AI Use

FINRA Regulatory Notice 24-09 (June 2024)

Foundational reminder that all FINRA rules apply to AI/GenAI use; technology-neutral framework.

FINRA 2025 & 2026 Annual Regulatory Oversight Reports

Most detailed current FINRA guidance on GenAI governance, testing, monitoring, and AI agents.

FINRA Rule 3110 (Supervision)

Requires a reasonably designed supervisory system covering any AI used in the business.

FINRA Rule 2210 (Communications with the Public)

Governs AI-generated or AI-assisted public communications, regardless of who/what created them.

FINRA Rule 4511/SEC Rule 17a-4

Books and records retention requirements apply to AI-generated records and communications.

Regulation S-P (incl. 2024 amendments)

Safeguarding customer information; incident response and notification requirements.

Regulation S-ID

Identity theft red flags program, relevant to AI-enabled identity fraud.

FINRA Rule 3310 (AML)

AML program obligations, including AI-enabled fraud typologies.

FINRA Rules 4512/2165

Trusted contact persons and temporary holds for vulnerable/senior investors.

FINRA Rules 3270/3280

Outside business activities and private securities transactions, including AI-facilitated ones.

FINRA Regulatory Notice 21-29

Supervisory obligations when outsourcing to third-party vendors, including AI vendors.

NIST AI Risk Management Framework (AI RMF 1.0)

Voluntary framework FINRA has referenced as a useful organizing structure.

Disclaimer: This checklist is a general compliance reference based on publicly available FINRA guidance as of June 2026. It does not constitute legal advice and does not cover every rule that may apply to a specific firm's business model (e.g., investment adviser dual registration, state-level requirements, or SEC rules outside those cited). Firms should validate this checklist against their own risk assessment and counsel before incorporating it into WSPs.

Stablecoins Just Got a Lot Cheaper to Hold: What the New 2% Haircut Means for Your Net Capital

For years, broker-dealers that wanted a proprietary position in a stablecoin faced a capital problem. Rule 15c3-1 has never explicitly addressed stablecoins, and in the absence of guidance, many firms did what cautious financial operations (FinOps) do with regulatory silence: they assumed the worst. A 100% haircut — treating the position as worthless for net capital purposes — was the conservative default at a number of firms, even though the underlying reserves backing those tokens looked a lot like the cash and short-term Treasuries sitting in a money market fund.

That math just changed.

Because broker-dealers must deduct applicable haircuts when calculating net capital, the percentage assigned to an asset directly affects how much regulatory capital the firm must maintain.  On February 19, 2026, the SEC’s Division of Trading and Markets updated its crypto FAQ to address exactly this gap. The staff stated it will not object if a broker-dealer treats a proprietary position in a qualifying “payment stablecoin” as having a “ready market” under Rule 15c3-1 and applies a 2% haircut — calculated on the market value of the greater of the long or short position, not netted — when computing net capital. Put simply: a $100 proprietary stablecoin position now counts as $98 toward net capital, not $0.

A few details worth noting:

It’s staff guidance, not a rule change. This is FAQ-level relief from SEC staff, not formal rulemaking. Commissioner Hester Peirce, who has been vocal that a 100% haircut was “unnecessarily punitive,” said she’d like to see Rule 15c3-1 formally amended to address stablecoins directly — but for now, firms are relying on a “we will not object” position. That’s meaningfully softer ground than a codified rule, and worth flagging in any capital adequacy memo.

The definition of “payment stablecoin” is doing a lot of work. The FAQ ties the 2% treatment to a specific definition — currently keyed to attestation standards around reserve composition, and after the GENIUS Act’s effective date, to stablecoins meeting that Act’s definition and issued by a “permitted” or “foreign” payment stablecoin issuer. Not every token marketed as a “stablecoin” will qualify. Treating a non-qualifying token under this favorable haircut would be a net capital miscalculation — exactly the kind of finding FINRA exam staff look for.

The “greater of long or short” detail isn’t a technicality. The haircut applies to whichever side of the position is larger; firms can’t reduce their capital charge by netting offsetting exposures on paper.

This lands squarely in FINRA’s existing net capital scrutiny. FINRA doesn’t need a new rule to examine this — net capital miscalculations, haircut misapplication, and inadequate processes for classifying nonmarketable or non-qualifying assets are already recurring findings in FINRA’s oversight reports. A firm claiming the 2% rate on a stablecoin that doesn’t meet the FAQ’s definition is the kind of “incorrect haircut” issue examiners have flagged before — just with a new asset class attached.

For broker-dealers already active in crypto, or weighing whether a stablecoin proprietary position makes sense, this guidance meaningfully narrows the capital cost of doing so. But “narrowed” isn’t “eliminated,” and the relief is only as good as the firm’s process for confirming, position by position, that what it’s holding actually meets the FAQ’s definition of a qualifying payment stablecoin.

Robert Heim
Co-Chair, White Collar and Regulatory Enforcement Practice, Tarter Krinsky & Drogin
rheim@tarterkrinsky.com

Stephen Zak
President, Three Mile Advisors LLC
szak@threemileadvisors.com

*This newsletter is for informational purposes only and not legal advice.*