August 12, 2026
Article

Financial Industry Regulatory Authority (FINRA) has been consistent on one point for two years running: it isn't writing new rules for artificial intelligence. It's applying the rules already on the books, such as supervision, communications, recordkeeping, Regulation Best Interest (Reg BI), anti-money laundering (AML), to whatever tool a firm happens to be using, AI included. That's the good news. The bad news is that "no new rules" doesn't mean "no new exposure." It means the burden is on firms to map a fast-moving technology onto a rulebook that wasn't written with it in mind, and to do it before an examiner asks how.
The signal that this is no longer a back-burner issue has gotten louder with each FINRA publication. Regulatory Notice 24-09 reminded members that GenAI implicates essentially the entire rulebook. The 2025 Annual Regulatory Oversight Report added detail on governance and testing expectations. The 2026 Report went further still, adding a standalone GenAI section and, for the first time, explicit guidance on autonomous AI agents: systems that can act on a user's behalf without a human approving each step.
For compliance and legal teams, the practical problem is less "is AI a risk" and more "where exactly does our existing program have gaps." Many firms have “some” AI-related language in their written supervisory procedures (WSP) by now. Far fewer have an inventoried use case list, documented testing for hallucination and bias, supervisory sign-off mapped to Rule 3110, Rule 2210 review applied consistently to AI-drafted communications, vendor due diligence that actually asks how the vendor itself uses GenAI, and a recordkeeping process that captures AI prompts and outputs the same way it captures everything else.
That gap is exactly what we built our checklist to close.
**The AI Usage Controls Checklist for FINRA-Registered Broker-Dealers** organizes 13 control areas involving governance, supervision and WSPs, model risk testing, public communications, recordkeeping, cybersecurity and Regulation S-P (Reg S-P), vendor diligence, AML and fraud, senior investor protection, market integrity, outside business activities, training, and exam readiness into a single working document. Every control item is tied to the specific rule or FINRA guidance behind it, so the checklist doubles as a citation map when it's time to update WSP language or respond to an exam request. It also includes a quick-reference table of the underlying rules (3110, 2210, 4511, Regulation S-P, Regulation S-ID (Reg S-ID), 3310, and more) for anyone who wants the regulatory backbone at a glance.
If your firm hasn't formally inventoried its AI use cases, including the AI that may be quietly embedded in software you've been using for years, that's the place to start and Three Mile Advisors and Tarter Krinsky & Drogin can assist you in performing that analysis.
For FINRA-Registered Broker-Dealers
Prepared as a general compliance reference. Reflects FINRA Regulatory Notice 24-09, the 2025 and 2026 FINRA Annual Regulatory Oversight Reports' GenAI guidance, and related FINRA/SEC rules current as of June 2026.
This checklist translates FINRA's technology-neutral rulebook into concrete controls for firms that build, buy, or otherwise use AI — including generative AI (GenAI), large language models (LLMs), machine learning, and autonomous AI agents — anywhere in the business. FINRA does not regulate AI as a separate category; it applies existing rules (supervision, communications, recordkeeping, Reg BI, AML, outsourcing, cybersecurity) to whatever tool is used, AI included.
Organize your AI inventory by use case (e.g., marketing copy generation, trade surveillance, code generation, customer chatbots, summarization of research) and risk-rate each one. Higher-risk use cases — those touching customer communications, suitability, surveillance, or money movement — warrant the fullest version of these controls; low-risk internal use (e.g., drafting an internal memo) may warrant a lighter touch, but should still be inventoried.
Checkbox items map to a specific control. The citation in parentheses points to the rule or guidance driving that control so your WSPs can reference it directly.
Rule 3110 requires a reasonably designed supervisory system tailored to the firm's business — and FINRA has been explicit that this extends to AI-assisted and AI-driven workflows, including autonomous agents.
AI-specific failure modes — hallucination and bias chief among them — need their own testing regime, not just standard software quality assurance (QA).
FINRA has been unambiguous: Rule 2210 governs AI-generated public-facing content exactly as it governs human-drafted content — there is no AI carve-out for accuracy, balance, or disclosure.
AI-generated and AI-assisted records are still books and records — they don't get a lighter retention standard because a model produced them.
Feeding customer or firm data into an AI model is a data-handling event subject to the same safeguarding obligations as any other system that touches that data.
Using a vendor's AI — including an AI feature embedded in software the firm already licenses — does not transfer the firm's regulatory responsibility to the vendor.
Both sides of this risk matter: AI is increasingly a target/tool for bad actors, and AI is increasingly used by firms to detect them. Both uses need controls.
AI-driven personalization and fraud both intersect with FINRA's ongoing focus on protecting senior and vulnerable customers.
Where AI touches order handling, pricing, or trading, the existing market-conduct rulebook applies in full.
AI tools used by registered persons outside firm-sanctioned channels create the same OBA/PST and conflicts exposure as any other unsupervised activity.
Controls on paper don't help if the people using the tools don't understand the limits.
Treat the AI program the way you'd treat any other area FINRA actively examines — because it now is one.
Use this table to anchor each control above to a specific rule or regulatory notice when drafting or updating WSP language.
Rule / Guidance |
Why It Matters for AI Use |
FINRA Regulatory Notice 24-09 (Jun. 2024) |
Foundational reminder that all FINRA rules apply to AI/GenAI use; technology-neutral framework. |
FINRA 2025 & 2026 Annual Regulatory Oversight Reports |
Most detailed current FINRA guidance on GenAI governance, testing, monitoring, and AI agents. |
FINRA Rule 3110 (Supervision) |
Requires a reasonably designed supervisory system covering any AI used in the business. |
FINRA Rule 2210 (Communications with the Public) |
Governs AI-generated or AI-assisted public communications, regardless of who/what created them. |
FINRA Rule 4511 / SEC Rule 17a-4 |
Books and records retention requirements apply to AI-generated records and communications. |
Regulation S-P (incl. 2024 amendments) |
Safeguarding customer information; incident response and notification requirements. |
Regulation S-ID |
Identity theft red flags program, relevant to AI-enabled identity fraud. |
FINRA Rule 3310 (AML) |
AML program obligations, including AI-enabled fraud typologies. |
FINRA Rules 4512 / 2165 |
Trusted contact persons and temporary holds for vulnerable/senior investors. |
FINRA Rules 3270 / 3280 |
Outside business activities and private securities transactions, including AI-facilitated ones. |
FINRA Regulatory Notice 21-29 |
Supervisory obligations when outsourcing to third-party vendors, including AI vendors. |
NIST AI Risk Management Framework (AI RMF 1.0) |
Voluntary framework FINRA has referenced as a useful organizing structure. |
Disclaimer: This checklist is a general compliance reference based on publicly available FINRA guidance as of June 2026. It does not constitute legal advice and does not cover every rule that may apply to a specific firm's business model (e.g., investment adviser dual registration, state-level requirements, or SEC rules outside those cited). Firms should validate this checklist against their own risk assessment and counsel before incorporating it into WSPs.
For years, broker-dealers that wanted a proprietary position in a stablecoin faced a capital problem. Rule 15c3-1 has never explicitly addressed stablecoins, and in the absence of guidance, many firms did what cautious FinOps do with regulatory silence: they assumed the worst. A 100% haircut — treating the position as worthless for net capital purposes — was the conservative default at a number of firms, even though the underlying reserves backing those tokens looked a lot like the cash and short-term Treasuries sitting in a money market fund.
That math just changed.
Because broker-dealers must deduct applicable haircuts when calculating net capital, the percentage assigned to an asset directly affects how much regulatory capital the firm must maintain. On February 19, 2026, the SEC’s Division of Trading and Markets updated its crypto FAQ to address exactly this gap. The staff stated it will not object if a broker-dealer treats a proprietary position in a qualifying “payment stablecoin” as having a “ready market” under Rule 15c3-1 and applies a 2% haircut — calculated on the market value of the greater of the long or short position, not netted — when computing net capital. Put simply: a $100 proprietary stablecoin position now counts as $98 toward net capital, not $0.
A few details worth noting:
It’s staff guidance, not a rule change. This is FAQ-level relief from SEC staff, not formal rulemaking. Commissioner Hester Peirce, who has been vocal that a 100% haircut was “unnecessarily punitive,” said she’d like to see Rule 15c3-1 formally amended to address stablecoins directly — but for now, firms are relying on a “we will not object” position. That’s meaningfully softer ground than a codified rule, and worth flagging in any capital adequacy memo.
The definition of “payment stablecoin” is doing a lot of work. The FAQ ties the 2% treatment to a specific definition — currently keyed to attestation standards around reserve composition, and after the GENIUS Act’s effective date, to stablecoins meeting that Act’s definition and issued by a “permitted” or “foreign” payment stablecoin issuer. Not every token marketed as a “stablecoin” will qualify. Treating a non-qualifying token under this favorable haircut would be a net capital miscalculation — exactly the kind of finding FINRA exam staff look for.
The “greater of long or short” detail isn’t a technicality. The haircut applies to whichever side of the position is larger; firms can’t reduce their capital charge by netting offsetting exposures on paper.
This lands squarely in FINRA’s existing net capital scrutiny. FINRA doesn’t need a new rule to examine this — net capital miscalculations, haircut misapplication, and inadequate processes for classifying nonmarketable or non-qualifying assets are already recurring findings in FINRA’s oversight reports. A firm claiming the 2% rate on a stablecoin that doesn’t meet the FAQ’s definition is the kind of “incorrect haircut” issue examiners have flagged before — just with a new asset class attached.
For broker-dealers already active in crypto, or weighing whether a stablecoin proprietary position makes sense, this guidance meaningfully narrows the capital cost of doing so. But “narrowed” isn’t “eliminated,” and the relief is only as good as the firm’s process for confirming, position by position, that what it’s holding actually meets the FAQ’s definition of a qualifying payment stablecoin.
FINRA Isn't Writing New AI Rules. That's the Problem.
FINRA has been consistent on one point for two years running: it isn't writing new rules for artificial intelligence. It's applying the rules already on the books, such as Supervision, Communications, Recordkeeping, Reg BI, AML, to whatever tool a firm happens to be using, AI included. That's the good news. The bad news is that "no new rules" doesn't mean "no new exposure." It means the burden is on firms to map a fast-moving technology onto a rulebook that wasn't written with it in mind, and to do it before an examiner asks how.
The signal that this is no longer a back-burner issue has gotten louder with each FINRA publication. Regulatory Notice 24-09 reminded members that GenAI implicates essentially the entire rulebook. The 2025 Annual Regulatory Oversight Report added detail on governance and testing expectations. The 2026 Report went further still, adding a standalone GenAI section and, for the first time, explicit guidance on autonomous AI agents: systems that can act on a user's behalf without a human approving each step.
For compliance and legal teams, the practical problem is less "is AI a risk" and more "where exactly does our existing program have gaps." Many firms have “some” AI-related language in their WSPs by now. Far fewer have an inventoried use case list, documented testing for hallucination and bias, supervisory sign-off mapped to Rule 3110, Rule 2210 review applied consistently to AI-drafted communications, vendor due diligence that actually asks how the vendor itself uses GenAI, and a recordkeeping process that captures AI prompts and outputs the same way it captures everything else.
That gap is exactly what we built our checklist to close.
**The AI Usage Controls Checklist for FINRA-Registered Broker-Dealers** organizes 13 control areas involving governance, supervision and WSPs, model risk testing, public communications, recordkeeping, cybersecurity and Reg S-P, vendor diligence, AML and fraud, senior investor protection, market integrity, outside business activities, training, and exam readiness into a single working document. Every control item is tied to the specific rule or FINRA guidance behind it, so the checklist doubles as a citation map when it's time to update WSP language or respond to an exam request. It also includes a quick-reference table of the underlying rules (3110, 2210, 4511, Reg S-P, Reg S-ID, 3310, and more) for anyone who wants the regulatory backbone at a glance.
If your firm hasn't formally inventoried its AI use cases, including the AI that may be quietly embedded in software you've been using for years, that's the place to start and Three Mile Advisors and Tarter Krinsky &Drogin can assist you in performing that analysis.
For FINRA-Registered Broker-Dealers
Prepared as a general compliance reference. Reflects FINRA Regulatory Notice 24-09, the 2025 and 2026 FINRA Annual Regulatory Oversight Reports' GenAI guidance, and related FINRA/SEC rules current as of June 2026.
This checklist translates FINRA's technology-neutral rulebook into concrete controls for firms that build, buy, or otherwise use AI — including generative AI (GenAI), large language models (LLMs), machine learning, and autonomous AI agents — anywhere in the business. FINRA does not regulate AI as a separate category; it applies existing rules (Supervision, Communications, Recordkeeping, Reg BI, AML, Outsourcing, Cybersecurity) to whatever tool is used, AI included.
Organize your AI inventory by use case (e.g., marketing copy generation, trade surveillance, code generation, customer chatbots, summarization of research) and risk-rate each one. Higher-risk use cases — those touching customer communications, suitability, surveillance, or money movement — warrant the fullest version of these controls; low-risk internal use (e.g., drafting an internal memo) may warrant a lighter touch, but should still be inventoried.
Checkbox items map to a specific control. The citation in parentheses points to the rule or guidance driving that control so your WSPs can reference it directly.
Before any AI tool goes into production, the firm needs an enterprise-level framework that owns AI risk the way it owns any other compliance risk.
Rule 3110 requires a reasonably designed supervisory system tailored to the firm's business — and FINRA has been explicit that this extends to AI-assisted and AI-driven workflows, including autonomous agents.
AI-specific failure modes — hallucination and bias chief among them — need their own testing regime, not just standard software QA.
FINRA has been unambiguous: Rule 2210 governs AI-generated public-facing content exactly as it governs human-drafted content — there is no AI carve-out for accuracy, balance, or disclosure.
AI-generated and AI-assisted records are still books and records — they don't get a lighter retention standard because a model produced them.
Feeding customer or firm data into an AI model is a data-handling event subject to the same safeguarding obligations as any other system that touches that data.
Using a vendor's AI — including an AI feature embedded in software the firm already licenses — does not transfer the firm's regulatory responsibility to the vendor.
Both sides of this risk matter: AI is increasingly a target/tool for bad actors, and AI is increasingly used by firms to detect them. Both uses need controls.
AI-driven personalization and fraud both intersect with FINRA's ongoing focus on protecting senior and vulnerable customers.
Where AI touches order handling, pricing, or trading, the existing market-conduct rulebook applies in full.
AI tools used by registered persons outside firm-sanctioned channels create the same outside business activity (OBA)/private securities transaction (PST) and conflicts exposure as any other unsupervised activity.
Controls on paper don't help if the people using the tools don't understand the limits.
Treat the AI program the way you'd treat any other area FINRA actively examines — because it now is one.
Use this table to anchor each control above to a specific rule or regulatory notice when drafting or updating WSP language.
Rule / Guidance |
Why It Matters for AI Use |
FINRA Regulatory Notice 24-09 (June 2024) |
Foundational reminder that all FINRA rules apply to AI/GenAI use; technology-neutral framework. |
FINRA 2025 & 2026 Annual Regulatory Oversight Reports |
Most detailed current FINRA guidance on GenAI governance, testing, monitoring, and AI agents. |
FINRA Rule 3110 (Supervision) |
Requires a reasonably designed supervisory system covering any AI used in the business. |
FINRA Rule 2210 (Communications with the Public) |
Governs AI-generated or AI-assisted public communications, regardless of who/what created them. |
FINRA Rule 4511/SEC Rule 17a-4 |
Books and records retention requirements apply to AI-generated records and communications. |
Regulation S-P (incl. 2024 amendments) |
Safeguarding customer information; incident response and notification requirements. |
Regulation S-ID |
Identity theft red flags program, relevant to AI-enabled identity fraud. |
FINRA Rule 3310 (AML) |
AML program obligations, including AI-enabled fraud typologies. |
FINRA Rules 4512/2165 |
Trusted contact persons and temporary holds for vulnerable/senior investors. |
FINRA Rules 3270/3280 |
Outside business activities and private securities transactions, including AI-facilitated ones. |
FINRA Regulatory Notice 21-29 |
Supervisory obligations when outsourcing to third-party vendors, including AI vendors. |
NIST AI Risk Management Framework (AI RMF 1.0) |
Voluntary framework FINRA has referenced as a useful organizing structure. |
Disclaimer: This checklist is a general compliance reference based on publicly available FINRA guidance as of June 2026. It does not constitute legal advice and does not cover every rule that may apply to a specific firm's business model (e.g., investment adviser dual registration, state-level requirements, or SEC rules outside those cited). Firms should validate this checklist against their own risk assessment and counsel before incorporating it into WSPs.
For years, broker-dealers that wanted a proprietary position in a stablecoin faced a capital problem. Rule 15c3-1 has never explicitly addressed stablecoins, and in the absence of guidance, many firms did what cautious financial operations (FinOps) do with regulatory silence: they assumed the worst. A 100% haircut — treating the position as worthless for net capital purposes — was the conservative default at a number of firms, even though the underlying reserves backing those tokens looked a lot like the cash and short-term Treasuries sitting in a money market fund.
That math just changed.
Because broker-dealers must deduct applicable haircuts when calculating net capital, the percentage assigned to an asset directly affects how much regulatory capital the firm must maintain. On February 19, 2026, the SEC’s Division of Trading and Markets updated its crypto FAQ to address exactly this gap. The staff stated it will not object if a broker-dealer treats a proprietary position in a qualifying “payment stablecoin” as having a “ready market” under Rule 15c3-1 and applies a 2% haircut — calculated on the market value of the greater of the long or short position, not netted — when computing net capital. Put simply: a $100 proprietary stablecoin position now counts as $98 toward net capital, not $0.
A few details worth noting:
It’s staff guidance, not a rule change. This is FAQ-level relief from SEC staff, not formal rulemaking. Commissioner Hester Peirce, who has been vocal that a 100% haircut was “unnecessarily punitive,” said she’d like to see Rule 15c3-1 formally amended to address stablecoins directly — but for now, firms are relying on a “we will not object” position. That’s meaningfully softer ground than a codified rule, and worth flagging in any capital adequacy memo.
The definition of “payment stablecoin” is doing a lot of work. The FAQ ties the 2% treatment to a specific definition — currently keyed to attestation standards around reserve composition, and after the GENIUS Act’s effective date, to stablecoins meeting that Act’s definition and issued by a “permitted” or “foreign” payment stablecoin issuer. Not every token marketed as a “stablecoin” will qualify. Treating a non-qualifying token under this favorable haircut would be a net capital miscalculation — exactly the kind of finding FINRA exam staff look for.
The “greater of long or short” detail isn’t a technicality. The haircut applies to whichever side of the position is larger; firms can’t reduce their capital charge by netting offsetting exposures on paper.
This lands squarely in FINRA’s existing net capital scrutiny. FINRA doesn’t need a new rule to examine this — net capital miscalculations, haircut misapplication, and inadequate processes for classifying nonmarketable or non-qualifying assets are already recurring findings in FINRA’s oversight reports. A firm claiming the 2% rate on a stablecoin that doesn’t meet the FAQ’s definition is the kind of “incorrect haircut” issue examiners have flagged before — just with a new asset class attached.
For broker-dealers already active in crypto, or weighing whether a stablecoin proprietary position makes sense, this guidance meaningfully narrows the capital cost of doing so. But “narrowed” isn’t “eliminated,” and the relief is only as good as the firm’s process for confirming, position by position, that what it’s holding actually meets the FAQ’s definition of a qualifying payment stablecoin.
Robert Heim
Co-Chair, White Collar and Regulatory Enforcement Practice, Tarter Krinsky & Drogin
rheim@tarterkrinsky.com
Stephen Zak
President, Three Mile Advisors LLC
szak@threemileadvisors.com
*This newsletter is for informational purposes only and not legal advice.*
