Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature AI Risk

FINRA's 2026 Oversight Report Moved Agentic AI to Active Examination Priority. Examiners Are Now Asking About It. Here's What Broker-Dealers Need in Place.

FINRA's 2026 Annual Regulatory Oversight Report formally classified agentic AI as an active supervisory priority, with examinations targeting broker-dealer governance in Q2-Q3 2026. Here is what examiners are asking about and what your program needs to have documented.

By Rebecca Leung · September 10, 2026 ·
Table of Contents

TL;DR

  • FINRA’s 2026 Annual Regulatory Oversight Report (published December 2025) formally classified agentic AI as an active supervisory priority — moving it from “emerging technology” to a standing examination topic.
  • Examiners are checking for AI agent governance in broker-dealer examinations in Q2-Q3 2026. If you haven’t updated your supervisory procedures for AI agents, you may be caught flat-footed.
  • The biggest compliance risks FINRA flagged: AI agents operating without human-in-the-loop oversight, agent permission and access control gaps, and AI-generated communications that are sent without proper review and retention.
  • The 2026 report is not a rulemaking — but existing rules apply: FINRA Rule 3110 (Supervision), Rule 4370 (BCP), and Rule 2210 (Communications) all reach AI-generated and AI-initiated activity.

In December 2025, FINRA published its 2026 Annual Regulatory Oversight Report — the annual document that tells broker-dealers what examiners will be focused on in the upcoming cycle. The AI section in the 2026 report is different from what appeared in prior years: generative AI moved from “emerging risk” to standing examination priority, and agentic AI appeared for the first time as a distinct risk category that FINRA explicitly flagged for supervisory attention.

Nine months later, examiners are in the middle of the examination cycle the 2026 report previewed. If your firm deployed AI agents — tools that autonomously take actions, send communications, interface with external systems, or make recommendations without human review at each step — and you haven’t updated your supervisory procedures to reflect them, this is your notice.

What the 2026 Report Actually Said About Agentic AI

FINRA’s 2026 Regulatory Oversight Report contains a standalone section on Generative AI that substantially expands on prior years’ coverage. The key shift: the 2026 report distinguishes generative AI from agentic AI and treats them as requiring different supervisory approaches.

FINRA defines agentic AI as systems capable of autonomously interpreting objectives, taking multi-step actions, interfacing with external tools and data sources, and adapting dynamically to changing environments — often without human approval at each step. This is distinct from generative AI that produces a response to a prompt and waits.

The practical difference matters for compliance: a generative AI that drafts a client suitability recommendation sits in the supervised-outputs bucket. An AI agent that receives a portfolio alert, generates a recommendation, sends the recommendation to the client via email, and follows up if the client doesn’t respond in 48 hours — that’s an agentic system, and it requires a different supervision model because human review isn’t happening between each action.

FINRA’s blog post on AI agent observations noted that member firms are already deploying agentic AI across functions including research synthesis, operational workflows, client communication, and compliance monitoring. The 2026 report formalized FINRA’s posture: these deployments require supervisory controls that firms haven’t always put in place.

”Active Supervisory Priority” vs. “Emerging Technology”

The language shift in the 2026 report is not subtle. Prior years classified AI as an “emerging technology” topic — something examiners were monitoring and that firms should be thinking about. The 2026 report moved agentic AI to “active supervisory priority,” which is examination terminology with a specific meaning: examiners will ask about it.

Debevoise’s analysis of the 2026 report notes that this classification means member firms should expect direct examiner inquiries about their agentic AI governance in upcoming exams, separate from the broader technology and cybersecurity review.

What examiners are asking about, per FINRA’s examinations in Q2-Q3 2026:

  • Governance documentation: Does the firm have a written policy or procedure that defines what constitutes an AI agent and what the supervisory requirements are?
  • Human oversight controls: For AI-initiated actions affecting customers or accounts, what human review steps exist? Is there a meaningful “human in the loop” or just a theoretical one?
  • Permissions and access: What can each AI agent access and what can it initiate? Are permissions scoped to what the agent actually needs, or are agents running with broad system access?
  • Communications compliance: When AI generates or sends communications with customers, how does the firm ensure those communications meet Rule 2210 standards? How are they reviewed and retained?
  • Testing and monitoring: How does the firm test AI accuracy before deployment? How does it monitor for hallucinations, drift, or unexpected outputs after deployment?
  • Vendor oversight: For third-party AI tools, what due diligence did the firm conduct before deployment, and how does the firm supervise outputs from a model it didn’t build?

The Three Risk Areas FINRA Flagged for Examinations

1. AI Agents Operating Without Meaningful Human Oversight

FINRA’s 2026 report identified AI agents acting autonomously with no “human in the loop” as the highest-priority governance concern. The risk is real: if an AI agent can send a communication, execute a recommendation, or initiate an account action without human review, and it does so based on a hallucinated or misinterpreted input — the supervisory failure is the firm’s, regardless of whose model was running.

The supervisory procedures requirement under FINRA Rule 3110 applies to all activities the firm conducts, including activities conducted by AI systems. An AI agent that takes customer-facing actions isn’t exempt from supervision because it’s automated — it requires supervision designed for its specific risk profile.

What “meaningful” human oversight looks like depends on what the agent does. An agent that generates a draft recommendation for human review and approval before any customer contact is different from an agent that generates and sends recommendations directly. Both require supervision; the latter requires more.

Debevoise’s analysis specifically notes that FINRA’s concern is not that firms are using AI agents, but that many have deployed them without building the supervisory infrastructure to match. The technology outpaced the governance.

2. Agent Permission and Access Control Gaps

The 2026 report flagged “agent permission/access issues” as a distinct risk category. The concern: AI agents with overly broad system permissions can access data, initiate actions, or interface with external systems in ways that weren’t intended — and without access logs or controls, the firm may not know until something goes wrong.

Firms deploying AI agents should be able to answer: What can each agent access? What can each agent initiate? What system calls can each agent make? What are the human authorization requirements before an agent can take a high-stakes action — placing a trade, sending a communication, modifying account information?

If agents are running with broad read-write access to systems because that was the path of least resistance at deployment, that’s a permissions gap examiners are looking for.

The access control question also extends to agent-to-agent interactions. Some agentic AI systems involve multiple agents collaborating — a research agent handing off to a recommendation agent handing off to a communication agent. Each handoff point is a permission boundary that needs to be defined.

3. AI-Generated Communications and Rule 2210 Compliance

FINRA Rule 2210 requires that all communications with the public be fair, balanced, not misleading, approved by a principal, and retained per recordkeeping requirements. When AI generates or assists in drafting those communications, every part of that obligation still applies.

The 2026 report is explicit: AI-generated hallucinations in client communications are not an acceptable failure mode. A model that “misinterprets regulatory requirements” or “misstates client information” in a communication creates a compliance violation — the AI’s error doesn’t relieve the firm of responsibility for what it sent.

What this requires in practice:

  • Human review of AI-generated client communications before delivery, or a supervision system that can review at scale
  • Retention of AI-generated communications in the same manner as any other record
  • Audit trails showing who approved communications and when
  • Testing protocols that specifically look for hallucinated facts, incorrect regulatory citations, or mischaracterized product information

If your firm is using AI to draft client emails, suitability letters, or recommendations at scale — with the goal of efficiency — the supervision model has to scale proportionally. Approving 100% of AI-generated communications individually may not be feasible; a sampling-based supervision model with clear escalation criteria is the alternative examiners are more likely to accept as reasonable.

What Your Supervisory Procedures Need to Say About AI

Most broker-dealer supervisory procedures written before 2025 don’t mention AI agents. Some have been updated to reference generative AI in a general way. Very few have been updated to address agentic AI as a distinct supervisory category with its own requirements.

Here’s what updated procedures should cover:

Scope definition. What constitutes an AI agent at your firm, and how is it distinguished from generative AI tools? Without a definition, you can’t apply different supervisory requirements to different tools.

Inventory and approval process. Before a new AI agent is deployed, what review is required? Who approves it, and on what criteria? This is the pre-deployment equivalent of the new-product approval process — and it needs to be documented.

Action authorization requirements. For agents that take customer-facing actions (communications, recommendations, account modifications), what human authorization is required? At what thresholds does human review become mandatory vs. advisory?

Testing and monitoring standards. Before deployment: what testing for accuracy, hallucination rates, and unexpected outputs? After deployment: what ongoing monitoring and at what frequency?

Communications review and retention. How AI-generated communications are reviewed, approved, and retained. Who is the responsible principal for AI-generated communications, and what does their review process look like?

Vendor AI oversight. For third-party AI tools, what due diligence was conducted? How does the firm monitor vendor model updates that might affect compliance? What escalation exists if a vendor’s model behaves unexpectedly?

Incident response. What happens when an AI agent produces a significant error — a hallucinated fact in a client communication, an unauthorized action, an unexpected output? Who is notified, what is the remediation process, and what is the recordkeeping requirement?

The McGuireWoods analysis of FINRA’s 2026 report notes that firms treating AI governance as a technology question rather than a supervisory procedure question are misunderstanding what FINRA is looking for. Examiners will review supervisory procedures, not technology architecture.

The Vendor Oversight Problem Specific to AI

Most broker-dealers using AI are using third-party models — not models built and trained in-house. This creates a supervisory complexity that FINRA’s 2026 report specifically addressed.

Firms cannot delegate supervisory responsibility to an AI vendor. The vendor builds and maintains the model; the firm is responsible for supervising how the model performs in its environment. When a vendor’s model produces a hallucinated regulatory citation or mischaracterized client account detail, the firm’s supervisory obligation was to have a system in place that caught it before it reached the client.

What this means for vendor AI due diligence:

  • What testing did you conduct before deploying the vendor’s model?
  • How do you monitor the vendor’s model outputs after deployment?
  • What is your process when the vendor updates the underlying model — do you re-test before the updated model goes live in your environment?
  • What contractual obligations does the vendor have to notify you of material model changes or incidents?

This connects directly to the vendor oversight expectations that regulators have been articulating across financial services. For the full picture of what AI vendor due diligence needs to cover, see our analysis of the FTC’s Cox Media Group settlement and what AI vendor due diligence needs to catch.

For firms with EU operations or EU-customer exposure, the EU AI Act inspection wave that began August 30 adds a parallel documentation requirement for high-risk AI systems — one that carries significantly higher penalties than FINRA examination findings.

So What?

The FINRA 2026 Annual Regulatory Oversight Report does not change what rules apply to AI. What it does is tell you, with significant specificity, that examiners are asking about AI agent governance right now — and what they’re looking for.

If your firm deployed AI agents in 2025 or early 2026 and your supervisory procedures haven’t been updated since, you’re in the situation the 2026 report was designed to prevent: governance that trails technology adoption.

The firms that are exam-ready on agentic AI have two things in common: a written definition of what an AI agent is at their firm, and supervisory procedures that are specific about what oversight those agents require. Everything else — testing protocols, communication review, vendor oversight, incident response — flows from those two foundations.

Examination Focus AreaWhat Examiners AskWhat Needs to Be Documented
Agent governanceDo you have written procedures for AI agents?Supervisory procedures covering AI agent classification, authorization, oversight
Human-in-the-loopWhat human oversight exists before AI actions?Authorization thresholds, approval workflows, escalation criteria
Permissions and accessWhat can agents access and initiate?Permission inventory, scope limitations, authorization requirements
Communications complianceHow are AI communications reviewed?Review and approval process, retention records, principal sign-off
Testing and monitoringHow do you test for hallucinations?Pre-deployment testing results, ongoing monitoring logs
Vendor oversightWho is responsible for the third-party model?Due diligence documentation, vendor monitoring procedures

The AI Risk Assessment Template & Guide includes an AI use case inventory with auto-tiering, a 44-question pre-deployment risk assessment, a 31-question third-party AI vendor questionnaire, and 8 worked examples — covering Shadow AI, vendor AI tools, and customer-facing GenAI deployments. Designed for compliance and risk teams that need to move from “we’re aware of the issue” to a documented program.


Frequently Asked Questions

Does FINRA’s 2026 report create new rules for AI? No — it’s examination guidance, not a rulemaking. But it carries examination weight: FINRA uses the annual report to communicate what examiners will focus on in upcoming examinations. Classifying agentic AI as an active supervisory priority means examiners will ask about it.

What FINRA rules apply to AI agent use? Existing rules apply: Rule 3110 (Supervision) covers all firm activities including those conducted by AI systems. Rule 4370 (BCP) covers AI system failures. Rule 2210 (Communications with the Public) covers AI-generated client communications. No AI-specific rules have been promulgated, but none are needed for existing rules to apply.

What is the difference between generative AI and agentic AI for supervisory purposes? Generative AI produces outputs in response to prompts. Agentic AI autonomously interprets objectives, takes multi-step actions, interfaces with external systems, and adapts without human approval at each step. The supervisory implications differ because human review isn’t happening between agentic AI actions.

What does “meaningful human-in-the-loop” mean for AI agents? A meaningful human oversight control is one that actually operates — a person reviews, approves, or has the opportunity to stop an AI-initiated action before it reaches the customer or affects an account. A theoretical override capability that nobody uses in practice doesn’t satisfy supervisory standards.

My firm uses a vendor’s AI — are we responsible for what it does? Yes. FINRA’s guidance is clear that firms cannot delegate supervisory responsibility to AI vendors. You are responsible for testing the vendor’s tool before deployment, monitoring its outputs after deployment, and supervising the actions it takes within your environment.


Sources: FINRA 2026 Annual Regulatory Oversight Report; FINRA 2026 Report PDF; Debevoise: FINRA’s 2026 Report — Generative AI and Emerging Agent-Based Risks; FINRA Blog: Observations on AI Agents; McGuireWoods: FINRA’s 2026 Report on AI and Cybersecurity

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Does FINRA's 2026 Oversight Report create new rules for broker-dealers using AI agents?
No. The 2026 Annual Regulatory Oversight Report is an examination guidance document, not a rulemaking. FINRA explicitly states it does not carry binding regulatory force and does not create new obligations. However, it does carry significant examination weight: FINRA issues the report annually to communicate what examiners will be looking for during the upcoming cycle. Classifying agentic AI as an 'active supervisory priority' means examiners will ask about agent governance in broker-dealer examinations in 2026 — regardless of whether formal rules have been promulgated.
What is the difference between generative AI and agentic AI under FINRA's classification?
FINRA's 2026 report distinguishes the two by autonomy and action scope. Generative AI produces outputs (text, code, summaries) in response to a prompt. Agentic AI goes further: it interprets objectives, takes multi-step actions, interfaces with external systems, and adapts dynamically to changing conditions — often without human approval at each step. An AI that drafts a client email is generative AI. An AI that sends that email, books a follow-up, updates the CRM, and routes an alert if the client doesn't respond is agentic AI. The governance implications are meaningfully different.
Which FINRA rules apply to AI agent use by broker-dealers?
FINRA hasn't issued AI-specific rules; existing rules apply. FINRA Rule 3110 (Supervision) requires firms to establish and maintain a supervisory system for all activities — including those conducted by AI systems. FINRA Rule 4370 (Business Continuity Plans) requires firms to have BCPs that address the failure or unavailability of critical systems, which now include AI systems used in operations. Communications generated or sent by AI must comply with FINRA Rule 2210 (Communications with the Public) — fair, balanced, not misleading, properly reviewed, and retained per recordkeeping requirements.
What does FINRA say about AI hallucinations and broker-dealer liability?
FINRA's 2026 report defines hallucinations as 'instances where the model generates information that is inaccurate or misleading, yet is presented as factual information.' The report specifically flags the risk of a model misinterpreting regulatory requirements or misstating client information, and treats hallucinations as a testing and monitoring problem requiring supervisory controls — not an inherent AI limitation that excuses inaccurate outputs. A broker-dealer that allows AI-generated client communications containing hallucinated information to go unreviewed is treating a compliance failure as a technology limitation.
What should broker-dealer supervisory procedures say about AI agents specifically?
At minimum, supervisory procedures for AI agents should cover: (1) how the firm classifies AI tools between generative and agentic; (2) what human oversight steps are required before AI-initiated actions affecting customers, accounts, or communications; (3) how AI-generated communications are reviewed and retained; (4) what testing and monitoring the firm conducts for accuracy and hallucination detection; (5) who is responsible for oversight of each AI tool; and (6) how the firm handles AI failures, unexpected outputs, or customer complaints about AI-generated content.
My firm uses a vendor's AI tool — does our supervisory responsibility extend to what the vendor's model does?
Yes. FINRA's guidance is clear that firms cannot delegate supervisory responsibility to a third-party AI vendor. The vendor builds and maintains the model; the firm is responsible for supervising how the model is deployed and used in its operations. This means your supervisory procedures must cover how you tested the vendor's AI before deployment, how you monitor its outputs, how you respond to vendor model updates, and what your escalation process is when the AI produces unexpected results. Vendor due diligence for AI tools should document all of this.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.