Feature AI Risk
FINRA's 2026 Oversight Report Moved Agentic AI to Active Examination Priority. Examiners Are Now Asking About It. Here's What Broker-Dealers Need in Place.
FINRA's 2026 Annual Regulatory Oversight Report formally classified agentic AI as an active supervisory priority, with examinations targeting broker-dealer governance in Q2-Q3 2026. Here is what examiners are asking about and what your program needs to have documented.
Table of Contents
TL;DR
- FINRA’s 2026 Annual Regulatory Oversight Report (published December 2025) formally classified agentic AI as an active supervisory priority — moving it from “emerging technology” to a standing examination topic.
- Examiners are checking for AI agent governance in broker-dealer examinations in Q2-Q3 2026. If you haven’t updated your supervisory procedures for AI agents, you may be caught flat-footed.
- The biggest compliance risks FINRA flagged: AI agents operating without human-in-the-loop oversight, agent permission and access control gaps, and AI-generated communications that are sent without proper review and retention.
- The 2026 report is not a rulemaking — but existing rules apply: FINRA Rule 3110 (Supervision), Rule 4370 (BCP), and Rule 2210 (Communications) all reach AI-generated and AI-initiated activity.
In December 2025, FINRA published its 2026 Annual Regulatory Oversight Report — the annual document that tells broker-dealers what examiners will be focused on in the upcoming cycle. The AI section in the 2026 report is different from what appeared in prior years: generative AI moved from “emerging risk” to standing examination priority, and agentic AI appeared for the first time as a distinct risk category that FINRA explicitly flagged for supervisory attention.
Nine months later, examiners are in the middle of the examination cycle the 2026 report previewed. If your firm deployed AI agents — tools that autonomously take actions, send communications, interface with external systems, or make recommendations without human review at each step — and you haven’t updated your supervisory procedures to reflect them, this is your notice.
What the 2026 Report Actually Said About Agentic AI
FINRA’s 2026 Regulatory Oversight Report contains a standalone section on Generative AI that substantially expands on prior years’ coverage. The key shift: the 2026 report distinguishes generative AI from agentic AI and treats them as requiring different supervisory approaches.
FINRA defines agentic AI as systems capable of autonomously interpreting objectives, taking multi-step actions, interfacing with external tools and data sources, and adapting dynamically to changing environments — often without human approval at each step. This is distinct from generative AI that produces a response to a prompt and waits.
The practical difference matters for compliance: a generative AI that drafts a client suitability recommendation sits in the supervised-outputs bucket. An AI agent that receives a portfolio alert, generates a recommendation, sends the recommendation to the client via email, and follows up if the client doesn’t respond in 48 hours — that’s an agentic system, and it requires a different supervision model because human review isn’t happening between each action.
FINRA’s blog post on AI agent observations noted that member firms are already deploying agentic AI across functions including research synthesis, operational workflows, client communication, and compliance monitoring. The 2026 report formalized FINRA’s posture: these deployments require supervisory controls that firms haven’t always put in place.
”Active Supervisory Priority” vs. “Emerging Technology”
The language shift in the 2026 report is not subtle. Prior years classified AI as an “emerging technology” topic — something examiners were monitoring and that firms should be thinking about. The 2026 report moved agentic AI to “active supervisory priority,” which is examination terminology with a specific meaning: examiners will ask about it.
Debevoise’s analysis of the 2026 report notes that this classification means member firms should expect direct examiner inquiries about their agentic AI governance in upcoming exams, separate from the broader technology and cybersecurity review.
What examiners are asking about, per FINRA’s examinations in Q2-Q3 2026:
- Governance documentation: Does the firm have a written policy or procedure that defines what constitutes an AI agent and what the supervisory requirements are?
- Human oversight controls: For AI-initiated actions affecting customers or accounts, what human review steps exist? Is there a meaningful “human in the loop” or just a theoretical one?
- Permissions and access: What can each AI agent access and what can it initiate? Are permissions scoped to what the agent actually needs, or are agents running with broad system access?
- Communications compliance: When AI generates or sends communications with customers, how does the firm ensure those communications meet Rule 2210 standards? How are they reviewed and retained?
- Testing and monitoring: How does the firm test AI accuracy before deployment? How does it monitor for hallucinations, drift, or unexpected outputs after deployment?
- Vendor oversight: For third-party AI tools, what due diligence did the firm conduct before deployment, and how does the firm supervise outputs from a model it didn’t build?
The Three Risk Areas FINRA Flagged for Examinations
1. AI Agents Operating Without Meaningful Human Oversight
FINRA’s 2026 report identified AI agents acting autonomously with no “human in the loop” as the highest-priority governance concern. The risk is real: if an AI agent can send a communication, execute a recommendation, or initiate an account action without human review, and it does so based on a hallucinated or misinterpreted input — the supervisory failure is the firm’s, regardless of whose model was running.
The supervisory procedures requirement under FINRA Rule 3110 applies to all activities the firm conducts, including activities conducted by AI systems. An AI agent that takes customer-facing actions isn’t exempt from supervision because it’s automated — it requires supervision designed for its specific risk profile.
What “meaningful” human oversight looks like depends on what the agent does. An agent that generates a draft recommendation for human review and approval before any customer contact is different from an agent that generates and sends recommendations directly. Both require supervision; the latter requires more.
Debevoise’s analysis specifically notes that FINRA’s concern is not that firms are using AI agents, but that many have deployed them without building the supervisory infrastructure to match. The technology outpaced the governance.
2. Agent Permission and Access Control Gaps
The 2026 report flagged “agent permission/access issues” as a distinct risk category. The concern: AI agents with overly broad system permissions can access data, initiate actions, or interface with external systems in ways that weren’t intended — and without access logs or controls, the firm may not know until something goes wrong.
Firms deploying AI agents should be able to answer: What can each agent access? What can each agent initiate? What system calls can each agent make? What are the human authorization requirements before an agent can take a high-stakes action — placing a trade, sending a communication, modifying account information?
If agents are running with broad read-write access to systems because that was the path of least resistance at deployment, that’s a permissions gap examiners are looking for.
The access control question also extends to agent-to-agent interactions. Some agentic AI systems involve multiple agents collaborating — a research agent handing off to a recommendation agent handing off to a communication agent. Each handoff point is a permission boundary that needs to be defined.
3. AI-Generated Communications and Rule 2210 Compliance
FINRA Rule 2210 requires that all communications with the public be fair, balanced, not misleading, approved by a principal, and retained per recordkeeping requirements. When AI generates or assists in drafting those communications, every part of that obligation still applies.
The 2026 report is explicit: AI-generated hallucinations in client communications are not an acceptable failure mode. A model that “misinterprets regulatory requirements” or “misstates client information” in a communication creates a compliance violation — the AI’s error doesn’t relieve the firm of responsibility for what it sent.
What this requires in practice:
- Human review of AI-generated client communications before delivery, or a supervision system that can review at scale
- Retention of AI-generated communications in the same manner as any other record
- Audit trails showing who approved communications and when
- Testing protocols that specifically look for hallucinated facts, incorrect regulatory citations, or mischaracterized product information
If your firm is using AI to draft client emails, suitability letters, or recommendations at scale — with the goal of efficiency — the supervision model has to scale proportionally. Approving 100% of AI-generated communications individually may not be feasible; a sampling-based supervision model with clear escalation criteria is the alternative examiners are more likely to accept as reasonable.
What Your Supervisory Procedures Need to Say About AI
Most broker-dealer supervisory procedures written before 2025 don’t mention AI agents. Some have been updated to reference generative AI in a general way. Very few have been updated to address agentic AI as a distinct supervisory category with its own requirements.
Here’s what updated procedures should cover:
Scope definition. What constitutes an AI agent at your firm, and how is it distinguished from generative AI tools? Without a definition, you can’t apply different supervisory requirements to different tools.
Inventory and approval process. Before a new AI agent is deployed, what review is required? Who approves it, and on what criteria? This is the pre-deployment equivalent of the new-product approval process — and it needs to be documented.
Action authorization requirements. For agents that take customer-facing actions (communications, recommendations, account modifications), what human authorization is required? At what thresholds does human review become mandatory vs. advisory?
Testing and monitoring standards. Before deployment: what testing for accuracy, hallucination rates, and unexpected outputs? After deployment: what ongoing monitoring and at what frequency?
Communications review and retention. How AI-generated communications are reviewed, approved, and retained. Who is the responsible principal for AI-generated communications, and what does their review process look like?
Vendor AI oversight. For third-party AI tools, what due diligence was conducted? How does the firm monitor vendor model updates that might affect compliance? What escalation exists if a vendor’s model behaves unexpectedly?
Incident response. What happens when an AI agent produces a significant error — a hallucinated fact in a client communication, an unauthorized action, an unexpected output? Who is notified, what is the remediation process, and what is the recordkeeping requirement?
The McGuireWoods analysis of FINRA’s 2026 report notes that firms treating AI governance as a technology question rather than a supervisory procedure question are misunderstanding what FINRA is looking for. Examiners will review supervisory procedures, not technology architecture.
The Vendor Oversight Problem Specific to AI
Most broker-dealers using AI are using third-party models — not models built and trained in-house. This creates a supervisory complexity that FINRA’s 2026 report specifically addressed.
Firms cannot delegate supervisory responsibility to an AI vendor. The vendor builds and maintains the model; the firm is responsible for supervising how the model performs in its environment. When a vendor’s model produces a hallucinated regulatory citation or mischaracterized client account detail, the firm’s supervisory obligation was to have a system in place that caught it before it reached the client.
What this means for vendor AI due diligence:
- What testing did you conduct before deploying the vendor’s model?
- How do you monitor the vendor’s model outputs after deployment?
- What is your process when the vendor updates the underlying model — do you re-test before the updated model goes live in your environment?
- What contractual obligations does the vendor have to notify you of material model changes or incidents?
This connects directly to the vendor oversight expectations that regulators have been articulating across financial services. For the full picture of what AI vendor due diligence needs to cover, see our analysis of the FTC’s Cox Media Group settlement and what AI vendor due diligence needs to catch.
For firms with EU operations or EU-customer exposure, the EU AI Act inspection wave that began August 30 adds a parallel documentation requirement for high-risk AI systems — one that carries significantly higher penalties than FINRA examination findings.
So What?
The FINRA 2026 Annual Regulatory Oversight Report does not change what rules apply to AI. What it does is tell you, with significant specificity, that examiners are asking about AI agent governance right now — and what they’re looking for.
If your firm deployed AI agents in 2025 or early 2026 and your supervisory procedures haven’t been updated since, you’re in the situation the 2026 report was designed to prevent: governance that trails technology adoption.
The firms that are exam-ready on agentic AI have two things in common: a written definition of what an AI agent is at their firm, and supervisory procedures that are specific about what oversight those agents require. Everything else — testing protocols, communication review, vendor oversight, incident response — flows from those two foundations.
| Examination Focus Area | What Examiners Ask | What Needs to Be Documented |
|---|---|---|
| Agent governance | Do you have written procedures for AI agents? | Supervisory procedures covering AI agent classification, authorization, oversight |
| Human-in-the-loop | What human oversight exists before AI actions? | Authorization thresholds, approval workflows, escalation criteria |
| Permissions and access | What can agents access and initiate? | Permission inventory, scope limitations, authorization requirements |
| Communications compliance | How are AI communications reviewed? | Review and approval process, retention records, principal sign-off |
| Testing and monitoring | How do you test for hallucinations? | Pre-deployment testing results, ongoing monitoring logs |
| Vendor oversight | Who is responsible for the third-party model? | Due diligence documentation, vendor monitoring procedures |
The AI Risk Assessment Template & Guide includes an AI use case inventory with auto-tiering, a 44-question pre-deployment risk assessment, a 31-question third-party AI vendor questionnaire, and 8 worked examples — covering Shadow AI, vendor AI tools, and customer-facing GenAI deployments. Designed for compliance and risk teams that need to move from “we’re aware of the issue” to a documented program.
Frequently Asked Questions
Does FINRA’s 2026 report create new rules for AI? No — it’s examination guidance, not a rulemaking. But it carries examination weight: FINRA uses the annual report to communicate what examiners will focus on in upcoming examinations. Classifying agentic AI as an active supervisory priority means examiners will ask about it.
What FINRA rules apply to AI agent use? Existing rules apply: Rule 3110 (Supervision) covers all firm activities including those conducted by AI systems. Rule 4370 (BCP) covers AI system failures. Rule 2210 (Communications with the Public) covers AI-generated client communications. No AI-specific rules have been promulgated, but none are needed for existing rules to apply.
What is the difference between generative AI and agentic AI for supervisory purposes? Generative AI produces outputs in response to prompts. Agentic AI autonomously interprets objectives, takes multi-step actions, interfaces with external systems, and adapts without human approval at each step. The supervisory implications differ because human review isn’t happening between agentic AI actions.
What does “meaningful human-in-the-loop” mean for AI agents? A meaningful human oversight control is one that actually operates — a person reviews, approves, or has the opportunity to stop an AI-initiated action before it reaches the customer or affects an account. A theoretical override capability that nobody uses in practice doesn’t satisfy supervisory standards.
My firm uses a vendor’s AI — are we responsible for what it does? Yes. FINRA’s guidance is clear that firms cannot delegate supervisory responsibility to AI vendors. You are responsible for testing the vendor’s tool before deployment, monitoring its outputs after deployment, and supervising the actions it takes within your environment.
Sources: FINRA 2026 Annual Regulatory Oversight Report; FINRA 2026 Report PDF; Debevoise: FINRA’s 2026 Report — Generative AI and Emerging Agent-Based Risks; FINRA Blog: Observations on AI Agents; McGuireWoods: FINRA’s 2026 Report on AI and Cybersecurity
◆ Need the working template?
Start with the source guide.
These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.
◆ Related template
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Immaterial Findings · Weekly
Sharp risk & compliance insights. No fluff.
◆ FAQ
Frequently asked questions.
Does FINRA's 2026 Oversight Report create new rules for broker-dealers using AI agents?
What is the difference between generative AI and agentic AI under FINRA's classification?
Which FINRA rules apply to AI agent use by broker-dealers?
What does FINRA say about AI hallucinations and broker-dealer liability?
What should broker-dealer supervisory procedures say about AI agents specifically?
My firm uses a vendor's AI tool — does our supervisory responsibility extend to what the vendor's model does?
Author
Rebecca Leung
Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.
◆ Related framework
AI Risk Assessment Template & Guide
Comprehensive AI model governance and risk assessment templates for financial services teams.
◆ Keep reading
Related posts.
AI Risk
Cox Media Group's 'Active Listening' Fallout: What the FTC Settlement Means for AI Vendor Due Diligence
The FTC finalized consent orders against Cox Media Group and two smaller firms on August 27, 2026, over deceptive 'active listening' AI claims — marketing that phones were capturing voice data to target ads. They weren't. The $930,000 in penalties and 20-year oversight period signal what the FTC will do with vendors who overclaim AI capabilities. Here's what your AI vendor due diligence program needs to cover.
Sep 6, 2026
AI Risk
The EU AI Office Started On-Site Audits August 30. Here's What September 2026's High-Risk AI Inspections Are Actually Requesting.
The August 2 compliance deadline has passed. Now the European AI Office and 24 national market surveillance authorities are conducting the EU AI Act's first wave of on-site inspections — targeting credit scoring, AML monitoring, and algorithmic HR tools. Here's what inspectors are requesting and what deployers need in place.
Sep 5, 2026
AI Risk
The FTC Just Put AI Pricing on Notice. What the Personalized Pricing Statement Means for Your Fintech.
On August 19, 2026, the FTC proposed an enforcement policy on personalized pricing — using AI and consumer data to set individualized prices. The comment deadline is September 18. Here's what the financial services exception means, where the line blurs with AI, and what your compliance program needs to document.
Sep 4, 2026