FINRA’s position on generative AI is short and can be stated in one sentence: the rulebook is technology-neutral and already applies. The value of the notice is not in what it adds but in which existing rules it names, because those are the ones an examination will be conducted against.
What Notice 24-09 is and is not
Regulatory Notice 24-09, issued on 27 June 2024, is titled “FINRA Reminds Members of Regulatory Obligations When Using Generative Artificial Intelligence and Large Language Models”. FINRA publishes Regulatory Notice 24-09. The word “reminds” in the title is doing real work. The notice creates no new rule, proposes no rule change, and does not require Securities and Exchange Commission approval, because it does not amend the rulebook. It restates that FINRA rules are technology-neutral and identifies the obligations most likely to be engaged.
It is nonetheless the document to build a compliance file around, for a practical reason: it tells you what examiners were told to think about. A firm whose AI governance is organised under the same rule headings the notice uses is answering the question in the form it will be asked. FINRA’s annual Regulatory Oversight Report has also carried sections on AI, and those describe observed practices and findings rather than requirements.
Not legal or compliance advice. Obligations differ by business line, by registration category and by the specific use, and a member firm’s supervisory procedures must be tailored to its own business. Consult your own compliance and legal functions.
Rule 3110 and the supervisory system
FINRA Rule 3110 requires each member to establish and maintain a supervisory system reasonably designed to achieve compliance with applicable securities laws and FINRA rules, and to have written supervisory procedures. FINRA publishes Rule 3110. Rule 3120 requires a system of testing and verifying those procedures.
“Reasonably designed” is the operative phrase and it is outcome-oriented: a procedure is not reasonably designed merely because it exists. For generative AI the specific supervisory questions are the ones the technology creates rather than the ones the rulebook enumerates:
- Inventory and approval. Which tools are in use, approved by whom, for what. Unapproved use by registered representatives is the most common finding, and it is a supervision failure regardless of whether any output was ever sent to a customer.
- Accuracy controls on outputs used with customers. A model that fabricates a fund’s expense ratio inside a client-facing summary produces a communications violation. The control is review before use, not confidence in the model.
- Confidentiality and information barriers. A shared assistant with access to material non-public information, or one that crosses a barrier between research and trading, is an information barrier problem with a new shape.
- Customer data and Regulation S-P. Sending customer information to a third-party model provider engages the safeguards rule and the firm’s privacy obligations.
- Testing. Rule 3120 means the AI controls have to be tested, not merely written. Sampling outputs and checking review evidence is the concrete form of that.
Rule 2210 and AI-generated communications
Rule 2210 governs communications with the public and imposes content standards: communications must be fair and balanced, must provide a sound basis for evaluating the facts, and may not be false, exaggerated, promissory or misleading. FINRA publishes Rule 2210. It also imposes approval, review and filing requirements depending on whether a communication is retail, institutional or correspondence.
Nothing in Rule 2210 turns on who or what drafted the communication. An AI-drafted retail communication requires principal approval before use in exactly the way a human-drafted one does, and the filing requirements apply identically. The compliance risk is volume: a tool that lets every representative generate tailored market commentary produces a review queue that the existing principal-approval process was not sized for, and the failure mode is approval becoming nominal.
There is a second-order point specific to AI. Claims a firm makes about its own use of AI are themselves communications subject to Rule 2210, and overstating them is both a FINRA content-standards problem and, for an adviser, a route to the enforcement actions described in the SEC’s AI washing cases. See also the law on AI marketing claims.
Books, records and Reg BI
FINRA Rule 4511 requires members to make and preserve books and records as required under FINRA rules, the Securities Exchange Act and its rules, and to preserve records for which no period is specified for at least six years. FINRA publishes Rule 4511. The underlying Exchange Act rules are 17a-3 and 17a-4.
For AI this produces a concrete engineering requirement that is easy to miss: if a generative tool produces a communication with a customer, the communication is a record. Whether the prompt and the model version are also records is less settled, but they are the only way to reconstruct how a communication came to say what it said, and a firm that cannot reconstruct that is in a poor position during an examination. The defensible practice is to retain the prompt, the model identifier and version, the output, and the identity of the principal who approved it.
Regulation Best Interest is engaged wherever an AI system contributes to a recommendation to a retail customer. Reg BI’s care obligation requires a reasonable basis to believe the recommendation is in the customer’s best interest; a recommendation the firm cannot explain is a recommendation for which it cannot demonstrate a reasonable basis. The SEC also proposed rules in 2023 addressing conflicts of interest associated with predictive data analytics in interactions with investors; that proposal drew substantial opposition and should not be described as in force. Check its current status before relying on it in either direction.
Vendor management and outsourcing
Most member-firm AI is bought, not built. FINRA addressed third-party vendor management in Regulatory Notice 21-29, which reminds members that outsourcing an activity does not relieve them of their supervisory obligations and sets out due diligence and ongoing monitoring expectations. FINRA publishes Regulatory Notice 21-29.
The AI-specific diligence questions are the same ones a bank asks under the interagency third-party guidance: which model providers sit behind the product, what the retention and training terms are, how you learn when a model version changes, and what happens on termination. See third-party AI model risk for the fuller lifecycle treatment; the framing differs but the questions do not.
What the notice leaves open
Notice 24-09 is deliberately short and there are things it does not answer. Saying so is more useful than inferring an answer.
- Whether an AI-generated research summary is research. The research rules turn on definitions written for human analysts. A tool that produces investment analysis for distribution raises the question and the notice does not resolve it.
- What supervision means for an assistant used internally. A tool used only to draft internal memoranda is plainly lower risk, but no threshold is stated, and firms have taken materially different positions on where approval is required.
- Whether prompts are required records. Treated above as good practice; it is not stated as an obligation anywhere.
- How disclosure to customers should work. There is no general FINRA rule requiring a firm to tell a customer that AI was used in producing a communication. Several state and non-US regimes are moving in that direction; FINRA has not.
A firm answering these in writing, with reasoning, is in a far better position than one that answered them implicitly by deployment. The reasoning is what a reasonably designed supervisory system looks like when the rule does not supply the answer.
Top comments (0)