shipping production AI · since 2026 NAICS 541330 / 541511 / 541512 / 541519  ·  CMMC-aware
Refinery Report / AI Governance / post · s-2026
AI GovernanceFINRABroker-DealersAgentic AI

FINRA AI Agent Governance for Broker-Dealers in 2026

FINRA's 2026 Annual Regulatory Oversight Report singles out autonomous AI agents as a distinct supervisory risk. What that means for a broker-dealer's Rule 3110 program, and the control set examiners will expect to see.

D
By the DSE practice team
Operator-led practice · how we research & review
October 8, 2026
11 min · 2,346 words

By the DSE practice team · published October 8, 2026 · reviewed October 8, 2026

FINRA’s 2026 Annual Regulatory Oversight Report treats autonomous AI agents as a distinct supervisory risk, separate from the generative AI tools firms have governed since Regulatory Notice 24-09. The report flags agents that act without a human approving each step, that can stretch beyond the task they were given, and that are hard to audit after the fact. No new rule accompanies that flag. In practice, a broker-dealer’s existing Rule 3110 supervisory system, Rule 2210 communications review, and Rule 4511 recordkeeping now have to reach a category of tool most written supervisory procedures were never drafted to describe: one that takes actions, not just one that drafts text.

This is for the Chief Compliance Officer or Head of Model Risk at a broker-dealer or dual registrant who already has an AI use inventory and a generative AI policy in place and now has to answer a sharper question: which of the firm’s AI tools are agents, and does the supervisory program actually govern what an agent does rather than just what it outputs. DSE runs this gap assessment inside its broker-dealer AI compliance engagement; the framework below is the same one we use whether you bring in a third party or run it internally.

What FINRA’s 2026 report actually changed

FINRA did not create a new agentic AI rule, and nothing below should be read as one. The 2026 report, released December 9, 2025, carries forward the generative AI section that first appeared in the 2025 edition and adds language specific to agents: systems capable of planning and executing tasks across multiple data sources and applications with limited human involvement. The framing is explicit about why that matters to a supervisor. An agent that acts without sign-off can exceed its intended authority, is harder to audit than a tool that only produces a draft for a human to review, and can touch sensitive data across a multi-step task in ways a single-prompt tool would not.

The legal mechanism is the one Regulatory Notice 24-09 established in June 2024: FINRA’s existing rules are technology-neutral. Rule 3110 requires a supervisory system reasonably designed to achieve compliance regardless of what technology is in use. Rule 2210 requires principal review of retail communications regardless of who or what drafted them. Rule 4511 requires books and records regardless of the system that generated the underlying decision. None of those rules mention AI, let alone agents. The Oversight Report is FINRA telling member firms, in effect, that an agent does not get a pass for being a new category of tool. If it supervises, communicates, or creates a record, the old rule already reaches it.

The practical consequence: a firm cannot treat “we have an AI governance program” as the end of the inquiry. The question an examiner will ask is narrower, for the specific agents in production: who is the named supervisor, where is the authority boundary written down, and what happens when the agent is wrong.

Why an agent is a different supervisory problem than a chatbot

Most broker-dealer AI governance programs built since 2024 were designed around a single-turn model: a representative asks a question, a model answers, a human decides whether to use the answer. That architecture maps cleanly onto Rule 3110’s assumption that a person makes the decision a supervisor then reviews. An agent breaks that assumption in three specific ways that a generic AI policy usually does not address.

What changes with an agent Why Rule 3110 supervision gets harder The control that closes the gap
It takes a sequence of actions, not one output A supervisor reviewing a final answer never sees the intermediate steps where an overreach happened An action-level audit trail that logs each step, not just the result
It can call other systems and tools on its own Access the agent was never explicitly granted can still be reachable if the firm’s systems are loosely segmented A written authority boundary naming exactly which systems and actions the agent may reach without escalation
It can act continuously, not only when asked Spot-checking outputs after the fact misses an agent that has been making a bad call repeatedly between reviews A defined human-review sampling cadence, not a one-time validation at launch
It is harder to reproduce after the fact An examiner asking “why did it do that” needs a specific, retrievable answer Retained logs tied to the Rule 4511 recordkeeping schedule, not ephemeral session data
It can be wrong in ways that compound A single bad decision early in a multi-step task can propagate into later steps before a human sees any of them A tested kill switch or access-revocation path, independent of the agent’s own interface

That last row is the one most programs skip entirely. A policy that says a human can “turn off the agent” is not the same as a tested procedure that confirms the kill switch actually works, who is authorized to use it, and how fast access is actually revoked once someone decides to pull it.

The five controls an examiner will look for

Turning the table above into something an examiner can be shown means naming each control, its owner, and the record that proves it exists.

  1. Action-level audit trail. Every autonomous action, not only the final output, is logged with a timestamp, the system or data touched, and the triggering input, retained under the same schedule that governs other supervisory records under Rule 4511 and, for broker-dealers, SEC Rule 17a-4.
  2. Written authority boundary. A document, not a verbal understanding, names exactly which systems, data, and actions each agent may reach without escalation, and what happens when it attempts something outside that boundary.
  3. Named supervisory reviewer with an override path. A specific person, tied to a Rule 3110 written supervisory procedure, is accountable for reviewing or approving an agent’s actions before they reach a customer or execute a transaction.
  4. A kill switch that has actually been tested. The ability to immediately disable or quarantine an agent, independent of its own interface, with a dated record of the last test and its result. An untested kill switch is a design intention, not a control.
  5. A human-review sampling cadence for agent outputs. Ongoing review, not a one-time validation at launch, with a documented frequency and a log of findings, the same fair-dealing and hallucination concern FINRA has flagged for generative AI generally.

A firm that can produce an owner, an artifact, and a dated record for each of these five is in a materially stronger position than one that can only point to a general AI policy.

How this differs from the SR 26-2 carve-out banks are navigating

Banks reading about agentic AI governance this year have been working through a different problem: SR 26-2, the revised interagency model risk management guidance issued in April 2026, explicitly excluded generative and agentic AI from its scope, leaving banks to figure out what still governs an agent once the model risk framework no longer claims it. We cover that gap in detail in Agentic AI Governance for Banks: What Applies When SR 26-2 Doesn’t.

A broker-dealer does not have that same carve-out to worry about, because FINRA’s supervisory rules were never framed as model risk guidance. Rule 3110 does not ask whether a tool is a model; it asks whether the firm’s supervisory system reasonably achieves compliance given whatever technology is in use. That technology-neutral framing means an agent was already inside FINRA’s rules before the 2026 report said so explicitly. Read it as FINRA closing a readiness gap in how firms applied rules that already reached agents, not as the agency opening a new scope question the way SR 26-2 did for banks. The compliance task is narrower: show the five controls above actually exist for each agent in production, not debate which framework claims the agent.

Building the control set before the next exam cycle

  1. Separate agents from single-turn AI tools in the inventory. An inventory built before 2026 likely lists tools by vendor or business function, not by whether they act autonomously. Add a field that flags agentic behavior; the discovery method for finding the full AI footprint, including tools adopted outside procurement, is covered in AI Use Inventory for Broker-Dealers and RIAs and Shadow AI Discovery for Finserv.
  2. Write the authority boundary for each agent identified. Name the systems, data, and actions each agent may reach without escalation, and route anything outside that boundary to a human.
  3. Assign a named supervisory reviewer to each agent inside an existing Rule 3110 WSP section. An agent without an owner in the written supervisory procedures is not supervised, regardless of what the underlying AI policy says.
  4. Test the kill switch and log the result. Confirm who can trigger it, how long revocation actually takes, and what the agent can still do before access is fully cut off.
  5. Set a human-review sampling cadence and confirm Rule 2210 still applies. Define how often agent outputs get reviewed for accuracy and fair-dealing concerns, retain the log, and route any customer-facing agent output through the same principal pre-approval a person’s draft would get.

This is readiness work, not certification. DSE prepares broker-dealers for examination and helps assemble the evidence an examiner expects; we do not certify FINRA compliance and we do not guarantee any examination outcome.

What this guide is / What it is not

What it is: A practitioner framework for identifying which of a broker-dealer’s AI tools are autonomous agents, and the five supervisory controls FINRA’s 2026 Annual Regulatory Oversight Report and existing Rule 3110, Rule 2210, and Rule 4511 obligations expect a firm to be able to show.

What it is not: Legal advice, a new regulatory requirement, or a guarantee of any examination outcome. FINRA has not issued an agent-specific rule; the Oversight Report is a supervisory and examination-priorities document, and whether a specific agent’s governance satisfies Rule 3110 is a legal and factual determination for your counsel, not a conclusion in a blog post. DSE prepares organizations for audit and examination; we do not certify, and we do not guarantee passing an exam.

FAQ

Did FINRA issue a new rule for AI agents in 2026? No. FINRA’s 2026 Annual Regulatory Oversight Report, published December 9, 2025, discusses autonomous AI agents as a distinct risk profile and names the oversight firms should have in place, but it is a supervisory and examination-priorities document, not a new rule. The obligations that reach an agent are the existing technology-neutral rules Regulatory Notice 24-09 already applied to generative AI: Rule 3110 supervision, Rule 2210 communications review, and Rule 4511 recordkeeping.

How is an AI agent different from the chatbots and drafting tools our AI policy already covers? An agent plans and executes a sequence of actions across systems with limited human involvement, rather than producing one output for a person to review. That changes what a supervisor has to see: not just a final answer, but the intermediate steps, the systems reached, and whether the agent stayed inside its intended scope. A policy written around single-turn tools usually has no mechanism to capture any of that.

What is the single control examiners are most likely to ask about first? The named supervisory reviewer tied to a specific Rule 3110 written supervisory procedure for each agent in production. Without that, none of the other controls, the audit trail, the authority boundary, the kill switch, have an owner accountable for acting on what they show.

Do RIAs face the same AI agent supervisory expectations as broker-dealers? The underlying concern, autonomous action without adequate human oversight, is the same, but the legal hook differs. A dually registered firm or an adviser-side agent is anchored more in Investment Advisers Act fiduciary and disclosure obligations than in FINRA’s Rule 3110, 2210, and 4511 framework. Our AI governance for RIAs page covers the adviser-specific version of this readiness work.

How often should the five agent controls be reviewed once they are in place? Treat a new agent, a materially changed authority boundary, or a vendor’s model update as a trigger for an off-cycle review of all five controls, and review the full set at least quarterly for any agent active in a client-facing or transaction-executing role. A kill switch that was tested at launch and never again is not meaningfully different from one that was never tested.

The Bottom Line

FINRA’s 2026 report did not create a new compliance regime for AI agents; it confirmed that the Rule 3110, Rule 2210, and Rule 4511 obligations a broker-dealer already carries reach autonomous systems the same way they reach any other technology, and named the oversight gap most firms have not yet closed. The five controls, an action-level audit trail, a written authority boundary, a named supervisory reviewer, a tested kill switch, and a human-review sampling cadence, are what turn a general AI policy into evidence an examiner accepts for the specific agents a firm runs.

Start with the AI Governance Checklist to structure the discovery and control-mapping work, and review the finserv compliance overview for how agent-specific supervision fits inside a broader, audit-ready AI governance program. The Exam-Readiness AI Evidence-Pack Generator is a free starting point for turning your agent inventory into the evidence pack an exam response window will actually require.

Key facts

Read next · AI Security & Governance

P
Founder · Principal Engineer
Data & AI engineer · 10+ yrs hands-on

Writes most of the long-form here. Lives in the codebase. Active on GitHub and LinkedIn.

§ Next step

Not sure which of these is you?

Tell us what's broken in a paragraph and a principal reads it directly, or walk the ladder from a low-commitment first engagement up to retained work.

One long-form a week. No marketing.

Subscribe to the Refinery Report. Practitioner deep-dives on AI engineering, security, and the realities of running production systems. Unsubscribe in one click.

~12 issues / quarter