Neither the SEC nor FINRA has written an AI rulebook: FINRA has said its existing rules apply to generative AI tools, and the SEC has enforced the Advisers Act and the Marketing Rule against advisers whose AI claims were untrue.
What counts as AI for this purpose
FINRA describes artificial intelligence as a wide-ranging term that generally means the capability of a machine to imitate intelligent human behavior. That breadth matters. For regulatory purposes the question is not whether a tool is marketed as AI. The question is what the tool does inside the firm, who relies on its output, and what the firm says about it to clients and the public.
In practice, firms meet AI in three places. First, in operations and compliance: tools that summarise documents, draft communications, or flag correspondence for review. Second, in the investment process: models that inform or make allocation decisions. Third, in marketing: statements to clients and prospects about what the firm’s technology can do. Each place maps to an existing obligation, and the two regulators have addressed them from different directions.
What FINRA has said
FINRA published Regulatory Notice 24-09 on June 27, 2024. The Notice states that it does not create legal or regulatory requirements, or interpretations of existing requirements, beyond those that already exist. FINRA states that its rules and the securities laws continue to apply when member firms use generative AI, just as they apply to any other technology or tool. The Notice is a reminder, not a rule. In our reading, that is the whole point: a firm cannot argue that an AI tool sits outside its supervisory obligations because no AI-specific rule exists.
The Notice gives supervision as its main example. Under Rule 3110 (Supervision), a member firm must have a reasonably designed supervisory system tailored to its business. If a firm uses generative AI as part of its supervisory system, for instance to review electronic correspondence, FINRA says its policies and procedures should address technology governance, including model risk management, data privacy and integrity, and the reliability and accuracy of the model. FINRA rules apply whether a firm develops generative AI tools for its own use or uses a third party’s technology, including through embedded features in existing third-party products. That last point closes an obvious gap. A feature switched on inside a vendor’s existing product is still the firm’s tool for supervisory purposes.
FINRA states that a firm should evaluate generative AI tools before deploying them and ensure it can continue to comply with existing FINRA rules that apply to the business use of those tools. FINRA has said that the content standards of Rule 2210 (Communications with the Public) apply whether a communication is generated by a human or by a technology tool. Depending on how a firm uses generative AI, FINRA says the use could implicate virtually every area of the firm’s regulatory obligations. The Notice lists accuracy, privacy, bias, intellectual property and possible exploitation by threat actors among the concerns that have accompanied generative AI.
FINRA also set out how it wants to hear from firms. Where a firm finds ambiguity in how the rules apply to its use of generative AI, FINRA says it may seek interpretive guidance through FINRA’s process for interpretive requests. FINRA also encourages firms to have ongoing discussions with their Risk Monitoring Analyst as AI-related issues or other changes in the business arise. FINRA notes that other federal and state laws, rules and regulations may also apply to a firm’s use of AI tools. FINRA has said it will consider issuing further guidance on how particular rules apply to specific use cases.
What the SEC has done
The SEC’s contribution to date has come through enforcement rather than guidance. The SEC announced settled charges against two investment advisers, Delphia (USA) Inc. and Global Predictions Inc., for making false and misleading statements about their use of AI, and the firms agreed to pay $400,000 in total civil penalties. The SEC gave the conduct a name: AI washing.
According to the SEC’s order, from 2019 to 2023 the Toronto-based Delphia made false and misleading statements in its SEC filings, in a press release and on its website about its use of AI and machine learning that incorporated client data. Delphia was also charged with violating the Marketing Rule, which prohibits a registered investment adviser from disseminating any advertisement that includes an untrue statement of material fact.
The order against Global Predictions, a San Francisco firm, found false and misleading claims about its use of AI on its website and social media in 2023, among them a claim to be the “first regulated AI financial advisor”. The SEC also found that Global Predictions violated the Marketing Rule by falsely claiming to offer tax-loss harvesting services and included an impermissible liability hedge clause in its advisory contract.
Without admitting or denying the findings, both firms consented to orders finding that they violated the Advisers Act, censuring them and ordering them to cease and desist. Delphia agreed to pay a civil penalty of $225,000 and Global Predictions agreed to pay $175,000.
SEC Chair Gary Gensler said at the time: “Investment advisers should not mislead the public by saying they are using an AI model when they are not. Such AI washing hurts investors.” Gurbir S. Grewal, Director of the SEC’s Division of Enforcement, put the test plainly: “if you claim to use AI in your investment processes, you need to ensure that your representations are not false or misleading.”
Two things stand out in these cases. Neither firm was penalised for using AI. Both were penalised for describing AI they did not have, and in Global Predictions’ case for other marketing and contract failures found alongside the AI claims. The lesson is not about the technology. It is about the truth of the firm’s own description of itself, in every channel: filings, press releases, websites and social media.
What the two regulators have in common
Read together, the FINRA Notice and the SEC orders point the same way. FINRA says the existing rules govern the tool. The SEC says the existing rules govern what you say about the tool. Neither has suggested that AI use is itself a problem, and neither has created an AI-specific obligation.
In our reading, the test is not whether a firm uses AI, but whether it can show what the tool does, who checks it, and whether its description of it is true.
That framing is useful because it tells a compliance officer where to look. The supervisory question is a Rule 3110 question for broker-dealers and a compliance-program question for advisers. The disclosure question is a Marketing Rule and antifraud question. The vendor question is a due-diligence question. None of these is novel. What is novel is the number of places in a firm where an AI feature can now appear without anyone in compliance having approved it.
What an examiner is likely to ask
Neither source describes a standard AI examination module, and we do not suggest one exists. But an examiner who has read the FINRA Notice and the SEC orders is likely to test the same points those documents raise. The table below sets out the questions we expect and the evidence that would answer them.
| Likely question | What to have ready |
|---|---|
| Which AI or generative AI tools does the firm use, and where? | An inventory covering in-house tools, vendor tools, and AI features embedded in existing products |
| Who approved each tool before it was deployed? | A dated pre-deployment evaluation for each tool, with the rules considered and the person who signed off |
| How does the firm supervise outputs the tool produces? | Procedures that address technology governance, model risk, data privacy and integrity, and accuracy, and evidence they are followed |
| Are AI-generated client communications reviewed to the same standard as human-written ones? | A review and approval trail that does not distinguish by author |
| What does the firm say publicly about its use of AI? | A list of every AI statement in filings, websites, social media, press releases and pitch material, with substantiation for each |
| Does the marketing match what the technology actually does? | A written reconciliation between each claim and the capability behind it, signed by someone who understands the technology |
| What data goes into the tool, and who can see it? | Data-flow documentation and vendor terms covering confidentiality and use of firm or client data |
| What has gone wrong, and what did the firm do? | An issues log for errors, inaccurate outputs or policy breaches, with remediation |
The order of these questions is deliberate. Inventory comes first because every later answer depends on it. A firm that cannot list its AI tools cannot show that it evaluated them, supervises them, or describes them accurately.
Implementation steps
The following checklist turns the regulators’ statements into work a compliance team can schedule.
- Build and maintain an AI tool inventory, including features inside vendor products that staff may have switched on without a procurement decision.
- Adopt a pre-deployment evaluation for any AI tool, recording the use case, the rules implicated, the data involved, the risks considered and who approved it.
- Where AI assists supervision or surveillance, amend policies and procedures to cover technology governance, model risk management, data privacy and integrity, and reliability and accuracy of the model.
- Route AI-generated communications with the public through the same content review as any other communication.
- Audit every public statement about AI, in filings, websites, social media, press releases and sales material, against what the technology does, and remove or correct anything that cannot be substantiated.
- Review advisory contracts and marketing material for the other failures the SEC found alongside AI claims, such as services the firm does not provide and liability hedge clauses.
- Add AI tools to vendor due diligence, with attention to confidentiality terms and the vendor’s own controls over accuracy and data use.
- Keep an issues log for AI-related errors and breaches, and feed it into the firm’s annual review of its compliance program.
- For FINRA members, raise material AI changes with the Risk Monitoring Analyst and use the interpretive request process where the application of a rule is genuinely unclear.
- Take legal advice where an AI use case touches disclosure obligations, contract terms or laws outside the securities rules. Taft does not provide legal advice.
A firm that can produce these records on request is in a different position from one that has to assemble them during an examination. Our exam readiness product is built around producing exactly that kind of evidence before the request arrives.
Questions people actually ask
Does FINRA’s Notice mean we need an AI policy? The Notice does not require a document with that title. It says existing rules apply, and that if AI forms part of supervision, the procedures should address governance, model risk, data privacy and integrity, and accuracy. Whether that lives in a standalone policy or inside existing procedures is a design choice. What matters is that the content exists and is followed.
We only use AI features inside our email archive and CRM. Does any of this apply? Yes. FINRA was explicit that its rules apply to third-party technology, including embedded features in existing third-party products. The inventory step above exists for this reason.
We do not use AI in the investment process, so is AI washing irrelevant to us? Not if the firm says anything about AI anywhere. The SEC’s findings against Global Predictions concerned website and social media claims in 2023. A marketing team that describes the firm as AI-driven creates the exposure regardless of what the portfolio managers do.
Can we say we use AI if a vendor’s product uses it? The SEC’s test, in Grewal’s words, is that representations about AI use must not be false or misleading. A truthful, specific description of what the vendor tool does and how the firm relies on it is a different statement from a claim that the firm’s own models drive its decisions. The reconciliation step in the table is where that distinction gets documented.
Will FINRA issue more specific guidance? FINRA has said it may issue further guidance on how particular rules apply to specific use cases. Until it does, the Notice and the general rules are the standard.
Should we expect state regulators to weigh in? FINRA itself noted that other federal and state laws, rules and regulations may apply to AI tools. That is a reason to involve counsel where a use case touches privacy or consumer-protection law.
Where Taft helps
Taft helps advisers and broker-dealers prepare for examinations by assembling the records an examiner is likely to request, including the AI tool inventory, pre-deployment evaluations, procedure updates and marketing reconciliations described in this guide. The work is delivered through our exam readiness product, and it is compliance support, not legal advice.
Questions
Did FINRA Regulatory Notice 24-09 create any requirements for AI?
No. The Notice states that it does not create legal or regulatory requirements or interpretations beyond those that already exist, and that FINRA's rules, which are intended to be technology neutral, continue to apply when firms use generative AI.
Do FINRA rules apply if the AI feature is built into a vendor product?
Yes. FINRA states that its rules apply whether a firm develops generative AI tools for proprietary use or uses the technology of a third party, including through embedded features in existing third-party products.
What is AI washing?
AI washing is the term the SEC used when it settled charges against Delphia and Global Predictions for making false and misleading statements about their use of AI. The firms paid $400,000 in total civil penalties.
What should a firm's procedures cover if it uses AI in supervision?
FINRA states that if a firm uses generative AI as part of its supervisory system, its policies and procedures should address technology governance, including model risk management, data privacy and integrity, and the reliability and accuracy of the model.
Sources
- Regulatory Notice 24-09 | FINRA.org, FINRA
- SEC Charges Two Investment Advisers with Making False and Misleading Statements About Their Use of Artificial Intelligence, U.S. Securities and Exchange Commission
Taft does not provide legal advice. Content is for informational purposes only and subject to regulatory guidance.