FINRA Rule 2210 Update Brings AI Supervision Into Focus
FINRA's proposed changes to Rule 2210 are the most specific FINRA has been about how AI tools fit into a reasonably designed supervisory system. The proposal, Regulatory Notice 26-14, was released in July and takes a more risk-based approach to supervising retail communications. For compliance teams, the point is simple: whether a communication is created by a person or an AI tool, the firm stays responsible.
Key takeaways
- FINRA's Regulatory Notice 26-14 proposes treating AI-generated and AI-reviewed communications the same as any other communication: the firm remains accountable.
- Gen AI tools can be part of a reasonably designed supervisory system, but only when they're vetted, tested, and monitored on an ongoing basis.
- Firms don't need to wait for a final rule, since existing guidance under Regulatory Notice 24-09 already expects supervision of Gen AI tools today.
- A documented testing baseline, run against communications that compliance has already reviewed, helps demonstrate a control is reasonably designed.
- Oversight should scale with risk, so a tool drafting generic content needs less scrutiny than one generating performance claims or personalized recommendations.
What FINRA is proposing
The core idea of the proposal is that AI tools used to generate, review, or flag communications should fit within a firm's broader supervisory framework. FINRA states that generative AI communication tools may be part of a reasonably designed supervisory system if they're reviewed, tested, and monitored. Firms may also consider broader governance and risk management practices to address issues like accuracy and hallucinations.
This passage from the proposal speaks directly to that point:
Gen AI communication tools can be part of a reasonably designed supervisory system, provided they are vetted, tested, and monitored. At the enterprise level, firms may consider establishing processes and governance frameworks to guide development and deployment of Gen AI communication tools, including risk management practices to address accuracy concerns like hallucinations.
If adopted, the proposal would make something increasingly important much more explicit: AI may be a useful part of the communications workflow, but it still needs supervision.
AI can sit on either side of the compliance equation. It can create the communication, or it can help review and supervise it. Either way, the firm remains responsible.
The underlying Rule 2210 standards don't change. Communications still need to be fair and balanced, not misleading, and otherwise compliant. The technology may change the process, but it doesn't change the standard.
What compliance teams should think about now
These five areas give compliance teams a practical starting point for putting the proposal into practice.
1. Build an inventory of where AI touches communications
Start with visibility. That could include marketing teams drafting fund descriptions with ChatGPT, a social platform generating posts, a communications platform using AI to screen or flag content, or a third-party vendor that has quietly added AI features.
For some firms, establishing a reliable inventory may be the first challenge.
2. Test each tool against a documented baseline
Testing should be documented. For an AI tool used in supervision, run it against a representative sample of communications your team has already reviewed (for example, 50 previously approved items) and compare results: which issues the tool catches, which it misses, and how often it creates unnecessary alerts.
That baseline can become an important part of demonstrating why the control is reasonably designed. Testing should also cover:
- False negatives the tool missed
- False positives it flagged unnecessarily
- Higher-risk content such as performance claims, recommendations, or complex products
- Performance shifts after a model or vendor update
3. Match testing to the risks that matter most
AI hallucinates and misses context, which is a major risk for financial communications. If you're using AI to review, screen, or flag communications, test the risks that matter most, including:
- Misleading language
- Missing risk disclosures
- Complex products
- Performance claims
- Recommendations
Not every AI use case needs the same level of controls. An AI tool drafting generic educational content carries a different risk profile than one generating product-specific communications, performance claims, or individualized content. That risk-based distinction matters.
4. Plan for ongoing monitoring, not a one-time check
If the proposal is adopted, firms would need to think about ongoing monitoring based on the risk of the use case. A lower-risk tool may not need the same level of oversight as one supporting high-volume or higher-risk communications.
Models can change, vendors will update their products, and performance can shift. Firms should be able to show what they monitored, what they found, and what they did about it.
5. Document where governance and accountability live
Governance and accountability for AI tools need a clear home, whether that's a firm's written supervisory procedures, an AI governance policy, or a broader technology governance framework. Somewhere, the firm should be able to show who approved the use of the tool, how it's supervised, and who's accountable for it.
The proposal also puts an important emphasis on evidence. Firms would need to maintain evidence that their supervisory procedures were implemented and carried out. The AI control working isn't enough on its own — the supervisory process around it has to hold up too.
Why compliance teams should pay attention now
The comment period for Regulatory Notice 26-14 closed September 11. FINRA will review industry feedback and determine next steps, but the notice doesn't specify a timeline for final action.
Firms don't need to wait for a final Rule 2210 amendment to start asking these questions. FINRA has already made clear through Regulatory Notice 24-09 and its Oversight Reports that existing FINRA rules apply when firms use Gen AI. RN 26-14 gives firms a clearer view of what that supervision may look like as AI becomes more embedded in communications workflows.
For compliance teams, the opportunity now is practical: understand where AI is being used, test whether the controls work, and make sure they can demonstrate how those controls are supervised.
Frequently asked questions
No. The underlying standard (fair, balanced, and not misleading) stays the same. RN 26-14 addresses how AI tools fit into supervising that standard, not the standard itself.
No. FINRA has already stated through Regulatory Notice 24-09 that existing rules apply to Gen AI use, so firms can start building an inventory and testing and monitoring processes now.
Documented testing against a representative sample of already-reviewed communications, tracking false positives, false negatives, and performance on higher-risk content such as performance claims or recommendations.
No. FINRA's risk-based approach suggests lower-risk uses, like generic educational content, may need lighter oversight than higher-risk uses, like personalized or product-specific communications.
The comment period closed September 11. FINRA has not specified a timeline for final action.
Share this post!
Smarsh Blog
Our internal subject matter experts and our network of external industry experts are featured with insights into the technology and industry trends that affect your electronic communications compliance initiatives. Sign up to benefit from their deep understanding, tips and best practices regarding how your company can manage compliance risk while unlocking the business value of your communications data.
Ready to enable compliant productivity?
Join the 6,500+ customers using Smarsh to drive their business forward.



Subscribe to the Smarsh Blog Digest
Subscribe to receive a monthly digest of articles exploring regulatory updates, news, trends and best practices in electronic communications capture and archiving.
Smarsh handles information you submit to Smarsh in accordance with its Privacy Policy. By clicking "submit", you consent to Smarsh processing your information and storing it in accordance with the Privacy Policy and agree to receive communications from Smarsh and its third-party partners regarding products and services that may be of interest to you. You may withdraw your consent at any time by emailing [email protected].
FOLLOW US