5 MCP servers live now What’s live ›
Real Biz Digital logo Real Biz Digital

United States

FINRA on AI agents: what the 2026 oversight report actually says

A US financial regulator has named agentic scope creep and the auditability of multi-step reasoning as supervisory risks, in an official 2026 report. FINRA's 2026 Annual Regulatory Oversight Report addresses AI agents directly, which makes it the strongest citation available for agent governance in US financial services. What it does not do is create a new rule. The obligations arrive through supervision, books and records, and market access controls already in force — and that changes what a firm has to build, and when.

How Barzel applies here Start free with BarzelVault

What does the report actually say about AI agents?

It names six supervisory risks specific to agents: autonomy without human validation; scope creep beyond intended authority; auditability of multi-step reasoning; sensitive-data disclosure; domain-knowledge gaps; and misaligned reward structures. Its recommendations are human-in-the-loop protocols, tracking mechanisms and behavioral guardrails. It states separately that supervisory systems relying on AI must evaluate the integrity, reliability and accuracy of the model.

Note the vocabulary: not model accuracy or hallucination, but an actor inside the firm — what it was permitted to do, what it did, whether anyone checked, and whether you can show all three afterwards. None of it is a rule; an oversight report states examination focus. The binding text is older. Regulatory Notice 24-09 (June 2024) confirmed that existing rules already apply to generative AI — Rule 3110 (supervision), Rule 2210 (communications with the public), Rule 4511 (books and records) and Reg BI.

Which existing rules already reach each named risk?

Risk or exposureRule in forceWhat it demands
Autonomy without human validation Rule 3110 (supervision) A reasonably designed supervisory system. An unreviewed agent action is still a firm action.
Auditability of multi-step reasoning Rule 4511 (books and records) Records preserved and retrievable. The basis for a decision is part of the record.
Agent-drafted client-facing output Rule 2210 (communications) Content and approval standards apply regardless of what drafted the material.
Agent-influenced retail recommendations Reg BI The obligation attaches to the firm, not the tool.
Market-facing automation Rule 15c3-5, Reg SCI Market access controls and systems integrity duties predate AI and already govern automated order flow.
Supervisory systems that use AI Rule 3110, with the report Evaluate the model's integrity, reliability and accuracy. A supervisory tool is not exempt from supervision.

The remaining three — sensitive-data disclosure, domain-knowledge gaps, misaligned reward structures — are design and testing problems before they are filing problems. Treat them as risk-assessment inputs.

Why is auditability of multi-step reasoning the hard one?

Because the method that works for deterministic systems does not work here, for mechanical rather than philosophical reasons. A deterministic process is audited by re-running it: same inputs, same code, same output — and that reproduction is the evidence. An agent cannot be. The same prompt on the same model may take a different path, and by the time anyone asks, the model may have been retired, upgraded, or swapped for a cheaper one in a cost review nobody logged as a control change. Re-running produces a new decision, not an explanation of the old one.

The consequence for Rule 4511 is specific: preserving the outcome is not preserving the record. Reconstruction requires that you captured, at the time, the inputs, the tools and data reached for, the intermediate steps, and the model and configuration version then in force. That is the part firms skip, and precisely the part that cannot be recovered later — the design problem behind an agent audit trail.

Is scope creep really the agent misbehaving?

Usually not, and the framing decides where the control belongs. An agent given a goal takes instrumental steps toward it. Told to resolve outstanding items on an account, closing it or issuing a credit may be a reasonable step — coherent, goal-directed, defensible on a plain reading. The agent is not exceeding its instructions. It is exceeding the authority somebody assumed those instructions carried.

That gap does not close with better prompting. A prompt is a request the model can reason its way around, and the more capable the model, the better it reasons. The boundary must be something the agent cannot argue with: a permission check, approval threshold or value limit enforced outside the model, in a layer every action passes through before execution. The agent should never decide whether it needs supervision — the practical content of agent permissioning.

Human-in-the-loop protocols meet the same test: a human in the loop is a control only where review is substantive and evidenced. A queue cleared at several hundred items an hour produces log entries, not supervision.

What is dead, absent or misattributed?

Is the SEC's predictive data analytics proposal still pending?

No. Proposed July 2023, formally withdrawn in June 2025 (Release 33-11377), one of fourteen rescinded proposals. The SEC stated it does not intend to issue final rules; any future action needs a new proposal. It is not pending.

Is there a SOC 2 for AI?

No. There is no AICPA attestation standard or criteria set specific to AI. The Trust Services Criteria have not been amended, and NIST AI RMF, ISO 42001 and the EU AI Act have not been incorporated into SOC 2. AI controls are mapped into the existing criteria. ISO/IEC 42001 is the only certifiable AI management system standard.

Is there a NIST AI RMF agentic profile?

Not from NIST. NIST AI RMF 1.0 (January 2023) is current — there is no 2.0 — and it is voluntary; the Generative AI Profile (NIST AI 600-1, July 2024) is final. The "NIST AI RMF Agentic Profile" circulating online is a Cloud Security Alliance work product. Citing it as NIST is an avoidable credibility cost.

Where does the SEC actually stand?

No AI rule exists and none is being written. The Chairman set a principles-based, technology-neutral posture in March 2026, anchored in materiality. AI remains an examination priority, and "AI-washing" is pursued under existing antifraud provisions — the exposure sits in what a firm claims about its AI, not in the AI.

Behind that, no federal AI statute binds private companies. EO 14179 (January 2025) and EO 14365 (December 2025) direct federal agencies: a DOJ AI Litigation Task Force to challenge state AI laws, Commerce to identify "onerous" ones, an FTC policy statement on preemption, an FCC rulemaking on a federal AI reporting standard, and legislative recommendations toward a preemptive federal standard. No preemption statute has been enacted.

So the real exposure is sector regulator plus state law — for financial and lending decisions, California's CPPA ADMT regulations: framework effective 1 January 2026, ADMT duties from 1 January 2027, biting where technology "replaces or substantially replaces human decision-making" in a significant decision, with a right of access to the logic and five-year risk-assessment retention. Mapped in our guide to US automated decision-making compliance.

What should a firm actually build?

Since the obligations arrive through supervision and record-keeping rather than AI law, the build list is unglamorous and largely infrastructural.

  1. An inventory of agent-taken actions — not of models or vendors, but of actions agents can take that a person would otherwise have taken. Workflows nobody classified as decision-making are what an examiner finds first.
  2. A defensible human-review boundary, with evidence that review was substantive rather than a queue confirmation.
  3. Version capture alongside the decision — inputs, intermediate steps, model and configuration version.
  4. Thresholds enforced outside the model, so authority is a property of the system rather than a request in a prompt.
  5. Retention on the compliance clock, not the log-rotation clock. Rule 4511 periods and the CPPA's five-year retention both outlast default application logging.

None of it requires a view on where AI regulation is heading, which is the point: each item is defensible under rules already in force.

Frequently asked questions

What does the 2026 report say about AI agents?

It names autonomy without human validation, scope creep, auditability of multi-step reasoning, sensitive-data disclosure, domain-knowledge gaps and misaligned reward structures, and recommends human-in-the-loop protocols, tracking mechanisms and behavioral guardrails.

Did FINRA create a new AI rule?

No. Notice 24-09 confirmed Rules 3110, 2210, 4511 and Reg BI already apply; Reg SCI and Rule 15c3-5 already reach automated decisioning.

Why can't an agent's decision be audited by re-running it?

The path may differ and the model may since have been replaced. Re-running produces a new decision, not an explanation of the old one.

Is the SEC's predictive data analytics proposal still live?

No. Withdrawn June 2025 under Release 33-11377; any future action needs a new proposal.

Is the NIST agentic profile a NIST document?

No. It is a Cloud Security Alliance work product. NIST AI RMF 1.0 remains current and there is no 2.0.

Related

BarzelVault enforces policy and approval thresholds in a layer the agent passes through, recording each action with its inputs, policy version and approver before execution — the shape of record Rule 4511 needs and re-running cannot produce. FinOps Atlas measures what those workflows cost, including the model swaps that quietly change the control surface.

In practice

Permission before the action. Evidence after it.

The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.

FINRA 2026 Annual Regulatory Oversight Report names agentic-AI risks

BarzelVault

The AI action firewall: decide what an agent may do before it does it.

  • Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
  • Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
  • Credential isolation, spend and action limits, and an emergency kill switch.

Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Barzel FinOps Atlas

Intelligent financial operations for AI agents and automation.

  • Cost per action, workflow and business outcome, allocated as it happens.
  • Spend limits and anomaly detection before the bill, not after.
  • Financial evidence tracing and close-readiness for SOX, SOC 2 and external audit.

Free tier: 500 calls a monthPaid plans from $29 a monthLive on MCPize

Start free Ask by emailProduct pageDocumentation

Enterprise: written quote by email within two business days. No sales call.


Sources

  1. FINRA, 2026 Annual Regulatory Oversight Report; Regulatory Notice 24-09 (June 2024).
  2. FINRA Rules 3110, 2210, 4511; Reg BI; Regulation SCI; Exchange Act Rule 15c3-5.
  3. SEC, Notice of Withdrawal, Release 33-11377 (June 2025); Chairman's remarks, March 2026.
  4. Executive Orders 14179 (January 2025) and 14365 (December 2025).
  5. CPPA regulations on automated decision-making technology and risk assessments.
  6. NIST AI RMF 1.0 (January 2023); NIST AI 600-1, Generative AI Profile (July 2024).
  7. AICPA Trust Services Criteria; ISO/IEC 42001.

This article is for information and does not constitute legal advice. Position as at 2 September 2026.