Est.

Sector-Specific AI Guidance From Financial Regulators

Regulators are examining firms on AI rules that don't yet exist.

Staff Writer · · 9 min read
Cover illustration for “Sector-Specific AI Guidance From Financial Regulators”
AI Risk Frameworks · October 9, 2026 · 9 min read · 2,107 words

Financial firms are running AI models in live production workflows, and the laws meant to govern them are nowhere close to finished. So regulators in the US, UK, and EU have moved ahead of their own legislatures, using examination priorities, supervisory frameworks, and in one case a binding statute to fill the gap. No one has passed an AI law for finance, yet firms are being examined as though one already exists, a strange but workable consensus. Understanding how that consensus formed, and what it actually demands sector by sector, matters more right now than waiting for lawmakers to catch up.

Why financial regulators are issuing AI guidance without waiting for AI-specific laws

No dedicated AI statute governs broker-dealers, investment advisers, or banks in the US or the UK, but firms that use AI face active examination scrutiny today. Regulators on both sides of the Atlantic have landed on the same working theory: the rules already on the books are the AI rules. The SEC, the CFTC, and FINRA have not issued a single new regulation written specifically for AI, and the SEC went further by formally withdrawing a proposed rule that would have created AI-specific obligations for advisers and broker-dealers. The FCA has confirmed the same posture for the UK, with CEO Nikhil Rathi pointing to the pace at which the technology changes as the reason not to legislate around a moving target. Instead, the FCA leans on tools it already has: a duty-of-care standard for firms, a regime holding senior managers individually accountable, and operational resilience rules, applied in a technology-neutral, principles-based, outcomes-focused way.

That leaves firms doing the interpretive work regulators have declined to do for them. Supervision obligations, recordkeeping rules, data privacy law, and marketing standards were all written before large language models existed in anything like their current form, and firms now have to map each of those obligations onto AI tools without a rulebook that mentions AI by name. The EU took a different route, passing a dedicated statute rather than relying on old law stretched to fit new technology, and that split is the organizing fact behind everything that follows.

The Three Mechanisms in Practice: Examination Priorities, Supervisory Frameworks, and Binding Statute

Diagram: Three Regulatory Mechanisms, Three Compliance Weights. Visualizes: Visualize a ranked or stepped hierarchy of the three mechanisms regulators use to govern AI in finance, ordered by binding force: (1) Examination Priorities — FINRA 2026…

Regulators aren't speaking through one channel, and firms need to tell the three mechanisms apart because each one carries a different weight and a different compliance response.

The first is examination priorities: statements from regulators about what their examiners will actually look for, without any accompanying rule change. FINRA's 2026 Annual Regulatory Oversight Report gives generative AI its own dedicated section, treating it as a supervised technology that demands the same rigor as any other critical system. The SEC's Division of Examinations took a similar tack: its fiscal year 2026 priorities list whether registrants accurately describe their AI capabilities and whether they have policies in place to supervise AI use. Neither of these documents is a rule. Both function as one, because firms that get examined are judged against what these documents describe.

The second mechanism is the supervisory framework, a step more structured than an exam priority list but still short of binding law. The Conference of State Bank Supervisors released its Artificial Intelligence Supervisory Framework on September 16, 2026, and it's described as the most comprehensive regulatory guidance on AI issued to date, the first examination-focused AI guidance built specifically for state-supervised financial institutions. It applies to state-chartered banks and state-licensed nonbank financial institutions, and it does not reach nationally chartered banks or federal savings associations, which stay under the OCC's authority. Internationally, IOSCO published a Supervisory Toolkit for AI Use in Capital Markets on May 25, 2026, giving regulators practical tools for overseeing AI systems across their full lifecycle, from traditional machine learning through generative AI to emerging agentic AI. IOSCO advises regulators across the world's major capital markets, and its language has a track record of showing up in national rulebooks and supervisory questions within a year or two of publication.

The third mechanism is binding statute, and so far it exists in only one place: the EU. A banking regulator ran a mapping exercise comparing the AI Act against existing banking and payment law and found no significant contradictions, concluding the Act complements what was already there. No immediate changes to EBA guidelines are planned, though some integration work remains. That finding sets up the jurisdiction-by-jurisdiction detail that follows: examination priorities and supervisory frameworks shape US practice, while a statute with a hard compliance deadline shapes EU practice.

What US regulators expect from broker-dealers, investment advisers, and banks right now

No single AI rule exists in the US, yet the expectations coming out of FINRA, the SEC, federal banking agencies, and the CSBS now line up closely enough that firms can treat them as one convergent standard covering governance, supervision, documentation, and vendor management.

FINRA's 2026 report expects firms to run formal AI governance programs, and it wants clear ownership split across business, compliance, technology, and risk functions. Pre-approval is expected for each use case, with a written purpose, named data sources, documented model and provider selection, and specific controls built in before deployment, not after. Anything customer-facing or anything that influences a decision needs a human in the loop, with documented sign-off and a named supervisory owner attached to it.

Supervisory procedures are expected to track the AI lifecycle from end to end: who gets to use a given tool, what data it can ingest, how its outputs get reviewed, and when a result gets escalated for further review. FINRA calls out prompt and output logging, version tracking, and access controls for both human users and non-human service accounts by name. AI-generated content counts as a firm communication, which pulls it into the same content standards, supervisory review, pre-use approval, and archiving rules that govern anything else a registered representative puts in front of a client. Under Reg BI and fiduciary duty, AI is allowed to inform a recommendation but not replace the adviser's judgment behind it, and a human still has to sign off on anything AI generates or summarizes before it reaches a client.

Agentic AI gets treated as its own risk category for the first time in the 2026 report. FINRA defines an AI agent as "systems or programs that are capable of autonomously performing and completing tasks on behalf of a user," and flags the risk of an agent acting without human validation or taking action beyond what the user actually intended or authorized. For agents that can act or transact on their own, FINRA recommends narrow scope, restricted permissions, a full audit trail of every action taken, and an explicit human checkpoint before execution. This is a new addition to the supervisory landscape: FINRA's January 2025 report did not treat agentic AI as a distinct category at all, and that changed only with the December 2025 report.

Retail communications are also in the middle of a procedural shift. FINRA's Regulatory Notice 26-14, published July 9, 2026, proposes replacing mandatory principal pre-use approval of retail communications with a risk-based standard instead. AI is named directly as a driver of that change: the notice states that applying blanket pre-approval to AI-generated retail communications is difficult in practice, and it expects firms to vet, test, and monitor any generative AI tool before it touches client-facing material.

Banks face a parallel but separate track. In April 2026, the FDIC, the Federal Reserve, and the OCC issued revised Model Risk Management guidance, SR 26-2, aimed most directly at banking organizations with more than $30 billion in assets. The guidance explicitly carves out generative and agentic AI from its scope, on the grounds that both are still novel and changing too fast to pin down in a fixed framework. That carve-out doesn't excuse banks from oversight. Institutions are still expected to apply sound governance and risk management to any AI system they run, carve-out or not. Credit unions sit in a gap of their own: the NCUA has issued no formal AI supervisory guidance and instead points institutions back to existing regulations and resources.

State-chartered institutions face the most detailed instructions of any US sub-sector, by way of the CSBS Framework. It breaks down into five parts: a Core Examiner Guide, an Examiner Work Program, Nonbank AI Supplements, an AI Use Case Risk Tiering Worksheet, and a Source Support Document. The Core Examiner Guide centers on governance and oversight, AI inventories and use cases, and generative AI alongside other emerging applications. Institutions have to build a full AI inventory, including AI capability embedded inside third-party products and vendor platforms; they must assign a risk tier to every use case and keep written documentation justifying each classification. The Framework reaches state-chartered banks and credit unions, along with state-licensed mortgage lenders, mortgage servicers, consumer lenders, money transmitters, debt collectors, and similar license holders.

Enforcement has already caught up with disclosure. In March 2024, the SEC brought simultaneous actions against Delphia (USA) Inc. and Global Predictions Inc. because they made false and misleading claims about their use of AI in investment decisions, and both firms settled and paid civil penalties. In January 2025, the SEC charged Presto Automation Inc. in the first AI-washing case against a public company, alleging it overstated what its Presto Voice AI product could actually do and failed to disclose that the underlying technology was owned and operated by a third party and relied on significant human intervention behind the scenes. These cases don't float out there as cautionary tales. They establish that accurate disclosure of AI capability is an enforceable obligation under securities law already on the books, not a best practice firms can take or leave.

Vendor management closes the loop across every US sub-sector. Contracts covering AI tools are expected to address training data rights, security controls, sub-processors, logging access, model change notifications, and incident reporting. FINRA, the SEC, and the CSBS all expect ongoing due diligence and control testing of AI vendors, not a one-time review signed off at onboarding and forgotten.

What the EU AI Act and EBA guidance require from financial institutions operating in Europe

The EU stands alone as the one jurisdiction where AI-specific legal obligations are already in force for financial institutions. Even so, the actual compliance lift tracks closer to existing sectoral rules than the Act's novelty might suggest.

Under Annex III of the EU AI Act, credit scoring, fraud detection, and underwriting AI all count as high-risk systems. The compliance deadline for high-risk systems landed on August 2, 2026, 24 months after the Act entered into force on August 1, 2024. High-risk classification carries a specific set of obligations: a risk management system, data governance requirements, technical documentation, logging of system operations, transparency toward users, human oversight measures, and accuracy and robustness standards that have to be demonstrated, not just claimed.

The EBA's mapping exercise compared the Act against existing EU banking and payment legislation and found no significant contradictions between them, concluding the Act complements a legal framework that was already comprehensive. No immediate changes to EBA guidelines are planned, though the EBA acknowledges some integration work is still needed. For firms, that finding carries a direct practical meaning: compliance with the AI Act's high-risk obligations is largely achievable inside the risk management, model validation, and operational resilience frameworks banks already run, as long as those frameworks get demonstrably extended to cover AI systems specifically.

Regulators are also watching a risk category that sits above any individual firm's compliance program. On July 31, 2026, the EBA, EIOPA, and ESMA jointly published statement JC 2026 25 on ICT risks tied to frontier AI models, warning that highly capable AI models significantly speed up cyber risk, since AI-enabled tools can discover and exploit vulnerabilities fast enough to create systemic cyber risk across the financial system. That statement moves AI risk out of individual firm governance and into financial stability territory, where regulators are watching for correlated model behavior across institutions that could amplify a market shock across the financial system.

For firms operating in the EU today, three steps follow directly from this. You have to check every AI use case against the high-risk categories in Annex III, so you can tell which obligations actually apply. Logging of AI system operations has to meet the Act's traceability requirements, which line up closely with the audit trail expectations already showing up in FINRA and CSBS guidance on the US side. And human oversight for high-risk AI systems is a mandatory requirement under the Act, not a discretionary safeguard, mirroring the human-in-the-loop standard that regulators elsewhere have been building into their own guidance throughout 2026.

Sources

  1. CSBS releases Artificial Intelligence Supervisory Framework
  2. FINRA’s 2026 Regulatory Priorities: What They Mean — and How CCOs Can Prepare
  3. SEC and FINRA 2026 Exam Priorities for AI
  4. AI Governance Is Becoming a Global Examination Priority - ACA Group
  5. New priorities for 2026 — What investment advisers and broker-dealers can expect
  6. FINRA AI Report: Governance Guidance for RIAs and Brokers
  7. AI Compliance for Firms and RIAs in 2026

More in AI Risk Frameworks