Logo
FrontierNews.ai

The Regulatory Gap That's Leaving Financial Firms Exposed to AI Risk

Financial regulators are applying decades-old rules to cutting-edge AI tools, and firms that haven't inventoried their AI use cases or documented their testing procedures are sitting ducks for enforcement action. The Financial Industry Regulatory Authority (FINRA) has made clear for two years running that it will not write new rules specifically for artificial intelligence. Instead, it is applying existing rules on supervision, communications, recordkeeping, and anti-money laundering to whatever AI tools firms deploy. That approach sounds straightforward in theory, but in practice it creates a compliance minefield.

Why Is FINRA Taking a "No New Rules" Approach?

FINRA's strategy reflects a pragmatic reality: artificial intelligence is evolving faster than regulators can write rules. Rather than wait for new regulations to catch up, the agency has decided to enforce existing rules more aggressively. The signal that this is no longer a back-burner issue has grown louder with each FINRA publication. Regulatory Notice 24-09 reminded members that generative AI (GenAI) implicates essentially the entire rulebook. The 2025 Annual Regulatory Oversight Report added detail on governance and testing expectations. The 2026 Report went further still, adding a standalone GenAI section and, for the first time, explicit guidance on autonomous AI agents: systems that can act on a user's behalf without a human approving each step.

For compliance and legal teams, the practical problem is less "is AI a risk" and more "where exactly does our existing program have gaps." Many firms have some AI-related language in their written supervisory procedures by now. Far fewer have an inventoried use case list, documented testing for hallucination and bias, supervisory sign-off mapped to specific rules, review procedures applied consistently to AI-drafted communications, vendor due diligence that actually asks how the vendor itself uses GenAI, and a recordkeeping process that captures AI prompts and outputs the same way it captures everything else.

What Specific AI Risks Are Regulators Most Concerned About?

FINRA's guidance reveals the agency's priorities. Hallucination, the phenomenon where AI systems generate confident but factually incorrect outputs, is a major concern, particularly where the tool touches regulatory analysis, customer communications, or product information. Bias arising from limited, outdated, or unrepresentative training data is another critical failure mode, especially in any tool influencing customer-facing outcomes. Autonomous AI agents present a new frontier: regulators now require guardrails limiting agent autonomy, such as approval gates before the agent executes a transaction, sends a communication, or modifies a record.

The regulatory framework also addresses the human element. FINRA requires human-in-the-loop review for any AI output that affects a customer, a regulatory filing, or a supervisory determination. Fully automated sign-off on these decisions is no longer acceptable. Additionally, firms must assign a registered principal with requisite knowledge to supervise each material AI use case, not a generic arrangement where IT owns it.

How to Build an AI Compliance Program That Passes Regulatory Scrutiny

  • Governance Framework: Maintain a written AI governance policy approved by senior management that defines what counts as "AI" for the firm's purposes and designates a qualified individual or committee responsible for reviewing and approving new AI use cases before deployment. Review and update this policy at least annually, or whenever a new high-risk use case or material model change is introduced.
  • Use Case Inventory and Risk Classification: Create a current, comprehensive inventory covering every AI tool in production, including embedded AI features inside third-party software the firm already uses. Classify each use case by risk tier, such as low-risk internal use versus high-risk customer-facing or surveillance-related applications, and apply review intensity proportionate to that risk.
  • Testing and Validation: Test each AI tool prior to deployment for accuracy, reliability, and consistency against known-correct answers relevant to its use case. Specifically test for hallucinations and bias, then re-test after any material model update. For AI-driven supervisory tools, conduct false-negative testing to confirm they are catching what a human reviewer would catch, not just delivering efficiency gains.
  • Supervision and Escalation: Document exactly how each AI use case fits into the supervisory system, including what it does, who supervises it, and how exceptions are escalated. Establish clear escalation procedures for when an AI tool's output is overridden, flagged as wrong, or fails, including who is notified and how the issue is remediated.
  • Recordkeeping and Vendor Diligence: Implement a recordkeeping process that captures AI prompts and outputs the same way it captures everything else. Conduct vendor due diligence that actually asks how the vendor itself uses GenAI, and require compliance and legal sign-off before procuring, building, or materially modifying any AI tool used in the business.

The stakes are high. Examiners are now asking firms to demonstrate that they have mapped AI tools onto existing rules, documented their testing procedures, and established clear lines of accountability. Firms that cannot produce this documentation face enforcement risk. The gap between what firms have done and what regulators now expect is widening, and the window to close it is narrowing.

Meanwhile, the broader cybersecurity landscape is shifting. The U.S. government is expanding its own capabilities to combat transnational cyber-enabled crime, including ransomware attacks, phishing campaigns, financial frauds, sextortion schemes, and impersonation scams often coordinated by sophisticated criminal organizations based outside the United States. In 2025, American consumers reported losing more than $20.8 billion to cyber-enabled crime. Seventy-three percent of U.S. adults have experienced some kind of online scam or attack, and 98 percent of Americans believe scams pose a threat to individuals in the U.S., with two-thirds saying it is a "major" threat.

For financial firms, the message is clear: regulators expect AI governance to be as rigorous as governance for any other material business risk. The absence of new rules does not mean the absence of new expectations. Firms that treat AI as a technology problem rather than a compliance problem are likely to find themselves on the wrong side of an examination.