FINRA’s Regulatory Notice 24-09 makes clear that broker-dealers must apply their existing rules when they start using generative-AI tools, and it spells out exactly what examiners will look for.
The notice does not create new regulations; it reminds firms that the same supervisory, communication, privacy, record-keeping and best-interest obligations that have governed traditional technology now extend to AI. Compliance officers must turn those duties into concrete processes that survive an on-site inspection.
Why the existing rulebook matters for AI
FINRA’s supervisory standards—Rule 3110 (general supervision) and Rule 3120 (supervision of associated persons)—require a system that monitors AI deployment. Firms need an inventory of every approved model, the purpose for each, and the people authorized to run them. Even if a client never sees an AI-generated output, using an unapproved tool counts as a supervision failure.
Rule 2210, which governs public communications, demands accuracy and fairness. Generative-AI can hallucinate facts or fabricate data. If a model produces a client summary with wrong numbers, the firm violates Rule 2210 the moment the material is distributed. The notice therefore obliges firms to review every AI-generated communication before it reaches a client.
Regulation S-P protects nonpublic personal information. Feeding client data into a third-party AI service risks inadvertent disclosure. Firms must keep information barriers intact and verify that the AI provider’s data-handling practices meet the regulation’s standards.
Rule 4511 requires record preservation. The notice treats AI output itself as a record and adds that firms should also retain the prompt that generated the response, the model version used, and the identity of the person who approved the content. Examiners will ask for those details to trace a statement’s origin.
Regulation BI (Best Interest) demands that any recommendation made on a client’s behalf be demonstrably in the client’s best interest. When an AI system contributes to a recommendation, the firm must explain the logic behind the suggestion. A black-box model cannot satisfy the “explainability” requirement and risks a BI violation.
Building a compliance framework
A practical compliance plan should address each rule area highlighted in the notice:
- Supervision – Draft a policy that lists approved AI tools, defines who may access them, and outlines monitoring procedures. Include periodic audits of usage logs.
- Accuracy – Add a mandatory human-review step for any AI-generated client communication. Use a checklist to verify factual correctness before release.
- Data privacy – Run a data-flow analysis to confirm that client information never leaves the firm’s secure environment without encryption and appropriate contractual safeguards.
- Recordkeeping – Configure the AI platform to automatically capture prompts, model identifiers, and approver signatures, then store those logs in the firm’s existing record-retention system.
- Best-interest compliance – Document the decision-support logic the AI provides for each recommendation, and retain a narrative that links the model’s output to the client’s investment objectives.
- Vendor management – Apply the same due-diligence checklist used for any third-party service provider: assess the vendor’s security controls, data-privacy policies, and dispute-resolution mechanisms. Remember, outsourcing does not shift responsibility away from the broker-dealer.
The notice also warns against “AI washing”—overstating a firm’s AI capabilities in marketing materials. Such embellishments fall squarely under Rule 2210’s prohibition on misleading communications.
Takeaway: FINRA’s notice does not rewrite the rulebook, but it forces broker-dealers to apply every existing obligation to the new world of generative AI. A disciplined inventory, rigorous human review, airtight data-privacy safeguards, and thorough record-keeping are the minimal controls needed to stay on the right side of the regulator.
