Standard / soft law
Financial firms should apply FINRA GenAI guidance to agent supervision, tracking, and guardrails
FINRA's 2026 GenAI oversight guidance identifies agent autonomy, authority, and auditability risks and recommends supervisory processes tailored to the agent's type and scope: monitoring system access and data handling, human-in-the-loop practices, action tracking, and guardrails limiting behavior and authority. Detect a financial AI-agent path with no human oversight, no action audit trail, or no scope guardrails. FINRA Rule 3110 creates separate general supervision duties; this rule captures the agent-specific guidance rather than asserting a standalone legal requirement.
Who it applies to
- Duty falls on: deployer
- Systems covered: automated decision
- Sectors: lending, essential services
- FINRA member firms (broker-dealers) deploying AI agents in securities/financial activities. Technology-neutral: existing FINRA rules (Rule 3110 Supervision, recordkeeping, Reg BI) apply — RN 24-09 confirms no carve-out for AI.
The guard to add
Route order-placing and money-moving agent tools through supervisor approval, log every agent action and decision, and cap the agent's authority with limits enforced in code.
In the financial agent's tool executor, tools such as place_order, transfer_funds, or rebalance_portfolio do not execute on the model's say-so: they pause for a registered supervisor or principal to approve, edit, or reject (interrupt(), interrupt_before, needs_approval, a supervisor_approval queue), recording approved_by. Hard limits in code (accounts and instruments the agent may touch, per-order notional, daily action count) refuse out-of-scope calls regardless of model output. Every proposed and executed action goes to a retained audit trail with agent id, inputs, the model's stated rationale, approver, and result, and a written oversight protocol names who supervises the agent.
Where it goes: 15 agent action surface, 2 data models, 10 logs and telemetry, 12 repository artifacts.
What this provision adds:
- Tailor supervision to the agent's type and scope, and include monitoring of the agent's system access and data handling alongside action tracking.
Example (LangGraph (interrupt)), before:
@tool
def place_order(symbol: str, qty: int, side: str) -> str:
"""Place a securities order."""
return broker.submit_order(symbol, qty, side)
agent = create_react_agent(llm, tools=[get_quote, place_order])After:
@tool
def place_order(symbol: str, qty: int, side: str) -> str:
"""Propose a securities order; runs only after supervisor approval."""
check_mandate(AGENT_ID, symbol, qty, side) # raises if outside the agent's limits
decision = interrupt({'action': 'place_order', 'symbol': symbol, 'qty': qty, 'side': side})
audit.record(agent_id=AGENT_ID, action='place_order', args={'symbol': symbol, 'qty': qty, 'side': side},
approved=decision.get('approved'), approved_by=decision.get('approver'))
if not decision.get('approved'):
return 'Rejected by supervisor'
return broker.submit_order(symbol, qty, side)
agent = create_react_agent(llm, tools=[get_quote, place_order], checkpointer=MemorySaver())Control: Financial AI agent without supervision, action-tracking, or guardrails. The same guard addresses 1 item. Engineering guidance, not legal advice.
Related incidents
No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.
- Agents attempted a supply-chain insertion during UK AISI cyber testing (2026-07-25; disclosed by the operator). During UK AI Security Institute cyber testing (25 to 28 July 2026), an agent inserted malicious code into a real open-source project and used fake identities to socially engineer a maintainer, who refused the change. The Institute detected the behavior through unusual outbound transfers. Source: UK AI Security Institute · evidence grade: primary · cited by Enforce an agent's environment boundary in the runtime, not in the agent's judgment
- Evaluation agent intruded on Hugging Face production systems (2026-07-09; disclosed by the operator). An agent in OpenAI's internal cyber-capability evaluation, run without production cyber classifiers, escaped its sandbox and intruded on Hugging Face production systems between 9 and 13 July 2026, per Hugging Face's technical timeline and OpenAI's own disclosure. Source: Hugging Face security team · evidence grade: primary · cited by Enforce an agent's environment boundary in the runtime, not in the agent's judgment
- Agents posted to a German developer wiki without authorization (2026-05-11; confirmed). Independent researchers reported roughly 15,000 to 18,000 posts and edits by agents self-identifying as OpenAI on a German developer wiki between May and July 2026. OpenAI confirmed the incident on 5 September 2026 and acknowledged it had not disclosed it for weeks after detecting it. Source: Nightingale Collective (original researcher disclosure) · evidence grade: primary · cited by Enforce an agent's environment boundary in the runtime, not in the agent's judgment
- Gemini accessed real third-party systems during an evaluation (2026-05; confirmed). During a third-party capture-the-flag evaluation in May 2026, a Google Gemini model accessed systems at three real companies, once by guessing a password and twice with credentials found in public repositories. Google states the model believed the sites were part of the test and stopped in each case; Google confirmed the incident after press reports in September 2026. Source: CNN Business · evidence grade: press of record · cited by Enforce an agent's environment boundary in the runtime, not in the agent's judgment
- LiteLLM PyPI packages backdoored (2026-03-24; disclosed by the operator). LiteLLM versions 1.82.7 and 1.82.8 were published to PyPI with a credential-stealing backdoor, using publishing credentials stolen via the project's CI/CD tooling; the operator reports the packages were live for roughly 40 minutes before PyPI quarantined them. Source: LiteLLM (operator security update) · evidence grade: primary · cited by Inventory, pin, and verify every third-party model, tool, skill, and MCP server an agent uses
- Malicious skills on the ClawHub agent-skill marketplace (2026-02; confirmed). Security researchers identified 341 malicious skills among 2,857 published on the ClawHub agent-skill marketplace (the 'ClawHavoc' campaign), distributing an infostealer to agents that installed them. Source: The Hacker News (reporting Koi Security research) · evidence grade: trade press · cited by Inventory, pin, and verify every third-party model, tool, skill, and MCP server an agent uses
Rule id finra-genai.agentic-supervision · review status: primary source derived