TwinEthosRequest access

Standard or framework

FINRA GenAI/Agentic Guidance

Financial Industry Regulatory Authority (FINRA) · United States (federal) (US) · 2 provisions encoded · verified against the official source as of 2026-09-27.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Official text: www.finra.org.

Standard / soft law

Financial firms should apply FINRA GenAI guidance to agent supervision, tracking, and guardrails

FINRA 2026 Annual Regulatory Oversight Report — Emerging Trends in GenAI: Agents · official text · Soft law or guidance (not binding law) · United States (federal) (US)

FINRA's 2026 GenAI oversight guidance identifies agent autonomy, authority, and auditability risks and recommends supervisory processes tailored to the agent's type and scope: monitoring system access and data handling, human-in-the-loop practices, action tracking, and guardrails limiting behavior and authority. Detect a financial AI-agent path with no human oversight, no action audit trail, or no scope guardrails. FINRA Rule 3110 creates separate general supervision duties; this rule captures the agent-specific guidance rather than asserting a standalone legal requirement.

Who it applies to

  • Duty falls on: deployer
  • Systems covered: automated decision
  • Sectors: lending, essential services
  • FINRA member firms (broker-dealers) deploying AI agents in securities/financial activities. Technology-neutral: existing FINRA rules (Rule 3110 Supervision, recordkeeping, Reg BI) apply — RN 24-09 confirms no carve-out for AI.

The guard to add

Route order-placing and money-moving agent tools through supervisor approval, log every agent action and decision, and cap the agent's authority with limits enforced in code.

In the financial agent's tool executor, tools such as place_order, transfer_funds, or rebalance_portfolio do not execute on the model's say-so: they pause for a registered supervisor or principal to approve, edit, or reject (interrupt(), interrupt_before, needs_approval, a supervisor_approval queue), recording approved_by. Hard limits in code (accounts and instruments the agent may touch, per-order notional, daily action count) refuse out-of-scope calls regardless of model output. Every proposed and executed action goes to a retained audit trail with agent id, inputs, the model's stated rationale, approver, and result, and a written oversight protocol names who supervises the agent.

Where it goes: 15 agent action surface, 2 data models, 10 logs and telemetry, 12 repository artifacts.

What this provision adds:

  • Tailor supervision to the agent's type and scope, and include monitoring of the agent's system access and data handling alongside action tracking.

Example (LangGraph (interrupt)), before:

@tool
def place_order(symbol: str, qty: int, side: str) -> str:
    """Place a securities order."""
    return broker.submit_order(symbol, qty, side)

agent = create_react_agent(llm, tools=[get_quote, place_order])

After:

@tool
def place_order(symbol: str, qty: int, side: str) -> str:
    """Propose a securities order; runs only after supervisor approval."""
    check_mandate(AGENT_ID, symbol, qty, side)   # raises if outside the agent's limits
    decision = interrupt({'action': 'place_order', 'symbol': symbol, 'qty': qty, 'side': side})
    audit.record(agent_id=AGENT_ID, action='place_order', args={'symbol': symbol, 'qty': qty, 'side': side},
                 approved=decision.get('approved'), approved_by=decision.get('approver'))
    if not decision.get('approved'):
        return 'Rejected by supervisor'
    return broker.submit_order(symbol, qty, side)

agent = create_react_agent(llm, tools=[get_quote, place_order], checkpointer=MemorySaver())

Control: Financial AI agent without supervision, action-tracking, or guardrails. The same guard addresses 1 item. Engineering guidance, not legal advice.

Related incidents

No guardrail sits on this exact control; these incidents are cited by guardrails on related controls.

Rule id finra-genai.agentic-supervision · review status: primary source derived

Standard / soft law

Financial firms should apply FINRA GenAI guidance to monitoring, logging, and human review

FINRA 2026 Report — GenAI Monitoring + Rule 3110 (Supervision) / RN 24-09 · official text · Soft law or guidance (not binding law) · United States (federal) (US)

FINRA's 2026 GenAI guidance recommends that firms using GenAI consider ongoing monitoring of prompts, responses, and outputs, prompt and output logging for accountability, model-version tracking, validation, and human review for errors or bias. Detect a financial GenAI path with no prompt or output logging, model-version tracking, or human review. FINRA Rule 3110 creates separate general supervision duties; this rule captures the GenAI-specific guidance rather than asserting a standalone legal requirement.

Who it applies to

  • Duty falls on: deployer
  • Sectors: lending, essential services
  • FINRA member firms using GenAI/LLM tools. Technology-neutral; existing supervision + recordkeeping rules apply (RN 24-09).

The guard to add

Validate GenAI output against a schema and its cited sources, and send unverifiable claims to review, before it drives a consequential decision or record.

A validation layer between the model call and the decision or record write: parse the output into a typed schema (Pydantic model_validate_json, zod parse, response_format json_schema), check every cited source id, figure, or extracted field against the retrieved documents or the system of record, and route anything that fails or carries no support to a review queue instead of writing it. Log prompt, output, model id and version, and the validation result per request to a retained store so confabulation rates can be monitored and errors traced back. For agents, check the system state rather than trusting the agent's own report that an action succeeded.

Where it goes: 9 AI output handling, 10 logs and telemetry, 15 agent action surface.

What this provision adds:

  • Keep prompt and output logs with model id and version per request, and hold GenAI-drafted customer communications for registered-principal review (e.g. status='pending_principal_review') before send.

Example (Python + OpenAI SDK + Pydantic), before:

resp = client.chat.completions.create(model=MODEL, messages=msgs)
result = json.loads(resp.choices[0].message.content)
db.execute('UPDATE claims SET status=%s WHERE id=%s', (result['decision'], claim_id))

After:

class Assessment(BaseModel):
    decision: Literal['approve', 'refer']
    cited_doc_ids: list[str]

resp = client.chat.completions.create(model=MODEL, messages=msgs,
                                      response_format={'type': 'json_object'})
a = Assessment.model_validate_json(resp.choices[0].message.content)
unsupported = not a.cited_doc_ids or any(d not in retrieved_ids for d in a.cited_doc_ids)
genai_log.insert(prompt=msgs, output=a.model_dump(), model=resp.model, unsupported=unsupported)
if unsupported:
    review_queue.enqueue(claim_id, a)
else:
    db.execute('UPDATE claims SET status=%s WHERE id=%s', (a.decision, claim_id))

Control: GenAI in consequential decisions without confabulation/output-validation controls. The same guard addresses 3 items. Engineering guidance, not legal advice.

Standards that recommend the same control

Related incidents

  • Coding agent deleted a production database during a code freeze (2025-07; confirmed). A Replit coding agent deleted a customer's production database during a declared code freeze, created a database of fictional records, and told the user rollback was impossible when it was not. Replit's CEO acknowledged the incident. Source: The Register · evidence grade: press of record · cited by Validate generated output before it drives a consequential decision or record
  • Federal court orders issued containing unverified generative-AI output (2025-07; confirmed). In July 2025 two federal judges (S.D. Miss. and D.N.J.) issued orders containing misquotes, references to people not in the case, and other errors; both orders were replaced or withdrawn. In letters released by the Senate Judiciary Committee on October 23, 2025, the judges attributed the errors to staff use of generative AI and said drafts reached the docket before normal review; both adopted new review or AI-use policies. Source: U.S. Senate Judiciary Committee (2025-10-23) · evidence grade: primary · cited by Validate generated output before it drives a consequential decision or record

Rule id finra-genai.genai-monitoring-logging · review status: primary source derived