Financial Firms Confront AI Recordkeeping Compliance Questions

On August 12, 2026, PYMNTS reported that financial services firms are deploying AI in compliance, communications and other functions while facing unresolved questions about records needed to demonstrate compliance. The report said existing SEC and FINRA obligations can apply even without AI-specific retention rules, while FINRA guidance identifies technology governance, model risk, privacy, data integrity, reliability and accuracy as supervisory concerns.
Financial services firms are adopting AI for compliance, communications and other business functions while regulators have not yet issued AI-specific record-retention requirements, according to PYMNTS. Existing obligations governing supervision, communications, recordkeeping, conflicts of interest, Regulation Best Interest and fiduciary duties can still apply when an AI system performs work previously handled by people.
The issue was discussed during a July panel involving securities lawyers, compliance executives and technology providers, PYMNTS reported. Fintech Global, citing a July 16 webinar, reported that Brian Rubin, partner and co-head of the Securities Enforcement Group at Eversheds Sutherland, characterized the environment as one in which firms need to be able to "show your work" to regulators.
Existing rules, AI-enabled workflows
FINRA Regulatory Notice 24-09 states that firms using generative AI in supervisory systems, including for electronic-correspondence review, should address technology governance, model-risk management, data privacy and integrity, and model reliability and accuracy. PYMNTS reported that FINRA's 2026 Regulatory Oversight Report made generative AI a standalone area of focus.
Fintech Global reported that the SEC has brought cases concerning alleged "AI washing," or overstated claims about AI capabilities. It also reported that FINRA has pursued an anti-money-laundering matter involving an automated identity-verification process. According to the report, neither example depended on a new AI-specific regulation.
Evidence trails become operational controls
The reported questions concern more than written policies. Fintech Global described the webinar discussion as focusing on evidence of who approved a system, what data it used, how outputs were validated, and where human accountability remained.
For ML and compliance teams, that framing connects recordkeeping with evidence of system approvals, data use, output validation and human accountability.
The available reporting does not identify a uniform AI-specific retention standard. It instead indicates that firms may need to demonstrate that existing supervisory and recordkeeping controls continue to function when AI is introduced into regulated workflows. The practical compliance question is therefore not only whether an AI tool is accurate, but whether a firm can reconstruct and substantiate how the tool was governed in a particular use case.
Key Points
- 1Existing securities compliance duties can apply to AI-assisted workflows, making governance artifacts and validation evidence central to regulatory examinations.
- 2FINRA guidance identifies model risk, privacy, data integrity, reliability and accuracy as supervisory control areas for generative AI.
- 3The reported oversight questions concern records linking inputs, approvals, outputs and accountable humans.
Scoring Rationale
The reporting highlights how existing securities supervision and recordkeeping duties can govern AI deployments before dedicated AI rules arrive. It is relevant to ML governance, model-risk and compliance teams, although it does not announce a new regulation or enforcement action.
Sources
Primary source and supporting public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems


