FINRA's Rule 2210 proposal would make AI supervision more risk-based, not less documented
FINRA's July 9 Regulatory Notice 26-14 requests comment on a proposed modernization of Rule 2210, not a current rule change. Comments close September 11. Today, an appropriately qualified principal generally must approve retail communications before use, subject to specified exceptions. The proposal would instead require written procedures, tailored to the member's business, size and structure, that determine which categories still require principal pre-use approval. The procedures would have to meet Rule 2210's unchanged content standards. If not every communication is approved before distribution, they should include training, documentation, surveillance and follow-up; firms would maintain evidence that the procedures were implemented. Risk factors include product complexity, preparer qualifications, recommendations or promotions, audience, distribution method and performance information. AI is in scope but not exempt. FINRA says members remain responsible for communications whether produced by a person or AI, and GenAI tools may participate in a supervisory system when vetted, tested and monitored. Higher-risk communications could receive more rigorous pre-use review while lower-risk communications follow a streamlined path. Current Rule 2210 remains in force while FINRA considers comments and any later rule filing.
Why it matters for advisers
For FINRA members and dual registrants, the operational question is not whether supervision disappears. It is how the firm classifies communication risk, documents the review path it selected and demonstrates that its procedures operated. A written policy describes the system; it does not show what happened on a particular communication. A run-level record can support that file, but it is only one component of the firm's governance, training, surveillance and escalation program. RIA-only firms are not governed by this FINRA proposal. For them, the notice is an industry signal rather than an applicable standard, and their federal or state adviser obligations remain separate.
Teranode read
RN 26-14 draws a boundary between enterprise tool governance and evidence created during an individual review. A firm must vet, test and monitor a GenAI tool at the program level; no single review record can establish those controls. At the run level, a record can show source metadata, findings, human dispositions, final decision, review vendors and whether the source vendor was excluded. Structural separation matters because a model or vendor evaluating its own output may reproduce the same blind spots or incentives, ours included. Cross-vendor review, however, is not third-party assurance, a compliance certification or a safe harbor. Each firm decides its procedures, which categories require principal pre-use approval, what it retains and when it escalates, with its own counsel and compliance professionals. Teranode's claim is narrower: a record can make review structure and human disposition inspectable while the firm remains responsible for supervision and the final determination.
