FINRA Rule 3110 and AI Agents: A Supervision Guide

FINRA Rule 3110 and AI Agents: A Supervision Guide

Model risk guidance has stepped back from generative and agentic AI. FINRA has not. For a broker-dealer deploying AI agents in 2026, Rule 3110 is the more demanding obligation and the one that is actually enforceable — and unlike model risk guidance, FINRA has written directly about what agents do.

What Rule 3110 requires

FINRA Rule 3110 requires a member firm to establish and maintain a supervisory system reasonably designed to achieve compliance with the securities laws and FINRA rules. In practice that means written supervisory procedures, designated supervisors with defined responsibilities, review of correspondence and internal communications, and internal inspections.

It is the rule under which supervisory failures are most often charged, and the reason is structural: 3110 does not ask whether misconduct occurred. It asks whether the firm had a system that should have caught it. A firm can be charged under 3110 for a supervisory gap that nothing ever fell through.

"Reasonably designed" is assessed on what the firm can show. That single word does more work than any other in the rule, and it is why the supervisory record has to exist before anyone asks for it.

Why the rule reaches AI

FINRA answered this directly in Regulatory Notice 24-09, issued 27 June 2024, which reminds members of their obligations when using generative AI and large language models. Two points from it matter most.

The rules are technology-neutral by design. FINRA states it intends its rules and guidance "to be technologically neutral and to function dynamically with evolutions in technology." There is no AI exemption to find, and equally no new AI rule to wait for.

Output is the firm's output, whatever produced it. On communications, the notice is explicit: the content standards of Rule 2210 "apply whether member firms' communications are generated by a human or technology tool." A model that drafts client correspondence has not created a new category of communication. It has created more of the existing one.

Notice 24-09 also addresses the reflexive case, where GenAI is used inside the supervisory system itself — reviewing electronic correspondence, for instance. FINRA's position is that the firm's policies then have to address the governance of that tool as well.

What FINRA has said about agents specifically

This is the part most firms have not caught up with. In January 2026, Greg Ruppert, FINRA's Executive Vice President and Chief Regulatory Operations Officer, published observations on AI agents — describing them as systems that "can perform and complete tasks autonomously, without human intervention." The piece names six risk areas:

  • Agents acting autonomously without human validation and approval
  • Agents operating beyond their intended scope of authority
  • Traceability of multi-step reasoning, which complicates auditability
  • Unintended handling or disclosure of sensitive data
  • Insufficient domain knowledge for the task at hand
  • Misaligned reward functions

Read that list as a supervisory agenda rather than a think-piece. Each item is something an examiner can ask a firm to evidence, and four of the six are runtime properties — they are true or false at the moment the agent acts, not at the moment it was configured.

FINRA followed in March 2026 with material on prompt injection fundamentals, and its 2026 Annual Regulatory Oversight Report carries a generative AI section with a dedicated subsection on agents, including where to place human-in-the-loop oversight and how to monitor agent system access and data handling.

The supervisory record problem

A supervisory system built for people assumes a reviewable artefact. A message was sent. A document was produced. A trade was entered. Supervision attaches to the artefact, and the record of the artefact is the record of the conduct.

An agent breaks that assumption. Between two reviewable artefacts it may take twenty actions: retrieve a document, call a tool, query a system, decide not to escalate, revise its own plan. None of those is a communication. All of them are conduct.

If the intermediate steps are not recorded, the supervisory record has a hole in precisely the place an examiner will look — because that is where the decision was actually made. A firm that can produce the final email and nothing else has evidence of the output and none of the supervision.

What a supervisory system for agents has to contain

Working backwards from Rule 3110 and from Ruppert's six risks, the record needs to answer four questions for any action an agent took:

  • Who authorised this agent, and is that authorisation traceable to a named human principal?
  • What was it permitted to do, expressed as an explicit scope rather than inherited credentials?
  • What did it actually do, step by step, including the steps that produced no artefact?
  • What was it prevented from doing, and by which control?

The fourth question is the one firms most often cannot answer, and it is the one that distinguishes a supervisory system from a log. A log records what happened. A supervisory system records what was not allowed to happen, which is the evidence that the system was reasonably designed.

How this differs from model risk

It is worth being precise, because the two are routinely conflated in vendor material.

Model risk guidance asks whether a model is conceptually sound and whether its outputs track reality. SR 26-2, which superseded SR 11-7 in April 2026, sets out those expectations — and explicitly places generative and agentic AI outside its scope, while stating that a banking organization's own risk management should determine the controls for systems it does not cover.

Rule 3110 asks a different question: whether the firm supervised the conduct. A model can be well validated and still be used in a way nobody supervised. That second failure is the one that gets charged, and it is unaffected by anything model risk guidance does or does not cover.

Where to start

Three steps, in order. Inventory the agents, not just the models — which agents are running, with whose authority, against which systems. Establish what the supervisory record contains today and where it goes silent between artefacts. Then close the gap at runtime, because that is the only place where what an agent is permitted to do can still be decided.

APERION's Smartflow governs agent traffic at the runtime plane: identity bound to a human principal through AIDA, policy enforced per request, and a record of every call including the ones that were refused.

See how examination readiness works

Craig Alberino
Craig Alberino
Craig Alberino is the Founder and CEO of APERION, which builds the runtime governance layer for AI agents in regulated enterprises. Inline policy enforcement and identity-bound audit, deployable on premises.

Ready to govern your AI infrastructure?

See how Smartflow gives regulated industries complete AI sovereignty.

Request a Demo View Documentation