Financial Firms Face Regulatory Gap as AI Deployment Outpaces Recordkeeping Rules
Regulators are applying existing fiduciary and supervision obligations to AI-driven outcomes despite a lack of AI-specific mandates.
Financial services firms are rapidly integrating artificial intelligence into compliance and communications, but the speed of adoption has created a dangerous regulatory gap. While specific AI recordkeeping guidelines remain absent, regulators are already enforcing existing rules against AI-driven failures.
The Securities and Exchange Commission (SEC) and FINRA have not yet established dedicated AI record-retention requirements. However, both agencies maintain that existing frameworks—including Regulation Best Interest (Reg BI) and general fiduciary obligations—apply regardless of whether a human or an algorithm performs the work. This technology-neutral approach means firms are held accountable for AI outcomes under the same standards as traditional processes.
The Enforcement Landscape
Regulators are not waiting for new legislation to take action. The SEC has already initiated enforcement proceedings against firms for "AI washing," a practice where companies misrepresent or exaggerate their AI capabilities to investors. These actions, which gained momentum around March 2024, signal a low tolerance for deceptive claims regarding automated technology.
Furthermore, FINRA has issued explicit guidance via Regulatory Notice 24-09. The notice reminds firms that their existing obligations regarding supervision, communications, and recordkeeping extend to the use of Generative AI. Specifically, firms utilizing Gen AI in supervisory systems must address technology governance, model-risk management, data privacy, and overall model reliability.
A Pattern of Technology Shifts
This current friction mirrors previous industry transitions from paper records to email, and later to encrypted messaging apps like WhatsApp. In those instances, regulators did not rewrite the underlying framework but instead applied existing "books-and-records" rules to the new medium.
This precedent suggests a high risk for firms using unapproved AI platforms for client work. Such usage can create records that exist outside a firm's ability to capture or supervise, echoing the failures seen in off-channel communications. Since 2021, the SEC has imposed more than $2 billion in fines against financial firms for failing to preserve off-channel communications, providing a stark warning of the costs associated with evidentiary gaps.
The Path to Compliance
Industry experts warn that firms cannot rely on the absence of a specific "AI rulebook" to avoid liability. Because accountability rests with the regulated firm rather than the software vendor, the burden of proof remains internal. Brian Rubin, a partner at Eversheds Sutherland, notes that while there are no existing AI rules, regulators are not waiting for new laws before bringing enforcement actions.
To mitigate risk, firms must implement explainable AI workflows and rigorous versioning to reconstruct decisions after a model is updated. Jamie Hoyle, VP of Product at MirrorWeb, cautions firms against vendor claims of putting compliance "on autopilot," suggesting such promises are a red flag.
What to Watch
Moving forward, the industry should expect increased scrutiny of how AI approvals and data access are documented. The primary challenge remains the ability to "show the work" behind an AI-generated output. Until formal AI-specific mandates are issued, the safest harbor for firms is the strict application of existing supervisory and fiduciary standards to every automated interaction.