AI Recordkeeping Raises Compliance Questions for Financial Services Firms
Financial services firms are moving rapidly to deploy artificial intelligence (AI) in compliance, communications and other business functions, but their use of the technology is raising a deceptively familiar regulatory problem: What records must they keep to prove they complied with rules written before AI existed?
That question is becoming more pressing even though the Securities and Exchange Commission (SEC) and Financial Industry Regulatory Authority (FINRA) have yet to establish AI-specific record-retention requirements, according to a panel of securities lawyers, compliance executives and technology providers assembled in July by technology firm Red Oak. But the absence of an AI rulebook does not mean firms can wait for regulators to provide one
Existing requirements covering supervision, communications, recordkeeping, conflicts of interest, Regulation Best Interest and fiduciary obligations generally apply regardless of whether a human or an AI system performed the underlying work, the panelists said
Regulators are already putting that principle into practice. FINRA’s Regulatory Notice 24-09 said firms using generative AI in supervisory systems, including to review electronic correspondence, should address technology governance, model-risk management, data privacy and integrity, and model reliability. FINRA’s 2026 Regulatory Oversight Report went further by making generative AI a standalone area of focus
Enforcement has also begun without regulators adopting new AI rules. Brian Rubin, an Eversheds Sutherland partner and former SEC and NASD enforcement attorney, pointed to SEC cases involving companies accused of “AI washing,” or exaggerating their AI capabilities. He also noted a FINRA anti-money-laundering case involving a deficient automated identity-verification process
The principle underlying those cases is straightforward, according to the panel. Firms remain responsible for outcomes generated by technology they choose to use
Rubin characterized the emerging regulatory approach as a “show your work” environment. Examiners want to know how AI is actually being used, including who approved a tool, what data it accesses, how its outputs are validated and where humans remain accountable. That creates potentially difficult recordkeeping questions, since there is currently no official requirement governing whether firms should retain operational data or how long those records should be maintained
Rubin recommended beginning with the existing rules. An AI-generated item used in a customer communication, recommendation or marketing material is generally subject to the applicable retention requirement just as it would be if a person created it. Some firms therefore apply full regulatory retention periods to AI records connected with communications, recommendations and supervisory reviews while using shorter periods for lower-risk operational information
But retention alone may not be sufficient. Firms must be able to reconstruct decisions and explain what role an AI system played. That could become difficult when a model used to make a decision has subsequently been updated or retired
The problem resembles regulators’ earlier response to email and, more recently, off-channel communications such as text messages and WhatsApp. Existing books-and-records rules were applied to new communications technologies without rewriting the underlying regulatory framework. Employees using unapproved AI platforms for client-related work could similarly create records beyond their firm’s ability to capture or supervise
Derek Stern, head of global distribution compliance at Manulife Wealth & Asset Management, said firms should involve compliance teams while AI systems are being designed rather than after deployment
Due diligence should examine where data are stored and who can access them; whether the system’s conclusions can be explained and defended; how vendors manage model updates, testing and change management; and how the technology integrates with human review
Firms should also test vendor claims against their own risk scenarios. Jamie Hoyle, vice president of product at MirrorWeb, warned firms to be particularly skeptical of promises to put compliance on “autopilot.”
AI could nevertheless improve supervision. Context-aware systems can potentially replace crude keyword searches that produce large numbers of false positives by interpreting communications against a firm’s actual policies
But Red Oak’s central message is that AI does not transfer accountability from the regulated firm to the technology. Until regulators provide more specific guidance, documentation, explainability and human oversight remain the safest guideposts for firms navigating the technology’s recordkeeping risks

