Re: Regulatory Notice 26-14, Proposed Changes to Modernize Rule 2210 (Communications with the Public)
To the Office of the Corporate Secretary,
I write in a personal capacity, at the industry level, as a quantitative finance and model-risk practitioner. These views are my own and not those of my employer.
The proposal is being debated on the wrong axis. The question is not pre-use approval versus risk-based supervision; it is whether a firm can demonstrate control over the system that produces its communications. When a person drafts a communication, reviewing that communication is a reasonable control. When a generative model drafts ten thousand, reviewing any one of them is theater. The unit of supervision has to move from the message to the model.
The industry does not need to invent that discipline. Supervising a consequential model whose outputs carry regulatory and financial consequence is exactly what model risk management does, and it is a discipline examiners already understand and accept. The interagency guidance most recently issued as SR 26-2 (superseding SR 11-7) codifies it: independent validation before deployment, documented limitations, ongoing monitoring, and effective challenge separate from the business that owns the model. A risk-based standard for AI-generated communications will only be as good as its willingness to import that rigor. Four elements would give it teeth:
1. Pre-deployment validation. Before a generative system is used to produce communications, the firm should validate it against a defined test suite of the very standards Rule 2210 enforces, prohibited claims, misleading performance representations, omitted risk disclosure, and document how it performs. A system is a control only once it has been tested against what it is supposed to prevent.
2. Ongoing output monitoring. Generative models drift as they are updated and as prompts evolve. Supervision cannot be a one-time sign-off; it requires monitoring live output for the same failure modes, with defined thresholds that trigger escalation.
3. Risk-tiered human review. Human oversight should be allocated by consequence, not by volume. High-risk communications, performance claims, complex or leveraged products, route to a person; lower-risk output is governed by sampling. The control that matters is a tested, documented threshold for when a human must intervene, not a blanket rule in either direction.
4. Independent challenge and examinable documentation. The function assessing the system should be independent of the desk using it, and the firm should document the model, its known failure modes, and its controls, so that an examiner can evaluate the control system rather than spot-check its products. Supervision that cannot be inspected is not supervision.
Replacing prescriptive pre-approval with risk-based standards is the right direction, and it is overdue. Whether it protects investors depends on one thing: whether the standard requires firms to govern the generative system with the discipline long applied to other consequential models, or merely lets them describe existing practice as risk-based. The risk in generative communications is never a single message. It is the untested system that can produce ten thousand. Govern the system, and the pre-approval question answers itself.
I would welcome the opportunity to expand on any of these points.
Respectfully submitted, Sarthak Gupta Data Scientist II, Finance Models sarthakgpt.com | linkedin.com/in/sarthakgpt
FINRA Utility Menu
For the Public
FINRA DATA
FINRA Data provides non-commercial use of data, specifically the ability to save data views and create and manage a Bond Watchlist.
For Industry Professionals
FINPRO GATEWAY
Registered representatives can fulfill Continuing Education requirements, view their industry CRD record and perform other compliance tasks.
For Member Firms
FINRA GATEWAY
Firm compliance professionals can access filings and requests, run reports and submit support tickets.
For Case Participants
DR PORTAL
Arbitration and mediation case participants and FINRA neutrals can view case information and submit documents through this Dispute Resolution Portal.
Need Help? | Check System Status
Log In to other FINRA systems
Sarthak Gupta Comment On Regulatory Notice 26-14
Re: Regulatory Notice 26-14, Proposed Changes to Modernize Rule 2210 (Communications with the Public)
To the Office of the Corporate Secretary,
I write in a personal capacity, at the industry level, as a quantitative finance and model-risk practitioner. These views are my own and not those of my employer.
The proposal is being debated on the wrong axis. The question is not pre-use approval versus risk-based supervision; it is whether a firm can demonstrate control over the system that produces its communications. When a person drafts a communication, reviewing that communication is a reasonable control. When a generative model drafts ten thousand, reviewing any one of them is theater. The unit of supervision has to move from the message to the model.
The industry does not need to invent that discipline. Supervising a consequential model whose outputs carry regulatory and financial consequence is exactly what model risk management does, and it is a discipline examiners already understand and accept. The interagency guidance most recently issued as SR 26-2 (superseding SR 11-7) codifies it: independent validation before deployment, documented limitations, ongoing monitoring, and effective challenge separate from the business that owns the model. A risk-based standard for AI-generated communications will only be as good as its willingness to import that rigor. Four elements would give it teeth:
1. Pre-deployment validation. Before a generative system is used to produce communications, the firm should validate it against a defined test suite of the very standards Rule 2210 enforces, prohibited claims, misleading performance representations, omitted risk disclosure, and document how it performs. A system is a control only once it has been tested against what it is supposed to prevent.
2. Ongoing output monitoring. Generative models drift as they are updated and as prompts evolve. Supervision cannot be a one-time sign-off; it requires monitoring live output for the same failure modes, with defined thresholds that trigger escalation.
3. Risk-tiered human review. Human oversight should be allocated by consequence, not by volume. High-risk communications, performance claims, complex or leveraged products, route to a person; lower-risk output is governed by sampling. The control that matters is a tested, documented threshold for when a human must intervene, not a blanket rule in either direction.
4. Independent challenge and examinable documentation. The function assessing the system should be independent of the desk using it, and the firm should document the model, its known failure modes, and its controls, so that an examiner can evaluate the control system rather than spot-check its products. Supervision that cannot be inspected is not supervision.
Replacing prescriptive pre-approval with risk-based standards is the right direction, and it is overdue. Whether it protects investors depends on one thing: whether the standard requires firms to govern the generative system with the discipline long applied to other consequential models, or merely lets them describe existing practice as risk-based. The risk in generative communications is never a single message. It is the untested system that can produce ten thousand. Govern the system, and the pre-approval question answers itself.
I would welcome the opportunity to expand on any of these points.
Respectfully submitted, Sarthak Gupta Data Scientist II, Finance Models sarthakgpt.com | linkedin.com/in/sarthakgpt