Tiffany Magri – [REDACTED], Principal Regulatory Compliance Advisor
Robert A. Cruz, VP, Information Governance
Smarsh, Inc.
FINRA Regulatory Notice 26-14 – Comments Regarding Communications with the Public
To the Office of the Corporate Secretary,
We appreciate the opportunity to comment on FINRA’s proposed amendments to Rule 2210. Two points frame our comments: first, the rule should remain technology-agnostic; second, it needs additional clarity on communications with the public that use artificial intelligence (AI).
A principles-based, risk-based posture is the only strategically viable direction given the pace of innovation in how firms engage the public. Regulation should remain technology-agnostic. Prescriptive guidance tied to specific modalities will likely be obsolete soon after publication and will raise countless questions about derivatives of that technology—for example, whether references to “video content” include transcripts, participant chats, shared whiteboards, or other collaborative features. SEA 17a-4 illustrates the risk: before its modernization, references to spinning disks and other long-abandoned technologies had become impractical.
A risk-based approach should instead focus on the nature and context of the communication, the information being conveyed, the decisions it influences, and the regulatory and other consequences if that communication is used inappropriately.
Any update should also acknowledge the fundamental change to communications driven by the rapid adoption of AI. The proposal mentions AI only briefly, which limits its usefulness to firms seeking guidance. Virtually every communications tool in use today has AI-generated features, and those outputs can be erroneous or contain deepfakes or hallucinations. Firms need operational clarity on what constitutes adequate testing, how often to monitor, what records to retain, and how governance differs by AI use case. Without it, firms face either over-compliance (an unsustainable burden) or under-compliance (regulatory risk). We ask FINRA to provide use-case-specific guidance, quantitative standards, and measurable thresholds to enable consistent, proportionate compliance.
Our comments on specific communications-related topics follow, based on our engagement across the industry.
QUESTION 2: Social Media
2a. Should FINRA eliminate, modify, or retain the distinction between interactive and static communications?
Eliminate. “Interactive” is heavily nuanced and its context may be inconsequential to a firm’s business, while static content can contain false or misleading statements. The level of oversight should be a firm’s risk-based decision.
2b. How should firms assess whether different platforms or communication types present higher or lower risk requiring different levels of supervisory review, and what factors should they consider?
Risks arise where communications are incomplete, inaccurate, subject to change after delivery, or false or misleading. Factors include, but are not limited to: (1) the method used to capture the communication, including whether it is supported by the original technology provider; (2) the method and location of preservation, including adherence to SEA 17a-4; and (3) the sufficiency of supervisory systems to interpret conversational context, metadata, and interactive elements that may indicate rule violations. Firms should be prepared to defend decisions to support higher-risk platforms, such as ephemeral applications captured by a non-vendor-supported provider.
QUESTION 3: Artificial Intelligence
3a. How is your firm using AI to generate, supervise, review, or approve communications?
We observe a wide variety of use cases, from content generation and compliance review to agent-driven workflow automation. Recurring questions include:
Which use cases trigger Rule 2210 obligations?
Does a pre-publication AI flagging tool itself need to be vetted and tested, or does using a commercial platform suffice?
Do internal AI systems require different governance than third-party services?
Does supervision depend on whether the AI assists humans versus makes recommendations?
The guidance doesn’t distinguish these scenarios, leaving firms uncertain about scope and applicability.
What is needed from FINRA: a Classification Framework emphasizing:
Supervision depends on function, not just AI presence. Content generation (AI drafts, humans approve) requires validating that AI doesn’t systematically miss compliance issues; compliance review (AI flags, humans decide) requires validating that AI accurately identifies real issues without false alarms; transactional automation (factual, rule-based messages) requires lighter supervision focused on data accuracy.
Different rules for internal versus third-party AI. Internal AI: the firm is directly responsible for vetting and ongoing monitoring. Third-party platforms: the firm is responsible for outcomes but may rely on vendor documentation, with independent testing in its own environment.
Clear examples by category. For example: “A firm tested an AI content-generation tool against 75 compliance-approved communications, found a 3% error rate, documents that 100% of AI output receives compliance review, and maintains monthly monitoring logs—compliant supervision.” Examples let firms calibrate their own governance.
3b. What challenges do you face adopting and supervising AI tools?
Firms have generally established initial guardrails and decided either to allow AI in communications with the public or to restrict it in favor of lower-risk internal uses. Common supervisory challenges remain: undefined testing standards, unclear monitoring cadence, and under-defined recordkeeping obligations for monitoring logs, audit trails, and related work product.
What is needed from FINRA:
1. Quantitative testing standards. Content generation: 50–100 representative communications, acceptable error rate <5% for factual claims and <10% for style. Compliance-flagging tools: 100+ communications with false-negative and false-positive rates tracked separately. Transactional automation: 100–200 messages with a <1% error threshold.
2. Defined monitoring frequency by risk tier (quarterly for content generation, monthly for compliance review, annual for automation), with explicit re-test triggers (error rate exceeding threshold, vendor updates, new product types).
3. Clear recordkeeping requirements. Confirm that AI governance records are supervisory records under Rule 3110 requiring 6-year retention; specify required documentation (approval memos, testing protocols and results, monitoring logs, escalation decisions); and clarify that these integrate with existing WSP recordkeeping rather than a separate system.
3c. How do firms currently supervise AI-generated communications?
Practices vary by firm size, expertise, risk posture, geographic footprint, and market segment. A comprehensive, risk-based supervisory framework should set expectations across:
Selection & Approval—tool identification, vendor risk assessment, and decision documentation.
Implementation—human oversight, training, and WSP documentation procedures.
Ongoing Monitoring—spot-check frequency, quarterly deep dives, and re-testing intervals.
Escalation—re-testing triggers and documentation of remediation decisions.
What is needed from FINRA: publish a model best-practice supervisory framework that firms can adapt to their scale and risk profile, creating a common understanding of adequate supervision and a practical template for compliance teams.
3d. How can FINRA facilitate efficiencies while protecting investors?
Following publication of final rules, FINRA should consider:
Adopt risk-based governance tiers. Content generation (AI drafts, human approves) is medium-risk: baseline testing and quarterly monitoring. Compliance review (AI flags, human decides) is higher-risk: rigorous testing, monthly monitoring, and false-positive/negative tracking. Transactional automation (factual alerts) is lower-risk: initial testing and annual spot-checks. Tying governance intensity to actual risk encourages adoption for legitimate use cases while focusing heavy supervision on genuinely risky ones.
Provide quantitative standards, concrete enough to operationalize but flexible enough to adapt to firm circumstances (as detailed above).
Clarify that AI governance is part of Rule 3110. Firms’ WSPs should include an AI-communications section covering tool inventory, vetting criteria, testing protocols, implementation, monitoring cadence, recordkeeping, and escalation—integrating AI governance into existing infrastructure rather than a separate framework.
Establish a transition period with safe harbor. Protect good-faith compliance efforts during transition so firms can demonstrate governance intent even if implementation is incomplete, reducing panic-driven over-compliance.
Continue collaborative forums to share experiences—including assessing third- and fourth-party risks of AI model providers, building inventories of tools suitable for financial-services obligations, and sharing best practices in AI communications governance.
We would welcome the opportunity to collaborate in any of these areas.
FINRA Utility Menu
For the Public
FINRA DATA
FINRA Data provides non-commercial use of data, specifically the ability to save data views and create and manage a Bond Watchlist.
For Industry Professionals
FINPRO GATEWAY
Registered representatives can fulfill Continuing Education requirements, view their industry CRD record and perform other compliance tasks.
For Member Firms
FINRA GATEWAY
Firm compliance professionals can access filings and requests, run reports and submit support tickets.
For Case Participants
DR PORTAL
Arbitration and mediation case participants and FINRA neutrals can view case information and submit documents through this Dispute Resolution Portal.
Need Help? | Check System Status
Log In to other FINRA systems
Smarsh Comment On Regulatory Notice 26-14
Tiffany Magri – [REDACTED], Principal Regulatory Compliance Advisor
Robert A. Cruz, VP, Information Governance
Smarsh, Inc.
FINRA Regulatory Notice 26-14 – Comments Regarding Communications with the Public
To the Office of the Corporate Secretary,
We appreciate the opportunity to comment on FINRA’s proposed amendments to Rule 2210. Two points frame our comments: first, the rule should remain technology-agnostic; second, it needs additional clarity on communications with the public that use artificial intelligence (AI).
A principles-based, risk-based posture is the only strategically viable direction given the pace of innovation in how firms engage the public. Regulation should remain technology-agnostic. Prescriptive guidance tied to specific modalities will likely be obsolete soon after publication and will raise countless questions about derivatives of that technology—for example, whether references to “video content” include transcripts, participant chats, shared whiteboards, or other collaborative features. SEA 17a-4 illustrates the risk: before its modernization, references to spinning disks and other long-abandoned technologies had become impractical.
A risk-based approach should instead focus on the nature and context of the communication, the information being conveyed, the decisions it influences, and the regulatory and other consequences if that communication is used inappropriately.
Any update should also acknowledge the fundamental change to communications driven by the rapid adoption of AI. The proposal mentions AI only briefly, which limits its usefulness to firms seeking guidance. Virtually every communications tool in use today has AI-generated features, and those outputs can be erroneous or contain deepfakes or hallucinations. Firms need operational clarity on what constitutes adequate testing, how often to monitor, what records to retain, and how governance differs by AI use case. Without it, firms face either over-compliance (an unsustainable burden) or under-compliance (regulatory risk). We ask FINRA to provide use-case-specific guidance, quantitative standards, and measurable thresholds to enable consistent, proportionate compliance.
Our comments on specific communications-related topics follow, based on our engagement across the industry.
QUESTION 2: Social Media
2a. Should FINRA eliminate, modify, or retain the distinction between interactive and static communications?
Eliminate. “Interactive” is heavily nuanced and its context may be inconsequential to a firm’s business, while static content can contain false or misleading statements. The level of oversight should be a firm’s risk-based decision.
2b. How should firms assess whether different platforms or communication types present higher or lower risk requiring different levels of supervisory review, and what factors should they consider?
Risks arise where communications are incomplete, inaccurate, subject to change after delivery, or false or misleading. Factors include, but are not limited to: (1) the method used to capture the communication, including whether it is supported by the original technology provider; (2) the method and location of preservation, including adherence to SEA 17a-4; and (3) the sufficiency of supervisory systems to interpret conversational context, metadata, and interactive elements that may indicate rule violations. Firms should be prepared to defend decisions to support higher-risk platforms, such as ephemeral applications captured by a non-vendor-supported provider.
QUESTION 3: Artificial Intelligence
3a. How is your firm using AI to generate, supervise, review, or approve communications?
We observe a wide variety of use cases, from content generation and compliance review to agent-driven workflow automation. Recurring questions include:
The guidance doesn’t distinguish these scenarios, leaving firms uncertain about scope and applicability.
What is needed from FINRA: a Classification Framework emphasizing:
3b. What challenges do you face adopting and supervising AI tools?
Firms have generally established initial guardrails and decided either to allow AI in communications with the public or to restrict it in favor of lower-risk internal uses. Common supervisory challenges remain: undefined testing standards, unclear monitoring cadence, and under-defined recordkeeping obligations for monitoring logs, audit trails, and related work product.
What is needed from FINRA:
1. Quantitative testing standards. Content generation: 50–100 representative communications, acceptable error rate <5% for factual claims and <10% for style. Compliance-flagging tools: 100+ communications with false-negative and false-positive rates tracked separately. Transactional automation: 100–200 messages with a <1% error threshold.
2. Defined monitoring frequency by risk tier (quarterly for content generation, monthly for compliance review, annual for automation), with explicit re-test triggers (error rate exceeding threshold, vendor updates, new product types).
3. Clear recordkeeping requirements. Confirm that AI governance records are supervisory records under Rule 3110 requiring 6-year retention; specify required documentation (approval memos, testing protocols and results, monitoring logs, escalation decisions); and clarify that these integrate with existing WSP recordkeeping rather than a separate system.
3c. How do firms currently supervise AI-generated communications?
Practices vary by firm size, expertise, risk posture, geographic footprint, and market segment. A comprehensive, risk-based supervisory framework should set expectations across:
What is needed from FINRA: publish a model best-practice supervisory framework that firms can adapt to their scale and risk profile, creating a common understanding of adequate supervision and a practical template for compliance teams.
3d. How can FINRA facilitate efficiencies while protecting investors?
Following publication of final rules, FINRA should consider:
We would welcome the opportunity to collaborate in any of these areas.
Respectfully,
Tiffany Magri
Robert A. Cruz