Key Takeaways
- Broker-dealers remain responsible for activities performed with AI assistance
- AI tools should be inventoried, risk-rated, approved, and monitored
- Human oversight should remain part of consequential decisions and regulated activities
- Governance should address data protection, cybersecurity, supervision, recordkeeping, and third-party risk
- Policies and controls should be reviewed as technology and regulatory expectations change
AI is rapidly becoming embedded across broker-dealer operations, including surveillance, compliance, trading, and client communications. While these tools offer meaningful efficiency gains, they also introduce governance, compliance, and operational risks that firms must proactively manage.
Common AI use cases by business function include:
| Business Function | AI Use Cases |
|---|---|
| Front-Office Teams | Use AI-based predictive analytics to inform investment strategies, perform client segmentation, and model risk, and assist in preparing reports, disclosures, and client communications |
| Traders | Analyze market data, venue liquidity, execution quality, and execution speed to inform trading and execution strategies |
| Client Service | Generate client insights, support segmentation, personalize communications, and triage client inquiries |
| Supervisors | Conduct surveillance, identify trends, perform exception reporting, and support routine supervisory reviews |
| Compliance | Accelerate surveillance, testing, and monitoring; identify potentially misleading or non-compliant communications; draft policies and procedures; and conduct regulatory research |
Regulators have been clear: broker-dealers may not replace human judgment with AI. Firms must take care to balance innovation with accountability, implementing governance frameworks to ensure AI is controlled, transparent, and aligned with regulatory expectations.
Key AI Governance Risks for Broker-Dealers
Integrating AI into broker-dealer operations demands careful oversight. In the absence of strong controls, AI tools can cause firms to breach their regulatory and contractual obligations.
AI tools can expose firms and their third-party vendors to risks such as:
- Expose confidential or material nonpublic information by sharing it with unprotected AI systems
- Compromise cybersecurity by expanding the firm’s attack surface and introducing new attack vectors
- Issue communications that are misleading, unbalanced, or unfair
- Rely on inaccurate, biased, or fabricated outputs, including hallucinations
- Create supervisory blind spots if AI output is opaque, induces overreliance, or acts without supervisory review
- Fail to preserve required records, including AI inputs, outputs, prompts, and data supporting decisions
- Deploy AI tools without adequately explaining their uses, limitations, and risks
- Make misleading or overstated claims about AI capabilities (“AI washing”), a practice that has resulted in SEC and criminal enforcement actions
- Use a third party’s proprietary work product without attribution or permission, exposing the firm to intellectual property claims
- Lose access to an AI input or process if a government bans or restricts the use of an AI system
These risks underscore the need for comprehensive policies, rigorous monitoring, and effective governance of AI in broker-dealer environments.
How to Build an Effective AI Governance Program
An effective AI governance program integrates AI risk management with business operations. In practice, this requires cross-functional collaboration among compliance, legal, information technology, risk management, and business teams, including trading, client service, operations, and marketing. Human resources and cybersecurity professionals should also contribute. This collaboration is often managed by a centralized governance committee.
As a first step, the AI committee should identify AI tools already operating or under consideration and use that information to develop a definition of AI that reflects the firm’s actual use cases and can serve as the foundation for the firm’s AI policies and procedures. Off-the-shelf frameworks should be customized to the firm’s operations and risk profile.
Firm leadership should require AI tools to be submitted to the committee for approval and prohibit the use of unapproved tools. Tools already in use should be given a defined grace period to complete the approval process. Given the growing use of unauthorized (“shadow”) AI, firms should also consider implementing technical controls to prevent its use and require employees to periodically certify that they are using only approved AI.
The AI committee should specify the information it requires to evaluate approval requests, including:
- Model design and purpose: Thorough documentation explaining how the AI tool functions, its intended use, and its anticipated benefits to the firm and its clients
- Model validation: Evidence supporting the tool’s reliability, including human validation of the AI tool’s design and output
- Data inputs: The tool’s data sources, data governance, and evidence that the inputs are collected and used appropriately
- Risks and controls: A risk rating and a description of the operational, cyber, legal, and reputational risks, including the individuals or groups the tool may affect, any automated decision-making, adversarial cyber risks, and the safeguards in place to mitigate each risk
- Vendors and third parties: Due diligence on third-party providers and contractual protections
- Governance and accountability: Responsible personnel and oversight structure, including backup plans for AI outages
- Regulatory considerations: Applicable regulations, including privacy requirements under Regulation S-P and Regulation S-ID
- Recordkeeping: Records that must be retained under SEC and FINRA recordkeeping requirements
- Monitoring: Plans to test performance and manage model drift and other emerging risks
The committee should evaluate whether each AI tool’s business benefits outweigh its operational, regulatory, and reputational risks, and whether proposed controls adequately mitigate those risks. The committee should include, or have access to, expertise in compliance, legal, cybersecurity, technology, and risk management to support informed approval decisions.
The approval process should be described in written procedures and shared with all staff. The procedures should also provide that approved AI tools will be added to the firm’s AI inventory, bearing in mind that a thorough and up-to-date AI inventory demonstrates effective governance and supports regulatory readiness. The procedures should also require the AI committee to periodically reassess AI risks, evaluate the effectiveness of controls, and update policies as needed.
Supervision
AI tools can create gaps in supervision if they cannot be understood, challenged, or validated. To manage this risk, firms should use explainable AI where possible and implement controls such as validation, testing, and ongoing monitoring to support effective supervision.
Compliance teams should also support supervisory review of AI-generated communications to ensure they are fair, balanced, not misleading, and compliant with all other applicable rules. Any weaknesses that cannot be resolved should be reported to the committee.
The AI committee can further support supervision by establishing AI supervisory policies consistent with FINRA’s supervision rule (Rule 3110) and reviewing disclosures regarding the firm’s use of AI.
Testing, Monitoring, and Ongoing AI Oversight
The AI committee should assign responsibility to independent functions (e.g., compliance, risk, or internal audit) for testing and monitoring of AI tools.
This includes:
- Validating performance and risk controls
- Reviewing testing and monitoring plans and identifying emerging risks and weaknesses
- Testing recordkeeping practices for compliance with SEC and FINRA requirements
- Evaluating vendors’ AI usage and ensuring that contracts include provisions for data protection and compliance obligations
- Obtaining certifications from employees and vendors, as appropriate
Findings should be reported to both business leadership and the governance committee.
The committee should assign responsibility to its legal and compliance members for monitoring regulatory changes to ensure AI policies remain compliant and update the committee as needed.
Training
Firms should require relevant employees and third-party vendors to complete training on AI risks, the firm’s governance framework and controls, and their respective responsibilities. Firms should also invest in broader AI literacy across the organization. Supervisors and professionals in compliance, audit, and risk management should understand AI tools well enough to test, validate, and challenge their outputs.
Preparing Your AI Governance Program for the Future
AI offers transformative potential for broker-dealers, but realizing that potential requires disciplined governance. Regulatory focus may shift over time, but firms’ obligations to act in their clients’ best interest remain constant. By investing in governance, monitoring, and training, broker-dealers can align innovation with compliance, improve efficiency, manage risk, and support better outcomes for clients and the firm. The key is balancing agility with accountability, ensuring that innovation does not come at the expense of trust.
Conclusion
As AI adoption accelerates, effective governance will increasingly differentiate firms that can innovate confidently from those that struggle to manage emerging risks. By establishing clear governance structures, maintaining human oversight, and aligning AI use with regulatory expectations, broker-dealers can harness AI’s benefits while protecting clients, strengthening compliance, and building long-term trust.
Connect with an ACA expert to begin your AI governance journey.
Frequently Asked Questions
What is AI governance for broker-dealers?
AI governance is the framework of policies, procedures, controls, and oversight that helps broker-dealers use AI responsibly and in compliance with regulatory expectations. An effective AI governance program establishes clear accountability for AI systems, manages operational and compliance risks, and ensures that AI-assisted activities remain subject to appropriate human oversight. While AI can improve efficiency and decision-making, firms remain responsible for complying with applicable securities laws and regulations.
Why do broker-dealers need an AI governance program?
As AI adoption expands across trading, compliance, supervision, and client service, broker-dealers face new operational, cybersecurity, legal, and regulatory risks. An AI governance program helps firms evaluate AI tools before deployment, monitor their ongoing performance, document decision-making, and maintain compliance with Securities and Exchange Commission (SEC) and Financial Industry Regulatory Authority (FINRA) requirements. Strong governance helps demonstrate to regulators that AI risks are being proactively managed.
What are the biggest AI compliance risks for broker-dealers?
Common AI-related compliance risks include:
- Inaccurate or fabricated AI-generated content (“hallucinations”)
- Biased or unreliable outputs that affect decision-making
- Misleading client communications or marketing materials
- Exposure of confidential or material nonpublic information
- Inadequate supervision of AI-assisted activities
- Failure to retain required books and records
- Third-party and cybersecurity risks
- Misrepresenting a firm’s AI capabilities, sometimes referred to as “AI washing”
Identifying and mitigating these risks should be a core objective of every AI governance program.
What do the SEC and FINRA expect regarding AI use?
The SEC and FINRA have emphasized that existing regulatory obligations continue to apply when firms use AI, even without a comprehensive AI-specific rulebook. Broker-dealers remain responsible for supervising their business, protecting customer information, maintaining required records, managing conflicts of interest, and ensuring that communications with the public are fair, balanced, and not misleading. Firms should not rely solely on AI to satisfy these obligations and should maintain appropriate human oversight.
What should an AI governance committee oversee?
An AI governance committee should provide cross-functional oversight of the firm’s AI use.
Responsibilities may include:
- Reviewing and approving new AI tools
- Maintaining an inventory of approved AI applications
- Assessing operational, compliance, legal, and cybersecurity risks
- Monitoring AI performance and model drift
- Overseeing third-party AI vendors
- Updating AI policies and procedures as regulatory expectations evolve
- Coordinating employee training and AI awareness initiatives
The committee typically includes representatives from compliance, legal, information technology (IT), cybersecurity, risk management, business operations, and other relevant functions.
How can firms supervise the use of generative AI?
Generative AI should support—not replace—human judgment. Firms should establish policies governing approved use cases, require supervisory review of AI-generated communications where appropriate, validate AI outputs before relying on them, and regularly monitor AI tools for accuracy and consistency. Training employees on the appropriate use and limitations of generative AI is also an important component of effective supervision.
What records should firms retain when using AI?
Depending on how AI is used, firms may need to retain records related to AI-generated communications, decisions, prompts, outputs, approvals, testing, monitoring activities, and governance documentation in accordance with applicable SEC and FINRA recordkeeping requirements. Maintaining thorough documentation can help demonstrate effective governance during regulatory examinations and support internal oversight.
How can broker-dealers prepare for future AI regulation?
The regulatory landscape for AI continues to evolve. Rather than waiting for new rules, firms should establish a scalable AI governance framework that includes risk assessments, documented policies, ongoing monitoring, employee training, and periodic reviews of AI systems. A proactive approach helps firms adapt to evolving regulatory expectations while continuing to realize the benefits of AI innovation.
Skip to content