Navigating the Regulatory Landscape of AI in U.S. Finance
Artificial Intelligence (AI) has become a focal point for various sectors, especially in finance. Despite an increased emphasis on AI by U.S. financial regulators, including the Securities and Exchange Commission (SEC), the Commodity Futures Trading Commission (CFTC), and the Financial Industry Regulatory Authority (FINRA), no new regulations specifically addressing AI have been enacted. Nevertheless, guidance from these agencies—particularly during the Biden administration—has highlighted the importance of the responsible use of AI within existing regulatory frameworks. This overview will delve into the regulatory landscape surrounding AI in the financial industry, emphasizing obligations and potential compliance risks.
Guidance from Regulatory Bodies
SEC’s Stance on AI
The SEC has made it clear that firms must continue complying with existing regulations, especially as AI integration into business operations introduces heightened operational and regulatory risks. The SEC Division of Examinations has identified AI as a significant risk area. They plan to scrutinize firms using digital engagement practices, including digital investment advisory services, to ensure that adequate policies and procedures are in place to monitor and supervise AI applications.
For instance, the SEC is keen on assessing whether firms are implementing sufficient oversight mechanisms in critical areas such as:
- Trading functions
- Safekeeping of client records
- Fraud prevention and detection
A recent enforcement action highlighted the SEC’s expectation that firms ensure the reliability of automated trading models and establish written policies regarding their use. The failure to fulfill these obligations could result in a breach of fiduciary duty.
Furthermore, the SEC’s Division of Corporate Finance noted that additional disclosures related to AI might be required across various sections of disclosure forms. This includes potential misrepresentations regarding AI’s roles within a firm, with several enforcement actions already taken against registrants for such discrepancies.
FINRA’s Regulatory Concerns
FINRA has identified several regulatory risks associated with AI, including challenges related to recordkeeping, customer information protection, and compliance with Regulation Best Interest (Reg BI). In June 2024, FINRA issued a regulatory notice reminding its member firms of their obligations concerning AI. The notice underscored the necessity for firms to establish robust policies and governance around AI usage, aligned with existing regulatory requirements.
In its 2025 Annual Regulatory Oversight Report, FINRA emphasized that its technology-neutral rules are applicable to AI just as they are to any other technology. Key recommendations for member firms include:
- Supervision of AI at both enterprise and individual levels
- Identification and mitigation of risks associated with AI accuracy and bias
- Implementation of strong cybersecurity measures to combat increasing cyber threats
CFTC’s Approach to AI
The CFTC has similarly reinforced the importance of adhering to its existing technology-neutral rules concerning AI. In December 2024, the CFTC published a nonbinding staff advisory addressing AI’s use by CFTC-regulated entities in the derivatives markets. This advisory was informed by prior public comments and signifies a measured first step in helping the marketplace achieve compliance with the Commodity Exchange Act.
The advisory outlines a variety of potential and current AI use cases, urging CFTC registrants to be cautious when deploying AI for aspects such as risk management and customer protection. Entities are encouraged to update their policies and procedures and to engage with CFTC staff regarding any new risks arising from AI usage.
Noteworthy is that the advisory was crafted under the previous administration and may be influenced by new directives from the current administration’s executive orders. CFTC-regulated entities are advised to remain vigilant for any future regulatory changes stemming from these new policies.
Future Directions
Currently, the regulatory oversight of AI remains a top priority for U.S. financial regulators. Firms are urged to carefully assess how they utilize AI in their operations, updating policies to align with regulatory expectations. It is essential for businesses to maintain inventories of AI tools and implement standard risk management practices, especially considering that many publicly accessible AI applications may expose firms to unmitigated cyber and privacy risks.
Despite the existing uncertainty over the regulatory future of AI, organizations must remain proactive in adapting to the evolving landscape. Flasking individuals accessing unapproved AI tools is critical for safeguarding against potential penalties and regulatory scrutiny. The importance placed on responsible AI use signals that financial firms should ramp up their preparations to stay ahead of compliance requirements, ensuring their operations are not only efficient but also secure and regulated.

